LLVMFuzzerTestOneInput:
   26|    572|LLVMFuzzerTestOneInput(const uint8_t *data, size_t size) {
   27|    572|    if(size >= MAX_PACKET_LEN)
  ------------------
  |  |   55|    572|#define MAX_PACKET_LEN 65535
  ------------------
  |  Branch (27:8): [True: 3, False: 569]
  ------------------
   28|      3|        return 0;
   29|    569|    memcpy(message_buf, data, size);
   30|    569|    message_buf[size] = 0; /* zero terminate */
   31|       |
   32|    569|    struct message m;
   33|    569|    memset(&m, 0, sizeof(struct message));
   34|       |
   35|    569|    int parseResult = message_parse(&m, message_buf);
   36|    569|    if(!parseResult)
  ------------------
  |  Branch (36:8): [True: 362, False: 207]
  ------------------
   37|    362|        return 0;
   38|       |
   39|    207|    mdns_daemon_t *d = mdnsd_new(QCLASS_IN, 1000);
  ------------------
  |  |   40|    207|#define QCLASS_IN (1)
  ------------------
   40|       |
   41|    207|    inet_addr_t from = {};
   42|    207|    inet_anyaddr(AF_INET, 2000, &from);
   43|    207|    mdnsd_in(d, &m, &from);
   44|    207|    mdnsd_free(d);
   45|       |
   46|    207|    return 0;
   47|    569|}

net2short:
   37|  1.22M|{
   38|  1.22M|	unsigned short int i;
   39|       |
   40|  1.22M|	i = **bufp;
   41|  1.22M|	i <<= 8;
   42|  1.22M|	i |= *(*bufp + 1);
   43|  1.22M|	*bufp += 2;
   44|       |
   45|  1.22M|	return i;
   46|  1.22M|}
net2long:
   49|   123k|{
   50|   123k|	long int l;
   51|       |
   52|   123k|	l = **bufp;
   53|   123k|	l <<= 8;
   54|   123k|	l |= *(*bufp + 1);
   55|   123k|	l <<= 8;
   56|   123k|	l |= *(*bufp + 2);
   57|   123k|	l <<= 8;
   58|   123k|	l |= *(*bufp + 3);
   59|   123k|	*bufp += 4;
   60|       |
   61|   123k|	return l;
   62|   123k|}
message_parse:
  356|    569|{
  357|    569|	int i;
  358|    569|	unsigned char *buf;
  359|       |
  360|    569|	if (packet == 0 || m == 0)
  ------------------
  |  Branch (360:6): [True: 0, False: 569]
  |  Branch (360:21): [True: 0, False: 569]
  ------------------
  361|      0|		return 1;
  362|       |
  363|       |	/* Header stuff bit crap */
  364|    569|	m->_buf = buf = packet;
  365|    569|	m->id = net2short(&buf);
  366|    569|	if (buf[0] & 0x80)
  ------------------
  |  Branch (366:6): [True: 286, False: 283]
  ------------------
  367|    286|		m->header.qr = 1;
  368|    569|	m->header.opcode = (buf[0] & 0x78) >> 3;
  369|    569|	if (buf[0] & 0x04)
  ------------------
  |  Branch (369:6): [True: 193, False: 376]
  ------------------
  370|    193|		m->header.aa = 1;
  371|    569|	if (buf[0] & 0x02)
  ------------------
  |  Branch (371:6): [True: 186, False: 383]
  ------------------
  372|    186|		m->header.tc = 1;
  373|    569|	if (buf[0] & 0x01)
  ------------------
  |  Branch (373:6): [True: 303, False: 266]
  ------------------
  374|    303|		m->header.rd = 1;
  375|    569|	if (buf[1] & 0x80)
  ------------------
  |  Branch (375:6): [True: 136, False: 433]
  ------------------
  376|    136|		m->header.ra = 1;
  377|    569|	m->header.z = (buf[1] & 0x70) >> 4;
  378|    569|	m->header.rcode = buf[1] & 0x0F;
  379|    569|	buf += 2;
  380|       |
  381|    569|	m->qdcount = net2short(&buf);
  382|    569|	if (m->_len + (sizeof(struct question) * m->qdcount) > MAX_PACKET_LEN - 8) {
  ------------------
  |  |   55|    569|#define MAX_PACKET_LEN 65535
  ------------------
  |  Branch (382:6): [True: 5, False: 564]
  ------------------
  383|      5|		m->qdcount = 0;
  384|      5|		return 1;
  385|      5|	}
  386|       |
  387|    564|	m->ancount = net2short(&buf);
  388|    564|	if (m->_len + (sizeof(struct resource) * m->ancount) > MAX_PACKET_LEN - 8) {
  ------------------
  |  |   55|    564|#define MAX_PACKET_LEN 65535
  ------------------
  |  Branch (388:6): [True: 13, False: 551]
  ------------------
  389|     13|		m->ancount = 0;
  390|     13|		return 1;
  391|     13|	}
  392|       |
  393|    551|	m->nscount = net2short(&buf);
  394|    551|	if (m->_len + (sizeof(struct resource) * m->nscount) > MAX_PACKET_LEN - 8) {
  ------------------
  |  |   55|    551|#define MAX_PACKET_LEN 65535
