Fuzz introspector
For issues and ideas: https://github.com/ossf/fuzz-introspector/issues

Fuzzers overview

Fuzzer Fuzzer filename Functions Reached Functions unreached Fuzzer depth Files reached Basic blocks reached Cyclomatic complexity Details
fuzz_json_decode_encode /src/open62541/tests/fuzz/fuzz_json_decode_encode.cc 25 5968 6 5 399 156 fuzz_json_decode_encode.cc
fuzz_pubsub_binary /src/open62541/tests/fuzz/fuzz_pubsub_binary.cc 42 5945 9 7 836 302 fuzz_pubsub_binary.cc
fuzz_certificate_parse /src/open62541/tests/fuzz/fuzz_certificate_parse.cc 58 5931 4 8 259 177 fuzz_certificate_parse.cc
fuzz_mdns_xht /src/open62541/tests/fuzz/fuzz_mdns_xht.cc 19 5968 5 3 173 83 fuzz_mdns_xht.cc
fuzz_base64_decode /src/open62541/tests/fuzz/fuzz_base64_decode.cc 2 5985 1 2 41 18 fuzz_base64_decode.cc
fuzz_parse_string /src/open62541/tests/fuzz/fuzz_parse_string.cc 265 5750 19 20 3465 1295 fuzz_parse_string.cc
fuzz_binary_decode /src/open62541/tests/fuzz/fuzz_binary_decode.cc 39 5954 5 6 363 159 fuzz_binary_decode.cc
fuzz_server_services /src/open62541/tests/fuzz/fuzz_server_services.cc 3065 3036 41 92 26313 11676 fuzz_server_services.cc
fuzz_process_request /src/open62541/tests/fuzz/fuzz_process_request.cc 2906 3097 41 93 25033 11145 fuzz_process_request.cc
fuzz_tcp_message /src/open62541/tests/fuzz/fuzz_tcp_message.cc 2925 3073 41 93 25334 11277 fuzz_tcp_message.cc
fuzz_config_json /src/open62541/tests/fuzz/fuzz_config_json.cc 2993 2994 42 103 26512 11755 fuzz_config_json.cc
fuzz_mdns_message /src/open62541/tests/fuzz/fuzz_mdns_message.cc 53 5934 6 5 727 316 fuzz_mdns_message.cc
fuzz_json_decode /src/open62541/tests/fuzz/fuzz_json_decode.cc 15 5976 6 5 312 121 fuzz_json_decode.cc
fuzz_xml_decode_encode /src/open62541/tests/fuzz/fuzz_xml_decode_encode.cc 59 5934 7 5 1139 481 fuzz_xml_decode_encode.cc
fuzz_pubsub_connection_config /src/open62541/tests/fuzz/fuzz_pubsub_connection_config.cc 19 5968 5 7 130 64 fuzz_pubsub_connection_config.cc
fuzz_src_ua_util /src/open62541/tests/fuzz/fuzz_src_ua_util.cc 13 5978 5 3 202 81 fuzz_src_ua_util.cc
fuzz_attributeoperand /src/open62541/tests/fuzz/fuzz_attributeoperand.cc 229 5766 20 19 2905 1142 fuzz_attributeoperand.cc
fuzz_eventfilter_parse /src/open62541/tests/fuzz/fuzz_eventfilter_parse.cc 265 5728 23 23 11579 1373 fuzz_eventfilter_parse.cc
fuzz_binary_message /src/open62541/tests/fuzz/fuzz_binary_message.cc 2900 3099 41 94 24970 11117 fuzz_binary_message.cc
fuzz_datatype_description /src/open62541/tests/fuzz/fuzz_datatype_description.cc 75 5916 10 10 833 329 fuzz_datatype_description.cc
fuzz_client /src/open62541/tests/fuzz/fuzz_client.cc 457 5541 24 45 6161 2506 fuzz_client.cc
fuzz_base64_encode /src/open62541/tests/fuzz/fuzz_base64_encode.cc 3 5984 2 2 26 12 fuzz_base64_encode.cc
fuzz_pubsub_json /src/open62541/tests/fuzz/fuzz_pubsub_json.cc 30 5957 6 10 523 204 fuzz_pubsub_json.cc

Project functions overview

The following table shows data about each function in the project. The functions included in this table correspond to all functions that exist in the executables of the fuzzers. As such, there may be functions that are from third-party libraries.

For further technical details on the meaning of columns in the below table, please see the Glossary .

Func name Functions filename Args Function call depth Reached by Fuzzers Runtime reached by Fuzzers Combined reached by Fuzzers Fuzzers runtime hit Func lines hit % I Count BB Count Cyclomatic complexity Functions reached Reached by functions Accumulated cyclomatic complexity Undiscovered complexity

Fuzzer details

Fuzzer: fuzz_json_decode_encode

Call tree

The calltree shows the control flow of the fuzzer. This is overlaid with coverage information to display how much of the potential code a fuzzer can reach is in fact covered at runtime. In the following there is a link to a detailed calltree visualisation as well as a bitmap showing a high-level view of the calltree. For further information about these topics please see the glossary for full calltree and calltree overview

Call tree overview bitmap:

The distribution of callsites in terms of coloring is
Color Runtime hitcount Callsite count Percentage
red 0 11 20.0%
gold [1:9] 1 1.81%
yellow [10:29] 0 0.0%
greenyellow [30:49] 0 0.0%
lawngreen 50+ 43 78.1%
All colors 55 100

Fuzz blockers

The following nodes represent call sites where fuzz blockers occur.

Amount of callsites blocked Calltree index Parent function Callsite Largest blocked function
4 29 LLVMFuzzerTestOneInput call site: 00029 UA_calcSizeJson
3 42 LLVMFuzzerTestOneInput call site: 00042
2 36 LLVMFuzzerTestOneInput call site: 00036
1 24 LLVMFuzzerTestOneInput call site: 00024 UA_clear
1 27 UA_ByteString_allocBuffer call site: 00027

Runtime coverage analysis

Covered functions
221
Functions that are reachable but not covered
3
Reachable functions
25
Percentage of reachable functions covered
88.0%
NB: The sum of covered functions and functions that are reachable but not covered need not be equal to Reachable functions . This is because the reachability analysis is an approximation and thus at runtime some functions may be covered that are not included in the reachability analysis. This is a limitation of our static analysis capabilities.
Warning: The number of covered functions are larger than the number of reachable functions. This means that there are more functions covered at runtime than are extracted using static analysis. This is likely a result of the static analysis component failing to extract the right call graph or the coverage runtime being compiled with sanitizers in code that the static analysis has not analysed. This can happen if lto/gold is not used in all places that coverage instrumentation is used.
Function name source code lines source lines hit percentage hit

Files reached

filename functions hit
/src/open62541/tests/fuzz/fuzz_json_decode_encode.cc 1
/work/open62541/src_generated/open62541/types_generated.h 5
/src/open62541/src/ua_types_encoding_json.c 4
/src/open62541/deps/cj5.c 7
/src/open62541/src/ua_types.c 3

Fuzzer: fuzz_pubsub_binary

Call tree

The calltree shows the control flow of the fuzzer. This is overlaid with coverage information to display how much of the potential code a fuzzer can reach is in fact covered at runtime. In the following there is a link to a detailed calltree visualisation as well as a bitmap showing a high-level view of the calltree. For further information about these topics please see the glossary for full calltree and calltree overview

Call tree overview bitmap:

The distribution of callsites in terms of coloring is
Color Runtime hitcount Callsite count Percentage
red 0 24 15.6%
gold [1:9] 5 3.26%
yellow [10:29] 6 3.92%
greenyellow [30:49] 4 2.61%
lawngreen 50+ 114 74.5%
All colors 153 100

Fuzz blockers

The following nodes represent call sites where fuzz blockers occur.

Amount of callsites blocked Calltree index Parent function Callsite Largest blocked function
14 106 stringOrder call site: 00106 nodeIdOrder
7 98 UA_DataSetMessage_keyFrame_decodeBinary call site: 00098 decodeRawField
1 145 UA_DataSetMessage_clear call site: 00145 UA_clear
1 147 UA_NetworkMessage_clear call site: 00147 UA_clear
1 149 UA_NetworkMessage_clear call site: 00149 UA_clear

Runtime coverage analysis

Covered functions
82
Functions that are reachable but not covered
8
Reachable functions
42
Percentage of reachable functions covered
80.95%
NB: The sum of covered functions and functions that are reachable but not covered need not be equal to Reachable functions . This is because the reachability analysis is an approximation and thus at runtime some functions may be covered that are not included in the reachability analysis. This is a limitation of our static analysis capabilities.
Warning: The number of covered functions are larger than the number of reachable functions. This means that there are more functions covered at runtime than are extracted using static analysis. This is likely a result of the static analysis component failing to extract the right call graph or the coverage runtime being compiled with sanitizers in code that the static analysis has not analysed. This can happen if lto/gold is not used in all places that coverage instrumentation is used.
Function name source code lines source lines hit percentage hit

Files reached

filename functions hit
/src/open62541/tests/fuzz/fuzz_pubsub_binary.cc 1
/src/open62541/tests/fuzz/custom_memory_manager.c 1
/src/open62541/src/pubsub/ua_pubsub_networkmessage_binary.c 22
/src/open62541/src/pubsub/../util/ua_util_internal.h 3
/src/open62541/src/ua_types_encoding_binary.c 2
/src/open62541/src/ua_types.c 7
/work/open62541/src_generated/open62541/types_generated.h 4

Fuzzer: fuzz_certificate_parse

Call tree

The calltree shows the control flow of the fuzzer. This is overlaid with coverage information to display how much of the potential code a fuzzer can reach is in fact covered at runtime. In the following there is a link to a detailed calltree visualisation as well as a bitmap showing a high-level view of the calltree. For further information about these topics please see the glossary for full calltree and calltree overview

Call tree overview bitmap:

The distribution of callsites in terms of coloring is
Color Runtime hitcount Callsite count Percentage
red 0 38 40.4%
gold [1:9] 16 17.0%
yellow [10:29] 1 1.06%
greenyellow [30:49] 5 5.31%
lawngreen 50+ 34 36.1%
All colors 94 100

Fuzz blockers

The following nodes represent call sites where fuzz blockers occur.

Amount of callsites blocked Calltree index Parent function Callsite Largest blocked function
16 77 UA_CertificateUtils_verifyApplicationUri call site: 00077 UA_String_clear
11 42 LLVMFuzzerTestOneInput call site: 00042 UA_OpenSSL_LoadCertificate
5 9 UA_OpenSSL_LoadPemCertificate call site: 00009 X509_get_pubkey
2 62 UA_CertificateUtils_getKeySize call site: 00062 EVP_PKEY_free
1 4 UA_OpenSSL_LoadCertificate call site: 00004 d2i_X509
1 17 UA_OpenSSL_LoadCrl call site: 00017 d2i_X509_CRL
1 27 UA_CertificateUtils_getSubjectName call site: 00027 UA_copy
1 32 LLVMFuzzerTestOneInput call site: 00032 UA_clear

Runtime coverage analysis

Covered functions
31
Functions that are reachable but not covered
34
Reachable functions
58
Percentage of reachable functions covered
41.38%
NB: The sum of covered functions and functions that are reachable but not covered need not be equal to Reachable functions . This is because the reachability analysis is an approximation and thus at runtime some functions may be covered that are not included in the reachability analysis. This is a limitation of our static analysis capabilities.
Function name source code lines source lines hit percentage hit

Files reached

filename functions hit
/src/open62541/tests/fuzz/fuzz_certificate_parse.cc 1
/src/open62541/tests/fuzz/custom_memory_manager.c 1
/src/open62541/plugins/crypto/openssl/certificategroup.c 7
/src/open62541/plugins/crypto/openssl/securitypolicy_common.c 6
/src/open62541/src/ua_types.c 3
/work/open62541/src_generated/open62541/types_generated.h 3
/src/open62541/deps/libc_time.c 3
/usr/include/openssl/x509v3.h 3

Fuzzer: fuzz_mdns_xht

Call tree

The calltree shows the control flow of the fuzzer. This is overlaid with coverage information to display how much of the potential code a fuzzer can reach is in fact covered at runtime. In the following there is a link to a detailed calltree visualisation as well as a bitmap showing a high-level view of the calltree. For further information about these topics please see the glossary for full calltree and calltree overview

Call tree overview bitmap:

The distribution of callsites in terms of coloring is
Color Runtime hitcount Callsite count Percentage
red 0 0 0.0%
gold [1:9] 0 0.0%
yellow [10:29] 1 3.57%
greenyellow [30:49] 0 0.0%
lawngreen 50+ 27 96.4%
All colors 28 100

Runtime coverage analysis

Covered functions
13
Functions that are reachable but not covered
6
Reachable functions
19
Percentage of reachable functions covered
68.42%
NB: The sum of covered functions and functions that are reachable but not covered need not be equal to Reachable functions . This is because the reachability analysis is an approximation and thus at runtime some functions may be covered that are not included in the reachability analysis. This is a limitation of our static analysis capabilities.
Function name source code lines source lines hit percentage hit

Files reached

filename functions hit
/src/open62541/tests/fuzz/fuzz_mdns_xht.cc 1
/work/open62541/src_generated/mdnsd/sdtxt.c 5
/work/open62541/src_generated/mdnsd/xht.c 7

Fuzzer: fuzz_base64_decode

Call tree

The calltree shows the control flow of the fuzzer. This is overlaid with coverage information to display how much of the potential code a fuzzer can reach is in fact covered at runtime. In the following there is a link to a detailed calltree visualisation as well as a bitmap showing a high-level view of the calltree. For further information about these topics please see the glossary for full calltree and calltree overview

Call tree overview bitmap:

The distribution of callsites in terms of coloring is
Color Runtime hitcount Callsite count Percentage
red 0 0 0.0%
gold [1:9] 0 0.0%
yellow [10:29] 0 0.0%
greenyellow [30:49] 0 0.0%
lawngreen 50+ 2 100.%
All colors 2 100

Runtime coverage analysis

Covered functions
2
Functions that are reachable but not covered
0
Reachable functions
2
Percentage of reachable functions covered
100.0%
NB: The sum of covered functions and functions that are reachable but not covered need not be equal to Reachable functions . This is because the reachability analysis is an approximation and thus at runtime some functions may be covered that are not included in the reachability analysis. This is a limitation of our static analysis capabilities.
Function name source code lines source lines hit percentage hit

Files reached

filename functions hit
/src/open62541/tests/fuzz/fuzz_base64_decode.cc 1
/src/open62541/deps/base64.c 1

Fuzzer: fuzz_parse_string

Call tree

The calltree shows the control flow of the fuzzer. This is overlaid with coverage information to display how much of the potential code a fuzzer can reach is in fact covered at runtime. In the following there is a link to a detailed calltree visualisation as well as a bitmap showing a high-level view of the calltree. For further information about these topics please see the glossary for full calltree and calltree overview

Call tree overview bitmap:

The distribution of callsites in terms of coloring is
Color Runtime hitcount Callsite count Percentage
red 0 370 66.0%
gold [1:9] 4 0.71%
yellow [10:29] 2 0.35%
greenyellow [30:49] 1 0.17%
lawngreen 50+ 183 32.6%
All colors 560 100

Fuzz blockers

The following nodes represent call sites where fuzz blockers occur.

Amount of callsites blocked Calltree index Parent function Callsite Largest blocked function
146 305 UA_STRING call site: 00305 buildEnumDefinitionFromProperties
105 158 stringOrder call site: 00158 UA_Server_readBrowseName
40 264 UA_Array_delete call site: 00264 UA_DataType_toDescription
39 118 lookupRefType call site: 00118 UA_Server_browseRecursive
7 12 UA_String_unescape call site: 00012 UA_NamespaceMapping_uri2Index
4 7 parse_nodeid call site: 00007 UA_String_unescape
3 482 nodeId_printEscape call site: 00482 UA_String_escapedSize
3 495 nodeId_printEscape call site: 00495 UA_String_escapeInsert
3 522 printRelativePath call site: 00522 UA_String_clear
2 102 parse_qn call site: 00102 UA_QualifiedName_clear
1 4 LLVMFuzzerTestOneInput call site: 00004 UA_NodeId_parseEx
1 24 UA_readNumberWithBase call site: 00024 UA_NamespaceMapping_remote2Local

Runtime coverage analysis

Covered functions
108
Functions that are reachable but not covered
150
Reachable functions
265
Percentage of reachable functions covered
43.4%
NB: The sum of covered functions and functions that are reachable but not covered need not be equal to Reachable functions . This is because the reachability analysis is an approximation and thus at runtime some functions may be covered that are not included in the reachability analysis. This is a limitation of our static analysis capabilities.
Function name source code lines source lines hit percentage hit

Files reached

filename functions hit
/src/open62541/tests/fuzz/fuzz_parse_string.cc 1
/src/open62541/src/ua_types.c 58
/work/open62541/src_generated/open62541/types_generated.h 63
/src/open62541/src/util/ua_types_lex.c 21
/src/open62541/src/util/ua_util.c 13
/src/open62541/deps/base64.c 2
/src/open62541/src/util/ua_util_internal.h 6
/src/open62541/deps/parse_num.c 2
/src/open62541/deps/libc_time.c 3
/src/open62541/src/server/ua_services_view.c 19
/src/open62541/src/server/ua_server.c 2
/work/open62541/src_generated/open62541/config.h 3
/src/open62541/include/open62541/plugin/nodestore.h 3
/src/open62541/src/server/ua_server_nodes.c 7
/src/open62541/deps/ziptree.c 6
/src/open62541/src/server/ua_server_internal.h 4
/src/open62541/src/server/ua_services_attribute.c 23
/src/open62541/src/server/ua_server_utils.c 2
/src/open62541/src/ua_types_definition.c 5
/src/open62541/deps/itoa.c 3

Fuzzer: fuzz_binary_decode

Call tree

The calltree shows the control flow of the fuzzer. This is overlaid with coverage information to display how much of the potential code a fuzzer can reach is in fact covered at runtime. In the following there is a link to a detailed calltree visualisation as well as a bitmap showing a high-level view of the calltree. For further information about these topics please see the glossary for full calltree and calltree overview

Call tree overview bitmap:

The distribution of callsites in terms of coloring is
Color Runtime hitcount Callsite count Percentage
red 0 13 21.3%
gold [1:9] 2 3.27%
yellow [10:29] 1 1.63%
greenyellow [30:49] 2 3.27%
lawngreen 50+ 43 70.4%
All colors 61 100

Fuzz blockers

The following nodes represent call sites where fuzz blockers occur.

