lldpd_alloc_mgmt:
  264|    209|{
  265|    209|	struct lldpd_mgmt *mgmt;
  266|       |
  267|    209|	log_debug("alloc", "allocate a new management address (family: %d)", family);
  268|       |
  269|    209|	if (family <= LLDPD_AF_UNSPEC || family >= LLDPD_AF_LAST) {
  ------------------
  |  Branch (269:6): [True: 0, False: 209]
  |  Branch (269:35): [True: 0, False: 209]
  ------------------
  270|      0|		errno = EAFNOSUPPORT;
  271|      0|		return NULL;
  272|      0|	}
  273|    209|	if (addrsize > LLDPD_MGMT_MAXADDRSIZE) {
  ------------------
  |  |  157|    209|#define LLDPD_MGMT_MAXADDRSIZE 16 /* sizeof(struct in6_addr) */
  ------------------
  |  Branch (273:6): [True: 0, False: 209]
  ------------------
  274|      0|		errno = EOVERFLOW;
  275|      0|		return NULL;
  276|      0|	}
  277|    209|	mgmt = calloc(1, sizeof(struct lldpd_mgmt));
  278|    209|	if (mgmt == NULL) {
  ------------------
  |  Branch (278:6): [True: 0, False: 209]
  ------------------
  279|      0|		errno = ENOMEM;
  280|      0|		return NULL;
  281|      0|	}
  282|    209|	mgmt->m_family = family;
  283|    209|	memcpy(&mgmt->m_addr, addrptr, addrsize);
  284|    209|	mgmt->m_addrsize = addrsize;
  285|    209|	mgmt->m_iface = iface;
  286|    209|	return mgmt;
  287|    209|}

edp_decode:
  220|    372|{
  221|    372|	struct lldpd_chassis *chassis;
  222|    372|	struct lldpd_port *port;
  223|    372|#  ifdef ENABLE_DOT1
  224|    372|	struct lldpd_mgmt *mgmt, *mgmt_next, *m;
  225|    372|	struct lldpd_vlan *lvlan = NULL, *lvlan_next;
  226|    372|#  endif
  227|    372|	const unsigned char edpaddr[] = EDP_MULTICAST_ADDR;
  ------------------
  |  |   22|    372|  {                                    \
  |  |   23|    372|    0x00, 0xe0, 0x2b, 0x00, 0x00, 0x00 \
  |  |   24|    372|  }
  ------------------
  228|    372|	int length, gotend = 0, gotvlans = 0, edp_len, tlv_len, tlv_type;
  229|    372|	int edp_port, edp_slot;
  230|    372|	u_int8_t *pos, *pos_edp, *tlv;
  231|    372|	u_int8_t version[4];
  232|    372|#  ifdef ENABLE_DOT1
  233|    372|	struct in_addr address;
  234|    372|	struct lldpd_port *oport;
  235|    372|#  endif
  236|       |
  237|    372|	log_debug("edp", "decode EDP frame on port %s", hardware->h_ifname);
  238|       |
  239|    372|	if ((chassis = calloc(1, sizeof(struct lldpd_chassis))) == NULL) {
  ------------------
  |  Branch (239:6): [True: 0, False: 372]
  ------------------
  240|      0|		log_warn("edp", "failed to allocate remote chassis");
  241|      0|		return -1;
  242|      0|	}
  243|    372|	TAILQ_INIT(&chassis->c_mgmt);
  244|    372|	if ((port = calloc(1, sizeof(struct lldpd_port))) == NULL) {
  ------------------
  |  Branch (244:6): [True: 0, False: 372]
  ------------------
  245|      0|		log_warn("edp", "failed to allocate remote port");
  246|      0|		free(chassis);
  247|      0|		return -1;
  248|      0|	}
  249|    372|#  ifdef ENABLE_DOT1
  250|    372|	TAILQ_INIT(&port->p_vlans);
  251|    372|#  endif
  252|       |
  253|    372|	length = s;
  254|    372|	pos = (u_int8_t *)frame;
  255|       |
  256|    372|	if (length < 2 * ETHER_ADDR_LEN + sizeof(u_int16_t) + 8 /* LLC */ + 10 +
  ------------------
  |  Branch (256:6): [True: 13, False: 359]
  ------------------
  257|    372|		ETHER_ADDR_LEN /* EDP header */) {
  258|     13|		log_warnx("edp", "too short EDP frame received on %s",
  259|     13|		    hardware->h_ifname);
  260|     13|		goto malformed;
  261|     13|	}
  262|       |
  263|    359|	if (PEEK_CMP(edpaddr, sizeof(edpaddr)) != 0) {
  ------------------
  |  |   80|    359|  (length -= (bytes), pos += (bytes), memcmp(pos - bytes, value, bytes))
  ------------------
  |  Branch (263:6): [True: 53, False: 306]
  ------------------
  264|     53|		log_info("edp",
  265|     53|		    "frame not targeted at EDP multicast address received on %s",
  266|     53|		    hardware->h_ifname);
  267|     53|		goto malformed;
  268|     53|	}
  269|    306|	PEEK_DISCARD(ETHER_ADDR_LEN);
  ------------------
  |  |   72|    306|  do {                      \
  |  |   73|    306|    length -= (bytes);      \
  |  |   74|    306|    pos += (bytes);         \
  |  |   75|    306|  } while (0)
  |  |  ------------------
  |  |  |  Branch (75:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  270|    306|	PEEK_DISCARD_UINT16;
  ------------------
  |  |   77|    306|#define PEEK_DISCARD_UINT16 PEEK_DISCARD(2)
  |  |  ------------------
  |  |  |  |   72|    306|  do {                      \
  |  |  |  |   73|    306|    length -= (bytes);      \
  |  |  |  |   74|    306|    pos += (bytes);         \
  |  |  |  |   75|    306|  } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (75:12): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  271|    306|	PEEK_DISCARD(6); /* LLC: DSAP + SSAP + control + org */
  ------------------
  |  |   72|    306|  do {                      \
  |  |   73|    306|    length -= (bytes);      \
  |  |   74|    306|    pos += (bytes);         \