  ------------------
  |  Branch (394:6): [True: 6, False: 545]
  ------------------
  395|      6|		m->nscount = 0;
  396|      6|		return 1;
  397|      6|	}
  398|       |
  399|    545|	m->arcount = net2short(&buf);
  400|    545|	if (m->_len + (sizeof(struct resource) * m->arcount) > MAX_PACKET_LEN - 8) {
  ------------------
  |  |   55|    545|#define MAX_PACKET_LEN 65535
  ------------------
  |  Branch (400:6): [True: 12, False: 533]
  ------------------
  401|     12|		m->arcount = 0;
  402|     12|		return 1;
  403|     12|	}
  404|       |
  405|       |	/* Process questions */
  406|    533|	my(m->qd, sizeof(struct question) * m->qdcount);
  ------------------
  |  |  350|    533|	while (m->_len & 7)			\
  |  |  ------------------
  |  |  |  Branch (350:9): [True: 0, False: 533]
  |  |  ------------------
  |  |  351|    533|		m->_len++;			\
  |  |  352|    533|	(x) = (void *)(m->_packet + m->_len);	\
  |  |  353|    533|	m->_len += (y);
  ------------------
  407|   427k|	for (i = 0; i < m->qdcount; i++) {
  ------------------
  |  Branch (407:14): [True: 427k, False: 515]
  ------------------
  408|   427k|		if (_label(m, &buf, &(m->qd[i].name)))
  ------------------
  |  Branch (408:7): [True: 18, False: 427k]
  ------------------
  409|     18|			return 1;
  410|   427k|		m->qd[i].type  = net2short(&buf);
  411|   427k|		m->qd[i].clazz = net2short(&buf);
  412|   427k|	}
  413|       |
  414|       |	/* Process rrs */
  415|    515|	my(m->an, sizeof(struct resource) * m->ancount);
  ------------------
  |  |  350|  1.90k|	while (m->_len & 7)			\
  |  |  ------------------
  |  |  |  Branch (350:9): [True: 1.38k, False: 515]
  |  |  ------------------
  |  |  351|  1.38k|		m->_len++;			\
  |  |  352|    515|	(x) = (void *)(m->_packet + m->_len);	\
  |  |  353|    515|	m->_len += (y);
  ------------------
  416|    515|	my(m->ns, sizeof(struct resource) * m->nscount);
  ------------------
  |  |  350|    515|	while (m->_len & 7)			\
  |  |  ------------------
  |  |  |  Branch (350:9): [True: 0, False: 515]
  |  |  ------------------
  |  |  351|    515|		m->_len++;			\
  |  |  352|    515|	(x) = (void *)(m->_packet + m->_len);	\
  |  |  353|    515|	m->_len += (y);
  ------------------
  417|    515|	my(m->ar, sizeof(struct resource) * m->arcount);
  ------------------
  |  |  350|    515|	while (m->_len & 7)			\
  |  |  ------------------
  |  |  |  Branch (350:9): [True: 0, False: 515]
  |  |  ------------------
  |  |  351|    515|		m->_len++;			\
  |  |  352|    515|	(x) = (void *)(m->_packet + m->_len);	\
  |  |  353|    515|	m->_len += (y);
  ------------------
  418|    515|	if (_rrparse(m, m->an, m->ancount, &buf))
  ------------------
  |  Branch (418:6): [True: 113, False: 402]
  ------------------
  419|    113|		return 1;
  420|    402|	if (_rrparse(m, m->ns, m->nscount, &buf))
  ------------------
  |  Branch (420:6): [True: 38, False: 364]
  ------------------
  421|     38|		return 1;
  422|    364|	if (_rrparse(m, m->ar, m->arcount, &buf))
  ------------------
  |  Branch (422:6): [True: 2, False: 362]
  ------------------
  423|      2|		return 1;
  424|       |
  425|    362|	return 0;
  426|    364|}
1035.c:_label:
   98|   551k|{
   99|   551k|	int x;
  100|   551k|	char *label, *name;
  101|       |
  102|       |
  103|       |	/* Sanity check */
  104|   551k|	if (m->_len >= (int)sizeof(m->_packet))
  ------------------
  |  Branch (104:6): [True: 121, False: 551k]
  ------------------
  105|    121|		return 1;
  106|       |
  107|       |	/* Set namep to the end of the block */
  108|   551k|	*namep = name = (char *)m->_packet + m->_len;
  109|       |
  110|       |	/* Loop storing label in the block */
  111|   645k|	for (label = (char *)*bufp; *label != 0; name += *label + 1, label += *label + 1) {
  ------------------
  |  Branch (111:30): [True: 94.0k, False: 551k]
  ------------------
  112|       |		/* Skip past any compression pointers, kick out if end encountered (bad data prolly) */
  113|  94.0k|		int prevOffset = -1;
  114|   106k|		while (*label & 0xc0) {
  ------------------
  |  Branch (114:10): [True: 14.5k, False: 91.6k]
