Fuzz introspector
For issues and ideas: https://github.com/ossf/fuzz-introspector/issues
Report generation date: 2026-09-27

Project overview: mod-auth-openidc

High level conclusions

Reachability and coverage overview

Functions statically reachable by fuzzers
67.0%
1186 / 1767
Cyclomatic complexity statically reachable by fuzzers
72.0%
10089 / 14087
Runtime code coverage of functions
52.0%
918 / 1767

Fuzzers overview

Fuzzer Fuzzer filename Functions Reached Functions unreached Fuzzer depth Files reached Basic blocks reached Cyclomatic complexity Details
fuzz_form_params mod_auth_openidc/test/fuzz/fuzz_form_params.c 174 1907 14 22 1042 593 fuzz_form_params.c
fuzz_base64 mod_auth_openidc/test/fuzz/fuzz_base64.c 168 1913 14 22 866 528 fuzz_base64.c
fuzz_url mod_auth_openidc/test/fuzz/fuzz_url.c 201 1880 14 26 1124 661 fuzz_url.c
fuzz_response_header mod_auth_openidc/test/fuzz/fuzz_response_header.c 165 1916 14 21 919 541 fuzz_response_header.c
fuzz_json mod_auth_openidc/test/fuzz/fuzz_json.c 168 1913 14 21 875 530 fuzz_json.c
fuzz_pem_key mod_auth_openidc/test/fuzz/fuzz_pem_key.c 276 1806 14 25 1967 1082 fuzz_pem_key.c
fuzz_strings mod_auth_openidc/test/fuzz/fuzz_strings.c 243 1839 14 28 1605 886 fuzz_strings.c
fuzz_cookie mod_auth_openidc/test/fuzz/fuzz_cookie.c 299 1782 14 35 2749 1322 fuzz_cookie.c
fuzz_jwks mod_auth_openidc/test/fuzz/fuzz_jwks.c 311 1771 14 24 2808 1414 fuzz_jwks.c
fuzz_metadata mod_auth_openidc/test/fuzz/fuzz_metadata.c 518 1563 14 31 4666 2186 fuzz_metadata.c
fuzz_authz_response mod_auth_openidc/test/fuzz/fuzz_authz_response.c 1121 967 18 65 20178 7944 fuzz_authz_response.c
fuzz_jwt mod_auth_openidc/test/fuzz/fuzz_jwt.c 359 1724 14 30 3797 1817 fuzz_jwt.c
fuzz_discovery_response mod_auth_openidc/test/fuzz/fuzz_discovery_response.c 994 1088 20 60 16056 6473 fuzz_discovery_response.c
fuzz_current_url mod_auth_openidc/test/fuzz/fuzz_current_url.c 205 1877 14 24 1367 743 fuzz_current_url.c
fuzz_bearer_token mod_auth_openidc/test/fuzz/fuzz_bearer_token.c 782 1308 16 51 13967 5628 fuzz_bearer_token.c
fuzz_state_cookie mod_auth_openidc/test/fuzz/fuzz_state_cookie.c 274 1807 14 32 2184 1111 fuzz_state_cookie.c
fuzz_backchannel_logout mod_auth_openidc/test/fuzz/fuzz_backchannel_logout.c 1027 1058 18 61 17643 7017 fuzz_backchannel_logout.c
fuzz_redirect_uri mod_auth_openidc/test/fuzz/fuzz_redirect_uri.c 1196 887 19 71 21752 8542 fuzz_redirect_uri.c
fuzz_post_preserve mod_auth_openidc/test/fuzz/fuzz_post_preserve.c 255 1828 14 30 2112 1064 fuzz_post_preserve.c

Project functions overview

The following table shows data about each function in the project. The functions included in this table correspond to all functions that exist in the executables of the fuzzers. As such, there may be functions that are from third-party libraries.

For further technical details on the meaning of columns in the below table, please see the Glossary .

Func name Functions filename Args Function call depth Reached by Fuzzers Runtime reached by Fuzzers Combined reached by Fuzzers Fuzzers runtime hit Func lines hit % I Count BB Count Cyclomatic complexity Functions reached Reached by functions Accumulated cyclomatic complexity Undiscovered complexity

Fuzzer details

Fuzzer: fuzz_form_params

Call tree

The calltree shows the control flow of the fuzzer. This is overlaid with coverage information to display how much of the potential code a fuzzer can reach is in fact covered at runtime. In the following there is a link to a detailed calltree visualisation as well as a bitmap showing a high-level view of the calltree. For further information about these topics please see the glossary for full calltree and calltree overview

Call tree overview bitmap:

The distribution of callsites in terms of coloring is
Color Runtime hitcount Callsite count Percentage
red 0 265 68.2%
gold [1:9] 96 24.7%
yellow [10:29] 0 0.0%
greenyellow [30:49] 0 0.0%
lawngreen 50+ 27 6.95%
All colors 388 100

Fuzz blockers

The following nodes represent call sites where fuzz blockers occur.

Amount of callsites blocked Calltree index Parent function Callsite Largest blocked function
100 230 _oidc_strstr call site: 00230 oidc_metrics_counter_set_or_update
88 141 oidc_cfg_post_config call site: 00141 oidc_metrics_thread_run
20 36 oidc_cfg_server_alloc call site: 00036 oidc_cfg_server_destroy
8 116 oidc_cache_mutex_global_create call site: 00116 ap_log_error_
5 76 _oidc_strnatcasecmp call site: 00076 _oidc_strnatcasecmp
5 337 oidc_cfg_parse_option call site: 00337 oidc_cfg_parse_options_flatten
5 372 oidc_util_read_form_encoded_params_impl call site: 00372 ap_log_rerror_
4 136 oidc_cache_mutex_global_create call site: 00136 ap_log_error_
4 350 oidc_http_curl_pool_init call site: 00350 oidc_http_curl_pool_cleanup
3 105 oidc_test_crypto_passphrase_derive_keys_cached call site: 00105 oidc_test_key_derive_cached
3 127 oidc_cache_mutex_global_create call site: 00127 ap_log_error_
3 131 oidc_cache_mutex_global_create call site: 00131 ap_log_error_

Runtime coverage analysis

Covered functions
50
Functions that are reachable but not covered
132
Reachable functions
174
Percentage of reachable functions covered
24.14%
NB: The sum of covered functions and functions that are reachable but not covered need not be equal to Reachable functions . This is because the reachability analysis is an approximation and thus at runtime some functions may be covered that are not included in the reachability analysis. This is a limitation of our static analysis capabilities.
Function name source code lines source lines hit percentage hit

Files reached

filename functions hit
mod_auth_openidc/test/fuzz/fuzz_form_params.c 2
mod_auth_openidc/test/util.c 6
mod_auth_openidccfg/cfg.c 9
mod_auth_openidc/test/stub.c 5
mod_auth_openidccfg/provider.c 7
mod_auth_openidcjose/jwk.c 3
cjosejwk.c 1
cjoseutil.c 1
mod_auth_openidccfg/oauth.c 2
mod_auth_openidccfg/cache.c 1
mod_auth_openidccfg/parse.c 5
mod_auth_openidc./const.h 6
mod_auth_openidccfg/dir.c 3
mod_auth_openidcconst.h 2
mod_auth_openidcutil/key.c 1
mod_auth_openidccache/common.c 6
mod_auth_openidcmetrics.c 24
mod_auth_openidcutil/random.c 2
mod_auth_openidcjson.c 10
/usr/include/jansson.h 2
mod_auth_openidchttp.c 5
mod_auth_openidcutil/util.c 3

Fuzzer: fuzz_base64

Call tree

The calltree shows the control flow of the fuzzer. This is overlaid with coverage information to display how much of the potential code a fuzzer can reach is in fact covered at runtime. In the following there is a link to a detailed calltree visualisation as well as a bitmap showing a high-level view of the calltree. For further information about these topics please see the glossary for full calltree and calltree overview

Call tree overview bitmap:

The distribution of callsites in terms of coloring is
Color Runtime hitcount Callsite count Percentage
red 0 258 69.9%
gold [1:9] 98 26.5%
yellow [10:29] 1 0.27%
greenyellow [30:49] 4 1.08%
lawngreen 50+ 8 2.16%
All colors 369 100

Fuzz blockers

The following nodes represent call sites where fuzz blockers occur.

Amount of callsites blocked Calltree index Parent function Callsite Largest blocked function
100 230 _oidc_strstr call site: 00230 oidc_metrics_counter_set_or_update
88 141 oidc_cfg_post_config call site: 00141 oidc_metrics_thread_run
20 36 oidc_cfg_server_alloc call site: 00036 oidc_cfg_server_destroy
8 116 oidc_cache_mutex_global_create call site: 00116 ap_log_error_
5 76 _oidc_strnatcasecmp call site: 00076 _oidc_strnatcasecmp
5 337 oidc_cfg_parse_option call site: 00337 oidc_cfg_parse_options_flatten
4 136 oidc_cache_mutex_global_create call site: 00136 ap_log_error_
4 350 oidc_http_curl_pool_init call site: 00350 oidc_http_curl_pool_cleanup
3 105 oidc_test_crypto_passphrase_derive_keys_cached call site: 00105 oidc_test_key_derive_cached
3 127 oidc_cache_mutex_global_create call site: 00127 ap_log_error_
3 131 oidc_cache_mutex_global_create call site: 00131 ap_log_error_
2 67 oidc_test_request_init call site: 00067 oidc_cfg_provider_authorization_endpoint_url_valid

Runtime coverage analysis

Covered functions
45
Functions that are reachable but not covered
131
Reachable functions
168
Percentage of reachable functions covered
22.02%
NB: The sum of covered functions and functions that are reachable but not covered need not be equal to Reachable functions . This is because the reachability analysis is an approximation and thus at runtime some functions may be covered that are not included in the reachability analysis. This is a limitation of our static analysis capabilities.
Function name source code lines source lines hit percentage hit

Files reached

filename functions hit
mod_auth_openidc/test/fuzz/fuzz_base64.c 2
mod_auth_openidc/test/util.c 5
mod_auth_openidccfg/cfg.c 9
mod_auth_openidc/test/stub.c 3
mod_auth_openidccfg/provider.c 7
mod_auth_openidcjose/jwk.c 3
cjosejwk.c 1
cjoseutil.c 1
mod_auth_openidccfg/oauth.c 2
mod_auth_openidccfg/cache.c 1
mod_auth_openidccfg/parse.c 5
mod_auth_openidc./const.h 6
mod_auth_openidccfg/dir.c 3
mod_auth_openidcconst.h 2
mod_auth_openidcutil/key.c 1
mod_auth_openidccache/common.c 6
mod_auth_openidcmetrics.c 24
mod_auth_openidcutil/random.c 2
mod_auth_openidcjson.c 10
/usr/include/jansson.h 2
mod_auth_openidchttp.c 2
mod_auth_openidcutil/base64.c 2

Fuzzer: fuzz_url

Call tree

The calltree shows the control flow of the fuzzer. This is overlaid with coverage information to display how much of the potential code a fuzzer can reach is in fact covered at runtime. In the following there is a link to a detailed calltree visualisation as well as a bitmap showing a high-level view of the calltree. For further information about these topics please see the glossary for full calltree and calltree overview

Call tree overview bitmap:

The distribution of callsites in terms of coloring is
Color Runtime hitcount Callsite count Percentage
red 0 292 61.8%
gold [1:9] 104 22.0%
yellow [10:29] 7 1.48%
greenyellow [30:49] 2 0.42%
lawngreen 50+ 67 14.1%
All colors 472 100

Fuzz blockers

The following nodes represent call sites where fuzz blockers occur.

Amount of callsites blocked Calltree index Parent function Callsite Largest blocked function
100 230 _oidc_strstr call site: 00230 oidc_metrics_counter_set_or_update
88 141 oidc_cfg_post_config call site: 00141 oidc_metrics_thread_run
20 36 oidc_cfg_server_alloc call site: 00036 oidc_cfg_server_destroy
9 401 oidc_util_regexp_first_match call site: 00401 pcre2_substring_get_bynumber_8
8 116 oidc_cache_mutex_global_create call site: 00116 ap_log_error_
6 431 oidc_util_strcasestr call site: 00431 oidc_http_hdr_in_x_forwarded_host_get
5 76 _oidc_strnatcasecmp call site: 00076 _oidc_strnatcasecmp
5 337 oidc_cfg_parse_option call site: 00337 oidc_cfg_parse_options_flatten
5 419 oidc_validate_redirect_url_host call site: 00419 oidc_http_hdr_forwarded_get
5 425 oidc_http_hdr_in_get call site: 00425 oidc_util_strcasestr
4 136 oidc_cache_mutex_global_create call site: 00136 ap_log_error_
4 350 oidc_http_curl_pool_init call site: 00350 oidc_http_curl_pool_cleanup

Runtime coverage analysis

Covered functions
62
Functions that are reachable but not covered
147
Reachable functions
201
Percentage of reachable functions covered
26.87%
NB: The sum of covered functions and functions that are reachable but not covered need not be equal to Reachable functions . This is because the reachability analysis is an approximation and thus at runtime some functions may be covered that are not included in the reachability analysis. This is a limitation of our static analysis capabilities.
Function name source code lines source lines hit percentage hit

Files reached

filename functions hit
mod_auth_openidc/test/fuzz/fuzz_url.c 2
mod_auth_openidc/test/util.c 7
mod_auth_openidccfg/cfg.c 11
mod_auth_openidc/test/stub.c 5
mod_auth_openidccfg/provider.c 7
mod_auth_openidcjose/jwk.c 3
cjosejwk.c 1
cjoseutil.c 1
mod_auth_openidccfg/oauth.c 2
mod_auth_openidccfg/cache.c 1
mod_auth_openidccfg/parse.c 5
mod_auth_openidc./const.h 6
mod_auth_openidccfg/dir.c 3
mod_auth_openidcconst.h 2
mod_auth_openidcutil/key.c 1
mod_auth_openidccache/common.c 6
mod_auth_openidcmetrics.c 24
mod_auth_openidcutil/random.c 2
mod_auth_openidcjson.c 10
/usr/include/jansson.h 2
mod_auth_openidchttp.c 8
mod_auth_openidcmod_auth_openidc.c 6
mod_auth_openidcutil/expr.c 1
mod_auth_openidcutil/pcre_subst.c 4
mod_auth_openidcutil/url.c 1
mod_auth_openidcutil/util.c 1

Fuzzer: fuzz_response_header

Call tree

The calltree shows the control flow of the fuzzer. This is overlaid with coverage information to display how much of the potential code a fuzzer can reach is in fact covered at runtime. In the following there is a link to a detailed calltree visualisation as well as a bitmap showing a high-level view of the calltree. For further information about these topics please see the glossary for full calltree and calltree overview

Call tree overview bitmap:

The distribution of callsites in terms of coloring is
Color Runtime hitcount Callsite count Percentage
red 0 260 68.6%
gold [1:9] 98 25.8%
yellow [10:29] 0 0.0%
greenyellow [30:49] 0 0.0%
lawngreen 50+ 21 5.54%
All colors 379 100

Fuzz blockers

The following nodes represent call sites where fuzz blockers occur.

Amount of callsites blocked Calltree index Parent function Callsite Largest blocked function
100 230 _oidc_strstr call site: 00230 oidc_metrics_counter_set_or_update
88 141 oidc_cfg_post_config call site: 00141 oidc_metrics_thread_run
20 36 oidc_cfg_server_alloc call site: 00036 oidc_cfg_server_destroy
8 116 oidc_cache_mutex_global_create call site: 00116 ap_log_error_
5 76 _oidc_strnatcasecmp call site: 00076 _oidc_strnatcasecmp
5 337 oidc_cfg_parse_option call site: 00337 oidc_cfg_parse_options_flatten
4 136 oidc_cache_mutex_global_create call site: 00136 ap_log_error_
4 350 oidc_http_curl_pool_init call site: 00350 oidc_http_curl_pool_cleanup
3 105 oidc_test_crypto_passphrase_derive_keys_cached call site: 00105 oidc_test_key_derive_cached
3 127 oidc_cache_mutex_global_create call site: 00127 ap_log_error_
3 131 oidc_cache_mutex_global_create call site: 00131 ap_log_error_
3 371 oidc_http_response_header call site: 00371 fprintf

Runtime coverage analysis

Covered functions
45
Functions that are reachable but not covered
128
Reachable functions
165
Percentage of reachable functions covered
22.42%
NB: The sum of covered functions and functions that are reachable but not covered need not be equal to Reachable functions . This is because the reachability analysis is an approximation and thus at runtime some functions may be covered that are not included in the reachability analysis. This is a limitation of our static analysis capabilities.
Function name source code lines source lines hit percentage hit

Files reached

filename functions hit
mod_auth_openidc/test/fuzz/fuzz_response_header.c 2
mod_auth_openidc/test/util.c 6
mod_auth_openidccfg/cfg.c 9
mod_auth_openidc/test/stub.c 4
mod_auth_openidccfg/provider.c 7
mod_auth_openidcjose/jwk.c 3
cjosejwk.c 1
cjoseutil.c 1
mod_auth_openidccfg/oauth.c 2
mod_auth_openidccfg/cache.c 1
mod_auth_openidccfg/parse.c 5
mod_auth_openidc./const.h 6
mod_auth_openidccfg/dir.c 3
mod_auth_openidcconst.h 2
mod_auth_openidcutil/key.c 1
mod_auth_openidccache/common.c 6
mod_auth_openidcmetrics.c 24
mod_auth_openidcutil/random.c 2
mod_auth_openidcjson.c 10
/usr/include/jansson.h 2
mod_auth_openidchttp.c 3

Fuzzer: fuzz_json

Call tree

The calltree shows the control flow of the fuzzer. This is overlaid with coverage information to display how much of the potential code a fuzzer can reach is in fact covered at runtime. In the following there is a link to a detailed calltree visualisation as well as a bitmap showing a high-level view of the calltree. For further information about these topics please see the glossary for full calltree and calltree overview

Call tree overview bitmap:

The distribution of callsites in terms of coloring is
Color Runtime hitcount Callsite count Percentage
red 0 251 67.2%
gold [1:9] 104 27.8%
yellow [10:29] 0 0.0%
greenyellow [30:49] 0 0.0%
lawngreen 50+ 18 4.82%
All colors 373 100

Fuzz blockers

The following nodes represent call sites where fuzz blockers occur.