Amount of callsites blocked Calltree index Parent function Callsite Largest blocked function
4 19 UA_encodeBinaryInternal call site: 00019 exchangeBuffer
2 28 LLVMFuzzerTestOneInput call site: 00028 UA_calcSizeBinary
2 31 UA_encodeBinary call site: 00031 UA_ByteString_clear
1 26 UA_ByteString_allocBuffer call site: 00026 UA_delete
1 49 copySubString call site: 00049 UA_Variant_copyRange
1 53 UA_Variant_copyRange call site: 00053 Variant_clear
1 56 UA_DataValue_copyRange call site: 00056 Variant_clear
1 58 LLVMFuzzerTestOneInput call site: 00058 UA_clear

Runtime coverage analysis

Covered functions
141
Functions that are reachable but not covered
3
Reachable functions
39
Percentage of reachable functions covered
92.31%
NB: The sum of covered functions and functions that are reachable but not covered need not be equal to Reachable functions . This is because the reachability analysis is an approximation and thus at runtime some functions may be covered that are not included in the reachability analysis. This is a limitation of our static analysis capabilities.
Warning: The number of covered functions are larger than the number of reachable functions. This means that there are more functions covered at runtime than are extracted using static analysis. This is likely a result of the static analysis component failing to extract the right call graph or the coverage runtime being compiled with sanitizers in code that the static analysis has not analysed. This can happen if lto/gold is not used in all places that coverage instrumentation is used.
Function name source code lines source lines hit percentage hit

Files reached

filename functions hit
/src/open62541/tests/fuzz/fuzz_binary_decode.cc 1
/src/open62541/tests/fuzz/custom_memory_manager.c 1
/src/open62541/src/ua_types.c 17
/src/open62541/src/ua_types_encoding_binary.c 8
/src/open62541/src/util/ua_util_internal.h 2
/work/open62541/src_generated/open62541/types_generated.h 6

Fuzzer: fuzz_server_services

Call tree

The calltree shows the control flow of the fuzzer. This is overlaid with coverage information to display how much of the potential code a fuzzer can reach is in fact covered at runtime. In the following there is a link to a detailed calltree visualisation as well as a bitmap showing a high-level view of the calltree. For further information about these topics please see the glossary for full calltree and calltree overview

Call tree overview bitmap:

The distribution of callsites in terms of coloring is
Color Runtime hitcount Callsite count Percentage
red 0 4236 23.6%
gold [1:9] 86 0.48%
yellow [10:29] 31 0.17%
greenyellow [30:49] 40 0.22%
lawngreen 50+ 13501 75.4%
All colors 17894 100

Fuzz blockers

The following nodes represent call sites where fuzz blockers occur.

Amount of callsites blocked Calltree index Parent function Callsite Largest blocked function
1016 15977 initPubSubNS0 call site: 15977 addDataSetReaderConfig
254 15170 ctxClear call site: 15170 processSecureChannelMessage
139 17054 initPubSubNS0 call site: 17054 UA_Server_addPublishedDataSet
130 1010 copyAttributeIntoNode call site: 01010 UA_MonitoredItem_processSampledValue
119 15659 Service_ActivateSession_inner call site: 15659 UA_Session_attachToSecureChannel
117 1306 UA_KeyValueMap_clear call site: 01306 recordModelChangeEvent
114 14810 UA_SecureChannel_clear call site: 14810 shutdownSecureChannel
106 15429 findSessionByToken call site: 15429 processServiceInternal
87 517 Variant_clear call site: 00517 UA_DataType_toDescription
81 17741 Service_CreateMonitoredItems call site: 17741 Operation_CreateMonitoredItem
80 1426 endModelChange call site: 01426 UA_ModelChangeAccumulator_finalize
62 1243 browseRecursive call site: 01243 UA_Server_readBrowseName

Runtime coverage analysis

Covered functions
2370
Functions that are reachable but not covered
801
Reachable functions
3065
Percentage of reachable functions covered
73.87%
NB: The sum of covered functions and functions that are reachable but not covered need not be equal to Reachable functions . This is because the reachability analysis is an approximation and thus at runtime some functions may be covered that are not included in the reachability analysis. This is a limitation of our static analysis capabilities.
Function name source code lines source lines hit percentage hit

Files reached

filename functions hit
/src/open62541/tests/fuzz/fuzz_server_services.cc 1
/src/open62541/plugins/include/open62541/server_config_default.h 2
/src/open62541/plugins/ua_config_default.c 7
/src/open62541/plugins/ua_nodestore_ziptree.c 1
/src/open62541/plugins/ua_log_stdout.c 2
/src/open62541/arch/posix/eventloop_posix.c 1
/work/open62541/src_generated/open62541/config.h 7
/src/open62541/arch/common/timer.c 1
/src/open62541/src/ua_types.c 88
/src/open62541/arch/posix/eventloop_posix_tcp.c 1
/work/open62541/src_generated/open62541/types_generated.h 180
/src/open62541/arch/posix/eventloop_posix_udp.c 1
/src/open62541/arch/posix/eventloop_posix_eth.c 1
/src/open62541/arch/posix/eventloop_posix_interrupt.c 2
/src/open62541/include/open62541/plugin/log.h 5
/src/open62541/arch/posix/clock_posix.c 1
/src/open62541/deps/mp_printf.c 13
/src/open62541/deps/dtoa.c 10
/src/open62541/src/util/ua_util.c 28
/src/open62541/src/util/ua_util_internal.h 16
/src/open62541/deps/itoa.c 3
/src/open62541/deps/base64.c 2
/src/open62541/plugins/crypto/ua_certificategroup_none.c 1
/src/open62541/src/server/ua_server_config.c 1
/src/open62541/plugins/crypto/ua_securitypolicy_none.c 2
/src/open62541/plugins/crypto/openssl/securitypolicy_common.c 10
/src/open62541/plugins/ua_accesscontrol_default.c 1
/src/open62541/include/open62541/server.h 1
/src/open62541/src/server/ua_server.c 16
/src/open62541/src/server/../util/ua_util_internal.h 4
/work/open62541/src_generated/open62541/statuscodes.c 1
/src/open62541/deps/pcg_basic.c 2
/src/open62541/src/server/ua_session.c 12
/src/open62541/src/server/ua_server_modelchange.c 19
/src/open62541/src/server/ua_subscription.c 43
/src/open62541/src/server/ua_server_async.c 17
/src/open62541/src/server/ua_server_ns0.c 14
/src/open62541/src/server/ua_services_nodemanagement.c 72
/src/open62541/src/server/ua_server_nodes.c 49
/src/open62541/src/server/ua_services_view.c 46
/src/open62541/deps/ziptree.c 11
/src/open62541/include/open62541/plugin/nodestore.h 7
/src/open62541/src/server/ua_server_internal.h 20
/src/open62541/src/server/ua_services_attribute.c 47
/src/open62541/src/server/ua_server_utils.c 18
/src/open62541/src/ua_types_definition.c 5
/src/open62541/src/util/ua_types_lex.c 12
/src/open62541/src/server/ua_subscription_datachange.c 8
/src/open62541/src/server/ua_subscription.h 8
/src/open62541/src/server/ua_subscription_event.c 14
/src/open62541/src/server/ua_server_auditing.c 15
/work/open62541/src_generated/open62541/namespace0_generated.c 1675
/src/open62541/src/ua_types_encoding_xml.c 3
/src/open62541/deps/yxml.c 34
/src/open62541/src/server/ua_services_session.c 25
/src/open62541/src/server/ua_transport_tcp.c 22
/src/open62541/src/server/ua_transport_http.c 7
/src/open62541/src/ua_securechannel_http.c 6
/src/open62541/src/ua_types_encoding_json.c 11
/src/open62541/src/ua_types_encoding_binary.c 7
/src/open62541/src/ua_securechannel.c 30
/src/open62541/src/ua_securechannel_crypto.c 22
/src/open62541/src/ua_securechannel.h 1
/src/open62541/src/server/ua_services_monitoreditem.c 13
/src/open62541/src/server/ua_services_subscription.c 9
/src/open62541/src/server/ua_services_securechannel.c 5
/work/open62541/src_generated/open62541/transport_generated.h 3
/src/open62541/src/server/ua_services.c 7
/src/open62541/plugins/crypto/openssl/certificategroup.c 3
/usr/include/openssl/x509v3.h 3
/usr/include/openssl/asn1.h 1
/src/open62541/src/server/ua_services_discovery.c 21
/src/open62541/src/server/../ua_securechannel.h 3
/src/open62541/src/server/ua_server_ns0_diagnostics.c 2
/src/open62541/src/util/ua_encryptedsecret.c 6
/src/open62541/src/util/../ua_securechannel.h 2
/src/open62541/src/server/ua_transport_ws.c 6
/src/open62541/src/server/ua_transport_tcp_reverse.c 1
/src/open62541/src/server/ua_server_discovery.c 1
/src/open62541/src/pubsub/ua_pubsub_manager.c 26
/src/open62541/src/pubsub/ua_pubsub_ns0.c 41
/src/open62541/src/pubsub/../server/ua_server_internal.h 4
/src/open62541/src/pubsub/ua_pubsub_internal.h 3
/src/open62541/src/pubsub/ua_pubsub_connection.c 10
/src/open62541/src/pubsub/../util/ua_util_internal.h 6
/src/open62541/src/pubsub/ua_pubsub_readergroup.c 10
/src/open62541/src/pubsub/ua_pubsub_reader.c 15
/src/open62541/src/pubsub/ua_pubsub_writergroup.c 24
/src/open62541/src/pubsub/ua_pubsub_writer.c 17
/src/open62541/src/pubsub/ua_pubsub_dataset.c 19
/src/open62541/src/pubsub/ua_pubsub_networkmessage_binary.c 26
/src/open62541/src/pubsub/ua_pubsub_networkmessage_json.c 4

Fuzzer: fuzz_process_request

Call tree

The calltree shows the control flow of the fuzzer. This is overlaid with coverage information to display how much of the potential code a fuzzer can reach is in fact covered at runtime. In the following there is a link to a detailed calltree visualisation as well as a bitmap showing a high-level view of the calltree. For further information about these topics please see the glossary for full calltree and calltree overview

Call tree overview bitmap:

The distribution of callsites in terms of coloring is
Color Runtime hitcount Callsite count Percentage
red 0 3823 21.8%
gold [1:9] 10 0.05%
yellow [10:29] 13 0.07%
greenyellow [30:49] 2 0.01%
lawngreen 50+ 13675 78.0%
All colors 17523 100

Fuzz blockers

The following nodes represent call sites where fuzz blockers occur.

Amount of callsites blocked Calltree index Parent function Callsite Largest blocked function
931 16038 findSingleChildNode call site: 16038 addDataSetReaderConfig
245 15170 ctxClear call site: 15170 processSecureChannelMessage
139 17054 initPubSubNS0 call site: 17054 UA_Server_addPublishedDataSet
130 1010 copyAttributeIntoNode call site: 01010 UA_MonitoredItem_processSampledValue
102 1321 getNodeContext call site: 01321 recordModelChangeEvent
87 517 Variant_clear call site: 00517 UA_DataType_toDescription
81 14810 UA_SecureChannel_clear call site: 14810 sendServiceMessage
80 1426 endModelChange call site: 01426 UA_ModelChangeAccumulator_finalize
64 15671 selectEndpointAndTokenPolicy call site: 15671 checkActivateSessionX509
62 1243 browseRecursive call site: 01243 UA_Server_readBrowseName
54 15977 initPubSubNS0 call site: 15977 addPubSubConnectionConfig
49 14739 UA_Session_detachFromSecureChannel call site: 14739 sendResponse

Runtime coverage analysis

Covered functions
2396
Functions that are reachable but not covered
710
Reachable functions
2906
Percentage of reachable functions covered
75.57%
NB: The sum of covered functions and functions that are reachable but not covered need not be equal to Reachable functions . This is because the reachability analysis is an approximation and thus at runtime some functions may be covered that are not included in the reachability analysis. This is a limitation of our static analysis capabilities.
Function name source code lines source lines hit percentage hit

Files reached

filename functions hit
/src/open62541/tests/fuzz/fuzz_process_request.cc 2
/src/open62541/plugins/include/open62541/server_config_default.h 2
/src/open62541/plugins/ua_config_default.c 7
/src/open62541/plugins/ua_nodestore_ziptree.c 1
/src/open62541/plugins/ua_log_stdout.c 2
/src/open62541/arch/posix/eventloop_posix.c 1
/work/open62541/src_generated/open62541/config.h 7
/src/open62541/arch/common/timer.c 1
/src/open62541/src/ua_types.c 84
/src/open62541/arch/posix/eventloop_posix_tcp.c 1
/work/open62541/src_generated/open62541/types_generated.h 121
/src/open62541/arch/posix/eventloop_posix_udp.c 1
/src/open62541/arch/posix/eventloop_posix_eth.c 1
/src/open62541/arch/posix/eventloop_posix_interrupt.c 2
/src/open62541/include/open62541/plugin/log.h 5
/src/open62541/arch/posix/clock_posix.c 1
/src/open62541/deps/mp_printf.c 13
/src/open62541/deps/dtoa.c 10
/src/open62541/src/util/ua_util.c 28
/src/open62541/src/util/ua_util_internal.h 16
/src/open62541/deps/itoa.c 3
/src/open62541/deps/base64.c 2
/src/open62541/plugins/crypto/ua_certificategroup_none.c 1
/src/open62541/src/server/ua_server_config.c 1
/src/open62541/plugins/crypto/ua_securitypolicy_none.c 2
/src/open62541/plugins/crypto/openssl/securitypolicy_common.c 11
/src/open62541/plugins/ua_accesscontrol_default.c 1
/src/open62541/include/open62541/server.h 1
/src/open62541/src/server/ua_server.c 15
/src/open62541/src/server/../util/ua_util_internal.h 4
/work/open62541/src_generated/open62541/statuscodes.c 1
/src/open62541/deps/pcg_basic.c 2
/src/open62541/src/server/ua_session.c 11
/src/open62541/src/server/ua_server_modelchange.c 19
/src/open62541/src/server/ua_subscription.c 35
/src/open62541/src/server/ua_server_async.c 16
/src/open62541/src/server/ua_server_ns0.c 14
/src/open62541/src/server/ua_services_nodemanagement.c 72
/src/open62541/src/server/ua_server_nodes.c 49
/src/open62541/src/server/ua_services_view.c 46
/src/open62541/deps/ziptree.c 11
/src/open62541/include/open62541/plugin/nodestore.h 7
/src/open62541/src/server/ua_server_internal.h 20
/src/open62541/src/server/ua_services_attribute.c 47
/src/open62541/src/server/ua_server_utils.c 18
/src/open62541/src/ua_types_definition.c 5
/src/open62541/src/util/ua_types_lex.c 12
/src/open62541/src/server/ua_subscription_datachange.c 8
/src/open62541/src/server/ua_subscription.h 7
/src/open62541/src/server/ua_subscription_event.c 12
/src/open62541/src/server/ua_server_auditing.c 14
/work/open62541/src_generated/open62541/namespace0_generated.c 1675
/src/open62541/src/ua_types_encoding_xml.c 3
/src/open62541/deps/yxml.c 34
/src/open62541/src/server/ua_services_session.c 24
/src/open62541/src/server/ua_transport_tcp.c 22
/src/open62541/src/server/ua_transport_http.c 7
/src/open62541/src/ua_securechannel_http.c 6
/src/open62541/src/ua_types_encoding_json.c 11
/src/open62541/src/ua_types_encoding_binary.c 6
/src/open62541/src/ua_securechannel.c 32
/src/open62541/src/ua_securechannel_crypto.c 22
/src/open62541/src/ua_securechannel.h 1
/src/open62541/src/server/ua_services_monitoreditem.c 1
/src/open62541/src/server/ua_services_subscription.c 1
/src/open62541/src/server/ua_services_securechannel.c 5
/work/open62541/src_generated/open62541/transport_generated.h 3
/src/open62541/src/server/ua_services.c 6
/src/open62541/plugins/crypto/openssl/certificategroup.c 3
/usr/include/openssl/x509v3.h 3
/usr/include/openssl/asn1.h 1
/src/open62541/src/server/ua_services_discovery.c 9
/src/open62541/src/server/../ua_securechannel.h 3
/src/open62541/src/server/ua_server_ns0_diagnostics.c 1
/src/open62541/src/util/ua_encryptedsecret.c 6
/src/open62541/src/util/../ua_securechannel.h 2
/src/open62541/src/server/ua_transport_ws.c 6
/src/open62541/src/server/ua_transport_tcp_reverse.c 1
/src/open62541/src/server/ua_server_discovery.c 1
/src/open62541/src/pubsub/ua_pubsub_manager.c 26
/src/open62541/src/pubsub/ua_pubsub_ns0.c 41
/src/open62541/src/pubsub/../server/ua_server_internal.h 4
/src/open62541/src/pubsub/ua_pubsub_internal.h 3
/src/open62541/src/pubsub/ua_pubsub_connection.c 10
/src/open62541/src/pubsub/../util/ua_util_internal.h 6
/src/open62541/src/pubsub/ua_pubsub_readergroup.c 10
/src/open62541/src/pubsub/ua_pubsub_reader.c 15
/src/open62541/src/pubsub/ua_pubsub_writergroup.c 24
/src/open62541/src/pubsub/ua_pubsub_writer.c 17
/src/open62541/src/pubsub/ua_pubsub_dataset.c 19
/src/open62541/src/pubsub/ua_pubsub_networkmessage_binary.c 26
/src/open62541/src/pubsub/ua_pubsub_networkmessage_json.c 4
/src/open62541/tests/testing-plugins/testing_networklayers.c 1

Fuzzer: fuzz_tcp_message

Call tree

The calltree shows the control flow of the fuzzer. This is overlaid with coverage information to display how much of the potential code a fuzzer can reach is in fact covered at runtime. In the following there is a link to a detailed calltree visualisation as well as a bitmap showing a high-level view of the calltree. For further information about these topics please see the glossary for full calltree and calltree overview

Call tree overview bitmap:

The distribution of callsites in terms of coloring is
Color Runtime hitcount Callsite count Percentage
red 0 4083 23.1%
gold [1:9] 18 0.10%
yellow [10:29] 2 0.01%
greenyellow [30:49] 0 0.0%
lawngreen 50+ 13519 76.7%
All colors 17622 100

Fuzz blockers

The following nodes represent call sites where fuzz blockers occur.