  ------------------
  115|  14.5k|			unsigned short int offset = _ldecomp(label);
  116|  14.5k|			if (offset <= prevOffset || offset > m->_len)
  ------------------
  |  Branch (116:8): [True: 15, False: 14.5k]
  |  Branch (116:32): [True: 5, False: 14.5k]
  ------------------
  117|     20|				return 1;
  118|  14.5k|			if (*(label = (char *)m->_buf + offset) == 0)
  ------------------
  |  Branch (118:8): [True: 2.37k, False: 12.1k]
  ------------------
  119|  2.37k|				break;
  120|  12.1k|			prevOffset = offset;
  121|  12.1k|		}
  122|       |
  123|       |		/* Make sure we're not over the limits, and that the source
  124|       |		 * label stays within the packet buffer */
  125|  93.9k|		if ((name + *label) - *namep > 255 || m->_len + ((name + *label) - *namep) >= MAX_PACKET_LEN ||
  ------------------
  |  |   55|   187k|#define MAX_PACKET_LEN 65535
  ------------------
  |  Branch (125:7): [True: 5, False: 93.9k]
  |  Branch (125:41): [True: 5, False: 93.9k]
  ------------------
  126|  93.9k|		    (label + 1 + *label) - (char *)m->_buf > MAX_PACKET_LEN)
  ------------------
  |  |   55|  93.9k|#define MAX_PACKET_LEN 65535
  ------------------
  |  Branch (126:7): [True: 0, False: 93.9k]
  ------------------
  127|     10|			return 1;
  128|       |
  129|       |		/* Copy chars for this label */
  130|  93.9k|		memcpy(name, label + 1, (size_t)*label);
  131|  93.9k|		name[(size_t)*label] = '.';
  132|  93.9k|	}
  133|       |
  134|       |	/* Advance buffer */
  135|   615k|	for (label = (char *)*bufp; *label != 0 && !(*label & 0xc0 && label++); label += *label + 1)
  ------------------
  |  Branch (135:30): [True: 77.8k, False: 537k]
  |  Branch (135:47): [True: 13.7k, False: 64.1k]
  |  Branch (135:64): [True: 13.7k, False: 0]
  ------------------
  136|  64.1k|		;
  137|   551k|	*bufp = (unsigned char *)(label + 1);
  138|       |
  139|       |	/* Terminate name and check for cache or cache it */
  140|   551k|	*name = '\0';
  141|  3.76M|	for (x = 0; x < MAX_NUM_LABELS && m->_labels[x]; x++) {
  ------------------
  |  |   56|  7.53M|#define MAX_NUM_LABELS 512
  ------------------
  |  Branch (141:14): [True: 3.76M, False: 195]
  |  Branch (141:36): [True: 3.75M, False: 9.72k]
  ------------------
  142|  3.75M|		if (strcmp(*namep, m->_labels[x]))
  ------------------
  |  Branch (142:7): [True: 3.21M, False: 541k]
  ------------------
  143|  3.21M|			continue;
  144|       |
  145|   541k|		*namep = m->_labels[x];
  146|   541k|		return 0;
  147|  3.75M|	}
  148|       |
  149|       |	/* No cache, so cache it if room */
  150|  9.91k|	if (x < MAX_NUM_LABELS && m->_labels[x] == 0)
  ------------------
  |  |   56|  19.8k|#define MAX_NUM_LABELS 512
  ------------------
  |  Branch (150:6): [True: 9.72k, False: 195]
  |  Branch (150:28): [True: 9.72k, False: 0]
  ------------------
  151|  9.72k|		m->_labels[x] = *namep;
  152|  9.91k|	m->_len += (int)(name - *namep) + 1;
  153|       |
  154|  9.91k|	return 0;
  155|   551k|}
1035.c:_ldecomp:
   85|  14.5k|{
   86|  14.5k|	unsigned short int i;
   87|       |
   88|  14.5k|	i = 0xc0 ^ ptr[0];
   89|  14.5k|	i <<= 8;
   90|  14.5k|	i |= (unsigned char)ptr[1];
   91|  14.5k|	if (i >= 4096)
  ------------------
  |  Branch (91:6): [True: 13.4k, False: 1.16k]
  ------------------
   92|  13.4k|		i = 4095;
   93|       |
   94|  14.5k|	return i;
   95|  14.5k|}
1035.c:_rrparse:
  264|  1.28k|{
  265|  1.28k|	int i;
  266|       |
  267|   124k|	for (i = 0; i < count; i++) {
  ------------------
  |  Branch (267:14): [True: 123k, False: 1.12k]
  ------------------
  268|   123k|		if (_label(m, bufp, &(rr[i].name)))
  ------------------
  |  Branch (268:7): [True: 128, False: 123k]
  ------------------
  269|    128|			return 1;
  270|   123k|		rr[i].type     = net2short(bufp);
  271|   123k|		rr[i].clazz    = net2short(bufp);
  272|   123k|		rr[i].ttl      = net2long(bufp);
  273|   123k|		rr[i].rdlength = net2short(bufp);
  274|       |//		fprintf(stderr, "Record type %d clazz 0x%2x ttl %lu len %d\n", rr[i].type, rr[i].clazz, rr[i].ttl, rr[i].rdlength);
  275|       |
  276|       |		/* If not going to overflow, make copy of source rdata */
