ares_create_query:
   83|    186|{
   84|    186|  size_t len;
   85|    186|  unsigned char *q;
   86|    186|  const char *p;
   87|    186|  size_t buflen;
   88|    186|  unsigned char *buf;
   89|       |
   90|       |  /* Set our results early, in case we bail out early with an error. */
   91|    186|  *buflenp = 0;
   92|    186|  *bufp = NULL;
   93|       |
   94|       |  /* Per RFC 7686, reject queries for ".onion" domain names with NXDOMAIN. */
   95|    186|  if (ares__is_onion_domain(name))
  ------------------
  |  Branch (95:7): [True: 2, False: 184]
  ------------------
   96|      2|    return ARES_ENOTFOUND;
  ------------------
  |  |  112|      2|#define ARES_ENOTFOUND          4
  ------------------
   97|       |
   98|       |  /* Allocate a memory area for the maximum size this packet might need. +2
   99|       |   * is for the length byte and zero termination if no dots or ecscaping is
  100|       |   * used.
  101|       |   */
  102|    184|  len = strlen(name) + 2 + HFIXEDSZ + QFIXEDSZ +
  103|    184|    (max_udp_size ? EDNSFIXEDSZ : 0);
  ------------------
  |  |  142|    184|#define EDNSFIXEDSZ    11    /* Size of EDNS header */
  ------------------
  |  Branch (103:6): [True: 184, False: 0]
  ------------------
  104|    184|  buf = ares_malloc(len);
  105|    184|  if (!buf)
  ------------------
  |  Branch (105:7): [True: 0, False: 184]
  ------------------
  106|      0|    return ARES_ENOMEM;
  ------------------
  |  |  125|      0|#define ARES_ENOMEM             15
  ------------------
  107|       |
  108|       |  /* Set up the header. */
  109|    184|  q = buf;
  110|    184|  memset(q, 0, HFIXEDSZ);
  111|    184|  DNS_HEADER_SET_QID(q, id);
  ------------------
  |  |   80|    184|#define DNS_HEADER_SET_QID(h, v)      DNS__SET16BIT(h, v)
  |  |  ------------------
  |  |  |  |   48|    184|#define DNS__SET16BIT(p, v)  (((p)[0] = (unsigned char)(((v) >> 8) & 0xff)), \
  |  |  |  |   49|    184|                              ((p)[1] = (unsigned char)((v) & 0xff)))
  |  |  ------------------
  ------------------
  112|    184|  DNS_HEADER_SET_OPCODE(q, O_QUERY);
  ------------------
  |  |   82|    184|#define DNS_HEADER_SET_OPCODE(h, v)   ((h)[2] |= (unsigned char)(((v) & 0xf) << 3))
  ------------------
  113|    184|  if (rd) {
  ------------------
  |  Branch (113:7): [True: 0, False: 184]
  ------------------
  114|      0|    DNS_HEADER_SET_RD(q, 1);
  ------------------
  |  |   85|      0|#define DNS_HEADER_SET_RD(h, v)       ((h)[2] |= (unsigned char)((v) & 0x1))
  ------------------
  115|      0|  }
  116|    184|  else {
  117|    184|    DNS_HEADER_SET_RD(q, 0);
  ------------------
  |  |   85|    184|#define DNS_HEADER_SET_RD(h, v)       ((h)[2] |= (unsigned char)((v) & 0x1))
  ------------------
  118|    184|  }
  119|    184|  DNS_HEADER_SET_QDCOUNT(q, 1);
  ------------------
  |  |   89|    184|#define DNS_HEADER_SET_QDCOUNT(h, v)  DNS__SET16BIT((h) + 4, v)
  |  |  ------------------
  |  |  |  |   48|    184|#define DNS__SET16BIT(p, v)  (((p)[0] = (unsigned char)(((v) >> 8) & 0xff)), \
  |  |  |  |   49|    184|                              ((p)[1] = (unsigned char)((v) & 0xff)))
  |  |  ------------------
  ------------------
  120|       |
  121|    184|  if (max_udp_size) {
  ------------------
  |  Branch (121:7): [True: 184, False: 0]
  ------------------
  122|    184|      DNS_HEADER_SET_ARCOUNT(q, 1);
  ------------------
  |  |   92|    184|#define DNS_HEADER_SET_ARCOUNT(h, v)  DNS__SET16BIT((h) + 10, v)
  |  |  ------------------
  |  |  |  |   48|    184|#define DNS__SET16BIT(p, v)  (((p)[0] = (unsigned char)(((v) >> 8) & 0xff)), \
  |  |  |  |   49|    184|                              ((p)[1] = (unsigned char)((v) & 0xff)))
  |  |  ------------------
  ------------------
  123|    184|  }
  124|       |
  125|       |  /* A name of "." is a screw case for the loop below, so adjust it. */
  126|    184|  if (strcmp(name, ".") == 0)
  ------------------
  |  Branch (126:7): [True: 1, False: 183]
  ------------------
  127|      1|    name++;
  128|       |
  129|       |  /* Start writing out the name after the header. */
  130|    184|  q += HFIXEDSZ;
  131|   909k|  while (*name)
  ------------------
  |  Branch (131:10): [True: 909k, False: 5]
  ------------------