Amount of callsites blocked Calltree index Parent function Callsite Largest blocked function
73 230 _oidc_strstr call site: 00230 oidc_metrics_counter_set_or_update
59 141 oidc_cfg_post_config call site: 00141 oidc_metrics_thread_run
26 304 oidc_json_decref call site: 00304 _oidc_metrics_storage_set
23 206 oidc_json_parse call site: 00206 oidc_metrics_store_counters
20 36 oidc_cfg_server_alloc call site: 00036 oidc_cfg_server_destroy
8 116 oidc_cache_mutex_global_create call site: 00116 ap_log_error_
5 76 _oidc_strnatcasecmp call site: 00076 _oidc_strnatcasecmp
5 337 oidc_cfg_parse_option call site: 00337 oidc_cfg_parse_options_flatten
4 136 oidc_cache_mutex_global_create call site: 00136 ap_log_error_
4 350 oidc_http_curl_pool_init call site: 00350 oidc_http_curl_pool_cleanup
3 105 oidc_test_crypto_passphrase_derive_keys_cached call site: 00105 oidc_test_key_derive_cached
3 127 oidc_cache_mutex_global_create call site: 00127 ap_log_error_

Runtime coverage analysis

Covered functions
51
Functions that are reachable but not covered
125
Reachable functions
168
Percentage of reachable functions covered
25.6%
NB: The sum of covered functions and functions that are reachable but not covered need not be equal to Reachable functions . This is because the reachability analysis is an approximation and thus at runtime some functions may be covered that are not included in the reachability analysis. This is a limitation of our static analysis capabilities.
Function name source code lines source lines hit percentage hit

Files reached

filename functions hit
mod_auth_openidc/test/fuzz/fuzz_json.c 2
mod_auth_openidc/test/util.c 6
mod_auth_openidccfg/cfg.c 9
mod_auth_openidc/test/stub.c 4
mod_auth_openidccfg/provider.c 7
mod_auth_openidcjose/jwk.c 3
cjosejwk.c 1
cjoseutil.c 1
mod_auth_openidccfg/oauth.c 2
mod_auth_openidccfg/cache.c 1
mod_auth_openidccfg/parse.c 5
mod_auth_openidc./const.h 6
mod_auth_openidccfg/dir.c 3
mod_auth_openidcconst.h 2
mod_auth_openidcutil/key.c 1
mod_auth_openidccache/common.c 6
mod_auth_openidcmetrics.c 24
mod_auth_openidcutil/random.c 2
mod_auth_openidcjson.c 13
/usr/include/jansson.h 2
mod_auth_openidchttp.c 2

Fuzzer: fuzz_pem_key

Call tree

The calltree shows the control flow of the fuzzer. This is overlaid with coverage information to display how much of the potential code a fuzzer can reach is in fact covered at runtime. In the following there is a link to a detailed calltree visualisation as well as a bitmap showing a high-level view of the calltree. For further information about these topics please see the glossary for full calltree and calltree overview

Call tree overview bitmap:

The distribution of callsites in terms of coloring is
Color Runtime hitcount Callsite count Percentage
red 0 369 50.2%
gold [1:9] 123 16.7%
yellow [10:29] 37 5.04%
greenyellow [30:49] 50 6.81%
lawngreen 50+ 155 21.1%
All colors 734 100

Fuzz blockers

The following nodes represent call sites where fuzz blockers occur.

Amount of callsites blocked Calltree index Parent function Callsite Largest blocked function
88 141 oidc_cfg_post_config call site: 00141 oidc_metrics_thread_run
69 230 _oidc_strstr call site: 00230 oidc_metrics_counter_set_or_update
28 302 oidc_json_encode call site: 00302 _oidc_metrics_storage_set
13 43 cjose_jwk_release call site: 00043 oidc_cfg_oauth_destroy
11 556 cjose_jwk_create_RSA_spec call site: 00556 cjose_err_message
8 116 oidc_cache_mutex_global_create call site: 00116 ap_log_error_
7 491 cjose_base64url_encode call site: 00491 cjose_err_message
7 548 cjose_jwk_create_RSA_spec call site: 00548 BN_bin2bn
5 36 oidc_cfg_server_alloc call site: 00036 oidc_cfg_server_destroy
5 76 _oidc_strnatcasecmp call site: 00076 _oidc_strnatcasecmp
5 701 oidc_jwk_to_json call site: 00701 _oidc_jose_error_set
4 136 oidc_cache_mutex_global_create call site: 00136 ap_log_error_

Runtime coverage analysis

Covered functions
111
Functions that are reachable but not covered
188
Reachable functions
276
Percentage of reachable functions covered
31.88%
NB: The sum of covered functions and functions that are reachable but not covered need not be equal to Reachable functions . This is because the reachability analysis is an approximation and thus at runtime some functions may be covered that are not included in the reachability analysis. This is a limitation of our static analysis capabilities.
Function name source code lines source lines hit percentage hit

Files reached

filename functions hit
mod_auth_openidc/test/fuzz/fuzz_pem_key.c 3
mod_auth_openidc/test/util.c 5
mod_auth_openidccfg/cfg.c 9
mod_auth_openidc/test/stub.c 3
mod_auth_openidccfg/provider.c 7
mod_auth_openidcjose/jwk.c 17
cjosejwk.c 15
cjoseutil.c 3
mod_auth_openidccfg/oauth.c 2
mod_auth_openidccfg/cache.c 1
mod_auth_openidccfg/parse.c 13
mod_auth_openidc./const.h 6
mod_auth_openidccfg/dir.c 3
mod_auth_openidcconst.h 2
mod_auth_openidcutil/key.c 1
mod_auth_openidccache/common.c 6
mod_auth_openidcmetrics.c 24
mod_auth_openidcutil/random.c 2
mod_auth_openidcjson.c 10
/usr/include/jansson.h 4
mod_auth_openidchttp.c 2
mod_auth_openidcutil/base64.c 2
mod_auth_openidcjose.c 3
cjosebase64.c 2
cjoseerror.c 1

Fuzzer: fuzz_strings

Call tree

The calltree shows the control flow of the fuzzer. This is overlaid with coverage information to display how much of the potential code a fuzzer can reach is in fact covered at runtime. In the following there is a link to a detailed calltree visualisation as well as a bitmap showing a high-level view of the calltree. For further information about these topics please see the glossary for full calltree and calltree overview

Call tree overview bitmap:

The distribution of callsites in terms of coloring is
Color Runtime hitcount Callsite count Percentage
red 0 271 47.7%
gold [1:9] 100 17.6%
yellow [10:29] 7 1.23%
greenyellow [30:49] 0 0.0%
lawngreen 50+ 189 33.3%
All colors 567 100

Fuzz blockers

The following nodes represent call sites where fuzz blockers occur.

Amount of callsites blocked Calltree index Parent function Callsite Largest blocked function
73 230 _oidc_strstr call site: 00230 oidc_metrics_counter_set_or_update
59 141 oidc_cfg_post_config call site: 00141 oidc_metrics_thread_run
26 304 oidc_json_decref call site: 00304 _oidc_metrics_storage_set
20 36 oidc_cfg_server_alloc call site: 00036 oidc_cfg_server_destroy
13 216 oidc_json_object_get call site: 00216 oidc_metrics_store_counter_entry
9 206 oidc_json_parse call site: 00206 oidc_metrics_store_counters
8 116 oidc_cache_mutex_global_create call site: 00116 ap_log_error_
5 337 oidc_cfg_parse_option call site: 00337 oidc_cfg_parse_options_flatten
5 487 oidc_http_hdr_in_get call site: 00487 ap_log_rerror_
4 136 oidc_cache_mutex_global_create call site: 00136 ap_log_error_
4 350 oidc_http_curl_pool_init call site: 00350 oidc_http_curl_pool_cleanup
4 502 oidc_jose_hash_bytes call site: 00502 _oidc_jose_error_set

Runtime coverage analysis

Covered functions
96
Functions that are reachable but not covered
155
Reachable functions
243
Percentage of reachable functions covered
36.21%
NB: The sum of covered functions and functions that are reachable but not covered need not be equal to Reachable functions . This is because the reachability analysis is an approximation and thus at runtime some functions may be covered that are not included in the reachability analysis. This is a limitation of our static analysis capabilities.
Function name source code lines source lines hit percentage hit

Files reached

filename functions hit
mod_auth_openidc/test/fuzz/fuzz_strings.c 2
mod_auth_openidc/test/util.c 7
mod_auth_openidccfg/cfg.c 11
mod_auth_openidc/test/stub.c 7
mod_auth_openidccfg/provider.c 7
mod_auth_openidcjose/jwk.c 3
cjosejwk.c 1
cjoseutil.c 1
mod_auth_openidccfg/oauth.c 2
mod_auth_openidccfg/cache.c 1
mod_auth_openidccfg/parse.c 6
mod_auth_openidc./const.h 7
mod_auth_openidccfg/dir.c 3
mod_auth_openidcconst.h 2
mod_auth_openidcutil/key.c 1
mod_auth_openidccache/common.c 6
mod_auth_openidcmetrics.c 24
mod_auth_openidcutil/random.c 2
mod_auth_openidcjson.c 14
/usr/include/jansson.h 2
mod_auth_openidchttp.c 17
mod_auth_openidc/test/fuzz/fuzz.h 1
mod_auth_openidcutil/html.c 5
mod_auth_openidcutil/util.c 10
mod_auth_openidcproto/jwt.c 1
mod_auth_openidcutil/base64.c 3
mod_auth_openidcstate.c 1
mod_auth_openidcjose.c 2

Fuzzer: fuzz_cookie

Call tree

The calltree shows the control flow of the fuzzer. This is overlaid with coverage information to display how much of the potential code a fuzzer can reach is in fact covered at runtime. In the following there is a link to a detailed calltree visualisation as well as a bitmap showing a high-level view of the calltree. For further information about these topics please see the glossary for full calltree and calltree overview

Call tree overview bitmap:

The distribution of callsites in terms of coloring is
Color Runtime hitcount Callsite count Percentage
red 0 417 51.2%
gold [1:9] 93 11.4%
yellow [10:29] 3 0.36%
greenyellow [30:49] 3 0.36%
lawngreen 50+ 297 36.5%
All colors 813 100

Fuzz blockers

The following nodes represent call sites where fuzz blockers occur.

Amount of callsites blocked Calltree index Parent function Callsite Largest blocked function
61 242 oidc_json_integer_value call site: 00242 oidc_metrics_counter_set_or_update
50 150 _oidc_str_to_int_checked call site: 00150 oidc_metrics_thread_run
43 478 _oidc_jose_error_set call site: 00478 oidc_jwk_set_or_generate_kid
26 304 oidc_json_decref call site: 00304 _oidc_metrics_storage_set
15 726 oidc_util_url_cur_is_secure call site: 00726 oidc_http_hdr_forwarded_get
13 43 cjose_jwk_release call site: 00043 oidc_cfg_oauth_destroy
13 216 oidc_json_object_get call site: 00216 oidc_metrics_store_counter_entry
11 230 _oidc_strstr call site: 00230 oidc_metrics_counter_set_or_update
11 660 oidc_alg2kty call site: 00660 cjose_jwe_decrypt
9 206 oidc_json_parse call site: 00206 oidc_metrics_store_counters
9 606 _cjose_header_validate_crit call site: 00606 cjose_err_message
8 116 oidc_cache_mutex_global_create call site: 00116 ap_log_error_

Runtime coverage analysis

Covered functions
139
Functions that are reachable but not covered
172
Reachable functions
299
Percentage of reachable functions covered
42.47%
NB: The sum of covered functions and functions that are reachable but not covered need not be equal to Reachable functions . This is because the reachability analysis is an approximation and thus at runtime some functions may be covered that are not included in the reachability analysis. This is a limitation of our static analysis capabilities.
Function name source code lines source lines hit percentage hit

Files reached

filename functions hit
mod_auth_openidc/test/fuzz/fuzz_cookie.c 2
mod_auth_openidc/test/util.c 7
mod_auth_openidccfg/cfg.c 16
mod_auth_openidc/test/stub.c 5
mod_auth_openidccfg/provider.c 7
mod_auth_openidcjose/jwk.c 6
cjosejwk.c 6
cjoseutil.c 5
mod_auth_openidccfg/oauth.c 2
mod_auth_openidccfg/cache.c 1
mod_auth_openidccfg/parse.c 5
mod_auth_openidc./const.h 7
mod_auth_openidccfg/dir.c 5
mod_auth_openidcconst.h 2
mod_auth_openidcutil/key.c 1
mod_auth_openidccache/common.c 6
mod_auth_openidcmetrics.c 24
mod_auth_openidcutil/random.c 2
mod_auth_openidcjson.c 14
/usr/include/jansson.h 2
mod_auth_openidchttp.c 18
mod_auth_openidcutil/util.c 3
mod_auth_openidcstate.c 5
mod_auth_openidcproto/state.c 5
mod_auth_openidcutil/jwt.c 2
mod_auth_openidcproto/jwt.c 1
mod_auth_openidcutil/base64.c 2
cjoseerror.c 1
mod_auth_openidcjose.c 6
cjosebase64.c 4
mod_auth_openidcjose/jwe.c 4
cjosejwe.c 13
cjoseheader.c 3
mod_auth_openidcjose/jws.c 1
mod_auth_openidcutil/url.c 2

Fuzzer: fuzz_jwks

Call tree

The calltree shows the control flow of the fuzzer. This is overlaid with coverage information to display how much of the potential code a fuzzer can reach is in fact covered at runtime. In the following there is a link to a detailed calltree visualisation as well as a bitmap showing a high-level view of the calltree. For further information about these topics please see the glossary for full calltree and calltree overview

Call tree overview bitmap:

The distribution of callsites in terms of coloring is
Color Runtime hitcount Callsite count Percentage
red 0 433 46.3%
gold [1:9] 183 19.5%
yellow [10:29] 15 1.60%
greenyellow [30:49] 7 0.74%
lawngreen 50+ 296 31.6%
All colors 934 100

Fuzz blockers

The following nodes represent call sites where fuzz blockers occur.

Amount of callsites blocked Calltree index Parent function Callsite Largest blocked function
69 230 _oidc_strstr call site: 00230 oidc_metrics_counter_set_or_update
59 141 oidc_cfg_post_config call site: 00141 oidc_metrics_thread_run
32 780 _oidc_jwk_rsa_key_to_jwk call site: 00780 _oidc_jwk_ec_key_to_jwk
31 593 _cjose_jwk_import_OKP call site: 00593 cjose_jwk_create_OKP_spec
26 304 oidc_json_decref call site: 00304 _oidc_metrics_storage_set
23 206 oidc_json_parse call site: 00206 oidc_metrics_store_counters
13 43 cjose_jwk_release call site: 00043 oidc_cfg_oauth_destroy
8 116 oidc_cache_mutex_global_create call site: 00116 ap_log_error_
5 76 _oidc_strnatcasecmp call site: 00076 _oidc_strnatcasecmp
5 337 oidc_cfg_parse_option call site: 00337 oidc_cfg_parse_options_flatten
4 136 oidc_cache_mutex_global_create call site: 00136 ap_log_error_
4 350 oidc_http_curl_pool_init call site: 00350 oidc_http_curl_pool_cleanup

Runtime coverage analysis

Covered functions
138
Functions that are reachable but not covered
196
Reachable functions
311
Percentage of reachable functions covered
36.98%
NB: The sum of covered functions and functions that are reachable but not covered need not be equal to Reachable functions . This is because the reachability analysis is an approximation and thus at runtime some functions may be covered that are not included in the reachability analysis. This is a limitation of our static analysis capabilities.
Function name source code lines source lines hit percentage hit

Files reached

filename functions hit
mod_auth_openidc/test/fuzz/fuzz_jwks.c 3
mod_auth_openidc/test/util.c 6
mod_auth_openidccfg/cfg.c 9
mod_auth_openidc/test/stub.c 4
mod_auth_openidccfg/provider.c 7
mod_auth_openidcjose/jwk.c 26
cjosejwk.c 35
cjoseutil.c 6
mod_auth_openidccfg/oauth.c 2
mod_auth_openidccfg/cache.c 1
mod_auth_openidccfg/parse.c 5
mod_auth_openidc./const.h 6
mod_auth_openidccfg/dir.c 3
mod_auth_openidcconst.h 2
mod_auth_openidcutil/key.c 1
mod_auth_openidccache/common.c 6
mod_auth_openidcmetrics.c 24
mod_auth_openidcutil/random.c 2
mod_auth_openidcjson.c 13
/usr/include/jansson.h 4
mod_auth_openidchttp.c 2
mod_auth_openidcjose.c 4
cjoseerror.c 1
cjosebase64.c 4

Fuzzer: fuzz_metadata

Call tree

The calltree shows the control flow of the fuzzer. This is overlaid with coverage information to display how much of the potential code a fuzzer can reach is in fact covered at runtime. In the following there is a link to a detailed calltree visualisation as well as a bitmap showing a high-level view of the calltree. For further information about these topics please see the glossary for full calltree and calltree overview

Call tree overview bitmap:

The distribution of callsites in terms of coloring is
Color Runtime hitcount Callsite count Percentage
red 0 851 53.9%
gold [1:9] 121 7.66%
yellow [10:29] 42 2.66%
greenyellow [30:49] 17 1.07%
lawngreen 50+ 547 34.6%
All colors 1578 100

Fuzz blockers

The following nodes represent call sites where fuzz blockers occur.

