current/doc/source developer-manual.sgml, 2.82, 2.83

Fabian Keil via ijbswa-commits <[email protected]> Thu, 08 Jun 2017 13:08:41 +0000
Newsgroups gmane.comp.web.privoxy.cvs
Message-ID <[email protected]>
Update of /cvsroot/ijbswa/current/doc/source
In directory sfp-cvs-1.v30.ch3.sourceforge.com:/tmp/cvs-serv32390/doc/source

Modified Files:
	developer-manual.sgml 
Log Message:
Add a small fuzzing section to the developer documentation


Index: developer-manual.sgml
===================================================================
RCS file: /cvsroot/ijbswa/current/doc/source/developer-manual.sgml,v
retrieving revision 2.82
retrieving revision 2.83
diff -C2 -d -r2.82 -r2.83
*** developer-manual.sgml	23 Jan 2017 12:59:45 -0000	2.82
--- developer-manual.sgml	8 Jun 2017 13:08:39 -0000	2.83
***************
*** 1976,1979 ****
--- 1976,2043 ----
      </sect2>
      <!-- XXX: Document how to write test reports and where to send them -->
+ 
+     <!--   ~~~~~       New section      ~~~~~     -->
+     <sect2 id="fuzzing"><title>Fuzzing Privoxy</title>
+      <para>
+        To make fuzzing more convenient, Privoxy can be configured
+        with --enable-fuzz which will result in the --fuzz option
+        becoming available.
+      </para>
+      <para>
+       Example (tested on ElectroBSD):
+      </para>
+      <programlisting>
+ # Compile Privoxy with instrumentation for afl
+ $ export CC=afl-clang
+ $ export CFLAGS="-fsanitize=address -ggdb"
+ $ export CPPFLAGS=-I/usr/local/include/
+ $ export LDFLAGS="-fsanitize=address -L/usr/local/lib"
+ $ export AFL_USE_ASAN=1
+ $ export AFL_HARDEN=1
+ $ ./configure --with-debug --enable-extended-host-patterns --enable-accept-filter --enable-no-gifs --enable-compression --enable-strptime-sanity-checks --enable-external-filters --enable-fuzz
+ 
+ $ ./privoxy --fuzz
+ Privoxy version 3.0.24 (http://www.privoxy.org/)
+ Usage: ./privoxy [--config-test] [--chroot] [--help] [--no-daemon] [--pidfile pidfile] [--pre-chroot-nslookup hostname] [--user user[.group]] [--version] [configfile]
+        ./privoxy --fuzz fuzz-mode ./path/to/fuzzed/input [--stfu]
+ 
+ Supported fuzz modes and the expected input:
+  action: Text to parse as action file.
+  client-request: Client request to parse. Currently incomplete
+  client-header: Client header to parse.
+  chunked-transfer-encoding: Chunk-encoded data to dechunk.
+  deflate: deflate-compressed data to decompress.
+  filter: Text to parse as filter file.
+  gif: gif to deanimate.
+  gzip: gzip-compressed data to decompress.
+  pcrs-substitute: A pcrs-substitute to compile. Not a whole pcrs job! Example: Bla $1 bla C $3 blah.
+  server-header: Server header to parse.
+  server-response: Server response to parse.
+ 
+ The following fuzz modes read data from stdin if the 'file' is '-'
+  client-request
+  client-header
+  chunked-transfer-encoding
+  deflate
+  gif
+  gzip
+  pcrs-substitute
+  server-header
+  server-response
+ 
+ Aborting
+ 
+ $ export ASAN_OPTIONS='abort_on_error=1'
+ $ mkdir input output
+ $ echo '$1 bla fasel $2' > input/pcrs
+ $ afl-fuzz -i input -o output -m none ~/git/privoxy/privoxy --fuzz pcrs-substitute - --stfu
+ 
+ $ cat >input/pcrs.txt
+ FILTER: bla fasel
+ s@(.{1})[432](\d+)@$1$2$hostname@UgisT
+ 
+ $ afl-fuzz -i input/ -o output/ -f bla.filter -m none privoxy --fuzz filter bla.filter --stfu
+ </programlisting>
+     </sect2>
    </sect1>
  


------------------------------------------------------------------------------
Check out the vibrant tech community on one of the world's most
engaging tech sites, Slashdot.org! http://sdm.link/slashdot