  277|   123k|		if (rr[i].rdlength + (*bufp - m->_buf) > MAX_PACKET_LEN || m->_len + rr[i].rdlength > MAX_PACKET_LEN) {
  ------------------
  |  |   55|   247k|#define MAX_PACKET_LEN 65535
  ------------------
              		if (rr[i].rdlength + (*bufp - m->_buf) > MAX_PACKET_LEN || m->_len + rr[i].rdlength > MAX_PACKET_LEN) {
  ------------------
  |  |   55|   123k|#define MAX_PACKET_LEN 65535
  ------------------
  |  Branch (277:7): [True: 4, False: 123k]
  |  Branch (277:62): [True: 14, False: 123k]
  ------------------
  278|     18|			rr[i].rdlength = 0;
  279|     18|			return 1;
  280|     18|		}
  281|       |
  282|       |		/* For the following records the rdata will be parsed later. So don't set it here:
  283|       |		 * NS, CNAME, PTR, DNAME, SOA, MX, AFSDB, RT, KX, RP, PX, SRV, NSEC
  284|       |		 * See 18.14 of https://tools.ietf.org/html/rfc6762#page-47 */
  285|   123k|		if (rr[i].type == QTYPE_NS || rr[i].type == QTYPE_CNAME || rr[i].type == QTYPE_PTR || rr[i].type == QTYPE_SRV) {
  ------------------
  |  |   64|   247k|#define QTYPE_NS     2
  ------------------
              		if (rr[i].type == QTYPE_NS || rr[i].type == QTYPE_CNAME || rr[i].type == QTYPE_PTR || rr[i].type == QTYPE_SRV) {
  ------------------
  |  |   65|   247k|#define QTYPE_CNAME  5
  ------------------
              		if (rr[i].type == QTYPE_NS || rr[i].type == QTYPE_CNAME || rr[i].type == QTYPE_PTR || rr[i].type == QTYPE_SRV) {
  ------------------
  |  |   66|   246k|#define QTYPE_PTR    12
  ------------------
              		if (rr[i].type == QTYPE_NS || rr[i].type == QTYPE_CNAME || rr[i].type == QTYPE_PTR || rr[i].type == QTYPE_SRV) {
  ------------------
  |  |   69|   122k|#define QTYPE_SRV    33
  ------------------
  |  Branch (285:7): [True: 200, False: 123k]
  |  Branch (285:33): [True: 298, False: 123k]
  |  Branch (285:62): [True: 195, False: 122k]
  |  Branch (285:89): [True: 195, False: 122k]
  ------------------
  286|    888|			rr[i].rdlength = 0;
  287|   122k|		} else {
  288|   122k|			rr[i].rdata = m->_packet + m->_len;
  289|   122k|			m->_len += rr[i].rdlength;
  290|   122k|			memcpy(rr[i].rdata, *bufp, rr[i].rdlength);
  291|   122k|		}
  292|       |
  293|       |
  294|       |		/* Parse commonly known ones */
  295|   123k|		switch (rr[i].type) {
  296|     96|		case QTYPE_A:
  ------------------
  |  |   63|     96|#define QTYPE_A      1
  ------------------
  |  Branch (296:3): [True: 96, False: 123k]
  ------------------
  297|     96|			if (m->_len + INET_ADDRSTRLEN > MAX_PACKET_LEN)
  ------------------
  |  |   55|     96|#define MAX_PACKET_LEN 65535
  ------------------
  |  Branch (297:8): [True: 1, False: 95]
  ------------------
  298|      1|				return 1;
  299|     95|			rr[i].known.a.name = (char *)m->_packet + m->_len;
  300|     95|			m->_len += INET_ADDRSTRLEN;
  301|     95|			inet_ntop(AF_INET, *bufp, rr[i].known.a.name, INET_ADDRSTRLEN);
  302|     95|			memcpy(&(rr[i].known.a.ip.s_addr), *bufp, sizeof(rr[i].known.a.ip.s_addr));
  303|     95|			*bufp += sizeof(rr[i].known.a.ip.s_addr);
  304|     95|			break;
  305|       |
  306|    222|		case QTYPE_AAAA:
  ------------------
  |  |   68|    222|#define QTYPE_AAAA   28
  ------------------
  |  Branch (306:3): [True: 222, False: 123k]
  ------------------
  307|    222|			if (m->_len + INET6_ADDRSTRLEN > MAX_PACKET_LEN)
  ------------------
  |  |   55|    222|#define MAX_PACKET_LEN 65535
  ------------------
  |  Branch (307:8): [True: 1, False: 221]
  ------------------
  308|      1|				return 1;
  309|    221|			rr[i].known.aaaa.name = (char *)m->_packet + m->_len;
  310|    221|			m->_len += INET6_ADDRSTRLEN;
  311|    221|			inet_ntop(AF_INET6, *bufp, rr[i].known.aaaa.name, INET6_ADDRSTRLEN);
  312|    221|			memcpy(rr[i].known.aaaa.ip6.s6_addr, *bufp, sizeof(rr[i].known.aaaa.ip6.s6_addr));
  313|    221|			*bufp += sizeof(rr[i].known.aaaa.ip6.s6_addr);
  314|    221|			break;
  315|       |
  316|    200|		case QTYPE_NS:
  ------------------
  |  |   64|    200|#define QTYPE_NS     2
  ------------------
  |  Branch (316:3): [True: 200, False: 123k]
  ------------------
