Files
finit/test
Joachim Wiberg c28acf21a1 test: fuzz target for the message parser
__msg_parse() turns bytes off a socket into pointers, before anything
has vouched for the peer, and it is the only place in libink that
does.  It had no test of its own beyond whatever the other tests
happened to send it, all of it well-formed.

The target checks the parser's contract, not merely that it survived.
A header field must point into the header field array, and terminate
inside it, and the parse must never claim more bytes than it was
handed.  Crash-only would pass a parser that walked into the body and
returned fields from there, since those bytes were handed over too.
The expected bounds are derived from the raw header rather than from
the parser, so the two have to agree independently.

Every input is copied into an allocation sized to it first.  Reading
past the end of a roomy buffer stays inside the allocation and the
sanitizer never sees it; against an exact one the same read is a
fault, which is where the sharpest findings come from.

Under libFuzzer it is an ordinary fuzz target and named files replay,
which is how a find gets reproduced.  With no arguments it runs a
fixed sweep -- every truncation, every single-byte corruption, every
value of the length that decides where the header ends, and seeded
garbage -- so the suite covers the same contract on every build,
without clang or a corpus in the tree.  It takes 40 ms.

CI fuzzes it properly on every pull request, keeps the crashers, and
carries the corpus between runs so it reaches deeper over time than
any single run can.  Note that clang links the fuzzer runtime against
the newest GCC tree it finds, so the libstdc++ headers have to match
that one and not the default compiler, which is worth saying since
installing the obvious package leaves you exactly where you started.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2026-08-13 10:15:19 +02:00
..
2023-02-05 18:19:23 +01:00
2025-02-11 10:17:33 +01:00

Finit Test Suite

Finit comes with a set of tests and a small framework for running them. Contributors are encouraged to write new tests when implementing features, or fixing bugs.

Each test is run in isolation, in it's own namespace. Finit will therefore be able to be launched as PID 1. Since it's also running with it's own root directory it will be able to function properly without having any super user privileges in the host environment.

Running tests

To run the test suite, first build Finit, e.g:

./configure --prefix=/usr --exec-prefix= --sysconfdir=/etc --localstatedir=/var --enable-testserv-plugin
make -j9 clean all

Then run (parallel does not work atm):

make check

make check will set up the required assets for the test environment, and then run the full set of tests. The environment is not removed afterwards so at this point individual tests can be executed without having to run the entire test suite, which is handy when developing new tests or debugging existing test. To execute an individual test, simply invoke the script containing it:

./test/name-of-the-test.sh

Another way to run a single (or more) test(s) is to define the TESTS environment variable:

TESTS="start-kill-service" make check