Coverage Report

Created: 2026-09-14 06:18

next uncovered line (L), next uncovered region (R), next uncovered branch (B)
/src/fuzz/raster_fuzzer.c
Line
Count
Source
1
// Copyright 2020 Google LLC
2
//
3
// Licensed under the Apache License, Version 2.0 (the "License");
4
// you may not use this file except in compliance with the License.
5
// You may obtain a copy of the License at
6
//
7
//      http://www.apache.org/licenses/LICENSE-2.0
8
//
9
// Unless required by applicable law or agreed to in writing, software
10
// distributed under the License is distributed on an "AS IS" BASIS,
11
// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
12
// See the License for the specific language governing permissions and
13
// limitations under the License.
14
15
#include <cairo.h>
16
#include "fuzzer_temp_file.h"
17
18
static cairo_surface_t *
19
acquire (cairo_pattern_t *pattern, void *closure,
20
       cairo_surface_t *target,
21
       const cairo_rectangle_int_t *extents)
22
0
{
23
0
    return cairo_image_surface_create_from_png(closure);
24
0
}
25
26
static void
27
release (cairo_pattern_t *pattern, void *closure, cairo_surface_t *surface)
28
0
{
29
0
    cairo_surface_destroy(surface);
30
0
}
31
32
0
int LLVMFuzzerTestOneInput(const uint8_t *data, size_t size) {
33
0
    cairo_t *cr;
34
0
    cairo_surface_t *surface;
35
0
    cairo_pattern_t *pattern;
36
0
    cairo_content_t content;
37
0
    cairo_status_t status;
38
0
    int w, h;
39
40
0
    char *tmpfile = fuzzer_get_tmpfile(data, size);
41
0
    surface = cairo_image_surface_create_from_png(tmpfile);
42
0
    status = cairo_surface_status (surface);
43
0
    if (status != CAIRO_STATUS_SUCCESS) {
44
0
        fuzzer_release_tmpfile(tmpfile);
45
0
        return 0;
46
0
    }
47
48
0
    cr = cairo_create(surface);
49
0
    content = cairo_surface_get_content(surface);
50
0
    w = cairo_image_surface_get_width(surface);
51
0
    h = cairo_image_surface_get_height(surface);
52
53
0
    char *buf = (char *) calloc(size + 1, sizeof(char));
54
0
    memcpy(buf, data, size);
55
0
    buf[size] = '\0';
56
57
0
    pattern = cairo_pattern_create_raster_source(buf, content, w, h);
58
0
    cairo_raster_source_pattern_set_acquire (pattern, acquire, release);
59
0
    cairo_set_source(cr, pattern);
60
0
    cairo_paint(cr);
61
62
0
    cairo_destroy(cr);
63
0
    cairo_pattern_destroy(pattern);
64
0
    cairo_surface_destroy(surface);
65
0
    free(buf);
66
0
    fuzzer_release_tmpfile(tmpfile);
67
0
    return 0;
68
0
}