Coverage Report

Created: 2026-07-16 06:55

next uncovered line (L), next uncovered region (R), next uncovered branch (B)
/src/capstonenext/suite/fuzz/fuzz_disasm.c
Line
Count
Source
1
// the following must precede stdio (woo, thanks msft)
2
#if defined(_MSC_VER) && _MSC_VER < 1900
3
#define _CRT_SECURE_NO_WARNINGS
4
#endif
5
6
#include <stdio.h>
7
#include <stdlib.h>
8
#include <inttypes.h>
9
10
#include <capstone/capstone.h>
11
12
#include "platform.h"
13
14
int LLVMFuzzerTestOneInput(const uint8_t *Data, size_t Size);
15
16
static FILE *outfile = NULL;
17
18
int LLVMFuzzerTestOneInput(const uint8_t *Data, size_t Size)
19
91.0k
{
20
91.0k
  csh handle;
21
91.0k
  cs_insn *all_insn;
22
91.0k
  cs_detail *detail;
23
91.0k
  cs_err err;
24
91.0k
  unsigned int i;
25
26
91.0k
  if (Size < 1) {
27
    // 1 byte for arch choice
28
0
    return 0;
29
91.0k
  } else if (Size > 0x1000) {
30
    //limit input to 4kb
31
0
    Size = 0x1000;
32
0
  }
33
34
91.0k
  if (outfile == NULL) {
35
    // we compute the output
36
2
    outfile = fopen("/dev/null", "w");
37
2
    if (outfile == NULL) {
38
0
      return 0;
39
0
    }
40
2
  }
41
42
91.0k
  i = get_platform_entry((uint8_t)Data[0]);
43
44
91.0k
  err = cs_open(platforms[i].arch, platforms[i].mode, &handle);
45
91.0k
  if (err) {
46
9
    return 0;
47
9
  }
48
49
91.0k
  cs_option(handle, CS_OPT_DETAIL, CS_OPT_ON);
50
91.0k
  if (Data[0] & 0x80) {
51
    //hack
52
20.6k
    cs_option(handle, CS_OPT_SYNTAX, CS_OPT_SYNTAX_ATT);
53
20.6k
  }
54
55
91.0k
  uint64_t address = 0x1000;
56
91.0k
  size_t count =
57
91.0k
    cs_disasm(handle, Data + 1, Size - 1, address, 0, &all_insn);
58
59
91.0k
  if (count) {
60
89.1k
    size_t j;
61
89.1k
    unsigned int n;
62
63
6.41M
    for (j = 0; j < count; j++) {
64
6.32M
      cs_insn *insn = &(all_insn[j]);
65
6.32M
      fprintf(outfile,
66
6.32M
        "0x%" PRIx64
67
6.32M
        ":\t%s\t\t%s // insn-ID: %u, insn-mnem: %s\n",
68
6.32M
        insn->address, insn->mnemonic, insn->op_str,
69
6.32M
        insn->id, cs_insn_name(handle, insn->id));
70
71
6.32M
      detail = insn->detail;
72
73
6.32M
      if (detail->regs_read_count > 0) {
74
1.50M
        fprintf(outfile, "\tImplicit registers read: ");
75
3.88M
        for (n = 0; n < detail->regs_read_count; n++) {
76
2.38M
          fprintf(outfile, "%s ",
77
2.38M
            cs_reg_name(
78
2.38M
              handle,
79
2.38M
              detail->regs_read[n]));
80
2.38M
        }
81
1.50M
      }
82
83
6.32M
      if (detail->regs_write_count > 0) {
84
2.71M
        fprintf(outfile,
85
2.71M
          "\tImplicit registers modified: ");
86
6.00M
        for (n = 0; n < detail->regs_write_count; n++) {
87
3.28M
          fprintf(outfile, "%s ",
88
3.28M
            cs_reg_name(
89
3.28M
              handle,
90
3.28M
              detail->regs_write[n]));
91
3.28M
        }
92
2.71M
      }
93
94
6.32M
      if (detail->groups_count > 0) {
95
3.72M
        fprintf(outfile,
96
3.72M
          "\tThis instruction belongs to groups: ");
97
9.05M
        for (n = 0; n < detail->groups_count; n++) {
98
5.33M
          fprintf(outfile, "%s ",
99
5.33M
            cs_group_name(
100
5.33M
              handle,
101
5.33M
              detail->groups[n]));
102
5.33M
        }
103
3.72M
      }
104
6.32M
    }
105
106
89.1k
    fprintf(outfile, "0x%" PRIx64 ":\n",
107
89.1k
      all_insn[j - 1].address + all_insn[j - 1].size);
108
89.1k
    cs_free(all_insn, count);
109
89.1k
  }
110
111
91.0k
  cs_close(&handle);
112
113
91.0k
  return 0;
114
91.0k
}