  |  |   75|    306|  } while (0)
  |  |  ------------------
  |  |  |  Branch (75:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  272|    306|	if (PEEK_UINT16 != LLC_PID_EDP) {
  ------------------
  |  |   63|    306|#define PEEK_UINT16 PEEK(types.f_uint16, ntohs)
  |  |  ------------------
  |  |  |  |   60|    306|  (memcpy(&type, pos, sizeof(type)), length -= sizeof(type), pos += sizeof(type), \
  |  |  |  |   61|    306|      func(type))
  |  |  |  |  ------------------
  |  |  |  |  |  |   63|    306|#define PEEK_UINT16 PEEK(types.f_uint16, ntohs)
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
              	if (PEEK_UINT16 != LLC_PID_EDP) {
  ------------------
  |  |   29|    306|#define LLC_PID_EDP 0x00bb
  ------------------
  |  Branch (272:6): [True: 29, False: 277]
  ------------------
  273|     29|		log_debug("edp", "incorrect LLC protocol ID received on %s",
  274|     29|		    hardware->h_ifname);
  275|     29|		goto malformed;
  276|     29|	}
  277|       |
  278|    277|	(void)PEEK_SAVE(pos_edp); /* Save the start of EDP packet */
  ------------------
  |  |   81|    277|#define PEEK_SAVE POKE_SAVE
  |  |  ------------------
  |  |  |  |   46|    277|#define POKE_SAVE(where) (where = pos, 1)
  |  |  ------------------
  ------------------
  279|    277|	if (PEEK_UINT8 != 1) {
  ------------------
  |  |   62|    277|#define PEEK_UINT8 PEEK(types.f_uint8, )
  |  |  ------------------
  |  |  |  |   60|    277|  (memcpy(&type, pos, sizeof(type)), length -= sizeof(type), pos += sizeof(type), \
  |  |  |  |   61|    277|      func(type))
  |  |  ------------------
  ------------------
  |  Branch (279:6): [True: 9, False: 268]
  ------------------
  280|      9|		log_warnx("edp", "incorrect EDP version for frame received on %s",
  281|      9|		    hardware->h_ifname);
  282|      9|		goto malformed;
  283|      9|	}
  284|    268|	PEEK_DISCARD_UINT8; /* Reserved */
  ------------------
  |  |   76|    268|#define PEEK_DISCARD_UINT8 PEEK_DISCARD(1)
  |  |  ------------------
  |  |  |  |   72|    268|  do {                      \
  |  |  |  |   73|    268|    length -= (bytes);      \
  |  |  |  |   74|    268|    pos += (bytes);         \
  |  |  |  |   75|    268|  } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (75:12): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  285|    268|	edp_len = PEEK_UINT16;
  ------------------
  |  |   63|    268|#define PEEK_UINT16 PEEK(types.f_uint16, ntohs)
  |  |  ------------------
  |  |  |  |   60|    268|  (memcpy(&type, pos, sizeof(type)), length -= sizeof(type), pos += sizeof(type), \
  |  |  |  |   61|    268|      func(type))
  |  |  |  |  ------------------
  |  |  |  |  |  |   63|    268|#define PEEK_UINT16 PEEK(types.f_uint16, ntohs)
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  286|    268|	PEEK_DISCARD_UINT16;	/* Checksum */
  ------------------
  |  |   77|    268|#define PEEK_DISCARD_UINT16 PEEK_DISCARD(2)
  |  |  ------------------
  |  |  |  |   72|    268|  do {                      \
  |  |  |  |   73|    268|    length -= (bytes);      \
  |  |  |  |   74|    268|    pos += (bytes);         \
  |  |  |  |   75|    268|  } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (75:12): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  287|    268|	PEEK_DISCARD_UINT16;	/* Sequence */
  ------------------
  |  |   77|    268|#define PEEK_DISCARD_UINT16 PEEK_DISCARD(2)
  |  |  ------------------
  |  |  |  |   72|    268|  do {                      \
  |  |  |  |   73|    268|    length -= (bytes);      \
  |  |  |  |   74|    268|    pos += (bytes);         \
  |  |  |  |   75|    268|  } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (75:12): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  288|    268|	if (PEEK_UINT16 != 0) { /* ID Type = 0 = MAC */
  ------------------
  |  |   63|    268|#define PEEK_UINT16 PEEK(types.f_uint16, ntohs)
  |  |  ------------------
  |  |  |  |   60|    268|  (memcpy(&type, pos, sizeof(type)), length -= sizeof(type), pos += sizeof(type), \
  |  |  |  |   61|    268|      func(type))
  |  |  |  |  ------------------
  |  |  |  |  |  |   63|    268|#define PEEK_UINT16 PEEK(types.f_uint16, ntohs)
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  |  Branch (288:6): [True: 18, False: 250]
  ------------------
  289|     18|		log_warnx("edp", "incorrect device id type for frame received on %s",
  290|     18|		    hardware->h_ifname);
  291|     18|		goto malformed;
  292|     18|	}
  293|    250|	if (edp_len > length + 10) {
  ------------------
  |  Branch (293:6): [True: 12, False: 238]
  ------------------
  294|     12|		log_warnx("edp", "incorrect size for EDP frame received on %s",
  295|     12|		    hardware->h_ifname);
  296|     12|		goto malformed;
  297|     12|	}
  298|    238|	port->p_ttl = cfg ? cfg->g_config.c_tx_interval * cfg->g_config.c_tx_hold : 0;
  ------------------
  |  Branch (298:16): [True: 238, False: 0]
  ------------------
