Coverage Report

Created: 2026-09-14 07:10

next uncovered line (L), next uncovered region (R), next uncovered branch (B)
/src/fmt/test/fuzzing/fuzzer-common.h
Line
Count
Source
1
// Copyright (c) 2019, Paul Dreik
2
// For the license information refer to format.h.
3
4
#ifndef FUZZER_COMMON_H
5
#define FUZZER_COMMON_H
6
7
#include <fmt/core.h>
8
9
#include <cstdint>  // std::uint8_t
10
#include <cstring>  // memcpy
11
#include <vector>
12
13
// One can format to either a string, or a buffer. The latter is faster, but
14
// one may be interested in formatting to a string instead to verify it works
15
// as intended. To avoid a combinatoric explosion, select this at compile time
16
// instead of dynamically from the fuzz data.
17
#define FMT_FUZZ_FORMAT_TO_STRING 0
18
19
// If {fmt} is given a buffer that is separately allocated, chances that address
20
// sanitizer detects out of bound reads is much higher. However, it slows down
21
// the fuzzing.
22
#define FMT_FUZZ_SEPARATE_ALLOCATION 1
23
24
// The size of the largest possible type in use.
25
// To let the fuzzer mutation be efficient at cross pollinating between
26
// different types, use a fixed size format. The same bit pattern, interpreted
27
// as another type, is likely interesting.
28
constexpr auto fixed_size = 16;
29
30
// Casts data to a char pointer.
31
90.3k
template <typename T> inline const char* as_chars(const T* data) {
32
90.3k
  return reinterpret_cast<const char*>(data);
33
90.3k
}
34
35
// Casts data to a byte pointer.
36
template <typename T> inline const std::uint8_t* as_bytes(const T* data) {
37
  return reinterpret_cast<const std::uint8_t*>(data);
38
}
39
40
// Blits bytes from data to form an (assumed trivially constructible) object
41
// of type Item.
42
126k
template <class Item> inline Item assign_from_buf(const std::uint8_t* data) {
43
126k
  auto item = Item();
44
126k
  std::memcpy(&item, data, sizeof(Item));
45
126k
  return item;
46
126k
}
char assign_from_buf<char>(unsigned char const*)
Line
Count
Source
42
6.95k
template <class Item> inline Item assign_from_buf(const std::uint8_t* data) {
43
6.95k
  auto item = Item();
44
6.95k
  std::memcpy(&item, data, sizeof(Item));
45
6.95k
  return item;
46
6.95k
}
signed char assign_from_buf<signed char>(unsigned char const*)
Line
Count
Source
42
6.82k
template <class Item> inline Item assign_from_buf(const std::uint8_t* data) {
43
6.82k
  auto item = Item();
44
6.82k
  std::memcpy(&item, data, sizeof(Item));
45
6.82k
  return item;
46
6.82k
}
unsigned char assign_from_buf<unsigned char>(unsigned char const*)
Line
Count
Source
42
6.32k
template <class Item> inline Item assign_from_buf(const std::uint8_t* data) {
43
6.32k
  auto item = Item();
44
6.32k
  std::memcpy(&item, data, sizeof(Item));
45
6.32k
  return item;
46
6.32k
}
short assign_from_buf<short>(unsigned char const*)
Line
Count
Source
42
6.89k
template <class Item> inline Item assign_from_buf(const std::uint8_t* data) {
43
6.89k
  auto item = Item();
44
6.89k
  std::memcpy(&item, data, sizeof(Item));
45
6.89k
  return item;
46
6.89k
}
unsigned short assign_from_buf<unsigned short>(unsigned char const*)
Line
Count
Source
42
6.61k
template <class Item> inline Item assign_from_buf(const std::uint8_t* data) {
43
6.61k
  auto item = Item();
44
6.61k
  std::memcpy(&item, data, sizeof(Item));
45
6.61k
  return item;
46
6.61k
}
int assign_from_buf<int>(unsigned char const*)
