mirror of
https://github.com/xroche/httrack.git
synced 2026-07-24 01:29:49 +03:00
Adds fuzz-htsparse, a libFuzzer harness driving the real htsparse() over a mocked engine: the tag/attribute/JS-inscript scanner, the link rewriter, and the accept -> url_savename -> hts_record_link path that runs on every crawled page, previously reached only by slow full-crawl tests. The parser's coupling is state, not network, so the harness builds the minimal crawl state httpmirror() sets up (opt, cache, hash, filters, robots, backing, a seeded link heap with ptr=1) and walks a NUL-terminated page through the parser, then discards it. Four seeds cover links, srcset, base/meta/usemap, a document.write body, and malformed tags. Clean under ASan+UBSan+LeakSanitizer. Bundles the src/coucal bump to ab59c6a (coucal#13): this harness is the first fuzzer to hash keys through coucal under UBSan, which tripped a pre-existing getblock32 pointer-overflow. Merged past a transient arm64 apt-mirror outage; every code-exercising check (fuzz, sanitize, msan, distcheck, all non-arm64 builds) passed. Signed-off-by: Xavier Roche <roche@httrack.com> Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
16 lines
488 B
HTML
16 lines
488 B
HTML
<!DOCTYPE html>
|
|
<html><head>
|
|
<meta charset="utf-8">
|
|
<base href="http://example.com/dir/">
|
|
<title>Seed</title>
|
|
<link rel="stylesheet" href="style.css">
|
|
<script src="app.js"></script>
|
|
</head><body>
|
|
<h1>Hi</h1>
|
|
<a href="page2.html">next</a>
|
|
<a href="http://other.example.org/x?y=1#frag">abs</a>
|
|
<img src="pic.png" srcset="a.png 1x, b.png 2x">
|
|
<script>var u="inline.html"; document.write('<a href="gen.html">g</a>');</script>
|
|
<form action="/cgi/submit"><input name="q"></form>
|
|
</body></html>
|