  299|    238|	port->p_ttl = (port->p_ttl + 999) / 1000;
  300|    238|	chassis->c_id_subtype = LLDP_CHASSISID_SUBTYPE_LLADDR;
  ------------------
  |  |   34|    238|#define LLDP_CHASSISID_SUBTYPE_LLADDR 4
  ------------------
  301|    238|	chassis->c_id_len = ETHER_ADDR_LEN;
  302|    238|	if ((chassis->c_id = (char *)malloc(ETHER_ADDR_LEN)) == NULL) {
  ------------------
  |  Branch (302:6): [True: 0, False: 238]
  ------------------
  303|      0|		log_warn("edp", "unable to allocate memory for chassis ID");
  304|      0|		goto malformed;
  305|      0|	}
  306|    238|	PEEK_BYTES(chassis->c_id, ETHER_ADDR_LEN);
  ------------------
  |  |   66|    238|  do {                           \
  |  |   67|    238|    memcpy(value, pos, bytes);   \
  |  |   68|    238|    length -= (bytes);           \
  |  |   69|    238|    pos += (bytes);              \
  |  |   70|    238|  } while (0)
  |  |  ------------------
  |  |  |  Branch (70:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  307|       |
  308|       |#  ifndef FUZZING_BUILD_MODE_UNSAFE_FOR_PRODUCTION
  309|       |	/* Let's check checksum */
  310|       |	if (frame_checksum(pos_edp, edp_len, 0) != 0) {
  311|       |		log_warnx("edp", "incorrect EDP checksum for frame received on %s",
  312|       |		    hardware->h_ifname);
  313|       |		goto malformed;
  314|       |	}
  315|       |#  endif
  316|       |
  317|  2.55k|	while (length && !gotend) {
  ------------------
  |  Branch (317:9): [True: 2.42k, False: 127]
  |  Branch (317:19): [True: 2.41k, False: 15]
  ------------------
  318|  2.41k|		if (length < 4) {
  ------------------
  |  Branch (318:7): [True: 10, False: 2.40k]
  ------------------
  319|     10|			log_warnx("edp",
  320|     10|			    "EDP TLV header is too large for "
  321|     10|			    "frame received on %s",
  322|     10|			    hardware->h_ifname);
  323|     10|			goto malformed;
  324|     10|		}
  325|  2.40k|		if (PEEK_UINT8 != EDP_TLV_MARKER) {
  ------------------
  |  |   62|  2.40k|#define PEEK_UINT8 PEEK(types.f_uint8, )
  |  |  ------------------
  |  |  |  |   60|  2.40k|  (memcpy(&type, pos, sizeof(type)), length -= sizeof(type), pos += sizeof(type), \
  |  |  |  |   61|  2.40k|      func(type))
  |  |  ------------------
  ------------------
              		if (PEEK_UINT8 != EDP_TLV_MARKER) {
  ------------------
  |  |   31|  2.40k|#define EDP_TLV_MARKER 0x99
  ------------------
  |  Branch (325:7): [True: 25, False: 2.37k]
  ------------------
  326|     25|			log_warnx("edp",
  327|     25|			    "incorrect marker starting EDP TLV header for frame "
  328|     25|			    "received on %s",
  329|     25|			    hardware->h_ifname);
  330|     25|			goto malformed;
  331|     25|		}
  332|  2.37k|		tlv_type = PEEK_UINT8;
  ------------------
  |  |   62|  2.37k|#define PEEK_UINT8 PEEK(types.f_uint8, )
  |  |  ------------------
  |  |  |  |   60|  2.37k|  (memcpy(&type, pos, sizeof(type)), length -= sizeof(type), pos += sizeof(type), \
  |  |  |  |   61|  2.37k|      func(type))
  |  |  ------------------
  ------------------
  333|  2.37k|		tlv_len = PEEK_UINT16 - 4;
  ------------------
  |  |   63|  2.37k|#define PEEK_UINT16 PEEK(types.f_uint16, ntohs)
  |  |  ------------------
  |  |  |  |   60|  2.37k|  (memcpy(&type, pos, sizeof(type)), length -= sizeof(type), pos += sizeof(type), \
  |  |  |  |   61|  2.37k|      func(type))
  |  |  |  |  ------------------
  |  |  |  |  |  |   63|  2.37k|#define PEEK_UINT16 PEEK(types.f_uint16, ntohs)
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  334|  2.37k|		(void)PEEK_SAVE(tlv);
  ------------------
  |  |   81|  2.37k|#define PEEK_SAVE POKE_SAVE
  |  |  ------------------
  |  |  |  |   46|  2.37k|#define POKE_SAVE(where) (where = pos, 1)
  |  |  ------------------
  ------------------
  335|  2.37k|		if ((tlv_len < 0) || (tlv_len > length)) {
  ------------------
  |  Branch (335:7): [True: 5, False: 2.37k]
  |  Branch (335:24): [True: 31, False: 2.34k]
  ------------------
  336|     36|			log_debug("edp",
  337|     36|			    "incorrect size in EDP TLV header for frame "
  338|     36|			    "received on %s",
  339|     36|			    hardware->h_ifname);
  340|       |			/* Some poor old Extreme Summit are quite bogus */
  341|     36|			gotend = 1;
  342|     36|			break;
  343|     36|		}
  344|  2.34k|		switch (tlv_type) {
  345|    116|		case EDP_TLV_INFO:
  ------------------
  |  Branch (345:3): [True: 116, False: 2.22k]
  ------------------
  346|    116|			CHECK_TLV_SIZE(32, "Info");
  ------------------
  |  |  209|    116|    do {                                                           \
  |  |  210|    116|      if (tlv_len < (x)) {                                         \
  |  |  ------------------
  |  |  |  Branch (210:11): [True: 9, False: 107]
  |  |  ------------------
  |  |  211|      9|	log_warnx("edp", name " EDP TLV too short received on %s", \
  |  |  212|      9|	    hardware->h_ifname);                                   \
