Coverage Report

Created: 2026-09-28 10:59

next uncovered line (L), next uncovered region (R), next uncovered branch (B)
/src/libreoffice/vcl/workben/fods2xlsfuzzer.cxx
Line
Count
Source
1
/* -*- Mode: C++; tab-width: 4; indent-tabs-mode: nil; c-basic-offset: 4 -*- */
2
/*
3
 * This file is part of the LibreOffice project.
4
 *
5
 * This Source Code Form is subject to the terms of the Mozilla Public
6
 * License, v. 2.0. If a copy of the MPL was not distributed with this
7
 * file, You can obtain one at http://mozilla.org/MPL/2.0/.
8
 */
9
10
#include <tools/stream.hxx>
11
#include <vcl/FilterConfigItem.hxx>
12
#include <com/sun/star/awt/XToolkit.hpp>
13
#include <com/sun/star/ucb/XContentProvider.hpp>
14
#include <com/sun/star/ucb/XUniversalContentBroker.hpp>
15
#include <libxml/parser.h>
16
#include "commonfuzzer.hxx"
17
18
0
extern "C" void* ScCreateDialogFactory() { return nullptr; }
19
20
extern "C" bool TestFODSExportXLS(SvStream& rStream);
21
22
0
static void silent_error_func(void*, const char* /*format*/, ...) {}
23
24
extern "C" int LLVMFuzzerInitialize(int* argc, char*** argv)
25
12
{
26
12
    if (__lsan_disable)
27
0
        __lsan_disable();
28
29
12
    CommonInitialize(argc, argv);
30
31
    // initialise unconfigured UCB:
32
12
    css::uno::Reference<css::ucb::XUniversalContentBroker> xUcb(
33
12
        comphelper::getProcessServiceFactory()->createInstance(
34
12
            "com.sun.star.ucb.UniversalContentBroker"),
35
12
        css::uno::UNO_QUERY_THROW);
36
12
    css::uno::Sequence<css::uno::Any> aArgs{ css::uno::Any(OUString("NoConfig")) };
37
12
    css::uno::Reference<css::ucb::XContentProvider> xFileProvider(
38
12
        comphelper::getProcessServiceFactory()->createInstanceWithArguments(
39
12
            "com.sun.star.ucb.FileContentProvider", aArgs),
40
12
        css::uno::UNO_QUERY_THROW);
41
12
    xUcb->registerContentProvider(xFileProvider, "file", true);
42
43
    // create and hold a reference to XToolkit here to avoid the lsan warning about its leak
44
    // due to getting created in the unusual case of no vcl main loop
45
12
    static css::uno::Reference<css::awt::XToolkit> xTk(
46
12
        comphelper::getProcessServiceFactory()->createInstance("com.sun.star.awt.Toolkit"),
47
12
        css::uno::UNO_QUERY_THROW);
48
49
12
    if (__lsan_enable)
50
0
        __lsan_enable();
51
52
12
    xmlInitParser();
53
12
    xmlSetGenericErrorFunc(nullptr, silent_error_func);
54
55
12
    return 0;
56
12
}
57
58
extern "C" size_t LLVMFuzzerMutate(uint8_t* Data, size_t Size, size_t MaxSize);
59
60
extern "C" {
61
5.25k
__attribute__((weak)) void __msan_unpoison(const volatile void*, size_t) {}
62
}
63
64
extern "C" size_t LLVMFuzzerCustomMutator(uint8_t* Data, size_t Size, size_t MaxSize,
65
                                          unsigned int /*Seed*/)
66
0
{
67
0
    size_t Ret = LLVMFuzzerMutate(Data, Size, MaxSize);
68
69
0
    __msan_unpoison(Data, Ret);
70
71
    // an effort to only generate valid xml, in this fuzzer we only really care
72
    // about the deeper levels of turning valid input into calc layout and
73
    // xls export
74
75
0
    xmlParserCtxtPtr ctxt = xmlNewParserCtxt();
76
0
    xmlDocPtr Doc = xmlCtxtReadMemory(ctxt, reinterpret_cast<const char*>(Data), Ret, nullptr,
77
0
                                      nullptr, XML_PARSE_NONET);
78
0
    if (Doc == nullptr)
79
0
        Ret = 0;
80
0
    else
81
0
        xmlFreeDoc(Doc);
82
0
    xmlFreeParserCtxt(ctxt);
83
0
    xmlResetLastError();
84
0
    return Ret;
85
0
}
86
87
extern "C" int LLVMFuzzerTestOneInput(const uint8_t* data, size_t size)
88
13.2k
{
89
13.2k
    SvMemoryStream aStream(const_cast<uint8_t*>(data), size, StreamMode::READ);
90
13.2k
    bool bFODTLoaded = TestFODSExportXLS(aStream);
91
    // if the fodt didn't load then reject so that input will not be added to the corpus
92
    // we're not interested in input that doesn't go on to exercise the xls export
93
13.2k
    return bFODTLoaded ? 0 : -1;
94
13.2k
}
95
96
/* vim:set shiftwidth=4 softtabstop=4 expandtab: */