  317|    200|			if (_label(m, bufp, &(rr[i].known.ns.name)))
  ------------------
  |  Branch (317:8): [True: 1, False: 199]
  ------------------
  318|      1|				return 1;
  319|    199|			break;
  320|       |
  321|    298|		case QTYPE_CNAME:
  ------------------
  |  |   65|    298|#define QTYPE_CNAME  5
  ------------------
  |  Branch (321:3): [True: 298, False: 123k]
  ------------------
  322|    298|			if (_label(m, bufp, &(rr[i].known.cname.name)))
  ------------------
  |  Branch (322:8): [True: 2, False: 296]
  ------------------
  323|      2|				return 1;
  324|    296|			break;
  325|       |
  326|    296|		case QTYPE_PTR:
  ------------------
  |  |   66|    195|#define QTYPE_PTR    12
  ------------------
  |  Branch (326:3): [True: 195, False: 123k]
  ------------------
  327|    195|			if (_label(m, bufp, &(rr[i].known.ptr.name)))
  ------------------
  |  Branch (327:8): [True: 1, False: 194]
  ------------------
  328|      1|				return 1;
  329|    194|			break;
  330|       |
  331|    195|		case QTYPE_SRV:
  ------------------
  |  |   69|    195|#define QTYPE_SRV    33
  ------------------
  |  Branch (331:3): [True: 195, False: 123k]
  ------------------
  332|    195|			rr[i].known.srv.priority = net2short(bufp);
  333|    195|			rr[i].known.srv.weight = net2short(bufp);
  334|    195|			rr[i].known.srv.port = net2short(bufp);
  335|    195|			if (_label(m, bufp, &(rr[i].known.srv.name)))
  ------------------
  |  Branch (335:8): [True: 1, False: 194]
  ------------------
  336|      1|				return 1;
  337|    194|			break;
  338|       |
  339|    194|		case QTYPE_TXT:
  ------------------
  |  |   67|      0|#define QTYPE_TXT    16
  ------------------
  |  Branch (339:3): [True: 0, False: 123k]
  ------------------
  340|   122k|		default:
  ------------------
  |  Branch (340:3): [True: 122k, False: 1.20k]
  ------------------
  341|   122k|			*bufp += rr[i].rdlength;
  342|   123k|		}
  343|   123k|	}
  344|       |
  345|  1.12k|	return 0;
  346|  1.28k|}

inet_family:
    9|    207|{
   10|    207|	return ss->ss_family;
   11|    207|}
inet_anyaddr:
   41|    207|{
   42|    207|	memset(ss, 0, sizeof(*ss));
   43|    207|	ss->ss_family = family;
   44|       |
   45|       |#ifdef ENABLE_IPV6
   46|       |	if (family == AF_INET6) {
   47|       |		struct sockaddr_in6 *sin6 = (struct sockaddr_in6 *)ss;
   48|       |
   49|       |		sin6->sin6_addr = in6addr_any;
   50|       |		sin6->sin6_port = htons(port);
   51|       |		return;
   52|       |	}
   53|       |#endif
   54|    207|	((struct sockaddr_in *)ss)->sin_addr.s_addr = htonl(INADDR_ANY);
   55|       |	((struct sockaddr_in *)ss)->sin_port        = htons(port);
   56|    207|}

mdnsd_new:
  922|    207|{
  923|    207|	mdns_daemon_t *d;
  924|       |
  925|    207|	d = calloc(1, sizeof(struct mdns_daemon));
  926|    207|	if (!d)
  ------------------
  |  Branch (926:6): [True: 0, False: 207]
  ------------------
  927|      0|		return NULL;
  928|       |
  929|    207|	gettimeofday(&d->now, 0);
  930|    207|	d->expireall = (unsigned long)d->now.tv_sec + GC;
  ------------------
  |  |   43|    207|#define GC 86400                /* Brute force garbage cleanup
  ------------------
  931|    207|	d->clazz = clazz;
  932|    207|	d->frame = frame;
  933|    207|	d->family = AF_INET;
  934|    207|	d->received_callback = NULL;
  935|    207|	d->local_ifaddrs = NULL;
  936|    207|	d->local_addrs_refreshed = 0;
  937|       |
  938|    207|	return d;
  939|    207|}
mdnsd_free:
 1052|    207|{
 1053|    207|	struct unicast *u;
 1054|       |
 1055|    207|	if (!d)
  ------------------
  |  Branch (1055:6): [True: 0, False: 207]
  ------------------
 1056|      0|		return;
 1057|       |
 1058|   209k|	for (size_t i = 0; i< LPRIME; i++) {
  ------------------
  |  |   41|   209k|#define LPRIME 1009		/* Size of cache hash */
  ------------------
  |  Branch (1058:21): [True: 208k, False: 207]
  ------------------
 1059|   208k|		struct cached *cur = d->cache[i];
 1060|       |
 1061|   208k|		while (cur) {
  ------------------
  |  Branch (1061:10): [True: 0, False: 208k]
  ------------------
