Files
c-toxcore/auto_tests/network_test.c
T
NoxToxCipher 02daf25560 fix(network): check buffer length before reading family in unpack_ip_port
In unpack_ip_port, data[0] was accessed without verifying that length > 0, causing a potential 1-byte out-of-bounds read on 0-length input. Additionally, checked ip_port and data before dereferencing.

In unpack_nodes, add an entry check verifying nodes is non-null when max_num_nodes > 0.

Added boundary unit tests in auto_tests/network_test.c covering zero-length inputs, truncated IPv4/IPv6 buffers, and invalid address families.
2026-08-25 18:20:00 +10:00

201 lines
6.8 KiB
C

#include <string.h>
#include "../toxcore/network.h"
#include "../toxcore/os_memory.h"
#include "check_compat.h"
#ifndef USE_IPV6
#define USE_IPV6 1
#endif
static void test_addr_resolv_localhost(void)
{
#ifdef __CYGWIN__
/* force initialization of network stack
* normally this should happen automatically
* cygwin doesn't do it for every network related function though
* e.g. not for getaddrinfo... */
net_socket(0, 0, 0);
errno = 0;
#endif
const Network *ns = os_network();
ck_assert(ns != nullptr);
const Memory *mem = os_memory();
ck_assert(mem != nullptr);
const char localhost[] = "localhost";
IP ip;
ip_init(&ip, 0); // ipv6enabled = 0
bool res = addr_resolve_or_parse_ip(ns, mem, localhost, &ip, nullptr, true);
int error = net_error();
Net_Strerror error_str;
ck_assert_msg(res, "Resolver failed: %d, %s", error, net_strerror(error, &error_str));
Ip_Ntoa ip_str;
ck_assert_msg(net_family_is_ipv4(ip.family), "Expected family TOX_AF_INET, got %u.", ip.family.value);
const uint32_t loopback = get_ip4_loopback().uint32;
ck_assert_msg(ip.ip.v4.uint32 == loopback, "Expected 127.0.0.1, got %s.",
net_ip_ntoa(&ip, &ip_str));
ip_init(&ip, 1); // ipv6enabled = 1
res = addr_resolve_or_parse_ip(ns, mem, localhost, &ip, nullptr, true);
#if USE_IPV6
int localhost_split = 0;
if (!net_family_is_ipv6(ip.family)) {
res = addr_resolve_or_parse_ip(ns, mem, "ip6-localhost", &ip, nullptr, true);
localhost_split = 1;
}
error = net_error();
ck_assert_msg(res, "Resolver failed: %d, %s", error, net_strerror(error, &error_str));
ck_assert_msg(net_family_is_ipv6(ip.family), "Expected family TOX_AF_INET6 (%d), got %u.", TOX_AF_INET6,
ip.family.value);
IP6 ip6_loopback = get_ip6_loopback();
ck_assert_msg(!memcmp(&ip.ip.v6, &ip6_loopback, sizeof(IP6)), "Expected ::1, got %s.",
net_ip_ntoa(&ip, &ip_str));
if (localhost_split) {
printf("Localhost seems to be split in two.\n");
return;
}
#endif
ip_init(&ip, 1); // ipv6enabled = 1
ip.family = net_family_unspec();
IP extra;
ip_reset(&extra);
res = addr_resolve_or_parse_ip(ns, mem, localhost, &ip, &extra, true);
error = net_error();
ck_assert_msg(res, "Resolver failed: %d, %s", error, net_strerror(error, &error_str));
#if USE_IPV6
ck_assert_msg(net_family_is_ipv6(ip.family), "Expected family TOX_AF_INET6 (%d), got %u.", TOX_AF_INET6,
ip.family.value);
ck_assert_msg(!memcmp(&ip.ip.v6, &ip6_loopback, sizeof(IP6)), "Expected ::1, got %s.",
net_ip_ntoa(&ip, &ip_str));
ck_assert_msg(net_family_is_ipv4(extra.family), "Expected family TOX_AF_INET (%d), got %u.", TOX_AF_INET,
extra.family.value);
ck_assert_msg(extra.ip.v4.uint32 == loopback, "Expected 127.0.0.1, got %s.",
net_ip_ntoa(&ip, &ip_str));
#elif 0
// TODO(iphydf): Fix this to work on IPv6-supporting systems.
ck_assert_msg(net_family_is_ipv4(ip.family), "Expected family TOX_AF_INET (%d), got %u.", TOX_AF_INET, ip.family.value);
