LLVMFuzzerTestOneInput:
   35|    122|extern "C" int LLVMFuzzerTestOneInput(const uint8_t* data, size_t size) {
   36|    122|    if (size < 2) return 0;
  ------------------
  |  Branch (36:9): [True: 1, False: 121]
  ------------------
   37|       |
   38|    121|    const uint8_t* payload = data;
   39|    121|    size_t payload_len = size;
   40|       |
   41|    121|    if (!validate_nsm_msg_length(payload, payload_len)) {
  ------------------
  |  Branch (41:9): [True: 3, False: 118]
  ------------------
   42|      3|        return 0;
   43|      3|    }
   44|       |
   45|    118|    const struct nsm_msg* msg = reinterpret_cast<const struct nsm_msg*>(payload);
   46|    118|    const struct nsm_msg_hdr* hdr = reinterpret_cast<const struct nsm_msg_hdr*>(payload);
   47|       |
   48|       |    // Mismatch prevention: verify request/response type
   49|    118|    if (hdr->request != false) {
  ------------------
  |  Branch (49:9): [True: 2, False: 116]
  ------------------
   50|      2|        return 0;
   51|      2|    }
   52|       |
   53|    116|    std::vector<uint8_t> out_buf(65536, 0);
   54|    116|    uint8_t fuzz_event_id = 0;
   55|    116|    uint8_t fuzz_event_class = 0;
   56|    116|    std::vector<uint8_t> fuzz_event_state_buf(65536, 0);
   57|    116|    uint16_t* fuzz_event_state = reinterpret_cast<uint16_t*>(fuzz_event_state_buf.data());
   58|    116|    uint8_t fuzz_data_size = 0;
   59|    116|    decode_nsm_event(msg, payload_len, fuzz_event_id, fuzz_event_class, fuzz_event_state, &fuzz_data_size);
   60|       |
   61|    116|    return 0;
   62|    118|}

_Z23validate_nsm_msg_lengthPKhm:
   27|    121|inline bool validate_nsm_msg_length(const uint8_t* payload, size_t payload_len) {
   28|    121|    return payload_len >= sizeof(struct nsm_msg_hdr);
   29|    121|}

decode_nsm_event:
  808|    116|{
  809|    116|	if (msg == NULL || event_state == NULL || data_size == NULL) {
  ------------------
  |  Branch (809:6): [True: 0, False: 116]
  |  Branch (809:21): [True: 0, False: 116]
  |  Branch (809:44): [True: 0, False: 116]
  ------------------
  810|      0|		return NSM_SW_ERROR_NULL;
  811|      0|	}
  812|       |
  813|    116|	if (msg_len < sizeof(struct nsm_msg_hdr) + NSM_EVENT_MIN_LEN) {
  ------------------
  |  |   49|    116|#define NSM_EVENT_MIN_LEN 6
  ------------------
  |  Branch (813:6): [True: 5, False: 111]
  ------------------
  814|      5|		return NSM_SW_ERROR_LENGTH;
  815|      5|	}
  816|       |
  817|    111|	struct nsm_event *event = (struct nsm_event *)msg->payload;
  818|       |
  819|    111|	if (event_id != event->event_id || event_class != event->event_class) {
  ------------------
  |  Branch (819:6): [True: 14, False: 97]
  |  Branch (819:37): [True: 11, False: 86]
  ------------------
  820|     25|		return NSM_SW_ERROR_DATA;
  821|     25|	}
  822|     86|	*event_state = le16toh(event->event_state);
  823|     86|	*data_size = event->data_size;
  824|       |
  825|     86|	if (msg_len < (sizeof(struct nsm_msg_hdr) + NSM_EVENT_MIN_LEN +
  ------------------
  |  |   49|     86|#define NSM_EVENT_MIN_LEN 6
  ------------------
  |  Branch (825:6): [True: 10, False: 76]
  ------------------
  826|     86|		       event->data_size)) {
  827|     10|		return NSM_SW_ERROR_LENGTH;
  828|     10|	}
  829|       |
  830|     76|	return NSM_SW_SUCCESS;
  831|     86|}