  132|   909k|    {
  133|   909k|      if (*name == '.') {
  ------------------
  |  Branch (133:11): [True: 18, False: 909k]
  ------------------
  134|     18|        ares_free (buf);
  135|     18|        return ARES_EBADNAME;
  ------------------
  |  |  118|     18|#define ARES_EBADNAME           8
  ------------------
  136|     18|      }
  137|       |
  138|       |      /* Count the number of bytes in this label. */
  139|   909k|      len = 0;
  140|  11.5M|      for (p = name; *p && *p != '.'; p++)
  ------------------
  |  Branch (140:22): [True: 11.5M, False: 146]
  |  Branch (140:28): [True: 10.6M, False: 909k]
  ------------------
  141|  10.6M|        {
  142|  10.6M|          if (*p == '\\' && *(p + 1) != 0)
  ------------------
  |  Branch (142:15): [True: 541, False: 10.6M]
  |  Branch (142:29): [True: 538, False: 3]
  ------------------
  143|    538|            p++;
  144|  10.6M|          len++;
  145|  10.6M|        }
  146|   909k|      if (len > MAXLABEL) {
  ------------------
  |  Branch (146:11): [True: 44, False: 909k]
  ------------------
  147|     44|        ares_free (buf);
  148|     44|        return ARES_EBADNAME;
  ------------------
  |  |  118|     44|#define ARES_EBADNAME           8
  ------------------
  149|     44|      }
  150|       |
  151|       |      /* Encode the length and copy the data. */
  152|   909k|      *q++ = (unsigned char)len;
  153|  5.90M|      for (p = name; *p && *p != '.'; p++)
  ------------------
  |  Branch (153:22): [True: 5.90M, False: 117]
  |  Branch (153:28): [True: 4.99M, False: 909k]
  ------------------
  154|  4.99M|        {
  155|  4.99M|          if (*p == '\\' && *(p + 1) != 0)
  ------------------
  |  Branch (155:15): [True: 271, False: 4.99M]
  |  Branch (155:29): [True: 268, False: 3]
  ------------------
  156|    268|            p++;
  157|  4.99M|          *q++ = *p;
  158|  4.99M|        }
  159|       |
  160|       |      /* Go to the next label and repeat, unless we hit the end. */
  161|   909k|      if (!*p)
  ------------------
  |  Branch (161:11): [True: 117, False: 909k]
  ------------------
  162|    117|        break;
  163|   909k|      name = p + 1;
  164|   909k|    }
  165|       |
  166|       |  /* Add the zero-length label at the end. */
  167|    122|  *q++ = 0;
  168|       |
  169|       |  /* Finish off the question with the type and class. */
  170|    122|  DNS_QUESTION_SET_TYPE(q, type);
  ------------------
  |  |   99|    122|#define DNS_QUESTION_SET_TYPE(q, v)     DNS__SET16BIT(q, v)
  |  |  ------------------
  |  |  |  |   48|    122|#define DNS__SET16BIT(p, v)  (((p)[0] = (unsigned char)(((v) >> 8) & 0xff)), \
  |  |  |  |   49|    122|                              ((p)[1] = (unsigned char)((v) & 0xff)))
  |  |  ------------------
  ------------------
  171|    122|  DNS_QUESTION_SET_CLASS(q, dnsclass);
  ------------------
  |  |  100|    122|#define DNS_QUESTION_SET_CLASS(q, v)    DNS__SET16BIT((q) + 2, v)
  |  |  ------------------
  |  |  |  |   48|    122|#define DNS__SET16BIT(p, v)  (((p)[0] = (unsigned char)(((v) >> 8) & 0xff)), \
  |  |  |  |   49|    122|                              ((p)[1] = (unsigned char)((v) & 0xff)))
  |  |  ------------------
  ------------------
  172|       |
  173|    122|  q += QFIXEDSZ;
  174|    122|  if (max_udp_size)
  ------------------
  |  Branch (174:7): [True: 122, False: 0]
  ------------------
  175|    122|  {
  176|    122|      memset(q, 0, EDNSFIXEDSZ);
  ------------------
  |  |  142|    122|#define EDNSFIXEDSZ    11    /* Size of EDNS header */
  ------------------
  177|    122|      q++;
  178|    122|      DNS_RR_SET_TYPE(q, T_OPT);
  ------------------
  |  |  109|    122|#define DNS_RR_SET_TYPE(r, v)           DNS__SET16BIT(r, v)
  |  |  ------------------
  |  |  |  |   48|    122|#define DNS__SET16BIT(p, v)  (((p)[0] = (unsigned char)(((v) >> 8) & 0xff)), \
  |  |  |  |   49|    122|                              ((p)[1] = (unsigned char)((v) & 0xff)))
  |  |  ------------------
  ------------------
  179|    122|      DNS_RR_SET_CLASS(q, max_udp_size);
  ------------------
  |  |  110|    122|#define DNS_RR_SET_CLASS(r, v)          DNS__SET16BIT((r) + 2, v)
  |  |  ------------------
  |  |  |  |   48|    122|#define DNS__SET16BIT(p, v)  (((p)[0] = (unsigned char)(((v) >> 8) & 0xff)), \
