Coverage Report

Created: 2025-11-15 06:27

next uncovered line (L), next uncovered region (R), next uncovered branch (B)
/src/flac/oss-fuzz/reencoder.cc
Line
Count
Source
1
/* Copyright 2019 Guido Vranken
2
 *
3
 * Permission is hereby granted, free of charge, to any person obtaining
4
 * a copy of this software and associated documentation files (the
5
 * "Software"), to deal in the Software without restriction, including
6
 * without limitation the rights to use, copy, modify, merge, publish,
7
 * distribute, sublicense, and/or sell copies of the Software, and to
8
 * permit persons to whom the Software is furnished to do so, subject
9
 * to the following conditions:
10
 *
11
 * The above copyright notice and this permission notice shall be
12
 * included in all copies or substantial portions of the Software.
13
 *
14
 * THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND,
15
 * EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF
16
 * MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND
17
 * NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS
18
 * BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN
19
 * ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN
20
 * CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE
21
 * SOFTWARE.
22
 */
23
24
#include <cstddef>
25
#include <cstdint>
26
#include <limits>
27
28
#include <fuzzing/datasource/datasource.hpp>
29
#include <fuzzing/memory.hpp>
30
31
#include "FLAC++/encoder.h"
32
#include "FLAC++/decoder.h"
33
#include "FLAC++/metadata.h"
34
#include "common.h"
35
36
38.7k
#define MAX_NUM_METADATA_BLOCKS 2048
37
38
namespace FLAC {
39
     namespace Encoder {
40
         class FuzzerStream : public Stream {
41
            private:
42
                // fuzzing::datasource::Datasource& ds;
43
            public:
44
                FuzzerStream(fuzzing::datasource::Datasource&) :
45
6.67k
                    Stream() { }
46
47
1.39M
                ::FLAC__StreamEncoderWriteStatus write_callback(const FLAC__byte buffer[], size_t bytes, uint32_t /* samples */, uint32_t /* current_frame */) override {
48
1.39M
                    fuzzing::memory::memory_test(buffer, bytes);
49
1.39M
                    return FLAC__STREAM_ENCODER_WRITE_STATUS_OK;
50
1.39M
                }
51
         };
52
    }
53
    namespace Decoder {
54
        class FuzzerDecoder : public Stream {
55
        private:
56
            fuzzing::datasource::Datasource& ds;
57
            FLAC::Encoder::FuzzerStream& encoder;
58
        public:
59
            FuzzerDecoder(fuzzing::datasource::Datasource& dsrc, FLAC::Encoder::FuzzerStream& encoder_arg) :
60
6.67k
                Stream(), ds(dsrc), encoder(encoder_arg) { }
61
62
            ::FLAC__StreamMetadata * metadata_blocks[MAX_NUM_METADATA_BLOCKS] = {0};
63
            int num_metadata_blocks = 0;
64
65
38.7k
            void metadata_callback(const ::FLAC__StreamMetadata *metadata) override {
66
38.7k
    if(num_metadata_blocks < MAX_NUM_METADATA_BLOCKS)
67
38.5k
                  if((metadata_blocks[num_metadata_blocks] = FLAC__metadata_object_clone(metadata)) != NULL)
68
38.5k
        num_metadata_blocks++;
69
38.7k
            }
70
71
75.4k
            ::FLAC__StreamDecoderReadStatus read_callback(FLAC__byte buffer[], size_t *bytes)  override {
72
75.4k
                try {
73
75.4k
                    const size_t maxCopySize = *bytes;
74
75
75.4k
                    if ( maxCopySize > 0 ) {
76
                        /* memset just to test if this overwrites anything, and triggers ASAN */
77
75.4k
                        memset(buffer, 0, maxCopySize);
78
75.4k
                    }
79
80
75.4k
                    const auto data = ds.GetData(0);
