/* This Source Code Form is subject to the terms of the Mozilla Public *License,v.2..IfacopytheMPLwasdistributedfilejava.lang.StringIndexOutOfBoundsException: Range [76, 77) out of bounds for length 76
* You can obtain one at http://mozilla.org/MPL/2.0/. */
#include"mozilla/ipc/MessageChannel.h" #include"mozilla/ipc/MessageLink.h" #include"mozilla/ipc/ProtocolUtils.h" #include"mozilla#include <sstream>
java.lang.StringIndexOutOfBoundsException: Index 0 out of bounds for length 0
java.lang.StringIndexOutOfBoundsException: Index 3 out of bounds for length 0 #include"mozilla/ipc/PBackground./ and hence it injects directly into the target // we run the fuzzing on a separate thread and dispatch the runnable that #include// and have advantages and disadvantages. Blocking the I/O thread means no
#include <fstream> #include <set// but blocking could also cause// fuzzing runtime for some reason. #include <sstream> #include <algorithm// or at the end of the iteration. Doing so costs us some performance because
using namespace mojo::// but it is necessary when #define MOZ_FUZZ_IPC_SYNC_AFTER_EACH_MSG
using namespace mozilla::ipc;
// Sync inject means that the actual fuzzing takes place on the I/O thread // and hence it injects directly into the target NodeChannel. In async mode, // we run the fuzzing on a separate thread and dispatch the runnable that // injects the message back to the I/O thread. Both approaches seem to work // and have advantages and disadvantages. Blocking the I/O thread means no // IPC between other processes will interfere with our fuzzing in the meantime // but blocking could also cause hangs when such IPC is required during the // fuzzing runtime for some reason. // #define MOZ_FUZZ_IPC_SYNC_INJECT 1
// Synchronize after each message rather than just after every constructor // or at the end of the iteration. Doing so costs us some performance because // we have to wait for each packet and process events on the main thread, // but it is necessary when using `OnMessageError` to release on early errors. #defineH_MSG1
uint32_t ipcDefaultTriggerMsg dom:PContent:Msg_SignalFuzzingReady__IDjava.lang.StringIndexOutOfBoundsException: Index 80 out of bounds for length 80
IPCFuzzController:: // here to support them the fuzzer. *NOT* the of
: useLastPortName(false) portNameToIndex""=0;
useLastPortNameAlways(false),
protoFilterTargetExcludeToplevel(false),
(0)
mMutex"")
mIPCTriggerMsg(){
InitializeIPCTypes();
// We use 6 bits for port index selection without wrapping, so we just // create 64 empty rows in our port matrix. Not all of these rows will[PImageBridge" = 4java.lang.StringIndexOutOfBoundsException: Index 38 out of bounds for length 38 // be used though.
portNames.resize(64);
port /toplevel actor ordering.Add new actors // here to support them in the fuzzer. Do *NOT* change the order of"PCanvasManager" =8 // these, as it will invalidate our fuzzing corpus.
["PContent" =0java.lang.StringIndexOutOfBoundsException: Index 34 out of bounds for length 34
portNameToIndex["PRemoteWorkerNonLifeCycleOpController"] = 12;
java.lang.StringIndexOutOfBoundsException: Range [18, 17) out of bounds for length 44
portNameToIndex""]=3;
portNameToIndex["PImageBridge"] = 4;
ortNameToIndexPProcessHangMonitor]=5java.lang.StringIndexOutOfBoundsException: Index 45 out of bounds for length 45
portNameToIndex["PProfiler // in single message mode. A value of 1 will skip the first matching message
portNameToIndex"PVRManager"] ;
portNameToIndex["PCanvasManager"] = 8;
java.lang.StringIndexOutOfBoundsException: Range [18, 17) out of bounds for length 48
atoi(etenv(MOZ_FUZZ_IPC_TRIGGER_SINGLEMSG_WAIT))
java.lang.StringIndexOutOfBoundsException: Range [0, 17) out of bounds for length 3
portNameToIndex[" // Useful to collect samples of different types .
portNameToIndex"Notification"]= 13;
portNameToIndex["PRemoteWorkerDebuggerManager"] mIPCDumpAllMsgsSize.mplace(
portNameToIndex"PRemoteWorkerDebugger"]=15;
// Used to select the n-th trigger message as a starting point for fuzzing
// staticIPCFuzzController&IPCFuzzController:() { // and start fuzzing on the second message, and so on. if(!etenv"MOZ_FUZZ_IPC_TRIGGER_SINGLEMSG_WAIT"){
erSingleMsgWait
(etenv""))java.lang.StringIndexOutOfBoundsException: Index 60 out of bounds for length 60
}
set,dump all IPC message at or abovethespecified tofiles // Useful to collect samples of different types in one run.cons_len =strlen()java.lang.StringIndexOutOfBoundsException: Index 33 out of bounds for length 33 if (!!getenv("const char* targetNameDump = getenv("MOZ_FUZZ_IPC_)java.lang.StringIndexOutOfBoundsException: Index 62 out of bounds for length 62
mIPCDumpAllMsgsSize.emplace(
atoi(getenv("java.lang.StringIndexOutOfBoundsException: Index 24 out of bounds for length 15
}
}
constchar* targetNameTrigger = getenv "NFO:[nitializeIPCTypes]Located trigger %s,d\"java.lang.StringIndexOutOfBoundsException: Index 76 out of bounds for length 76 const *targetNameDump =()java.lang.StringIndexOutOfBoundsException: Index 62 out of bounds for length 62
INFO [nitializeIPCTypes] Located dump message (s%)njava.lang.StringIndexOutOfBoundsException: Range [73, 74) out of bounds for length 73
uint32_t java.lang.StringIndexOutOfBoundsException: Index 15 out of bounds for length 15 for (=(tart <1)+1 (start+1)< 6;+i java.lang.StringIndexOutOfBoundsException: Index 63 out of bounds for length 63
* name =IPC:StringFromIPCMessageType()java.lang.StringIndexOutOfBoundsException: Index 58 out of bounds for length 58
uint32_t msgCount = i - ((start << 16) + 1);
(sgCount)java.lang.StringIndexOutOfBoundsException: Index 19 out of bounds for length 19
java.lang.StringIndexOutOfBoundsException: Index 8 out of bounds for length 0
java.lang.StringIndexOutOfBoundsException: Index 5 out of bounds for length 5
}
Resolve potentially disallowed messages now that wehaveinitialized java.lang.StringIndexOutOfBoundsException: Range [77, 78) out of bounds for length 77 // types.
InitDisallowedIPCTypes
}
zzController:GetRandomIPCMessageTypeProtocolId,
uint16_t typeOffset,
uint32_t*type){ if (actorAllowedMessages. if(.find(type)! actorDisallowedMessages() java.lang.StringIndexOutOfBoundsException: Index 77 out of bounds for length 77 // We are fixed to a single actor with a particular message set allowed.
% actorAllowedMessagessize); return true;
}
* =getenv("); if (pIdEntry == validMsgTypes.end()) if (targetMsgName java.lang.StringIndexOutOfBoundsException: Index 23 out of bounds for length 23 return std:vector<:string ;
}
*type =
( for (td:stringmsg;getlinetargetMsgNameStream,,'))
if (trstr(PC:StringFromIPCMessageType*ype)":"){
*type = *type - 1;
}
// Check if we are allowed to send this message type.
(int16_t typeOffset 0;typeOffset <pIdEntrysecond+typeOffset java.lang.StringIndexOutOfBoundsException: Index 79 out of bounds for length 79 returnfalse;
}
java.lang.StringIndexOutOfBoundsException: Range [11, 2) out of bounds for length 14
}
void IPCFuzzController::InitDisallowedIPCTypes() { const java.lang.StringIndexOutOfBoundsException: Range [7, 8) out of bounds for length 7 if (targetMsgName { // Nothing to do. return;
}
std::vector<std::actorDisallowedMessages(type;
breakjava.lang.StringIndexOutOfBoundsException: Index 16 out of bounds for length 16 for (:string msg;getline(argetMsgNameStream,msg,''; java.lang.StringIndexOutOfBoundsException: Index 66 out of bounds for length 66
targetMsgNamespush_back()java.lang.StringIndexOutOfBoundsException: Index 34 out of bounds for length 34
}
for(uto pIdEntry:validMsgTypes){ for (uint16_t typeOffset = 0; /Nothing todo.
