Coverage Report

Created: 2026-09-13 06:28

next uncovered line (L), next uncovered region (R), next uncovered branch (B)
/src/libraw_fuzzer.cc
Line
Count
Source
1
/*  Copyright 2020 Google Inc.
2
3
Licensed under the Apache License, Version 2.0 (the "License");
4
you may not use this file except in compliance with the License.
5
You may obtain a copy of the License at
6
7
      http://www.apache.org/licenses/LICENSE-2.0
8
9
Unless required by applicable law or agreed to in writing, software
10
distributed under the License is distributed on an "AS IS" BASIS,
11
WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
12
See the License for the specific language governing permissions and
13
limitations under the License.
14
*/
15
16
#include <stddef.h>
17
#include <stdint.h>
18
19
#include <string>
20
#include <fuzzer/FuzzedDataProvider.h>
21
22
#include <libraw.h>
23
24
enum InterpolationOptions {
25
  Linear = 0,
26
  Vng = 1, 
27
  Ppg = 2,
28
  Ahd = 3,
29
  Dcb = 4,
30
  Dht = 11,
31
  AhdModified = 12
32
};
33
static const InterpolationOptions options[] = {Linear, Vng, Ppg, Ahd, Dcb, Dht, AhdModified};
34
35
101k
extern "C" int LLVMFuzzerTestOneInput(const uint8_t* data, size_t size) {
36
  // Input less than 15mb
37
101k
  if (size > 15000000) {
38
0
    return 0;
39
0
  }
40
41
101k
  FuzzedDataProvider fdp(data, size);
42
43
101k
  LibRaw lib_raw;
44
101k
  lib_raw.imgdata.rawparams.max_raw_memory_mb = 300;
45
46
505k
  for(int i =0; i < 4; i++)
47
404k
    lib_raw.output_params_ptr()->aber[i] = fdp.ConsumeFloatingPoint<double>();
48
505k
  for(int i =0; i < 4; i++)
49
404k
    lib_raw.output_params_ptr()->user_mul[i] = fdp.ConsumeFloatingPoint<float>();
50
303k
  for(int i =0; i < 2; i++)
51
202k
    lib_raw.output_params_ptr()->gamm[i] = fdp.ConsumeFloatingPoint<double>();
52
101k
  lib_raw.output_params_ptr()->bright = fdp.ConsumeFloatingPoint<float>();
53
101k
  lib_raw.output_params_ptr()->threshold = fdp.ConsumeFloatingPoint<float>();
54
101k
  lib_raw.output_params_ptr()->use_auto_wb = fdp.ConsumeIntegral<int>();
55
101k
  lib_raw.output_params_ptr()->output_color = fdp.ConsumeIntegralInRange<int>(0, 6);
56
101k
  lib_raw.output_params_ptr()->user_flip = fdp.ConsumeIntegralInRange<int>(0, 7);
57
101k
  lib_raw.output_params_ptr()->user_black = fdp.ConsumeIntegral<int>();
58
101k
  lib_raw.output_params_ptr()->user_sat = fdp.ConsumeIntegral<int>();
59
101k
  lib_raw.output_params_ptr()->auto_bright_thr = fdp.ConsumeFloatingPoint<float>();
60
101k
  lib_raw.output_params_ptr()->adjust_maximum_thr = fdp.ConsumeFloatingPointInRange<float>(0.f, 1.f);
61
101k
  lib_raw.output_params_ptr()->fbdd_noiserd = fdp.ConsumeIntegralInRange<int>(0, 5);
62
63
101k
  std::vector<char> payload = fdp.ConsumeRemainingBytes<char>();
64
101k
  int result = lib_raw.open_buffer(payload.data(), payload.size());
65
101k
  if (result != LIBRAW_SUCCESS) {
66
73.7k
    return 0;
67
73.7k
  }
68
69
27.3k
  result = lib_raw.unpack();
70
27.3k
  if (result != LIBRAW_SUCCESS) {
71
13.3k
    return 0;
72
13.3k
  }
73
74
14.0k
  result = lib_raw.unpack_thumb();
75
14.0k
  if (result != LIBRAW_SUCCESS) {
76
4.30k
    return 0;
77
4.30k
  }
78
79
9.79k
  result = lib_raw.raw2image();
80
9.79k
  if (result != LIBRAW_SUCCESS) {
81
1.05k
    return 0;
82
1.05k
  }
83
8.74k
  lib_raw.free_image();
84
85
63.2k
  for (int i = 0; i < sizeof(options)/sizeof(*options); i++) {
86
55.7k
    lib_raw.output_params_ptr()->user_qual = static_cast<int>(options[i]);
87
88
55.7k
    result = lib_raw.dcraw_process();
89
55.7k
    if (result != LIBRAW_SUCCESS) {
90
1.24k
      return 0;
91
1.24k
    }
92
55.7k
  }
93
94
7.49k
  return 0;
95
8.74k
}