 1062|      0|			struct cached *next = cur->next;
 1063|       |
 1064|      0|			cur->next = NULL;
 1065|      0|			_free_cached(cur);
 1066|      0|			cur = next;
 1067|      0|		}
 1068|   208k|	}
 1069|       |
 1070|  22.7k|	for (size_t i = 0; i< SPRIME; i++) {
  ------------------
  |  |   40|  22.7k|#define SPRIME 109		/* Size of query/publish hashes */
  ------------------
  |  Branch (1070:21): [True: 22.5k, False: 207]
  ------------------
 1071|  22.5k|		struct mdns_record *cur = d->published[i];
 1072|  22.5k|		struct query *curq;
 1073|       |
 1074|  22.5k|		while (cur) {
  ------------------
  |  Branch (1074:10): [True: 0, False: 22.5k]
  ------------------
 1075|      0|			struct mdns_record *next = cur->next;
 1076|       |
 1077|      0|			cur->next = NULL;
 1078|      0|			_free_record(cur);
 1079|      0|			cur = next;
 1080|      0|		}
 1081|       |
 1082|  22.5k|		curq = d->queries[i];
 1083|  22.5k|		while (curq) {
  ------------------
  |  Branch (1083:10): [True: 0, False: 22.5k]
  ------------------
 1084|      0|			struct query *next = curq->next;
 1085|       |
 1086|      0|			curq->next = NULL;
 1087|      0|			free(curq->name);
 1088|      0|			free(curq);
 1089|      0|			curq = next;
 1090|      0|		}
 1091|  22.5k|	}
 1092|       |
 1093|    207|	u = d->uanswers;
 1094|    207|	while (u) {
  ------------------
  |  Branch (1094:9): [True: 0, False: 207]
  ------------------
 1095|      0|		struct unicast *next = u->next;
 1096|       |
 1097|      0|		u->next = NULL;
 1098|      0|		free(u);
 1099|      0|		u = next;
 1100|      0|	}
 1101|       |
 1102|    207|	if (d->local_ifaddrs)
  ------------------
  |  Branch (1102:6): [True: 0, False: 207]
  ------------------
 1103|      0|		freeifaddrs(d->local_ifaddrs);
 1104|       |
 1105|    207|	free(d);
 1106|    207|}
mdnsd_in:
 1116|    207|{
 1117|    207|	mdns_record_t *r = NULL;
 1118|    207|	int i, j;
 1119|    207|	bool did_addr_refresh = false;
 1120|       |
 1121|    207|	if (d->shutdown)
  ------------------
  |  Branch (1121:6): [True: 0, False: 207]
  ------------------
 1122|      0|		return 1;
 1123|       |
 1124|    207|	gettimeofday(&d->now, 0);
 1125|       |
 1126|       |	/* Ignore packets originated from any of our own local addresses */
 1127|    207|	if (_is_local(d, from))
  ------------------
  |  Branch (1127:6): [True: 207, False: 0]
  ------------------
 1128|    207|		return 0;
 1129|       |
 1130|      0|	if (m->header.qr == 0) {
  ------------------
  |  Branch (1130:6): [True: 0, False: 0]
  ------------------
 1131|       |		/* Process each query */
 1132|      0|		for (i = 0; i < m->qdcount; i++) {
  ------------------
  |  Branch (1132:15): [True: 0, False: 0]
  ------------------
 1133|      0|			mdns_record_t *r_start, *r_next;
 1134|      0|			bool has_conflict = false;
 1135|       |
 1136|      0|			if (!m->qd || m->qd[i].clazz != d->clazz)
  ------------------
  |  Branch (1136:8): [True: 0, False: 0]
  |  Branch (1136:18): [True: 0, False: 0]
  ------------------
 1137|      0|				continue;
 1138|       |
 1139|      0|			INFO("Query for %s of type %d ...", m->qd[i].name, m->qd[i].type);
  ------------------
  |  |   44|      0|#define INFO(fmt, args...) mdnsd_log(LOG_INFO, "%s(): " fmt, __func__, ##args)
  ------------------
 1140|      0|			r = _r_next(d, NULL, m->qd[i].name, m->qd[i].type);
 1141|      0|			if (!r)
  ------------------
  |  Branch (1141:8): [True: 0, False: 0]
  ------------------
 1142|      0|				continue;
 1143|       |
 1144|       |			/* Service enumeration/discovery prepare to send all matching records */
 1145|      0|			if (!strcmp(m->qd[i].name, DISCO_NAME)) {
  ------------------
  |  |   41|      0|#define DISCO_NAME "_services._dns-sd._udp.local."
  ------------------
  |  Branch (1145:8): [True: 0, False: 0]
  ------------------
 1146|      0|				d->disco = 1;
 1147|      0|				while (r) {
  ------------------
  |  Branch (1147:12): [True: 0, False: 0]
  ------------------
 1148|      0|					if (!strcmp(r->rr.name, DISCO_NAME))
  ------------------
  |  |   41|      0|#define DISCO_NAME "_services._dns-sd._udp.local."