81
75.4k
                    const auto dataSize = data.size();
82
75.4k
                    const auto copySize = std::min(maxCopySize, dataSize);
83
84
75.4k
                    if ( copySize > 0 ) {
85
11.7k
                        memcpy(buffer, data.data(), copySize);
86
11.7k
                    }
87
88
75.4k
                    *bytes = copySize;
89
90
75.4k
                    return FLAC__STREAM_DECODER_READ_STATUS_CONTINUE;
91
75.4k
                } catch ( ... ) {
92
5.89k
                        return FLAC__STREAM_DECODER_READ_STATUS_ABORT;
93
5.89k
                }
94
75.4k
            }
95
96
35.4k
            ::FLAC__StreamDecoderWriteStatus write_callback(const ::FLAC__Frame *frame, const FLAC__int32 * const buffer[])  override {
97
35.4k
                {
98
35.4k
                    fuzzing::memory::memory_test(&(frame->header), sizeof(frame->header));
99
35.4k
                    fuzzing::memory::memory_test(&(frame->footer), sizeof(frame->footer));
100
35.4k
                }
101
102
35.4k
                {
103
35.4k
                    const auto numChannels = get_channels();
104
35.4k
                    const size_t bytesPerChannel = frame->header.blocksize * sizeof(FLAC__int32);
105
112k
                    for (size_t i = 0; i < numChannels; i++) {
106
77.2k
                        fuzzing::memory::memory_test(buffer[i], bytesPerChannel);
107
77.2k
                    }
108
35.4k
                }
109
110
    /* Data is checked, now pass it towards encoder */
111
35.4k
                if(encoder.get_state() == FLAC__STREAM_ENCODER_OK) {
112
35.4k
                    if(encoder.get_channels() != get_channels())
113
41
                         return FLAC__STREAM_DECODER_WRITE_STATUS_ABORT;
114
35.3k
                    if(encoder.get_bits_per_sample() != get_bits_per_sample())
115
16
                         return FLAC__STREAM_DECODER_WRITE_STATUS_ABORT;
116
35.3k
                    encoder.process(buffer, frame->header.blocksize);
117
35.3k
                    return FLAC__STREAM_DECODER_WRITE_STATUS_CONTINUE;
118
35.3k
                }
119
0
                else
120
0
                    return FLAC__STREAM_DECODER_WRITE_STATUS_ABORT;
121
35.4k
            }
122
59.0k
            void error_callback(::FLAC__StreamDecoderErrorStatus status)  override {
123
59.0k
                fuzzing::memory::memory_test(status);
124
59.0k
            }
125
        };
126
    }
127
}
128
129
6.67k
extern "C" int LLVMFuzzerTestOneInput(const uint8_t *data, size_t size) {
130
6.67k
    fuzzing::datasource::Datasource ds(data, size);
131
6.67k
    FLAC::Encoder::FuzzerStream encoder(ds);
132
6.67k
    FLAC::Decoder::FuzzerDecoder decoder(ds, encoder);
133
134
6.67k
    try {
135
6.67k
            const int channels = ds.Get<uint8_t>();
136
6.67k
            const int bps = ds.Get<uint8_t>();
137
6.67k
            encoder.set_channels(channels);
138
6.67k
            encoder.set_bits_per_sample(bps);
139
140
6.67k
        {
141
6.67k
            const bool res = encoder.set_streamable_subset(ds.Get<bool>());
142
6.67k
            fuzzing::memory::memory_test(res);
143
6.67k
        }
144
6.67k
        {
145
6.67k
            const bool res = encoder.set_ogg_serial_number(ds.Get<long>());
146
6.67k
            fuzzing::memory::memory_test(res);
147
6.67k
        }
148
6.67k
        {
149
6.67k
            const bool res = encoder.set_verify(ds.Get<bool>());
150
6.67k
            fuzzing::memory::memory_test(res);
151
6.67k
        }
152
6.67k
        {
153
6.67k
            const bool res = encoder.set_compression_level(ds.Get<uint8_t>());
154
6.67k
            fuzzing::memory::memory_test(res);
155
