Coverage Report

Created: 2026-08-14 06:37

next uncovered line (L), next uncovered region (R), next uncovered branch (B)
/src/libraw_fuzzer.cc
Line
Count
Source
1
/*  Copyright 2020 Google Inc.
2
3
Licensed under the Apache License, Version 2.0 (the "License");
4
you may not use this file except in compliance with the License.
5
You may obtain a copy of the License at
6
7
      http://www.apache.org/licenses/LICENSE-2.0
8
9
Unless required by applicable law or agreed to in writing, software
10
distributed under the License is distributed on an "AS IS" BASIS,
11
WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
12
See the License for the specific language governing permissions and
13
limitations under the License.
14
*/
15
16
#include <stddef.h>
17
#include <stdint.h>
18
19
#include <string>
20
#include <fuzzer/FuzzedDataProvider.h>
21
22
#include <libraw.h>
23
24
enum InterpolationOptions {
25
  Linear = 0,
26
  Vng = 1, 
27
  Ppg = 2,
28
  Ahd = 3,
29
  Dcb = 4,
30
  Dht = 11,
31
  AhdModified = 12
32
};
33
static const InterpolationOptions options[] = {Linear, Vng, Ppg, Ahd, Dcb, Dht, AhdModified};
34
35
19.2k
extern "C" int LLVMFuzzerTestOneInput(const uint8_t* data, size_t size) {
36
  // Input less than 15mb
37
19.2k
  if (size > 15000000) {
38
0
    return 0;
39
0
  }
40
41
19.2k
  FuzzedDataProvider fdp(data, size);
42
43
19.2k
  LibRaw lib_raw;
44
19.2k
  lib_raw.imgdata.rawparams.max_raw_memory_mb = 300;
45
46
96.0k
  for(int i =0; i < 4; i++)
47
76.8k
    lib_raw.output_params_ptr()->aber[i] = fdp.ConsumeFloatingPoint<double>();
48
96.0k
  for(int i =0; i < 4; i++)
49
76.8k
    lib_raw.output_params_ptr()->user_mul[i] = fdp.ConsumeFloatingPoint<float>();
50
57.6k
  for(int i =0; i < 2; i++)
51
38.4k
    lib_raw.output_params_ptr()->gamm[i] = fdp.ConsumeFloatingPoint<double>();
52
19.2k
  lib_raw.output_params_ptr()->bright = fdp.ConsumeFloatingPoint<float>();
53
19.2k
  lib_raw.output_params_ptr()->threshold = fdp.ConsumeFloatingPoint<float>();
54
19.2k
  lib_raw.output_params_ptr()->use_auto_wb = fdp.ConsumeIntegral<int>();
55
19.2k
  lib_raw.output_params_ptr()->output_color = fdp.ConsumeIntegralInRange<int>(0, 6);
56
19.2k
  lib_raw.output_params_ptr()->user_flip = fdp.ConsumeIntegralInRange<int>(0, 7);
57
19.2k
  lib_raw.output_params_ptr()->user_black = fdp.ConsumeIntegral<int>();
58
19.2k
  lib_raw.output_params_ptr()->user_sat = fdp.ConsumeIntegral<int>();
59
19.2k
  lib_raw.output_params_ptr()->auto_bright_thr = fdp.ConsumeFloatingPoint<float>();
60
19.2k
  lib_raw.output_params_ptr()->adjust_maximum_thr = fdp.ConsumeFloatingPointInRange<float>(0.f, 1.f);
61
19.2k
  lib_raw.output_params_ptr()->fbdd_noiserd = fdp.ConsumeIntegralInRange<int>(0, 5);
62
63
19.2k
  std::vector<char> payload = fdp.ConsumeRemainingBytes<char>();
64
19.2k
  int result = lib_raw.open_buffer(payload.data(), payload.size());
65
19.2k
  if (result != LIBRAW_SUCCESS) {
66
14.1k
    return 0;
67
14.1k
  }
68
69
5.07k
  result = lib_raw.unpack();
70
5.07k
  if (result != LIBRAW_SUCCESS) {
71
2.67k
    return 0;
72
2.67k
  }
73
74
2.40k
  result = lib_raw.unpack_thumb();
75
2.40k
  if (result != LIBRAW_SUCCESS) {
76
773
    return 0;
77
773
  }
78
79
1.62k
  result = lib_raw.raw2image();
80
1.62k
  if (result != LIBRAW_SUCCESS) {
81
136
    return 0;
82
136
  }
83
1.49k
  lib_raw.free_image();
84
85
10.6k
  for (int i = 0; i < sizeof(options)/sizeof(*options); i++) {
86
9.40k
    lib_raw.output_params_ptr()->user_qual = static_cast<int>(options[i]);
87
88
9.40k
    result = lib_raw.dcraw_process();
89
9.40k
    if (result != LIBRAW_SUCCESS) {
90
232
      return 0;
91
232
    }
92
9.40k
  }
93
94
1.26k
  return 0;
95
1.49k
}