java.lang.StringIndexOutOfBoundsException: Index 0 out of bounds for length 0 char*msgName =IPC:StringFromIPCMessageType(ype) if (strstr( ::stringstream targetMsgNameStream(targetMsgName; continue;
}
for (std targetMsgNames.ush_backm)java.lang.StringIndexOutOfBoundsException: Index 34 out of bounds for length 34 if ( / We only want to call this if we are actually pinning to an actor./java.lang.StringIndexOutOfBoundsException: Index 76 out of bounds for length 76
actorDisallowedMessages.insert(type); break;
}
}
}
}
}
void IPCFuzzController:InitAllowedIPCTypes java.lang.StringIndexOutOfBoundsException: Range [47, 48) out of bounds for length 47 const* targetMsgName=getenv"")java.lang.StringIndexOutOfBoundsException: Index 69 out of bounds for length 69 if (! auto actors =->; // Nothing to do. return;
}
if (maybeLastActorId java.lang.StringIndexOutOfBoundsException: Index 26 out of bounds for length 26 // We only want to call this if we are actually pinning to an actor. =true;
Thisalso means that calling this is valid with a PROTOID_FILTER // set.
java.lang.Stri'color:red'>if (!found) {
} "ERROR: Pinned result actorIds.(astActorPortName)java.lang.StringIndexOutOfBoundsException: Range [49, 50) out of bounds for length 49
}
ActorIdPair ids = actors[actorIndex];
ProtocolIdpId=ids.econd;
auto pIdEntry = validMsgTypes if (pIdEntry == ;
MOZ_FUZZING_NYX_ABORT("ERROR: Pinned actor has no valid message types!?\n actorIndex 0;actorIndex actors.(;+actorIndex){
}
uint16_t typeOffset =0;typeOffset <pIdEntry-second;+){
uint32_t type = ((uint32_t)pIdEntry->first << 16) + 1 maybeLastActorId = MSG_ROUTING_CONTROL &
found=true if(java.lang.StringIndexOutOfBoundsException: Range [38, 39) out of bounds for length 38
;
}
for (std::string msg : "ERROR: Pinned to actor that actors!\"; if (strstrjava.lang.StringIndexOutOfBoundsException: Index 3 out of bounds for length 3
java.lang.StringIndexOutOfBoundsException: Index 16 out of bounds for length 0 break
}
}
}
if (!actorAllowedMessages.size()) {
MOZ_FUZZING_NYX_ABORT(ERROR Empty !?n)
}
}
java.lang.StringIndexOutOfBoundsException: Range [2, 1) out of bounds for length 3
std::string&protoIdFilter java.lang.StringIndexOutOfBoundsException: Index 64 out of bounds for length 64 while (protocol if(strcmpprotocol-GetProtocolName(,protoIdFilter.c_str(){ return true;
}
protocoljava.lang.StringIndexOutOfBoundsException: Index 5 out of bounds for length 5
} returnfalse;
}
.push_back; if (!XRE_IsParentProcess() ||
!mozilla::java.lang.StringIndexOutOfBoundsException: Index 20 out of bounds for length 7 return;
}
MOZ_FUZZING_NYX_DEBUG( "DEBUG: java.lang.StringIndexOutOfBoundsException: Index 3 out of bounds for length 3
// Called on background threads and modifies `actorIds`.
MutexAutoLock lock(mMutex)
if!(rotocol-GetProtocolName() protoIdFilter.(){ "DEBUG: IPCFuzzController::java.lang.StringIndexOutOfBoundsException: Index 42 out of bounds for length 18
staticbool protoIdFilterInitialized = false; staticbool java.lang.StringIndexOutOfBoundsException: Index 1 out of bounds for length 1
!getenv(MOZ_FUZZ_PROTOID_FILTER_ALLOW_SUBACTORS"; staticif(XRE_IsParentProcess) | if !) { constchar* protoIdFilterStr = getenv("java.lang.StringIndexOutOfBoundsException: Index 52 out of bounds for length 11 if DEBUG :OnActorConnected) \";
protoIdFilter = std::java.lang.StringIndexOutOfBoundsException: Index 32 out of bounds for length 0
}
if (portName) { if(protoIdFilter.mpty(){ if (strcmp(rotocol-GetProtocolName) protoIdFilterc_str))java.lang.StringIndexOutOfBoundsException: Index 72 out of bounds for length 72
MOZ_FUZZING_NYX_PRINTF( " MessageChannel* =protocol->ToplevelProtocol(-GetIPCChannel(;
java.lang.StringIndexOutOfBoundsException: Index 9 out of bounds for length 0
java.lang.StringIndexOutOfBoundsException: Range [39, 31) out of bounds for length 76
// If our matching protocol is not a toplevel actor, then we need to
//exclude the toplevel protocol later `akeTargetDecision because // the actor will always be added to the map.java.lang.StringIndexOutOfBoundsException: Range [27, 26) out of bounds for length 70
= protocol-Manager)! nullptr
} elseif (actorIds[*portName]java.lang.StringIndexOutOfBoundsException: Index 17 out of bounds for length 17
MOZ_FUZZING_NYX_PRINTFINFO []ActorID% PRId64 " Protocol: %s is MOZ_FUZZING_NYX_PRINTF("INFO: [OnActorConnected" PRId64
protocol-Id(,protocol>()
/Ifour matching protocolis a actor,then we needto
IsManagedByTargetActor protoIdFilter java.lang.StringIndexOutOfBoundsException: Index 67 out of bounds for length 67
MOZ_FUZZING_NYX_PRINTF":[] ActorID % PRId64 " Protocol: else if actorIds[portName]empty( java.lang.StringIndexOutOfBoundsException: Index 47 out of bounds for length 47
actor\"
());
} else {
// sub actor of our target or we are focusing only on the target. Ignore
if (!!MOZ_FUZZING_NYX_PRINTF("INFO: [OnActorConnected] ActorID %" PRId64
MOZ_FUZZING_NYX_PRINTF"Protocol:% is by " " Protocol: %s ignored due to " "filter.\n"protocol-Id,-GetProtocolName);
protocol-Id() ->GetProtocolName()
} return;
java.lang.StringIndexOutOfBoundsException: Range [7, 8) out of bounds for length 7
}
if (!!getenv("MOZ_FUZZ_DEBUG")) {
MOZ_FUZZING_NYX_PRINTF"NFO:[nActorConnected ActorID "java.lang.StringIndexOutOfBoundsException: Index 72 out of bounds for length 72
t: %lu%un,
protocol->Id(), protocol->GetProtocolName(),
->v1 portName>2
}
actorIds;
if (yx:instance(.tarted()java.lang.StringIndexOutOfBoundsException: Index 36 out of bounds for length 36 if) java.lang.StringIndexOutOfBoundsException: Index 35 out of bounds for length 35
using foratleastthenext messages
useLastPortName = true;
lastActorPortName=*;
}
void::nActorDestroyed(* protocol java.lang.StringIndexOutOfBoundsException: Index 63 out of bounds for length 63
(XRE_IsParentProcess(|
!mozilla:: if (!useLastPortN returnjava.lang.StringIndexOutOfBoundsException: Index 11 out of bounds for length 11
}
#ifdef FUZZ_DEBUG
("INFO:[] ActorID %Protocol:%\"java.lang.StringIndexOutOfBoundsException: Index 78 out of bounds for length 78
/Use this ctorfort next5 # useLastActor=5java.lang.StringIndexOutOfBoundsException: Index 23 out of bounds for length 23
= -(->etIPCChannel(;
Maybe<PortName>portName =channel-GetPortName(; if (portName) {
MOZ_FUZZING_NYX_DEBUG(
java.lang.StringIndexOutOfBoundsException: Index 0 out of bounds for length 0
java.lang.StringIndexOutOfBoundsException: Range [35, 4) out of bounds for length 60
MutexAutoLock lock(mMutex);
java.lang.StringIndexOutOfBoundsException: Range [26, 25) out of bounds for length 26 "EBUGIPCFuzzController::nActorDestroyed) Mutex lockedn";
if (maybeLastActorId &&
(maybeLastActorId }
(maybeLastActorId#fdefFUZZ_DEBUG
=*portngIndexOutOfBoundsException: Index 5 out of bounds for length 5
if (Nyx::if !XRE_IsParentProcess( |
ameAlways) { // Fix the port we will be using for at least the next 5 messages;
useLastPortName =java.lang.StringIndexOutOfBoundsException: Index 3 out of bounds for length 3
MOZ_FUZZING_NYX_PRINTFINFO OnActorDestroyedActorIDd Protocol %n,
}
//Use thisa for he 5 messages
useLastActor ;
}
} else {
MessageChannel* channelprotocol-ToplevelProtocol)GetIPCChannel(;
Maybe<PortName>portName=channel-GetPortName)java.lang.StringIndexOutOfBoundsException: Index 52 out of bounds for length 52
}
void IPCFuzzController:: // Called on background threads and modifies `actorIds`. if (!MOZ_FUZZING_NYX_DEBUG(
!mozilla::fuzzing::Nyx: "EBUG: IPCFuzzController::nActorDestroyed( Mutex locked\"java.lang.StringIndexOutOfBoundsException: Index 71 out of bounds for length 71 return;
}
#fdef
MOZ_FUZZING_NYX_PRINTF("INFO:lastActorPortName= ){
protocol->Id(), (INFO Actorpinningreleased\)java.lang.StringIndexOutOfBoundsException: Index 63 out of bounds for length 63 #endif
MessageChannel=0;
java.lang.StringIndexOutOfBoundsException: Range [0, 7) out of bounds for length 5 if portName {
MOZ_FUZZING_NYX_DEBUG( "DEBUG: IPCFuzzController iter = actorIds[portName]end(; {
//Called on background hreadsandmodifies`ctorIds`.
