Coverage Report

Created: 2026-01-09 06:21

next uncovered line (L), next uncovered region (R), next uncovered branch (B)
/proc/self/cwd/test/fuzz.cpp
Line
Count
Source
1
#include <cassert>
2
#include <cxxopts.hpp>
3
#include <fuzzer/FuzzedDataProvider.h>
4
5
constexpr int kMaxOptions = 1024;
6
constexpr int kMaxArgSize = 1024;
7
8
enum class ParseableTypes
9
{
10
  kInt,
11
  kString,
12
  kVectorString,
13
  kFloat,
14
  kDouble,
15
16
  // Marker for fuzzer.
17
  kMaxValue,
18
};
19
20
template <typename T>
21
void
22
add_fuzzed_option(cxxopts::Options* options, FuzzedDataProvider* provider)
23
20.5k
{
24
20.5k
  assert(options);
25
20.5k
  assert(provider);
26
27
20.5k
  options->add_options()(provider->ConsumeRandomLengthString(kMaxArgSize),
28
20.5k
                         provider->ConsumeRandomLengthString(kMaxArgSize),
29
20.5k
                         cxxopts::value<T>());
30
20.5k
}
void add_fuzzed_option<int>(cxxopts::Options*, FuzzedDataProvider*)
Line
Count
Source
23
4.18k
{
24
4.18k
  assert(options);
25
4.18k
  assert(provider);
26
27
4.18k
  options->add_options()(provider->ConsumeRandomLengthString(kMaxArgSize),
28
4.18k
                         provider->ConsumeRandomLengthString(kMaxArgSize),
29
4.18k
                         cxxopts::value<T>());
30
4.18k
}
void add_fuzzed_option<std::__1::basic_string<char, std::__1::char_traits<char>, std::__1::allocator<char> > >(cxxopts::Options*, FuzzedDataProvider*)
Line
Count
Source
23
3.31k
{
24
3.31k
  assert(options);
25
3.31k
  assert(provider);
26
27
3.31k
  options->add_options()(provider->ConsumeRandomLengthString(kMaxArgSize),
28
3.31k
                         provider->ConsumeRandomLengthString(kMaxArgSize),
29
3.31k
                         cxxopts::value<T>());
30
3.31k
}
void add_fuzzed_option<std::__1::vector<std::__1::basic_string<char, std::__1::char_traits<char>, std::__1::allocator<char> >, std::__1::allocator<std::__1::basic_string<char, std::__1::char_traits<char>, std::__1::allocator<char> > > > >(cxxopts::Options*, FuzzedDataProvider*)
Line
Count
Source
23
5.03k
{
24
5.03k
  assert(options);
25
5.03k
  assert(provider);
26
27
5.03k
  options->add_options()(provider->ConsumeRandomLengthString(kMaxArgSize),
28
5.03k
                         provider->ConsumeRandomLengthString(kMaxArgSize),
29
5.03k
                         cxxopts::value<T>());
30
5.03k
}
void add_fuzzed_option<float>(cxxopts::Options*, FuzzedDataProvider*)
Line
Count
Source
23
5.40k
{
24
5.40k
  assert(options);
25
5.40k
  assert(provider);
26
27
5.40k
  options->add_options()(provider->ConsumeRandomLengthString(kMaxArgSize),
28
5.40k
                         provider->ConsumeRandomLengthString(kMaxArgSize),
29
5.40k
                         cxxopts::value<T>());
30
5.40k
}
void add_fuzzed_option<double>(cxxopts::Options*, FuzzedDataProvider*)
Line
Count
Source
23
2.60k
{
24
2.60k
  assert(options);
25
2.60k
  assert(provider);
26
27
2.60k
  options->add_options()(provider->ConsumeRandomLengthString(kMaxArgSize),
28
2.60k
                         provider->ConsumeRandomLengthString(kMaxArgSize),
29
2.60k
                         cxxopts::value<T>());
30
2.60k
}
31
32
extern "C" int
33
LLVMFuzzerTestOneInput(const uint8_t* data, size_t size)
34
4.30k
{
35
4.30k
  try
36
4.30k
  {
37
4.30k
    FuzzedDataProvider provider(data, size);
38
39
    // Randomly generate a usage string.
40
4.30k
    cxxopts::Options options(provider.ConsumeRandomLengthString(kMaxArgSize),
41
4.30k
                             provider.ConsumeRandomLengthString(kMaxArgSize));
42
43
    // Randomly generate a set of flags configurations.
44
26.0k
    for (int i = 0; i < provider.ConsumeIntegralInRange<int>(0, kMaxOptions);
45
21.7k
         i++)
46
22.1k
    {
47
22.1k
      switch (provider.ConsumeEnum<ParseableTypes>())
48
22.1k
      {
49
4.18k
      case ParseableTypes::kInt:
50
4.18k
        add_fuzzed_option<int>(&options, &provider);
51
4.18k
        break;
52
3.31k
      case ParseableTypes::kString:
53
3.31k
        add_fuzzed_option<std::string>(&options, &provider);
54
3.31k
        break;
55
5.03k
      case ParseableTypes::kVectorString:
56
5.03k
        add_fuzzed_option<std::vector<std::string>>(&options, &provider);
57
5.03k
        break;
58
5.40k
      case ParseableTypes::kFloat:
59
5.40k
        add_fuzzed_option<float>(&options, &provider);
60
5.40k
        break;
61
2.60k
      case ParseableTypes::kDouble:
62
2.60k
        add_fuzzed_option<double>(&options, &provider);
63
2.60k
        break;
64
1.56k
      default:
65
1.56k
        break;
66
22.1k
      }
67
22.1k
    }
68
    // Sometimes allow unrecognised options.
69
3.94k
    if (provider.ConsumeBool())
70
1.27k
    {
71
1.27k
      options.allow_unrecognised_options();
72
1.27k
    }
73
    // Sometimes allow trailing positional arguments.
74
3.94k
    if (provider.ConsumeBool())
75
1.24k
    {
76
1.24k
      std::string positional_option_name =
77
1.24k
        provider.ConsumeRandomLengthString(kMaxArgSize);
78
1.24k
      options.add_options()(positional_option_name,
79
1.24k
                            provider.ConsumeRandomLengthString(kMaxArgSize),
80
1.24k
                            cxxopts::value<std::vector<std::string>>());
81
1.24k
      options.parse_positional({positional_option_name});
82
1.24k
    }
83
84
    // Build command line input.
85
3.94k
    const int argc = provider.ConsumeIntegralInRange<int>(1, kMaxOptions);
86
87
3.94k
    std::vector<std::string> command_line_container;
88
3.94k
    command_line_container.reserve(argc);
89
90
3.94k
    std::vector<const char*> argv;
91
3.94k
    argv.reserve(argc);
92
93
947k
    for (int i = 0; i < argc; i++)
94
944k
    {
95
944k
      command_line_container.push_back(
96
944k
        provider.ConsumeRandomLengthString(kMaxArgSize));
97
944k
      argv.push_back(command_line_container[i].c_str());
98
944k
    }
99
100
    // Parse command line;
101
3.94k
    auto result = options.parse(argc, argv.data());
102
3.94k
  } catch (...)
103
4.30k
  {
104
1.06k
  }
105
106
4.30k
  return 0;
107
4.30k
}