Amount of callsites blocked Calltree index Parent function Callsite Largest blocked function
234 624 cjose_jwk_import_json call site: 00624 _cjose_jwk_import_EC
188 867 _oidc_jwk_parse_x5c_spec call site: 00867 _oidc_jwk_parse_x5c
59 141 oidc_cfg_post_config call site: 00141 oidc_metrics_thread_run
57 242 oidc_json_integer_value call site: 00242 oidc_metrics_counter_set_or_update
26 304 oidc_json_decref call site: 00304 _oidc_metrics_storage_set
26 1057 oidc_jwk_parse call site: 01057 oidc_jwk_from_cjose
16 40 oidc_jwk_list_destroy call site: 00040 oidc_cfg_oauth_destroy
14 1098 oidc_cfg_provider_signed_jwks_uri_keys_set call site: 01098 oidc_jwk_copy
13 216 oidc_json_object_get call site: 00216 oidc_metrics_store_counter_entry
11 230 _oidc_strstr call site: 00230 oidc_metrics_counter_set_or_update
9 206 oidc_json_parse call site: 00206 oidc_metrics_store_counters
8 116 oidc_cache_mutex_global_create call site: 00116 ap_log_error_

Runtime coverage analysis

Covered functions
231
Functions that are reachable but not covered
313
Reachable functions
518
Percentage of reachable functions covered
39.58%
NB: The sum of covered functions and functions that are reachable but not covered need not be equal to Reachable functions . This is because the reachability analysis is an approximation and thus at runtime some functions may be covered that are not included in the reachability analysis. This is a limitation of our static analysis capabilities.
Function name source code lines source lines hit percentage hit

Files reached

filename functions hit
mod_auth_openidc/test/fuzz/fuzz_metadata.c 2
mod_auth_openidc/test/util.c 7
mod_auth_openidccfg/cfg.c 13
mod_auth_openidc/test/stub.c 7
mod_auth_openidccfg/provider.c 131
mod_auth_openidcjose/jwk.c 24
cjosejwk.c 32
cjoseutil.c 6
mod_auth_openidccfg/oauth.c 2
mod_auth_openidccfg/cache.c 1
mod_auth_openidccfg/parse.c 17
mod_auth_openidc./const.h 7
mod_auth_openidccfg/dir.c 3
mod_auth_openidcconst.h 2
mod_auth_openidcutil/key.c 1
mod_auth_openidccache/common.c 6
mod_auth_openidcmetrics.c 24
mod_auth_openidcutil/random.c 2
mod_auth_openidcjson.c 28
/usr/include/jansson.h 2
mod_auth_openidchttp.c 2
mod_auth_openidcmetadata/provider.c 5
mod_auth_openidcutil/util.c 3
mod_auth_openidcmetadata/util.c 9
mod_auth_openidcproto/proto.c 2
mod_auth_openidcproto/profile.c 7
mod_auth_openidcjose.c 11
cjoseerror.c 1
cjosebase64.c 4
mod_auth_openidcmetadata/conf.c 14
mod_auth_openidcmetadata/client.c 3

Fuzzer: fuzz_authz_response

Call tree

The calltree shows the control flow of the fuzzer. This is overlaid with coverage information to display how much of the potential code a fuzzer can reach is in fact covered at runtime. In the following there is a link to a detailed calltree visualisation as well as a bitmap showing a high-level view of the calltree. For further information about these topics please see the glossary for full calltree and calltree overview

Call tree overview bitmap:

The distribution of callsites in terms of coloring is
Color Runtime hitcount Callsite count Percentage
red 0 3390 69.4%
gold [1:9] 154 3.15%
yellow [10:29] 39 0.79%
greenyellow [30:49] 7 0.14%
lawngreen 50+ 1291 26.4%
All colors 4881 100

Fuzz blockers

The following nodes represent call sites where fuzz blockers occur.

Amount of callsites blocked Calltree index Parent function Callsite Largest blocked function
420 1745 oidc_http_request call site: 01745 oidc_metadata_provider_parse
291 2170 oidc_cfg_endpoint_auth_is_mtls call site: 02170 oidc_cfg_provider_signed_jwks_uri_set
289 2717 oidc_get_provider_for_issuer call site: 02717 oidc_metadata_get
228 2488 oidc_jose_get_string call site: 02488 oidc_jwks_parse_json
195 4370 oidc_userinfo_retrieve_claims call site: 04370 oidc_refresh_token_grant
130 3007 oidc_proto_profile_id_token_aud_values_get call site: 03007 oidc_metadata_conf_parse_response
115 3267 oidc_util_url_cur_host call site: 03267 oidc_util_url_redirect_uri
104 3814 oidc_proto_jwt_validate call site: 03814 oidc_proto_jwks_uri_keys
71 4075 oidc_proto_endpoint_client_secret_basic call site: 04075 oidc_proto_endpoint_auth_client_secret_jwt
57 242 oidc_json_integer_value call site: 00242 oidc_metrics_counter_set_or_update
54 3693 oidc_jwt_alg2kty call site: 03693 oidc_proto_jwks_uri_keys
51 4228 oidc_proto_token_endpoint_call call site: 04228 oidc_proto_token_endpoint_dpop_retry

Runtime coverage analysis

Covered functions
467
Functions that are reachable but not covered
694
Reachable functions
1121
Percentage of reachable functions covered
38.09%
NB: The sum of covered functions and functions that are reachable but not covered need not be equal to Reachable functions . This is because the reachability analysis is an approximation and thus at runtime some functions may be covered that are not included in the reachability analysis. This is a limitation of our static analysis capabilities.
Function name source code lines source lines hit percentage hit

Files reached

filename functions hit
mod_auth_openidc/test/fuzz/fuzz_authz_response.c 7
mod_auth_openidc/test/util.c 7
mod_auth_openidccfg/cfg.c 51
mod_auth_openidc/test/stub.c 14
mod_auth_openidccfg/provider.c 141
mod_auth_openidcjose/jwk.c 28
cjosejwk.c 35
cjoseutil.c 6
mod_auth_openidccfg/oauth.c 2
mod_auth_openidccfg/cache.c 2
mod_auth_openidccfg/parse.c 17
mod_auth_openidc./const.h 7
mod_auth_openidccfg/dir.c 7
mod_auth_openidcconst.h 2
mod_auth_openidcutil/key.c 6
mod_auth_openidccache/common.c 14
mod_auth_openidcmetrics.c 34
mod_auth_openidcutil/random.c 5
mod_auth_openidcjson.c 46
/usr/include/jansson.h 4
mod_auth_openidchttp.c 63
mod_auth_openidcproto/state.c 29
mod_auth_openidcstate.c 7
mod_auth_openidcjose.c 22
mod_auth_openidcutil/base64.c 3
mod_auth_openidcutil/jwt.c 5
cjoseerror.c 1
cjosebase64.c 4
mod_auth_openidcjose/jws.c 15
mod_auth_openidcjose/jwe.c 5
cjosejwe.c 22
cjoseheader.c 3
cjosejws.c 15
mod_auth_openidc/test/fuzz/fuzz.h 1
mod_auth_openidcutil/util.c 23
mod_auth_openidcsession.c 56
mod_auth_openidcproto/jwt.c 8
mod_auth_openidc./metrics.h 2
mod_auth_openidcutil/url.c 8
mod_auth_openidcutil/request_state.c 3
mod_auth_openidchandle/response.c 15
mod_auth_openidcutil/html.c 10
mod_auth_openidcmod_auth_openidc.c 5
mod_auth_openidcmetadata/provider.c 7
mod_auth_openidcmetadata/util.c 15
mod_auth_openidcproto/proto.c 3
mod_auth_openidc./cfg/cfg_int.h 2
mod_auth_openidcproto/profile.c 8
mod_auth_openidcmetadata.c 1
mod_auth_openidcutil/file.c 4
mod_auth_openidcmetadata/conf.c 19
mod_auth_openidcmetadata/client.c 6
mod_auth_openidcproto/response.c 16
mod_auth_openidcproto/id_token.c 12
mod_auth_openidcproto/jwks.c 4
mod_auth_openidcmetadata/jwks.c 8
cjoseversion.c 1
mod_auth_openidcproto/token.c 8
mod_auth_openidcproto/auth.c 10
mod_auth_openidcproto/dpop.c 2
mod_auth_openidchandle/userinfo.c 2
mod_auth_openidcproto/userinfo.c 7
mod_auth_openidchandle/refresh.c 7
mod_auth_openidcutil/expr.c 2
mod_auth_openidcutil/pcre_subst.c 5

Fuzzer: fuzz_jwt

Call tree

The calltree shows the control flow of the fuzzer. This is overlaid with coverage information to display how much of the potential code a fuzzer can reach is in fact covered at runtime. In the following there is a link to a detailed calltree visualisation as well as a bitmap showing a high-level view of the calltree. For further information about these topics please see the glossary for full calltree and calltree overview

Call tree overview bitmap:

The distribution of callsites in terms of coloring is
Color Runtime hitcount Callsite count Percentage
red 0 673 56.6%
gold [1:9] 207 17.4%
yellow [10:29] 52 4.38%
greenyellow [30:49] 6 0.50%
lawngreen 50+ 249 20.9%
All colors 1187 100

Fuzz blockers

The following nodes represent call sites where fuzz blockers occur.

Amount of callsites blocked Calltree index Parent function Callsite Largest blocked function
87 736 _cjose_base64_encode_impl call site: 00736 oidc_jwk_pkey_to_jwk
69 230 _oidc_strstr call site: 00230 oidc_metrics_counter_set_or_update
69 661 oidc_jwk_new call site: 00661 oidc_jwk_pem_bio_read_public
59 141 oidc_cfg_post_config call site: 00141 oidc_metrics_thread_run
30 571 _cjose_jwk_import_oct call site: 00571 _cjose_jwk_import_OKP
30 630 oidc_jose_get_string call site: 00630 _oidc_jwk_parse_x5c
27 202 oidc_json_parse call site: 00202 oidc_metrics_store_counters
26 304 oidc_json_decref call site: 00304 _oidc_metrics_storage_set
16 1079 oidc_jwt_parse call site: 01079 oidc_jose_uncompress
15 602 cjose_const_memcmp call site: 00602 _cjose_jwk_OKP_new
9 444 cjose_jwk_create_EC_spec call site: 00444 cjose_err_message
9 906 _cjose_header_validate_crit call site: 00906 cjose_err_message

Runtime coverage analysis

Covered functions
159
Functions that are reachable but not covered
227
Reachable functions
359
Percentage of reachable functions covered
36.77%
NB: The sum of covered functions and functions that are reachable but not covered need not be equal to Reachable functions . This is because the reachability analysis is an approximation and thus at runtime some functions may be covered that are not included in the reachability analysis. This is a limitation of our static analysis capabilities.
Function name source code lines source lines hit percentage hit

Files reached

filename functions hit
mod_auth_openidc/test/fuzz/fuzz_jwt.c 3
mod_auth_openidc/test/util.c 6
mod_auth_openidccfg/cfg.c 9
mod_auth_openidc/test/stub.c 4
mod_auth_openidccfg/provider.c 7
mod_auth_openidcjose/jwk.c 19
cjosejwk.c 31
cjoseutil.c 6
mod_auth_openidccfg/oauth.c 2
mod_auth_openidccfg/cache.c 1
mod_auth_openidccfg/parse.c 5
mod_auth_openidc./const.h 7
mod_auth_openidccfg/dir.c 3
mod_auth_openidcconst.h 2
mod_auth_openidcutil/key.c 1
mod_auth_openidccache/common.c 6
mod_auth_openidcmetrics.c 24
mod_auth_openidcutil/random.c 2
mod_auth_openidcjson.c 13
/usr/include/jansson.h 2
mod_auth_openidchttp.c 2
mod_auth_openidcjose.c 9
cjoseerror.c 1
cjosebase64.c 4
mod_auth_openidcjose/jws.c 11
mod_auth_openidcjose/jwe.c 4
cjosejwe.c 13
cjoseheader.c 3
cjosejws.c 12
cjoseversion.c 1

Fuzzer: fuzz_discovery_response

Call tree

The calltree shows the control flow of the fuzzer. This is overlaid with coverage information to display how much of the potential code a fuzzer can reach is in fact covered at runtime. In the following there is a link to a detailed calltree visualisation as well as a bitmap showing a high-level view of the calltree. For further information about these topics please see the glossary for full calltree and calltree overview

Call tree overview bitmap:

The distribution of callsites in terms of coloring is
Color Runtime hitcount Callsite count Percentage
red 0 3377 81.8%
gold [1:9] 106 2.56%
yellow [10:29] 4 0.09%
greenyellow [30:49] 8 0.19%
lawngreen 50+ 631 15.2%
All colors 4126 100

Fuzz blockers

The following nodes represent call sites where fuzz blockers occur.

Amount of callsites blocked Calltree index Parent function Callsite Largest blocked function
711 3413 oidc_request_authenticate_user call site: 03413 oidc_discovery_response_authenticate
555 1778 oidc_proto_profile_ops call site: 01778 oidc_cfg_provider_signed_jwks_uri_set
506 2594 oidc_proto_request_auth_params_set call site: 02594 oidc_proto_request_object_param_add
385 1197 oidc_http_query_encoded_url call site: 01197 oidc_http_request
183 3102 oidc_proto_profile_auth_request_method_get call site: 03102 oidc_proto_request_auth_push
138 1037 oidc_util_jwt_verify call site: 01037 oidc_metadata_provider_retrieve
98 3301 oidc_response_post_preserve_javascript call site: 03301 oidc_original_request_method
83 1694 oidc_util_jwt_create call site: 01694 oidc_metadata_provider_parse
60 239 oidc_json_integer call site: 00239 oidc_metrics_counter_set_or_update
39 719 oidc_util_base64url_encode call site: 00719 oidc_cache_crypto_decrypt
33 603 oidc_validate_redirect_url call site: 00603 oidc_validate_redirect_url_allowed
29 141 oidc_cfg_post_config call site: 00141 oidc_metrics_thread_run

Runtime coverage analysis

Covered functions
249
Functions that are reachable but not covered
766
Reachable functions
994
Percentage of reachable functions covered
22.94%
NB: The sum of covered functions and functions that are reachable but not covered need not be equal to Reachable functions . This is because the reachability analysis is an approximation and thus at runtime some functions may be covered that are not included in the reachability analysis. This is a limitation of our static analysis capabilities.
Function name source code lines source lines hit percentage hit

Files reached

filename functions hit
mod_auth_openidc/test/fuzz/fuzz_discovery_response.c 2
mod_auth_openidc/test/util.c 7
mod_auth_openidccfg/cfg.c 44
mod_auth_openidc/test/stub.c 14
mod_auth_openidccfg/provider.c 140
mod_auth_openidcjose/jwk.c 27
cjosejwk.c 35
cjoseutil.c 6
mod_auth_openidccfg/oauth.c 2
mod_auth_openidccfg/cache.c 2
mod_auth_openidccfg/parse.c 18
mod_auth_openidc./const.h 7
mod_auth_openidccfg/dir.c 7
mod_auth_openidcconst.h 2
mod_auth_openidcutil/key.c 3
mod_auth_openidccache/common.c 14
mod_auth_openidcmetrics.c 34
mod_auth_openidcutil/random.c 4
mod_auth_openidcjson.c 43
/usr/include/jansson.h 4
mod_auth_openidchttp.c 56
mod_auth_openidchandle/discovery.c 10
mod_auth_openidcutil/url.c 12
mod_auth_openidcutil/util.c 20
mod_auth_openidcutil/html.c 10
mod_auth_openidcmod_auth_openidc.c 9
mod_auth_openidcutil/expr.c 1
mod_auth_openidcutil/pcre_subst.c 4
mod_auth_openidcjose.c 18
mod_auth_openidcutil/base64.c 3
mod_auth_openidcutil/jwt.c 5
mod_auth_openidcproto/jwt.c 5
cjoseerror.c 1
cjosebase64.c 4
mod_auth_openidcjose/jwe.c 5
cjosejwe.c 22
cjoseheader.c 3
mod_auth_openidcjose/jws.c 13
mod_auth_openidc./metrics.h 1
mod_auth_openidcmetadata/provider.c 7
mod_auth_openidcmetadata/util.c 15
mod_auth_openidcproto/proto.c 4
cjosejws.c 15
mod_auth_openidc./cfg/cfg_int.h 2
mod_auth_openidcproto/profile.c 9
mod_auth_openidchandle/request.c 9
mod_auth_openidcutil/request_state.c 3
mod_auth_openidcproto/state.c 24
mod_auth_openidcstate.c 7
mod_auth_openidcproto/request.c 4
mod_auth_openidcproto/request_object.c 14
mod_auth_openidcmetadata/jwks.c 8
cjoseversion.c 1
mod_auth_openidcproto/auth.c 10
mod_auth_openidchandle/response.c 1
mod_auth_openidcutil/file.c 4
mod_auth_openidcproto/discovery.c 4
mod_auth_openidcmetadata.c 1
mod_auth_openidcmetadata/conf.c 19
mod_auth_openidcmetadata/client.c 6

Fuzzer: fuzz_current_url

Call tree

The calltree shows the control flow of the fuzzer. This is overlaid with coverage information to display how much of the potential code a fuzzer can reach is in fact covered at runtime. In the following there is a link to a detailed calltree visualisation as well as a bitmap showing a high-level view of the calltree. For further information about these topics please see the glossary for full calltree and calltree overview

Call tree overview bitmap:

The distribution of callsites in terms of coloring is
Color Runtime hitcount Callsite count Percentage
red 0 274 57.3%
gold [1:9] 93 19.4%
yellow [10:29] 1 0.20%
greenyellow [30:49] 1 0.20%
lawngreen 50+ 109 22.8%
All colors 478 100

Fuzz blockers

The following nodes represent call sites where fuzz blockers occur.