6.67k
        }
156
6.67k
        {
157
6.67k
            const bool res = encoder.set_do_mid_side_stereo(ds.Get<bool>());
158
6.67k
            fuzzing::memory::memory_test(res);
159
6.67k
        }
160
6.67k
        {
161
6.67k
            const bool res = encoder.set_loose_mid_side_stereo(ds.Get<bool>());
162
6.67k
            fuzzing::memory::memory_test(res);
163
6.67k
        }
164
6.67k
        {
165
6.67k
            const bool res = encoder.set_max_lpc_order(ds.Get<uint8_t>());
166
6.67k
            fuzzing::memory::memory_test(res);
167
6.67k
        }
168
6.67k
        {
169
6.67k
            const bool res = encoder.set_qlp_coeff_precision(ds.Get<uint32_t>());
170
6.67k
            fuzzing::memory::memory_test(res);
171
6.67k
        }
172
6.67k
        {
173
6.67k
            const bool res = encoder.set_do_escape_coding(ds.Get<bool>());
174
6.67k
            fuzzing::memory::memory_test(res);
175
6.67k
        }
176
6.67k
        {
177
6.67k
            const bool res = encoder.set_min_residual_partition_order(ds.Get<uint32_t>());
178
6.67k
            fuzzing::memory::memory_test(res);
179
6.67k
        }
180
6.67k
        {
181
6.67k
            const bool res = encoder.set_max_residual_partition_order(ds.Get<uint32_t>());
182
6.67k
            fuzzing::memory::memory_test(res);
183
6.67k
        }
184
6.67k
        {
185
6.67k
            const bool res = encoder.set_total_samples_estimate(ds.Get<uint64_t>());
186
6.67k
            fuzzing::memory::memory_test(res);
187
6.67k
        }
188
6.67k
        {
189
6.67k
            const bool res = encoder.set_blocksize(ds.Get<uint16_t>());
190
6.67k
            fuzzing::memory::memory_test(res);
191
6.67k
        }
192
6.67k
        {
193
6.67k
            const bool res = encoder.set_limit_min_bitrate(ds.Get<bool>());
194
6.67k
            fuzzing::memory::memory_test(res);
195
6.67k
        }
196
6.67k
        {
197
6.67k
            const bool res = encoder.set_sample_rate(ds.Get<uint32_t>());
198
6.67k
            fuzzing::memory::memory_test(res);
199
6.67k
        }
200
6.67k
        {
201
6.67k
            const bool res = encoder.set_num_threads(ds.Get<uint32_t>());
202
6.67k
            fuzzing::memory::memory_test(res);
203
6.67k
        }
204
205
6.67k
        decoder.set_metadata_respond_all();
206
207
6.67k
        {
208
6.67k
            ::FLAC__StreamDecoderInitStatus ret;
209
6.67k
            if ( ds.Get<bool>() ) {
210
5.74k
                ret = decoder.init();
211
5.74k
            } else {
212
928
                ret = decoder.init_ogg();
213
928
            }
214
215
6.67k
            if ( ret != FLAC__STREAM_DECODER_INIT_STATUS_OK ) {
216
0
                goto end;
217
0
            }
218
219
6.67k
            decoder.process_until_end_of_metadata();
220
6.67k
            if(decoder.num_metadata_blocks > 0)
221
807
                encoder.set_metadata(decoder.metadata_blocks, decoder.num_metadata_blocks);
222
6.67k
        }
223
224
0
        {
225
6.67k
            ::FLAC__StreamEncoderInitStatus ret;
226
6.67k
            if ( ds.Get<bool>() ) {
227
2.45k
                ret = encoder.init();
228
4.22k
            } else {
229
4.22k
                ret = encoder.init_ogg();
230
4.22k
            }
231
232
6.67k
            if ( ret != FLAC__STREAM_ENCODER_INIT_STATUS_OK ) {
233
660
                goto end;
234
660
            }
235
6.67k
        }
236
237
  /* These sets must fail, because encoder is already initialized */
238
6.01k
        {
239
6.01k
            bool res = false;
240
6.01k
            res = res || encoder.set_streamable_subset(true);
241
6.01k
            res = res || encoder.set_ogg_serial_number(0);
242
6.01k
