Coverage Report

Created: 2026-09-03 06:32

next uncovered line (L), next uncovered region (R), next uncovered branch (B)
/src/libssh/tests/fuzz/ssh_bind_config_fuzzer.c
Line
Count
Source
1
/*
2
 * Copyright 2021 Jakub Jelen <jjelen@redhat.com>
3
 *
4
 * Licensed under the Apache License, Version 2.0 (the "License");
5
 * you may not use this file except in compliance with the License.
6
 * You may obtain a copy of the License at
7
 *
8
 *      http://www.apache.org/licenses/LICENSE-2.0
9
 *
10
 * Unless required by applicable law or agreed to in writing, software
11
 * distributed under the License is distributed on an "AS IS" BASIS,
12
 * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
13
 * See the License for the specific language governing permissions and
14
 * limitations under the License.
15
 */
16
17
#include <assert.h>
18
#include <stdio.h>
19
#include <stdlib.h>
20
#include <string.h>
21
22
#define LIBSSH_STATIC 1
23
#include "libssh/libssh.h"
24
#include "libssh/server.h"
25
#include "libssh/bind_config.h"
26
27
#include "nallocinc.c"
28
29
static void _fuzz_finalize(void)
30
3
{
31
3
    ssh_finalize();
32
3
}
33
34
int LLVMFuzzerInitialize(int *argc, char ***argv)
35
42
{
36
42
    (void)argc;
37
38
42
    nalloc_init(*argv[0]);
39
40
42
    ssh_init();
41
42
42
    atexit(_fuzz_finalize);
43
44
42
    return 0;
45
42
}
46
47
int LLVMFuzzerTestOneInput(const uint8_t *data, size_t size)
48
11.0k
{
49
11.0k
    ssh_bind bind = NULL;
50
11.0k
    char *input = NULL;
51
11.0k
    const char *env = NULL;
52
53
11.0k
    input = (char *)malloc(size + 1);
54
11.0k
    if (!input) {
55
0
        return 1;
56
0
    }
57
11.0k
    memcpy(input, data, size);
58
11.0k
    input[size] = '\0';
59
60
11.0k
    assert(nalloc_start(data, size) > 0);
61
62
11.0k
    bind = ssh_bind_new();
63
11.0k
    if (bind == NULL) {
64
1.38k
        goto out;
65
1.38k
    }
66
67
9.67k
    env = getenv("LIBSSH_VERBOSITY");
68
9.67k
    if (env != NULL && strlen(env) > 0) {
69
0
        ssh_bind_options_set(bind, SSH_BIND_OPTIONS_LOG_VERBOSITY_STR, env);
70
0
    }
71
9.67k
    ssh_bind_config_parse_string(bind, input);
72
73
9.67k
    ssh_bind_free(bind);
74
75
11.0k
out:
76
11.0k
    free(input);
77
78
11.0k
    nalloc_end();
79
11.0k
    return 0;
80
9.67k
}