Coverage Report

Created: 2026-09-04 06:26

next uncovered line (L), next uncovered region (R), next uncovered branch (B)
/src/pupnp/fuzzer/FuzzServiceTable.c
Line
Count
Source
1
#include "service_table.h"
2
3
/* "ixml.h" is not included here on purpose: service_table.h already includes
4
 * it, together with the other headers this target needs (config.h, upnp.h,
5
 * LinkedList.h). */
6
7
#include <stddef.h>
8
#include <stdint.h>
9
#include <stdlib.h>
10
#include <string.h>
11
12
extern int LLVMFuzzerTestOneInput(const uint8_t *Data, size_t Size)
13
3.19k
{
14
/* service_table, getServiceTable() and freeServiceTable() are only declared
15
 * when the device APIs and GENA are compiled in. Without this guard the
16
 * target fails to build on a client-only configuration, for instance
17
 * cmake -DFUZZER=ON -DUPNP_ENABLE_DEVICE_API=OFF. */
18
3.19k
#if defined(INCLUDE_DEVICE_APIS) && EXCLUDE_GENA == 0
19
3.19k
  IXML_Document *doc = NULL;
20
3.19k
  service_table table;
21
3.19k
  char *xml;
22
23
  /* The upper bound is a harness-side safety net only. The input size is
24
   * meant to be driven by the runner, through libFuzzer's -max_len flag:
25
   * on the command line, as in
26
   *     ./FuzzServiceTable corpus/ -max_len=65536
27
   * or, under OSS-Fuzz, through a FuzzServiceTable.options file holding
28
   *     [libfuzzer]
29
   *     max_len = 65536
30
   * Neither is set today, so libFuzzer's own default of 4096 bytes
31
   * applies and the test below never actually fires. */
32
3.19k
  if (Size < 1 || Size > 65536) {
33
0
    return 0;
34
0
  }
35
36
3.19k
  xml = malloc(Size + 1);
37
3.19k
  if (!xml) {
38
0
    return 0;
39
0
  }
40
3.19k
  memcpy(xml, Data, Size);
41
3.19k
  xml[Size] = '\0';
42
43
  /* A control point parses the device description document fetched from a
44
   * device, then builds the service table from it. */
45
3.19k
  if (ixmlParseBufferEx(xml, &doc) == IXML_SUCCESS && doc) {
46
80
    memset(&table, 0, sizeof(table));
47
80
    getServiceTable((IXML_Node *)doc, &table, "http://127.0.0.1/");
48
80
    freeServiceTable(&table);
49
80
    ixmlDocument_free(doc);
50
80
  }
51
52
3.19k
  free(xml);
53
#else
54
  (void)Data;
55
  (void)Size;
56
#endif
57
58
3.19k
  return 0;
59
3.19k
}