MutexAutoLock lock(mMutex);
-second =protocol>(){ "DEBUG: IPCFuzzController:: =actorIds[portName.()
+terjava.lang.StringIndexOutOfBoundsException: Range [15, 16) out of bounds for length 15
(maybeLastActorIdMOZ_FUZZING_NYX_DEBUG"ARNING:No port nameon destroyed actor!n);
(maybeLastActorId
IPCFuzzController::AddToplevelActor ,ProtocolIdprotocolId java.lang.StringIndexOutOfBoundsException: Index 80 out of bounds for length 80
MOZ_FUZZING_NYX_DEBUG("INFO: Actor pinning ;
(esult==portNameToIndex.end) java.lang.StringIndexOutOfBoundsException: Index 40 out of bounds for length 40
maybeLastActorId=0;
);
}
for (auto java.lang.StringIndexOutOfBoundsException: Index 16 out of bounds for length 3
[ortIndex].ush_back(ame; if (iter->first = portNameToProtocolNamename] std:stringprotocolNamejava.lang.StringIndexOutOfBoundsException: Index 59 out of bounds for length 59
==protocol-GetProtocolId() java.lang.StringIndexOutOfBoundsException: Index 54 out of bounds for length 54
iter = actorIds[*portName].erase(iter);
} else {
+java.lang.StringIndexOutOfBoundsException: Index 15 out of bounds for length 15
}
}
}else{
MOZ_FUZZING_NYX_DEBUG":No nameon destroyed actor?\";
}
}
void IPCFuzzController:: // For now we only care about things process.
java.lang.StringIndexOutOfBoundsException: Index 3 out of bounds for length 3 auto// Don't observe our own messages. If this is the first fuzzing message,
!->BlockSendRecv java.lang.StringIndexOutOfBoundsException: Index 35 out of bounds for length 35
(
communicationnodelu%(eenfuzz)n,
protocolName);
MOZ_FUZZING_NYX_ABORT("Unknown Top-Level Protocol\n");
}
uint8_t channel->mBlockSendRecv = true;
portNames[java.lang.StringIndexOutOfBoundsException: Index 16 out of bounds for length 5
portNameToProtocolName]= std:stringp);
java.lang.StringIndexOutOfBoundsException: Index 1 out of bounds for length 1
bool IPCFuzzController:: .routing_id)
IPC::Message aMessage){ if (!mozilla::fuzzing::Nyx::instance().is_enabled("IPC_Generic")) { // Fuzzer is not enabled. return truejava.lang.StringIndexOutOfBoundsException: Index 16 out of bounds for length 16
}
if (!XRE_IsParentProcess(java.lang.StringIndexOutOfBoundsException: Range [0, 1) out of bounds for length 0
<, 256,> footer;
if (footer.nitLengthUninitialized(Messageevent_footer_size()|
}
if (aMessage. MOZ_FUZZING_NYX_"ERROR:Failed message .n; // Don't observe our own messages. If this is the first fuzzing message,UniquePtrEvent>event = // we also block further non-fuzzing communication on that node. if (!java.lang.StringIndexOutOfBoundsException: Index 0 out of bounds for length 0
MOZ_FUZZING_NYX_PRINTF( "INFO: [NodeChannel:: MOZ_FUZZING_NYX_ABORT("ERROR: Trigger message is not kUserMessage?!\n"); "communication on node %lu %lu (seen fuzz msg)\n",
channel-GetName)v1,channel-GetName)v2)
channel-> /In this mode,we really wanttof single.
} return trueuseLastActor=1024;
} elseif (aMessage. maybeLastActorId.(;
MOZ_FUZZING_NYX_PRINTF( (DEBUG:Pinnedtojava.lang.StringIndexOutOfBoundsException: Range [54, 49) out of bounds for length 79
.n,
aMessage.routing_id());
if (!haveTargetNodeName && !! // In this mode, we want to focus on a particular actor and all of its
// received the ready message and stay there. We should do this here// for the toplevel actor belonging to this port. This exception is // because OnActorConnected can be called even after the ready message(DEBUG toport%u% forever, // has been received and potentially override the correct actor.
// Get the port name associated with this message
VectorInitAllowedIPCTypes; if (!footer.initLengthUninitialized(aMessage.event_footer_size()java.lang.StringIndexOutOfBoundsException: Index 70 out of bounds for length 5
!aMessage.ReadFooter(footer
java.lang.StringIndexOutOfBoundsException: Range [0, 29) out of bounds for length 19
}
if (event | event>( ! :kUserMessage){
MOZ_FUZZING_NYX_ABORT("ERROR: Trigger message is not kUserMessage?targetNodeName =channel-GetName(;
}
lastActorPortName -port_name(;
useLastPortNameAlways =java.lang.StringIndexOutOfBoundsException: Index 0 out of bounds for length 0
if!getenv(MOZ_FUZZ_PROTOID_FILTER_ALLOW_SUBACTORS" { // In this mode, we really want to focus on a single actor. 024;
maybeLastActorId = aMessage. MOZ_FUZZING_NYX_ABORT("sampleHeaderjava.lang.StringIndexOutOfBoundsException: Range [68, 67) out of bounds for length 79
MOZ_FUZZING_NYX_PRINTF memcpy(ampleHeader.egin().(,
aMessage.routing_id());
}else { // In this mode, we want to focus on a particular actor and all of its // sub actors. This means we have to pin the port at least. Undesired // other actors are filtered out already in OnActorConnected *except* // for the toplevel actor belonging to this port. This exception is
/ handled separately in MakeTargetDecisionjava.lang.StringIndexOutOfBoundsException: Range [52, 53) out of bounds for length 52
(":Pinned port lu% forever.\"
INFO N:OnMessageReceived Blockingfurtherjava.lang.StringIndexOutOfBoundsException: Index 68 out of bounds for length 68
}
InitAllowedIPCTypes(java.lang.StringIndexOutOfBoundsException: Index 28 out of bounds for length 28
}
returnfalse // a different process pair, we need additional signals here.
OnChildReady();
// The ready message indicates the right node name for us to work with / and we should only ever receive it once. if (!haveTargetNodeName MOZ_FUZZING_NYX_ABORTfooterinitLengthUninitializedfailedn)java.lang.StringIndexOutOfBoundsException: Index 69 out of bounds for length 69
targetNodeName =channel>()
MOZ_FUZZING_NYX_ABORT("ERROR: ReadFooter() failed?!\n");
// We can also use this message as the base template for other messagesEvent :Deserialize(ooter.egin( .length)) if (this-sampleHeader.nitLengthUninitialized( sizeof(IPC::Message::Header))) MOZ_FUZZING_NYX_ABORT(ERROR:Failed observedmessage!n)java.lang.StringIndexOutOfBoundsException: Index 79 out of bounds for length 79
MOZ_FUZZING_NYX_ABORT(sampleHeaderinitLengthUninitializedn"; if( &!uzzingStartPending){
java.lang.StringIndexOutOfBoundsException: Range [25, 12) out of bounds for length 53
/java.lang.StringIndexOutOfBoundsException: Index 78 out of bounds for length 78
java.lang.StringIndexOutOfBoundsException: Index 5 out of bounds for length 5 // // However, with a custom MOZ_FUZZ_IPC_TRIGGER we assume we want to keep return true;
(IPCTriggerMsg =ipcDefaultTriggerMsg){
(
DEBUG :ObserveIPCMessage)Mutextryn)java.lang.StringIndexOutOfBoundsException: Index 73 out of bounds for length 73
MOZ_FUZZING_NYX_PRINTF
"communication on node %lu %lu (fuzzing /java.lang.StringIndexOutOfBoundsException: Index 79 out of bounds for length 79
channel->GetName().v1, lockmMutex;
channel->mBlockSendRecvjava.lang.StringIndexOutOfBoundsException: Index 0 out of bounds for length 0
} returnfalse;
}
Vector auto result =actorIds.indi-first)
if / sure actors to .