  |  |  213|      9|	goto malformed;                                            \
  |  |  214|      9|      }                                                            \
  |  |  215|    116|    } while (0)
  |  |  ------------------
  |  |  |  Branch (215:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
  347|    107|			port->p_id_subtype = LLDP_PORTID_SUBTYPE_IFNAME;
  ------------------
  |  |   45|    107|#define LLDP_PORTID_SUBTYPE_IFNAME 5
  ------------------
  348|    107|			edp_slot = PEEK_UINT16;
  ------------------
  |  |   63|    107|#define PEEK_UINT16 PEEK(types.f_uint16, ntohs)
  |  |  ------------------
  |  |  |  |   60|    107|  (memcpy(&type, pos, sizeof(type)), length -= sizeof(type), pos += sizeof(type), \
  |  |  |  |   61|    107|      func(type))
  |  |  |  |  ------------------
  |  |  |  |  |  |   63|    107|#define PEEK_UINT16 PEEK(types.f_uint16, ntohs)
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  349|    107|			edp_port = PEEK_UINT16;
  ------------------
  |  |   63|    107|#define PEEK_UINT16 PEEK(types.f_uint16, ntohs)
  |  |  ------------------
  |  |  |  |   60|    107|  (memcpy(&type, pos, sizeof(type)), length -= sizeof(type), pos += sizeof(type), \
  |  |  |  |   61|    107|      func(type))
  |  |  |  |  ------------------
  |  |  |  |  |  |   63|    107|#define PEEK_UINT16 PEEK(types.f_uint16, ntohs)
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  350|    107|			free(port->p_id);
  351|    107|			port->p_id_len =
  352|    107|			    asprintf(&port->p_id, "%d/%d", edp_slot + 1, edp_port + 1);
  353|    107|			if (port->p_id_len == -1) {
  ------------------
  |  Branch (353:8): [True: 0, False: 107]
  ------------------
  354|      0|				log_warn("edp",
  355|      0|				    "unable to allocate memory for "
  356|      0|				    "port ID");
  357|      0|				goto malformed;
  358|      0|			}
  359|    107|			free(port->p_descr);
  360|    107|			if (asprintf(&port->p_descr, "Slot %d / Port %d", edp_slot + 1,
  ------------------
  |  Branch (360:8): [True: 0, False: 107]
  ------------------
  361|    107|				edp_port + 1) == -1) {
  362|      0|				log_warn("edp",
  363|      0|				    "unable to allocate memory for "
  364|      0|				    "port description");
  365|      0|				goto malformed;
  366|      0|			}
  367|    107|			PEEK_DISCARD_UINT16; /* vchassis */
  ------------------
  |  |   77|    107|#define PEEK_DISCARD_UINT16 PEEK_DISCARD(2)
  |  |  ------------------
  |  |  |  |   72|    107|  do {                      \
  |  |  |  |   73|    107|    length -= (bytes);      \
  |  |  |  |   74|    107|    pos += (bytes);         \
  |  |  |  |   75|    107|  } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (75:12): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  368|    107|			PEEK_DISCARD(6);     /* Reserved */
  ------------------
  |  |   72|    107|  do {                      \
  |  |   73|    107|    length -= (bytes);      \
  |  |   74|    107|    pos += (bytes);         \
  |  |   75|    107|  } while (0)
  |  |  ------------------
  |  |  |  Branch (75:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  369|    107|			PEEK_BYTES(version, 4);
  ------------------
  |  |   66|    107|  do {                           \
  |  |   67|    107|    memcpy(value, pos, bytes);   \
  |  |   68|    107|    length -= (bytes);           \
  |  |   69|    107|    pos += (bytes);              \
  |  |   70|    107|  } while (0)
  |  |  ------------------
  |  |  |  Branch (70:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  370|    107|			free(chassis->c_descr);
  371|    107|			if (asprintf(&chassis->c_descr,
  ------------------
  |  Branch (371:8): [True: 0, False: 107]
  ------------------
  372|    107|				"EDP enabled device, version %d.%d.%d.%d", version[0],
  373|    107|				version[1], version[2], version[3]) == -1) {
  374|      0|				log_warn("edp",
  375|      0|				    "unable to allocate memory for "
  376|      0|				    "chassis description");
  377|      0|				goto malformed;
  378|      0|			}
  379|    107|			break;
  380|    366|		case EDP_TLV_DISPLAY:
  ------------------
  |  Branch (380:3): [True: 366, False: 1.97k]
  ------------------
  381|    366|			free(chassis->c_name);
  382|    366|			if ((chassis->c_name = (char *)calloc(1, tlv_len + 1)) ==
  ------------------
  |  Branch (382:8): [True: 0, False: 366]
  ------------------
  383|    366|			    NULL) {
  384|      0|				log_warn("edp",
  385|      0|				    "unable to allocate memory for chassis "
  386|      0|				    "name");
  387|      0|				goto malformed;
  388|      0|			}
  389|       |			/* TLV display contains a lot of garbage */
  390|    366|			PEEK_BYTES(chassis->c_name, tlv_len);
  ------------------
  |  |   66|    366|  do {                           \
  |  |   67|    366|    memcpy(value, pos, bytes);   \
  |  |   68|    366|    length -= (bytes);           \
  |  |   69|    366|    pos += (bytes);              \
  |  |   70|    366|  } while (0)
