Coverage Report

Created: 2026-09-03 06:54

next uncovered line (L), next uncovered region (R), next uncovered branch (B)
/src/h3/src/apps/fuzzers/fuzzerPolygonToCells.c
Line
Count
Source
1
/*
2
 * Copyright 2022-2024 Uber Technologies, Inc.
3
 *
4
 * Licensed under the Apache License, Version 2.0 (the "License");
5
 * you may not use this file except in compliance with the License.
6
 * You may obtain a copy of the License at
7
 *
8
 *         http://www.apache.org/licenses/LICENSE-2.0
9
 *
10
 * Unless required by applicable law or agreed to in writing, software
11
 * distributed under the License is distributed on an "AS IS" BASIS,
12
 * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
13
 * See the License for the specific language governing permissions and
14
 * limitations under the License.
15
 */
16
/** @file
17
 * @brief Fuzzer program for polygonToCells and related functions
18
 */
19
20
#include "aflHarness.h"
21
#include "h3api.h"
22
#include "polygon.h"
23
#include "utility.h"
24
25
typedef struct {
26
    int res;
27
    int numHoles;
28
    // repeating: num verts, verts
29
    // We add a large fixed buffer so our test case generator for AFL
30
    // knows how large to make the file.
31
    uint8_t buffer[1024];
32
} inputArgs;
33
34
const int MAX_RES = 15;
35
const int MAX_SZ = 4000000;
36
const int MAX_HOLES = 100;
37
38
int populateGeoLoop(GeoLoop *g, const uint8_t *data, size_t *offset,
39
9.30k
                    size_t size) {
40
9.30k
    if (size < *offset + sizeof(int)) {
41
8
        return 1;
42
8
    }
43
9.29k
    int numVerts = *(const int *)(data + *offset);
44
9.29k
    *offset = *offset + sizeof(int);
45
9.29k
    g->numVerts = numVerts;
46
9.29k
    if (size < *offset + sizeof(LatLng) * numVerts) {
47
148
        return 1;
48
148
    }
49
9.14k
    g->verts = (LatLng *)(data + *offset);
50
9.14k
    *offset = *offset + sizeof(LatLng) * numVerts;
51
9.14k
    return 0;
52
9.29k
}
53
54
5.12k
void run(GeoPolygon *geoPolygon, uint32_t flags, int res) {
55
5.12k
    int64_t sz;
56
5.12k
    H3Error err = H3_EXPORT(maxPolygonToCellsSize)(geoPolygon, res, flags, &sz);
57
5.12k
    if (!err && sz < MAX_SZ) {
58
4.18k
        H3Index *out = calloc(sz, sizeof(H3Index));
59
4.18k
        H3_EXPORT(polygonToCells)(geoPolygon, res, flags, out);
60
4.18k
        free(out);
61
4.18k
    }
62
5.12k
}
63
64
599
int LLVMFuzzerTestOneInput(const uint8_t *data, size_t size) {
65
    // TODO: It is difficult for the fuzzer to generate inputs that are
66
    // considered valid by this fuzzer. fuzzerPolygonToCellsNoHoles.c
67
    // is a workaround for that.
68
599
    if (size < sizeof(inputArgs)) {
69
20
        return 0;
70
20
    }
71
579
    const inputArgs *args = (const inputArgs *)data;
72
579
    int res = args->res % (MAX_RES + 1);
73
74
579
    GeoPolygon geoPolygon;
75
579
    int originalNumHoles = args->numHoles % MAX_HOLES;
76
579
    geoPolygon.numHoles = originalNumHoles;
77
579
    if (geoPolygon.numHoles < 0) {
78
9
        return 0;
79
9
    }
80
570
    geoPolygon.holes = calloc(geoPolygon.numHoles, sizeof(GeoLoop));
81
570
    size_t offset = sizeof(inputArgs) - sizeof(args->buffer);
82
570
    if (populateGeoLoop(&geoPolygon.geoloop, data, &offset, size)) {
83
71
        free(geoPolygon.holes);
84
71
        return 0;
85
71
    }
86
9.14k
    for (int i = 0; i < geoPolygon.numHoles; i++) {
87
8.73k
        if (populateGeoLoop(&geoPolygon.holes[i], data, &offset, size)) {
88
85
            free(geoPolygon.holes);
89
85
            return 0;
90
85
        }
91
8.73k
    }
92
93
2.07k
    for (uint32_t flags = 0; flags < CONTAINMENT_INVALID; flags++) {
94
1.65k
        geoPolygon.numHoles = originalNumHoles;
95
1.65k
        run(&geoPolygon, 0, res);
96
1.65k
        geoPolygon.numHoles = 0;
97
1.65k
        run(&geoPolygon, 0, res);
98
1.65k
    }
99
414
    free(geoPolygon.holes);
100
101
414
    return 0;
102
499
}
103
104
AFL_HARNESS_MAIN(sizeof(inputArgs));