Amount of callsites blocked Calltree index Parent function Callsite Largest blocked function
100 230 _oidc_strstr call site: 00230 oidc_metrics_counter_set_or_update
88 141 oidc_cfg_post_config call site: 00141 oidc_metrics_thread_run
20 36 oidc_cfg_server_alloc call site: 00036 oidc_cfg_server_destroy
9 381 oidc_check_x_forwarded_hdr call site: 00381 oidc_util_spaced_string_to_hashtable
8 116 oidc_cache_mutex_global_create call site: 00116 ap_log_error_
5 76 _oidc_strnatcasecmp call site: 00076 _oidc_strnatcasecmp
5 337 oidc_cfg_parse_option call site: 00337 oidc_cfg_parse_options_flatten
4 136 oidc_cache_mutex_global_create call site: 00136 ap_log_error_
4 350 oidc_http_curl_pool_init call site: 00350 oidc_http_curl_pool_cleanup
3 105 oidc_test_crypto_passphrase_derive_keys_cached call site: 00105 oidc_test_key_derive_cached
3 127 oidc_cache_mutex_global_create call site: 00127 ap_log_error_
3 131 oidc_cache_mutex_global_create call site: 00131 ap_log_error_

Runtime coverage analysis

Covered functions
74
Functions that are reachable but not covered
139
Reachable functions
205
Percentage of reachable functions covered
32.2%
NB: The sum of covered functions and functions that are reachable but not covered need not be equal to Reachable functions . This is because the reachability analysis is an approximation and thus at runtime some functions may be covered that are not included in the reachability analysis. This is a limitation of our static analysis capabilities.
Function name source code lines source lines hit percentage hit

Files reached

filename functions hit
mod_auth_openidc/test/fuzz/fuzz_current_url.c 2
mod_auth_openidc/test/util.c 7
mod_auth_openidccfg/cfg.c 13
mod_auth_openidc/test/stub.c 7
mod_auth_openidccfg/provider.c 7
mod_auth_openidcjose/jwk.c 3
cjosejwk.c 1
cjoseutil.c 1
mod_auth_openidccfg/oauth.c 2
mod_auth_openidccfg/cache.c 1
mod_auth_openidccfg/parse.c 5
mod_auth_openidc./const.h 6
mod_auth_openidccfg/dir.c 3
mod_auth_openidcconst.h 2
mod_auth_openidcutil/key.c 1
mod_auth_openidccache/common.c 6
mod_auth_openidcmetrics.c 24
mod_auth_openidcutil/random.c 2
mod_auth_openidcjson.c 10
/usr/include/jansson.h 2
mod_auth_openidchttp.c 10
mod_auth_openidc/test/fuzz/fuzz.h 1
mod_auth_openidcutil/url.c 11
mod_auth_openidcutil/util.c 3

Fuzzer: fuzz_bearer_token

Call tree

The calltree shows the control flow of the fuzzer. This is overlaid with coverage information to display how much of the potential code a fuzzer can reach is in fact covered at runtime. In the following there is a link to a detailed calltree visualisation as well as a bitmap showing a high-level view of the calltree. For further information about these topics please see the glossary for full calltree and calltree overview

Call tree overview bitmap:

The distribution of callsites in terms of coloring is
Color Runtime hitcount Callsite count Percentage
red 0 2061 64.9%
gold [1:9] 153 4.82%
yellow [10:29] 121 3.81%
greenyellow [30:49] 2 0.06%
lawngreen 50+ 837 26.3%
All colors 3174 100

Fuzz blockers

The following nodes represent call sites where fuzz blockers occur.

Amount of callsites blocked Calltree index Parent function Callsite Largest blocked function
395 1410 oidc_oauth_provider_config call site: 01410 oidc_oauth_metadata_provider_retrieve
262 2708 cjose_const_memcmp call site: 02708 oidc_proto_jwks_uri_keys
238 2469 oidc_jwt_verify call site: 02469 oidc_metadata_jwks_retrieve_and_cache
189 1946 oidc_oauth_get_cached_access_token call site: 01946 oidc_oauth_introspect
77 855 oidc_util_url_redirect_uri call site: 00855 _oidc_util_url_base_cur
57 242 oidc_json_integer_value call site: 00242 oidc_metrics_counter_set_or_update
53 1833 oidc_json_array_get call site: 01833 oidc_metadata_cert_bound_tokens_enabled
52 2372 oidc_jwt_alg2kty call site: 02372 oidc_proto_jwks_uri_keys
43 3025 oidc_get_remote_user call site: 03025 oidc_util_regexp_first_match
38 141 oidc_cfg_post_config call site: 00141 oidc_metrics_thread_run
31 936 oidc_util_url_cur_matches call site: 00936 oidc_oauth_check_userid_redirect_uri
20 180 oidc_cache_mutex_lock call site: 00180 oidc_metrics_store

Runtime coverage analysis

Covered functions
340
Functions that are reachable but not covered
475
Reachable functions
782
Percentage of reachable functions covered
39.26%
NB: The sum of covered functions and functions that are reachable but not covered need not be equal to Reachable functions . This is because the reachability analysis is an approximation and thus at runtime some functions may be covered that are not included in the reachability analysis. This is a limitation of our static analysis capabilities.
Function name source code lines source lines hit percentage hit

Files reached

filename functions hit
mod_auth_openidc/test/fuzz/fuzz_bearer_token.c 8
mod_auth_openidc/test/util.c 7
mod_auth_openidccfg/cfg.c 35
mod_auth_openidc/test/stub.c 17
mod_auth_openidccfg/provider.c 12
mod_auth_openidcjose/jwk.c 22
cjosejwk.c 34
cjoseutil.c 6
mod_auth_openidccfg/oauth.c 35
mod_auth_openidccfg/cache.c 2
mod_auth_openidccfg/parse.c 15
mod_auth_openidc./const.h 7
mod_auth_openidccfg/dir.c 13
mod_auth_openidcconst.h 2
mod_auth_openidcutil/key.c 6
mod_auth_openidccache/common.c 14
mod_auth_openidcmetrics.c 34
mod_auth_openidcutil/random.c 4
mod_auth_openidcjson.c 41
/usr/include/jansson.h 4
mod_auth_openidchttp.c 52
mod_auth_openidcutil/base64.c 3
cjoseerror.c 1
mod_auth_openidcjose.c 11
cjosebase64.c 4
mod_auth_openidc/test/fuzz/fuzz.h 1
mod_auth_openidcjose/jws.c 13
cjosejws.c 15
cjoseheader.c 3
mod_auth_openidcoauth.c 27
mod_auth_openidcutil/util.c 21
mod_auth_openidcmod_auth_openidc.c 6
mod_auth_openidcutil/url.c 11
mod_auth_openidc./metrics.h 1
mod_auth_openidchandle/revoke.c 1
mod_auth_openidcutil/jwt.c 5
mod_auth_openidcproto/jwt.c 7
mod_auth_openidcjose/jwe.c 5
cjosejwe.c 22
mod_auth_openidcmetadata/oauth.c 1
mod_auth_openidcmetadata/util.c 6
mod_auth_openidcproto/profile.c 2
mod_auth_openidcproto/proto.c 2
mod_auth_openidcutil/request_state.c 6
mod_auth_openidcproto/auth.c 10
mod_auth_openidcproto/jwks.c 4
mod_auth_openidcmetadata/jwks.c 8
cjoseversion.c 1
mod_auth_openidcutil/expr.c 2
mod_auth_openidcutil/pcre_subst.c 5
mod_auth_openidcutil/appinfo.c 9

Fuzzer: fuzz_state_cookie

Call tree

The calltree shows the control flow of the fuzzer. This is overlaid with coverage information to display how much of the potential code a fuzzer can reach is in fact covered at runtime. In the following there is a link to a detailed calltree visualisation as well as a bitmap showing a high-level view of the calltree. For further information about these topics please see the glossary for full calltree and calltree overview

Call tree overview bitmap:

The distribution of callsites in terms of coloring is
Color Runtime hitcount Callsite count Percentage
red 0 368 51.5%
gold [1:9] 167 23.3%
yellow [10:29] 8 1.12%
greenyellow [30:49] 5 0.70%
lawngreen 50+ 166 23.2%
All colors 714 100

Fuzz blockers

The following nodes represent call sites where fuzz blockers occur.

Amount of callsites blocked Calltree index Parent function Callsite Largest blocked function
59 141 oidc_cfg_post_config call site: 00141 oidc_metrics_thread_run
57 242 oidc_json_integer_value call site: 00242 oidc_metrics_counter_set_or_update
43 427 _oidc_jose_error_set call site: 00427 oidc_jwk_set_or_generate_kid
26 304 oidc_json_decref call site: 00304 _oidc_metrics_storage_set
13 43 cjose_jwk_release call site: 00043 oidc_cfg_oauth_destroy
11 230 _oidc_strstr call site: 00230 oidc_metrics_counter_set_or_update
9 206 oidc_json_parse call site: 00206 oidc_metrics_store_counters
9 220 oidc_json_object_set_new call site: 00220 oidc_metrics_store_counter_entry
9 555 _cjose_header_validate_crit call site: 00555 cjose_err_message
8 116 oidc_cache_mutex_global_create call site: 00116 ap_log_error_
8 609 oidc_alg2kty call site: 00609 _oidc_jose_error_set
5 36 oidc_cfg_server_alloc call site: 00036 oidc_cfg_server_destroy

Runtime coverage analysis

Covered functions
127
Functions that are reachable but not covered
159
Reachable functions
274
Percentage of reachable functions covered
41.97%
NB: The sum of covered functions and functions that are reachable but not covered need not be equal to Reachable functions . This is because the reachability analysis is an approximation and thus at runtime some functions may be covered that are not included in the reachability analysis. This is a limitation of our static analysis capabilities.
Function name source code lines source lines hit percentage hit

Files reached

filename functions hit
mod_auth_openidc/test/fuzz/fuzz_state_cookie.c 2
mod_auth_openidc/test/util.c 7
mod_auth_openidccfg/cfg.c 10
mod_auth_openidc/test/stub.c 4
mod_auth_openidccfg/provider.c 7
mod_auth_openidcjose/jwk.c 6
cjosejwk.c 6
cjoseutil.c 5
mod_auth_openidccfg/oauth.c 2
mod_auth_openidccfg/cache.c 1
mod_auth_openidccfg/parse.c 5
mod_auth_openidc./const.h 7
mod_auth_openidccfg/dir.c 3
mod_auth_openidcconst.h 2
mod_auth_openidcutil/key.c 1
mod_auth_openidccache/common.c 6
mod_auth_openidcmetrics.c 24
mod_auth_openidcutil/random.c 2
mod_auth_openidcjson.c 16
/usr/include/jansson.h 2
mod_auth_openidchttp.c 2
mod_auth_openidcproto/state.c 17
mod_auth_openidcutil/jwt.c 2
mod_auth_openidcproto/jwt.c 1
mod_auth_openidcutil/base64.c 2
cjoseerror.c 1
mod_auth_openidcjose.c 6
cjosebase64.c 4
mod_auth_openidcjose/jwe.c 4
cjosejwe.c 13
cjoseheader.c 3
mod_auth_openidcjose/jws.c 1

Fuzzer: fuzz_backchannel_logout

Call tree

The calltree shows the control flow of the fuzzer. This is overlaid with coverage information to display how much of the potential code a fuzzer can reach is in fact covered at runtime. In the following there is a link to a detailed calltree visualisation as well as a bitmap showing a high-level view of the calltree. For further information about these topics please see the glossary for full calltree and calltree overview

Call tree overview bitmap:

The distribution of callsites in terms of coloring is
Color Runtime hitcount Callsite count Percentage
red 0 3347 75.7%
gold [1:9] 205 4.64%
yellow [10:29] 52 1.17%
greenyellow [30:49] 44 0.99%
lawngreen 50+ 770 17.4%
All colors 4418 100

Fuzz blockers

The following nodes represent call sites where fuzz blockers occur.

Amount of callsites blocked Calltree index Parent function Callsite Largest blocked function
539 1401 oidc_json_array_get call site: 01401 oidc_metadata_provider_parse
384 4030 oidc_logout call site: 04030 oidc_logout_build_op_request
296 1941 oidc_proto_profile_ops call site: 01941 oidc_cfg_provider_signed_jwks_uri_set
291 2495 oidc_get_provider_for_issuer call site: 02495 oidc_metadata_get
259 2787 oidc_proto_profile_id_token_aud_values_get call site: 02787 oidc_metadata_client_get
232 2262 oidc_jose_get_string call site: 02262 oidc_jwks_parse_json
176 3052 oidc_util_url_cur_host call site: 03052 oidc_http_post_json
171 3236 oidc_json_array_has_value call site: 03236 oidc_logout_revoke_one_token
102 3757 oidc_proto_validate_iat call site: 03757 oidc_proto_jwks_uri_keys
57 242 oidc_json_integer_value call site: 00242 oidc_metrics_counter_set_or_update
52 3636 oidc_jwt_alg2kty call site: 03636 oidc_proto_jwks_uri_keys
32 1251 oidc_session_save call site: 01251 oidc_session_save_cookie

Runtime coverage analysis

Covered functions
328
Functions that are reachable but not covered
730
Reachable functions
1027
Percentage of reachable functions covered
28.92%
NB: The sum of covered functions and functions that are reachable but not covered need not be equal to Reachable functions . This is because the reachability analysis is an approximation and thus at runtime some functions may be covered that are not included in the reachability analysis. This is a limitation of our static analysis capabilities.
Function name source code lines source lines hit percentage hit

Files reached

filename functions hit
mod_auth_openidc/test/fuzz/fuzz_backchannel_logout.c 4
mod_auth_openidc/test/util.c 7
mod_auth_openidccfg/cfg.c 45
mod_auth_openidc/test/stub.c 14
mod_auth_openidccfg/provider.c 141
mod_auth_openidcjose/jwk.c 28
cjosejwk.c 35
cjoseutil.c 6
mod_auth_openidccfg/oauth.c 2
mod_auth_openidccfg/cache.c 2
mod_auth_openidccfg/parse.c 17
mod_auth_openidc./const.h 7
mod_auth_openidccfg/dir.c 6
mod_auth_openidcconst.h 2
mod_auth_openidcutil/key.c 6
mod_auth_openidccache/common.c 14
mod_auth_openidcmetrics.c 34
mod_auth_openidcutil/random.c 5
mod_auth_openidcjson.c 44
/usr/include/jansson.h 4
mod_auth_openidchttp.c 63
mod_auth_openidc/test/fuzz/fuzz.h 1
mod_auth_openidcjose.c 18
cjoseerror.c 1
cjosebase64.c 4
mod_auth_openidcjose/jws.c 15
cjosejws.c 15
cjoseheader.c 3
mod_auth_openidcsession.c 44
mod_auth_openidcutil/util.c 20
mod_auth_openidcutil/base64.c 3
mod_auth_openidcutil/jwt.c 5
mod_auth_openidcproto/jwt.c 8
mod_auth_openidcjose/jwe.c 5
cjosejwe.c 22
mod_auth_openidc./metrics.h 1
mod_auth_openidcutil/url.c 9
mod_auth_openidcutil/request_state.c 3
mod_auth_openidchandle/logout.c 19
mod_auth_openidcmod_auth_openidc.c 11
mod_auth_openidcmetadata/provider.c 7
mod_auth_openidcmetadata/util.c 15
mod_auth_openidcproto/proto.c 3
mod_auth_openidc./cfg/cfg_int.h 2
mod_auth_openidcproto/profile.c 9
mod_auth_openidcmetadata.c 1
mod_auth_openidcutil/file.c 4
mod_auth_openidcmetadata/conf.c 19
mod_auth_openidcmetadata/client.c 6
mod_auth_openidcproto/auth.c 10
mod_auth_openidchandle/response.c 1
mod_auth_openidcutil/html.c 2
mod_auth_openidcproto/jwks.c 4
mod_auth_openidcmetadata/jwks.c 8
cjoseversion.c 1
mod_auth_openidcproto/id_token.c 8
mod_auth_openidcutil/expr.c 1
mod_auth_openidcutil/pcre_subst.c 4
mod_auth_openidchandle/refresh.c 7
mod_auth_openidcproto/token.c 8
mod_auth_openidcproto/dpop.c 2

Fuzzer: fuzz_redirect_uri

Call tree

The calltree shows the control flow of the fuzzer. This is overlaid with coverage information to display how much of the potential code a fuzzer can reach is in fact covered at runtime. In the following there is a link to a detailed calltree visualisation as well as a bitmap showing a high-level view of the calltree. For further information about these topics please see the glossary for full calltree and calltree overview

Call tree overview bitmap:

The distribution of callsites in terms of coloring is
Color Runtime hitcount Callsite count Percentage
red 0 4216 80.0%
gold [1:9] 343 6.50%
yellow [10:29] 46 0.87%
greenyellow [30:49] 5 0.09%
lawngreen 50+ 659 12.5%
All colors 5269 100

Fuzz blockers

The following nodes represent call sites where fuzz blockers occur.

