Coverage Report

Created: 2026-09-03 07:24

next uncovered line (L), next uncovered region (R), next uncovered branch (B)
/src/samba/lib/fuzzing/fuzz_lzxpress_huffman_compress.c
Line
Count
Source
1
/*
2
   Fuzzing for lzxpress_huffman_compress_talloc
3
   Copyright (C) Michael Hanselmann 2019
4
   Copyright (C) Douglas Bagnall 2022 <dbagnall@samba.org>
5
6
   This program is free software; you can redistribute it and/or modify
7
   it under the terms of the GNU General Public License as published by
8
   the Free Software Foundation; either version 3 of the License, or
9
   (at your option) any later version.
10
11
   This program is distributed in the hope that it will be useful,
12
   but WITHOUT ANY WARRANTY; without even the implied warranty of
13
   MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
14
   GNU General Public License for more details.
15
16
   You should have received a copy of the GNU General Public License
17
   along with this program.  If not, see <http://www.gnu.org/licenses/>.
18
*/
19
20
#include "includes.h"
21
#include "fuzzing/fuzzing.h"
22
#include "compression/lzxpress_huffman.h"
23
24
int LLVMFuzzerInitialize(int *argc, char ***argv)
25
377
{
26
377
  return 0;
27
377
}
28
29
30
#define MAX_SIZE (1024 * 1024)
31
32
int LLVMFuzzerTestOneInput(const uint8_t *buf, size_t len)
33
1.99k
{
34
1.99k
  static uint8_t *output;
35
1.99k
  size_t output_len;
36
1.99k
  TALLOC_CTX *mem_ctx = NULL;
37
1.99k
  struct lzxhuff_compressor_mem cmp_mem;
38
39
  /*
40
   * The round-trip fuzzer checks the compressor with an unconstrained
41
   * output buffer; here we see what happens if the buffer is possibly too
42
   * small.
43
   */
44
1.99k
  if (len < 3) {
45
4
    return 0;
46
4
  }
47
1.99k
  output_len = MIN(MAX_SIZE, buf[0] | (buf[1] << 8) | (buf[2] << 16));
48
1.99k
  buf += 3;
49
1.99k
  len -= 3;
50
1.99k
  mem_ctx = talloc_new(NULL);
51
52
1.99k
  output = talloc_array(mem_ctx, uint8_t, output_len);
53
54
1.99k
  lzxpress_huffman_compress(&cmp_mem, buf, len, output, output_len);
55
56
  talloc_free(mem_ctx);
57
1.99k
  return 0;
58
1.99k
}