Coverage Report

Created: 2026-09-23 07:12

next uncovered line (L), next uncovered region (R), next uncovered branch (B)
/src/wt/fuzz/fuzz-http.C
Line
Count
Source
1
/*
2
 * Copyright (C) 2026 Emweb bv, Herent, Belgium.
3
 *
4
 * See the LICENSE file for terms of use.
5
 */
6
7
#include <stdint.h>
8
#include <stddef.h>
9
#include <vector>
10
11
#include "http/RequestParser.h"
12
#include "http/Request.h"
13
14
3.94k
#define kMinInputLength 10
15
1.96k
#define kMaxInputLength 5120
16
17
// Fuzzes the httpd request line/header parser; parse() and validate() do not
18
// use the Server, so it is driven with a null one.
19
1.97k
extern "C" int LLVMFuzzerTestOneInput(const uint8_t *Data, size_t Size) {
20
21
1.97k
    if (Size < kMinInputLength || Size > kMaxInputLength) {
22
23
        return 1;
23
23
    }
24
25
1.94k
    std::vector<char> buf(Data, Data + Size);
26
27
1.94k
    http::server::RequestParser parser(nullptr);
28
1.94k
    http::server::Request req;
29
30
1.94k
    char *begin = &buf[0];
31
1.94k
    char *end = begin + buf.size();
32
33
1.94k
    boost::tribool result;
34
1.94k
    char *next;
35
1.94k
    boost::tie(result, next) = parser.parse(req, begin, end);
36
37
1.94k
    if (result) {
38
1.44k
        parser.validate(req);
39
1.44k
    }
40
41
1.94k
    return 0;
42
1.97k
}