Coverage Report

Created: 2026-09-28 06:22

next uncovered line (L), next uncovered region (R), next uncovered branch (B)
/src/open5gs/tests/fuzzing/gtp-message-fuzz.c
Line
Count
Source
1
/*
2
 * Copyright (C) 2019-2023 by Sukchan Lee <acetcom@gmail.com>
3
 *
4
 * This file is part of Open5GS.
5
 *
6
 * This program is free software: you can redistribute it and/or modify
7
 * it under the terms of the GNU Affero General Public License as published by
8
 * the Free Software Foundation, either version 3 of the License, or
9
 * (at your option) any later version.
10
 *
11
 * This program is distributed in the hope that it will be useful,
12
 * but WITHOUT ANY WARRANTY; without even the implied warranty of
13
 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
14
 * GNU General Public License for more details.
15
 *
16
 * You should have received a copy of the GNU General Public License
17
 * along with this program.  If not, see <https://www.gnu.org/licenses/>.
18
 */
19
20
#include <stdio.h>
21
#include <stdint.h>
22
23
#include "fuzzing.h"
24
#include "ogs-gtp.h"
25
26
1.43k
#define kMinInputLength 5
27
712
#define kMaxInputLength 1024
28
690
#define GTP_VERSION(byte) (((byte) >> 5) & 0x07)
29
30
extern int LLVMFuzzerTestOneInput(const uint8_t *Data, size_t Size) 
31
716
{ /* open5gs/tests/non3gpp/gtp-path.c */
32
33
716
    if (Size < kMinInputLength || Size > kMaxInputLength) {
34
26
        return 1;
35
26
    }
36
37
690
    if (!initialized) {
38
1
        initialize();
39
1
        ogs_log_install_domain(&__ogs_gtp_domain, "gtp", OGS_LOG_NONE);
40
1
        ogs_log_install_domain(&__ogs_tlv_domain, "tlv", OGS_LOG_NONE);
41
1
    }
42
43
690
    ogs_pkbuf_t *pkbuf;
44
690
    pkbuf = ogs_pkbuf_alloc(NULL, OGS_MAX_SDU_LEN);
45
46
690
    if (pkbuf == NULL) {
47
0
        return 1;
48
0
    }
49
690
    ogs_pkbuf_put_data(pkbuf, Data, Size);
50
51
690
    if (GTP_VERSION(Data[0]) == OGS_GTP1_VERSION_1) {
52
        /* GTPv1 */
53
362
        ogs_gtp1_message_t gtp1_message;
54
362
        ogs_gtp1_parse_msg(&gtp1_message, pkbuf);
55
362
    } else {
56
        /* GTPv2 */
57
328
        ogs_gtp2_message_t gtp2_message;
58
328
        ogs_gtp2_parse_msg(&gtp2_message, pkbuf);
59
328
    }
60
61
690
    ogs_pkbuf_free(pkbuf);
62
63
690
    return 0;
64
690
}