Coverage Report

Created: 2026-05-30 06:46

next uncovered line (L), next uncovered region (R), next uncovered branch (B)
/src/libyaml_emitter_fuzzer.c
Line
Count
Source
1
// Copyright 2020 Google LLC
2
//
3
// Licensed under the Apache License, Version 2.0 (the "License");
4
// you may not use this file except in compliance with the License.
5
// You may obtain a copy of the License at
6
//
7
//      http://www.apache.org/licenses/LICENSE-2.0
8
//
9
// Unless required by applicable law or agreed to in writing, software
10
// distributed under the License is distributed on an "AS IS" BASIS,
11
// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
12
// See the License for the specific language governing permissions and
13
// limitations under the License.
14
15
#include "yaml.h"
16
#include "yaml_write_handler.h"
17
#include <assert.h>
18
#include <stdbool.h>
19
#include <stdint.h>
20
#include <stdio.h>
21
#include <stdlib.h>
22
#include <string.h>
23
24
#ifdef NDEBUG
25
#undef NDEBUG
26
#endif
27
28
508k
#define MAX_EVENTS 1024
29
30
279k
bool events_equal(yaml_event_t *event1, yaml_event_t *event2) {
31
  
32
279k
  const bool equal = true;
33
34
279k
  if (event1->type != event2->type)
35
1
    return equal;
36
37
279k
  switch (event1->type) {
38
1.67k
  case YAML_STREAM_START_EVENT:
39
1.67k
    return !equal;
40
41
13.4k
  case YAML_DOCUMENT_START_EVENT:
42
13.4k
    if ((event1->data.document_start.version_directive &&
43
1.17k
         !event2->data.document_start.version_directive) ||
44
13.4k
        (!event1->data.document_start.version_directive &&
45
12.2k
         event2->data.document_start.version_directive) ||
46
13.4k
        (event1->data.document_start.version_directive &&
47
1.17k
         event2->data.document_start.version_directive &&
48
1.17k
         (event1->data.document_start.version_directive->major !=
49
1.17k
              event2->data.document_start.version_directive->major ||
50
1.17k
          event1->data.document_start.version_directive->minor !=
51
1.17k
              event2->data.document_start.version_directive->minor)))
52
0
      return equal;
53
13.4k
    if ((event1->data.document_start.tag_directives.end -
54
13.4k
         event1->data.document_start.tag_directives.start) !=
55
13.4k
        (event2->data.document_start.tag_directives.end -
56
13.4k
         event2->data.document_start.tag_directives.start))
57
0
      return equal;
58
17.8k
    for (int k = 0; k < (event1->data.document_start.tag_directives.end -
59
17.8k
                         event1->data.document_start.tag_directives.start);
60
13.4k
         k++) {
61
4.42k
      if ((strcmp((char *)event1->data.document_start.tag_directives.start[k]
62
4.42k
                      .handle,
63
4.42k
                  (char *)event2->data.document_start.tag_directives.start[k]
64
4.42k
                      .handle) != 0) ||
65
4.42k
          (strcmp((char *)event1->data.document_start.tag_directives.start[k]
66
4.42k
                      .prefix,
67
4.42k
                  (char *)event2->data.document_start.tag_directives.start[k]
68
4.42k
                      .prefix) != 0))
69
0
        return equal;
70
4.42k
    }
71
13.4k
    return !equal;
72
73
13.3k
  case YAML_DOCUMENT_END_EVENT:
74
13.3k
    return !equal;
75
76
14
  case YAML_ALIAS_EVENT:
77
14
    return (strcmp((char *)event1->data.alias.anchor,
78
14
                   (char *)event2->data.alias.anchor) == 0);
79
80
81.8k
  case YAML_SCALAR_EVENT:
81
81.8k
    if ((event1->data.scalar.anchor && !event2->data.scalar.anchor) ||
82
81.8k
        (!event1->data.scalar.anchor && event2->data.scalar.anchor) ||
83
81.8k
        (event1->data.scalar.anchor && event2->data.scalar.anchor &&
84
711
         strcmp((char *)event1->data.scalar.anchor,
85
711
                (char *)event2->data.scalar.anchor) != 0))
86
0
      return equal;
87
81.8k
    if ((event1->data.scalar.tag && !event2->data.scalar.tag &&
88
240
         strcmp((char *)event1->data.scalar.tag, "!") != 0) ||
89
81.8k
        (!event1->data.scalar.tag && event2->data.scalar.tag &&
90
40.6k
         strcmp((char *)event2->data.scalar.tag, "!") != 0) ||
