Coverage Report

Created: 2026-09-18 06:12

next uncovered line (L), next uncovered region (R), next uncovered branch (B)
/src/xmlsec/apps/oss-fuzz/xmlsec_target.c
Line
Count
Source
1
#include <stdint.h>
2
#include <stddef.h>
3
4
#include <xmlsec/buffer.h>
5
#include <xmlsec/parser.h>
6
7
int LLVMFuzzerTestOneInput(const uint8_t* data, size_t size);
8
9
2.43M
static void ignore(void* ctx, const char* msg, ...) {
10
    /* Error handler to avoid spam of error messages from libxml parser. */
11
2.43M
    (void)ctx;
12
2.43M
    (void)msg;
13
2.43M
}
14
15
static int g_initialized = 0;
16
17
20.9k
int LLVMFuzzerTestOneInput(const uint8_t* data, size_t size) {
18
20.9k
    xmlSecBufferPtr buf;
19
20.9k
    xmlDocPtr doc;
20
21
20.9k
    if (!g_initialized) {
22
1
        xmlSetGenericErrorFunc(NULL, &ignore);
23
1
        g_initialized = 1;
24
1
    }
25
    /* A zero-size buffer never allocates data, so xmlSecBufferGetData() would
26
     * return NULL; skip empty inputs like the sibling targets do. */
27
20.9k
    if (size == 0) {
28
0
        return 0;
29
0
    }
30
20.9k
    buf = xmlSecBufferCreate(size);
31
20.9k
    if(buf == NULL) {
32
0
        return 0;
33
0
    }
34
20.9k
    if(xmlSecBufferSetData(buf, data, size) < 0) {
35
0
        xmlSecBufferDestroy(buf);
36
0
        return 0;
37
0
    }
38
20.9k
    doc = xmlSecParseMemory(xmlSecBufferGetData(buf),
39
20.9k
            xmlSecBufferGetSize(buf), 0);
40
41
20.9k
    if (doc != NULL) {
42
79
        xmlFreeDoc(doc);
43
79
    }
44
20.9k
    xmlSecBufferDestroy(buf);
45
20.9k
    return 0;
46
20.9k
}