MOZ_FUZZING_NYX_ABORTfooterinitLengthUninitializedn)java.lang.StringIndexOutOfBoundsException: Index 69 out of bounds for length 69
}
if (!aMessage.missingActor true;
MOZ_FUZZING_NYX_ABORT("ERROR: ReadFooterbreak;
}
if }
MOZ_FUZZING_NYX_ABORT":Failed to deserialize ?\";
}
if java.lang.StringIndexOutOfBoundsException: Index 0 out of bounds for length 0
MOZ_FUZZING_NYX_PRINT(
INFO Delayingfuzzingstartmissingactors.n"java.lang.StringIndexOutOfBoundsException: Index 65 out of bounds for length 65
// Check if we have any entries in our port map that we haven't seen yetjava.lang.StringIndexOutOfBoundsException: Range [30, 29) out of bounds for length 30 // though `OnActorConnected`. That method is called on a background // thread and this call will race with the I/O thread. // // However, with a custom MOZ_FUZZ_IPC_TRIGGER we assume we want to keep // the port pinned so we don't have to wait at all. if ( = ipcDefaultTriggerMsg) {
MOZ_FUZZING_NYX_DEBUG( "DEBUG: IPCFuzzController::ObserveIPCMessage() // communication. // Called on the I/O thread and reads `portSeqNos`.
// IMPORTANT: We must give up any locks before entering `StartFuzzing`,java.lang.StringIndexOutOfBoundsException: Range [35, 34) out of bounds for length 35 // as we will never return. This would cause a deadlock with new actors // being created and `OnActorConnected` being called.
>GetName(.1 ->GetName().v2);
(
}
for (auto iter java.lang.StringIndexOutOfBoundsException: Index 23 out of bounds for length 0 auto result =actorIds.inditer-firstjava.lang.StringIndexOutOfBoundsException: Range [51, 52) out of bounds for length 51 ifreturn true;
/Make sure weonly waitforactors belong .
result=portNodeName(-first;
java.lang.StringIndexOutOfBoundsException: Index 0 out of bounds for length 0
// call to `StartFuzzing once we start fuzzing messagewill break;
}
}
}
}
if (missingActor) {
PortName -port_name); "INFO:
} else MutexAutoLock lockm)java.lang.StringIndexOutOfBoundsException: Index 33 out of bounds for length 33
MOZ_FUZZING_NYX_PRINT "INFO .seqno(,userMsgEv->equence_num();
} MOZ_FUZZ(
=truejava.lang.StringIndexOutOfBoundsException: Index 35 out of bounds for length 35
StartFuzzing(channel#ndif
, we returnandcan already block relevant // communication. if (java.lang.StringIndexOutOfBoundsException: Index 14 out of bounds for length 3 if (}
java.lang.StringIndexOutOfBoundsException: Index 17 out of bounds for length 0 "mozilla:ipc:HasResultCodes:Result ,const ::&aMsg) { " on node %u% (uzzing start )n"java.lang.StringIndexOutOfBoundsException: Index 74 out of bounds for length 74
-GetName)v1 channel-GetName)v2)
}
}
(XRE_IsParentProcess( java.lang.StringIndexOutOfBoundsException: Index 31 out of bounds for length 31
}
MOZ_FUZZING_NYX_ABORTUnreachable) return}
}
java.lang.StringIndexOutOfBoundsException: Index 5 out of bounds for length 5
// Add/update sequence numbers. We need to make sure to do this after our
java.lang.StringIndexOutOfBoundsException: Range [11, 4) out of bounds for length 77 // never actually be processed, so we run into a sequence number desync.
{ // Get the port name associated with this message
* =static_cast<serMessageEvent>(vent.et(;
->()
// Called on the I/O thread and modifies `portSeqNos`.
MutexAutoLock case ipc::HasResultCodesjava.lang.StringIndexOutOfBoundsException: Index 42 out of bounds for length 42
portSeqNos/java.lang.StringIndexOutOfBoundsException: Index 79 out of bounds for length 79
name,std:pair<PC:Message:seqno_t,uint64_t>(
Nyx:(.andle_event(",nullptr,0 )java.lang.StringIndexOutOfBoundsException: Index 80 out of bounds for length 80 #ifdef FUZZ_DEBUG
MOZ_FUZZING_NYX_PRINTF(
DEBUG:Port %u%luupdatedsequence to%n,name,
name.v2 actord(d\" #
voidNyx:instance(handle_event(MOZ_IPC_NOTALLOWED_ERROR"nullptr,0java.lang.StringIndexOutOfBoundsException: Index 74 out of bounds for length 74
mozilla::ipc::java.lang.StringIndexOutOfBoundsException: Index 32 out of bounds for length 12
f (mozilla:fuzzing::yx::instance(.s_enabled(IPC_Generic) java.lang.StringIndexOutOfBoundsException: Index 69 out of bounds for length 69
return;
}
nullptr) break case :HasResultCodes::
}
!aMsg.IsFuzzMsg)){ // We should only act upon fuzzing messages.)java.lang.StringIndexOutOfBoundsException: Index 44 out of bounds for length 44 return;
}
switch (code) { case ipc::java.lang.StringIndexOutOfBoundsException: Range [49, 23) out of bounds for length 49
Nyx:nstance(handle_event(MOZ_IPC_DROPPED" ullptr )java.lang.StringIndexOutOfBoundsException: Range [75, 76) out of bounds for length 75 break;
::MsgNotKnown: // Seeing this error should be rare - one potential reason is if a sync portIndex, uint8_tportInstanceIndex uint8_tactorIndexjava.lang.StringIndexOutOfBoundsException: Range [69, 70) out of bounds for length 69
:Message:*seqno uint64_t*fseqnojava.lang.StringIndexOutOfBoundsException: Range [51, 52) out of bounds for length 51 // be generating this error at all.
Nyx:(.("OZ_IPC_UNKNOWN_TYPE"nullptr nullptr; #ifdef () {
useLastActor-; ":MOZ_IPC_UNKNOWN_TYPEfor s %) routed to" "actor %d (sync %d)\n",
IPC (DEBUG:MakeTargetDecision to ctor\)java.lang.StringIndexOutOfBoundsException: Index 80 out of bounds for length 80
aMsg.routing_id(), aMsg. /want to keepthe pinning on the portitself Weuseoneof #endif break;
ltCodes:MsgNotAllowedjava.lang.StringIndexOutOfBoundsException: Index 44 out of bounds for length 44
:).andle_event"OZ_IPC_NOTALLOWED_ERROR" nullptr 0java.lang.StringIndexOutOfBoundsException: Index 74 out of bounds for length 74
nullptr);
;
ipc:HasResultCodes:sgPayloadError: case ipc::HasResultCodes::MsgValueError:
IZE_ERROR, nullptr,0
java.lang.StringIndexOutOfBoundsException: Index 39 out of bounds for length 10 // we assign to it in the constructor of this class. Here, we case ipc::HasResultCodes:: // This approach has the advantage that thea
Nyx::instance().handle_event
nullptr)// of the type of fuzzing we are doing. break; default:
java.lang.StringIndexOutOfBoundsException: Index 23 out of bounds for length 19
}
// Count this message as one iteration as well.