Amount of callsites blocked Calltree index Parent function Callsite Largest blocked function
546 2022 oidc_cfg_endpoint_auth_is_mtls call site: 02022 oidc_cfg_provider_signed_jwks_uri_set
418 1599 oidc_http_request call site: 01599 oidc_metadata_provider_parse
414 3517 oidc_jwt_parse call site: 03517 oidc_proto_jwt_verify
351 2641 oidc_util_rand_str call site: 02641 oidc_metadata_conf_parse
298 4474 oidc_refresh_token_grant_obtain_tokens call site: 04474 oidc_proto_userinfo_request
252 4159 oidc_proto_token_endpoint_call call site: 04159 oidc_userinfo_retrieve_claims
202 3122 oidc_util_url_cur_host call site: 03122 oidc_http_post_json
123 3954 oidc_proto_endpoint_client_secret_basic call site: 03954 oidc_proto_endpoint_auth_client_secret_jwt
86 5180 oidc_util_read_post_params_impl call site: 05180 oidc_metadata_list
77 4983 oidc_session_get_idtoken call site: 04983 oidc_session_save
68 2569 oidc_get_provider_for_issuer call site: 02569 oidc_metadata_get
60 239 oidc_json_integer call site: 00239 oidc_metrics_counter_set_or_update

Runtime coverage analysis

Covered functions
458
Functions that are reachable but not covered
853
Reachable functions
1196
Percentage of reachable functions covered
28.68%
NB: The sum of covered functions and functions that are reachable but not covered need not be equal to Reachable functions . This is because the reachability analysis is an approximation and thus at runtime some functions may be covered that are not included in the reachability analysis. This is a limitation of our static analysis capabilities.
Function name source code lines source lines hit percentage hit

Files reached

filename functions hit
mod_auth_openidc/test/fuzz/fuzz_redirect_uri.c 2
mod_auth_openidc/test/util.c 7
mod_auth_openidccfg/cfg.c 56
mod_auth_openidc/test/stub.c 19
mod_auth_openidccfg/provider.c 141
mod_auth_openidcjose/jwk.c 28
cjosejwk.c 35
cjoseutil.c 6
mod_auth_openidccfg/oauth.c 2
mod_auth_openidccfg/cache.c 2
mod_auth_openidccfg/parse.c 17
mod_auth_openidc./const.h 8
mod_auth_openidccfg/dir.c 15
mod_auth_openidcconst.h 2
mod_auth_openidcutil/key.c 6
mod_auth_openidccache/common.c 14
mod_auth_openidcmetrics.c 41
mod_auth_openidcutil/random.c 5
mod_auth_openidcjson.c 46
/usr/include/jansson.h 4
mod_auth_openidchttp.c 66
mod_auth_openidc/test/fuzz/fuzz.h 1
mod_auth_openidcsession.c 70
mod_auth_openidcutil/util.c 24
mod_auth_openidcjose.c 22
mod_auth_openidcutil/base64.c 3
mod_auth_openidcutil/jwt.c 5
mod_auth_openidcproto/jwt.c 8
cjoseerror.c 1
cjosebase64.c 4
mod_auth_openidcjose/jwe.c 5
cjosejwe.c 22
cjoseheader.c 3
mod_auth_openidcjose/jws.c 15
mod_auth_openidc./metrics.h 2
cjosejws.c 15
mod_auth_openidcutil/url.c 13
mod_auth_openidcutil/request_state.c 3
mod_auth_openidcmod_auth_openidc.c 10
mod_auth_openidchandle/response.c 15
mod_auth_openidcstate.c 7
mod_auth_openidcproto/state.c 18
mod_auth_openidcutil/html.c 12
mod_auth_openidcmetadata/provider.c 7
mod_auth_openidcmetadata/util.c 16
mod_auth_openidcproto/proto.c 3
mod_auth_openidc./cfg/cfg_int.h 2
mod_auth_openidcproto/profile.c 8
mod_auth_openidcmetadata.c 2
mod_auth_openidcutil/file.c 4
mod_auth_openidcmetadata/conf.c 19
mod_auth_openidcmetadata/client.c 6
mod_auth_openidcproto/response.c 16
mod_auth_openidcproto/id_token.c 12
mod_auth_openidcproto/jwks.c 4
mod_auth_openidcmetadata/jwks.c 8
cjoseversion.c 1
mod_auth_openidcproto/token.c 8
mod_auth_openidcproto/auth.c 10
mod_auth_openidcproto/dpop.c 2
mod_auth_openidchandle/userinfo.c 3
mod_auth_openidcproto/userinfo.c 7
mod_auth_openidchandle/refresh.c 7
mod_auth_openidcutil/expr.c 3
mod_auth_openidcutil/pcre_subst.c 5
mod_auth_openidchandle/content.c 3
mod_auth_openidchandle/info.c 6
mod_auth_openidcutil/appinfo.c 5
mod_auth_openidchandle/dpop.c 1
mod_auth_openidchandle/jwks.c 1
mod_auth_openidchandle/discovery.c 6

Fuzzer: fuzz_post_preserve

Call tree

The calltree shows the control flow of the fuzzer. This is overlaid with coverage information to display how much of the potential code a fuzzer can reach is in fact covered at runtime. In the following there is a link to a detailed calltree visualisation as well as a bitmap showing a high-level view of the calltree. For further information about these topics please see the glossary for full calltree and calltree overview

Call tree overview bitmap:

The distribution of callsites in terms of coloring is
Color Runtime hitcount Callsite count Percentage
red 0 447 71.7%
gold [1:9] 103 16.5%
yellow [10:29] 0 0.0%
greenyellow [30:49] 0 0.0%
lawngreen 50+ 73 11.7%
All colors 623 100

Fuzz blockers

The following nodes represent call sites where fuzz blockers occur.

Amount of callsites blocked Calltree index Parent function Callsite Largest blocked function
100 230 _oidc_strstr call site: 00230 oidc_metrics_counter_set_or_update
88 141 oidc_cfg_post_config call site: 00141 oidc_metrics_thread_run
77 410 oidc_http_hdr_in_get call site: 00410 _oidc_util_url_cur_port
39 555 oidc_response_post_preserve_javascript call site: 00555 oidc_util_html_send_in_template
25 384 oidc_original_request_method call site: 00384 oidc_util_url_redirect_uri
20 36 oidc_cfg_server_alloc call site: 00036 oidc_cfg_server_destroy
17 601 oidc_util_html_javascript_escape call site: 00601 oidc_util_template_escape
9 536 oidc_util_read_form_encoded_params_impl call site: 00536 oidc_util_userdata_set_post_param
8 116 oidc_cache_mutex_global_create call site: 00116 ap_log_error_
5 76 _oidc_strnatcasecmp call site: 00076 _oidc_strnatcasecmp
5 337 oidc_cfg_parse_option call site: 00337 oidc_cfg_parse_options_flatten
4 136 oidc_cache_mutex_global_create call site: 00136 ap_log_error_

Runtime coverage analysis

Covered functions
68
Functions that are reachable but not covered
195
Reachable functions
255
Percentage of reachable functions covered
23.53%
NB: The sum of covered functions and functions that are reachable but not covered need not be equal to Reachable functions . This is because the reachability analysis is an approximation and thus at runtime some functions may be covered that are not included in the reachability analysis. This is a limitation of our static analysis capabilities.
Function name source code lines source lines hit percentage hit

Files reached

filename functions hit
mod_auth_openidc/test/fuzz/fuzz_post_preserve.c 2
mod_auth_openidc/test/util.c 7
mod_auth_openidccfg/cfg.c 14
mod_auth_openidc/test/stub.c 11
mod_auth_openidccfg/provider.c 7
mod_auth_openidcjose/jwk.c 3
cjosejwk.c 1
cjoseutil.c 1
mod_auth_openidccfg/oauth.c 2
mod_auth_openidccfg/cache.c 1
mod_auth_openidccfg/parse.c 6
mod_auth_openidc./const.h 7
mod_auth_openidccfg/dir.c 5
mod_auth_openidcconst.h 2
mod_auth_openidcutil/key.c 1
mod_auth_openidccache/common.c 6
mod_auth_openidcmetrics.c 24
mod_auth_openidcutil/random.c 2
mod_auth_openidcjson.c 10
/usr/include/jansson.h 2
mod_auth_openidchttp.c 15
mod_auth_openidc/test/fuzz/fuzz.h 1
mod_auth_openidchandle/response.c 1
mod_auth_openidcmod_auth_openidc.c 1
mod_auth_openidcutil/url.c 11
mod_auth_openidcutil/util.c 10
mod_auth_openidchandle/discovery.c 1
mod_auth_openidcutil/html.c 8
mod_auth_openidcutil/file.c 3
mod_auth_openidcutil/request_state.c 2

Analyses and suggestions

Optimal target analysis

Remaining optimal interesting functions

The following table shows a list of functions that are optimal targets. Optimal targets are identified by finding the functions that in combination, yield a high code coverage.

Func name Functions filename Arg count Args Function depth hitcount instr count bb count cyclomatic complexity Reachable functions Incoming references total cyclomatic complexity Unreached complexity
oidc_register_hooks /src/mod_auth_openidc/src/mod_auth_openidc.c 1 ['N/A'] 19 0 23 3 2 1417 0 10678 711
oidc_authz_24_checker_claim /src/mod_auth_openidc/src/handle/authz.c 3 ['N/A', 'N/A', 'N/A'] 24 0 21 3 2 762 0 5608 259
_cjose_jwe_encrypt_ek_ecdh_es_a256kw /src/cjose/src/jwe.c 4 ['N/A', 'N/A', 'N/A', 'N/A'] 6 0 24 3 2 66 0 368 157
oidc_cache_file_set /src/mod_auth_openidc/src/cache/file.c 5 ['N/A', 'N/A', 'N/A', 'N/A', 'size_t'] 6 0 511 84 28 46 0 285 147
oidc_session_management /src/mod_auth_openidc/src/handle/session_management.c 3 ['N/A', 'N/A', 'N/A'] 22 0 783 143 49 960 0 6488 103
oidc_cache_shm_set /src/mod_auth_openidc/src/cache/shm.c 5 ['N/A', 'N/A', 'N/A', 'N/A', 'size_t'] 5 0 417 61 21 55 0 183 84
_cjose_jwe_decrypt_dat_aes_cbc /src/cjose/src/jwe.c 2 ['N/A', 'N/A'] 4 0 700 108 37 28 0 126 78

Implementing fuzzers that target the above functions will improve reachability such that it becomes:

Functions statically reachable by fuzzers
76.0%
1336 / 1767
Cyclomatic complexity statically reachable by fuzzers
82.0%
11564 / 14087

All functions overview

If you implement fuzzers for these functions, the status of all functions in the project will be:

Func name Functions filename Args Function call depth Reached by Fuzzers Runtime reached by Fuzzers Combined reached by Fuzzers Fuzzers runtime hit Func lines hit % I Count BB Count Cyclomatic complexity Functions reached Reached by functions Accumulated cyclomatic complexity Undiscovered complexity

Fuzz engine guidance

This sections provides heuristics that can be used as input to a fuzz engine when running a given fuzz target. The current focus is on providing input that is usable by libFuzzer.

mod_auth_openidc/test/fuzz/fuzz_form_params.c

Dictionary

Use this with the libFuzzer -dict=DICT.file flag


Fuzzer function priority

Use one of these functions as input to libfuzzer with flag: -focus_function name

-focus_function=['_oidc_strstr', 'oidc_cfg_post_config', 'oidc_cfg_server_alloc', 'oidc_cache_mutex_global_create', '_oidc_strnatcasecmp', 'oidc_cfg_parse_option', 'oidc_util_read_form_encoded_params_impl', 'oidc_http_curl_pool_init', 'oidc_test_crypto_passphrase_derive_keys_cached']

mod_auth_openidc/test/fuzz/fuzz_base64.c

Dictionary

Use this with the libFuzzer -dict=DICT.file flag


Fuzzer function priority

Use one of these functions as input to libfuzzer with flag: -focus_function name

-focus_function=['_oidc_strstr', 'oidc_cfg_post_config', 'oidc_cfg_server_alloc', 'oidc_cache_mutex_global_create', '_oidc_strnatcasecmp', 'oidc_cfg_parse_option', 'oidc_http_curl_pool_init', 'oidc_test_crypto_passphrase_derive_keys_cached']

mod_auth_openidc/test/fuzz/fuzz_url.c

Dictionary

Use this with the libFuzzer -dict=DICT.file flag


Fuzzer function priority

Use one of these functions as input to libfuzzer with flag: -focus_function name

-focus_function=['_oidc_strstr', 'oidc_cfg_post_config', 'oidc_cfg_server_alloc', 'oidc_util_regexp_first_match', 'oidc_cache_mutex_global_create', 'oidc_util_strcasestr', '_oidc_strnatcasecmp', 'oidc_cfg_parse_option', 'oidc_validate_redirect_url_host', 'oidc_http_hdr_in_get']

mod_auth_openidc/test/fuzz/fuzz_response_header.c

Dictionary

Use this with the libFuzzer -dict=DICT.file flag


Fuzzer function priority

Use one of these functions as input to libfuzzer with flag: -focus_function name

-focus_function=['_oidc_strstr', 'oidc_cfg_post_config', 'oidc_cfg_server_alloc', 'oidc_cache_mutex_global_create', '_oidc_strnatcasecmp', 'oidc_cfg_parse_option', 'oidc_http_curl_pool_init', 'oidc_test_crypto_passphrase_derive_keys_cached']

mod_auth_openidc/test/fuzz/fuzz_json.c

Dictionary

Use this with the libFuzzer -dict=DICT.file flag


Fuzzer function priority

Use one of these functions as input to libfuzzer with flag: -focus_function name

-focus_function=['_oidc_strstr', 'oidc_cfg_post_config', 'oidc_json_decref', 'oidc_json_parse', 'oidc_cfg_server_alloc', 'oidc_cache_mutex_global_create', '_oidc_strnatcasecmp', 'oidc_cfg_parse_option', 'oidc_http_curl_pool_init']

mod_auth_openidc/test/fuzz/fuzz_pem_key.c

Dictionary

Use this with the libFuzzer -dict=DICT.file flag


Fuzzer function priority

Use one of these functions as input to libfuzzer with flag: -focus_function name

-focus_function=['oidc_cfg_post_config', '_oidc_strstr', 'oidc_json_encode', 'cjose_jwk_release', 'cjose_jwk_create_RSA_spec', 'oidc_cache_mutex_global_create', 'cjose_base64url_encode', 'oidc_cfg_server_alloc', '_oidc_strnatcasecmp']

mod_auth_openidc/test/fuzz/fuzz_strings.c

Dictionary

Use this with the libFuzzer -dict=DICT.file flag


Fuzzer function priority

Use one of these functions as input to libfuzzer with flag: -focus_function name

-focus_function=['_oidc_strstr', 'oidc_cfg_post_config', 'oidc_json_decref', 'oidc_cfg_server_alloc', 'oidc_json_object_get', 'oidc_json_parse', 'oidc_cache_mutex_global_create', 'oidc_cfg_parse_option', 'oidc_http_hdr_in_get']

mod_auth_openidc/test/fuzz/fuzz_cookie.c

Dictionary

Use this with the libFuzzer -dict=DICT.file flag


Fuzzer function priority

Use one of these functions as input to libfuzzer with flag: -focus_function name

-focus_function=['oidc_json_integer_value', '_oidc_str_to_int_checked', '_oidc_jose_error_set', 'oidc_json_decref', 'oidc_util_url_cur_is_secure', 'cjose_jwk_release', 'oidc_json_object_get', '_oidc_strstr', 'oidc_alg2kty', 'oidc_json_parse']

mod_auth_openidc/test/fuzz/fuzz_jwks.c

Dictionary

Use this with the libFuzzer -dict=DICT.file flag


Fuzzer function priority

Use one of these functions as input to libfuzzer with flag: -focus_function name

-focus_function=['_oidc_strstr', 'oidc_cfg_post_config', '_oidc_jwk_rsa_key_to_jwk', '_cjose_jwk_import_OKP', 'oidc_json_decref', 'oidc_json_parse', 'cjose_jwk_release', 'oidc_cache_mutex_global_create', '_oidc_strnatcasecmp', 'oidc_cfg_parse_option']

mod_auth_openidc/test/fuzz/fuzz_metadata.c

Dictionary

Use this with the libFuzzer -dict=DICT.file flag


Fuzzer function priority

Use one of these functions as input to libfuzzer with flag: -focus_function name

-focus_function=['cjose_jwk_import_json', '_oidc_jwk_parse_x5c_spec', 'oidc_cfg_post_config', 'oidc_json_integer_value', 'oidc_json_decref', 'oidc_jwk_parse', 'oidc_jwk_list_destroy', 'oidc_cfg_provider_signed_jwks_uri_keys_set', 'oidc_json_object_get', '_oidc_strstr']

mod_auth_openidc/test/fuzz/fuzz_authz_response.c

Dictionary

Use this with the libFuzzer -dict=DICT.file flag


Fuzzer function priority

Use one of these functions as input to libfuzzer with flag: -focus_function name

-focus_function=['oidc_http_request', 'oidc_cfg_endpoint_auth_is_mtls', 'oidc_get_provider_for_issuer', 'oidc_jose_get_string', 'oidc_userinfo_retrieve_claims', 'oidc_proto_profile_id_token_aud_values_get', 'oidc_util_url_cur_host', 'oidc_proto_jwt_validate', 'oidc_proto_endpoint_client_secret_basic', 'oidc_json_integer_value']

mod_auth_openidc/test/fuzz/fuzz_jwt.c

Dictionary

Use this with the libFuzzer -dict=DICT.file flag


Fuzzer function priority

Use one of these functions as input to libfuzzer with flag: -focus_function name

-focus_function=['_cjose_base64_encode_impl', '_oidc_strstr', 'oidc_jwk_new', 'oidc_cfg_post_config', '_cjose_jwk_import_oct', 'oidc_jose_get_string', 'oidc_json_parse', 'oidc_json_decref', 'oidc_jwt_parse', 'cjose_const_memcmp']

mod_auth_openidc/test/fuzz/fuzz_discovery_response.c

Dictionary

Use this with the libFuzzer -dict=DICT.file flag


Fuzzer function priority

Use one of these functions as input to libfuzzer with flag: -focus_function name

-focus_function=['oidc_request_authenticate_user', 'oidc_proto_profile_ops', 'oidc_proto_request_auth_params_set', 'oidc_http_query_encoded_url', 'oidc_proto_profile_auth_request_method_get', 'oidc_util_jwt_verify', 'oidc_response_post_preserve_javascript', 'oidc_util_jwt_create', 'oidc_json_integer', 'oidc_util_base64url_encode']

