Coverage Report

Created: 2026-09-03 06:20

next uncovered line (L), next uncovered region (R), next uncovered branch (B)
/src/qpdf/fuzz/qpdf_lin_fuzzer.cc
Line
Count
Source
1
#include <qpdf/Buffer.hh>
2
#include <qpdf/BufferInputSource.hh>
3
#include <qpdf/Pl_Discard.hh>
4
#include <qpdf/Pl_Flate.hh>
5
#include <qpdf/QPDF.hh>
6
#include <qpdf/QPDFWriter.hh>
7
#include <qpdf/QUtil.hh>
8
#include <qpdf/global.hh>
9
10
class FuzzHelper
11
{
12
  public:
13
    FuzzHelper(unsigned char const* data, size_t size) :
14
        // We do not modify data, so it is safe to remove the const for Buffer
15
326k
        input_buffer(const_cast<unsigned char*>(data), size)
16
326k
    {
17
326k
    }
18
19
    void
20
    run()
21
216k
    {
22
216k
        qpdf::global::options::fuzz_mode(true);
23
        // The goal here is that you should be able to throw anything at libqpdf and it will respond
24
        // without any memory errors and never do anything worse than throwing a QPDFExc or
25
        // std::runtime_error. Throwing any other kind of exception, segfaulting, or having a memory
26
        // error (when built with appropriate sanitizers) will all cause abnormal exit.
27
216k
        try {
28
216k
            std::cerr << "\ninfo: starting testWrite\n";
29
30
216k
            auto is = std::make_shared<BufferInputSource>("fuzz input", &input_buffer);
31
216k
            QPDF qpdf;
32
216k
            qpdf.processInputSource(is);
33
216k
            QPDFWriter w(qpdf);
34
216k
            w.setOutputPipeline(&discard);
35
216k
            w.setDecodeLevel(qpdf_dl_all);
36
216k
            w.setDeterministicID(true);
37
216k
            w.setObjectStreamMode(qpdf_o_generate);
38
216k
            w.setLinearization(true);
39
216k
            w.write();
40
216k
        } catch (std::runtime_error const& e) {
41
143k
            std::cerr << "runtime_error: " << e.what() << '\n';
42
143k
        }
43
216k
    }
44
45
  private:
46
    Buffer input_buffer;
47
    Pl_Discard discard;
48
};
49
50
extern "C" int
51
LLVMFuzzerTestOneInput(unsigned char const* data, size_t size)
52
326k
{
53
326k
#ifndef _WIN32
54
    // Used by jpeg library to work around false positives in memory sanitizer.
55
326k
    setenv("JSIMD_FORCENONE", "1", 1);
56
326k
#endif
57
326k
    FuzzHelper f(data, size);
58
326k
    f.run();
59
326k
    return 0;
60
326k
}