  |  |  ------------------
  |  |  |  Branch (70:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  391|    366|			break;
  392|     28|		case EDP_TLV_NULL:
  ------------------
  |  Branch (392:3): [True: 28, False: 2.31k]
  ------------------
  393|     28|			if (tlv_len != 0) {
  ------------------
  |  Branch (393:8): [True: 10, False: 18]
  ------------------
  394|     10|				log_warnx("edp",
  395|     10|				    "null tlv with incorrect size in frame "
  396|     10|				    "received on %s",
  397|     10|				    hardware->h_ifname);
  398|     10|				goto malformed;
  399|     10|			}
  400|     18|			if (length)
  ------------------
  |  Branch (400:8): [True: 15, False: 3]
  ------------------
  401|     15|				log_debug("edp", "extra data after edp frame on %s",
  402|     15|				    hardware->h_ifname);
  403|     18|			gotend = 1;
  404|     18|			break;
  405|    297|		case EDP_TLV_VLAN:
  ------------------
  |  Branch (405:3): [True: 297, False: 2.04k]
  ------------------
  406|    297|#  ifdef ENABLE_DOT1
  407|    297|			CHECK_TLV_SIZE(12, "VLAN");
  ------------------
  |  |  209|    297|    do {                                                           \
  |  |  210|    297|      if (tlv_len < (x)) {                                         \
  |  |  ------------------
  |  |  |  Branch (210:11): [True: 6, False: 291]
  |  |  ------------------
  |  |  211|      6|	log_warnx("edp", name " EDP TLV too short received on %s", \
  |  |  212|      6|	    hardware->h_ifname);                                   \
  |  |  213|      6|	goto malformed;                                            \
  |  |  214|      6|      }                                                            \
  |  |  215|    297|    } while (0)
  |  |  ------------------
  |  |  |  Branch (215:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
  408|    291|			if ((lvlan = (struct lldpd_vlan *)calloc(1,
  ------------------
  |  Branch (408:8): [True: 0, False: 291]
  ------------------
  409|    291|				 sizeof(struct lldpd_vlan))) == NULL) {
  410|      0|				log_warn("edp", "unable to allocate vlan");
  411|      0|				goto malformed;
  412|      0|			}
  413|    291|			PEEK_DISCARD_UINT16;	    /* Flags + reserved */
  ------------------
  |  |   77|    291|#define PEEK_DISCARD_UINT16 PEEK_DISCARD(2)
  |  |  ------------------
  |  |  |  |   72|    291|  do {                      \
  |  |  |  |   73|    291|    length -= (bytes);      \
  |  |  |  |   74|    291|    pos += (bytes);         \
  |  |  |  |   75|    291|  } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (75:12): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  414|    291|			lvlan->v_vid = PEEK_UINT16; /* VID */
  ------------------
  |  |   63|    291|#define PEEK_UINT16 PEEK(types.f_uint16, ntohs)
  |  |  ------------------
  |  |  |  |   60|    291|  (memcpy(&type, pos, sizeof(type)), length -= sizeof(type), pos += sizeof(type), \
  |  |  |  |   61|    291|      func(type))
  |  |  |  |  ------------------
  |  |  |  |  |  |   63|    291|#define PEEK_UINT16 PEEK(types.f_uint16, ntohs)
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  415|    291|			PEEK_DISCARD(4);	    /* Reserved */
  ------------------
  |  |   72|    291|  do {                      \
  |  |   73|    291|    length -= (bytes);      \
  |  |   74|    291|    pos += (bytes);         \
  |  |   75|    291|  } while (0)
  |  |  ------------------
  |  |  |  Branch (75:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  416|    291|			PEEK_BYTES(&address, sizeof(address));
  ------------------
  |  |   66|    291|  do {                           \
  |  |   67|    291|    memcpy(value, pos, bytes);   \
  |  |   68|    291|    length -= (bytes);           \
  |  |   69|    291|    pos += (bytes);              \
  |  |   70|    291|  } while (0)
  |  |  ------------------
  |  |  |  Branch (70:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  417|       |
  418|    291|			if (address.s_addr != INADDR_ANY) {
  ------------------
  |  Branch (418:8): [True: 209, False: 82]
  ------------------
  419|    209|				mgmt = lldpd_alloc_mgmt(LLDPD_AF_IPV4, &address,
  420|    209|				    sizeof(struct in_addr), 0);
  421|    209|				if (mgmt == NULL) {
  ------------------
  |  Branch (421:9): [True: 0, False: 209]
  ------------------
  422|      0|					log_warn("edp", "Out of memory");
  423|      0|					goto malformed;
  424|      0|				}
  425|    209|				TAILQ_INSERT_TAIL(&chassis->c_mgmt, mgmt, m_entries);
  426|    209|			}
  427|       |
  428|    291|			if ((lvlan->v_name = (char *)calloc(1, tlv_len + 1 - 12)) ==
  ------------------
  |  Branch (428:8): [True: 0, False: 291]
  ------------------
  429|    291|			    NULL) {
  430|      0|				log_warn("edp", "unable to allocate vlan name");
  431|      0|				goto malformed;
  432|      0|			}
  433|    291|			PEEK_BYTES(lvlan->v_name, tlv_len - 12);
  ------------------
  |  |   66|    291|  do {                           \