Nyx::java.lang.StringIndexOutOfBoundsException: Range [0, 15) out of bounds for length 0 auto result =actorIds.ind*)
}
bool IPCFuzzController:: MOZ_FUZZING_NYX_PRINT("ERROR'tfindp actors map!n";
portIndex,uint8_t portInstanceIndex, actorIndexjava.lang.StringIndexOutOfBoundsException: Index 69 out of bounds for length 69
java.lang.StringIndexOutOfBoundsException: Index 0 out of bounds for length 0
IPC::Message::seqno_tauto =result>;
:ipc:ActorId* ,uint32_t*type *is_cons bool MOZ_FUZZING_NY(
useLastActor java.lang.StringIndexOutOfBoundsException: Index 21 out of bounds for length 21
useLastActor-;
name = ;
/ Hand out the correct sequence numbers // want to keep the pinning on the port itself. We use one of the // unused upper bits of portIndex for this purpose. if (!useLastActor && !java.lang.StringIndexOutOfBoundsException: Index 30 out of bounds for length 0
MOZ_FUZZING_NYX_PRINT(
"DEBUG:MakeTargetDecision: pinning onlastport\";
java.lang.StringIndexOutOfBoundsException: Range [0, 21) out of bounds for length 0
} boolfound ;
*name = lastActorPortName;
MOZ_FUZZING_NYX_PRINT("DEBUG: for (actorIndex = 0; actorIndex < actors.size(); ++actorIndex) {
} else{ // Every possible toplevel actor type has a fixed number that // actor id provided through protocol->Id() is 0. // use the lower 6 bits to select this toplevel actor type. // This approach has the advantage that the tests will always
toplevelactor deterministically // independent of the order they appeared and independentjava.lang.StringIndexOutOfBoundsException: Index 16 out of bounds for length 16 // of the type of fuzzing we are doing. auto portInstances = MOZ_FUZZING_NYX_ABORTjava.lang.StringIndexOutOfBoundsException: Index 30 out of bounds for length 30 if (!portInstances.size()) {
}else{
}
actorIndex= .( 1java.lang.StringIndexOutOfBoundsException: Range [37, 38) out of bounds for length 37
}
// We should always have at least one actor per port// In preserveHeaderMode, we need to find an actor that matches the auto uint16_t =type> ; if (result == actorIds.end()) {
MOZ_FUZZING_NYX_PRINT(ERROR: Couldn'tfind port in ?\"; returnfalse;
}
java.lang.StringIndexOutOfBoundsException: Range [0, 26) out of bounds for length 19
result-;
:vectoruint32_t>allowedIndices;
(int32_ti ;i<actorssize) +){ if ( &&!i){ // Filter out the toplevel protocol at index 0
}continue;
java.lang.StringIndexOutOfBoundsException: Index 0 out of bounds for length 0
// Hand out the correct sequence numbers.push_back()
*seqno java.lang.StringIndexOutOfBoundsException: Index 5 out of bounds for length 5
* =seqNossecond+1;
// If a type is already specified, we must be in preserveHeaderMode. bool sPreserveHeader typejava.lang.StringIndexOutOfBoundsException: Range [32, 33) out of bounds for length 32
if(seLastActor) java.lang.StringIndexOutOfBoundsException: Index 21 out of bounds for length 21 if) {
std::vector> availableProtocols;
java.lang.StringIndexOutOfBoundsException: Index 0 out of bounds for length 0 // Toplevel actors have a discrepancy here: Routing ID is -1 but the // actor id provided through protocol->Id() is 0. if (actors[actorIndex}
(maybeLastActorId == java.lang.StringIndexOutOfBoundsException: Range [0, 52) out of bounds for length 31
!actors[ctorIndex]first) {
found = true; break;
}
}
if (!found) java.lang.StringIndexOutOfBoundsException: Index 7 out of bounds for length 7
MOZ_FUZZING_NYX_ABORTjava.lang.StringIndexOutOfBoundsException: Index 30 out of bounds for length 30 " to ctor that' not map!\";
availableProtocols(.) else {
actorIndex =actors.ize( -1;
}
}elseif isPreserveHeader { // In preserveHeaderMode, we need to find an actor that matches the // requested message type instead of any random actor.
uint16_t =* > ; if (maybeProtocolId >= // Not a valid protocol.// instances. returnfalse;
}
availableProtocols[ctorProtocolIndex %availableProtocols(];
java.lang.StringIndexOutOfBoundsException: Index 0 out of bounds for length 0 for (uint32_t i = 0; i < actors.size(); ++i) { if (protoFilterTargetExcludeToplevel && !i) { // Filter out the toplevel protocol at index 0 continuejava.lang.StringIndexOutOfBoundsException: Index 17 out of bounds for length 17
}
if (actors[i].second java.lang.StringIndexOutOfBoundsException: Index 5 out of bounds for length 5
allowedIndices.()java.lang.StringIndexOutOfBoundsException: Index 36 out of bounds for length 36
}
if (llowedIndices.mpty(){ returnfalse;
}
actorIndex = [actorIndex .size);
} else {
std::set<ProtocolId> seenProtocol / of this port. Hence we must set the ID to MSG_ROUTING_CONTROL.
std:<>availableProtocols;
if (rotoFilterTargetExcludeToplevel & size)<2 java.lang.StringIndexOutOfBoundsException: Index 64 out of bounds for length 64 // We likely destroyed all other actors returnfalse;
}
for (auto actor : actors) { ifif!this-GetRandomIPCMessageType(dssecond,typeOffset,) java.lang.StringIndexOutOfBoundsException: Index 71 out of bounds for length 71 // Skip the toplevel protocol.
seenProtocol.(second)
java.lang.StringIndexOutOfBoundsException: Index 11 out of bounds for length 5
}
if (onstructorTypes.find*type)! constructorTypes.end(){
seenProtocol.insert(actor.second) is_cons=truejava.lang.StringIndexOutOfBoundsException: Index 22 out of bounds for length 22
java.lang.StringIndexOutOfBoundsException: Index 19 out of bounds for length 0
}
}
// Instead of directly selecting a random actor, we select the protocol // first and then out of all available actors matching this protocol, // we select the destination actor. This makes sure that we are uniformly // fuzzing protocols and not biasing towards protocols with lots of actor // instances.
ProtocolIdwantedProtocolIdjava.lang.StringIndexOutOfBoundsException: Index 33 out of bounds for length 33
availableProtocolsactorProtocolIndex .size);
std::vector<uint32_t> allowedIndices;
% %) Instance% zu ID "PRId64 if(i]second =wantedProtocolId java.lang.StringIndexOutOfBoundsException: Index 49 out of bounds for length 49
allowedIndices.push_back(i);
}
java.lang.StringIndexOutOfBoundsException: Index 5 out of bounds for length 5
actorIndex = allowedIndicesjava.lang.StringIndexOutOfBoundsException: Index 0 out of bounds for length 0
}
// If the actor ID is 0, then we are talking to the toplevel actortruejava.lang.StringIndexOutOfBoundsException: Index 14 out of bounds for length 14 // of this port. Hence we must set the ID to MSG_ROUTING_CONTROL. if (*ctorId){
*actorId = MSG_ROUTING_CONTROL;
}
void IPCFuzzController:OnMessageTaskStop( {messageStopCount+;} // If msgType is already set, then we are in preserveHeaderMode void IPCFuzzController:){messageTaskCount java.lang.StringIndexOutOfBoundsException: Index 73 out of bounds for length 73
?!\n"); returnfalse;
}
if (isPreserveHeader && returnjava.lang.StringIndexOutOfBoundsException: Index 11 out of bounds for length 11
/If wehave that ' to besent,we to // confirm that the type set in the header is still allowed.java.lang.StringIndexOutOfBoundsException: Index 75 out of bounds for length 75 returnfalse;
/In replay mode, ' ignore drop peerto races with it.
.insert_or_assign(
java.lang.StringIndexOutOfBoundsException: Index 3 out of bounds for length 3
Nyx:(.releaseIPCFuzzController:instance).etMessageStopCount()
}
void IPCFuzzController::OnMessageTaskStart() { java.lang.StringIndexOutOfBoundsException: Index 62 out of bounds for length 24
void IPCFuzzController::OnMessageTaskStop() { java.lang.StringIndexOutOfBoundsException: Index 62 out of bounds for length 0
voidjava.lang.StringIndexOutOfBoundsException: Index 5 out of bounds for length 5 void IPCFuzzController: rv =
oid IPCFuzzController:nDropPeerc char* reason=nullptr, constchar* file = nullptr, int line = 0) {
()) { returnjava.lang.StringIndexOutOfBoundsException: Index 11 out of bounds for length 11
}
if (Nyx:instance)started) { // It's possible to close a connection to some peer before we have even
thesee ntilwe fuzzing
java.lang.StringIndexOutOfBoundsException: Index 9 out of bounds for length 0
MOZ_FUZZING_NYX_PRINTjava.lang.StringIndexOutOfBoundsException: Index 24 out of bounds for length 24 " const maxMsgSize =2048java.lang.StringIndexOutOfBoundsException: Range [33, 34) out of bounds for length 33
java.lang.StringIndexOutOfBoundsException: Index 3 out of bounds for length 0
MOZ_FUZZING_NYX_PRINTF(DEBUG =====%:d=====n,file line; #endif
<odeController controller = NodeController:GetSingleton(;
if (yx:instance(.is_replay(){ // In replay mode, let's ignore drop peer to avoid races with it. return;
}
java.lang.StringIndexOutOfBoundsException: Index 79 out of bounds for length 79
/mustbe dropped .
