The followings are the branches where fuzzer fails to bypass.
Unique non-covered Complexity | Unique Reachable Complexities | Unique Reachable Functions | All non-covered Complexity | All Reachable Complexity | Function Name | Function Callsite | Blocked Branch |
---|---|---|---|---|---|---|---|
465 | 465 |
2 :
['sshkey_free', 'cert_new'] |
465 | 465 | sshkey_new | call site: 00010 | /src/hpn-ssh/sshkey.c:733 |
225 | 225 |
1 :
['sshkey_free'] |
225 | 225 | sshkey_generate | call site: 00007 | /src/hpn-ssh/sshkey.c:1521 |
165 | 165 |
1 :
['_getentropy_fail'] |
169 | 230 | _rs_stir | call site: 00000 | /src/hpn-ssh/openbsd-compat/arc4random.c:116 |
165 | 165 |
2 :
['sshfatal', 'ERR_get_error'] |
165 | 165 | _ssh_compat_getentropy | call site: 00000 | /src/hpn-ssh/openbsd-compat/bsd-getentropy.c:45 |
158 | 158 |
5 :
['do_log', 'match_pattern_list', 'getpid', 'strlcpy', 'strrchr'] |
158 | 158 | sshlogv | call site: 00031 | /src/hpn-ssh/log.c:469 |
73 | 73 |
2 :
['abort', 'ssh_err'] |
73 | 73 | generate_or_die(int,unsignedint) | call site: 00000 | /src/hpn-ssh/regress/misc/fuzz-harness/sig_fuzz.cc:18 |
13 | 13 |
1 :
['rsa_hash_id_from_keyname'] |
23 | 674 | ssh_rsa_verify | call site: 00000 | /src/hpn-ssh/ssh-rsa.c:504 |
2 | 2 |
1 :
['_exit'] |
2 | 2 | _rs_init | call site: 00000 | /src/hpn-ssh/openbsd-compat/arc4random.c:102 |
2 | 2 |
1 :
['memset'] |
2 | 2 | _rs_forkdetect | call site: 00000 | /src/hpn-ssh/openbsd-compat/./arc4random.h:60 |
2 | 2 |
1 :
['munmap'] |
2 | 2 | _rs_allocate | call site: 00000 | /src/hpn-ssh/openbsd-compat/./arc4random.h:73 |
2 | 2 |
1 :
['BN_clear_free'] |
2 | 2 | sshbuf_get_bignum2 | call site: 00000 | /src/hpn-ssh/sshbuf-getput-crypto.c:48 |
0 | 199 |
1 :
['sshbuf_free'] |
0 | 199 | sshbuf_froms | call site: 00000 | /src/hpn-ssh/sshbuf-getput-basic.c:561 |
LLVMFuzzerTestOneInput
[function]
[call site]
00000
__cxa_guard_acquire
[call site]
00001
generate_or_die(int, unsigned int)
[function]
[call site]
00002
sshkey_generate
[function]
[call site]
00003
sshkey_type_is_cert
[function]
[call site]
00004
sshkey_impl_from_type
[function]
[call site]
00005
sshkey_impl_from_type
[function]
[call site]
00006
sshkey_new
[function]
[call site]
00007
sshkey_impl_from_type
[function]
[call site]
00008
calloc
[call site]
00009
sshkey_is_cert
[function]
[call site]
00010
sshkey_type_is_cert
[function]
[call site]
00011
cert_new
[function]
[call site]
00012
calloc
[call site]
00013
sshbuf_new_label
[function]
[call site]
00014
sshbuf_new_label
[function]
[call site]
00018
sshbuf_new_label
[function]
[call site]
00019
cert_free
[function]
[call site]
00020
sshbuf_free
[function]
[call site]
00021
sshbuf_check_sanity
[function]
[call site]
00022
ssh_signal
[function]
[call site]
00023
memset
[call site]
00024
sigfillset
[call site]
00025
sigaction
[call site]
00026
strsignal
[call site]
00027
__errno_location
[call site]
00028
strerror
[call site]
00029
sshlog
[function]
[call site]
00030
sshlogv
[function]
[call site]
00031
strrchr
[call site]
00032
getpid
[call site]
00033
snprintf
[call site]
00034
match_pattern_list
[function]
[call site]
00035
strlen
[call site]
00036
__ctype_b_loc
[call site]
00037
tolower
[call site]
00038
match_pattern