Amount of callsites blocked Calltree index Parent function Callsite Largest blocked function
1016 15978 initPubSubNS0 call site: 15978 addDataSetReaderConfig
274 15538 UA_KeyValueMap_setScalar call site: 15538 Service_ActivateSession
236 15300 processHEL call site: 15300 processMSG
139 17055 initPubSubNS0 call site: 17055 UA_Server_addPublishedDataSet
130 1011 copyAttributeIntoNode call site: 01011 UA_MonitoredItem_processSampledValue
117 1307 UA_KeyValueMap_clear call site: 01307 recordModelChangeEvent
109 15172 extractCompleteChunk call site: 15172 unpackPayloadMSG
96 14811 UA_SecureChannel_clear call site: 14811 shutdownSecureChannel
80 1427 endModelChange call site: 01427 UA_ModelChangeAccumulator_finalize
65 15016 notifySubscription call site: 15016 cleanupSessionEntry
62 1244 browseRecursive call site: 01244 UA_Server_readBrowseName
60 545 UA_findDataTypeWithCustom call site: 00545 UA_DataType_toDescription

Runtime coverage analysis

Covered functions
2328
Functions that are reachable but not covered
791
Reachable functions
2925
Percentage of reachable functions covered
72.96%
NB: The sum of covered functions and functions that are reachable but not covered need not be equal to Reachable functions . This is because the reachability analysis is an approximation and thus at runtime some functions may be covered that are not included in the reachability analysis. This is a limitation of our static analysis capabilities.
Function name source code lines source lines hit percentage hit

Files reached

filename functions hit
/src/open62541/tests/fuzz/fuzz_tcp_message.cc 2
/src/open62541/tests/fuzz/custom_memory_manager.c 2
/src/open62541/plugins/include/open62541/server_config_default.h 1
/src/open62541/plugins/ua_config_default.c 7
/src/open62541/plugins/ua_nodestore_ziptree.c 1
/src/open62541/plugins/ua_log_stdout.c 2
/src/open62541/arch/posix/eventloop_posix.c 1
/work/open62541/src_generated/open62541/config.h 5
/src/open62541/arch/common/timer.c 1
/src/open62541/src/ua_types.c 84
/src/open62541/arch/posix/eventloop_posix_tcp.c 1
/work/open62541/src_generated/open62541/types_generated.h 119
/src/open62541/arch/posix/eventloop_posix_udp.c 1
/src/open62541/arch/posix/eventloop_posix_eth.c 1
/src/open62541/arch/posix/eventloop_posix_interrupt.c 2
/src/open62541/include/open62541/plugin/log.h 6
/src/open62541/arch/posix/clock_posix.c 1
/src/open62541/deps/mp_printf.c 13
/src/open62541/deps/dtoa.c 10
/src/open62541/src/util/ua_util.c 28
/src/open62541/src/util/ua_util_internal.h 16
/src/open62541/deps/itoa.c 3
/src/open62541/deps/base64.c 2
/src/open62541/plugins/crypto/ua_certificategroup_none.c 1
/src/open62541/src/server/ua_server_config.c 1
/src/open62541/plugins/crypto/ua_securitypolicy_none.c 2
/src/open62541/plugins/crypto/openssl/securitypolicy_common.c 10
/src/open62541/plugins/ua_accesscontrol_default.c 1
/src/open62541/include/open62541/server.h 1
/src/open62541/src/server/ua_server.c 24
/src/open62541/src/server/../util/ua_util_internal.h 4
/work/open62541/src_generated/open62541/statuscodes.c 1
/src/open62541/deps/pcg_basic.c 2
/src/open62541/src/server/ua_session.c 11
/src/open62541/src/server/ua_server_modelchange.c 19
/src/open62541/src/server/ua_subscription.c 35
/src/open62541/src/server/ua_server_async.c 19
/src/open62541/src/server/ua_server_ns0.c 14
/src/open62541/src/server/ua_services_nodemanagement.c 72
/src/open62541/src/server/ua_server_nodes.c 49
/src/open62541/src/server/ua_services_view.c 46
/src/open62541/deps/ziptree.c 11
/src/open62541/include/open62541/plugin/nodestore.h 7
/src/open62541/src/server/ua_server_internal.h 20
/src/open62541/src/server/ua_services_attribute.c 47
/src/open62541/src/server/ua_server_utils.c 19
/src/open62541/src/ua_types_definition.c 5
/src/open62541/src/util/ua_types_lex.c 12
/src/open62541/src/server/ua_subscription_datachange.c 8
/src/open62541/src/server/ua_subscription.h 7
/src/open62541/src/server/ua_subscription_event.c 12
/src/open62541/src/server/ua_server_auditing.c 14
/work/open62541/src_generated/open62541/namespace0_generated.c 1675
/src/open62541/src/ua_types_encoding_xml.c 3
/src/open62541/deps/yxml.c 34
/src/open62541/src/server/ua_services_session.c 25
/src/open62541/src/server/ua_transport_tcp.c 22
/src/open62541/src/server/ua_transport_http.c 9
/src/open62541/src/ua_securechannel_http.c 6
/src/open62541/src/ua_types_encoding_json.c 11
/src/open62541/src/ua_types_encoding_binary.c 6
/src/open62541/src/ua_securechannel.c 30
/src/open62541/src/ua_securechannel_crypto.c 22
/src/open62541/src/ua_securechannel.h 1
/src/open62541/src/server/ua_services_monitoreditem.c 1
/src/open62541/src/server/ua_services_subscription.c 1
/src/open62541/src/server/ua_services_securechannel.c 5
/work/open62541/src_generated/open62541/transport_generated.h 3
/src/open62541/src/server/ua_services.c 6
/src/open62541/plugins/crypto/openssl/certificategroup.c 3
/usr/include/openssl/x509v3.h 3
/usr/include/openssl/asn1.h 1
/src/open62541/src/server/ua_services_discovery.c 11
/src/open62541/src/server/../ua_securechannel.h 3
/src/open62541/src/server/ua_server_ns0_diagnostics.c 1
/src/open62541/src/util/ua_encryptedsecret.c 6
/src/open62541/src/util/../ua_securechannel.h 2
/src/open62541/src/server/ua_transport_ws.c 6
/src/open62541/src/server/ua_transport_tcp_reverse.c 1
/src/open62541/src/server/ua_server_discovery.c 1
/src/open62541/src/pubsub/ua_pubsub_manager.c 26
/src/open62541/src/pubsub/ua_pubsub_ns0.c 41
/src/open62541/src/pubsub/../server/ua_server_internal.h 4
/src/open62541/src/pubsub/ua_pubsub_internal.h 3
/src/open62541/src/pubsub/ua_pubsub_connection.c 10
/src/open62541/src/pubsub/../util/ua_util_internal.h 6
/src/open62541/src/pubsub/ua_pubsub_readergroup.c 10
/src/open62541/src/pubsub/ua_pubsub_reader.c 15
/src/open62541/src/pubsub/ua_pubsub_writergroup.c 24
/src/open62541/src/pubsub/ua_pubsub_writer.c 17
/src/open62541/src/pubsub/ua_pubsub_dataset.c 19
/src/open62541/src/pubsub/ua_pubsub_networkmessage_binary.c 26
/src/open62541/src/pubsub/ua_pubsub_networkmessage_json.c 4

Fuzzer: fuzz_config_json

Call tree

The calltree shows the control flow of the fuzzer. This is overlaid with coverage information to display how much of the potential code a fuzzer can reach is in fact covered at runtime. In the following there is a link to a detailed calltree visualisation as well as a bitmap showing a high-level view of the calltree. For further information about these topics please see the glossary for full calltree and calltree overview

Call tree overview bitmap:

The distribution of callsites in terms of coloring is
Color Runtime hitcount Callsite count Percentage
red 0 4340 23.9%
gold [1:9] 79 0.43%
yellow [10:29] 15 0.08%
greenyellow [30:49] 4 0.02%
lawngreen 50+ 13662 75.4%
All colors 18100 100

Fuzz blockers

The following nodes represent call sites where fuzz blockers occur.

Amount of callsites blocked Calltree index Parent function Callsite Largest blocked function
1016 16593 initPubSubNS0 call site: 16593 addDataSetReaderConfig
432 15721 UA_Session_clear call site: 15721 processSecureChannelMessage
302 16155 UA_KeyValueMap_setScalar call site: 16155 createServerConnection
185 15360 UA_Session_detachFromSecureChannel call site: 15360 shutdownSecureChannel
151 1640 copyAttributeIntoNode call site: 01640 UA_MonitoredItem_processSampledValue
139 17670 initPubSubNS0 call site: 17670 UA_Server_addPublishedDataSet
117 1928 UA_KeyValueMap_clear call site: 01928 recordModelChangeEvent
87 1148 Variant_clear call site: 01148 UA_DataType_toDescription
80 2048 endModelChange call site: 02048 UA_ModelChangeAccumulator_finalize
65 15636 notifySubscription call site: 15636 cleanupSessionEntry
62 1865 browseRecursive call site: 01865 UA_Server_readBrowseName
52 2145 deleteNodeOperation_inner call site: 02145 deleteNodeSet

Runtime coverage analysis

Covered functions
2277
Functions that are reachable but not covered
858
Reachable functions
2993
Percentage of reachable functions covered
71.33%
NB: The sum of covered functions and functions that are reachable but not covered need not be equal to Reachable functions . This is because the reachability analysis is an approximation and thus at runtime some functions may be covered that are not included in the reachability analysis. This is a limitation of our static analysis capabilities.
Function name source code lines source lines hit percentage hit

Files reached

filename functions hit
/src/open62541/tests/fuzz/fuzz_config_json.cc 1
/src/open62541/plugins/ua_config_json.c 33
/src/open62541/plugins/include/open62541/server_config_default.h 2
/src/open62541/plugins/ua_config_default.c 7
/src/open62541/plugins/ua_nodestore_ziptree.c 1
/src/open62541/plugins/ua_log_stdout.c 2
/src/open62541/arch/posix/eventloop_posix.c 1
/work/open62541/src_generated/open62541/config.h 5
/src/open62541/arch/common/timer.c 1
/src/open62541/src/ua_types.c 84
/src/open62541/arch/posix/eventloop_posix_tcp.c 1
/work/open62541/src_generated/open62541/types_generated.h 122
/src/open62541/arch/posix/eventloop_posix_udp.c 1
/src/open62541/arch/posix/eventloop_posix_eth.c 1
/src/open62541/arch/posix/eventloop_posix_interrupt.c 2
/src/open62541/include/open62541/plugin/log.h 5
/src/open62541/arch/posix/clock_posix.c 1
/src/open62541/deps/mp_printf.c 13
/src/open62541/deps/dtoa.c 10
/src/open62541/src/util/ua_util.c 30
/src/open62541/src/util/ua_util_internal.h 16
/src/open62541/deps/itoa.c 3
/src/open62541/deps/base64.c 2
/src/open62541/plugins/crypto/ua_certificategroup_none.c 1
/src/open62541/src/server/ua_server_config.c 1
/src/open62541/plugins/crypto/ua_securitypolicy_none.c 2
/src/open62541/plugins/crypto/openssl/securitypolicy_common.c 14
/src/open62541/plugins/ua_accesscontrol_default.c 1
/src/open62541/deps/cj5.c 10
/src/open62541/deps/utf8.h 1
/src/open62541/src/ua_types_encoding_json.c 13
/src/open62541/plugins/crypto/openssl/securitypolicy_basic128rsa15.c 1
/src/open62541/plugins/crypto/openssl/securitypolicy_basic256.c 1
/src/open62541/plugins/crypto/openssl/securitypolicy_basic256sha256.c 1
/src/open62541/plugins/crypto/openssl/securitypolicy_aes128sha256rsaoaep.c 1
/src/open62541/plugins/crypto/openssl/securitypolicy_aes256sha256rsapss.c 1
/src/open62541/plugins/crypto/openssl/securitypolicy_eccnistp256.c 2
/src/open62541/plugins/crypto/ua_certificategroup_filestore.c 10
/src/open62541/plugins/crypto/openssl/certificategroup.c 5
/usr/include/openssl/x509.h 6
/src/open62541/plugins/crypto/ua_filestore_common.c 1
/src/open62541/src/server/ua_server.c 15
/src/open62541/src/server/../util/ua_util_internal.h 4
/work/open62541/src_generated/open62541/statuscodes.c 1
/src/open62541/deps/pcg_basic.c 2
/src/open62541/src/server/ua_session.c 11
/src/open62541/src/server/ua_server_modelchange.c 19
/src/open62541/src/server/ua_subscription.c 35
/src/open62541/src/server/ua_server_async.c 16
/src/open62541/src/server/ua_server_ns0.c 14
/src/open62541/src/server/ua_services_nodemanagement.c 72
/src/open62541/src/server/ua_server_nodes.c 49
/src/open62541/src/server/ua_services_view.c 46
/src/open62541/deps/ziptree.c 11
/src/open62541/include/open62541/plugin/nodestore.h 7
/src/open62541/src/server/ua_server_internal.h 20
/src/open62541/src/server/ua_services_attribute.c 47
/src/open62541/src/server/ua_server_utils.c 18
/src/open62541/src/ua_types_definition.c 5
/src/open62541/src/util/ua_types_lex.c 12
/src/open62541/src/server/ua_subscription_datachange.c 8
/src/open62541/src/server/ua_subscription.h 7
/src/open62541/src/server/ua_subscription_event.c 12
/src/open62541/src/server/ua_server_auditing.c 14
/work/open62541/src_generated/open62541/namespace0_generated.c 1675
/src/open62541/src/ua_types_encoding_xml.c 3
/src/open62541/deps/yxml.c 34
/src/open62541/src/server/ua_services_session.c 24
/src/open62541/src/server/ua_transport_tcp.c 22
/src/open62541/src/server/ua_transport_http.c 7
/src/open62541/src/ua_securechannel_http.c 6
/src/open62541/src/ua_types_encoding_binary.c 6
/src/open62541/src/ua_securechannel.c 30
/src/open62541/src/ua_securechannel_crypto.c 22
/src/open62541/src/ua_securechannel.h 1
/src/open62541/src/server/ua_services_monitoreditem.c 1
/src/open62541/src/server/ua_services_subscription.c 1
/src/open62541/src/server/ua_services_securechannel.c 5
/work/open62541/src_generated/open62541/transport_generated.h 3
/src/open62541/src/server/ua_services.c 6
/usr/include/openssl/x509v3.h 3
/usr/include/openssl/asn1.h 1
/src/open62541/src/server/ua_services_discovery.c 9
/src/open62541/src/server/../ua_securechannel.h 3
/src/open62541/src/server/ua_server_ns0_diagnostics.c 1
/src/open62541/src/util/ua_encryptedsecret.c 6
/src/open62541/src/util/../ua_securechannel.h 2
/src/open62541/src/server/ua_transport_ws.c 6
/src/open62541/src/server/ua_transport_tcp_reverse.c 1
/src/open62541/src/server/ua_server_discovery.c 1
/src/open62541/src/pubsub/ua_pubsub_manager.c 26
/src/open62541/src/pubsub/ua_pubsub_ns0.c 41
/src/open62541/src/pubsub/../server/ua_server_internal.h 4
/src/open62541/src/pubsub/ua_pubsub_internal.h 3
/src/open62541/src/pubsub/ua_pubsub_connection.c 10
/src/open62541/src/pubsub/../util/ua_util_internal.h 6
/src/open62541/src/pubsub/ua_pubsub_readergroup.c 10
/src/open62541/src/pubsub/ua_pubsub_reader.c 15
/src/open62541/src/pubsub/ua_pubsub_writergroup.c 24
/src/open62541/src/pubsub/ua_pubsub_writer.c 17
/src/open62541/src/pubsub/ua_pubsub_dataset.c 19
/src/open62541/src/pubsub/ua_pubsub_networkmessage_binary.c 26
/src/open62541/src/pubsub/ua_pubsub_networkmessage_json.c 4

Fuzzer: fuzz_mdns_message

Call tree

The calltree shows the control flow of the fuzzer. This is overlaid with coverage information to display how much of the potential code a fuzzer can reach is in fact covered at runtime. In the following there is a link to a detailed calltree visualisation as well as a bitmap showing a high-level view of the calltree. For further information about these topics please see the glossary for full calltree and calltree overview

Call tree overview bitmap:

The distribution of callsites in terms of coloring is
Color Runtime hitcount Callsite count Percentage
red 0 54 41.5%
gold [1:9] 0 0.0%
yellow [10:29] 1 0.76%
greenyellow [30:49] 1 0.76%
lawngreen 50+ 74 56.9%
All colors 130 100

Fuzz blockers

The following nodes represent call sites where fuzz blockers occur.