  |  |  |  |   49|    122|                              ((p)[1] = (unsigned char)((v) & 0xff)))
  |  |  ------------------
  ------------------
  180|    122|      q += (EDNSFIXEDSZ-1);
  ------------------
  |  |  142|    122|#define EDNSFIXEDSZ    11    /* Size of EDNS header */
  ------------------
  181|    122|  }
  182|    122|  buflen = (q - buf);
  183|       |
  184|       |  /* Reject names that are longer than the maximum of 255 bytes that's
  185|       |   * specified in RFC 1035 ("To simplify implementations, the total length of
  186|       |   * a domain name (i.e., label octets and label length octets) is restricted
  187|       |   * to 255 octets or less."). */
  188|    122|  if (buflen > (size_t)(MAXCDNAME + HFIXEDSZ + QFIXEDSZ +
  ------------------
  |  Branch (188:7): [True: 40, False: 82]
  ------------------
  189|    122|                (max_udp_size ? EDNSFIXEDSZ : 0))) {
  ------------------
  |  |  142|    122|#define EDNSFIXEDSZ    11    /* Size of EDNS header */
  ------------------
  |  Branch (189:18): [True: 122, False: 0]
  ------------------
  190|     40|    ares_free (buf);
  191|     40|    return ARES_EBADNAME;
  ------------------
  |  |  118|     40|#define ARES_EBADNAME           8
  ------------------
  192|     40|  }
  193|       |
  194|       |  /* we know this fits in an int at this point */
  195|     82|  *buflenp = (int) buflen;
  196|     82|  *bufp = buf;
  197|       |
  198|     82|  return ARES_SUCCESS;
  ------------------
  |  |  106|     82|#define ARES_SUCCESS            0
  ------------------
  199|    122|}

ares__is_onion_domain:
  441|    186|{
  442|    186|  if (ares_striendstr(name, ".onion"))
  ------------------
  |  Branch (442:7): [True: 1, False: 185]
  ------------------
  443|      1|    return 1;
  444|       |
  445|    185|  if (ares_striendstr(name, ".onion."))
  ------------------
  |  Branch (445:7): [True: 1, False: 184]
  ------------------
  446|      1|    return 1;
  447|       |
  448|    184|  return 0;
  449|    185|}
ares_getnameinfo.c:ares_striendstr:
  412|    371|{
  413|    371|  const char *c1, *c2, *c1_begin;
  414|    371|  int lo1, lo2;
  415|    371|  size_t s1_len = strlen(s1), s2_len = strlen(s2);
  416|       |
  417|       |  /* If the substr is longer than the full str, it can't match */
  418|    371|  if (s2_len > s1_len)
  ------------------
  |  Branch (418:7): [True: 90, False: 281]
  ------------------
  419|     90|    return NULL;
  420|       |
  421|       |  /* Jump to the end of s1 minus the length of s2 */
  422|    281|  c1_begin = s1+s1_len-s2_len;
  423|    281|  c1 = (const char *)c1_begin;
  424|    281|  c2 = s2;
  425|    356|  while (c2 < s2+s2_len)
  ------------------
  |  Branch (425:10): [True: 354, False: 2]
  ------------------
  426|    354|    {
  427|    354|      lo1 = TOLOWER(*c1);
  ------------------
  |  |  295|    354|#define TOLOWER(x)  (tolower((int)  ((unsigned char)x)))
  ------------------
  428|    354|      lo2 = TOLOWER(*c2);
  ------------------
  |  |  295|    354|#define TOLOWER(x)  (tolower((int)  ((unsigned char)x)))
  ------------------
  429|    354|      if (lo1 != lo2)
  ------------------
  |  Branch (429:11): [True: 279, False: 75]
  ------------------
  430|    279|        return NULL;
  431|     75|      else
  432|     75|        {
  433|     75|          c1++;
  434|     75|          c2++;
  435|     75|        }
  436|    354|    }
  437|      2|  return (char *)c1_begin;
  438|    281|}

ares_library_init.c:default_malloc:
   42|    184|static void *default_malloc(size_t size) { if (size == 0) { return NULL; } return malloc(size); }
  ------------------
  |  Branch (42:48): [True: 0, False: 184]
  ------------------

LLVMFuzzerTestOneInput:
   28|    186|                           unsigned long size) {
   29|       |  // Null terminate the data.
   30|    186|  char *name = malloc(size + 1);
   31|    186|  name[size] = '\0';
   32|    186|  memcpy(name, data, size);
   33|       |
   34|    186|  unsigned char *buf = NULL;
   35|    186|  int buflen = 0;
   36|    186|  ares_create_query(name, C_IN, T_AAAA, 1234, 0, &buf, &buflen, 1024);
   37|    186|  free(buf);
   38|    186|  free(name);
   39|    186|  return 0;
   40|    186|}