  |  |   67|    291|    memcpy(value, pos, bytes);   \
  |  |   68|    291|    length -= (bytes);           \
  |  |   69|    291|    pos += (bytes);              \
  |  |   70|    291|  } while (0)
  |  |  ------------------
  |  |  |  Branch (70:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  434|       |
  435|    291|			TAILQ_INSERT_TAIL(&port->p_vlans, lvlan, v_entries);
  436|    291|			lvlan = NULL;
  437|    291|#  endif
  438|    291|			gotvlans = 1;
  439|    291|			break;
  440|  1.53k|		default:
  ------------------
  |  Branch (440:3): [True: 1.53k, False: 807]
  ------------------
  441|  1.53k|			log_debug("edp", "unknown EDP TLV type (%d) received on %s",
  442|  1.53k|			    tlv_type, hardware->h_ifname);
  443|  1.53k|			hardware->h_rx_unrecognized_cnt++;
  444|  2.34k|		}
  445|  2.31k|		PEEK_DISCARD(tlv + tlv_len - pos);
  ------------------
  |  |   72|  2.31k|  do {                      \
  |  |   73|  2.31k|    length -= (bytes);      \
  |  |   74|  2.31k|    pos += (bytes);         \
  |  |   75|  2.31k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (75:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  446|  2.31k|	}
  447|    178|	if ((chassis->c_id == NULL) || (port->p_id == NULL) ||
  ------------------
  |  Branch (447:6): [True: 0, False: 178]
  |  Branch (447:33): [True: 158, False: 20]
  ------------------
  448|    178|	    (chassis->c_name == NULL) || (chassis->c_descr == NULL) ||
  ------------------
  |  Branch (448:6): [True: 17, False: 3]
  |  Branch (448:35): [True: 0, False: 3]
  ------------------
  449|    178|	    (port->p_descr == NULL) || (gotend == 0)) {
  ------------------
  |  Branch (449:6): [True: 0, False: 3]
  |  Branch (449:33): [True: 1, False: 2]
  ------------------
  450|    176|#  ifdef ENABLE_DOT1
  451|    176|		if (gotvlans && gotend) {
  ------------------
  |  Branch (451:7): [True: 78, False: 98]
  |  Branch (451:19): [True: 3, False: 75]
  ------------------
  452|       |			/* VLAN can be sent in a separate frames. We need to add
  453|       |			 * those vlans to an existing port */
  454|      3|			TAILQ_FOREACH (oport, &hardware->h_rports, p_entries) {
  455|      0|				if (!((oport->p_protocol == LLDPD_MODE_EDP) &&
  ------------------
  |  |  332|      0|#define LLDPD_MODE_EDP 5
  ------------------
  |  Branch (455:11): [True: 0, False: 0]
  ------------------
  456|      0|					(oport->p_chassis->c_id_subtype ==
  ------------------
  |  Branch (456:6): [True: 0, False: 0]
  ------------------
  457|      0|					    chassis->c_id_subtype) &&
  458|      0|					(oport->p_chassis->c_id_len ==
  ------------------
  |  Branch (458:6): [True: 0, False: 0]
  ------------------
  459|      0|					    chassis->c_id_len) &&
  460|      0|					(memcmp(oport->p_chassis->c_id, chassis->c_id,
  ------------------
  |  Branch (460:6): [True: 0, False: 0]
  ------------------
  461|      0|					     chassis->c_id_len) == 0)))
  462|      0|					continue;
  463|       |				/* We attach the VLANs to the found port */
  464|      0|				lldpd_vlan_cleanup(oport);
  465|      0|				for (lvlan = TAILQ_FIRST(&port->p_vlans); lvlan != NULL;
  ------------------
  |  Branch (465:47): [True: 0, False: 0]
  ------------------
  466|      0|				     lvlan = lvlan_next) {
  467|      0|					lvlan_next = TAILQ_NEXT(lvlan, v_entries);
  468|      0|					TAILQ_REMOVE(&port->p_vlans, lvlan, v_entries);
  469|      0|					TAILQ_INSERT_TAIL(&oport->p_vlans, lvlan,
  470|      0|					    v_entries);
  471|      0|				}
  472|       |				/* And the IP addresses */
  473|      0|				for (mgmt = TAILQ_FIRST(&chassis->c_mgmt); mgmt != NULL;
  ------------------
  |  Branch (473:48): [True: 0, False: 0]
  ------------------
  474|      0|				     mgmt = mgmt_next) {
  475|      0|					mgmt_next = TAILQ_NEXT(mgmt, m_entries);
  476|      0|					TAILQ_REMOVE(&chassis->c_mgmt, mgmt, m_entries);
  477|       |					/* Don't add an address that already exists! */
  478|      0|					TAILQ_FOREACH (m, &chassis->c_mgmt, m_entries)
  479|      0|						if (m->m_family == mgmt->m_family &&
  ------------------
  |  Branch (479:11): [True: 0, False: 0]
  ------------------
  480|      0|						    !memcmp(&m->m_addr, &mgmt->m_addr,
  ------------------
  |  Branch (480:11): [True: 0, False: 0]
  ------------------
  481|      0|							sizeof(m->m_addr)))
  482|      0|							break;
  483|      0|					if (m == NULL)
  ------------------
  |  Branch (483:10): [True: 0, False: 0]
  ------------------
  484|      0|						TAILQ_INSERT_TAIL(
  485|      0|						    &oport->p_chassis->c_mgmt, mgmt,
  486|      0|						    m_entries);
  487|      0|				}
  488|      0|			}
  489|       |			/* We discard the remaining frame */
  490|      3|			goto malformed;
  491|      3|		}
  492|       |#  else
  493|       |		if (gotvlans) goto malformed;
  494|       |#  endif
  495|    173|		log_warnx("edp",
  496|    173|		    "some mandatory tlv are missing for frame received on %s",
  497|    173|		    hardware->h_ifname);
