Fuzz introspector: TestFuzzNTLMMessage
For issues and ideas: https://github.com/ossf/fuzz-introspector/issues

Fuzz blockers

The following nodes represent call sites where fuzz blockers occur.

Amount of callsites blocked Calltree index Parent function Callsite Largest blocked function
35 166 WLog_ConsoleAppender_New call site: 00166 WLog_FileAppender_New
14 116 NtCurrentTeb call site: 00116 GetEnvironmentVariableA
14 211 WLog_ParseFilters call site: 00211 WLog_AddStringLogFilters_int
7 78 EnterCriticalSection call site: 00078 log_recursion
7 154 WLog_InitializeRoot call site: 00154 GetEnvironmentVariableA
5 20 WLog_GetLogLevel call site: 00020 _stricmp
5 89 InterlockedDecrement call site: 00089 UnWaitCriticalSection
5 257 winpr_InitializeSSL call site: 00257 WLog_Print_dbg_tag
4 48 unwind_backtrace_callback call site: 00048 WLog_Print_dbg_tag
4 73 GetCurrentThreadId call site: 00073 WaitForCriticalSection
4 227 winpr_atexit call site: 00227 WLog_Print_dbg_tag
4 234 WLog_Uninit_ call site: 00234 WLog_Uninit_

Fuzzer calltree

0 LLVMFuzzerTestOneInput [function] [call site] 00000
1 WLog_GetRoot [function] [call site] 00001
2 winpr_InitOnceExecuteOnce [function] [call site] 00002
3 InterlockedCompareExchangePointer [function] [call site] 00003
4 winpr_int_assert [function] [call site] 00004
5 WLog_Get [function] [call site] 00005
6 WLog_GetRoot [function] [call site] 00006
7 WLog_InitializeRoot [function] [call site] 00007
8 WLog_New [function] [call site] 00008
9 calloc [call site] 00009
9 _strdup [function] [call site] 00010
10 strdup [call site] 00011
10 WLog_Print_dbg_tag [function] [call site] 00012
11 WLog_Get [function] [call site] 00013
12 WLog_Get_int [function] [call site] 00014
13 WLog_FindChild [function] [call site] 00015
14 WLog_Lock [function] [call site] 00016
15 winpr_int_assert [function] [call site] 00017
16 WLog_IsLevelActive [function] [call site] 00018
17 WLog_GetLogLevel [function] [call site] 00019
18 WLog_GetFilterLogLevel [function] [call site] 00020
19 _stricmp [function] [call site] 00021
20 strcasecmp [call site] 00022
19 __assert_fail [call site] 00023
19 _stricmp [function] [call site] 00024
19 __assert_fail [call site] 00025
18 WLog_GetLogLevel [function] [call site] 00026
16 WLog_PrintTextMessage [function] [call site] 00027
17 WLog_PrintTextMessageVA [function] [call site] 00028
18 WLog_PrintTextMessageInternal [function] [call site] 00029
19 __assert_fail [call site] 00030
19 vsnprintf [call site] 00031
19 WLog_Write [function] [call site] 00032
20 WLog_GetLogAppender [function] [call site] 00033
21 WLog_GetLogAppender [function] [call site] 00034
20 WLog_OpenAppender [function] [call site] 00035
21 WLog_GetLogAppender [function] [call site] 00036
20 EnterCriticalSection [function] [call site] 00037
21 winpr_int_assert [function] [call site] 00038
22 winpr_log_backtrace_ex [function] [call site] 00039
23 winpr_backtrace [function] [call site] 00040
24 winpr_unwind_backtrace [function] [call site] 00041
25 calloc [call site] 00042
25 calloc [call site] 00043
25 _Unwind_Backtrace [call site] 00044
25 unwind_backtrace_callback [function] [call site] 00045
26 __assert_fail [call site] 00046
26 _Unwind_GetIP [call site] 00047
26 _Unwind_GetLanguageSpecificData [call site] 00048
25 unwind_reason_str_buffer [function] [call site] 00049
26 unwind_reason_str [function] [call site] 00050