Amount of callsites blocked Calltree index Parent function Callsite Largest blocked function
18 73 _a_match call site: 00073 _conflict
17 50 _r_next call site: 00050 _r_send
6 37 mdnsd_in call site: 00037 _is_local_ipv4
4 104 _cache call site: 00104 _q_answer
3 95 mdnsd_in call site: 00095 _conflict
2 122 _q_next call site: 00122 _q_answer
2 127 mdnsd_free call site: 00127 _free_record
1 33 inet_anyaddr call site: 00033 htons
1 44 mdnsd_in call site: 00044 vsyslog

Runtime coverage analysis

Covered functions
20
Functions that are reachable but not covered
33
Reachable functions
53
Percentage of reachable functions covered
37.74%
NB: The sum of covered functions and functions that are reachable but not covered need not be equal to Reachable functions . This is because the reachability analysis is an approximation and thus at runtime some functions may be covered that are not included in the reachability analysis. This is a limitation of our static analysis capabilities.
Function name source code lines source lines hit percentage hit

Files reached

filename functions hit
/src/open62541/tests/fuzz/fuzz_mdns_message.cc 1
/work/open62541/src_generated/mdnsd/1035.c 6
/work/open62541/src_generated/mdnsd/mdnsd.c 26
/work/open62541/src_generated/mdnsd/inet.c 3
/work/open62541/src_generated/mdnsd/log.c 1

Fuzzer: fuzz_json_decode

Call tree

The calltree shows the control flow of the fuzzer. This is overlaid with coverage information to display how much of the potential code a fuzzer can reach is in fact covered at runtime. In the following there is a link to a detailed calltree visualisation as well as a bitmap showing a high-level view of the calltree. For further information about these topics please see the glossary for full calltree and calltree overview

Call tree overview bitmap:

The distribution of callsites in terms of coloring is
Color Runtime hitcount Callsite count Percentage
red 0 1 4.0%
gold [1:9] 0 0.0%
yellow [10:29] 0 0.0%
greenyellow [30:49] 0 0.0%
lawngreen 50+ 24 96.0%
All colors 25 100

Fuzz blockers

The following nodes represent call sites where fuzz blockers occur.

Amount of callsites blocked Calltree index Parent function Callsite Largest blocked function
1 23 LLVMFuzzerTestOneInput call site: 00023 UA_clear

Runtime coverage analysis

Covered functions
115
Functions that are reachable but not covered
0
Reachable functions
15
Percentage of reachable functions covered
100.0%
NB: The sum of covered functions and functions that are reachable but not covered need not be equal to Reachable functions . This is because the reachability analysis is an approximation and thus at runtime some functions may be covered that are not included in the reachability analysis. This is a limitation of our static analysis capabilities.
Warning: The number of covered functions are larger than the number of reachable functions. This means that there are more functions covered at runtime than are extracted using static analysis. This is likely a result of the static analysis component failing to extract the right call graph or the coverage runtime being compiled with sanitizers in code that the static analysis has not analysed. This can happen if lto/gold is not used in all places that coverage instrumentation is used.
Function name source code lines source lines hit percentage hit

Files reached

filename functions hit
/src/open62541/tests/fuzz/fuzz_json_decode.cc 1
/work/open62541/src_generated/open62541/types_generated.h 2
/src/open62541/src/ua_types_encoding_json.c 2
/src/open62541/deps/cj5.c 7
/src/open62541/src/ua_types.c 1

Fuzzer: fuzz_xml_decode_encode

Call tree

The calltree shows the control flow of the fuzzer. This is overlaid with coverage information to display how much of the potential code a fuzzer can reach is in fact covered at runtime. In the following there is a link to a detailed calltree visualisation as well as a bitmap showing a high-level view of the calltree. For further information about these topics please see the glossary for full calltree and calltree overview

Call tree overview bitmap:

The distribution of callsites in terms of coloring is
Color Runtime hitcount Callsite count Percentage
red 0 12 8.82%
gold [1:9] 1 0.73%
yellow [10:29] 3 2.20%
greenyellow [30:49] 0 0.0%
lawngreen 50+ 120 88.2%
All colors 136 100

Fuzz blockers

The following nodes represent call sites where fuzz blockers occur.

Amount of callsites blocked Calltree index Parent function Callsite Largest blocked function
3 123 LLVMFuzzerTestOneInput call site: 00123
2 109 LLVMFuzzerTestOneInput call site: 00109 UA_calcSizeXml
2 112 UA_encodeXml call site: 00112 UA_ByteString_clear
2 117 LLVMFuzzerTestOneInput call site: 00117
1 88 UA_decodeXml call site: 00088 UA_STRING
1 104 LLVMFuzzerTestOneInput call site: 00104 UA_clear
1 107 UA_ByteString_allocBuffer call site: 00107

Runtime coverage analysis

Covered functions
202
Functions that are reachable but not covered
4
Reachable functions
59
Percentage of reachable functions covered
93.22%
NB: The sum of covered functions and functions that are reachable but not covered need not be equal to Reachable functions . This is because the reachability analysis is an approximation and thus at runtime some functions may be covered that are not included in the reachability analysis. This is a limitation of our static analysis capabilities.
Warning: The number of covered functions are larger than the number of reachable functions. This means that there are more functions covered at runtime than are extracted using static analysis. This is likely a result of the static analysis component failing to extract the right call graph or the coverage runtime being compiled with sanitizers in code that the static analysis has not analysed. This can happen if lto/gold is not used in all places that coverage instrumentation is used.
Function name source code lines source lines hit percentage hit

Files reached

filename functions hit
/src/open62541/tests/fuzz/fuzz_xml_decode_encode.cc 1
/work/open62541/src_generated/open62541/types_generated.h 5
/src/open62541/src/ua_types_encoding_xml.c 9
/src/open62541/deps/yxml.c 34
/src/open62541/src/ua_types.c 4

Fuzzer: fuzz_pubsub_connection_config

Call tree

The calltree shows the control flow of the fuzzer. This is overlaid with coverage information to display how much of the potential code a fuzzer can reach is in fact covered at runtime. In the following there is a link to a detailed calltree visualisation as well as a bitmap showing a high-level view of the calltree. For further information about these topics please see the glossary for full calltree and calltree overview

Call tree overview bitmap:

The distribution of callsites in terms of coloring is
Color Runtime hitcount Callsite count Percentage
red 0 10 27.7%
gold [1:9] 0 0.0%
yellow [10:29] 0 0.0%
greenyellow [30:49] 0 0.0%
lawngreen 50+ 26 72.2%
All colors 36 100

Fuzz blockers

The following nodes represent call sites where fuzz blockers occur.

Amount of callsites blocked Calltree index Parent function Callsite Largest blocked function
3 9 UA_PubSubConnectionConfig_copy call site: 00009 UA_String_copy
2 24 UA_PubSubConnectionConfig_clear call site: 00024 UA_String_clear
1 14 UA_PubSubConnectionConfig_copy call site: 00014 UA_copy
1 20 UA_Array_copy call site: 00020 UA_Array_delete
1 22 UA_Array_delete call site: 00022 UA_PubSubConnectionConfig_clear
1 29 UA_PubSubConnectionConfig_clear call site: 00029 UA_clear
1 32 UA_PubSubConnectionConfig_clear call site: 00032 UA_Array_delete

Runtime coverage analysis

Covered functions
82
Functions that are reachable but not covered
0
Reachable functions
19
Percentage of reachable functions covered
100.0%
NB: The sum of covered functions and functions that are reachable but not covered need not be equal to Reachable functions . This is because the reachability analysis is an approximation and thus at runtime some functions may be covered that are not included in the reachability analysis. This is a limitation of our static analysis capabilities.
Warning: The number of covered functions are larger than the number of reachable functions. This means that there are more functions covered at runtime than are extracted using static analysis. This is likely a result of the static analysis component failing to extract the right call graph or the coverage runtime being compiled with sanitizers in code that the static analysis has not analysed. This can happen if lto/gold is not used in all places that coverage instrumentation is used.
Function name source code lines source lines hit percentage hit

Files reached

filename functions hit
/src/open62541/tests/fuzz/fuzz_pubsub_connection_config.cc 1
/src/open62541/src/ua_types_encoding_binary.c 3
/src/open62541/src/ua_types.c 4
/src/open62541/src/pubsub/ua_pubsub_connection.c 2
/work/open62541/src_generated/open62541/types_generated.h 5
/src/open62541/src/pubsub/ua_pubsub_manager.c 2
/src/open62541/src/util/ua_util.c 2

Fuzzer: fuzz_src_ua_util

Call tree

The calltree shows the control flow of the fuzzer. This is overlaid with coverage information to display how much of the potential code a fuzzer can reach is in fact covered at runtime. In the following there is a link to a detailed calltree visualisation as well as a bitmap showing a high-level view of the calltree. For further information about these topics please see the glossary for full calltree and calltree overview

Call tree overview bitmap:

The distribution of callsites in terms of coloring is
Color Runtime hitcount Callsite count Percentage
red 0 0 0.0%
gold [1:9] 0 0.0%
yellow [10:29] 0 0.0%
greenyellow [30:49] 0 0.0%
lawngreen 50+ 17 100.%
All colors 17 100

Runtime coverage analysis

Covered functions
8
Functions that are reachable but not covered
3
Reachable functions
13
Percentage of reachable functions covered
76.92%
NB: The sum of covered functions and functions that are reachable but not covered need not be equal to Reachable functions . This is because the reachability analysis is an approximation and thus at runtime some functions may be covered that are not included in the reachability analysis. This is a limitation of our static analysis capabilities.
Function name source code lines source lines hit percentage hit

Files reached

filename functions hit
/src/open62541/tests/fuzz/fuzz_src_ua_util.cc 3
/src/open62541/tests/fuzz/custom_memory_manager.c 1
/src/open62541/src/util/ua_util.c 4

Fuzzer: fuzz_attributeoperand

Call tree

The calltree shows the control flow of the fuzzer. This is overlaid with coverage information to display how much of the potential code a fuzzer can reach is in fact covered at runtime. In the following there is a link to a detailed calltree visualisation as well as a bitmap showing a high-level view of the calltree. For further information about these topics please see the glossary for full calltree and calltree overview

Call tree overview bitmap:

The distribution of callsites in terms of coloring is
Color Runtime hitcount Callsite count Percentage
red 0 383 75.5%
gold [1:9] 0 0.0%
yellow [10:29] 10 1.97%
greenyellow [30:49] 8 1.57%
lawngreen 50+ 106 20.9%
All colors 507 100

Fuzz blockers

The following nodes represent call sites where fuzz blockers occur.

Amount of callsites blocked Calltree index Parent function Callsite Largest blocked function
151 247 UA_STRING call site: 00247 buildEnumDefinitionFromProperties
104 98 stringOrder call site: 00098 UA_Server_readBrowseName
40 206 UA_Array_delete call site: 00206 UA_DataType_toDescription
39 58 lookupRefType call site: 00058 UA_Server_browseRecursive
7 15 UA_String_unescape call site: 00015 UA_NamespaceMapping_uri2Index
6 33 parse_nodeid_body call site: 00033 UA_readNumberWithBase
5 416 nodeId_printEscape call site: 00416 UA_String_escapedSize
5 480 UA_AttributeOperand_print call site: 00480 UA_STRING
3 10 parse_nodeid call site: 00010 UA_String_unescape
3 445 printRelativePath call site: 00445 UA_STRING
2 203 UA_ByteString_allocBuffer call site: 00203 UA_Variant_copyRange
2 402 parse_relativepathElement call site: 00402 UA_RelativePathElement_clear

Runtime coverage analysis

Covered functions
83
Functions that are reachable but not covered
159
Reachable functions
229
Percentage of reachable functions covered
30.57%
NB: The sum of covered functions and functions that are reachable but not covered need not be equal to Reachable functions . This is because the reachability analysis is an approximation and thus at runtime some functions may be covered that are not included in the reachability analysis. This is a limitation of our static analysis capabilities.
Function name source code lines source lines hit percentage hit

Files reached

filename functions hit
/src/open62541/tests/fuzz/fuzz_attributeoperand.cc 1
/src/open62541/tests/fuzz/custom_memory_manager.c 1
/work/open62541/src_generated/open62541/types_generated.h 49
/src/open62541/src/util/ua_types_lex.c 12
/src/open62541/src/ua_types.c 58
/src/open62541/src/util/ua_util_internal.h 6
/src/open62541/src/util/ua_util.c 14
/src/open62541/deps/base64.c 2
/src/open62541/src/server/ua_services_view.c 19
/src/open62541/src/server/ua_server.c 2
/work/open62541/src_generated/open62541/config.h 3
/src/open62541/include/open62541/plugin/nodestore.h 3
/src/open62541/src/server/ua_server_nodes.c 7
/src/open62541/deps/ziptree.c 6
/src/open62541/src/server/ua_server_internal.h 4
/src/open62541/src/server/ua_services_attribute.c 23
/src/open62541/src/server/ua_server_utils.c 2
/src/open62541/src/ua_types_definition.c 5
/src/open62541/deps/itoa.c 3

Fuzzer: fuzz_eventfilter_parse

Call tree

The calltree shows the control flow of the fuzzer. This is overlaid with coverage information to display how much of the potential code a fuzzer can reach is in fact covered at runtime. In the following there is a link to a detailed calltree visualisation as well as a bitmap showing a high-level view of the calltree. For further information about these topics please see the glossary for full calltree and calltree overview

Call tree overview bitmap:

The distribution of callsites in terms of coloring is
Color Runtime hitcount Callsite count Percentage
red 0 363 64.1%
gold [1:9] 2 0.35%
yellow [10:29] 1 0.17%
greenyellow [30:49] 1 0.17%
lawngreen 50+ 199 35.1%
All colors 566 100

Fuzz blockers

The following nodes represent call sites where fuzz blockers occur.

Amount of callsites blocked Calltree index Parent function Callsite Largest blocked function
107 346 UA_ExtensionObject_setValue call site: 00346 buildEnumDefinitionFromProperties
105 156 stringOrder call site: 00156 UA_Server_readBrowseName
39 116 lookupRefType call site: 00116 UA_Server_browseRecursive
39 306 UA_QualifiedName_parseEx call site: 00306 UA_DataType_toStructureDescription
14 265 Variant_clear call site: 00265 readExternalValueAttribute
13 280 UA_Array_copy call site: 00280 UA_findDataTypeWithCustom
11 294 UA_findDataTypeWithCustom call site: 00294 UA_DataType_toDescription
7 45 UA_String_unescape call site: 00045 UA_NamespaceMapping_uri2Index
4 40 parse_nodeid call site: 00040 UA_String_unescape
2 262 UA_Array_delete call site: 00262 Variant_clear
2 526 UA_Array_append call site: 00526 UA_Array_delete
1 37 UA_EventFilter_lex call site: 00037 UA_NodeId_parseEx

Runtime coverage analysis

Covered functions
200
Functions that are reachable but not covered
142
Reachable functions
265
Percentage of reachable functions covered
46.42%
NB: The sum of covered functions and functions that are reachable but not covered need not be equal to Reachable functions . This is because the reachability analysis is an approximation and thus at runtime some functions may be covered that are not included in the reachability analysis. This is a limitation of our static analysis capabilities.
Function name source code lines source lines hit percentage hit

Files reached

filename functions hit
/src/open62541/tests/fuzz/fuzz_eventfilter_parse.cc 1
/src/open62541/src/ua_types.c 52
/work/open62541/src_generated/open62541/types_generated.h 58
/src/open62541/src/util/ua_eventfilter_grammar.c 14
/src/open62541/src/util/ua_eventfilter_lex.c 2
/src/open62541/src/util/ua_eventfilter_parser.c 14
/src/open62541/include/open62541/plugin/log.h 1
/src/open62541/src/ua_types_encoding_json.c 2
/src/open62541/deps/cj5.c 7
/src/open62541/src/util/ua_types_lex.c 19
/src/open62541/src/util/ua_util.c 6
/src/open62541/deps/base64.c 1
/src/open62541/src/util/ua_util_internal.h 5
/src/open62541/src/server/ua_services_view.c 19
/src/open62541/src/server/ua_server.c 2
/work/open62541/src_generated/open62541/config.h 3
/src/open62541/include/open62541/plugin/nodestore.h 3
/src/open62541/src/server/ua_server_nodes.c 7
/src/open62541/deps/ziptree.c 6
/src/open62541/src/server/ua_server_internal.h 4
/src/open62541/src/server/ua_services_attribute.c 23
/src/open62541/src/server/ua_server_utils.c 2
/src/open62541/src/ua_types_definition.c 5

Fuzzer: fuzz_binary_message

Call tree

The calltree shows the control flow of the fuzzer. This is overlaid with coverage information to display how much of the potential code a fuzzer can reach is in fact covered at runtime. In the following there is a link to a detailed calltree visualisation as well as a bitmap showing a high-level view of the calltree. For further information about these topics please see the glossary for full calltree and calltree overview

Call tree overview bitmap:

The distribution of callsites in terms of coloring is
Color Runtime hitcount Callsite count Percentage
red 0 3822 21.8%
gold [1:9] 17 0.09%
yellow [10:29] 6 0.03%
greenyellow [30:49] 8 0.04%
lawngreen 50+ 13647 77.9%
All colors 17500 100

Fuzz blockers

The following nodes represent call sites where fuzz blockers occur.