Line
Count
Source
42
8.97k
template <class Item> inline Item assign_from_buf(const std::uint8_t* data) {
43
8.97k
  auto item = Item();
44
8.97k
  std::memcpy(&item, data, sizeof(Item));
45
8.97k
  return item;
46
8.97k
}
unsigned int assign_from_buf<unsigned int>(unsigned char const*)
Line
Count
Source
42
8.65k
template <class Item> inline Item assign_from_buf(const std::uint8_t* data) {
43
8.65k
  auto item = Item();
44
8.65k
  std::memcpy(&item, data, sizeof(Item));
45
8.65k
  return item;
46
8.65k
}
long assign_from_buf<long>(unsigned char const*)
Line
Count
Source
42
12.8k
template <class Item> inline Item assign_from_buf(const std::uint8_t* data) {
43
12.8k
  auto item = Item();
44
12.8k
  std::memcpy(&item, data, sizeof(Item));
45
12.8k
  return item;
46
12.8k
}
unsigned long assign_from_buf<unsigned long>(unsigned char const*)
Line
Count
Source
42
9.25k
template <class Item> inline Item assign_from_buf(const std::uint8_t* data) {
43
9.25k
  auto item = Item();
44
9.25k
  std::memcpy(&item, data, sizeof(Item));
45
9.25k
  return item;
46
9.25k
}
float assign_from_buf<float>(unsigned char const*)
Line
Count
Source
42
14.6k
template <class Item> inline Item assign_from_buf(const std::uint8_t* data) {
43
14.6k
  auto item = Item();
44
14.6k
  std::memcpy(&item, data, sizeof(Item));
45
14.6k
  return item;
46
14.6k
}
double assign_from_buf<double>(unsigned char const*)
Line
Count
Source
42
19.5k
template <class Item> inline Item assign_from_buf(const std::uint8_t* data) {
43
19.5k
  auto item = Item();
44
19.5k
  std::memcpy(&item, data, sizeof(Item));
45
19.5k
  return item;
46
19.5k
}
long double assign_from_buf<long double>(unsigned char const*)
Line
Count
Source
42
14.1k
template <class Item> inline Item assign_from_buf(const std::uint8_t* data) {
43
14.1k
  auto item = Item();
44
14.1k
  std::memcpy(&item, data, sizeof(Item));
45
14.1k
  return item;
46
14.1k
}
long long assign_from_buf<long long>(unsigned char const*)
Line
Count
Source
42
3.76k
template <class Item> inline Item assign_from_buf(const std::uint8_t* data) {
43
3.76k
  auto item = Item();
44
3.76k
  std::memcpy(&item, data, sizeof(Item));
45
3.76k
  return item;
46
3.76k
}
void* assign_from_buf<void*>(unsigned char const*)
Line
Count
Source
42
739
template <class Item> inline Item assign_from_buf(const std::uint8_t* data) {
43
739
  auto item = Item();
44
739
  std::memcpy(&item, data, sizeof(Item));
45
739
  return item;
46
739
}
47
48
// Reads a boolean value by looking at the first byte from data.
49
1.68k
template <> inline bool assign_from_buf<bool>(const std::uint8_t* data) {
50
1.68k
  return *data != 0;
51
1.68k
}
52
53
struct data_to_string {
54
#if FMT_FUZZ_SEPARATE_ALLOCATION
55
  std::vector<char> buffer;
56
57
  data_to_string(const uint8_t* data, size_t size, bool add_terminator = false)
58
34.5k
      : buffer(size + (add_terminator ? 1 : 0)) {
59
34.5k
    if (size) {
60
34.5k
      std::memcpy(buffer.data(), data, size);
61
34.5k
    }
62
34.5k
  }
63
64
34.5k
  fmt::string_view get() const { return {buffer.data(), buffer.size()}; }
65
#else
66
  fmt::string_view sv;
67
68
  data_to_string(const uint8_t* data, size_t size, bool = false)
69
      : str(as_chars(data), size) {}
70
71
  fmt::string_view get() const { return sv; }
72
#endif
73
74
10.8k
  const char* data() const { return get().data(); }
75
};
76
77
#endif  // FUZZER_COMMON_H