26 snprintf [call site] 00051
25 WLog_Print_dbg_tag [function] [call site] 00052
26 WLog_IsLevelActive [function] [call site] 00053
26 WLog_PrintTextMessageVA [function] [call site] 00054
25 winpr_unwind_backtrace_free [function] [call site] 00055
23 WLog_IsLevelActive [function] [call site] 00056
23 WLog_PrintTextMessage [function] [call site] 00057
23 winpr_backtrace_symbols [function] [call site] 00058
24 WLog_Print_dbg_tag [function] [call site] 00059
24 winpr_unwind_backtrace_symbols [function] [call site] 00060
25 calloc [call site] 00061
25 dladdr [call site] 00062
25 snprintf [call site] 00063
25 snprintf [call site] 00064
23 WLog_IsLevelActive [function] [call site] 00065
23 WLog_PrintTextMessage [function] [call site] 00066
23 winpr_backtrace_free [function] [call site] 00067
24 winpr_unwind_backtrace_free [function] [call site] 00068
22 abort [call site] 00069
21 InterlockedIncrement [function] [call site] 00070
22 winpr_int_assert [function] [call site] 00071
21 GetCurrentThreadId [function] [call site] 00072
22 syscall [call site] 00073
21 WaitForCriticalSection [function] [call site] 00074
22 winpr_int_assert [function] [call site] 00075
22 winpr_int_assert [function] [call site] 00076
22 sem_wait [call site] 00077
21 GetCurrentThreadId [function] [call site] 00078
20 log_recursion [function] [call site] 00079
21 winpr_backtrace [function] [call site] 00080
21 winpr_backtrace_symbols [function] [call site] 00081
21 fprintf [call site] 00082
21 fprintf [call site] 00083
21 fprintf [call site] 00084
21 winpr_backtrace_free [function] [call site] 00085
20 LeaveCriticalSection [function] [call site] 00086
21 winpr_int_assert [function] [call site] 00087
21 InterlockedDecrement [function] [call site] 00088
22 winpr_int_assert [function] [call site] 00089
21 UnWaitCriticalSection [function] [call site] 00090
22 winpr_int_assert [function] [call site] 00091
22 winpr_int_assert [function] [call site] 00092
22 sem_post [call site] 00093
21 InterlockedDecrement [function] [call site] 00094
15 EnterCriticalSection [function] [call site] 00095
14 strcmp [call site] 00096
14 WLog_Unlock [function] [call site] 00097
15 winpr_int_assert [function] [call site] 00098
15 LeaveCriticalSection [function] [call site] 00099
13 WLog_New [function] [call site] 00100
14 WLog_ParseName [function] [call site] 00101
15 strchr [call site] 00102
15 calloc [call site] 00104
15 strchr [call site] 00105
14 GetEnvironmentVariableA [function] [call site] 00106
15 getenv [call site] 00107
15 SetLastError [function] [call site] 00108
16 NtCurrentTeb [function] [call site] 00109
17 pthread_once [call site] 00110
17 sTebInitOnce [function] [call site] 00111
18 pthread_key_create [call site] 00112
18 sTebDestruct [function] [call site] 00113
17 pthread_getspecific [call site] 00114
17 calloc [call site] 00115
17 pthread_setspecific [call site] 00116
15 strlen [call site] 00117
14 GetEnvironmentVariableA [function] [call site] 00118
14 fprintf [call site] 00119
14 WLog_ParseLogLevel [function] [call site] 00120
14 WLog_SetLogLevel [function] [call site] 00128
15 WLog_UpdateInheritLevel [function] [call site] 00129
16 WLog_UpdateInheritLevel [function] [call site] 00130
15 WLog_reset_log_filters [function] [call site] 00131
16 WLog_reset_log_filters [function] [call site] 00132
14 WLog_GetFilterLogLevel [function] [call site] 00133