Amount of callsites blocked Calltree index Parent function Callsite Largest blocked function
1016 15979 initPubSubNS0 call site: 15979 addDataSetReaderConfig
184 15621 policyUriContains call site: 15621 Service_ActivateSession
139 17056 initPubSubNS0 call site: 17056 UA_Server_addPublishedDataSet
130 1012 copyAttributeIntoNode call site: 01012 UA_MonitoredItem_processSampledValue
117 1308 UA_KeyValueMap_clear call site: 01308 recordModelChangeEvent
87 519 Variant_clear call site: 00519 UA_DataType_toDescription
80 1428 endModelChange call site: 01428 UA_ModelChangeAccumulator_finalize
80 15539 UA_KeyValueMap_setScalar call site: 15539 UA_Session_remove
62 1245 browseRecursive call site: 01245 UA_Server_readBrowseName
59 15017 notifySubscription call site: 15017 UA_Subscription_delete
52 1525 deleteNodeOperation_inner call site: 01525 deleteNodeSet
49 14951 UA_Subscription_delete call site: 14951 deleteMonitoredItem

Runtime coverage analysis

Covered functions
2356
Functions that are reachable but not covered
723
Reachable functions
2900
Percentage of reachable functions covered
75.07%
NB: The sum of covered functions and functions that are reachable but not covered need not be equal to Reachable functions . This is because the reachability analysis is an approximation and thus at runtime some functions may be covered that are not included in the reachability analysis. This is a limitation of our static analysis capabilities.
Function name source code lines source lines hit percentage hit

Files reached

filename functions hit
/src/open62541/tests/fuzz/fuzz_binary_message.cc 1
/src/open62541/tests/fuzz/custom_memory_manager.c 1
/src/open62541/plugins/include/open62541/server_config_default.h 2
/src/open62541/plugins/ua_config_default.c 7
/src/open62541/plugins/ua_nodestore_ziptree.c 1
/src/open62541/plugins/ua_log_stdout.c 2
/src/open62541/arch/posix/eventloop_posix.c 1
/work/open62541/src_generated/open62541/config.h 5
/src/open62541/arch/common/timer.c 1
/src/open62541/src/ua_types.c 84
/src/open62541/arch/posix/eventloop_posix_tcp.c 1
/work/open62541/src_generated/open62541/types_generated.h 121
/src/open62541/arch/posix/eventloop_posix_udp.c 1
/src/open62541/arch/posix/eventloop_posix_eth.c 1
/src/open62541/arch/posix/eventloop_posix_interrupt.c 2
/src/open62541/include/open62541/plugin/log.h 6
/src/open62541/arch/posix/clock_posix.c 1
/src/open62541/deps/mp_printf.c 13
/src/open62541/deps/dtoa.c 10
/src/open62541/src/util/ua_util.c 28
/src/open62541/src/util/ua_util_internal.h 16
/src/open62541/deps/itoa.c 3
/src/open62541/deps/base64.c 2
/src/open62541/plugins/crypto/ua_certificategroup_none.c 1
/src/open62541/src/server/ua_server_config.c 1
/src/open62541/plugins/crypto/ua_securitypolicy_none.c 2
/src/open62541/plugins/crypto/openssl/securitypolicy_common.c 10
/src/open62541/plugins/ua_accesscontrol_default.c 1
/src/open62541/include/open62541/server.h 1
/src/open62541/src/server/ua_server.c 15
/src/open62541/src/server/../util/ua_util_internal.h 4
/work/open62541/src_generated/open62541/statuscodes.c 1
/src/open62541/deps/pcg_basic.c 2
/src/open62541/src/server/ua_session.c 11
/src/open62541/src/server/ua_server_modelchange.c 19
/src/open62541/src/server/ua_subscription.c 35
/src/open62541/src/server/ua_server_async.c 16
/src/open62541/src/server/ua_server_ns0.c 14
/src/open62541/src/server/ua_services_nodemanagement.c 72
/src/open62541/src/server/ua_server_nodes.c 49
/src/open62541/src/server/ua_services_view.c 46
/src/open62541/deps/ziptree.c 11
/src/open62541/include/open62541/plugin/nodestore.h 7
/src/open62541/src/server/ua_server_internal.h 20
/src/open62541/src/server/ua_services_attribute.c 47
/src/open62541/src/server/ua_server_utils.c 18
/src/open62541/src/ua_types_definition.c 5
/src/open62541/src/util/ua_types_lex.c 12
/src/open62541/src/server/ua_subscription_datachange.c 8
/src/open62541/src/server/ua_subscription.h 7
/src/open62541/src/server/ua_subscription_event.c 12
/src/open62541/src/server/ua_server_auditing.c 14
/work/open62541/src_generated/open62541/namespace0_generated.c 1675
/src/open62541/src/ua_types_encoding_xml.c 3
/src/open62541/deps/yxml.c 34
/src/open62541/src/server/ua_services_session.c 24
/src/open62541/src/server/ua_transport_tcp.c 22
/src/open62541/src/server/ua_transport_http.c 7
/src/open62541/src/ua_securechannel_http.c 6
/src/open62541/src/ua_types_encoding_json.c 11
/src/open62541/src/ua_types_encoding_binary.c 6
/src/open62541/src/ua_securechannel.c 30
/src/open62541/src/ua_securechannel_crypto.c 22
/src/open62541/src/ua_securechannel.h 1
/src/open62541/src/server/ua_services_monitoreditem.c 1
/src/open62541/src/server/ua_services_subscription.c 1
/src/open62541/src/server/ua_services_securechannel.c 5
/work/open62541/src_generated/open62541/transport_generated.h 3
/src/open62541/src/server/ua_services.c 6
/src/open62541/plugins/crypto/openssl/certificategroup.c 3
/usr/include/openssl/x509v3.h 3
/usr/include/openssl/asn1.h 1
/src/open62541/src/server/ua_services_discovery.c 9
/src/open62541/src/server/../ua_securechannel.h 3
/src/open62541/src/server/ua_server_ns0_diagnostics.c 1
/src/open62541/src/util/ua_encryptedsecret.c 6
/src/open62541/src/util/../ua_securechannel.h 2
/src/open62541/src/server/ua_transport_ws.c 6
/src/open62541/src/server/ua_transport_tcp_reverse.c 1
/src/open62541/src/server/ua_server_discovery.c 1
/src/open62541/src/pubsub/ua_pubsub_manager.c 26
/src/open62541/src/pubsub/ua_pubsub_ns0.c 41
/src/open62541/src/pubsub/../server/ua_server_internal.h 4
/src/open62541/src/pubsub/ua_pubsub_internal.h 3
/src/open62541/src/pubsub/ua_pubsub_connection.c 10
/src/open62541/src/pubsub/../util/ua_util_internal.h 6
/src/open62541/src/pubsub/ua_pubsub_readergroup.c 10
/src/open62541/src/pubsub/ua_pubsub_reader.c 15
/src/open62541/src/pubsub/ua_pubsub_writergroup.c 24
/src/open62541/src/pubsub/ua_pubsub_writer.c 17
/src/open62541/src/pubsub/ua_pubsub_dataset.c 19
/src/open62541/src/pubsub/ua_pubsub_networkmessage_binary.c 26
/src/open62541/src/pubsub/ua_pubsub_networkmessage_json.c 4
/src/open62541/tests/testing-plugins/testing_networklayers.c 1

Fuzzer: fuzz_datatype_description

Call tree

The calltree shows the control flow of the fuzzer. This is overlaid with coverage information to display how much of the potential code a fuzzer can reach is in fact covered at runtime. In the following there is a link to a detailed calltree visualisation as well as a bitmap showing a high-level view of the calltree. For further information about these topics please see the glossary for full calltree and calltree overview

Call tree overview bitmap:

The distribution of callsites in terms of coloring is
Color Runtime hitcount Callsite count Percentage
red 0 37 25.0%
gold [1:9] 10 6.75%
yellow [10:29] 1 0.67%
greenyellow [30:49] 2 1.35%
lawngreen 50+ 98 66.2%
All colors 148 100

Fuzz blockers

The following nodes represent call sites where fuzz blockers occur.

Amount of callsites blocked Calltree index Parent function Callsite Largest blocked function
11 92 parse_qn call site: 00092 UA_String_unescape
2 18 fromDescription call site: 00018 UA_QualifiedName_printEx
2 23 reverse call site: 00023 UA_ByteString_allocBuffer
2 124 UA_DataType_toStructureDescription call site: 00124 UA_StructureDescription_clear
2 133 UA_DataType_toStructureDescription call site: 00133 UA_StructureDescription_clear
1 15 fromDescription call site: 00015 UA_copy
1 30 UA_DataType_clear call site: 00030 UA_clear
1 39 UA_DataType_fromEnumDescription call site: 00039 UA_DataType_clear
1 52 UA_DataType_fromStructureDescription call site: 00052 UA_order
1 58 guidOrder call site: 00058 stringOrder
1 60 stringOrder call site: 00060 nodeIdOrder
1 71 UA_DataType_fromStructureDescription call site: 00071 UA_DataType_clear

Runtime coverage analysis

Covered functions
93
Functions that are reachable but not covered
11
Reachable functions
75
Percentage of reachable functions covered
85.33%
NB: The sum of covered functions and functions that are reachable but not covered need not be equal to Reachable functions . This is because the reachability analysis is an approximation and thus at runtime some functions may be covered that are not included in the reachability analysis. This is a limitation of our static analysis capabilities.
Warning: The number of covered functions are larger than the number of reachable functions. This means that there are more functions covered at runtime than are extracted using static analysis. This is likely a result of the static analysis component failing to extract the right call graph or the coverage runtime being compiled with sanitizers in code that the static analysis has not analysed. This can happen if lto/gold is not used in all places that coverage instrumentation is used.
Function name source code lines source lines hit percentage hit

Files reached

filename functions hit
/src/open62541/tests/fuzz/fuzz_datatype_description.cc 1
/src/open62541/tests/fuzz/custom_memory_manager.c 1
/src/open62541/src/ua_types.c 22
/src/open62541/src/ua_types_encoding_binary.c 3
/work/open62541/src_generated/open62541/types_generated.h 19
/src/open62541/src/ua_types_definition.c 11
/src/open62541/deps/itoa.c 3
/src/open62541/src/util/ua_util_internal.h 2
/src/open62541/src/util/ua_types_lex.c 4
/src/open62541/src/util/ua_util.c 4

Fuzzer: fuzz_client

Call tree

The calltree shows the control flow of the fuzzer. This is overlaid with coverage information to display how much of the potential code a fuzzer can reach is in fact covered at runtime. In the following there is a link to a detailed calltree visualisation as well as a bitmap showing a high-level view of the calltree. For further information about these topics please see the glossary for full calltree and calltree overview

Call tree overview bitmap:

The distribution of callsites in terms of coloring is
Color Runtime hitcount Callsite count Percentage
red 0 1459 92.5%
gold [1:9] 0 0.0%
yellow [10:29] 93 5.89%
greenyellow [30:49] 19 1.20%
lawngreen 50+ 6 0.38%
All colors 1577 100

Fuzz blockers

The following nodes represent call sites where fuzz blockers occur.

Amount of callsites blocked Calltree index Parent function Callsite Largest blocked function
586 548 UA_SecureChannel_clear call site: 00548 __Client_networkCallback
305 1140 cleanupSession call site: 01140 __Client_Subscriptions_backgroundPublish
162 363 UA_Array_delete call site: 00363 __Client_Subscriptions_backgroundPublish
138 172 notifyClientState call site: 00172 __UA_Client_startup
95 76 __Client_Service call site: 00076 connectSync
74 1446 processServiceResponse call site: 01446 connectActivity
50 312 UA_UNLOCK call site: 00312 __Client_Subscriptions_backgroundPublish
23 38 setLocalCertificate_none call site: 00038 UA_OpenSSL_LoadLocalCertificate
4 1567 UA_ClientConfig_clear call site: 01567 UA_DataType_clear
3 539 UA_SecureChannel_deleteBuffered call site: 00539 UA_Chunk_delete
3 544 UA_NamespaceMapping_delete call site: 00544 UA_Array_delete
2 17 UA_ConnectionManager_new_POSIX_TCP call site: 00017 UA_copy

Runtime coverage analysis

Covered functions
97
Functions that are reachable but not covered
388
Reachable functions
457
Percentage of reachable functions covered
15.1%
NB: The sum of covered functions and functions that are reachable but not covered need not be equal to Reachable functions . This is because the reachability analysis is an approximation and thus at runtime some functions may be covered that are not included in the reachability analysis. This is a limitation of our static analysis capabilities.
Function name source code lines source lines hit percentage hit

Files reached

filename functions hit
/src/open62541/tests/fuzz/fuzz_client.cc 1
/src/open62541/tests/testing-plugins/test_helpers.c 1
/src/open62541/plugins/ua_log_stdout.c 2
/src/open62541/plugins/ua_config_default.c 1
/src/open62541/arch/posix/eventloop_posix.c 1
/work/open62541/src_generated/open62541/config.h 5
/src/open62541/arch/common/timer.c 1
/src/open62541/src/ua_types.c 49
/src/open62541/arch/posix/eventloop_posix_tcp.c 1
/work/open62541/src_generated/open62541/types_generated.h 51
/src/open62541/arch/posix/eventloop_posix_udp.c 1
/src/open62541/arch/posix/eventloop_posix_interrupt.c 2
/src/open62541/include/open62541/plugin/log.h 5
/src/open62541/plugins/crypto/ua_certificategroup_none.c 1
/src/open62541/plugins/crypto/ua_securitypolicy_none.c 2
/src/open62541/plugins/crypto/openssl/securitypolicy_common.c 8
/src/open62541/src/client/ua_client.c 33
/src/open62541/src/ua_securechannel.c 32
/src/open62541/src/client/ua_client_connect.c 54
/src/open62541/src/util/ua_util_internal.h 16
/src/open62541/src/ua_securechannel_crypto.c 22
/src/open62541/src/ua_securechannel.h 1
/src/open62541/src/ua_types_encoding_binary.c 6
/src/open62541/src/client/../util/ua_util_internal.h 3
/work/open62541/src_generated/open62541/statuscodes.c 1
/work/open62541/src_generated/open62541/transport_generated.h 4
/src/open62541/src/ua_securechannel_http.c 7
/src/open62541/src/ua_types_encoding_json.c 4
/src/open62541/src/client/ua_client_subscriptions.c 29
/src/open62541/deps/ziptree.c 8
/src/open62541/src/util/ua_util.c 15
/src/open62541/deps/itoa.c 3
/src/open62541/deps/base64.c 1
/src/open62541/src/client/ua_client_connect_http.c 6
/src/open62541/plugins/crypto/openssl/certificategroup.c 2
/usr/include/openssl/asn1.h 1
/src/open62541/src/client/../ua_securechannel.h 3
/src/open62541/deps/mp_printf.c 13
/src/open62541/deps/dtoa.c 10
/src/open62541/src/client/ua_client_discovery.c 1
/usr/include/openssl/x509v3.h 3
/src/open62541/src/util/ua_encryptedsecret.c 8
/src/open62541/src/util/../ua_securechannel.h 1
/src/open62541/arch/posix/clock_posix.c 1
/src/open62541/deps/cj5.c 7

Fuzzer: fuzz_base64_encode

Call tree

The calltree shows the control flow of the fuzzer. This is overlaid with coverage information to display how much of the potential code a fuzzer can reach is in fact covered at runtime. In the following there is a link to a detailed calltree visualisation as well as a bitmap showing a high-level view of the calltree. For further information about these topics please see the glossary for full calltree and calltree overview

Call tree overview bitmap:

The distribution of callsites in terms of coloring is
Color Runtime hitcount Callsite count Percentage
red 0 0 0.0%
gold [1:9] 0 0.0%
yellow [10:29] 0 0.0%
greenyellow [30:49] 0 0.0%
lawngreen 50+ 3 100.%
All colors 3 100

Runtime coverage analysis

Covered functions
3
Functions that are reachable but not covered
0
Reachable functions
3
Percentage of reachable functions covered
100.0%
NB: The sum of covered functions and functions that are reachable but not covered need not be equal to Reachable functions . This is because the reachability analysis is an approximation and thus at runtime some functions may be covered that are not included in the reachability analysis. This is a limitation of our static analysis capabilities.
Function name source code lines source lines hit percentage hit

Files reached

filename functions hit
/src/open62541/tests/fuzz/fuzz_base64_encode.cc 1
/src/open62541/deps/base64.c 2

Fuzzer: fuzz_pubsub_json

Call tree

The calltree shows the control flow of the fuzzer. This is overlaid with coverage information to display how much of the potential code a fuzzer can reach is in fact covered at runtime. In the following there is a link to a detailed calltree visualisation as well as a bitmap showing a high-level view of the calltree. For further information about these topics please see the glossary for full calltree and calltree overview

Call tree overview bitmap:

The distribution of callsites in terms of coloring is
Color Runtime hitcount Callsite count Percentage
red 0 6 9.09%
gold [1:9] 0 0.0%
yellow [10:29] 1 1.51%
greenyellow [30:49] 2 3.03%
lawngreen 50+ 57 86.3%
All colors 66 100

Fuzz blockers

The following nodes represent call sites where fuzz blockers occur.