mod_auth_openidc/test/fuzz/fuzz_current_url.c

Dictionary

Use this with the libFuzzer -dict=DICT.file flag


Fuzzer function priority

Use one of these functions as input to libfuzzer with flag: -focus_function name

-focus_function=['_oidc_strstr', 'oidc_cfg_post_config', 'oidc_cfg_server_alloc', 'oidc_check_x_forwarded_hdr', 'oidc_cache_mutex_global_create', '_oidc_strnatcasecmp', 'oidc_cfg_parse_option', 'oidc_http_curl_pool_init', 'oidc_test_crypto_passphrase_derive_keys_cached']

mod_auth_openidc/test/fuzz/fuzz_bearer_token.c

Dictionary

Use this with the libFuzzer -dict=DICT.file flag


Fuzzer function priority

Use one of these functions as input to libfuzzer with flag: -focus_function name

-focus_function=['oidc_oauth_provider_config', 'cjose_const_memcmp', 'oidc_jwt_verify', 'oidc_oauth_get_cached_access_token', 'oidc_util_url_redirect_uri', 'oidc_json_integer_value', 'oidc_json_array_get', 'oidc_jwt_alg2kty', 'oidc_get_remote_user', 'oidc_cfg_post_config']

mod_auth_openidc/test/fuzz/fuzz_state_cookie.c

Dictionary

Use this with the libFuzzer -dict=DICT.file flag


Fuzzer function priority

Use one of these functions as input to libfuzzer with flag: -focus_function name

-focus_function=['oidc_cfg_post_config', 'oidc_json_integer_value', '_oidc_jose_error_set', 'oidc_json_decref', 'cjose_jwk_release', '_oidc_strstr', 'oidc_json_parse', 'oidc_json_object_set_new', '_cjose_header_validate_crit', 'oidc_cache_mutex_global_create']

mod_auth_openidc/test/fuzz/fuzz_backchannel_logout.c

Dictionary

Use this with the libFuzzer -dict=DICT.file flag


Fuzzer function priority

Use one of these functions as input to libfuzzer with flag: -focus_function name

-focus_function=['oidc_json_array_get', 'oidc_logout', 'oidc_proto_profile_ops', 'oidc_get_provider_for_issuer', 'oidc_proto_profile_id_token_aud_values_get', 'oidc_jose_get_string', 'oidc_util_url_cur_host', 'oidc_json_array_has_value', 'oidc_proto_validate_iat', 'oidc_json_integer_value']

mod_auth_openidc/test/fuzz/fuzz_redirect_uri.c

Dictionary

Use this with the libFuzzer -dict=DICT.file flag


Fuzzer function priority

Use one of these functions as input to libfuzzer with flag: -focus_function name

-focus_function=['oidc_cfg_endpoint_auth_is_mtls', 'oidc_http_request', 'oidc_jwt_parse', 'oidc_util_rand_str', 'oidc_refresh_token_grant_obtain_tokens', 'oidc_proto_token_endpoint_call', 'oidc_util_url_cur_host', 'oidc_proto_endpoint_client_secret_basic', 'oidc_util_read_post_params_impl', 'oidc_session_get_idtoken']

mod_auth_openidc/test/fuzz/fuzz_post_preserve.c

Dictionary

Use this with the libFuzzer -dict=DICT.file flag


Fuzzer function priority

Use one of these functions as input to libfuzzer with flag: -focus_function name

-focus_function=['_oidc_strstr', 'oidc_cfg_post_config', 'oidc_http_hdr_in_get', 'oidc_response_post_preserve_javascript', 'oidc_original_request_method', 'oidc_cfg_server_alloc', 'oidc_util_html_javascript_escape', 'oidc_util_read_form_encoded_params_impl', 'oidc_cache_mutex_global_create', '_oidc_strnatcasecmp']

Runtime coverage analysis

This section shows analysis of runtime coverage data.

For futher technical details on how this section is generated, please see the Glossary .

Complex functions with low coverage

Func name Function total lines Lines covered at runtime percentage covered Reached by fuzzers
cjose_jwk_to_json 69 35 50.72% ['fuzz_discovery_response', 'fuzz_authz_response', 'fuzz_pem_key', 'fuzz_redirect_uri', 'fuzz_bearer_token', 'fuzz_backchannel_logout', 'fuzz_jwks']
_cjose_jwk_RSA_private_fields 34 16 47.05% ['fuzz_pem_key', 'fuzz_jwks']
_cjose_header_validate_crit 47 10 21.27% ['fuzz_discovery_response', 'fuzz_cookie', 'fuzz_authz_response', 'fuzz_jwt', 'fuzz_bearer_token', 'fuzz_backchannel_logout', 'fuzz_state_cookie', 'fuzz_redirect_uri']
_cjose_jwe_validate_decrypt_key 31 14 45.16% ['fuzz_discovery_response', 'fuzz_cookie', 'fuzz_authz_response', 'fuzz_jwt', 'fuzz_bearer_token', 'fuzz_backchannel_logout', 'fuzz_state_cookie', 'fuzz_redirect_uri']
oidc_state_cookies_delete_oldest 31 8 25.80% ['fuzz_redirect_uri', 'fuzz_authz_response', 'fuzz_discovery_response', 'fuzz_cookie']
cjose_jwe_encrypt_multi_iv 101 35 34.65% ['fuzz_discovery_response', 'fuzz_authz_response', 'fuzz_redirect_uri', 'fuzz_bearer_token', 'fuzz_backchannel_logout']
_cjose_jwe_encrypt_dat_aes_gcm 86 34 39.53% ['fuzz_discovery_response', 'fuzz_authz_response', 'fuzz_redirect_uri', 'fuzz_bearer_token', 'fuzz_backchannel_logout']
cjose_jws_sign 46 14 30.43% ['fuzz_discovery_response', 'fuzz_authz_response', 'fuzz_redirect_uri', 'fuzz_bearer_token', 'fuzz_backchannel_logout']
_cjose_jws_build_dig_hmac_sha 85 41 48.23% ['fuzz_jwt', 'fuzz_bearer_token', 'fuzz_authz_response', 'fuzz_backchannel_logout']
_cjose_jws_validate_verify_key 47 19 40.42% ['fuzz_discovery_response', 'fuzz_authz_response', 'fuzz_jwt', 'fuzz_bearer_token', 'fuzz_backchannel_logout', 'fuzz_redirect_uri']
oidc_response_proto_state_restore 41 21 51.21% ['fuzz_redirect_uri', 'fuzz_authz_response']
oidc_userinfo_retrieve_claims 66 15 22.72% ['fuzz_redirect_uri', 'fuzz_authz_response']
oidc_http_request 102 23 22.54% ['fuzz_discovery_response', 'fuzz_authz_response', 'fuzz_redirect_uri', 'fuzz_bearer_token', 'fuzz_backchannel_logout']
oidc_provider_static_config 38 8 21.05% ['fuzz_redirect_uri', 'fuzz_authz_response', 'fuzz_discovery_response', 'fuzz_backchannel_logout']
oidc_proto_token_endpoint_auth 41 10 24.39% ['fuzz_discovery_response', 'fuzz_authz_response', 'fuzz_redirect_uri', 'fuzz_bearer_token', 'fuzz_backchannel_logout']
oidc_proto_idtoken_validate_aud_array 36 17 47.22% ['fuzz_redirect_uri', 'fuzz_authz_response', 'fuzz_backchannel_logout']
oidc_proto_jwt_verify 53 27 50.94% ['fuzz_redirect_uri', 'fuzz_bearer_token', 'fuzz_authz_response', 'fuzz_backchannel_logout']
oidc_proto_resolve_code_and_validate_response 40 18 45.0% ['fuzz_redirect_uri', 'fuzz_authz_response']
oidc_util_set_trace_parent 54 14 25.92% ['fuzz_redirect_uri', 'fuzz_bearer_token', 'fuzz_authz_response', 'fuzz_backchannel_logout']
_cjose_jwe_decrypt_dat_aes_cbc 85 38 44.70% ['fuzz_jwt']
_cjose_jws_build_dig_sha 77 40 51.94% ['fuzz_jwt']
oidc_request_check_cookie_domain 39 21 53.84% ['fuzz_redirect_uri', 'fuzz_discovery_response']
oidc_oauth_get_cached_access_token 31 17 54.83% ['fuzz_bearer_token']
oidc_oauth_parse_and_cache_token_expiry 39 12 30.76% ['fuzz_bearer_token']
oidc_logout_cleanup_by_sid 33 17 51.51% ['fuzz_redirect_uri', 'fuzz_backchannel_logout']
oidc_dpop_request 59 19 32.20% ['fuzz_redirect_uri']
oidc_info_request 46 21 45.65% ['fuzz_redirect_uri']
oidc_logout_revoke_tokens 32 16 50.0% ['fuzz_redirect_uri', 'fuzz_backchannel_logout']
oidc_refresh_token_grant 36 16 44.44% ['fuzz_redirect_uri', 'fuzz_authz_response', 'fuzz_backchannel_logout']
oidc_refresh_token_cache_get 46 24 52.17% ['fuzz_redirect_uri', 'fuzz_authz_response', 'fuzz_backchannel_logout']
oidc_handle_existing_session 48 15 31.25% ['fuzz_redirect_uri']

Files and Directories in report

This section shows which files and directories are considered in this report. The main reason for showing this is fuzz introspector may include more code in the reasoning than is desired. This section helps identify if too many files/directories are included, e.g. third party code, which may be irrelevant for the threat model. In the event too much is included, fuzz introspector supports a configuration file that can exclude data from the report. See the following link for more information on how to create a config file: link