14 WLog_SetLogLevel [function] [call site] 00134
14 InitializeCriticalSectionAndSpinCount [function] [call site] 00135
15 InitializeCriticalSectionEx [function] [call site] 00136
16 winpr_int_assert [function] [call site] 00137
16 WLog_Print_dbg_tag [function] [call site] 00138
16 sem_init [call site] 00139
16 SetCriticalSectionSpinCount [function] [call site] 00140
17 winpr_int_assert [function] [call site] 00141
14 WLog_Free [function] [call site] 00142
15 WLog_Appender_Free [function] [call site] 00143
16 WLog_Layout_Free [function] [call site] 00144
16 DeleteCriticalSection [function] [call site] 00145
17 winpr_int_assert [function] [call site] 00146
17 sem_destroy [call site] 00147
15 DeleteCriticalSection [function] [call site] 00148
13 WLog_AddChild [function] [call site] 00149
14 WLog_Lock [function] [call site] 00150
14 realloc [call site] 00151
14 WLog_Unlock [function] [call site] 00152
13 WLog_Free [function] [call site] 00153
8 GetEnvironmentVariableA [function] [call site] 00154
8 GetEnvironmentVariableA [function] [call site] 00155
8 fprintf [call site] 00156
8 WLog_SetLogAppenderType [function] [call site] 00162
9 WLog_Appender_Free [function] [call site] 00163
9 WLog_Appender_New [function] [call site] 00164
10 WLog_ConsoleAppender_New [function] [call site] 00165
11 calloc [call site] 00166
10 WLog_FileAppender_New [function] [call site] 00167
11 calloc [call site] 00168
11 GetEnvironmentVariableA [function] [call site] 00169
11 GetEnvironmentVariableA [function] [call site] 00170
11 WLog_FileAppender_SetOutputFilePath [function] [call site] 00171
11 GetEnvironmentVariableA [function] [call site] 00173
11 GetEnvironmentVariableA [function] [call site] 00174
11 WLog_FileAppender_SetOutputFileName [function] [call site] 00175
12 winpr_int_assert [function] [call site] 00176
12 winpr_int_assert [function] [call site] 00177
10 WLog_BinaryAppender_New [function] [call site] 00179
11 calloc [call site] 00180
10 WLog_CallbackAppender_New [function] [call site] 00181
11 calloc [call site] 00182
10 WLog_SyslogAppender_New [function] [call site] 00183
11 calloc [call site] 00184
10 WLog_UdpAppender_New [function] [call site] 00185
11 calloc [call site] 00186
11 _socket [function] [call site] 00187
12 socket [call site] 00188
11 GetEnvironmentVariableA [function] [call site] 00189
11 GetEnvironmentVariableA [function] [call site] 00190
11 WLog_UdpAppender_Open [function] [call site] 00191
12 strchr [call site] 00192
12 winpr_int_assert [function] [call site] 00193
12 getaddrinfo [call site] 00194
12 freeaddrinfo [call site] 00195
12 freeaddrinfo [call site] 00196
11 closesocket [function] [call site] 00198
12 close [call site] 00199
10 fprintf [call site] 00200
10 WLog_ConsoleAppender_New [function] [call site] 00201
10 WLog_Layout_New [function] [call site] 00202
11 calloc [call site] 00203
11 GetEnvironmentVariableA [function] [call site] 00204
11 GetEnvironmentVariableA [function] [call site] 00205
10 WLog_Appender_Free [function] [call site] 00207
10 InitializeCriticalSectionAndSpinCount [function] [call site] 00208
10 WLog_Appender_Free [function] [call site] 00209
8 WLog_ParseFilters [function] [call site] 00210
9 GetEnvironmentVariableA [function] [call site] 00211
9 GetEnvironmentVariableA [function] [call site] 00212
9 WLog_AddStringLogFilters_int [function] [call site] 00213