            res = res || encoder.set_verify(true);
243
6.01k
            res = res || encoder.set_compression_level(0);
244
6.01k
            res = res || encoder.set_do_exhaustive_model_search(true);
245
6.01k
            res = res || encoder.set_do_mid_side_stereo(true);
246
6.01k
            res = res || encoder.set_loose_mid_side_stereo(true);
247
6.01k
            res = res || encoder.set_apodization("test");
248
6.01k
            res = res || encoder.set_max_lpc_order(0);
249
6.01k
            res = res || encoder.set_qlp_coeff_precision(0);
250
6.01k
            res = res || encoder.set_do_qlp_coeff_prec_search(true);
251
6.01k
            res = res || encoder.set_do_escape_coding(true);
252
6.01k
            res = res || encoder.set_min_residual_partition_order(0);
253
6.01k
            res = res || encoder.set_max_residual_partition_order(0);
254
6.01k
            res = res || encoder.set_rice_parameter_search_dist(0);
255
6.01k
            res = res || encoder.set_total_samples_estimate(0);
256
6.01k
            res = res || encoder.set_channels(channels);
257
6.01k
            res = res || encoder.set_bits_per_sample(16);
258
6.01k
            res = res || encoder.set_limit_min_bitrate(true);
259
6.01k
            res = res || encoder.set_blocksize(3021);
260
6.01k
            res = res || encoder.set_sample_rate(44100);
261
6.01k
            res = res || (encoder.set_num_threads(4) == FLAC__STREAM_ENCODER_SET_NUM_THREADS_OK);
262
6.01k
            fuzzing::memory::memory_test(res);
263
6.01k
            if(res)
264
0
                abort();
265
6.01k
        }
266
267
268
6.01k
        {
269
            /* XORing values as otherwise compiler will optimize, apparently */
270
6.01k
            bool res = false;
271
6.01k
            res = res != encoder.get_streamable_subset();
272
6.01k
            res = res != encoder.get_verify();
273
6.01k
            res = res != encoder.get_do_exhaustive_model_search();
274
6.01k
            res = res != encoder.get_do_mid_side_stereo();
275
6.01k
            res = res != encoder.get_loose_mid_side_stereo();
276
6.01k
            res = res != encoder.get_max_lpc_order();
277
6.01k
            res = res != encoder.get_qlp_coeff_precision();
278
6.01k
            res = res != encoder.get_do_qlp_coeff_prec_search();
279
6.01k
            res = res != encoder.get_do_escape_coding();
280
6.01k
            res = res != encoder.get_min_residual_partition_order();
281
6.01k
            res = res != encoder.get_max_residual_partition_order();
282
6.01k
            res = res != encoder.get_rice_parameter_search_dist();
283
6.01k
            res = res != encoder.get_total_samples_estimate();
284
6.01k
            res = res != encoder.get_channels();
285
6.01k
            res = res != encoder.get_bits_per_sample();
286
6.01k
            res = res != encoder.get_limit_min_bitrate();
287
6.01k
            res = res != encoder.get_blocksize();
288
6.01k
            res = res != encoder.get_sample_rate();
289
6.01k
            res = res != encoder.get_num_threads();
290
6.01k
            fuzzing::memory::memory_test(res);
291
6.01k
        }
292
293
6.01k
        decoder.process_until_end_of_stream();
294
295
6.01k
    } catch ( ... ) { }
296
297
6.67k
end:
298
6.67k
    {
299
6.67k
        const bool res = encoder.finish();
300
6.67k
        fuzzing::memory::memory_test(res);
301
6.67k
    }
302
6.67k
    {
303
6.67k
        const bool res = decoder.finish();
304
6.67k
        fuzzing::memory::memory_test(res);
305
6.67k
    }
306
45.2k
    for(int i = 0; i < decoder.num_metadata_blocks; i++)
307
38.5k
        FLAC__metadata_object_delete(decoder.metadata_blocks[i]);
308
309
6.67k
    return 0;
310
6.67k
}