ck_assert_msg(ip.ip.v4.uint32 == loopback, "Expected 127.0.0.1, got %s.",
net_ip_ntoa(&ip, &ip_str));
#endif
}
static void test_ip_equal(void)
{
int res;
IP ip1, ip2;
ip_reset(&ip1);
ip_reset(&ip2);
res = ip_equal(nullptr, nullptr);
ck_assert_msg(res == 0, "ip_equal(NULL, NULL): expected result 0, got %d.", res);
res = ip_equal(&ip1, nullptr);
ck_assert_msg(res == 0, "ip_equal(PTR, NULL): expected result 0, got %d.", res);
res = ip_equal(nullptr, &ip1);
ck_assert_msg(res == 0, "ip_equal(NULL, PTR): expected result 0, got %d.", res);
ip1.family = net_family_ipv4();
ip1.ip.v4.uint32 = net_htonl(0x7F000001);
res = ip_equal(&ip1, &ip2);
ck_assert_msg(res == 0, "ip_equal( {TOX_AF_INET, 127.0.0.1}, {TOX_AF_UNSPEC, 0} ): "
"expected result 0, got %d.", res);
ip2.family = net_family_ipv4();
ip2.ip.v4.uint32 = net_htonl(0x7F000001);
res = ip_equal(&ip1, &ip2);
ck_assert_msg(res != 0, "ip_equal( {TOX_AF_INET, 127.0.0.1}, {TOX_AF_INET, 127.0.0.1} ): "
"expected result != 0, got 0.");
ip2.ip.v4.uint32 = net_htonl(0x7F000002);
res = ip_equal(&ip1, &ip2);
ck_assert_msg(res == 0, "ip_equal( {TOX_AF_INET, 127.0.0.1}, {TOX_AF_INET, 127.0.0.2} ): "
"expected result 0, got %d.", res);
ip2.family = net_family_ipv6();
ip2.ip.v6.uint32[0] = 0;
ip2.ip.v6.uint32[1] = 0;
ip2.ip.v6.uint32[2] = net_htonl(0xFFFF);
ip2.ip.v6.uint32[3] = net_htonl(0x7F000001);
ck_assert_msg(ipv6_ipv4_in_v6(&ip2.ip.v6) != 0,
"ipv6_ipv4_in_v6(::ffff:127.0.0.1): expected != 0, got 0.");
res = ip_equal(&ip1, &ip2);
ck_assert_msg(res != 0, "ip_equal( {TOX_AF_INET, 127.0.0.1}, {TOX_AF_INET6, ::ffff:127.0.0.1} ): "
"expected result != 0, got 0.");
IP6 ip6_loopback = get_ip6_loopback();
memcpy(&ip2.ip.v6, &ip6_loopback, sizeof(IP6));
res = ip_equal(&ip1, &ip2);
ck_assert_msg(res == 0, "ip_equal( {TOX_AF_INET, 127.0.0.1}, {TOX_AF_INET6, ::1} ): expected result 0, got %d.", res);
memcpy(&ip1, &ip2, sizeof(IP));
res = ip_equal(&ip1, &ip2);
ck_assert_msg(res != 0, "ip_equal( {TOX_AF_INET6, ::1}, {TOX_AF_INET6, ::1} ): expected result != 0, got 0.");
ip2.ip.v6.uint8[15]++;
res = ip_equal(&ip1, &ip2);
ck_assert_msg(res == 0, "ip_equal( {TOX_AF_INET6, ::1}, {TOX_AF_INET6, ::2} ): expected result 0, got %d.", res);
}
static void test_unpack_ip_port_bounds(void)
{
IP_Port ipp;
ipport_reset(&ipp);
const uint8_t dummy_v4[7] = {TOX_AF_INET, 192, 168, 1, 1, 0x12, 0x34};
ck_assert_int_eq(unpack_ip_port(&ipp, dummy_v4, 0, false), -1);
for (uint16_t len = 1; len < (uint16_t)sizeof(dummy_v4); ++len) {
ck_assert_int_eq(unpack_ip_port(&ipp, dummy_v4, len, false), -1);
}
ck_assert_int_eq(unpack_ip_port(&ipp, dummy_v4, sizeof(dummy_v4), false), (int)sizeof(dummy_v4));
ck_assert(net_family_is_ipv4(ipp.ip.family));
uint8_t dummy_v6[19];
memset(dummy_v6, 0, sizeof(dummy_v6));
dummy_v6[0] = TOX_AF_INET6;
for (uint16_t len = 1; len < (uint16_t)sizeof(dummy_v6); ++len) {
ck_assert_int_eq(unpack_ip_port(&ipp, dummy_v6, len, false), -1);
}
ck_assert_int_eq(unpack_ip_port(&ipp, dummy_v6, sizeof(dummy_v6), false), (int)sizeof(dummy_v6));
ck_assert(net_family_is_ipv6(ipp.ip.family));
const uint8_t invalid_family[7] = {0xFF, 1, 2, 3, 4, 5, 6};
ck_assert_int_eq(unpack_ip_port(&ipp, invalid_family, sizeof(invalid_family), false), -1);
}
int main(void)
{
setvbuf(stdout, nullptr, _IONBF, 0);
test_addr_resolv_localhost();
test_ip_equal();
test_unpack_ip_port_bounds();
return 0;
}