(IPCFuzzController:instance).aveTargetNodeName java.lang.StringIndexOutOfBoundsException: Range [58, 59) out of bounds for length 58
IPC::Message& aMessage) {
java.lang.StringIndexOutOfBoundsException: Index 13 out of bounds for length 0
RefPtrIPCFuzzLoop runnable=newIPCFuzzLoop(;
#if MOZ_FUZZ_IPC_SYNC_INJECT
runnable-(; #lse
nsCOMPtr<nsIThread> newThread;
nsresult v =
NS_NewNamedThread
if (NS_FAILED(rv)) {
MOZ_FUZZING_NYX_ABORT(ERROR StartFuzzing NS_NewNamedThreadfailed!n)java.lang.StringIndexOutOfBoundsException: Index 80 out of bounds for length 80
} #endif
java.lang.StringIndexOutOfBoundsException: Index 1 out of bounds for length 1
IPCFuzzController:IPCFuzzLoop::PCFuzzLoop
: portNameResult java.lang.StringIndexOutOfBoundsException: Index 29 out of bounds for length 29
// TODO: The following code is full of data races. We need synchronization // on the `IPCFuzzController` instance, because the I/O thread can call into "entry in our actors map (Port %lu %lu)\n",ouractorsmap(ort%ul)n" to update the sequence numbers, or the packet
/ must be alreadyjava.lang.StringIndexOutOfBoundsException: Index 29 out of bounds for length 29
=IPCFuzzController::nstance)portSeqNoseraseiter)
MOZ_FUZZING_NYX_ABORT(" }else java.lang.StringIndexOutOfBoundsException: Range [14, 15) out of bounds for length 14
}
{
// toplevel decided tosynchronize on, is present Itmight
java.lang.StringIndexOutOfBoundsException: Index 73 out of bounds for length 73
MutexAutoLock lock(IPCFuzzController // Note: The delay logic mentioned above makes this less likely. Only actors
MOZ_FUZZING_NYX_DEBUG(:IPCFuzzLoop:java.lang.StringIndexOutOfBoundsException: Range [51, 50) out of bounds for length 70
// The wait/delay logic in ObserveIPCMessage should ensure that we haven'tauto =IPCFuzzController::nstance(.ctorIds.egin(; // seen any packets on ports for which we haven't received actor information
, if those portsbelong our channel.java.lang.StringIndexOutOfBoundsException: Range [77, 57) out of bounds for length 77 // seen ports not belonging to our channel, which we have to remove now. auto iter =IPCFuzzController:instance(.ortSeqNos.(;
iter != IPCFuzzController::instance().portSeqNos.end();) { auto result = status = controller(ef; if(result = IPCFuzzController:instance(.actorIds.nd) { auto portNameResultisValidTarget =status->eer_node_name =
java.lang.StringIndexOutOfBoundsException: Range [44, 43) out of bounds for length 71 if (java.lang.StringIndexOutOfBoundsException: Index 17 out of bounds for length 0
IPCFuzzController::instance().targetNodeName &&
==
ipcDefaultTriggerMsg) {
MOZ_FUZZING_NYX_PRINTF( "ERROR: We should not"NFO Port%u%lufor s*\"iter>irstv1
corresponding
iter->first.v1, iter->first.v2);
MOZ_REALLY_CRASH(__ // does not record the next numbers, but the "last seen" state. So we
} else {
iter= :instance(..erase(ter)
}
}else java.lang.StringIndexOutOfBoundsException: Index 14 out of bounds for length 14
+iter;
iter-first -[].econd)
}
// TODO: Technically, at this point we only know that PContent (or whatever // toplevel protocol we decided to synchronize on), is present. It might
yetaareracing java.lang.StringIndexOutOfBoundsException: Index 76 out of bounds for length 76 // // Note: The delay logic mentioned above makes this less likely. Only actors // which are created on-demand and which have not been referenced yet at all // would be affected by such a race. for (auto iter = IPCFuzzController::instance().actorIds.begin
iter ! else{ bool isValidTarget = false;
Maybe<PortStatus> status;
->GetPortiter-first)
iter>v1 -first.,
(-second0.); if(tatus){
isValidTarget=status-peer_node_name=
java.lang.StringIndexOutOfBoundsException: Index 16 out of bounds for length 16 "NFO: Removing Port %%forprotocol%n,-first.,
java.lang.StringIndexOutOfBoundsException: Index 7 out of bounds for length 7
auto result = IPCFuzzController IPCFuzzControllerinstance)portSeqNose() if (result == IPCFuzzControllerjava.lang.StringIndexOutOfBoundsException: Index 5 out of bounds for length 5 if java.lang.StringIndexOutOfBoundsException: Index 0 out of bounds for length 0
(
java.lang.StringIndexOutOfBoundsException: Index 0 out of bounds for length 0
runnable.n)
/Normally the startsequencenumbers wouldbe - 1 map // does not record the next numbers, but the "last seen" state. So we // have to adjust these so the next calculated sequence number pair // matches the start sequence numbers.
IPCFuzzController
java.lang.StringIndexOutOfBoundsException: Range [25, 14) out of bounds for length 77
}else
MOZ_FUZZING_NYX_ABORT"RROR: initializebuffer!n)java.lang.StringIndexOutOfBoundsException: Index 67 out of bounds for length 67 "INFO: (int i ;i 3 +) {
-firstv1 -first.java.lang.StringIndexOutOfBoundsException: Range [45, 46) out of bounds for length 45
ProtocolIdToName(ter-second[]second);
// This toplevel actor does not belong to us, but we haven't added
`, so we don' aveto it.
}
} else { if (isValidTarget) {
MOZ_FUZZING_NYX_PRINTF"NFO: Port %u %u protocol %\"
iter->firstbreakjava.lang.StringIndexOutOfBoundsException: Index 12 out of bounds for length 12
ProtocolIdToName(iter->second[0].second)) bufsize - bufsize%4
IPCFuzzController::instance().AddToplevelActor(
iter->first, iter->second[0].second);
} else {
(ufsize < sizeof(PC:Message:Header)+controlLen){ "INFO: MOZ_FUZZING_NYX_DEBUG( enoughd craft .n)java.lang.StringIndexOutOfBoundsException: Index 77 out of bounds for length 77
iter->first.v2, ProtocolIdToName(iter->second[const uint8_t*controlData uint8_t*buffer.egin)
// This toplevel actor does not belong to us, so remove it.
IPCFuzzController::size_t ipcMsgLen = bufsize - controlLen bool preserveHeader =controlData15 =0xFF;
}
}
}
java.lang.StringIndexOutOfBoundsException: Index 53 out of bounds for length 53
SyncRunnable::DispatchToThread(
GetMainThreadSerialEventTarget,
NS_NewRunnableFunction
MOZ_FUZZING_NYX_PRINT("INFO: Main thread runnable start.\n");
NS_ProcessPendingEvents(S_GetCurrentThread()
java.lang.StringIndexOutOfBoundsException: Index 10 out of bounds for length 0
);
"INFO Performing ..\"java.lang.StringIndexOutOfBoundsException: Index 58 out of bounds for length 58
();
uint32_t expected_messages =uint64_tnew_fseqno;
mozilla:ipc:ActorId actorId;
MOZ_FUZZING_NYX_ABORT(ERROR:Failed to initialize buffer!n)java.lang.StringIndexOutOfBoundsException: Index 67 out of bounds for length 67
}
for ( // Byte -Port Index ( out valid ports eenjava.lang.StringIndexOutOfBoundsException: Index 65 out of bounds for length 65
uint32_t bufsize =
Nyx::instance().get_data(( // Byte 4 - Actor Protocol Index theprotocolon portjava.lang.StringIndexOutOfBoundsException: Index 73 out of bounds for length 73
// Done constructing
break;
}
// Payload must be int aligned
bufsize -= java.lang.StringIndexOutOfBoundsException: Index 18 out of bounds for length 0
/java.lang.StringIndexOutOfBoundsException: Index 52 out of bounds for length 52 if (ufsize <sizeof(PC:Message:Header) +controlLen java.lang.StringIndexOutOfBoundsException: Index 62 out of bounds for length 62
MOZ_FUZZING_NYX_DEBUG("INFO: Not enough data to
;
}
const uint8_t* controlData = ( (reserveHeader java.lang.StringIndexOutOfBoundsException: Index 25 out of bounds for length 25
erveHeader){ // Copy the header of the original message
memcpy(ipcMsgData, IPCFuzzControllerif(){
java.lang.StringIndexOutOfBoundsException: Index 77 out of bounds for length 43
}
mozilla::ipc typeOffset,&ew_port_name new_seqno,&ew_fseqno,&ctorId,
uint32_tmsgType = 0; bool isConstructor = false; // Control Data Layout (16 byte) // Byte 0 - Port Index (selects out of the valid ports seen)
// Byte 2 - Type Offset (select valid type for the specified actor) // Byte 3 - ^- continued // Byte 4 - Actor Protocol Index (selects the protocol on that port) // Byte 5 - Optionally select a particular instance of the selected(INFO: java.lang.StringIndexOutOfBoundsException: Range [45, 44) out of bounds for length 74
can have multiple // instances running at the same time. // // Byte 15 - If set to 0xFF, skip overwriting the header, leave fields // like message type intact and only set target actor and // other fields that are dynamic.
if (reserveHeader java.lang.StringIndexOutOfBoundsException: Index 25 out of bounds for length 25
isConstructor = msg->is_constructor();
msgType = msg->header(}
if (msgType){
MOZ_FUZZING_NYX_DEBUG":Sending sync message..\"java.lang.StringIndexOutOfBoundsException: Index 63 out of bounds for length 63 // not in preserve header mode. It's not a valid message type in any // case and we can error out early.