Files in report

Source file Reached by Covered by
[] []
/src/cjose/src/jws.c ['fuzz_authz_response', 'fuzz_jwt', 'fuzz_discovery_response', 'fuzz_bearer_token', 'fuzz_backchannel_logout', 'fuzz_redirect_uri'] ['fuzz_authz_response', 'fuzz_jwt', 'fuzz_bearer_token', 'fuzz_backchannel_logout', 'fuzz_redirect_uri']
/src/mod_auth_openidc/src/proto/discovery.c ['fuzz_discovery_response'] []
/src/mod_auth_openidc/src/handle/logout.c ['fuzz_backchannel_logout'] ['fuzz_backchannel_logout']
/src/mod_auth_openidc/test/fuzz/fuzz_current_url.c ['fuzz_current_url'] ['fuzz_current_url']
/src/mod_auth_openidc/src/proto/jwt.c ['fuzz_strings', 'fuzz_cookie', 'fuzz_authz_response', 'fuzz_discovery_response', 'fuzz_bearer_token', 'fuzz_state_cookie', 'fuzz_backchannel_logout', 'fuzz_redirect_uri'] ['fuzz_strings', 'fuzz_cookie', 'fuzz_authz_response', 'fuzz_discovery_response', 'fuzz_bearer_token', 'fuzz_state_cookie', 'fuzz_backchannel_logout', 'fuzz_redirect_uri']
/src/mod_auth_openidc/src/util/util.c ['fuzz_form_params', 'fuzz_url', 'fuzz_strings', 'fuzz_cookie', 'fuzz_metadata', 'fuzz_authz_response', 'fuzz_discovery_response', 'fuzz_current_url', 'fuzz_bearer_token', 'fuzz_backchannel_logout', 'fuzz_redirect_uri', 'fuzz_post_preserve'] ['fuzz_form_params', 'fuzz_url', 'fuzz_strings', 'fuzz_metadata', 'fuzz_authz_response', 'fuzz_discovery_response', 'fuzz_current_url', 'fuzz_bearer_token', 'fuzz_backchannel_logout', 'fuzz_redirect_uri', 'fuzz_post_preserve']
/src/mod_auth_openidc/test/fuzz/fuzz_authz_response.c ['fuzz_authz_response'] ['fuzz_authz_response']
/src/mod_auth_openidc/test/fuzz/fuzz_strings.c ['fuzz_strings'] ['fuzz_strings']
/src/mod_auth_openidc/src/cfg/provider.c ['fuzz_form_params', 'fuzz_base64', 'fuzz_url', 'fuzz_response_header', 'fuzz_json', 'fuzz_pem_key', 'fuzz_strings', 'fuzz_cookie', 'fuzz_jwks', 'fuzz_metadata', 'fuzz_authz_response', 'fuzz_jwt', 'fuzz_discovery_response', 'fuzz_current_url', 'fuzz_bearer_token', 'fuzz_state_cookie', 'fuzz_backchannel_logout', 'fuzz_redirect_uri', 'fuzz_post_preserve'] ['fuzz_form_params', 'fuzz_base64', 'fuzz_url', 'fuzz_response_header', 'fuzz_json', 'fuzz_pem_key', 'fuzz_strings', 'fuzz_cookie', 'fuzz_jwks', 'fuzz_metadata', 'fuzz_authz_response', 'fuzz_jwt', 'fuzz_discovery_response', 'fuzz_current_url', 'fuzz_bearer_token', 'fuzz_state_cookie', 'fuzz_backchannel_logout', 'fuzz_redirect_uri', 'fuzz_post_preserve']
/src/mod_auth_openidc/src/proto/dpop.c ['fuzz_authz_response', 'fuzz_backchannel_logout', 'fuzz_redirect_uri'] []
/src/mod_auth_openidc/src/mod_auth_openidc.c ['fuzz_url', 'fuzz_authz_response', 'fuzz_discovery_response', 'fuzz_bearer_token', 'fuzz_backchannel_logout', 'fuzz_redirect_uri', 'fuzz_post_preserve'] ['fuzz_url', 'fuzz_authz_response', 'fuzz_discovery_response', 'fuzz_bearer_token', 'fuzz_backchannel_logout', 'fuzz_redirect_uri', 'fuzz_post_preserve']
/src/cjose/src/jwe.c ['fuzz_cookie', 'fuzz_authz_response', 'fuzz_jwt', 'fuzz_discovery_response', 'fuzz_bearer_token', 'fuzz_state_cookie', 'fuzz_backchannel_logout', 'fuzz_redirect_uri'] ['fuzz_cookie', 'fuzz_authz_response', 'fuzz_jwt', 'fuzz_discovery_response', 'fuzz_bearer_token', 'fuzz_state_cookie', 'fuzz_backchannel_logout', 'fuzz_redirect_uri']
/src/mod_auth_openidc/src/jose/jwe.c ['fuzz_cookie', 'fuzz_authz_response', 'fuzz_jwt', 'fuzz_discovery_response', 'fuzz_bearer_token', 'fuzz_state_cookie', 'fuzz_backchannel_logout', 'fuzz_redirect_uri'] ['fuzz_cookie', 'fuzz_authz_response', 'fuzz_jwt', 'fuzz_discovery_response', 'fuzz_bearer_token', 'fuzz_state_cookie', 'fuzz_backchannel_logout', 'fuzz_redirect_uri']
/src/mod_auth_openidc/src/cache/memcache.c [] []
/src/mod_auth_openidc/src/util/html.c ['fuzz_strings', 'fuzz_authz_response', 'fuzz_discovery_response', 'fuzz_backchannel_logout', 'fuzz_redirect_uri', 'fuzz_post_preserve'] ['fuzz_strings', 'fuzz_authz_response', 'fuzz_discovery_response', 'fuzz_backchannel_logout', 'fuzz_redirect_uri', 'fuzz_post_preserve']
/src/mod_auth_openidc/test/fuzz/fuzz_base64.c ['fuzz_base64'] ['fuzz_base64']
/src/mod_auth_openidc/src/./const.h ['fuzz_form_params', 'fuzz_base64', 'fuzz_url', 'fuzz_response_header', 'fuzz_json', 'fuzz_pem_key', 'fuzz_strings', 'fuzz_cookie', 'fuzz_jwks', 'fuzz_metadata', 'fuzz_authz_response', 'fuzz_jwt', 'fuzz_discovery_response', 'fuzz_current_url', 'fuzz_bearer_token', 'fuzz_state_cookie', 'fuzz_backchannel_logout', 'fuzz_redirect_uri', 'fuzz_post_preserve'] []
/src/mod_auth_openidc/src/handle/refresh.c ['fuzz_authz_response', 'fuzz_backchannel_logout', 'fuzz_redirect_uri'] ['fuzz_redirect_uri']
/src/mod_auth_openidc/src/proto/state.c ['fuzz_cookie', 'fuzz_authz_response', 'fuzz_discovery_response', 'fuzz_state_cookie', 'fuzz_redirect_uri'] ['fuzz_cookie', 'fuzz_authz_response', 'fuzz_discovery_response', 'fuzz_state_cookie', 'fuzz_redirect_uri']
/src/mod_auth_openidc/test/fuzz/fuzz_jwks.c ['fuzz_jwks'] ['fuzz_jwks']
/src/cjose/src/header.c ['fuzz_cookie', 'fuzz_authz_response', 'fuzz_jwt', 'fuzz_discovery_response', 'fuzz_bearer_token', 'fuzz_state_cookie', 'fuzz_backchannel_logout', 'fuzz_redirect_uri'] ['fuzz_cookie', 'fuzz_authz_response', 'fuzz_jwt', 'fuzz_discovery_response', 'fuzz_bearer_token', 'fuzz_state_cookie', 'fuzz_backchannel_logout', 'fuzz_redirect_uri']
/src/mod_auth_openidc/src/proto/response.c ['fuzz_authz_response', 'fuzz_redirect_uri'] ['fuzz_authz_response', 'fuzz_redirect_uri']
/src/mod_auth_openidc/src/util/expr.c ['fuzz_url', 'fuzz_authz_response', 'fuzz_discovery_response', 'fuzz_bearer_token', 'fuzz_backchannel_logout', 'fuzz_redirect_uri'] ['fuzz_url', 'fuzz_redirect_uri']
/src/mod_auth_openidc/test/fuzz/fuzz_cookie.c ['fuzz_cookie'] ['fuzz_cookie']
/src/mod_auth_openidc/src/util/pcre_subst.c ['fuzz_url', 'fuzz_authz_response', 'fuzz_discovery_response', 'fuzz_bearer_token', 'fuzz_backchannel_logout', 'fuzz_redirect_uri'] ['fuzz_url']
/src/mod_auth_openidc/src/cfg/check.c [] []
/src/mod_auth_openidc/test/fuzz/fuzz_url.c ['fuzz_url'] ['fuzz_url']
/src/mod_auth_openidc/test/fuzz/fuzz_jwt.c ['fuzz_jwt'] ['fuzz_jwt']
/src/mod_auth_openidc/src/handle/authz.c [] []
/src/mod_auth_openidc/src/util/random.c ['fuzz_form_params', 'fuzz_base64', 'fuzz_url', 'fuzz_response_header', 'fuzz_json', 'fuzz_pem_key', 'fuzz_strings', 'fuzz_cookie', 'fuzz_jwks', 'fuzz_metadata', 'fuzz_authz_response', 'fuzz_jwt', 'fuzz_discovery_response', 'fuzz_current_url', 'fuzz_bearer_token', 'fuzz_state_cookie', 'fuzz_backchannel_logout', 'fuzz_redirect_uri', 'fuzz_post_preserve'] ['fuzz_authz_response', 'fuzz_discovery_response', 'fuzz_backchannel_logout', 'fuzz_redirect_uri']
/src/mod_auth_openidc/src/util/request_state.c ['fuzz_authz_response', 'fuzz_discovery_response', 'fuzz_bearer_token', 'fuzz_backchannel_logout', 'fuzz_redirect_uri', 'fuzz_post_preserve'] ['fuzz_authz_response', 'fuzz_bearer_token', 'fuzz_backchannel_logout', 'fuzz_redirect_uri']
/src/mod_auth_openidc/src/metadata/jwks.c ['fuzz_authz_response', 'fuzz_discovery_response', 'fuzz_bearer_token', 'fuzz_backchannel_logout', 'fuzz_redirect_uri'] []
/src/cjose/src/jwk.c ['fuzz_form_params', 'fuzz_base64', 'fuzz_url', 'fuzz_response_header', 'fuzz_json', 'fuzz_pem_key', 'fuzz_strings', 'fuzz_cookie', 'fuzz_jwks', 'fuzz_metadata', 'fuzz_authz_response', 'fuzz_jwt', 'fuzz_discovery_response', 'fuzz_current_url', 'fuzz_bearer_token', 'fuzz_state_cookie', 'fuzz_backchannel_logout', 'fuzz_redirect_uri', 'fuzz_post_preserve'] ['fuzz_pem_key', 'fuzz_cookie', 'fuzz_jwks', 'fuzz_metadata', 'fuzz_authz_response', 'fuzz_jwt', 'fuzz_discovery_response', 'fuzz_bearer_token', 'fuzz_state_cookie', 'fuzz_backchannel_logout', 'fuzz_redirect_uri']
/src/mod_auth_openidc/src/metadata.c ['fuzz_authz_response', 'fuzz_discovery_response', 'fuzz_backchannel_logout', 'fuzz_redirect_uri'] []
/src/mod_auth_openidc/test/fuzz/fuzz_json.c ['fuzz_json'] ['fuzz_json']
/src/mod_auth_openidc/src/cache/file.c [] []
/src/mod_auth_openidc/src/handle/session_management.c [] []
/src/mod_auth_openidc/src/metadata/conf.c ['fuzz_metadata', 'fuzz_authz_response', 'fuzz_discovery_response', 'fuzz_backchannel_logout', 'fuzz_redirect_uri'] ['fuzz_metadata']
/src/mod_auth_openidc/test/fuzz/fuzz_redirect_uri.c ['fuzz_redirect_uri'] ['fuzz_redirect_uri']
/src/mod_auth_openidc/test/fuzz/fuzz_post_preserve.c ['fuzz_post_preserve'] ['fuzz_post_preserve']
/src/mod_auth_openidc/src/metadata/oauth.c ['fuzz_bearer_token'] []
/src/mod_auth_openidc/src/handle/revoke.c ['fuzz_bearer_token'] []
/src/mod_auth_openidc/test/fuzz/fuzz_state_cookie.c ['fuzz_state_cookie'] ['fuzz_state_cookie']
/src/mod_auth_openidc/src/proto/id_token.c ['fuzz_authz_response', 'fuzz_backchannel_logout', 'fuzz_redirect_uri'] ['fuzz_authz_response', 'fuzz_backchannel_logout']
/src/mod_auth_openidc/src/proto/request.c ['fuzz_discovery_response'] ['fuzz_discovery_response']
/src/mod_auth_openidc/src/handle/response.c ['fuzz_authz_response', 'fuzz_discovery_response', 'fuzz_backchannel_logout', 'fuzz_redirect_uri', 'fuzz_post_preserve'] ['fuzz_authz_response', 'fuzz_discovery_response', 'fuzz_backchannel_logout', 'fuzz_redirect_uri', 'fuzz_post_preserve']
/src/mod_auth_openidc/src/cache/common.c ['fuzz_form_params', 'fuzz_base64', 'fuzz_url', 'fuzz_response_header', 'fuzz_json', 'fuzz_pem_key', 'fuzz_strings', 'fuzz_cookie', 'fuzz_jwks', 'fuzz_metadata', 'fuzz_authz_response', 'fuzz_jwt', 'fuzz_discovery_response', 'fuzz_current_url', 'fuzz_bearer_token', 'fuzz_state_cookie', 'fuzz_backchannel_logout', 'fuzz_redirect_uri', 'fuzz_post_preserve'] ['fuzz_form_params', 'fuzz_base64', 'fuzz_url', 'fuzz_response_header', 'fuzz_json', 'fuzz_pem_key', 'fuzz_strings', 'fuzz_cookie', 'fuzz_jwks', 'fuzz_metadata', 'fuzz_authz_response', 'fuzz_jwt', 'fuzz_discovery_response', 'fuzz_current_url', 'fuzz_bearer_token', 'fuzz_state_cookie', 'fuzz_backchannel_logout', 'fuzz_redirect_uri', 'fuzz_post_preserve']
/src/mod_auth_openidc/src/handle/userinfo.c ['fuzz_authz_response', 'fuzz_redirect_uri'] ['fuzz_authz_response']
/src/mod_auth_openidc/test/stub.c ['fuzz_form_params', 'fuzz_base64', 'fuzz_url', 'fuzz_response_header', 'fuzz_json', 'fuzz_pem_key', 'fuzz_strings', 'fuzz_cookie', 'fuzz_jwks', 'fuzz_metadata', 'fuzz_authz_response', 'fuzz_jwt', 'fuzz_discovery_response', 'fuzz_current_url', 'fuzz_bearer_token', 'fuzz_state_cookie', 'fuzz_backchannel_logout', 'fuzz_redirect_uri', 'fuzz_post_preserve'] ['fuzz_form_params', 'fuzz_base64', 'fuzz_url', 'fuzz_response_header', 'fuzz_json', 'fuzz_pem_key', 'fuzz_strings', 'fuzz_cookie', 'fuzz_jwks', 'fuzz_metadata', 'fuzz_authz_response', 'fuzz_jwt', 'fuzz_discovery_response', 'fuzz_current_url', 'fuzz_bearer_token', 'fuzz_state_cookie', 'fuzz_backchannel_logout', 'fuzz_redirect_uri', 'fuzz_post_preserve']
/src/mod_auth_openidc/src/cfg/cache.c ['fuzz_form_params', 'fuzz_base64', 'fuzz_url', 'fuzz_response_header', 'fuzz_json', 'fuzz_pem_key', 'fuzz_strings', 'fuzz_cookie', 'fuzz_jwks', 'fuzz_metadata', 'fuzz_authz_response', 'fuzz_jwt', 'fuzz_discovery_response', 'fuzz_current_url', 'fuzz_bearer_token', 'fuzz_state_cookie', 'fuzz_backchannel_logout', 'fuzz_redirect_uri', 'fuzz_post_preserve'] ['fuzz_form_params', 'fuzz_base64', 'fuzz_url', 'fuzz_response_header', 'fuzz_json', 'fuzz_pem_key', 'fuzz_strings', 'fuzz_cookie', 'fuzz_jwks', 'fuzz_metadata', 'fuzz_authz_response', 'fuzz_jwt', 'fuzz_discovery_response', 'fuzz_current_url', 'fuzz_bearer_token', 'fuzz_state_cookie', 'fuzz_backchannel_logout', 'fuzz_redirect_uri', 'fuzz_post_preserve']
/src/mod_auth_openidc/src/proto/pkce.c [] []
/src/mod_auth_openidc/src/cfg/dir.c ['fuzz_form_params', 'fuzz_base64', 'fuzz_url', 'fuzz_response_header', 'fuzz_json', 'fuzz_pem_key', 'fuzz_strings', 'fuzz_cookie', 'fuzz_jwks', 'fuzz_metadata', 'fuzz_authz_response', 'fuzz_jwt', 'fuzz_discovery_response', 'fuzz_current_url', 'fuzz_bearer_token', 'fuzz_state_cookie', 'fuzz_backchannel_logout', 'fuzz_redirect_uri', 'fuzz_post_preserve'] ['fuzz_form_params', 'fuzz_base64', 'fuzz_url', 'fuzz_response_header', 'fuzz_json', 'fuzz_pem_key', 'fuzz_strings', 'fuzz_cookie', 'fuzz_jwks', 'fuzz_metadata', 'fuzz_authz_response', 'fuzz_jwt', 'fuzz_discovery_response', 'fuzz_current_url', 'fuzz_bearer_token', 'fuzz_state_cookie', 'fuzz_backchannel_logout', 'fuzz_redirect_uri', 'fuzz_post_preserve']
/src/mod_auth_openidc/src/util/base64.c ['fuzz_base64', 'fuzz_pem_key', 'fuzz_strings', 'fuzz_cookie', 'fuzz_authz_response', 'fuzz_discovery_response', 'fuzz_bearer_token', 'fuzz_state_cookie', 'fuzz_backchannel_logout', 'fuzz_redirect_uri'] ['fuzz_base64', 'fuzz_pem_key', 'fuzz_strings', 'fuzz_cookie', 'fuzz_authz_response', 'fuzz_discovery_response', 'fuzz_bearer_token', 'fuzz_state_cookie', 'fuzz_backchannel_logout', 'fuzz_redirect_uri']
/src/mod_auth_openidc/src/cache/shm.c [] []
/src/mod_auth_openidc/src/metrics.c ['fuzz_form_params', 'fuzz_base64', 'fuzz_url', 'fuzz_response_header', 'fuzz_json', 'fuzz_pem_key', 'fuzz_strings', 'fuzz_cookie', 'fuzz_jwks', 'fuzz_metadata', 'fuzz_authz_response', 'fuzz_jwt', 'fuzz_discovery_response', 'fuzz_current_url', 'fuzz_bearer_token', 'fuzz_state_cookie', 'fuzz_backchannel_logout', 'fuzz_redirect_uri', 'fuzz_post_preserve'] []
/src/mod_auth_openidc/test/fuzz/fuzz_backchannel_logout.c ['fuzz_backchannel_logout'] ['fuzz_backchannel_logout']
/src/cjose/src/base64.c ['fuzz_pem_key', 'fuzz_cookie', 'fuzz_jwks', 'fuzz_metadata', 'fuzz_authz_response', 'fuzz_jwt', 'fuzz_discovery_response', 'fuzz_bearer_token', 'fuzz_state_cookie', 'fuzz_backchannel_logout', 'fuzz_redirect_uri'] ['fuzz_pem_key', 'fuzz_cookie', 'fuzz_jwks', 'fuzz_authz_response', 'fuzz_jwt', 'fuzz_discovery_response', 'fuzz_bearer_token', 'fuzz_state_cookie', 'fuzz_backchannel_logout', 'fuzz_redirect_uri']
/src/mod_auth_openidc/test/util.c ['fuzz_form_params', 'fuzz_base64', 'fuzz_url', 'fuzz_response_header', 'fuzz_json', 'fuzz_pem_key', 'fuzz_strings', 'fuzz_cookie', 'fuzz_jwks', 'fuzz_metadata', 'fuzz_authz_response', 'fuzz_jwt', 'fuzz_discovery_response', 'fuzz_current_url', 'fuzz_bearer_token', 'fuzz_state_cookie', 'fuzz_backchannel_logout', 'fuzz_redirect_uri', 'fuzz_post_preserve'] ['fuzz_form_params', 'fuzz_base64', 'fuzz_url', 'fuzz_response_header', 'fuzz_json', 'fuzz_pem_key', 'fuzz_strings', 'fuzz_cookie', 'fuzz_jwks', 'fuzz_metadata', 'fuzz_authz_response', 'fuzz_jwt', 'fuzz_discovery_response', 'fuzz_current_url', 'fuzz_bearer_token', 'fuzz_state_cookie', 'fuzz_backchannel_logout', 'fuzz_redirect_uri', 'fuzz_post_preserve']
/src/mod_auth_openidc/src/./cfg/cfg_int.h ['fuzz_authz_response', 'fuzz_discovery_response', 'fuzz_backchannel_logout', 'fuzz_redirect_uri'] []
/src/mod_auth_openidc/src/util/url.c ['fuzz_url', 'fuzz_cookie', 'fuzz_authz_response', 'fuzz_discovery_response', 'fuzz_current_url', 'fuzz_bearer_token', 'fuzz_backchannel_logout', 'fuzz_redirect_uri', 'fuzz_post_preserve'] ['fuzz_url', 'fuzz_cookie', 'fuzz_authz_response', 'fuzz_discovery_response', 'fuzz_current_url', 'fuzz_bearer_token', 'fuzz_backchannel_logout', 'fuzz_redirect_uri']
/src/mod_auth_openidc/src/util/file.c ['fuzz_authz_response', 'fuzz_discovery_response', 'fuzz_backchannel_logout', 'fuzz_redirect_uri', 'fuzz_post_preserve'] []
/src/mod_auth_openidc/src/cfg/oauth.c ['fuzz_form_params', 'fuzz_base64', 'fuzz_url', 'fuzz_response_header', 'fuzz_json', 'fuzz_pem_key', 'fuzz_strings', 'fuzz_cookie', 'fuzz_jwks', 'fuzz_metadata', 'fuzz_authz_response', 'fuzz_jwt', 'fuzz_discovery_response', 'fuzz_current_url', 'fuzz_bearer_token', 'fuzz_state_cookie', 'fuzz_backchannel_logout', 'fuzz_redirect_uri', 'fuzz_post_preserve'] ['fuzz_form_params', 'fuzz_base64', 'fuzz_url', 'fuzz_response_header', 'fuzz_json', 'fuzz_pem_key', 'fuzz_strings', 'fuzz_cookie', 'fuzz_jwks', 'fuzz_metadata', 'fuzz_authz_response', 'fuzz_jwt', 'fuzz_discovery_response', 'fuzz_current_url', 'fuzz_bearer_token', 'fuzz_state_cookie', 'fuzz_backchannel_logout', 'fuzz_redirect_uri', 'fuzz_post_preserve']
/src/mod_auth_openidc/src/json.c ['fuzz_form_params', 'fuzz_base64', 'fuzz_url', 'fuzz_response_header', 'fuzz_json', 'fuzz_pem_key', 'fuzz_strings', 'fuzz_cookie', 'fuzz_jwks', 'fuzz_metadata', 'fuzz_authz_response', 'fuzz_jwt', 'fuzz_discovery_response', 'fuzz_current_url', 'fuzz_bearer_token', 'fuzz_state_cookie', 'fuzz_backchannel_logout', 'fuzz_redirect_uri', 'fuzz_post_preserve'] ['fuzz_json', 'fuzz_pem_key', 'fuzz_strings', 'fuzz_cookie', 'fuzz_jwks', 'fuzz_metadata', 'fuzz_authz_response', 'fuzz_jwt', 'fuzz_discovery_response', 'fuzz_bearer_token', 'fuzz_state_cookie', 'fuzz_backchannel_logout', 'fuzz_redirect_uri']
/src/mod_auth_openidc/test/fuzz/fuzz_form_params.c ['fuzz_form_params'] ['fuzz_form_params']
/src/mod_auth_openidc/src/util/jwt.c ['fuzz_cookie', 'fuzz_authz_response', 'fuzz_discovery_response', 'fuzz_bearer_token', 'fuzz_state_cookie', 'fuzz_backchannel_logout', 'fuzz_redirect_uri'] ['fuzz_cookie', 'fuzz_authz_response', 'fuzz_discovery_response', 'fuzz_bearer_token', 'fuzz_state_cookie', 'fuzz_backchannel_logout', 'fuzz_redirect_uri']
/src/mod_auth_openidc/src/handle/content.c ['fuzz_redirect_uri'] ['fuzz_redirect_uri']
/src/mod_auth_openidc/src/proto/proto.c ['fuzz_metadata', 'fuzz_authz_response', 'fuzz_discovery_response', 'fuzz_bearer_token', 'fuzz_backchannel_logout', 'fuzz_redirect_uri'] ['fuzz_metadata', 'fuzz_discovery_response', 'fuzz_bearer_token', 'fuzz_redirect_uri']
/src/mod_auth_openidc/src/metadata/util.c ['fuzz_metadata', 'fuzz_authz_response', 'fuzz_discovery_response', 'fuzz_bearer_token', 'fuzz_backchannel_logout', 'fuzz_redirect_uri'] ['fuzz_metadata']
/src/mod_auth_openidc/test/fuzz/fuzz_metadata.c ['fuzz_metadata'] ['fuzz_metadata']
/src/mod_auth_openidc/src/jose/jwk.c ['fuzz_form_params', 'fuzz_base64', 'fuzz_url', 'fuzz_response_header', 'fuzz_json', 'fuzz_pem_key', 'fuzz_strings', 'fuzz_cookie', 'fuzz_jwks', 'fuzz_metadata', 'fuzz_authz_response', 'fuzz_jwt', 'fuzz_discovery_response', 'fuzz_current_url', 'fuzz_bearer_token', 'fuzz_state_cookie', 'fuzz_backchannel_logout', 'fuzz_redirect_uri', 'fuzz_post_preserve'] ['fuzz_pem_key', 'fuzz_cookie', 'fuzz_jwks', 'fuzz_metadata', 'fuzz_authz_response', 'fuzz_jwt', 'fuzz_discovery_response', 'fuzz_bearer_token', 'fuzz_state_cookie', 'fuzz_backchannel_logout', 'fuzz_redirect_uri']
/src/mod_auth_openidc/test/fuzz/fuzz_response_header.c ['fuzz_response_header'] ['fuzz_response_header']
/usr/include/jansson.h ['fuzz_form_params', 'fuzz_base64', 'fuzz_url', 'fuzz_response_header', 'fuzz_json', 'fuzz_pem_key', 'fuzz_strings', 'fuzz_cookie', 'fuzz_jwks', 'fuzz_metadata', 'fuzz_authz_response', 'fuzz_jwt', 'fuzz_discovery_response', 'fuzz_current_url', 'fuzz_bearer_token', 'fuzz_state_cookie', 'fuzz_backchannel_logout', 'fuzz_redirect_uri', 'fuzz_post_preserve'] []
/src/mod_auth_openidc/src/handle/dpop.c ['fuzz_redirect_uri'] ['fuzz_redirect_uri']
/src/mod_auth_openidc/src/proto/token.c ['fuzz_authz_response', 'fuzz_backchannel_logout', 'fuzz_redirect_uri'] ['fuzz_authz_response', 'fuzz_redirect_uri']
/src/mod_auth_openidc/src/proto/auth.c ['fuzz_authz_response', 'fuzz_discovery_response', 'fuzz_bearer_token', 'fuzz_backchannel_logout', 'fuzz_redirect_uri'] ['fuzz_authz_response', 'fuzz_redirect_uri']
/src/cjose/src/error.c ['fuzz_pem_key', 'fuzz_cookie', 'fuzz_jwks', 'fuzz_metadata', 'fuzz_authz_response', 'fuzz_jwt', 'fuzz_discovery_response', 'fuzz_bearer_token', 'fuzz_state_cookie', 'fuzz_backchannel_logout', 'fuzz_redirect_uri'] ['fuzz_pem_key', 'fuzz_cookie', 'fuzz_jwks', 'fuzz_metadata', 'fuzz_authz_response', 'fuzz_jwt', 'fuzz_discovery_response', 'fuzz_bearer_token', 'fuzz_state_cookie', 'fuzz_backchannel_logout', 'fuzz_redirect_uri']
/src/mod_auth_openidc/src/jose.c ['fuzz_pem_key', 'fuzz_strings', 'fuzz_cookie', 'fuzz_jwks', 'fuzz_metadata', 'fuzz_authz_response', 'fuzz_jwt', 'fuzz_discovery_response', 'fuzz_bearer_token', 'fuzz_state_cookie', 'fuzz_backchannel_logout', 'fuzz_redirect_uri'] ['fuzz_pem_key', 'fuzz_strings', 'fuzz_cookie', 'fuzz_jwks', 'fuzz_metadata', 'fuzz_authz_response', 'fuzz_jwt', 'fuzz_discovery_response', 'fuzz_bearer_token', 'fuzz_state_cookie', 'fuzz_backchannel_logout', 'fuzz_redirect_uri']
/src/mod_auth_openidc/src/cfg/parse.c ['fuzz_form_params', 'fuzz_base64', 'fuzz_url', 'fuzz_response_header', 'fuzz_json', 'fuzz_pem_key', 'fuzz_strings', 'fuzz_cookie', 'fuzz_jwks', 'fuzz_metadata', 'fuzz_authz_response', 'fuzz_jwt', 'fuzz_discovery_response', 'fuzz_current_url', 'fuzz_bearer_token', 'fuzz_state_cookie', 'fuzz_backchannel_logout', 'fuzz_redirect_uri', 'fuzz_post_preserve'] ['fuzz_form_params', 'fuzz_base64', 'fuzz_url', 'fuzz_response_header', 'fuzz_json', 'fuzz_pem_key', 'fuzz_strings', 'fuzz_cookie', 'fuzz_jwks', 'fuzz_metadata', 'fuzz_authz_response', 'fuzz_jwt', 'fuzz_discovery_response', 'fuzz_current_url', 'fuzz_bearer_token', 'fuzz_state_cookie', 'fuzz_backchannel_logout', 'fuzz_redirect_uri', 'fuzz_post_preserve']
/src/mod_auth_openidc/src/handle/jwks.c ['fuzz_redirect_uri'] ['fuzz_redirect_uri']
/src/mod_auth_openidc/src/proto/jwks.c ['fuzz_authz_response', 'fuzz_bearer_token', 'fuzz_backchannel_logout', 'fuzz_redirect_uri'] []
/src/mod_auth_openidc/src/proto/userinfo.c ['fuzz_authz_response', 'fuzz_redirect_uri'] []
/src/mod_auth_openidc/src/session.c ['fuzz_authz_response', 'fuzz_backchannel_logout', 'fuzz_redirect_uri'] ['fuzz_authz_response', 'fuzz_backchannel_logout', 'fuzz_redirect_uri']
/src/mod_auth_openidc/src/proto/request_object.c ['fuzz_discovery_response'] []
/src/cjose/src/util.c ['fuzz_form_params', 'fuzz_base64', 'fuzz_url', 'fuzz_response_header', 'fuzz_json', 'fuzz_pem_key', 'fuzz_strings', 'fuzz_cookie', 'fuzz_jwks', 'fuzz_metadata', 'fuzz_authz_response', 'fuzz_jwt', 'fuzz_discovery_response', 'fuzz_current_url', 'fuzz_bearer_token', 'fuzz_state_cookie', 'fuzz_backchannel_logout', 'fuzz_redirect_uri', 'fuzz_post_preserve'] ['fuzz_pem_key', 'fuzz_cookie', 'fuzz_jwks', 'fuzz_authz_response', 'fuzz_jwt', 'fuzz_discovery_response', 'fuzz_bearer_token', 'fuzz_state_cookie', 'fuzz_backchannel_logout', 'fuzz_redirect_uri']
/src/mod_auth_openidc/src/jose/jws.c ['fuzz_cookie', 'fuzz_authz_response', 'fuzz_jwt', 'fuzz_discovery_response', 'fuzz_bearer_token', 'fuzz_state_cookie', 'fuzz_backchannel_logout', 'fuzz_redirect_uri'] ['fuzz_cookie', 'fuzz_authz_response', 'fuzz_jwt', 'fuzz_discovery_response', 'fuzz_bearer_token', 'fuzz_state_cookie', 'fuzz_backchannel_logout', 'fuzz_redirect_uri']
/src/mod_auth_openidc/src/handle/info.c ['fuzz_redirect_uri'] ['fuzz_redirect_uri']
/src/mod_auth_openidc/src/proto/profile.c ['fuzz_metadata', 'fuzz_authz_response', 'fuzz_discovery_response', 'fuzz_bearer_token', 'fuzz_backchannel_logout', 'fuzz_redirect_uri'] ['fuzz_metadata', 'fuzz_authz_response', 'fuzz_discovery_response', 'fuzz_backchannel_logout', 'fuzz_redirect_uri']
/src/mod_auth_openidc/test/fuzz/fuzz_discovery_response.c ['fuzz_discovery_response'] ['fuzz_discovery_response']
/src/mod_auth_openidc/src/cfg/cfg.c ['fuzz_form_params', 'fuzz_base64', 'fuzz_url', 'fuzz_response_header', 'fuzz_json', 'fuzz_pem_key', 'fuzz_strings', 'fuzz_cookie', 'fuzz_jwks', 'fuzz_metadata', 'fuzz_authz_response', 'fuzz_jwt', 'fuzz_discovery_response', 'fuzz_current_url', 'fuzz_bearer_token', 'fuzz_state_cookie', 'fuzz_backchannel_logout', 'fuzz_redirect_uri', 'fuzz_post_preserve'] ['fuzz_form_params', 'fuzz_base64', 'fuzz_url', 'fuzz_response_header', 'fuzz_json', 'fuzz_pem_key', 'fuzz_strings', 'fuzz_cookie', 'fuzz_jwks', 'fuzz_metadata', 'fuzz_authz_response', 'fuzz_jwt', 'fuzz_discovery_response', 'fuzz_current_url', 'fuzz_bearer_token', 'fuzz_state_cookie', 'fuzz_backchannel_logout', 'fuzz_redirect_uri', 'fuzz_post_preserve']
/src/mod_auth_openidc/src/metadata/provider.c ['fuzz_metadata', 'fuzz_authz_response', 'fuzz_discovery_response', 'fuzz_backchannel_logout', 'fuzz_redirect_uri'] ['fuzz_metadata']
/src/mod_auth_openidc/src/util/key.c ['fuzz_form_params', 'fuzz_base64', 'fuzz_url', 'fuzz_response_header', 'fuzz_json', 'fuzz_pem_key', 'fuzz_strings', 'fuzz_cookie', 'fuzz_jwks', 'fuzz_metadata', 'fuzz_authz_response', 'fuzz_jwt', 'fuzz_discovery_response', 'fuzz_current_url', 'fuzz_bearer_token', 'fuzz_state_cookie', 'fuzz_backchannel_logout', 'fuzz_redirect_uri', 'fuzz_post_preserve'] ['fuzz_form_params', 'fuzz_base64', 'fuzz_url', 'fuzz_response_header', 'fuzz_json', 'fuzz_pem_key', 'fuzz_strings', 'fuzz_cookie', 'fuzz_jwks', 'fuzz_metadata', 'fuzz_authz_response', 'fuzz_jwt', 'fuzz_discovery_response', 'fuzz_current_url', 'fuzz_bearer_token', 'fuzz_state_cookie', 'fuzz_backchannel_logout', 'fuzz_redirect_uri', 'fuzz_post_preserve']
/src/mod_auth_openidc/src/handle/discovery.c ['fuzz_discovery_response', 'fuzz_redirect_uri', 'fuzz_post_preserve'] ['fuzz_discovery_response', 'fuzz_redirect_uri']
/src/mod_auth_openidc/src/./metrics.h ['fuzz_authz_response', 'fuzz_discovery_response', 'fuzz_bearer_token', 'fuzz_backchannel_logout', 'fuzz_redirect_uri'] []
/src/cjose/src/version.c ['fuzz_authz_response', 'fuzz_jwt', 'fuzz_discovery_response', 'fuzz_bearer_token', 'fuzz_backchannel_logout', 'fuzz_redirect_uri'] ['fuzz_jwt', 'fuzz_bearer_token', 'fuzz_backchannel_logout']
/src/mod_auth_openidc/src/oauth.c ['fuzz_bearer_token'] ['fuzz_bearer_token']
/src/cjose/src/concatkdf.c [] []
/src/mod_auth_openidc/src/metadata/client.c ['fuzz_metadata', 'fuzz_authz_response', 'fuzz_discovery_response', 'fuzz_backchannel_logout', 'fuzz_redirect_uri'] ['fuzz_metadata']
/src/mod_auth_openidc/src/state.c ['fuzz_strings', 'fuzz_cookie', 'fuzz_authz_response', 'fuzz_discovery_response', 'fuzz_redirect_uri'] ['fuzz_strings', 'fuzz_cookie', 'fuzz_authz_response', 'fuzz_discovery_response', 'fuzz_redirect_uri']
/src/mod_auth_openidc/test/fuzz/fuzz_bearer_token.c ['fuzz_bearer_token'] ['fuzz_bearer_token']
/src/mod_auth_openidc/src/http.c ['fuzz_form_params', 'fuzz_base64', 'fuzz_url', 'fuzz_response_header', 'fuzz_json', 'fuzz_pem_key', 'fuzz_strings', 'fuzz_cookie', 'fuzz_jwks', 'fuzz_metadata', 'fuzz_authz_response', 'fuzz_jwt', 'fuzz_discovery_response', 'fuzz_current_url', 'fuzz_bearer_token', 'fuzz_state_cookie', 'fuzz_backchannel_logout', 'fuzz_redirect_uri', 'fuzz_post_preserve'] ['fuzz_form_params', 'fuzz_base64', 'fuzz_url', 'fuzz_response_header', 'fuzz_json', 'fuzz_pem_key', 'fuzz_strings', 'fuzz_cookie', 'fuzz_jwks', 'fuzz_metadata', 'fuzz_authz_response', 'fuzz_jwt', 'fuzz_discovery_response', 'fuzz_current_url', 'fuzz_bearer_token', 'fuzz_state_cookie', 'fuzz_backchannel_logout', 'fuzz_redirect_uri', 'fuzz_post_preserve']
/src/mod_auth_openidc/src/handle/request_uri.c [] []
/src/mod_auth_openidc/test/fuzz/fuzz.h ['fuzz_strings', 'fuzz_authz_response', 'fuzz_current_url', 'fuzz_bearer_token', 'fuzz_backchannel_logout', 'fuzz_redirect_uri', 'fuzz_post_preserve'] ['fuzz_strings', 'fuzz_authz_response', 'fuzz_current_url', 'fuzz_bearer_token', 'fuzz_backchannel_logout', 'fuzz_redirect_uri', 'fuzz_post_preserve']
/src/mod_auth_openidc/test/fuzz/fuzz_pem_key.c ['fuzz_pem_key'] ['fuzz_pem_key']
/src/mod_auth_openidc/src/util/appinfo.c ['fuzz_bearer_token', 'fuzz_redirect_uri'] ['fuzz_bearer_token']
/src/mod_auth_openidc/src/handle/request.c ['fuzz_discovery_response'] ['fuzz_discovery_response']

