Coverage Report

Created: 2026-07-16 06:52

next uncovered line (L), next uncovered region (R), next uncovered branch (B)
/src/xpdf-4.06/build/fuzz_pdfload.cc
Line
Count
Source
1
/*  Copyright 2020 Google Inc.
2
3
Licensed under the Apache License, Version 2.0 (the "License");
4
you may not use this file except in compliance with the License.
5
You may obtain a copy of the License at
6
7
      http://www.apache.org/licenses/LICENSE-2.0
8
9
Unless required by applicable law or agreed to in writing, software
10
distributed under the License is distributed on an "AS IS" BASIS,
11
WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
12
See the License for the specific language governing permissions and
13
limitations under the License.
14
*/
15
#include <fuzzer/FuzzedDataProvider.h>
16
17
#include <vector>
18
#include <aconf.h>
19
#include <stdio.h>
20
#include <stdint.h>
21
#include <stdlib.h>
22
#include <stddef.h>
23
#include <string.h>
24
#include <png.h>
25
26
#include "gmem.h"
27
#include "gmempp.h"
28
#include "parseargs.h"
29
#include "GString.h"
30
#include "gfile.h"
31
#include "GlobalParams.h"
32
#include "Object.h"
33
#include "PDFDoc.h"
34
#include "SplashBitmap.h"
35
#include "Splash.h"
36
#include "SplashOutputDev.h"
37
#include "Stream.h"
38
#include "config.h"
39
#include "JBIG2Stream.h"
40
41
extern "C" int LLVMFuzzerTestOneInput(const uint8_t *data, size_t size)
42
27.7k
{
43
27.7k
    FuzzedDataProvider fdp (data, size);
44
27.7k
    double hdpi = fdp.ConsumeFloatingPoint<double>();
45
27.7k
    double vdpi = fdp.ConsumeFloatingPoint<double>();
46
27.7k
    int rotate = fdp.ConsumeIntegral<int>();
47
27.7k
    bool useMediaBox = fdp.ConsumeBool();
48
27.7k
    bool crop = fdp.ConsumeBool();
49
27.7k
    bool printing = fdp.ConsumeBool();
50
27.7k
    std::vector<char> payload = fdp.ConsumeRemainingBytes<char>();
51
52
27.7k
    Object xpdf_obj;
53
27.7k
    xpdf_obj.initNull();
54
27.7k
    BaseStream *stream = new MemStream(payload.data(), 0, payload.size(), &xpdf_obj);
55
56
27.7k
    Object info, xfa;
57
27.7k
    Object *acroForm;
58
27.7k
    globalParams = new GlobalParams(NULL);
59
27.7k
    globalParams->setErrQuiet(1);
60
27.7k
    globalParams->setupBaseFonts(NULL);
61
27.7k
    char yes[] = "yes";
62
27.7k
    globalParams->setEnableFreeType(yes);  // Yes, it's a string and not a bool.
63
27.7k
    globalParams->setErrQuiet(1);
64
65
27.7k
    PDFDoc *doc = NULL;
66
27.7k
    try {
67
27.7k
      PDFDoc doc(stream);
68
27.7k
        if (doc.isOk() == gTrue)
69
17.7k
        {
70
17.7k
            doc.getNumPages();
71
17.7k
            doc.getOutline();
72
17.7k
            doc.getStructTreeRoot();
73
17.7k
            doc.getXRef();
74
17.7k
            doc.okToPrint(gTrue);
75
17.7k
            doc.okToCopy(gTrue);
76
17.7k
            doc.okToChange(gTrue);
77
17.7k
            doc.okToAddNotes(gTrue);
78
17.7k
            doc.isLinearized();
79
17.7k
            doc.getPDFVersion();
80
81
17.7k
            GString *metadata;
82
17.7k
            if ((metadata = doc.readMetadata())) {
83
1.08k
              (void)metadata->getCString();
84
1.08k
            }
85
17.7k
            delete metadata;
86
87
17.7k
            Object info;
88
17.7k
            doc.getDocInfo(&info);
89
17.7k
            if (info.isDict()) {
90
3.52k
              info.getDict();
91
3.52k
            }
92
17.7k
            info.free();
93
94
17.7k
            if ((acroForm = doc.getCatalog()->getAcroForm())->isDict()) {
95
1.43k
                acroForm->dictLookup("XFA", &xfa);
96
1.43k
                xfa.free();
97
1.43k
            }
98
99
263k
            for (size_t i = 1; i <= doc.getNumPages(); i++) {
100
245k
              doc.getLinks(i);
101
245k
              auto page = doc.getCatalog()->getPage(i);
102
245k
              if (!page->isOk()) {
103
0
                continue;
104
0
              }
105
245k
              page->getResourceDict();
106
245k
              page->getMetadata();
107
245k
              page->getResourceDict();
108
245k
            }
109
110
17.7k
            SplashColor paperColor = {0xff, 0xff, 0xff};
111
17.7k
            SplashOutputDev *splashOut = new SplashOutputDev(splashModeRGB8, 1, gFalse, paperColor);
112
17.7k
            splashOut->setNoComposite(gTrue);
113
17.7k
            splashOut->startDoc(doc.getXRef());
114
263k
            for (size_t i = 1; i <= doc.getNumPages(); ++i) {
115
245k
              doc.displayPage(splashOut, NULL, i, hdpi, vdpi, rotate, useMediaBox, crop, printing);
116
245k
            }
117
17.7k
            (void)splashOut->getBitmap();
118
119
17.7k
            delete splashOut;
120
17.7k
        }
121
27.7k
    } catch (...) {
122
123
140
    }
124
125
27.7k
    delete globalParams;
126
127
27.7k
    return 0;
128
27.7k
}
129