Amount of callsites blocked Calltree index Parent function Callsite Largest blocked function
2 57 UA_DataSetMessage_clear call site: 00057 UA_DataValue_clear
1 39 NetworkMessage_decodeJsonInternal call site: 00039 decodeFieldsInternal
1 53 UA_NetworkMessage_decodeJson call site: 00053 UA_Array_delete
1 60 UA_NetworkMessage_clear call site: 00060 UA_clear
1 62 UA_NetworkMessage_clear call site: 00062 UA_clear

Runtime coverage analysis

Covered functions
142
Functions that are reachable but not covered
3
Reachable functions
30
Percentage of reachable functions covered
90.0%
NB: The sum of covered functions and functions that are reachable but not covered need not be equal to Reachable functions . This is because the reachability analysis is an approximation and thus at runtime some functions may be covered that are not included in the reachability analysis. This is a limitation of our static analysis capabilities.
Warning: The number of covered functions are larger than the number of reachable functions. This means that there are more functions covered at runtime than are extracted using static analysis. This is likely a result of the static analysis component failing to extract the right call graph or the coverage runtime being compiled with sanitizers in code that the static analysis has not analysed. This can happen if lto/gold is not used in all places that coverage instrumentation is used.
Function name source code lines source lines hit percentage hit

Files reached

filename functions hit
/src/open62541/tests/fuzz/fuzz_pubsub_json.cc 1
/src/open62541/tests/fuzz/custom_memory_manager.c 1
/src/open62541/src/pubsub/ua_pubsub_networkmessage_json.c 2
/src/open62541/src/ua_types_encoding_json.c 7
/src/open62541/deps/cj5.c 7
/src/open62541/src/pubsub/../ua_types_encoding_json.h 2
/src/open62541/src/ua_types_encoding_json.h 2
/src/open62541/src/pubsub/ua_pubsub_networkmessage_binary.c 2
/src/open62541/src/ua_types.c 2
/work/open62541/src_generated/open62541/types_generated.h 3

Fuzz engine guidance

This sections provides heuristics that can be used as input to a fuzz engine when running a given fuzz target. The current focus is on providing input that is usable by libFuzzer.

/src/open62541/tests/fuzz/fuzz_json_decode_encode.cc

Dictionary

Use this with the libFuzzer -dict=DICT.file flag


Fuzzer function priority

Use one of these functions as input to libfuzzer with flag: -focus_function name

-focus_function=['LLVMFuzzerTestOneInput', 'UA_ByteString_allocBuffer']

/src/open62541/tests/fuzz/fuzz_pubsub_binary.cc

Dictionary

Use this with the libFuzzer -dict=DICT.file flag


Fuzzer function priority

Use one of these functions as input to libfuzzer with flag: -focus_function name

-focus_function=['stringOrder', 'UA_DataSetMessage_keyFrame_decodeBinary', 'UA_DataSetMessage_clear', 'UA_NetworkMessage_clear']

/src/open62541/tests/fuzz/fuzz_certificate_parse.cc

Dictionary

Use this with the libFuzzer -dict=DICT.file flag


Fuzzer function priority

Use one of these functions as input to libfuzzer with flag: -focus_function name

-focus_function=['UA_CertificateUtils_verifyApplicationUri', 'LLVMFuzzerTestOneInput', 'UA_OpenSSL_LoadPemCertificate', 'UA_CertificateUtils_getKeySize', 'UA_OpenSSL_LoadCertificate', 'UA_OpenSSL_LoadCrl', 'UA_CertificateUtils_getSubjectName']

/src/open62541/tests/fuzz/fuzz_mdns_xht.cc

Dictionary

Use this with the libFuzzer -dict=DICT.file flag


/src/open62541/tests/fuzz/fuzz_base64_decode.cc

Dictionary

Use this with the libFuzzer -dict=DICT.file flag


/src/open62541/tests/fuzz/fuzz_parse_string.cc

Dictionary

Use this with the libFuzzer -dict=DICT.file flag


Fuzzer function priority

Use one of these functions as input to libfuzzer with flag: -focus_function name

-focus_function=['UA_STRING', 'stringOrder', 'UA_Array_delete', 'lookupRefType', 'UA_String_unescape', 'parse_nodeid', 'nodeId_printEscape', 'printRelativePath', 'parse_qn']

/src/open62541/tests/fuzz/fuzz_binary_decode.cc

Dictionary

Use this with the libFuzzer -dict=DICT.file flag


Fuzzer function priority

Use one of these functions as input to libfuzzer with flag: -focus_function name

-focus_function=['UA_encodeBinaryInternal', 'LLVMFuzzerTestOneInput', 'UA_encodeBinary', 'UA_ByteString_allocBuffer', 'copySubString', 'UA_Variant_copyRange', 'UA_DataValue_copyRange']

/src/open62541/tests/fuzz/fuzz_server_services.cc

Dictionary

Use this with the libFuzzer -dict=DICT.file flag


Fuzzer function priority

Use one of these functions as input to libfuzzer with flag: -focus_function name

-focus_function=['initPubSubNS0', 'ctxClear', 'copyAttributeIntoNode', 'Service_ActivateSession_inner', 'UA_KeyValueMap_clear', 'UA_SecureChannel_clear', 'findSessionByToken', 'Variant_clear', 'Service_CreateMonitoredItems']

/src/open62541/tests/fuzz/fuzz_process_request.cc

Dictionary

Use this with the libFuzzer -dict=DICT.file flag


Fuzzer function priority

Use one of these functions as input to libfuzzer with flag: -focus_function name

-focus_function=['findSingleChildNode', 'ctxClear', 'initPubSubNS0', 'copyAttributeIntoNode', 'getNodeContext', 'Variant_clear', 'UA_SecureChannel_clear', 'endModelChange', 'selectEndpointAndTokenPolicy', 'browseRecursive']

/src/open62541/tests/fuzz/fuzz_tcp_message.cc

Dictionary

Use this with the libFuzzer -dict=DICT.file flag


Fuzzer function priority

Use one of these functions as input to libfuzzer with flag: -focus_function name

-focus_function=['initPubSubNS0', 'UA_KeyValueMap_setScalar', 'processHEL', 'copyAttributeIntoNode', 'UA_KeyValueMap_clear', 'extractCompleteChunk', 'UA_SecureChannel_clear', 'endModelChange', 'notifySubscription']

/src/open62541/tests/fuzz/fuzz_config_json.cc

Dictionary

Use this with the libFuzzer -dict=DICT.file flag


Fuzzer function priority

Use one of these functions as input to libfuzzer with flag: -focus_function name

-focus_function=['initPubSubNS0', 'UA_Session_clear', 'UA_KeyValueMap_setScalar', 'UA_Session_detachFromSecureChannel', 'copyAttributeIntoNode', 'UA_KeyValueMap_clear', 'Variant_clear', 'endModelChange', 'notifySubscription']

/src/open62541/tests/fuzz/fuzz_mdns_message.cc

Dictionary

Use this with the libFuzzer -dict=DICT.file flag


Fuzzer function priority

Use one of these functions as input to libfuzzer with flag: -focus_function name

-focus_function=['_a_match', '_r_next', 'mdnsd_in', '_cache', '_q_next', 'mdnsd_free', 'inet_anyaddr']

/src/open62541/tests/fuzz/fuzz_json_decode.cc

Dictionary

Use this with the libFuzzer -dict=DICT.file flag


Fuzzer function priority

Use one of these functions as input to libfuzzer with flag: -focus_function name

-focus_function=['LLVMFuzzerTestOneInput']

/src/open62541/tests/fuzz/fuzz_xml_decode_encode.cc

Dictionary

Use this with the libFuzzer -dict=DICT.file flag


Fuzzer function priority

Use one of these functions as input to libfuzzer with flag: -focus_function name

-focus_function=['LLVMFuzzerTestOneInput', 'UA_encodeXml', 'UA_decodeXml', 'UA_ByteString_allocBuffer']

/src/open62541/tests/fuzz/fuzz_pubsub_connection_config.cc

Dictionary

Use this with the libFuzzer -dict=DICT.file flag


Fuzzer function priority

Use one of these functions as input to libfuzzer with flag: -focus_function name

-focus_function=['UA_PubSubConnectionConfig_copy', 'UA_PubSubConnectionConfig_clear', 'UA_Array_copy', 'UA_Array_delete']

/src/open62541/tests/fuzz/fuzz_src_ua_util.cc

Dictionary

Use this with the libFuzzer -dict=DICT.file flag


/src/open62541/tests/fuzz/fuzz_attributeoperand.cc

Dictionary

Use this with the libFuzzer -dict=DICT.file flag


Fuzzer function priority

Use one of these functions as input to libfuzzer with flag: -focus_function name

-focus_function=['UA_STRING', 'stringOrder', 'UA_Array_delete', 'lookupRefType', 'UA_String_unescape', 'parse_nodeid_body', 'nodeId_printEscape', 'UA_AttributeOperand_print', 'parse_nodeid', 'printRelativePath']

/src/open62541/tests/fuzz/fuzz_eventfilter_parse.cc

Dictionary

Use this with the libFuzzer -dict=DICT.file flag


Fuzzer function priority

Use one of these functions as input to libfuzzer with flag: -focus_function name

-focus_function=['UA_ExtensionObject_setValue', 'stringOrder', 'lookupRefType', 'UA_QualifiedName_parseEx', 'Variant_clear', 'UA_Array_copy', 'UA_findDataTypeWithCustom', 'UA_String_unescape', 'parse_nodeid', 'UA_Array_delete']

/src/open62541/tests/fuzz/fuzz_binary_message.cc

Dictionary

Use this with the libFuzzer -dict=DICT.file flag


Fuzzer function priority

Use one of these functions as input to libfuzzer with flag: -focus_function name

-focus_function=['initPubSubNS0', 'policyUriContains', 'copyAttributeIntoNode', 'UA_KeyValueMap_clear', 'Variant_clear', 'endModelChange', 'UA_KeyValueMap_setScalar', 'browseRecursive', 'notifySubscription']

/src/open62541/tests/fuzz/fuzz_datatype_description.cc

Dictionary

Use this with the libFuzzer -dict=DICT.file flag


Fuzzer function priority

Use one of these functions as input to libfuzzer with flag: -focus_function name

-focus_function=['parse_qn', 'fromDescription', 'reverse', 'UA_DataType_toStructureDescription', 'UA_DataType_clear', 'UA_DataType_fromEnumDescription', 'UA_DataType_fromStructureDescription', 'guidOrder']

/src/open62541/tests/fuzz/fuzz_client.cc

Dictionary

Use this with the libFuzzer -dict=DICT.file flag


Fuzzer function priority

Use one of these functions as input to libfuzzer with flag: -focus_function name

-focus_function=['UA_SecureChannel_clear', 'cleanupSession', 'UA_Array_delete', 'notifyClientState', '__Client_Service', 'processServiceResponse', 'UA_UNLOCK', 'setLocalCertificate_none', 'UA_ClientConfig_clear', 'UA_SecureChannel_deleteBuffered']

/src/open62541/tests/fuzz/fuzz_base64_encode.cc

Dictionary

Use this with the libFuzzer -dict=DICT.file flag


/src/open62541/tests/fuzz/fuzz_pubsub_json.cc

Dictionary

Use this with the libFuzzer -dict=DICT.file flag


Fuzzer function priority

Use one of these functions as input to libfuzzer with flag: -focus_function name

-focus_function=['UA_DataSetMessage_clear', 'NetworkMessage_decodeJsonInternal', 'UA_NetworkMessage_decodeJson', 'UA_NetworkMessage_clear']

Runtime coverage analysis

This section shows analysis of runtime coverage data.

For futher technical details on how this section is generated, please see the Glossary .

Complex functions with low coverage

Func name Function total lines Lines covered at runtime percentage covered Reached by fuzzers
clearStructure 35 19 54.28% ['fuzz_json_decode_encode', 'fuzz_parse_string', 'fuzz_json_decode', 'fuzz_config_json', 'fuzz_client', 'fuzz_datatype_description', 'fuzz_pubsub_binary', 'fuzz_pubsub_connection_config', 'fuzz_tcp_message', 'fuzz_xml_decode_encode', 'fuzz_binary_decode', 'fuzz_eventfilter_parse', 'fuzz_binary_message', 'fuzz_pubsub_json', 'fuzz_attributeoperand', 'fuzz_process_request', 'fuzz_server_services']
structureOrder 51 28 54.90% ['fuzz_json_decode_encode', 'fuzz_attributeoperand', 'fuzz_xml_decode_encode', 'fuzz_binary_decode']
UA_encodeJson 33 17 51.51% ['fuzz_json_decode_encode', 'fuzz_client', 'fuzz_process_request', 'fuzz_config_json', 'fuzz_binary_message', 'fuzz_tcp_message', 'fuzz_server_services']
DiagnosticInfo_encodeJson 35 12 34.28% ['fuzz_json_decode_encode']
decodeJsonStructureInternal 81 39 48.14% ['fuzz_json_decode_encode', 'fuzz_json_decode', 'fuzz_pubsub_json', 'fuzz_eventfilter_parse']
UA_CertificateUtils_verifyApplicationUri 37 12 32.43% ['fuzz_certificate_parse', 'fuzz_client', 'fuzz_process_request', 'fuzz_config_json', 'fuzz_binary_message', 'fuzz_tcp_message', 'fuzz_server_services']
UA_CertificateUtils_getThumbprint 33 3 9.090% ['fuzz_certificate_parse']
lookupRefType 38 12 31.57% ['fuzz_parse_string', 'fuzz_process_request', 'fuzz_config_json', 'fuzz_eventfilter_parse', 'fuzz_binary_message', 'fuzz_attributeoperand', 'fuzz_tcp_message', 'fuzz_server_services']
UA_KeyValueRestriction_validate 35 15 42.85% ['fuzz_process_request', 'fuzz_config_json', 'fuzz_binary_message', 'fuzz_tcp_message', 'fuzz_server_services']
UA_EventLoopPOSIX_start 77 38 49.35% ['fuzz_process_request', 'fuzz_config_json', 'fuzz_binary_message', 'fuzz_tcp_message', 'fuzz_server_services']
openSignalPipe 33 17 51.51% ['fuzz_process_request', 'fuzz_config_json', 'fuzz_binary_message', 'fuzz_tcp_message', 'fuzz_server_services']
format_string_loop 239 110 46.02% ['fuzz_client', 'fuzz_process_request', 'fuzz_config_json', 'fuzz_binary_message', 'fuzz_tcp_message', 'fuzz_server_services']
print_integer_finalization 51 16 31.37% ['fuzz_client', 'fuzz_process_request', 'fuzz_config_json', 'fuzz_binary_message', 'fuzz_tcp_message', 'fuzz_server_services']
addDriver 32 12 37.5% ['fuzz_process_request', 'fuzz_config_json', 'fuzz_binary_message', 'fuzz_tcp_message', 'fuzz_server_services']
auditEvent 87 4 4.597% ['fuzz_process_request', 'fuzz_config_json', 'fuzz_binary_message', 'fuzz_tcp_message', 'fuzz_server_services']
UA_Node_insertOrUpdateLocale 37 14 37.83% ['fuzz_process_request', 'fuzz_config_json', 'fuzz_binary_message', 'fuzz_tcp_message', 'fuzz_server_services']
createSubscriptionObject 56 18 32.14% ['fuzz_server_services']
compatibleValue 37 10 27.02% ['fuzz_process_request', 'fuzz_config_json', 'fuzz_binary_message', 'fuzz_tcp_message', 'fuzz_server_services']
Operation_WriteWithNode 64 26 40.62% ['fuzz_process_request', 'fuzz_config_json', 'fuzz_binary_message', 'fuzz_tcp_message', 'fuzz_server_services']
readValueAttributeComplete 33 18 54.54% ['fuzz_parse_string', 'fuzz_process_request', 'fuzz_config_json', 'fuzz_eventfilter_parse', 'fuzz_binary_message', 'fuzz_attributeoperand', 'fuzz_tcp_message', 'fuzz_server_services']
copyAttributeIntoNode 209 57 27.27% ['fuzz_process_request', 'fuzz_config_json', 'fuzz_binary_message', 'fuzz_tcp_message', 'fuzz_server_services']
writeNodeValueAttribute 91 39 42.85% ['fuzz_process_request', 'fuzz_config_json', 'fuzz_binary_message', 'fuzz_tcp_message', 'fuzz_server_services']
triggerImmediateDataChange 33 4 12.12% ['fuzz_process_request', 'fuzz_config_json', 'fuzz_binary_message', 'fuzz_tcp_message', 'fuzz_server_services']
process_FindServersOnNetwork 50 4 8.0% ['fuzz_server_services']
process_RegisterServer 104 5 4.807% ['fuzz_process_request', 'fuzz_server_services']
Service_CreateMonitoredItems 34 18 52.94% ['fuzz_server_services']
callEarlyConstructors 66 35 53.03% ['fuzz_process_request', 'fuzz_config_json', 'fuzz_binary_message', 'fuzz_tcp_message', 'fuzz_server_services']
addNode_raw 73 35 47.94% ['fuzz_process_request', 'fuzz_config_json', 'fuzz_binary_message', 'fuzz_tcp_message', 'fuzz_server_services']
useVariableTypeAttributes 52 20 38.46% ['fuzz_process_request', 'fuzz_config_json', 'fuzz_binary_message', 'fuzz_tcp_message', 'fuzz_server_services']
typeCheckVariableNode 81 28 34.56% ['fuzz_process_request', 'fuzz_config_json', 'fuzz_binary_message', 'fuzz_tcp_message', 'fuzz_server_services']
recursiveCallConstructors 92 42 45.65% ['fuzz_process_request', 'fuzz_config_json', 'fuzz_binary_message', 'fuzz_tcp_message', 'fuzz_server_services']
UA_Server_addMethodNodeEx_finish 90 41 45.55% ['fuzz_process_request', 'fuzz_config_json', 'fuzz_binary_message', 'fuzz_tcp_message', 'fuzz_server_services']
Service_Cancel 32 15 46.87% ['fuzz_process_request', 'fuzz_server_services']
Service_ActivateSession_inner 231 103 44.58% ['fuzz_process_request', 'fuzz_config_json', 'fuzz_binary_message', 'fuzz_tcp_message', 'fuzz_server_services']
Service_ModifySubscription 41 12 29.26% ['fuzz_server_services']
browseResolvedNode 39 21 53.84% ['fuzz_process_request', 'fuzz_config_json', 'fuzz_binary_message', 'fuzz_tcp_message', 'fuzz_server_services']
browseWithNode 65 27 41.53% ['fuzz_process_request', 'fuzz_config_json', 'fuzz_binary_message', 'fuzz_tcp_message', 'fuzz_server_services']
walkBrowsePathElement 95 52 54.73% ['fuzz_parse_string', 'fuzz_process_request', 'fuzz_config_json', 'fuzz_eventfilter_parse', 'fuzz_binary_message', 'fuzz_attributeoperand', 'fuzz_tcp_message', 'fuzz_server_services']
UA_Session_detachFromSecureChannel 33 16 48.48% ['fuzz_process_request', 'fuzz_config_json', 'fuzz_binary_message', 'fuzz_tcp_message', 'fuzz_server_services']
activateSession_default 73 29 39.72% ['fuzz_process_request']
UA_AsyncManager_cancelSession 41 16 39.02% ['fuzz_process_request', 'fuzz_config_json', 'fuzz_binary_message', 'fuzz_tcp_message', 'fuzz_server_services']
Service_Read 52 18 34.61% ['fuzz_process_request']
Service_HistoryRead 121 9 7.438% ['fuzz_process_request']
Service_HistoryUpdate 64 11 17.18% ['fuzz_process_request']
UA_Session_remove 66 33 50.0% ['fuzz_process_request', 'fuzz_config_json', 'fuzz_binary_message', 'fuzz_tcp_message', 'fuzz_server_services']
Service_CreateSession_inner 158 75 47.46% ['fuzz_process_request', 'fuzz_config_json', 'fuzz_binary_message', 'fuzz_tcp_message', 'fuzz_server_services']
signCreateSessionResponse 35 3 8.571% ['fuzz_process_request', 'fuzz_config_json', 'fuzz_binary_message', 'fuzz_tcp_message', 'fuzz_server_services']
selectTokenPolicy 69 27 39.13% ['fuzz_process_request', 'fuzz_config_json', 'fuzz_binary_message', 'fuzz_tcp_message', 'fuzz_server_services']
Service_Publish 76 12 15.78% ['fuzz_process_request']
Operation_TransferSubscription 114 10 8.771% ['fuzz_process_request']
Operation_BrowseNext 54 10 18.51% ['fuzz_process_request']
TCP_registerListenSocket 167 72 43.11% ['fuzz_tcp_message']
TCP_connectionSocketCallback 64 28 43.75% ['fuzz_tcp_message']
TCP_sendWithConnection 42 23 54.76% ['fuzz_tcp_message']
UA_PubSubManager_setState 36 16 44.44% ['fuzz_process_request', 'fuzz_config_json', 'fuzz_binary_message', 'fuzz_tcp_message', 'fuzz_server_services']
UA_Server_run_startup 154 70 45.45% ['fuzz_tcp_message']
UA_HttpProtocolManager_validateConfig 70 4 5.714% ['fuzz_tcp_message']
startHttp 37 8 21.62% ['fuzz_tcp_message']
startWebSocketTransport 51 7 13.72% ['fuzz_process_request', 'fuzz_config_json', 'fuzz_binary_message', 'fuzz_tcp_message', 'fuzz_server_services']
reloadCertificates 64 18 28.12% ['fuzz_config_json']
readCertificates 49 23 46.93% ['fuzz_config_json']
ApplicationTypeField_parseJson 35 16 45.71% ['fuzz_config_json']
loadCertificateFile 37 19 51.35% ['fuzz_config_json']
UA_TrustListDataType_add 73 32 43.83% ['fuzz_config_json']
mdnsd_in 96 38 39.58% ['fuzz_mdns_message']
decodeMatrixVariant 40 10 25.0% ['fuzz_xml_decode_encode']
validateCertificate 94 15 15.95% ['fuzz_process_request', 'fuzz_config_json', 'fuzz_binary_message', 'fuzz_tcp_message', 'fuzz_server_services']
UA_SecureChannel_generateLocalKeys 39 13 33.33% ['fuzz_client', 'fuzz_process_request', 'fuzz_config_json', 'fuzz_binary_message', 'fuzz_tcp_message', 'fuzz_server_services']
generateRemoteKeys 44 13 29.54% ['fuzz_client', 'fuzz_process_request', 'fuzz_config_json', 'fuzz_binary_message', 'fuzz_tcp_message', 'fuzz_server_services']
hideBytesAsym 50 15 30.0% ['fuzz_client', 'fuzz_process_request', 'fuzz_config_json', 'fuzz_binary_message', 'fuzz_tcp_message', 'fuzz_server_services']
signAndEncryptAsym 47 4 8.510% ['fuzz_client', 'fuzz_process_request', 'fuzz_config_json', 'fuzz_binary_message', 'fuzz_tcp_message', 'fuzz_server_services']
signAndEncryptSym 57 4 7.017% ['fuzz_client', 'fuzz_process_request', 'fuzz_config_json', 'fuzz_binary_message', 'fuzz_tcp_message', 'fuzz_server_services']
setBufPos 40 5 12.5% ['fuzz_client', 'fuzz_process_request', 'fuzz_config_json', 'fuzz_binary_message', 'fuzz_tcp_message', 'fuzz_server_services']
decryptAndVerifyChunk 115 43 37.39% ['fuzz_client', 'fuzz_process_request', 'fuzz_config_json', 'fuzz_binary_message', 'fuzz_tcp_message', 'fuzz_server_services']
processServiceResponse 41 10 24.39% ['fuzz_client']
__Client_Service 61 8 13.11% ['fuzz_client']