  ------------------
  |  Branch (1148:10): [True: 0, False: 0]
  ------------------
 1149|      0|						_r_send(d, r);
 1150|      0|					r = _r_next(d, r, m->qd[i].name, m->qd[i].type);
 1151|      0|				}
 1152|       |
 1153|      0|				continue;
 1154|      0|			}
 1155|       |
 1156|       |			/* Check all of our potential answers */
 1157|      0|			for (r_start = r; r != NULL; r = r_next) {
  ------------------
  |  Branch (1157:22): [True: 0, False: 0]
  ------------------
 1158|      0|				INFO("Local record: %s, type: %d, rdname: %s", r->rr.name, r->rr.type, r->rr.rdname);
  ------------------
  |  |   44|      0|#define INFO(fmt, args...) mdnsd_log(LOG_INFO, "%s(): " fmt, __func__, ##args)
  ------------------
 1159|       |
 1160|       |				/* Fetch next here, because _conflict() might delete r, invalidating next */
 1161|      0|				r_next = _r_next(d, r, m->qd[i].name, m->qd[i].type);
 1162|       |
 1163|       |				/* probing state, check for conflicts */
 1164|      0|				if (r->unique && r->unique < 5 && !r->modified) {
  ------------------
  |  Branch (1164:9): [True: 0, False: 0]
  |  Branch (1164:22): [True: 0, False: 0]
  |  Branch (1164:39): [True: 0, False: 0]
  ------------------
 1165|       |					/* Check all to-be answers against our own */
 1166|      0|					for (j = 0; j < m->ancount; j++) {
  ------------------
  |  Branch (1166:18): [True: 0, False: 0]
  ------------------
 1167|      0|						if (!m->an || m->qd[i].type != m->an[j].type || strcmp(m->qd[i].name, m->an[j].name))
  ------------------
  |  Branch (1167:11): [True: 0, False: 0]
  |  Branch (1167:21): [True: 0, False: 0]
  |  Branch (1167:55): [True: 0, False: 0]
  ------------------
 1168|      0|							continue;
 1169|       |
 1170|       |						/* This answer isn't ours, conflict! */
 1171|      0|						if (!_a_match(&m->an[j], &r->rr)) {
  ------------------
  |  Branch (1171:11): [True: 0, False: 0]
  ------------------
 1172|       |							/* Before flagging conflict, force a local address refresh and re-check */
 1173|      0|							if (!did_addr_refresh) {
  ------------------
  |  Branch (1173:12): [True: 0, False: 0]
  ------------------
 1174|      0|								did_addr_refresh = true;
 1175|      0|								_refresh_local_addrs(d, true);
 1176|      0|							}
 1177|      0|							if (_is_local(d, from))
  ------------------
  |  Branch (1177:12): [True: 0, False: 0]
  ------------------
 1178|      0|								continue;
 1179|      0|							_conflict(d, r);
 1180|      0|							has_conflict = true;
 1181|      0|							break;
 1182|      0|						}
 1183|      0|					}
 1184|      0|					continue;
 1185|      0|				}
 1186|       |
 1187|       |				/* Check the known answers for this question */
 1188|      0|				for (j = 0; j < m->ancount; j++) {
  ------------------
  |  Branch (1188:17): [True: 0, False: 0]
  ------------------
 1189|      0|					if (!m->an || m->qd[i].type != m->an[j].type || strcmp(m->qd[i].name, m->an[j].name))
  ------------------
  |  Branch (1189:10): [True: 0, False: 0]
  |  Branch (1189:20): [True: 0, False: 0]
  |  Branch (1189:54): [True: 0, False: 0]
  ------------------
 1190|      0|						continue;
 1191|       |
 1192|      0|					if (d->received_callback)
  ------------------
  |  Branch (1192:10): [True: 0, False: 0]
  ------------------
 1193|      0|						d->received_callback(&m->an[j], d->received_callback_data);
 1194|       |
 1195|       |					/* Do they already have this answer? */
 1196|      0|					if (_a_match(&m->an[j], &r->rr))
  ------------------
  |  Branch (1196:10): [True: 0, False: 0]
  ------------------
 1197|      0|						break;
 1198|      0|				}
 1199|       |
 1200|      0|				INFO("Should we send answer? j: %d, m->ancount: %d", j, m->ancount);
  ------------------
  |  |   44|      0|#define INFO(fmt, args...) mdnsd_log(LOG_INFO, "%s(): " fmt, __func__, ##args)
  ------------------
 1201|      0|				if (j == m->ancount) {
  ------------------
  |  Branch (1201:9): [True: 0, False: 0]
  ------------------
 1202|      0|					INFO("Yes we should, enquing %s for outbound", r->rr.name);
  ------------------
  |  |   44|      0|#define INFO(fmt, args...) mdnsd_log(LOG_INFO, "%s(): " fmt, __func__, ##args)
  ------------------
 1203|      0|					_r_send(d, r);
 1204|      0|				}
 1205|      0|			}
 1206|       |
 1207|       |			/* Send the matching unicast reply */
 1208|      0|			if (!has_conflict && inet_port(from) != 5353)
  ------------------
  |  Branch (1208:8): [True: 0, False: 0]
  |  Branch (1208:25): [True: 0, False: 0]