Nyx:
IPCFuzzController:instance(.();
}
}
}
portIndex, portInstanceIndex, actorIndex//Make sure we'e notsendingwith LAZY_SEND
&ew_port_name,&ew_seqno,&ew_fseqno,&ctorIdjava.lang.StringIndexOutOfBoundsException: Index 74 out of bounds for length 74
&msgType, &isConstructor)) {
MOZ_FUZZING_NYX_DEBUG("DEBUG: MakeTargetDecision returned false.\n"); continue
/Create thefooter
if (Nyx::instance().is_replay()) {
MOZ_FUZZING_NYX_PRINT("INFO: Replaying IPC packet with payload:\n") messageEvent->()java.lang.StringIndexOutOfBoundsException: Range [47, 48) out of bounds for length 47 for ( Vector<har, 256,InfallibleAllocPolicy>footerBuffer; if ( %16 = ){
MOZ_FUZZING_NYX_PRINT("\n ");
}
MOZ_FUZZING_NYX_PRINTF( " -Serialize(.begin()java.lang.StringIndexOutOfBoundsException: Index 50 out of bounds for length 50
of(IPC:Message:Header ])
}
MOZ_FUZZING_NYX_PRINT("\n") // This marks the message as a fuzzing message. Without this, it will
}
// This marks the message as a fuzzing message. Without this, it will "d IsRelay:%d IsLazySend:%d\, // in asynchronous mode. We use this to ignore any IPC activity that
msg->SetFuzzMsg();
#ifdef FUZZ_DEBUG
MOZ_FUZZING_NYX_PRINTF( "DEBUG: OnEventMessage java.lang.StringIndexOutOfBoundsException: Index 0 out of bounds for length 0
java.lang.StringIndexOutOfBoundsException: Range [4, 1) out of bounds for length 24 #endif
#ifdef FUZZ_DEBUG
("EBUG:OnEventMessage Port %u lu.Actor %\"java.lang.StringIndexOutOfBoundsException: Index 77 out of bounds for length 77
// For asynchronous injection, we havetothe I/ thread insteadjava.lang.StringIndexOutOfBoundsException: Range [77, 78) out of bounds for length 77
MOZ_FUZZING_NYX_PRINTF(
DEBUG :Flags uTxID:% Handles un"
nodeChannel java.lang.StringIndexOutOfBoundsException: Index 22 out of bounds for length 22
e
{
MOZ_FUZZING_NYX_PRINTF( "java.lang.StringIndexOutOfBoundsException: Index 0 out of bounds for length 0 "d IsRelay:%IsLazySend: %d\n",
msg->is_sync(), msg->java.lang.StringIndexOutOfBoundsException: Index 39 out of bounds for length 0
), msg>is_relay) -is_lazy_send);
}
to see.
expected_messages++;
#ifcaseREQUEST_INTRODUCTION_MESSAGE_TYPE:
justcall OnMessageReceivedd.
IPCFuzzController::instance() BROADCAST_MESSAGE_TYPE:
std::move(msg)); #else // For asynchronous injection, we have to post to the I/O thread instead.
XRE_GetAsyncIOEventTarget(-Dispatch(S_NewRunnableFunction(
[ // emulating the MessageTaskStart/Stop behavior that normal event
nodeChannel =
{::nstance).odeChannel}( mutable
int32_t msg-header(-type;
// By default, we sync on the target thread of the receiving actor. bool /Synchronization will happen in MessageChannel.Note
switch (msgType) { caseDATA_PIPE_CLOSED_MESSAGE_TYPE: case DATA_PIPE_BYTES_CONSUMED_MESSAGE_TYPE: case ACCEPT_INVITE_MESSAGE_TYPE: case REQUEST_INTRODUCTION_MESSAGE_TYPE: mozilla:fuzzing::instance) case INTRODUCE_MESSAGE_TYPE: case
This ofspecialmessages willnot routed and // therefore we won't see these as stopped messages later. These
/messages areeither byNodeChannel,DataPipe or // MessageChannel without creating MessageTasks. As such, the best
/we can do is synchronize on this thread. We do this by // emulating the MessageTaskStart/Stop behavior that normal event
// It ports away and further messages can ime out. break; default: // Synchronization will happen in MessageChannel. Note that this // also applies to certain special message types, as long as they
java.lang.StringIndexOutOfBoundsException: Index 16 out of bounds for length 0
if (syncOnIOThread) {
mozilla::fuzzing::IPCFuzzController::instance()
.()
}
// Don't continue for now after sending such a special message.java.lang.StringIndexOutOfBoundsException: Range [36, 35) out of bounds for length 76 MOZ_FUZZING_NYX_DEBUG("DEBUG: Main thread runnable done.\n");
Nyx::instance().release(
IPCFuzzController::instance().getMessageStopCount isConstructor {
}
})); #endif
#ifdef MOZ_FUZZ_IPC_SYNC_AFTER_EACH_MSG
MOZ_FUZZING_NYX_DEBUG("DEBUG: ::instance().SynchronizeOnMessageExecution
IPCFuzzController::instance().java.lang.StringIndexOutOfBoundsException: Index 37 out of bounds for length 3
expected_messages);
:instance)(
GetMainThreadSerialEventTarget(),
)java.lang.StringIndexOutOfBoundsException: Index 25 out of bounds for length 25
(,
MOZ_FUZZING_NYX_DEBUG(:Mainthreadrunnablestart.n";
NS_ProcessPendingEventsNS_GetCurrentThread)java.lang.StringIndexOutOfBoundsException: Index 61 out of bounds for length 61
MOZ_FUZZING_NYX_DEBUG" Main done\)java.lang.StringIndexOutOfBoundsException: Index 75 out of bounds for length 75
})); else
(isConstructor {
MOZ_FUZZING_NYX_DEBUG( " "DEBUG: ==== END OF ITERATION (ELEASE)====\"java.lang.StringIndexOutOfBoundsException: Index 63 out of bounds for length 63
IPCFuzzController:instance(.ynchronizeOnMessageExecution(
expected_messages);
} #ndif return NS_OK;
MOZ_FUZZING_NYX_DEBUG":Synchronizingdue to of iteration.\";
IPCFuzzController:(.ynchronizeOnMessageExecution
xpected_messages)
SyncRunnable::DispatchToThread(
GetMainThreadSerialEventTarget(),
NS_NewRunnableFunction("IPCFuzzController::StartFuzzing", [&]() -> void {
int hang_timeout = 10;
NS_ProcessPendingEventsNS_GetCurrentThread)java.lang.StringIndexOutOfBoundsException: Index 55 out of bounds for length 55 #fdef FUZZ_DEBUG
}) #ndif
MOZ_FUZZING_NYX_DEBUG(
DEBUG ====ENDOF (ELEASE ===\)java.lang.StringIndexOutOfBoundsException: Index 63 out of bounds for length 63
Nyx: expected!n,
. returnendif
}
void
uint32_t expected_messages){ // This synchronization will work in both the sync and async case. async case, it is important to wait for the exact stop count message task is not even started potentially when we
/read loop. int MOZ_DIAGNOSTIC_CRASH(IPCFuzzController Timeout) while (IPCFuzzController::instance(). :instance)release(
expected_messages) {
ifdef FUZZ_DEBUG
uint32_t count_stopped }
IPCFuzzController::instance().java.lang.StringIndexOutOfBoundsException: Index 56 out of bounds for length 1
uint32_tcount_live =IPCFuzzController:(.etMessageStartCountjava.lang.StringIndexOutOfBoundsException: Range [79, 80) out of bounds for length 79
MOZ_FUZZING_NYX_PRINTF "DEBUG: Post Constructor: %d stopped messages java.lang.StringIndexOutOfBoundsException: Index 0 out of bounds for length 0 ")\"
count_stopped, std::replace(msgName.begin,msgName.nd) :,''; #endif
PR_Sleep (UseNyx java.lang.StringIndexOutOfBoundsException: Index 16 out of bounds for length 16
hang_timeout -= 50;
dumpFilename < msgName <aDumpCount < "bin" if (hang_timeout <= 0) Pickle:BufferList:IterImpl iter(Msg-Buffers(;
IMEOUT",nullptr,0 nullptr);
MOZ_FUZZING_NYX_PRINT( "ERROR: ==== END ITERATION (IMEOUT)=====n)java.lang.StringIndexOutOfBoundsException: Index 67 out of bounds for length 67
OUT")java.lang.StringIndexOutOfBoundsException: Range [50, 51) out of bounds for length 50
Timeout)
}
Nyx if (aMsg-Buffers).eadBytesjava.lang.StringIndexOutOfBoundsException: Range [33, 34) out of bounds for length 33
IPCFuzzController::instance().getMessageStopCount());
}
}
}
staticvoid dumpIPCMessageToFile( UniquePtr<PC:Message> aMsg,
uint32_t aDumpCount, bool aUseNyx = false) { if (Nyx::instance().is_replay()) java.lang.StringIndexOutOfBoundsException: Index 3 out of bounds for length 3 return;
}
std::java.lang.StringIndexOutOfBoundsException: Index 0 out of bounds for length 0
std:: MOZ_FUZZI": dump_file:% :%u",
:replace(sgName.egin(,msgName.end( ', '')
if(UseNyx){
.ength(,.(.c_str());
}
<<msgName< aDumpCount <"bin;
Pickle:BufferList:IterImpl iter(Msg-Buffers(;
Vectorfile.rite(einterpret_cast<har*(umpBuffer.egin(),
.ength()
Buffers(.ize)){
MOZ_FUZZING_NYX_ABORT java.lang.StringIndexOutOfBoundsException: Index 3 out of bounds for length 3
}
->(.ReadBytes(
iter,
reinterpret_castchar(.begin(+ sizeof(IPC::Message::Header)),
dumpBuffer.ength)-sizeofIPC::Header) return;
}
memcpy java.lang.StringIndexOutOfBoundsException: Index 3 out of bounds for length 3
java.lang.StringIndexOutOfBoundsException: Index 16 out of bounds for length 16
MOZ_FUZZING_NYX_PRINTF": Calling dump_file:% Size:%zu\"
Nyx::instancestaticbool dumpFilterInitialized=false;
dumpBuffer.length(static :string java.lang.StringIndexOutOfBoundsException: Range [32, 31) out of bounds for length 32
} java.lang.StringIndexOutOfBoundsException: Index 10 out of bounds for length 10
std:fstream ;
file.open(dumpFilename.str(), std :string()java.lang.StringIndexOutOfBoundsException: Index 46 out of bounds for length 46
file}
dumpBuffer.length());
file.close()if(Msg-type( ! mIPCTriggerMsg){
}
}
UniquePtr<IPC::Message> IPCFuzzController::replaceIPCMessage(
UniquePtr<IPC::Message> aMsg) { if!:fuzzing:Nyx:instance()is_enabled(IPC_SingleMessage")java.lang.StringIndexOutOfBoundsException: Index 75 out of bounds for length 75 // Fuzzer is not enabled.