Files and Directories in report

This section shows which files and directories are considered in this report. The main reason for showing this is fuzz introspector may include more code in the reasoning than is desired. This section helps identify if too many files/directories are included, e.g. third party code, which may be irrelevant for the threat model. In the event too much is included, fuzz introspector supports a configuration file that can exclude data from the report. See the following link for more information on how to create a config file: link

Files in report

Source file Reached by Covered by
[] []
/src/open62541/src/server/ua_subscription.c ['fuzz_server_services', 'fuzz_process_request', 'fuzz_tcp_message', 'fuzz_config_json', 'fuzz_binary_message'] ['fuzz_server_services', 'fuzz_process_request', 'fuzz_tcp_message', 'fuzz_config_json', 'fuzz_binary_message']
/src/open62541/src/server/ua_services_view.c ['fuzz_parse_string', 'fuzz_server_services', 'fuzz_process_request', 'fuzz_tcp_message', 'fuzz_config_json', 'fuzz_attributeoperand', 'fuzz_eventfilter_parse', 'fuzz_binary_message'] ['fuzz_server_services', 'fuzz_process_request', 'fuzz_tcp_message', 'fuzz_config_json', 'fuzz_binary_message']
/src/open62541/src/ua_securechannel.h ['fuzz_server_services', 'fuzz_process_request', 'fuzz_tcp_message', 'fuzz_config_json', 'fuzz_binary_message', 'fuzz_client'] ['fuzz_binary_message']
/src/open62541/src/pubsub/../server/ua_server_internal.h ['fuzz_server_services', 'fuzz_process_request', 'fuzz_tcp_message', 'fuzz_config_json', 'fuzz_binary_message'] ['fuzz_server_services', 'fuzz_process_request', 'fuzz_tcp_message', 'fuzz_config_json', 'fuzz_binary_message']
/src/open62541/tests/fuzz/fuzz_client.cc ['fuzz_client'] ['fuzz_client']
/src/open62541/tests/fuzz/fuzz_pubsub_json.cc ['fuzz_pubsub_json'] ['fuzz_pubsub_json']
/usr/include/openssl/asn1.h ['fuzz_server_services', 'fuzz_process_request', 'fuzz_tcp_message', 'fuzz_config_json', 'fuzz_binary_message', 'fuzz_client'] []
/src/open62541/arch/common/eventloop_common.c [] []
/src/open62541/tests/fuzz/fuzz_pubsub_binary.cc ['fuzz_pubsub_binary'] ['fuzz_pubsub_binary']
/src/open62541/plugins/crypto/ua_securitypolicy_none.c ['fuzz_server_services', 'fuzz_process_request', 'fuzz_tcp_message', 'fuzz_config_json', 'fuzz_binary_message', 'fuzz_client'] ['fuzz_server_services', 'fuzz_process_request', 'fuzz_tcp_message', 'fuzz_config_json', 'fuzz_binary_message', 'fuzz_client']
/src/open62541/include/open62541/plugin/nodestore.h ['fuzz_parse_string', 'fuzz_server_services', 'fuzz_process_request', 'fuzz_tcp_message', 'fuzz_config_json', 'fuzz_attributeoperand', 'fuzz_eventfilter_parse', 'fuzz_binary_message'] ['fuzz_server_services', 'fuzz_process_request', 'fuzz_tcp_message', 'fuzz_config_json', 'fuzz_binary_message']
/src/open62541/arch/posix/eventloop_posix_tcp.c ['fuzz_server_services', 'fuzz_process_request', 'fuzz_tcp_message', 'fuzz_config_json', 'fuzz_binary_message', 'fuzz_client'] ['fuzz_server_services', 'fuzz_process_request', 'fuzz_tcp_message', 'fuzz_config_json', 'fuzz_binary_message', 'fuzz_client']
/src/open62541/src/util/ua_eventfilter_lex.c ['fuzz_eventfilter_parse'] ['fuzz_eventfilter_parse']
/src/open62541/src/server/ua_server_ns0.c ['fuzz_server_services', 'fuzz_process_request', 'fuzz_tcp_message', 'fuzz_config_json', 'fuzz_binary_message'] ['fuzz_server_services', 'fuzz_process_request', 'fuzz_tcp_message', 'fuzz_config_json', 'fuzz_binary_message']
/src/open62541/src/client/ua_client_highlevel.c [] []
/work/open62541/src_generated/open62541/config.h ['fuzz_parse_string', 'fuzz_server_services', 'fuzz_process_request', 'fuzz_tcp_message', 'fuzz_config_json', 'fuzz_attributeoperand', 'fuzz_eventfilter_parse', 'fuzz_binary_message', 'fuzz_client'] ['fuzz_server_services', 'fuzz_process_request', 'fuzz_tcp_message', 'fuzz_config_json', 'fuzz_binary_message', 'fuzz_client']
/work/open62541/src_generated/open62541/types_generated.h ['fuzz_json_decode_encode', 'fuzz_pubsub_binary', 'fuzz_certificate_parse', 'fuzz_parse_string', 'fuzz_binary_decode', 'fuzz_server_services', 'fuzz_process_request', 'fuzz_tcp_message', 'fuzz_config_json', 'fuzz_json_decode', 'fuzz_xml_decode_encode', 'fuzz_pubsub_connection_config', 'fuzz_attributeoperand', 'fuzz_eventfilter_parse', 'fuzz_binary_message', 'fuzz_datatype_description', 'fuzz_client', 'fuzz_pubsub_json'] ['fuzz_json_decode_encode', 'fuzz_pubsub_binary', 'fuzz_certificate_parse', 'fuzz_parse_string', 'fuzz_binary_decode', 'fuzz_server_services', 'fuzz_process_request', 'fuzz_tcp_message', 'fuzz_config_json', 'fuzz_json_decode', 'fuzz_xml_decode_encode', 'fuzz_pubsub_connection_config', 'fuzz_attributeoperand', 'fuzz_eventfilter_parse', 'fuzz_binary_message', 'fuzz_datatype_description', 'fuzz_client', 'fuzz_pubsub_json']
/src/open62541/src/util/ua_eventfilter_grammar.c ['fuzz_eventfilter_parse'] ['fuzz_eventfilter_parse']
/src/open62541/arch/posix/eventloop_posix.h [] []
/src/open62541/src/util/ua_util.c ['fuzz_parse_string', 'fuzz_server_services', 'fuzz_process_request', 'fuzz_tcp_message', 'fuzz_config_json', 'fuzz_pubsub_connection_config', 'fuzz_src_ua_util', 'fuzz_attributeoperand', 'fuzz_eventfilter_parse', 'fuzz_binary_message', 'fuzz_datatype_description', 'fuzz_client'] ['fuzz_parse_string', 'fuzz_server_services', 'fuzz_process_request', 'fuzz_tcp_message', 'fuzz_config_json', 'fuzz_pubsub_connection_config', 'fuzz_src_ua_util', 'fuzz_attributeoperand', 'fuzz_eventfilter_parse', 'fuzz_binary_message', 'fuzz_datatype_description', 'fuzz_client']
/src/open62541/tests/fuzz/fuzz_process_request.cc ['fuzz_process_request'] ['fuzz_process_request']
/src/open62541/deps/base64.c ['fuzz_base64_decode', 'fuzz_parse_string', 'fuzz_server_services', 'fuzz_process_request', 'fuzz_tcp_message', 'fuzz_config_json', 'fuzz_attributeoperand', 'fuzz_eventfilter_parse', 'fuzz_binary_message', 'fuzz_client', 'fuzz_base64_encode'] ['fuzz_base64_decode', 'fuzz_parse_string', 'fuzz_server_services', 'fuzz_process_request', 'fuzz_tcp_message', 'fuzz_config_json', 'fuzz_attributeoperand', 'fuzz_eventfilter_parse', 'fuzz_binary_message', 'fuzz_base64_encode']
/src/open62541/src/client/ua_client_connect.c ['fuzz_client'] ['fuzz_client']
/src/open62541/plugins/crypto/ua_certificategroup_none.c ['fuzz_server_services', 'fuzz_process_request', 'fuzz_tcp_message', 'fuzz_config_json', 'fuzz_binary_message', 'fuzz_client'] ['fuzz_server_services', 'fuzz_process_request', 'fuzz_tcp_message', 'fuzz_config_json', 'fuzz_binary_message', 'fuzz_client']
/src/open62541/src/client/ua_client_util.c [] []
/src/open62541/tests/fuzz/fuzz_src_ua_util.cc ['fuzz_src_ua_util'] ['fuzz_src_ua_util']
/src/open62541/src/server/ua_subscription_event.c ['fuzz_server_services', 'fuzz_process_request', 'fuzz_tcp_message', 'fuzz_config_json', 'fuzz_binary_message'] []
/src/open62541/tests/fuzz/fuzz_certificate_parse.cc ['fuzz_certificate_parse'] ['fuzz_certificate_parse']
/src/open62541/deps/libc_time.c ['fuzz_certificate_parse', 'fuzz_parse_string'] ['fuzz_certificate_parse', 'fuzz_parse_string']
/work/open62541/src_generated/open62541/transport_generated.h ['fuzz_server_services', 'fuzz_process_request', 'fuzz_tcp_message', 'fuzz_config_json', 'fuzz_binary_message', 'fuzz_client'] ['fuzz_tcp_message', 'fuzz_binary_message']
/src/open62541/src/client/ua_client_discovery.c ['fuzz_client'] []
/src/open62541/tests/fuzz/fuzz_mdns_message.cc ['fuzz_mdns_message'] ['fuzz_mdns_message']
/src/open62541/src/server/ua_session.c ['fuzz_server_services', 'fuzz_process_request', 'fuzz_tcp_message', 'fuzz_config_json', 'fuzz_binary_message'] ['fuzz_server_services', 'fuzz_process_request', 'fuzz_tcp_message', 'fuzz_config_json', 'fuzz_binary_message']
/work/open62541/src_generated/mdnsd/xht.c ['fuzz_mdns_xht'] ['fuzz_mdns_xht']
/src/open62541/src/server/ua_services_monitoreditem.c ['fuzz_server_services', 'fuzz_process_request', 'fuzz_tcp_message', 'fuzz_config_json', 'fuzz_binary_message'] ['fuzz_server_services']
/src/open62541/src/server/ua_server.c ['fuzz_parse_string', 'fuzz_server_services', 'fuzz_process_request', 'fuzz_tcp_message', 'fuzz_config_json', 'fuzz_attributeoperand', 'fuzz_eventfilter_parse', 'fuzz_binary_message'] ['fuzz_server_services', 'fuzz_process_request', 'fuzz_tcp_message', 'fuzz_config_json', 'fuzz_binary_message']
/src/open62541/src/server/ua_services_attribute.c ['fuzz_parse_string', 'fuzz_server_services', 'fuzz_process_request', 'fuzz_tcp_message', 'fuzz_config_json', 'fuzz_attributeoperand', 'fuzz_eventfilter_parse', 'fuzz_binary_message'] ['fuzz_server_services', 'fuzz_process_request', 'fuzz_tcp_message', 'fuzz_config_json', 'fuzz_binary_message']
/src/open62541/src/util/ua_types_lex.c ['fuzz_parse_string', 'fuzz_server_services', 'fuzz_process_request', 'fuzz_tcp_message', 'fuzz_config_json', 'fuzz_attributeoperand', 'fuzz_eventfilter_parse', 'fuzz_binary_message', 'fuzz_datatype_description'] ['fuzz_parse_string', 'fuzz_server_services', 'fuzz_process_request', 'fuzz_tcp_message', 'fuzz_config_json', 'fuzz_attributeoperand', 'fuzz_eventfilter_parse', 'fuzz_binary_message', 'fuzz_datatype_description']
/src/open62541/plugins/crypto/openssl/securitypolicy_ecccurve25519.c [] []
/src/open62541/src/pubsub/ua_pubsub_writer.c ['fuzz_server_services', 'fuzz_process_request', 'fuzz_tcp_message', 'fuzz_config_json', 'fuzz_binary_message'] []
/src/open62541/plugins/crypto/openssl/securitypolicy_eccnistp256_aesgcm.c [] []
/src/open62541/src/ua_types_encoding_binary.c ['fuzz_pubsub_binary', 'fuzz_binary_decode', 'fuzz_server_services', 'fuzz_process_request', 'fuzz_tcp_message', 'fuzz_config_json', 'fuzz_pubsub_connection_config', 'fuzz_binary_message', 'fuzz_datatype_description', 'fuzz_client'] ['fuzz_pubsub_binary', 'fuzz_binary_decode', 'fuzz_server_services', 'fuzz_process_request', 'fuzz_tcp_message', 'fuzz_pubsub_connection_config', 'fuzz_binary_message', 'fuzz_datatype_description']
/src/open62541/src/server/ua_services.c ['fuzz_server_services', 'fuzz_process_request', 'fuzz_tcp_message', 'fuzz_config_json', 'fuzz_binary_message'] ['fuzz_server_services', 'fuzz_process_request', 'fuzz_binary_message']
/src/open62541/plugins/crypto/openssl/securitypolicy_basic128rsa15.c ['fuzz_config_json'] []
/src/open62541/src/server/ua_server_async.c ['fuzz_server_services', 'fuzz_process_request', 'fuzz_tcp_message', 'fuzz_config_json', 'fuzz_binary_message'] ['fuzz_server_services', 'fuzz_process_request', 'fuzz_tcp_message', 'fuzz_config_json', 'fuzz_binary_message']
/src/open62541/src/ua_types_definition.c ['fuzz_parse_string', 'fuzz_server_services', 'fuzz_process_request', 'fuzz_tcp_message', 'fuzz_config_json', 'fuzz_attributeoperand', 'fuzz_eventfilter_parse', 'fuzz_binary_message', 'fuzz_datatype_description'] ['fuzz_datatype_description']
/src/open62541/tests/testing-plugins/testing_networklayers.c ['fuzz_process_request', 'fuzz_binary_message'] ['fuzz_process_request', 'fuzz_binary_message']
/src/open62541/plugins/crypto/ua_certificategroup_filestore.c ['fuzz_config_json'] ['fuzz_config_json']
/src/open62541/src/server/ua_transport_http.c ['fuzz_server_services', 'fuzz_process_request', 'fuzz_tcp_message', 'fuzz_config_json', 'fuzz_binary_message'] ['fuzz_server_services', 'fuzz_process_request', 'fuzz_tcp_message', 'fuzz_config_json', 'fuzz_binary_message']
/src/open62541/tests/fuzz/fuzz_json_decode.cc ['fuzz_json_decode'] ['fuzz_json_decode']