  ------------------
 1209|      0|				_u_push(d, r_start, m->id, from);
 1210|      0|		}
 1211|       |
 1212|      0|		return 0;
 1213|      0|	}
 1214|       |
 1215|       |	/* Process each answer, check for a conflict, and cache */
 1216|      0|	for (i = 0; i < m->ancount; i++) {
  ------------------
  |  Branch (1216:14): [True: 0, False: 0]
  ------------------
 1217|      0|		if (!m->an)
  ------------------
  |  Branch (1217:7): [True: 0, False: 0]
  ------------------
 1218|      0|			continue;
 1219|       |
 1220|      0|		if (!m->an[i].name) {
  ------------------
  |  Branch (1220:7): [True: 0, False: 0]
  ------------------
 1221|      0|			ERR("Got answer with NULL name at %p. Type: %d, TTL: %ld, skipping",
  ------------------
  |  |   47|      0|#define ERR(fmt, args...)  mdnsd_log(LOG_ERR, fmt, ##args)
  ------------------
 1222|      0|			    (void*)&m->an[i], m->an[i].type, m->an[i].ttl);
 1223|      0|			continue;
 1224|      0|		}
 1225|       |
 1226|      0|		INFO("Got Answer: Name: %s, Type: %d", m->an[i].name, m->an[i].type);
  ------------------
  |  |   44|      0|#define INFO(fmt, args...) mdnsd_log(LOG_INFO, "%s(): " fmt, __func__, ##args)
  ------------------
 1227|      0|		r = _r_next(d, NULL, m->an[i].name, m->an[i].type);
 1228|      0|		if (r && r->unique && r->modified && _a_match(&m->an[i], &r->rr)) {
  ------------------
  |  Branch (1228:7): [True: 0, False: 0]
  |  Branch (1228:12): [True: 0, False: 0]
  |  Branch (1228:25): [True: 0, False: 0]
  |  Branch (1228:40): [True: 0, False: 0]
  ------------------
 1229|       |			/* double check, is this actually from us, looped back? */
 1230|      0|			if (!did_addr_refresh) {
  ------------------
  |  Branch (1230:8): [True: 0, False: 0]
  ------------------
 1231|      0|				did_addr_refresh = true;
 1232|      0|				_refresh_local_addrs(d, true);
 1233|      0|			}
 1234|      0|			if (_is_local(d, from))
  ------------------
  |  Branch (1234:8): [True: 0, False: 0]
  ------------------
 1235|      0|				continue;
 1236|      0|			_conflict(d, r);
 1237|      0|		}
 1238|       |
 1239|      0|		if (d->received_callback)
  ------------------
  |  Branch (1239:7): [True: 0, False: 0]
  ------------------
 1240|      0|			d->received_callback(&m->an[i], d->received_callback_data);
 1241|       |
 1242|      0|		if (_cache(d, &m->an[i], from) != 0) {
  ------------------
  |  Branch (1242:7): [True: 0, False: 0]
  ------------------
 1243|      0|			ERR("Failed caching answer, possibly too long packet, skipping.");
  ------------------
  |  |   47|      0|#define ERR(fmt, args...)  mdnsd_log(LOG_ERR, fmt, ##args)
  ------------------
 1244|      0|			continue;
 1245|      0|		}
 1246|      0|	}
 1247|       |
 1248|      0|	return 0;
 1249|      0|}
mdnsd.c:_is_local:
  890|    207|{
  891|       |#ifdef ENABLE_IPV6
  892|       |	if (inet_family(from) == AF_INET6)
  893|       |		return _is_local_ipv6(d, ((const struct sockaddr_in6 *)from)->sin6_addr);
  894|       |#endif
  895|    207|	if (inet_family(from) != AF_INET)
  ------------------
  |  Branch (895:6): [True: 0, False: 207]
  ------------------
  896|      0|		return false;
  897|       |
  898|    207|	const struct sockaddr_in *sin4 = (const struct sockaddr_in *)from;
  899|    207|	return _is_local_ipv4(d, &sin4->sin_addr);
  900|    207|}
mdnsd.c:_is_local_ipv4:
  840|    207|{
  841|    207|	struct ifaddrs *it;
  842|       |
  843|       |	/* Always consider the primary configured address as local */
  844|    207|	if (ip->s_addr == d->addr.s_addr)
  ------------------
  |  Branch (844:6): [True: 207, False: 0]
  ------------------
  845|    207|		return true;
  846|       |
  847|      0|	_refresh_local_addrs(d, false);
  848|       |
  849|      0|	for (it = d->local_ifaddrs; it; it = it->ifa_next) {
  ------------------
  |  Branch (849:30): [True: 0, False: 0]
  ------------------
  850|      0|		struct sockaddr_in *sin;
  851|      0|		if (!it->ifa_addr)
  ------------------
  |  Branch (851:7): [True: 0, False: 0]
  ------------------
  852|      0|			continue;
  853|      0|		if (it->ifa_addr->sa_family != AF_INET)
  ------------------
  |  Branch (853:7): [True: 0, False: 0]
  ------------------
  854|      0|			continue;
  855|      0|		sin = (struct sockaddr_in *)it->ifa_addr;
  856|      0|		if (sin->sin_addr.s_addr == ip->s_addr)
  ------------------
  |  Branch (856:7): [True: 0, False: 0]
  ------------------
  857|      0|			return true;
  858|      0|	}
  859|       |
  860|      0|	return false;
  861|      0|}

