Coverage Report

Created: 2026-08-06 06:25

next uncovered line (L), next uncovered region (R), next uncovered branch (B)
/src/fuzz_list.c
Line
Count
Source
1
/* Copyright 2021 Google LLC
2
Licensed under the Apache License, Version 2.0 (the "License");
3
you may not use this file except in compliance with the License.
4
You may obtain a copy of the License at
5
      http://www.apache.org/licenses/LICENSE-2.0
6
Unless required by applicable law or agreed to in writing, software
7
distributed under the License is distributed on an "AS IS" BASIS,
8
WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
9
See the License for the specific language governing permissions and
10
limitations under the License.
11
*/
12
13
#include "config.h"
14
#include "syshead.h"
15
#include "list.h"
16
17
#include "fuzz_randomizer.h"
18
19
7.03k
#define KEY_SIZE 23
20
21
/* Required for hash_init() */
22
3.24k
static uint32_t word_hash_function(const void *key, uint32_t iv) {
23
3.24k
  return hash_func(key, KEY_SIZE, iv);
24
3.24k
}
25
26
/* Required for hash_init() */
27
305
static bool word_compare_function(const void *key1, const void *key2) {
28
305
  return ((size_t)key1 & 0xFFF) == ((size_t)key1 & 0xFFF);
29
305
}
30
31
518
int LLVMFuzzerTestOneInput(const uint8_t *data, size_t size) {
32
518
  struct gc_arena gc;
33
518
  struct hash *hash = NULL;
34
518
  ssize_t generic_ssizet, generic_ssizet2, num_loops;
35
36
518
  fuzz_random_init(data, size);
37
38
518
  gc = gc_new();
39
40
518
  int total_to_fuzz = fuzz_randomizer_get_int(1, 20);
41
8.87k
  for (int i = 0; i < total_to_fuzz; i++) {
42
8.36k
    generic_ssizet = fuzz_randomizer_get_int(0, 8);
43
44
8.36k
    switch (generic_ssizet) {
45
5.03k
    case 0:
46
5.03k
      if (hash == NULL) {
47
568
        int n_buckets = fuzz_randomizer_get_int(1, 1000);
48
568
        uint32_t iv;
49
50
568
        hash =
51
568
            hash_init(n_buckets, iv, word_hash_function, word_compare_function);
52
568
      }
53
5.03k
      break;
54
113
    case 1:
55
113
      if (hash) {
56
68
        hash_free(hash);
57
68
        hash = NULL;
58
68
      }
59
113
      break;
60
340
    case 2:
61
340
      if (hash) {
62
296
        struct hash_iterator hi;
63
296
        struct hash_element *he;
64
296
        hash_iterator_init(hash, &hi);
65
1.34k
        while ((he = hash_iterator_next(&hi))) {
66
1.05k
          void *w = he->value;
67
1.05k
        }
68
296
        hash_iterator_free(&hi);
69
296
      }
70
340
      break;
71
1.51k
    case 3:
72
1.51k
      if (hash) {
73
1.45k
        void *key;
74
1.45k
        void *value;
75
1.45k
        char arr[KEY_SIZE];
76
1.45k
        memset(arr, 0, KEY_SIZE);
77
1.45k
        fuzz_get_random_data(arr, KEY_SIZE);
78
1.45k
        key = (void *)arr;
79
1.45k
        if (!hash_lookup(hash, key)) {
80
1.34k
          generic_ssizet = fuzz_randomizer_get_int(0, 0xfffffff);
81
1.34k
          value = (void *)generic_ssizet;
82
1.34k
          hash_add(hash, key, value, false);
83
1.34k
        }
84
1.45k
      }
85
1.51k
      break;
86
86
    case 4:
87
86
      if (hash) {
88
48
        hash_n_elements(hash);
89
48
      }
90
86
      break;
91
103
    case 5:
92
103
      if (hash) {
93
47
        hash_n_buckets(hash);
94
47
      }
95
103
      break;
96
120
    case 6:
97
120
      if (hash) {
98
80
        uint32_t hv;
99
80
        generic_ssizet = fuzz_randomizer_get_int(0, 0xfffffff);
100
80
        hv = generic_ssizet;
101
80
        hash_bucket(hash, hv);
102
80
      }
103
120
      break;
104
518
    case 7:
105
518
      if (hash) {
106
441
        void *key;
107
441
        char arr[KEY_SIZE];
108
441
        memset(arr, 0, KEY_SIZE);
109
441
        fuzz_get_random_data(arr, KEY_SIZE);
110
441
        key = (void *)arr;
111
441
        hash_remove(hash, key);
112
441
      }
113
518
      break;
114
531
    case 8:
115
531
      if (hash) {
116
488
        void *value;
117
488
        generic_ssizet = fuzz_randomizer_get_int(0, 0xfffffff);
118
488
        value = (void *)generic_ssizet;
119
488
        hash_remove_by_value(hash, value);
120
488
      }
121
531
    default:
122
531
      break;
123
8.36k
    }
124
8.36k
  }
125
126
518
  if (hash) {
127
500
    hash_free(hash);
128
500
  }
129
130
518
  gc_free(&gc);
131
132
518
  fuzz_random_destroy();
133
134
518
  return 0;
135
518
}