midi-harbor/fuzz/fuzz_targets/rtpmidi_packet.rs
James Coleman be2e93bcda feat(network): follow a machine's session and forget removed ones
- A network port kept a machine it had connected to after the connection was removed, listed it as on the network whenever its host advertised any session, and could not connect to it again: Connect resolved identifiers only among advertised sessions and failed with "no peer named". A machine remembered only for a connection is now dropped once no network port uses it, an untrusted machine is marked present only by a session at its exact address, and Connect resolves remembered machines by identifier or name.
- A network port invited the one address it had connected to until it answered, so a session that came back on another port was never reached. The session name advertised at a machine's address is now stored as advertised_as in the configuration, and while the link is down the port connects where that session is advertised and stores the new address. A machine carrying MIDI is never moved.
- Each daemon now holds an Ed25519 key in identity.key beside the configuration and publishes mhkey and mhport in every session's TXT record. Two packets on the control port, a challenge and a signed proof, let a network port prove which port of which daemon it is. A machine stored with a proved key and port_id is followed under any name and to another host, with its trust, and a port deleted and made again is not followed. The challenge is sent only to a session that advertises a key, so no other RTP-MIDI implementation receives it.
- A machine with no key is followed by name to a new port on its host, and to another host only when it is not trusted, since an advertisement proves nothing and trust is held by host.
- An invitation over an IPv6 link-local address was never answered, because the sender's address was kept without its scope. Apple's Network MIDI invites that way and reported that the port did not respond. The address is now kept whole for the control and data ports.
- Adds ed25519-dalek and hex. The packet fuzz target reads the new packets.
2026-10-02 11:56:20 -05:00

59 lines
2.5 KiB
Rust

//! Feeds hostile datagrams to the three RTP-MIDI parsers a peer on the network can reach.
//!
//! Both ports read whatever arrives, so the control parser, the identity parser and the data
//! parser each get every input. None may allocate more than a small multiple of what it was sent,
//! and whatever one accepts has to come back unchanged after being encoded and parsed again: a
//! packet the daemon would read one way and send another is a peer misreading us.
#![no_main]
use libfuzzer_sys::fuzz_target;
use midi_harbor_rtpmidi::{ControlPacket, IdentityPacket, RtpMidiPacket};
/// Heap bytes a parse may hold per byte of input, which covers a vector doubling past a message
/// list at one message per input byte.
const BYTES_PER_INPUT_BYTE: u64 = 64;
/// Heap bytes a parse may hold whatever its input, for fixed-size bookkeeping.
const FIXED_BYTES: u64 = 4096;
fuzz_target!(
init: {
// The allocation checks below prove nothing unless the counter is really installed.
let probe = allocation_counter::measure(|| drop(std::hint::black_box(vec![0_u8; 64])));
assert!(probe.count_total > 0, "the allocation counter is not installed");
},
|data: &[u8]| {
let bound = bound(data);
let mut control = None;
let allocations = allocation_counter::measure(|| control = ControlPacket::parse(data).ok());
assert!(allocations.bytes_max <= bound, "control parse held {allocations:?}");
if let Some(packet) = control {
assert_eq!(ControlPacket::parse(&packet.encode()), Ok(packet));
}
let mut identity = None;
let allocations = allocation_counter::measure(|| identity = IdentityPacket::parse(data).ok());
assert!(allocations.bytes_max <= bound, "identity parse held {allocations:?}");
if let Some(packet) = identity {
assert_eq!(IdentityPacket::parse(&packet.encode()), Ok(packet));
}
let mut rtp = None;
let allocations = allocation_counter::measure(|| rtp = RtpMidiPacket::parse(data).ok());
assert!(allocations.bytes_max <= bound, "rtp parse held {allocations:?}");
if let Some(packet) = rtp {
assert!(packet.messages.len() <= data.len(), "more messages than bytes");
assert_eq!(RtpMidiPacket::parse(&packet.encode()), Ok(packet));
}
}
);
/// The most heap a parse of `data` may hold at once.
fn bound(data: &[u8]) -> u64 {
u64::try_from(data.len())
.unwrap_or(u64::MAX)
.saturating_mul(BYTES_PER_INPUT_BYTE)
.saturating_add(FIXED_BYTES)
}