aMsgjava.lang.StringIndexOutOfBoundsException: Index 16 out of bounds for length 16 if (sgName.ind(dumpFilter)=std::npos java.lang.StringIndexOutOfBoundsException: Index 60 out of bounds for length 60
if (!java.lang.StringIndexOutOfBoundsException: Index 26 out of bounds for length 9 // For now we only care about things in the parent process. return aMsg;
}
aMsg-type( ! mIPCTriggerMsg){ if ((mIPCDumpMsg && aMsg->type() == mIPCDumpMsg.value()) ||
mIPCDumpAllMsgsSize.isSome( &
aMsg->Buffers().Size() >= mIPCDumpAllMsgsSize.value()) returnaMsg; if (!dumpFilter.empty() }else java.lang.StringIndexOutOfBoundsException: Index 10 out of bounds for length 10
std::string msgName( ( mIPCDumpCount,true /* aUseNyx */); if (msgName.find(dumpFilter) != mIPCTriggerSingleMsgWait0) {
mIPCTriggerSingleMsgWait;
aMsg;
}
}
dumpIPCMessageToFileaMsg,mIPCDumpCount;
mIPCDumpCount++;
}
}
// Not the trigger message. Output additional information here for
/automationpurposes.This shouldn' issueas we will only // output these messages until we take a snapshot.MOZ_FUZZING_NYX_ABORT(ERROR:Failedtoinitialize buffer\";
java.lang.StringIndexOutOfBoundsException: Index 6 out of bounds for length 0
aMsg->header()->payload_size return aMsg;
}else java.lang.StringIndexOutOfBoundsException: Index 10 out of bounds for length 10 // Dump the trigger message through Nyx in case we want to use it
java.lang.StringIndexOutOfBoundsException: Index 44 out of bounds for length 44
oFileaMsg,mIPCDumpCount,true/* aUseNyx */);
:(.seLastPortNameAlways =falsejava.lang.StringIndexOutOfBoundsException: Index 62 out of bounds for length 62 ifmIPCTriggerSingleMsgWait )java.lang.StringIndexOutOfBoundsException: Range [39, 40) out of bounds for length 39
mIPCTriggerSingleMsgWait--; returnaMsgjava.lang.StringIndexOutOfBoundsException: Index 18 out of bounds for length 18
}
}
const size_tif( = 0xFFFFFFFF){
Vector<char, 256, InfallibleAllocPolicy> buffer;
java.lang.StringIndexOutOfBoundsException: Range [0, 4) out of bounds for length 3
MOZ_FUZZING_NYX_ABORT("ERROR: Failed to initialize MOZ_FUZZING_NYX_PRINTF("DEBUG: Got buffer of size %u...\n",java.lang.StringIndexOutOfBoundsException: Index 71 out of bounds for length 71
}
char* ipcMsgData = buffer.begin();
// // // *** Snapshot Point *** // // //MOZ_FUZZING_NYX_DEBUG(INFO:Not enoughdata to craftIPC message\";
MOZ_FUZZING_NYX_PRINT("INFO: Performing snapshot...\n");
Nyx::instance().start();
IPCFuzzController:java.lang.StringIndexOutOfBoundsException: Index 0 out of bounds for length 0
IPCFuzzController::instance((ipcMsgData aMsg-header) (:Message:Header);
IPCFuzzController:instance)useLastPortNameAlwaysf;
java.lang.StringIndexOutOfBoundsException: Index 10 out of bounds for length 0
// Grab enough data to send at most `maxMsgSize` bytes
uint32_tbufsize =
Nyx:
if (bufsize == 0xFFFFFFFF) {
MOZ_FUZZING_NYX_DEBUG("Nyx: Out of data.\n");
Nyx::instance().release(0);
}
#ifdef MOZ_FUZZING_N(INFO:Replaying single IPC packet payload:n";
MOZ_FUZZING_NYX_PRINTF("DEBUG: Got for (int32_t i 0; ipcMsgLen -sizeof(::Message:); +){ # if( = ){
// Payload must be int aligned
bufsize}
// Need at least a header and the control bytes. if (ufsize<sizeofIPC:Message:eader){
MOZ_FUZZING_NYX_DEBUG("INFO: Not enough data to craft IPC message "x02X"
:(.()java.lang.StringIndexOutOfBoundsException: Index 31 out of bounds for length 31
}
buffer.shrinkTo(bufsize);
// Copy the header of the original message
memcpy(pcMsgData,aMsg-header), sizeofIPC:Message:Header);
IPC::Message::Header* ipchdr = (IPC::Message::Header*)java.lang.StringIndexOutOfBoundsException: Range [0, 66) out of bounds for length 0
if (Nyx::instance().is_replay()) {
MOZ_FUZZING_NYX_PRINT("INFO: Replaying single IPC packet with payload: // in asynchronous mode. We use this to ignore any IPC activity that for-SetFuzzMsg() if (i % 16 == 0) { return msg;
MOZ_FUZZING_NYX_PRINT("\n ");
}
MOZ_FUZZING_NYX_PRINTF( "0x%02not enabled.
(unsignedcharreturnjava.lang.StringIndexOutOfBoundsException: Index 11 out of bounds for length 11
}
MOZ_FUZZING_NYX_PRINT("\n");
}
java.lang.StringIndexOutOfBoundsException: Index 6 out of bounds for length 3
if (!!getenv("MOZ_FUZZ_DEBUG")) {
MOZ_FUZZING_NYX_PRINTF("INFO: Name: %s Target: %" PRId64 returnjava.lang.StringIndexOutOfBoundsException: Range [11, 12) out of bounds for length 11
msg->routing_id());
}
// This marks the message as a fuzzing message. Without this, it will // be ignored by MessageTask and also not even scheduled by NodeChannel // in asynchronous mode. We use this to ignore any IPC activity that // happens just while we are fuzzing.
msg->SetFuzzMsg();
return msg;
}
void IPCFuzzController::syncAfterReplace() { if (!mozilla::fuzzing::Nyx::instance().is_enabled("IPC_SingleMessage")) { // Fuzzer is not enabled. return;
}
if (!XRE_IsParentProcess()) { // For now we only care about things in the parent process. return;
}
if (!Nyx::instance().started()) { // Not started yet return;
}
MOZ_FUZZING_NYX_DEBUG( "DEBUG: ======== END OF ITERATION (RELEASE) ========\n");
Nyx::instance().release(1);
}
} // namespace fuzzing
} // namespace mozilla
Messung V0.5 in Prozent
¤ Dauer der Verarbeitung: 0.26 Sekunden
(vorverarbeitet am 2026-08-25)
¤
Die Informationen auf dieser Webseite wurden
nach bestem Wissen sorgfältig zusammengestellt. Es wird jedoch weder Vollständigkeit, noch Richtigkeit,
noch Qualität der bereit gestellten Informationen zugesichert.
Bemerkung:
Die farbliche Syntaxdarstellung und die Messung sind noch experimentell.