91
81.8k
        (event1->data.scalar.tag && event2->data.scalar.tag &&
92
2.97k
         strcmp((char *)event1->data.scalar.tag,
93
2.97k
                (char *)event2->data.scalar.tag) != 0))
94
19
      return equal;
95
81.8k
    if ((event1->data.scalar.length != event2->data.scalar.length) ||
96
81.8k
        memcmp(event1->data.scalar.value, event2->data.scalar.value,
97
81.8k
               event1->data.scalar.length) != 0)
98
8
      return equal;
99
81.8k
    if ((event1->data.scalar.plain_implicit !=
100
81.8k
         event2->data.scalar.plain_implicit) ||
101
81.7k
        (event1->data.scalar.quoted_implicit !=
102
81.7k
         event2->data.scalar.quoted_implicit))
103
30
      return equal;
104
81.7k
    return !equal;
105
106
45.9k
  case YAML_SEQUENCE_START_EVENT:
107
45.9k
    if ((event1->data.sequence_start.anchor &&
108
259
         !event2->data.sequence_start.anchor) ||
109
45.9k
        (!event1->data.sequence_start.anchor &&
110
45.6k
         event2->data.sequence_start.anchor) ||
111
45.9k
        (event1->data.sequence_start.anchor &&
112
259
         event2->data.sequence_start.anchor &&
113
259
         strcmp((char *)event1->data.sequence_start.anchor,
114
259
                (char *)event2->data.sequence_start.anchor) != 0))
115
0
      return equal;
116
45.9k
    if ((event1->data.sequence_start.tag && !event2->data.sequence_start.tag) ||
117
45.9k
        (!event1->data.sequence_start.tag && event2->data.sequence_start.tag) ||
118
45.9k
        (event1->data.sequence_start.tag && event2->data.sequence_start.tag &&
119
390
         strcmp((char *)event1->data.sequence_start.tag,
120
390
                (char *)event2->data.sequence_start.tag) != 0))
121
2
      return equal;
122
45.9k
    if ((event1->data.sequence_start.implicit !=
123
45.9k
         event2->data.sequence_start.implicit))
124
0
      return equal;
125
45.9k
    return !equal;
126
127
38.0k
  case YAML_MAPPING_START_EVENT:
128
38.0k
    if ((event1->data.mapping_start.anchor &&
129
374
         !event2->data.mapping_start.anchor) ||
130
38.0k
        (!event1->data.mapping_start.anchor &&
131
37.6k
         event2->data.mapping_start.anchor) ||
132
38.0k
        (event1->data.mapping_start.anchor &&
133
374
         event2->data.mapping_start.anchor &&
134
374
         strcmp((char *)event1->data.mapping_start.anchor,
135
374
                (char *)event2->data.mapping_start.anchor) != 0))
136
0
      return equal;
137
38.0k
    if ((event1->data.mapping_start.tag && !event2->data.mapping_start.tag) ||
138
38.0k
        (!event1->data.mapping_start.tag && event2->data.mapping_start.tag) ||
139
38.0k
        (event1->data.mapping_start.tag && event2->data.mapping_start.tag &&
140
611
         strcmp((char *)event1->data.mapping_start.tag,
141
611
                (char *)event2->data.mapping_start.tag) != 0))
142
2
      return equal;
143
38.0k
    if ((event1->data.mapping_start.implicit !=
144
38.0k
         event2->data.mapping_start.implicit))
145
0
      return equal;
146
38.0k
    return !equal;
147
148
85.0k
  default:
149
85.0k
    return !equal;
150
279k
  }
151
279k
}
152
153
508k
bool copy_event(yaml_event_t *event_to, yaml_event_t *event_from) {
154
155
508k
  switch (event_from->type) {
156
9.84k
  case YAML_STREAM_START_EVENT:
157
9.84k
    return yaml_stream_start_event_initialize(
158
9.84k
        event_to, event_from->data.stream_start.encoding);
159
160
1.85k
  case YAML_STREAM_END_EVENT:
161
1.85k
    return yaml_stream_end_event_initialize(event_to);
162
163
23.2k
  case YAML_DOCUMENT_START_EVENT:
164
23.2k
    return yaml_document_start_event_initialize(
165
23.2k
        event_to, event_from->data.document_start.version_directive,
166
23.2k
        event_from->data.document_start.tag_directives.start,
167
23.2k
        event_from->data.document_start.tag_directives.end,
168
23.2k
        event_from->data.document_start.implicit);
169
170
21.0k
  case YAML_DOCUMENT_END_EVENT:
171
21.0k
    return yaml_document_end_event_initialize(
172
21.0k
        event_to, event_from->data.document_end.implicit);
173
174
1.08k
  case YAML_ALIAS_EVENT:
175
