Coverage Report

Created: 2025-10-27 06:14

next uncovered line (L), next uncovered region (R), next uncovered branch (B)
/proc/self/cwd/test/fuzz.cpp
Line
Count
Source
1
#include <cassert>
2
#include <cxxopts.hpp>
3
#include <fuzzer/FuzzedDataProvider.h>
4
5
constexpr int kMaxOptions = 1024;
6
constexpr int kMaxArgSize = 1024;
7
8
enum class ParseableTypes
9
{
10
  kInt,
11
  kString,
12
  kVectorString,
13
  kFloat,
14
  kDouble,
15
16
  // Marker for fuzzer.
17
  kMaxValue,
18
};
19
20
template <typename T>
21
void
22
add_fuzzed_option(cxxopts::Options* options, FuzzedDataProvider* provider)
23
19.4k
{
24
19.4k
  assert(options);
25
19.4k
  assert(provider);
26
27
19.4k
  options->add_options()(provider->ConsumeRandomLengthString(kMaxArgSize),
28
19.4k
                         provider->ConsumeRandomLengthString(kMaxArgSize),
29
19.4k
                         cxxopts::value<T>());
30
19.4k
}
void add_fuzzed_option<int>(cxxopts::Options*, FuzzedDataProvider*)
Line
Count
Source
23
3.98k
{
24
3.98k
  assert(options);
25
3.98k
  assert(provider);
26
27
3.98k
  options->add_options()(provider->ConsumeRandomLengthString(kMaxArgSize),
28
3.98k
                         provider->ConsumeRandomLengthString(kMaxArgSize),
29
3.98k
                         cxxopts::value<T>());
30
3.98k
}
void add_fuzzed_option<std::__1::basic_string<char, std::__1::char_traits<char>, std::__1::allocator<char> > >(cxxopts::Options*, FuzzedDataProvider*)
Line
Count
Source
23
3.39k
{
24
3.39k
  assert(options);
25
3.39k
  assert(provider);
26
27
3.39k
  options->add_options()(provider->ConsumeRandomLengthString(kMaxArgSize),
28
3.39k
                         provider->ConsumeRandomLengthString(kMaxArgSize),
29
3.39k
                         cxxopts::value<T>());
30
3.39k
}
void add_fuzzed_option<std::__1::vector<std::__1::basic_string<char, std::__1::char_traits<char>, std::__1::allocator<char> >, std::__1::allocator<std::__1::basic_string<char, std::__1::char_traits<char>, std::__1::allocator<char> > > > >(cxxopts::Options*, FuzzedDataProvider*)
Line
Count
Source
23
4.87k
{
24
4.87k
  assert(options);
25
4.87k
  assert(provider);
26
27
4.87k
  options->add_options()(provider->ConsumeRandomLengthString(kMaxArgSize),
28
4.87k
                         provider->ConsumeRandomLengthString(kMaxArgSize),
29
4.87k
                         cxxopts::value<T>());
30
4.87k
}
void add_fuzzed_option<float>(cxxopts::Options*, FuzzedDataProvider*)
Line
Count
Source
23
4.79k
{
24
4.79k
  assert(options);
25
4.79k
  assert(provider);
26
27
4.79k
  options->add_options()(provider->ConsumeRandomLengthString(kMaxArgSize),
28
4.79k
                         provider->ConsumeRandomLengthString(kMaxArgSize),
29
4.79k
                         cxxopts::value<T>());
30
4.79k
}
void add_fuzzed_option<double>(cxxopts::Options*, FuzzedDataProvider*)
Line
Count
Source
23
2.43k
{
24
2.43k
  assert(options);
25
2.43k
  assert(provider);
26
27
2.43k
  options->add_options()(provider->ConsumeRandomLengthString(kMaxArgSize),
28
2.43k
                         provider->ConsumeRandomLengthString(kMaxArgSize),
29
2.43k
                         cxxopts::value<T>());
30
2.43k
}
31
32
extern "C" int
33
LLVMFuzzerTestOneInput(const uint8_t* data, size_t size)
34
4.19k
{
35
4.19k
  try
36
4.19k
  {
37
4.19k
    FuzzedDataProvider provider(data, size);
38
39
    // Randomly generate a usage string.
40
4.19k
    cxxopts::Options options(provider.ConsumeRandomLengthString(kMaxArgSize),
41
4.19k
                             provider.ConsumeRandomLengthString(kMaxArgSize));
42
43
    // Randomly generate a set of flags configurations.
44
24.6k
    for (int i = 0; i < provider.ConsumeIntegralInRange<int>(0, kMaxOptions);
45
20.4k
         i++)
46
20.8k
    {
47
20.8k
      switch (provider.ConsumeEnum<ParseableTypes>())
48
20.8k
      {
49
3.98k
      case ParseableTypes::kInt:
50
3.98k
        add_fuzzed_option<int>(&options, &provider);
51
3.98k
        break;
52
3.39k
      case ParseableTypes::kString:
53
3.39k
        add_fuzzed_option<std::string>(&options, &provider);
54
3.39k
        break;
55
4.87k
      case ParseableTypes::kVectorString:
56
4.87k
        add_fuzzed_option<std::vector<std::string>>(&options, &provider);
57
4.87k
        break;
58
4.79k
      case ParseableTypes::kFloat:
59
4.79k
        add_fuzzed_option<float>(&options, &provider);
60
4.79k
        break;
61
2.43k
      case ParseableTypes::kDouble:
62
2.43k
        add_fuzzed_option<double>(&options, &provider);
63
2.43k
        break;
64
1.38k
      default:
65
1.38k
        break;
66
20.8k
      }
67
20.8k
    }
68
    // Sometimes allow unrecognised options.
69
3.80k
    if (provider.ConsumeBool())
70
1.25k
    {
71
1.25k
      options.allow_unrecognised_options();
72
1.25k
    }
73
    // Sometimes allow trailing positional arguments.
74
3.80k
    if (provider.ConsumeBool())
75
1.23k
    {
76
1.23k
      std::string positional_option_name =
77
1.23k
        provider.ConsumeRandomLengthString(kMaxArgSize);
78
1.23k
      options.add_options()(positional_option_name,
79
1.23k
                            provider.ConsumeRandomLengthString(kMaxArgSize),
80
1.23k
                            cxxopts::value<std::vector<std::string>>());
81
1.23k
      options.parse_positional({positional_option_name});
82
1.23k
    }
83
84
    // Build command line input.
85
3.80k
    const int argc = provider.ConsumeIntegralInRange<int>(1, kMaxOptions);
86
87
3.80k
    std::vector<std::string> command_line_container;
88
3.80k
    command_line_container.reserve(argc);
89
90
3.80k
    std::vector<const char*> argv;
91
3.80k
    argv.reserve(argc);
92
93
983k
    for (int i = 0; i < argc; i++)
94
979k
    {
95
979k
      command_line_container.push_back(
96
979k
        provider.ConsumeRandomLengthString(kMaxArgSize));
97
979k
      argv.push_back(command_line_container[i].c_str());
98
979k
    }
99
100
    // Parse command line;
101
3.80k
    auto result = options.parse(argc, argv.data());
102
3.80k
  } catch (...)
103
4.19k
  {
104
1.04k
  }
105
106
4.19k
  return 0;
107
4.19k
}