Coverage Report

Created: 2025-10-10 06:59

next uncovered line (L), next uncovered region (R), next uncovered branch (B)
/proc/self/cwd/test/fuzz.cpp
Line
Count
Source
1
#include <cassert>
2
#include <cxxopts.hpp>
3
#include <fuzzer/FuzzedDataProvider.h>
4
5
constexpr int kMaxOptions = 1024;
6
constexpr int kMaxArgSize = 1024;
7
8
enum class ParseableTypes
9
{
10
  kInt,
11
  kString,
12
  kVectorString,
13
  kFloat,
14
  kDouble,
15
16
  // Marker for fuzzer.
17
  kMaxValue,
18
};
19
20
template <typename T>
21
void
22
add_fuzzed_option(cxxopts::Options* options, FuzzedDataProvider* provider)
23
18.8k
{
24
18.8k
  assert(options);
25
18.8k
  assert(provider);
26
27
18.8k
  options->add_options()(provider->ConsumeRandomLengthString(kMaxArgSize),
28
18.8k
                         provider->ConsumeRandomLengthString(kMaxArgSize),
29
18.8k
                         cxxopts::value<T>());
30
18.8k
}
void add_fuzzed_option<int>(cxxopts::Options*, FuzzedDataProvider*)
Line
Count
Source
23
4.00k
{
24
4.00k
  assert(options);
25
4.00k
  assert(provider);
26
27
4.00k
  options->add_options()(provider->ConsumeRandomLengthString(kMaxArgSize),
28
4.00k
                         provider->ConsumeRandomLengthString(kMaxArgSize),
29
4.00k
                         cxxopts::value<T>());
30
4.00k
}
void add_fuzzed_option<std::__1::basic_string<char, std::__1::char_traits<char>, std::__1::allocator<char> > >(cxxopts::Options*, FuzzedDataProvider*)
Line
Count
Source
23
3.20k
{
24
3.20k
  assert(options);
25
3.20k
  assert(provider);
26
27
3.20k
  options->add_options()(provider->ConsumeRandomLengthString(kMaxArgSize),
28
3.20k
                         provider->ConsumeRandomLengthString(kMaxArgSize),
29
3.20k
                         cxxopts::value<T>());
30
3.20k
}
void add_fuzzed_option<std::__1::vector<std::__1::basic_string<char, std::__1::char_traits<char>, std::__1::allocator<char> >, std::__1::allocator<std::__1::basic_string<char, std::__1::char_traits<char>, std::__1::allocator<char> > > > >(cxxopts::Options*, FuzzedDataProvider*)
Line
Count
Source
23
4.76k
{
24
4.76k
  assert(options);
25
4.76k
  assert(provider);
26
27
4.76k
  options->add_options()(provider->ConsumeRandomLengthString(kMaxArgSize),
28
4.76k
                         provider->ConsumeRandomLengthString(kMaxArgSize),
29
4.76k
                         cxxopts::value<T>());
30
4.76k
}
void add_fuzzed_option<float>(cxxopts::Options*, FuzzedDataProvider*)
Line
Count
Source
23
4.34k
{
24
4.34k
  assert(options);
25
4.34k
  assert(provider);
26
27
4.34k
  options->add_options()(provider->ConsumeRandomLengthString(kMaxArgSize),
28
4.34k
                         provider->ConsumeRandomLengthString(kMaxArgSize),
29
4.34k
                         cxxopts::value<T>());
30
4.34k
}
void add_fuzzed_option<double>(cxxopts::Options*, FuzzedDataProvider*)
Line
Count
Source
23
2.49k
{
24
2.49k
  assert(options);
25
2.49k
  assert(provider);
26
27
2.49k
  options->add_options()(provider->ConsumeRandomLengthString(kMaxArgSize),
28
2.49k
                         provider->ConsumeRandomLengthString(kMaxArgSize),
29
2.49k
                         cxxopts::value<T>());
30
2.49k
}
31
32
extern "C" int
33
LLVMFuzzerTestOneInput(const uint8_t* data, size_t size)
34
4.54k
{
35
4.54k
  try
36
4.54k
  {
37
4.54k
    FuzzedDataProvider provider(data, size);
38
39
    // Randomly generate a usage string.
40
4.54k
    cxxopts::Options options(provider.ConsumeRandomLengthString(kMaxArgSize),
41
4.54k
                             provider.ConsumeRandomLengthString(kMaxArgSize));
42
43
    // Randomly generate a set of flags configurations.
44
24.0k
    for (int i = 0; i < provider.ConsumeIntegralInRange<int>(0, kMaxOptions);
45
19.5k
         i++)
46
19.8k
    {
47
19.8k
      switch (provider.ConsumeEnum<ParseableTypes>())
48
19.8k
      {
49
4.00k
      case ParseableTypes::kInt:
50
4.00k
        add_fuzzed_option<int>(&options, &provider);
51
4.00k
        break;
52
3.20k
      case ParseableTypes::kString:
53
3.20k
        add_fuzzed_option<std::string>(&options, &provider);
54
3.20k
        break;
55
4.76k
      case ParseableTypes::kVectorString:
56
4.76k
        add_fuzzed_option<std::vector<std::string>>(&options, &provider);
57
4.76k
        break;
58
4.34k
      case ParseableTypes::kFloat:
59
4.34k
        add_fuzzed_option<float>(&options, &provider);
60
4.34k
        break;
61
2.49k
      case ParseableTypes::kDouble:
62
2.49k
        add_fuzzed_option<double>(&options, &provider);
63
2.49k
        break;
64
1.07k
      default:
65
1.07k
        break;
66
19.8k
      }
67
19.8k
    }
68
    // Sometimes allow unrecognised options.
69
4.16k
    if (provider.ConsumeBool())
70
1.40k
    {
71
1.40k
      options.allow_unrecognised_options();
72
1.40k
    }
73
    // Sometimes allow trailing positional arguments.
74
4.16k
    if (provider.ConsumeBool())
75
1.30k
    {
76
1.30k
      std::string positional_option_name =
77
1.30k
        provider.ConsumeRandomLengthString(kMaxArgSize);
78
1.30k
      options.add_options()(positional_option_name,
79
1.30k
                            provider.ConsumeRandomLengthString(kMaxArgSize),
80
1.30k
                            cxxopts::value<std::vector<std::string>>());
81
1.30k
      options.parse_positional({positional_option_name});
82
1.30k
    }
83
84
    // Build command line input.
85
4.16k
    const int argc = provider.ConsumeIntegralInRange<int>(1, kMaxOptions);
86
87
4.16k
    std::vector<std::string> command_line_container;
88
4.16k
    command_line_container.reserve(argc);
89
90
4.16k
    std::vector<const char*> argv;
91
4.16k
    argv.reserve(argc);
92
93
998k
    for (int i = 0; i < argc; i++)
94
994k
    {
95
994k
      command_line_container.push_back(
96
994k
        provider.ConsumeRandomLengthString(kMaxArgSize));
97
994k
      argv.push_back(command_line_container[i].c_str());
98
994k
    }
99
100
    // Parse command line;
101
4.16k
    auto result = options.parse(argc, argv.data());
102
4.16k
  } catch (...)
103
4.54k
  {
104
1.07k
  }
105
106
4.54k
  return 0;
107
4.54k
}