1.08k
    return yaml_alias_event_initialize(event_to, event_from->data.alias.anchor);
176
177
167k
  case YAML_SCALAR_EVENT:
178
167k
    return yaml_scalar_event_initialize(
179
167k
        event_to, event_from->data.scalar.anchor, event_from->data.scalar.tag,
180
167k
        event_from->data.scalar.value, event_from->data.scalar.length,
181
167k
        event_from->data.scalar.plain_implicit,
182
167k
        event_from->data.scalar.quoted_implicit, event_from->data.scalar.style);
183
184
85.1k
  case YAML_SEQUENCE_START_EVENT:
185
85.1k
    return yaml_sequence_start_event_initialize(
186
85.1k
        event_to, event_from->data.sequence_start.anchor,
187
85.1k
        event_from->data.sequence_start.tag,
188
85.1k
        event_from->data.sequence_start.implicit,
189
85.1k
        event_from->data.sequence_start.style);
190
191
61.3k
  case YAML_SEQUENCE_END_EVENT:
192
61.3k
    return yaml_sequence_end_event_initialize(event_to);
193
194
88.1k
  case YAML_MAPPING_START_EVENT:
195
88.1k
    return yaml_mapping_start_event_initialize(
196
88.1k
        event_to, event_from->data.mapping_start.anchor,
197
88.1k
        event_from->data.mapping_start.tag,
198
88.1k
        event_from->data.mapping_start.implicit,
199
88.1k
        event_from->data.mapping_start.style);
200
201
49.8k
  case YAML_MAPPING_END_EVENT:
202
49.8k
    return yaml_mapping_end_event_initialize(event_to);
203
508k
  }
204
205
0
  return false;
206
508k
}
207
208
9.98k
int LLVMFuzzerTestOneInput(const uint8_t *data, size_t size) {
209
9.98k
  if (size < 2)
210
1
    return 0;
211
212
9.98k
  yaml_parser_t parser;
213
9.98k
  yaml_emitter_t emitter;
214
9.98k
  yaml_event_t event;
215
9.98k
  yaml_event_t events[MAX_EVENTS];
216
9.98k
  size_t event_number = 0;
217
9.98k
  bool done = false;
218
9.98k
  int count = 0;
219
9.98k
  bool is_canonical = data[0] & 1;
220
9.98k
  bool is_unicode = data[1] & 1;
221
9.98k
  data += 2;
222
9.98k
  size -= 2;
223
224
9.98k
  if (!yaml_parser_initialize(&parser))
225
0
    return 0;
226
227
9.98k
  yaml_parser_set_input_string(&parser, data, size);
228
9.98k
  if (!yaml_emitter_initialize(&emitter)) {
229
0
    yaml_parser_delete(&parser);
230
0
    return 0;
231
0
  }
232
233
9.98k
  yaml_emitter_set_canonical(&emitter, is_canonical);
234
9.98k
  yaml_emitter_set_unicode(&emitter, is_unicode);
235
236
9.98k
  yaml_output_buffer_t out = {/*buf=*/NULL, /*size=*/0, /*capacity=*/1000};
237
9.98k
  yaml_emitter_set_output(&emitter, yaml_write_handler, &out);
238
239
514k
  while (!done) {
240
512k
    if (!yaml_parser_parse(&parser, &event)) {
241
4.13k
      goto delete_parser;
242
4.13k
    }
243
244
508k
    done = (event.type == YAML_STREAM_END_EVENT);
245
508k
    if (event_number >= MAX_EVENTS) {
246
22
      yaml_event_delete(&event);
247
22
      goto delete_parser;
248
22
    }
249
250
508k
    if (!copy_event(&events[event_number], &event)) {
251
43
      yaml_event_delete(&event);
252
43
      goto delete_parser;
253
43
    }
254
508k
    event_number++;
255
256
508k
    if (!yaml_emitter_emit(&emitter, &event)) {
257
3.96k
      goto delete_parser;
258
3.96k
    }
259
260
508k
  }
261
262
1.81k
  yaml_parser_delete(&parser);
263
264
1.81k
  if (!out.buf || out.size == 0)
265
143
    goto error;
266
267
1.67k
  done = false;
268
1.67k
  if (!yaml_parser_initialize(&parser))
269
0
    goto error;
270
271
1.67k
  yaml_parser_set_input_string(&parser, out.buf, out.size);
272
273
280k
  while (!done) {
274
279k
    if (!yaml_parser_parse(&parser, &event))
275
2
      break;
276
277
279k
    done = (event.type == YAML_STREAM_END_EVENT);
278
279k
    if (events_equal(events + count, &event)) {
279
76
      yaml_event_delete(&event);
280
76
      break;
281
76
    }
282
283
279k
    yaml_event_delete(&event);
284
279k
    count++;
285
279k
  }
286
287
9.84k
delete_parser:
288
289
9.84k
  yaml_parser_delete(&parser);
290
291
9.98k
error:
292
293
9.98k
  yaml_emitter_delete(&emitter);
294
295
518k
  for (int k = 0; k < event_number; k++) {
296
508k
    yaml_event_delete(events + k);
297
508k
  }
298
299
9.98k
  free(out.buf);
300
301
9.98k
  return 0;
302
9.84k
}