[function]
[call site]
00039
match_pattern
[function]
[call site]
00040
match_pattern
[function]
[call site]
00041
snprintf
[call site]
00042
snprintf
[call site]
00043
strlcpy
[function]
[call site]
00044
do_log
[function]
[call site]
00045
__errno_location
[call site]
00046
snprintf
[call site]
00047
vsnprintf
[call site]
00048
vsnprintf
[call site]
00049
snprintf
[call site]
00050
strlcpy
[function]
[call site]
00051
strnvis
[function]
[call site]
00052
__ctype_b_loc
[call site]
00053
vis
[function]
[call site]
00054
__ctype_b_loc
[call site]
00055
__ctype_b_loc
[call site]
00056
vis
[function]
[call site]
00057
snprintf
[call site]
00058
strlen
[call site]
00059
write
[call site]
00060
openlog
[call site]
00061
syslog
[call site]
00062
closelog
[call site]
00063
__errno_location
[call site]
00064
raise
[call site]
00065
sshbuf_free
[function]
[call site]
00066
freezero
[function]
[call site]
00067
explicit_bzero
[call site]
00068
freezero
[function]
[call site]
00069
sshbuf_free
[function]
[call site]
00070
sshbuf_free
[function]
[call site]
00071
sshkey_free
[function]
[call site]
00072
sshkey_free_contents
[function]
[call site]
00073
sshkey_impl_from_type
[function]
[call site]
00074
sshkey_is_cert
[function]
[call site]
00075
cert_free
[function]
[call site]
00076
freezero
[function]
[call site]
00077
freezero
[function]
[call site]
00078
sshkey_prekey_free
[function]
[call site]
00079
munmap
[call site]
00080
freezero
[function]
[call site]
00081
sshkey_free
[function]
[call site]
00082
sshkey_free
[function]
[call site]
00083
ssh_err
[function]
[call site]
00084
__errno_location
[call site]
00085
strerror
[call site]
00086
fprintf
[call site]
00087
abort
[call site]
00088
__cxa_guard_release
[call site]
00089
__cxa_guard_acquire
[call site]
00090
generate_or_die(int, unsigned int)
[function]
[call site]
00091
__cxa_guard_release
[call site]
00092
__cxa_guard_acquire
[call site]
00093
generate_or_die(int, unsigned int)
[function]
[call site]
00094
__cxa_guard_release
[call site]
00095
__cxa_guard_acquire
[call site]
00096
generate_or_die(int, unsigned int)
[function]
[call site]
00097
__cxa_guard_release
[call site]
00098
__cxa_guard_acquire
[call site]
00099
generate_or_die(int, unsigned int)
[function]
[call site]
00100
__cxa_guard_release
[call site]
00101
__cxa_guard_acquire
[call site]
00102
strlen
[call site]
00103
__cxa_guard_release
[call site]
00104
sshkey_verify
[function]
[call site]
00105
sshkey_impl_from_key
[function]
[call site]
00106
sshkey_impl_from_type_nid
[function]
[call site]
00107
sshkey_sig_details_free
[function]
[call site]
00108
freezero
[function]
[call site]
00109
sshkey_verify
[function]
[call site]
00110
sshkey_sig_details_free
[function]
[call site]
00111
sshkey_verify
[function]
[call site]
00112
sshkey_sig_details_free
[function]
[call site]
00113
sshkey_verify
[function]
[call site]
00114
sshkey_sig_details_free
[function]
[call site]
00115
sshkey_verify
[function]
[call site]
00116
sshkey_sig_details_free
[function]
[call site]
00117
__cxa_guard_abort
[call site]
00118
__cxa_guard_abort
[call site]
00119
__cxa_guard_abort
[call site]
00120
__cxa_guard_abort
[call site]
00121
__cxa_guard_abort
[call site]
00122