Coverage Report

Created: 2026-09-28 06:34

next uncovered line (L), next uncovered region (R), next uncovered branch (B)
/src/capstonev5/suite/fuzz/fuzz_disasm.c
Line
Count
Source
1
// the following must precede stdio (woo, thanks msft)
2
#if defined(_MSC_VER) && _MSC_VER < 1900
3
#define _CRT_SECURE_NO_WARNINGS
4
#endif
5
6
#include <stdio.h>
7
#include <stdlib.h>
8
#include <inttypes.h>
9
10
#include <capstone/capstone.h>
11
12
#include "platform.h"
13
14
int LLVMFuzzerTestOneInput(const uint8_t *Data, size_t Size);
15
16
17
static FILE *outfile = NULL;
18
19
74.2k
int LLVMFuzzerTestOneInput(const uint8_t *Data, size_t Size) {
20
74.2k
    csh handle;
21
74.2k
    cs_insn *all_insn;
22
74.2k
    cs_detail *detail;
23
74.2k
    cs_err err;
24
74.2k
    unsigned int i;
25
26
74.2k
    if (Size < 1) {
27
        // 1 byte for arch choice
28
0
        return 0;
29
74.2k
    } else if (Size > 0x1000) {
30
        //limit input to 4kb
31
0
        Size = 0x1000;
32
0
    }
33
34
74.2k
    if (outfile == NULL) {
35
        // we compute the output
36
2
        outfile = fopen("/dev/null", "w");
37
2
        if (outfile == NULL) {
38
0
            return 0;
39
0
        }
40
2
    }
41
42
74.2k
    i = get_platform_entry((uint8_t)Data[0]);
43
44
74.2k
    err = cs_open(platforms[i].arch, platforms[i].mode, &handle);
45
74.2k
    if (err) {
46
9
        return 0;
47
9
    }
48
49
74.1k
    cs_option(handle, CS_OPT_DETAIL, CS_OPT_ON);
50
74.1k
    if (Data[0]&0x80) {
51
        //hack
52
18.0k
        cs_option(handle, CS_OPT_SYNTAX, CS_OPT_SYNTAX_ATT);
53
18.0k
    }
54
55
74.1k
    uint64_t address = 0x1000;
56
74.1k
    size_t count = cs_disasm(handle, Data+1, Size-1, address, 0, &all_insn);
57
58
74.1k
    if (count) {
59
72.3k
        size_t j;
60
72.3k
        unsigned int n;
61
62
4.66M
        for (j = 0; j < count; j++) {
63
4.59M
            cs_insn *i = &(all_insn[j]);
64
4.59M
            fprintf(outfile, "0x%"PRIx64":\t%s\t\t%s // insn-ID: %u, insn-mnem: %s\n",
65
4.59M
                   i->address, i->mnemonic, i->op_str,
66
4.59M
                   i->id, cs_insn_name(handle, i->id));
67
68
4.59M
            detail = i->detail;
69
70
4.59M
            if (detail->regs_read_count > 0) {
71
1.12M
                fprintf(outfile, "\tImplicit registers read: ");
72
2.88M
                for (n = 0; n < detail->regs_read_count; n++) {
73
1.76M
                    fprintf(outfile, "%s ", cs_reg_name(handle, detail->regs_read[n]));
74
1.76M
                }
75
1.12M
            }
76
77
4.59M
            if (detail->regs_write_count > 0) {
78
1.93M
                fprintf(outfile, "\tImplicit registers modified: ");
79
4.28M
                for (n = 0; n < detail->regs_write_count; n++) {
80
2.35M
                    fprintf(outfile, "%s ", cs_reg_name(handle, detail->regs_write[n]));
81
2.35M
                }
82
1.93M
            }
83
84
4.59M
            if (detail->groups_count > 0) {
85
2.59M
                fprintf(outfile, "\tThis instruction belongs to groups: ");
86
6.39M
                for (n = 0; n < detail->groups_count; n++) {
87
3.79M
                    fprintf(outfile, "%s ", cs_group_name(handle, detail->groups[n]));
88
3.79M
                }
89
2.59M
            }
90
4.59M
        }
91
92
72.3k
        fprintf(outfile, "0x%"PRIx64":\n", all_insn[j-1].address + all_insn[j-1].size);
93
72.3k
        cs_free(all_insn, count);
94
72.3k
    }
95
96
74.1k
    cs_close(&handle);
97
98
74.1k
    return 0;
99
74.2k
}