From 411f803beb30bf62421ed9f2b7112fe3c24979d3 Mon Sep 17 00:00:00 2001 From: "Patrice.S" Date: Tue, 23 Aug 2022 14:27:01 +0200 Subject: [PATCH] spring-webmvc: initial integration (#8321) Add fuzz target for CookieLocaleResolver --- .../CookieLocaleResolverFuzzer.java | 47 +++++++++++++++++++ projects/spring-framework/build.sh | 17 ++++++- 2 files changed, 63 insertions(+), 1 deletion(-) create mode 100644 projects/spring-framework/CookieLocaleResolverFuzzer.java diff --git a/projects/spring-framework/CookieLocaleResolverFuzzer.java b/projects/spring-framework/CookieLocaleResolverFuzzer.java new file mode 100644 index 000000000..89c1aef9d --- /dev/null +++ b/projects/spring-framework/CookieLocaleResolverFuzzer.java @@ -0,0 +1,47 @@ +import com.code_intelligence.jazzer.api.FuzzedDataProvider; +import jakarta.servlet.http.Cookie; +import org.springframework.mock.web.MockHttpServletRequest; +import org.springframework.mock.web.MockHttpServletResponse; +import org.springframework.web.servlet.i18n.CookieLocaleResolver; + +import java.util.Locale; + +import static org.springframework.web.servlet.i18n.CookieLocaleResolver.LOCALE_REQUEST_ATTRIBUTE_NAME; + +public class CookieLocaleResolverFuzzer { + public static void fuzzerTestOneInput(FuzzedDataProvider data) { + CookieLocaleResolver resolver = new CookieLocaleResolver(); + String cookieName = data.consumeString(100); + if (cookieName.isEmpty()) { + return; + } + + MockHttpServletRequest request = new MockHttpServletRequest(); + request.setScheme("http"); + request.setServerName("localhost"); + request.setServerPort(data.consumeInt()); + request.setRequestURI(data.consumeString(100)); + request.setQueryString(data.consumeString(100)); + request.removeAttribute(LOCALE_REQUEST_ATTRIBUTE_NAME); + + + MockHttpServletResponse response = new MockHttpServletResponse(); + if (data.consumeBoolean()) { + try { + response.setHeader(data.consumeString(50), data.consumeString(100)); + } catch (IllegalArgumentException ignored) {} + } + + try { + if (data.consumeBoolean()) { + Locale locale = new Locale(data.consumeString(50)); + resolver.setLocale(request, response, locale); + } + + Cookie cookie = new Cookie(data.consumeString(100), data.consumeString(500)); + request.setCookies(cookie); + resolver.resolveLocaleContext(request); + + } catch (IllegalArgumentException | IllegalStateException ignored) {} + } +} diff --git a/projects/spring-framework/build.sh b/projects/spring-framework/build.sh index f5d29fac6..1022f7d4d 100755 --- a/projects/spring-framework/build.sh +++ b/projects/spring-framework/build.sh @@ -22,6 +22,18 @@ mkdir -p $JAVA_HOME rsync -aL --exclude=*.zip "/usr/lib/jvm/java-17-openjdk-amd64/" "$JAVA_HOME" cat > patch.diff <<- EOM +diff --git a/spring-webmvc/spring-webmvc.gradle b/spring-webmvc/spring-webmvc.gradle +index c2ccacb..d2b80b4 100644 +--- a/spring-webmvc/spring-webmvc.gradle ++++ b/spring-webmvc/spring-webmvc.gradle +@@ -1,5 +1,6 @@ + description = "Spring Web MVC" + ++apply plugin: 'com.github.johnrengelman.shadow' + apply plugin: "kotlin" + + dependencies { + diff --git a/spring-core/spring-core.gradle b/spring-core/spring-core.gradle index 6546aa7..3e83242 100644 --- a/spring-core/spring-core.gradle @@ -42,12 +54,15 @@ CURRENT_VERSION=$(./gradlew properties --console=plain | sed -nr "s/^version:\ ( ./gradlew build -x test -i -x javadoc ./gradlew shadowJar --build-file spring-core/spring-core.gradle -x javadoc -x test +./gradlew shadowJar --build-file spring-webmvc/spring-webmvc.gradle -x javadoc -x test cp "spring-core/build/libs/spring-core-$CURRENT_VERSION-all.jar" "$OUT/spring-core.jar" cp "spring-web/build/libs/spring-web-$CURRENT_VERSION.jar" "$OUT/spring-web.jar" cp "spring-context/build/libs/spring-context-$CURRENT_VERSION.jar" "$OUT/spring-context.jar" cp "spring-beans/build/libs/spring-beans-$CURRENT_VERSION.jar" "$OUT/spring-beans.jar" +cp "spring-webmvc/build/libs/spring-webmvc-$CURRENT_VERSION-all.jar" "$OUT/spring-webmvc.jar" +cp "./spring-test/build/libs/spring-test-$CURRENT_VERSION.jar" "$OUT/spring-test.jar" -ALL_JARS="spring-web.jar spring-core.jar spring-context.jar spring-beans.jar" +ALL_JARS="spring-web.jar spring-core.jar spring-context.jar spring-beans.jar spring-webmvc.jar spring-test.jar" # The classpath at build-time includes the project jars in $OUT as well as the # Jazzer API.