Directories in report

Directory
/src/mod_auth_openidc/src/cache/
/src/mod_auth_openidc/src/proto/
/src/mod_auth_openidc/src/handle/
/src/mod_auth_openidc/src/util/
/src/mod_auth_openidc/src/jose/
/src/mod_auth_openidc/src/metadata/
/src/mod_auth_openidc/src/./cfg/
/src/mod_auth_openidc/test/
/src/mod_auth_openidc/src/
/src/mod_auth_openidc/test/fuzz/
/src/mod_auth_openidc/src/./
/src/cjose/src/
/usr/include/
/src/mod_auth_openidc/src/cfg/

Metadata section

This sections shows the raw data that is used to produce this report. This is mainly used for further processing and developer debugging.

Fuzzer Calltree file Program data file Coverage file
fuzz_form_params fuzzerLogFile-0-7GjgOwOinr.data fuzzerLogFile-0-7GjgOwOinr.data.yaml fuzz_form_params.covreport
fuzz_base64 fuzzerLogFile-0-scJgS6nj9u.data fuzzerLogFile-0-scJgS6nj9u.data.yaml fuzz_base64.covreport
fuzz_url fuzzerLogFile-0-RMgw9Ue46p.data fuzzerLogFile-0-RMgw9Ue46p.data.yaml fuzz_url.covreport
fuzz_response_header fuzzerLogFile-0-9DACp48Ri1.data fuzzerLogFile-0-9DACp48Ri1.data.yaml fuzz_response_header.covreport
fuzz_json fuzzerLogFile-0-AERRPWbvAb.data fuzzerLogFile-0-AERRPWbvAb.data.yaml fuzz_json.covreport
fuzz_pem_key fuzzerLogFile-0-5EgnEBlfAj.data fuzzerLogFile-0-5EgnEBlfAj.data.yaml fuzz_pem_key.covreport
fuzz_strings fuzzerLogFile-0-7745u3lcei.data fuzzerLogFile-0-7745u3lcei.data.yaml fuzz_strings.covreport
fuzz_cookie fuzzerLogFile-0-Ik7MdlX6Am.data fuzzerLogFile-0-Ik7MdlX6Am.data.yaml fuzz_cookie.covreport
fuzz_jwks fuzzerLogFile-0-zC62AfJZJ3.data fuzzerLogFile-0-zC62AfJZJ3.data.yaml fuzz_jwks.covreport
fuzz_metadata fuzzerLogFile-0-TWFzde8YUp.data fuzzerLogFile-0-TWFzde8YUp.data.yaml fuzz_metadata.covreport
fuzz_authz_response fuzzerLogFile-0-BPWNC1SvrK.data fuzzerLogFile-0-BPWNC1SvrK.data.yaml fuzz_authz_response.covreport
fuzz_jwt fuzzerLogFile-0-GxTHtvdjd7.data fuzzerLogFile-0-GxTHtvdjd7.data.yaml fuzz_jwt.covreport
fuzz_discovery_response fuzzerLogFile-0-udAmMj1Lch.data fuzzerLogFile-0-udAmMj1Lch.data.yaml fuzz_discovery_response.covreport
fuzz_current_url fuzzerLogFile-0-ElZr5e6NgM.data fuzzerLogFile-0-ElZr5e6NgM.data.yaml fuzz_current_url.covreport
fuzz_bearer_token fuzzerLogFile-0-Kfb8lmfSvZ.data fuzzerLogFile-0-Kfb8lmfSvZ.data.yaml fuzz_bearer_token.covreport
fuzz_state_cookie fuzzerLogFile-0-OqOYr5L4rr.data fuzzerLogFile-0-OqOYr5L4rr.data.yaml fuzz_state_cookie.covreport
fuzz_backchannel_logout fuzzerLogFile-0-7l9MnXJzn8.data fuzzerLogFile-0-7l9MnXJzn8.data.yaml fuzz_backchannel_logout.covreport
fuzz_redirect_uri fuzzerLogFile-0-ZxaZRvitgp.data fuzzerLogFile-0-ZxaZRvitgp.data.yaml fuzz_redirect_uri.covreport
fuzz_post_preserve fuzzerLogFile-0-GltI4QKFq4.data fuzzerLogFile-0-GltI4QKFq4.data.yaml fuzz_post_preserve.covreport