10 strchr [call site] 00214
10 realloc [call site] 00215
10 strchr [call site] 00217
10 WLog_ParseFilter [function] [call site] 00218
11 strchr [call site] 00219
11 calloc [call site] 00221
11 strrchr [call site] 00222
11 WLog_ParseLogLevel [function] [call site] 00223
11 strchr [call site] 00224
10 WLog_reset_log_filters [function] [call site] 00225
8 winpr_atexit [function] [call site] 00226
9 atexit [call site] 00227
9 __errno_location [call site] 00228
9 winpr_strerror [function] [call site] 00229
10 __xpg_strerror_r [call site] 00230
9 WLog_Print_dbg_tag [function] [call site] 00231
8 WLog_Uninit_ [function] [call site] 00232
8 WLog_Uninit_ [function] [call site] 00235
3 WLog_Print_dbg_tag [function] [call site] 00236
3 Sleep [function] [call site] 00237
4 usleep [call site] 00238
1 WLog_SetLogLevel [function] [call site] 00239
1 fuzz_ntlm_negotiate [function] [call site] 00240
2 fuzz_ntlm_server_init [function] [call site] 00241
3 winpr_int_assert [function] [call site] 00242
3 InitSecurityInterfaceExA [function] [call site] 00243
4 winpr_InitOnceExecuteOnce [function] [call site] 00244
4 InitializeSspiModuleInt [function] [call site] 00245
5 sspi_GlobalInit [function] [call site] 00246
6 winpr_InitOnceExecuteOnce [function] [call site] 00247
6 sspi_init [function] [call site] 00248
7 winpr_InitializeSSL [function] [call site] 00249
8 winpr_InitOnceExecuteOnce [function] [call site] 00250
8 winpr_openssl_initialize [function] [call site] 00251
9 OPENSSL_init_ssl [call site] 00252
9 winpr_atexit [function] [call site] 00253
9 winpr_openssl_cleanup [function] [call site] 00254
10 winpr_CleanupSSL [function] [call site] 00255
11 WLog_Print_dbg_tag [function] [call site] 00256
8 winpr_enable_fips [function] [call site] 00257
9 WLog_Print_dbg_tag [function] [call site] 00258
9 FIPS_mode [call site] 00259
9 FIPS_mode_set [call site] 00260
9 WLog_Print_dbg_tag [function] [call site] 00261
9 WLog_Print_dbg_tag [function] [call site] 00262
7 sspi_ContextBufferAllocTableNew [function] [call site] 00263
8 calloc [call site] 00264
7 SCHANNEL_init [function] [call site] 00265
8 InitializeConstWCharFromUtf8 [function] [call site] 00266
9 winpr_int_assert [function] [call site] 00267
9 winpr_int_assert [function] [call site] 00268
9 ConvertUtf8ToWChar [function] [call site] 00269
10 strlen [call site] 00270
10 ConvertUtf8NToWChar [function] [call site] 00271
11 strnlen [call site] 00272
11 winpr_int_assert [function] [call site] 00273
11 SetLastError [function] [call site] 00274
11 MultiByteToWideChar [function] [call site] 00275
12 int_MultiByteToWideChar [function] [call site] 00276
13 strlen [call site] 00277
13 winpr_int_assert [function] [call site] 00278
13 WLog_Print_dbg_tag [function] [call site] 00279
13 winpr_int_assert [function] [call site] 00280
13 winpr_ConvertUTF8toUTF16 [function] [call site] 00281
14 strnlen [call site] 00282
14 winpr_ConvertUTF8toUTF16_Internal [function] [call site] 00283
15 winpr_int_assert [function] [call site] 00284
15 isLegalUTF8 [function] [call site] 00285
15 setWcharFrom [function] [call site] 00286
15 setWcharFrom [function] [call site] 00287
15 setWcharFrom [function] [call site] 00288
15 setWcharFrom [function] [call site] 00289
15 setWcharFrom [function] [call site] 00290
14 winpr_ConvertUTF8toUTF16_Internal [function] [call site] 00291