  498|    173|		goto malformed;
  499|    176|	}
  500|      2|	*newchassis = chassis;
  501|      2|	*newport = port;
  502|      2|	return 1;
  503|       |
  504|    370|malformed:
  505|    370|#  ifdef ENABLE_DOT1
  506|    370|	free(lvlan);
  507|    370|#  endif
  508|    370|	lldpd_chassis_cleanup(chassis, 1);
  509|    370|	lldpd_port_cleanup(port, 1);
  510|    370|	free(port);
  511|    370|	return -1;
  512|    178|}

lldpd_chassis_mgmt_cleanup:
   26|    372|{
   27|    372|	struct lldpd_mgmt *mgmt, *mgmt_next;
   28|       |
   29|    372|	log_debug("alloc", "cleanup management addresses for chassis %s",
   30|    372|	    chassis->c_name ? chassis->c_name : "(unknown)");
  ------------------
  |  Branch (30:6): [True: 26, False: 346]
  ------------------
   31|       |
   32|    581|	for (mgmt = TAILQ_FIRST(&chassis->c_mgmt); mgmt != NULL; mgmt = mgmt_next) {
  ------------------
  |  Branch (32:45): [True: 209, False: 372]
  ------------------
   33|    209|		mgmt_next = TAILQ_NEXT(mgmt, m_entries);
   34|    209|		free(mgmt);
   35|    209|	}
   36|    372|	TAILQ_INIT(&chassis->c_mgmt);
   37|    372|}
lldpd_chassis_cleanup:
   41|    372|{
   42|    372|	lldpd_chassis_mgmt_cleanup(chassis);
   43|    372|	log_debug("alloc", "cleanup chassis %s",
   44|    372|	    chassis->c_name ? chassis->c_name : "(unknown)");
  ------------------
  |  Branch (44:6): [True: 26, False: 346]
  ------------------
   45|    372|#ifdef ENABLE_LLDPMED
   46|    372|	free(chassis->c_med_hw);
   47|    372|	free(chassis->c_med_sw);
   48|    372|	free(chassis->c_med_fw);
   49|    372|	free(chassis->c_med_sn);
   50|    372|	free(chassis->c_med_manuf);
   51|    372|	free(chassis->c_med_model);
   52|    372|	free(chassis->c_med_asset);
   53|    372|#endif
   54|    372|	free(chassis->c_id);
   55|    372|	free(chassis->c_name);
   56|    372|	free(chassis->c_descr);
   57|    372|	if (all) free(chassis);
  ------------------
  |  Branch (57:6): [True: 372, False: 0]
  ------------------
   58|    372|}
lldpd_vlan_cleanup:
   63|    372|{
   64|    372|	struct lldpd_vlan *vlan, *vlan_next;
   65|    663|	for (vlan = TAILQ_FIRST(&port->p_vlans); vlan != NULL; vlan = vlan_next) {
  ------------------
  |  Branch (65:43): [True: 291, False: 372]
  ------------------
   66|    291|		free(vlan->v_name);
   67|    291|		vlan_next = TAILQ_NEXT(vlan, v_entries);
   68|    291|		free(vlan);
   69|    291|	}
   70|    372|	TAILQ_INIT(&port->p_vlans);
   71|    372|	port->p_pvid = 0;
   72|    372|}
lldpd_ppvid_cleanup:
   76|    372|{
   77|    372|	struct lldpd_ppvid *ppvid, *ppvid_next;
   78|    372|	for (ppvid = TAILQ_FIRST(&port->p_ppvids); ppvid != NULL; ppvid = ppvid_next) {
  ------------------
  |  Branch (78:45): [True: 0, False: 372]
  ------------------
   79|      0|		ppvid_next = TAILQ_NEXT(ppvid, p_entries);
   80|      0|		free(ppvid);
   81|      0|	}
   82|    372|	TAILQ_INIT(&port->p_ppvids);
   83|    372|}
lldpd_pi_cleanup:
   87|    372|{
   88|    372|	struct lldpd_pi *pi, *pi_next;
   89|    372|	for (pi = TAILQ_FIRST(&port->p_pids); pi != NULL; pi = pi_next) {
  ------------------
  |  Branch (89:40): [True: 0, False: 372]
  ------------------
   90|      0|		free(pi->p_pi);
   91|      0|		pi_next = TAILQ_NEXT(pi, p_entries);
   92|      0|		free(pi);
   93|      0|	}
   94|    372|	TAILQ_INIT(&port->p_pids);
   95|    372|}
lldpd_custom_list_cleanup:
  135|    372|{
  136|    372|	struct lldpd_custom *custom, *custom_next;
  137|    372|	for (custom = TAILQ_FIRST(&port->p_custom_list); custom != NULL;
  ------------------
  |  Branch (137:51): [True: 0, False: 372]
  ------------------
  138|    372|	     custom = custom_next) {
  139|      0|		custom_next = TAILQ_NEXT(custom, next);
  140|      0|		free(custom->oui_info);
  141|      0|		free(custom);
  142|      0|	}
  143|    372|	TAILQ_INIT(&port->p_custom_list);
  144|    372|}
lldpd_port_cleanup:
  190|    372|{
  191|    372|#ifdef ENABLE_LLDPMED
  192|    372|	int i;
  193|    372|	if (all)
  ------------------
  |  Branch (193:6): [True: 372, False: 0]
  ------------------
  194|  1.48k|		for (i = 0; i < LLDP_MED_LOCFORMAT_LAST; i++)
  ------------------
  |  |  292|  1.48k|#define LLDP_MED_LOCFORMAT_LAST LLDP_MED_LOCFORMAT_ELIN
  |  |  ------------------
  |  |  |  |  291|  1.48k|#define LLDP_MED_LOCFORMAT_ELIN 3
  |  |  ------------------
  ------------------
  |  Branch (194:15): [True: 1.11k, False: 372]
  ------------------
  195|  1.11k|			free(port->p_med_location[i].data);
  196|    372|#endif
  197|    372|#ifdef ENABLE_DOT1
  198|    372|	lldpd_vlan_cleanup(port);
  199|    372|	lldpd_ppvid_cleanup(port);
  200|    372|	lldpd_pi_cleanup(port);
  201|    372|#endif
  202|       |	/* will set these to NULL so we don't free wrong memory */
  203|       |
  204|    372|	if (all) {
  ------------------
  |  Branch (204:6): [True: 372, False: 0]
  ------------------
  205|    372|		free(port->p_id);
  206|    372|		port->p_id = NULL;
  207|    372|		free(port->p_descr);
  208|    372|		port->p_descr = NULL;
  209|    372|		free(port->p_lastframe);
  210|    372|		if (port->p_chassis) { /* chassis may not have been attributed, yet */
  ------------------
  |  Branch (210:7): [True: 0, False: 372]
  ------------------
  211|      0|			port->p_chassis->c_refcount--;
  212|      0|			port->p_chassis = NULL;
  213|      0|		}
  214|    372|#ifdef ENABLE_CUSTOM
  215|    372|		lldpd_custom_list_cleanup(port);
  216|    372|#endif
  217|    372|	}
  218|    372|}

log_register:
   63|    372|{
   64|    372|	logh = cb;
   65|    372|}
log_warnx:
  216|    285|{
  217|    285|	va_list ap;
  218|       |
  219|    285|	va_start(ap, emsg);
  220|    285|	vlog(LOG_WARNING, token, emsg, ap);
  221|    285|	va_end(ap);
  222|    285|}
log_info:
  226|     53|{
  227|     53|	va_list ap;
  228|       |
  229|     53|	if (use_syslog || debug > 0 || logh) {
  ------------------
  |  Branch (229:6): [True: 0, False: 53]
  |  Branch (229:20): [True: 0, False: 53]
  |  Branch (229:33): [True: 53, False: 0]
  ------------------
  230|     53|		va_start(ap, emsg);
  231|     53|		vlog(LOG_INFO, token, emsg, ap);
  232|     53|		va_end(ap);
  233|     53|	}
  234|     53|}
log_debug:
  249|  2.94k|{
  250|  2.94k|	va_list ap;
  251|       |
  252|  2.94k|	if ((debug > 1 && log_debug_accept_token(token)) || logh) {
  ------------------
  |  Branch (252:7): [True: 0, False: 2.94k]
  |  Branch (252:20): [True: 0, False: 0]
  |  Branch (252:54): [True: 2.94k, False: 0]
  ------------------
  253|  2.94k|		va_start(ap, emsg);
  254|  2.94k|		vlog(LOG_DEBUG, token, emsg, ap);
  255|  2.94k|		va_end(ap);
  256|  2.94k|	}
  257|  2.94k|}
log.c:vlog:
  153|  3.27k|{
  154|  3.27k|	if (logh) {
  ------------------
  |  Branch (154:6): [True: 3.27k, False: 0]
  ------------------
  155|  3.27k|		char *result = NULL;
  156|  3.27k|		if (vasprintf(&result, fmt, ap) != -1) {
  ------------------
  |  Branch (156:7): [True: 3.27k, False: 0]
  ------------------
  157|  3.27k|			logh(pri, result);
  158|  3.27k|			free(result);
  159|  3.27k|			return;
  160|  3.27k|		}
  161|       |		/* Otherwise, abort. We don't know if "ap" is still OK. We could
  162|       |		 * have made a copy, but this is too much overhead for a
  163|       |		 * situation that shouldn't happen. */
  164|      0|		return;
  165|  3.27k|	}
  166|       |
  167|       |	/* Log to syslog if requested */
  168|      0|	if (use_syslog) {
  ------------------
  |  Branch (168:6): [True: 0, False: 0]
  ------------------
  169|      0|		va_list ap2;
  170|      0|		va_copy(ap2, ap);
  171|      0|		vsyslog(pri, fmt, ap2);
  172|      0|		va_end(ap2);
  173|      0|	}
  174|       |
  175|       |	/* Log to standard error in all cases */
  176|      0|	char *nfmt;
  177|       |	/* best effort in out of mem situations */
  178|      0|	if (asprintf(&nfmt, "%s %s%s%s]%s %s\n", date(), translate(STDERR_FILENO, pri),
  ------------------
  |  Branch (178:6): [True: 0, False: 0]
  ------------------
  179|      0|		token ? "/" : "", token ? token : "",
  180|      0|		isatty(STDERR_FILENO) ? "\033[0m" : "", fmt) == -1) {
  181|      0|		vfprintf(stderr, fmt, ap);
  182|      0|		fprintf(stderr, "\n");
  183|      0|	} else {
  184|      0|		vfprintf(stderr, nfmt, ap);
  185|      0|		free(nfmt);
  186|      0|	}
  187|      0|	fflush(stderr);
  188|      0|}

donothing:
   24|  3.27k|void donothing(int pri, const char *msg) {};
LLVMFuzzerTestOneInput:
   28|    398|{
   29|    398|	if (Size < kMinInputLength || Size > kMaxInputLength) {
  ------------------
  |  |   20|    796|#define kMinInputLength 5
  ------------------
              	if (Size < kMinInputLength || Size > kMaxInputLength) {
  ------------------
  |  |   21|    394|#define kMaxInputLength 2048
  ------------------
  |  Branch (29:6): [True: 4, False: 394]
  |  Branch (29:32): [True: 22, False: 372]
  ------------------
   30|     26|		return 1;
   31|     26|	}
   32|       |
   33|    372|	struct lldpd cfg;
   34|    372|	cfg.g_config.c_mgmt_pattern = NULL;
   35|    372|	cfg.g_config.c_tx_hold = LLDPD_TX_HOLD;
  ------------------
  |  |   68|    372|#define LLDPD_TX_HOLD 4
  ------------------
   36|       |
   37|    372|	struct lldpd_chassis *nchassis = NULL;
   38|    372|	struct lldpd_port *nport = NULL;
   39|    372|	struct lldpd_hardware hardware;
   40|    372|	TAILQ_INIT(&hardware.h_rports);
   41|    372|	log_register(donothing);
   42|       |
   43|    372|	edp_decode(&cfg, (char *)Data, Size, &hardware, &nchassis, &nport);
   44|       |
   45|    372|	if (!nchassis || !nport) {
  ------------------
  |  Branch (45:6): [True: 370, False: 2]
  |  Branch (45:19): [True: 0, False: 2]
  ------------------
   46|    370|		return 1;
   47|    370|	}
   48|       |
   49|      2|	lldpd_port_cleanup(nport, 1);
   50|      2|	free(nport);
   51|      2|	lldpd_chassis_cleanup(nchassis, 1);
   52|       |
   53|      2|	return 0;
   54|    372|}