14 SetLastError [function] [call site] 00292
14 winpr_int_assert [function] [call site] 00293
8 InitializeConstWCharFromUtf8 [function] [call site] 00294
7 KERBEROS_init [function] [call site] 00295
8 InitializeConstWCharFromUtf8 [function] [call site] 00296
8 InitializeConstWCharFromUtf8 [function] [call site] 00297
7 NTLM_init [function] [call site] 00298
8 InitializeConstWCharFromUtf8 [function] [call site] 00299
8 InitializeConstWCharFromUtf8 [function] [call site] 00300
7 CREDSSP_init [function] [call site] 00301
8 InitializeConstWCharFromUtf8 [function] [call site] 00302
8 InitializeConstWCharFromUtf8 [function] [call site] 00303
7 NEGOTIATE_init [function] [call site] 00304
8 InitializeConstWCharFromUtf8 [function] [call site] 00305
8 InitializeConstWCharFromUtf8 [function] [call site] 00306
7 WINPR_init [function] [call site] 00307
8 InitializeConstWCharFromUtf8 [function] [call site] 00308
6 WLog_Print_dbg_tag [function] [call site] 00309
5 winpr_InitSecurityInterfaceW [function] [call site] 00311
5 winpr_InitSecurityInterfaceA [function] [call site] 00312
4 WLog_IsLevelActive [function] [call site] 00313
4 WLog_PrintTextMessage [function] [call site] 00314
2 fuzz_ntlm_set_input [function] [call site] 00315
3 winpr_int_assert [function] [call site] 00316
3 winpr_int_assert [function] [call site] 00317
2 fuzz_ntlm_server_step [function] [call site] 00318
3 winpr_int_assert [function] [call site] 00319
3 calloc [call site] 00320
3 IsSecurityStatusError [function] [call site] 00321
2 fuzz_ntlm_server_uninit [function] [call site] 00322
1 fuzz_ntlm_challenge [function] [call site] 00323
2 fuzz_ntlm_client_init [function] [call site] 00324
3 winpr_int_assert [function] [call site] 00325
3 InitSecurityInterfaceExA [function] [call site] 00326
3 sspi_SetAuthIdentityA [function] [call site] 00327
4 ConvertUtf8ToWCharAlloc [function] [call site] 00328
5 ConvertUtf8ToWChar [function] [call site] 00329
5 calloc [call site] 00330
5 ConvertUtf8ToWChar [function] [call site] 00331
5 winpr_int_assert [function] [call site] 00332
4 ConvertUtf8ToWCharAlloc [function] [call site] 00333
4 ConvertUtf8ToWCharAlloc [function] [call site] 00334
4 sspi_SetAuthIdentityWithLengthW [function] [call site] 00335
5 winpr_int_assert [function] [call site] 00336
5 copy [function] [call site] 00341
6 winpr_int_assert [function] [call site] 00342
6 winpr_int_assert [function] [call site] 00343
6 calloc [call site] 00344
6 winpr_int_assert [function] [call site] 00345
2 fuzz_ntlm_client_step [function] [call site] 00351
3 winpr_int_assert [function] [call site] 00352
3 IsSecurityStatusError [function] [call site] 00353
2 IsSecurityStatusError [function] [call site] 00354
2 fuzz_ntlm_set_input [function] [call site] 00355
2 fuzz_ntlm_client_step [function] [call site] 00356
2 fuzz_ntlm_client_uninit [function] [call site] 00357
1 fuzz_ntlm_authenticate [function] [call site] 00358
2 fuzz_ntlm_client_init [function] [call site] 00359
2 fuzz_ntlm_server_init [function] [call site] 00360
2 fuzz_ntlm_client_step [function] [call site] 00361
2 fuzz_ntlm_set_input [function] [call site] 00362
2 fuzz_ntlm_server_step [function] [call site] 00363
2 fuzz_ntlm_set_input [function] [call site] 00364
2 fuzz_ntlm_server_step [function] [call site] 00365
2 fuzz_ntlm_client_uninit [function] [call site] 00366
2 fuzz_ntlm_server_uninit [function] [call site] 00367