/src/open62541/src/util/ua_util_internal.h ['fuzz_parse_string', 'fuzz_binary_decode', 'fuzz_server_services', 'fuzz_process_request', 'fuzz_tcp_message', 'fuzz_config_json', 'fuzz_attributeoperand', 'fuzz_eventfilter_parse', 'fuzz_binary_message', 'fuzz_datatype_description', 'fuzz_client'] ['fuzz_parse_string', 'fuzz_attributeoperand', 'fuzz_eventfilter_parse']
/src/open62541/src/client/ua_client.c ['fuzz_client'] ['fuzz_client']
/src/open62541/tests/fuzz/fuzz_pubsub_connection_config.cc ['fuzz_pubsub_connection_config'] ['fuzz_pubsub_connection_config']
/src/open62541/arch/common/timer.c ['fuzz_server_services', 'fuzz_process_request', 'fuzz_tcp_message', 'fuzz_config_json', 'fuzz_binary_message', 'fuzz_client'] ['fuzz_server_services', 'fuzz_process_request', 'fuzz_tcp_message', 'fuzz_config_json', 'fuzz_binary_message', 'fuzz_client']
/src/open62541/plugins/crypto/openssl/certificategroup.c ['fuzz_certificate_parse', 'fuzz_server_services', 'fuzz_process_request', 'fuzz_tcp_message', 'fuzz_config_json', 'fuzz_binary_message', 'fuzz_client'] ['fuzz_certificate_parse', 'fuzz_config_json']
/src/open62541/deps/utf8.c [] []
/src/open62541/tests/fuzz/fuzz_datatype_description.cc ['fuzz_datatype_description'] ['fuzz_datatype_description']
/src/open62541/src/pubsub/ua_pubsub_writergroup.c ['fuzz_server_services', 'fuzz_process_request', 'fuzz_tcp_message', 'fuzz_config_json', 'fuzz_binary_message'] []
/src/open62541/deps/yxml.c ['fuzz_server_services', 'fuzz_process_request', 'fuzz_tcp_message', 'fuzz_config_json', 'fuzz_xml_decode_encode', 'fuzz_binary_message'] ['fuzz_server_services', 'fuzz_process_request', 'fuzz_tcp_message', 'fuzz_config_json', 'fuzz_xml_decode_encode', 'fuzz_binary_message']
/src/open62541/src/server/ua_transport_ws.c ['fuzz_server_services', 'fuzz_process_request', 'fuzz_tcp_message', 'fuzz_config_json', 'fuzz_binary_message'] ['fuzz_server_services', 'fuzz_process_request', 'fuzz_tcp_message', 'fuzz_config_json', 'fuzz_binary_message']
/src/open62541/src/server/ua_services_method.c [] []
/src/open62541/plugins/ua_nodestore_ziptree.c ['fuzz_server_services', 'fuzz_process_request', 'fuzz_tcp_message', 'fuzz_config_json', 'fuzz_binary_message'] ['fuzz_server_services', 'fuzz_process_request', 'fuzz_tcp_message', 'fuzz_config_json', 'fuzz_binary_message']
/src/open62541/src/pubsub/ua_pubsub_networkmessage_json.c ['fuzz_server_services', 'fuzz_process_request', 'fuzz_tcp_message', 'fuzz_config_json', 'fuzz_binary_message', 'fuzz_pubsub_json'] ['fuzz_pubsub_json']
/src/open62541/src/server/ua_services_securechannel.c ['fuzz_server_services', 'fuzz_process_request', 'fuzz_tcp_message', 'fuzz_config_json', 'fuzz_binary_message'] ['fuzz_tcp_message', 'fuzz_binary_message']
/src/open62541/drivers/discovery_mdns_mdnsd.c [] []
/src/open62541/src/pubsub/ua_pubsub_dataset.c ['fuzz_server_services', 'fuzz_process_request', 'fuzz_tcp_message', 'fuzz_config_json', 'fuzz_binary_message'] []
/src/open62541/tests/fuzz/fuzz_binary_message.cc ['fuzz_binary_message'] ['fuzz_binary_message']
/src/open62541/src/server/ua_transport_tcp.c ['fuzz_server_services', 'fuzz_process_request', 'fuzz_tcp_message', 'fuzz_config_json', 'fuzz_binary_message'] ['fuzz_server_services', 'fuzz_process_request', 'fuzz_tcp_message', 'fuzz_config_json', 'fuzz_binary_message']
/src/open62541/deps/pcg_basic.c ['fuzz_server_services', 'fuzz_process_request', 'fuzz_tcp_message', 'fuzz_config_json', 'fuzz_binary_message'] ['fuzz_server_services', 'fuzz_process_request', 'fuzz_tcp_message', 'fuzz_config_json', 'fuzz_binary_message']
/src/open62541/src/pubsub/ua_pubsub_ns0.c ['fuzz_server_services', 'fuzz_process_request', 'fuzz_tcp_message', 'fuzz_config_json', 'fuzz_binary_message'] ['fuzz_server_services', 'fuzz_process_request', 'fuzz_tcp_message', 'fuzz_config_json', 'fuzz_binary_message']
/src/open62541/plugins/ua_config_json.c ['fuzz_config_json'] ['fuzz_config_json']
/src/open62541/tests/fuzz/fuzz_eventfilter_parse.cc ['fuzz_eventfilter_parse'] ['fuzz_eventfilter_parse']
/src/open62541/plugins/crypto/openssl/securitypolicy_eccbrainpoolp256r1.c [] []
/src/open62541/plugins/crypto/openssl/securitypolicy_ecccurve448.c [] []
/src/open62541/src/server/ua_server_modelchange.c ['fuzz_server_services', 'fuzz_process_request', 'fuzz_tcp_message', 'fuzz_config_json', 'fuzz_binary_message'] ['fuzz_server_services', 'fuzz_process_request', 'fuzz_tcp_message', 'fuzz_config_json', 'fuzz_binary_message']
/src/open62541/src/server/ua_server_utils.c ['fuzz_parse_string', 'fuzz_server_services', 'fuzz_process_request', 'fuzz_tcp_message', 'fuzz_config_json', 'fuzz_attributeoperand', 'fuzz_eventfilter_parse', 'fuzz_binary_message'] ['fuzz_server_services', 'fuzz_process_request', 'fuzz_tcp_message', 'fuzz_config_json', 'fuzz_binary_message']
/src/open62541/src/server/ua_server_auditing.c ['fuzz_server_services', 'fuzz_process_request', 'fuzz_tcp_message', 'fuzz_config_json', 'fuzz_binary_message'] ['fuzz_server_services', 'fuzz_process_request', 'fuzz_binary_message']
/src/open62541/src/ua_types_encoding_json.c ['fuzz_json_decode_encode', 'fuzz_server_services', 'fuzz_process_request', 'fuzz_tcp_message', 'fuzz_config_json', 'fuzz_json_decode', 'fuzz_eventfilter_parse', 'fuzz_binary_message', 'fuzz_client', 'fuzz_pubsub_json'] ['fuzz_json_decode_encode', 'fuzz_config_json', 'fuzz_json_decode', 'fuzz_eventfilter_parse', 'fuzz_pubsub_json']
/usr/include/openssl/x509.h ['fuzz_config_json'] []
/src/open62541/deps/musl_inet_pton.c [] []
/src/open62541/plugins/historydata/ua_history_database_default.c [] []
/src/open62541/include/open62541/plugin/log.h ['fuzz_server_services', 'fuzz_process_request', 'fuzz_tcp_message', 'fuzz_config_json', 'fuzz_eventfilter_parse', 'fuzz_binary_message', 'fuzz_client'] ['fuzz_server_services', 'fuzz_process_request', 'fuzz_tcp_message', 'fuzz_config_json', 'fuzz_eventfilter_parse', 'fuzz_binary_message', 'fuzz_client']
/src/open62541/tests/testing-plugins/test_helpers.c ['fuzz_client'] ['fuzz_client']
/src/open62541/plugins/crypto/openssl/securitypolicy_aes256sha256rsapss.c ['fuzz_config_json'] []
/src/open62541/src/server/ua_server_nodes.c ['fuzz_parse_string', 'fuzz_server_services', 'fuzz_process_request', 'fuzz_tcp_message', 'fuzz_config_json', 'fuzz_attributeoperand', 'fuzz_eventfilter_parse', 'fuzz_binary_message'] ['fuzz_server_services', 'fuzz_process_request', 'fuzz_tcp_message', 'fuzz_config_json', 'fuzz_binary_message']
/src/open62541/src/server/ua_services_session.c ['fuzz_server_services', 'fuzz_process_request', 'fuzz_tcp_message', 'fuzz_config_json', 'fuzz_binary_message'] ['fuzz_server_services', 'fuzz_process_request', 'fuzz_binary_message']
/src/open62541/src/client/../ua_securechannel.h ['fuzz_client'] ['fuzz_binary_message']
/src/open62541/tests/fuzz/fuzz_base64_decode.cc ['fuzz_base64_decode'] ['fuzz_base64_decode']
/src/open62541/arch/posix/clock_posix.c ['fuzz_server_services', 'fuzz_process_request', 'fuzz_tcp_message', 'fuzz_config_json', 'fuzz_binary_message', 'fuzz_client'] ['fuzz_server_services', 'fuzz_process_request', 'fuzz_tcp_message', 'fuzz_config_json', 'fuzz_binary_message']
/work/open62541/src_generated/mdnsd/sdtxt.c ['fuzz_mdns_xht'] ['fuzz_mdns_xht']
/src/open62541/plugins/crypto/openssl/create_certificate.c [] []
/src/open62541/src/pubsub/ua_pubsub_manager.c ['fuzz_server_services', 'fuzz_process_request', 'fuzz_tcp_message', 'fuzz_config_json', 'fuzz_pubsub_connection_config', 'fuzz_binary_message'] ['fuzz_server_services', 'fuzz_process_request', 'fuzz_tcp_message', 'fuzz_config_json', 'fuzz_pubsub_connection_config', 'fuzz_binary_message']
/src/open62541/tests/fuzz/custom_memory_manager.c ['fuzz_pubsub_binary', 'fuzz_certificate_parse', 'fuzz_binary_decode', 'fuzz_tcp_message', 'fuzz_src_ua_util', 'fuzz_attributeoperand', 'fuzz_binary_message', 'fuzz_datatype_description', 'fuzz_pubsub_json'] ['fuzz_pubsub_binary', 'fuzz_certificate_parse', 'fuzz_binary_decode', 'fuzz_tcp_message', 'fuzz_src_ua_util', 'fuzz_attributeoperand', 'fuzz_binary_message', 'fuzz_datatype_description', 'fuzz_pubsub_json']
/src/open62541/src/server/ua_server_discovery.c ['fuzz_server_services', 'fuzz_process_request', 'fuzz_tcp_message', 'fuzz_config_json', 'fuzz_binary_message'] ['fuzz_server_services', 'fuzz_process_request', 'fuzz_tcp_message', 'fuzz_config_json', 'fuzz_binary_message']
/src/open62541/plugins/ua_config_default.c ['fuzz_server_services', 'fuzz_process_request', 'fuzz_tcp_message', 'fuzz_config_json', 'fuzz_binary_message', 'fuzz_client'] ['fuzz_server_services', 'fuzz_process_request', 'fuzz_tcp_message', 'fuzz_config_json', 'fuzz_binary_message', 'fuzz_client']
/work/open62541/src_generated/open62541/statuscodes.c ['fuzz_server_services', 'fuzz_process_request', 'fuzz_tcp_message', 'fuzz_config_json', 'fuzz_binary_message', 'fuzz_client'] ['fuzz_binary_message']
/work/open62541/src_generated/open62541/namespace0_generated.c ['fuzz_server_services', 'fuzz_process_request', 'fuzz_tcp_message', 'fuzz_config_json', 'fuzz_binary_message'] ['fuzz_server_services', 'fuzz_process_request', 'fuzz_tcp_message', 'fuzz_config_json', 'fuzz_binary_message']
/src/open62541/plugins/crypto/openssl/securitypolicy_common.c ['fuzz_certificate_parse', 'fuzz_server_services', 'fuzz_process_request', 'fuzz_tcp_message', 'fuzz_config_json', 'fuzz_binary_message', 'fuzz_client'] ['fuzz_certificate_parse', 'fuzz_process_request', 'fuzz_binary_message']
/src/open62541/src/pubsub/../ua_types_encoding_json.h ['fuzz_pubsub_json'] []
/src/open62541/plugins/crypto/openssl/securitypolicy_aes128sha256rsaoaep.c ['fuzz_config_json'] []
/src/open62541/tests/fuzz/fuzz_base64_encode.cc ['fuzz_base64_encode'] ['fuzz_base64_encode']
/src/open62541/src/server/ua_services_nodemanagement.c ['fuzz_server_services', 'fuzz_process_request', 'fuzz_tcp_message', 'fuzz_config_json', 'fuzz_binary_message'] ['fuzz_server_services', 'fuzz_process_request', 'fuzz_tcp_message', 'fuzz_config_json', 'fuzz_binary_message']
/src/open62541/src/server/ua_transport_tcp_reverse.c ['fuzz_server_services', 'fuzz_process_request', 'fuzz_tcp_message', 'fuzz_config_json', 'fuzz_binary_message'] ['fuzz_server_services', 'fuzz_process_request', 'fuzz_tcp_message', 'fuzz_config_json', 'fuzz_binary_message']
/src/open62541/src/util/ua_eventfilter_parser.c ['fuzz_eventfilter_parse'] ['fuzz_eventfilter_parse']
/src/open62541/plugins/crypto/openssl/securitypolicy_eccnistp256_chachapoly.c [] []
/src/open62541/src/pubsub/ua_pubsub_networkmessage_binary.c ['fuzz_pubsub_binary', 'fuzz_server_services', 'fuzz_process_request', 'fuzz_tcp_message', 'fuzz_config_json', 'fuzz_binary_message', 'fuzz_pubsub_json'] ['fuzz_pubsub_binary', 'fuzz_pubsub_json']
/src/open62541/tests/fuzz/fuzz_attributeoperand.cc ['fuzz_attributeoperand'] ['fuzz_attributeoperand']
/src/open62541/src/ua_types.c ['fuzz_json_decode_encode', 'fuzz_pubsub_binary', 'fuzz_certificate_parse', 'fuzz_parse_string', 'fuzz_binary_decode', 'fuzz_server_services', 'fuzz_process_request', 'fuzz_tcp_message', 'fuzz_config_json', 'fuzz_json_decode', 'fuzz_xml_decode_encode', 'fuzz_pubsub_connection_config', 'fuzz_attributeoperand', 'fuzz_eventfilter_parse', 'fuzz_binary_message', 'fuzz_datatype_description', 'fuzz_client', 'fuzz_pubsub_json'] ['fuzz_json_decode_encode', 'fuzz_pubsub_binary', 'fuzz_certificate_parse', 'fuzz_parse_string', 'fuzz_binary_decode', 'fuzz_server_services', 'fuzz_process_request', 'fuzz_tcp_message', 'fuzz_config_json', 'fuzz_json_decode', 'fuzz_xml_decode_encode', 'fuzz_pubsub_connection_config', 'fuzz_attributeoperand', 'fuzz_eventfilter_parse', 'fuzz_binary_message', 'fuzz_datatype_description', 'fuzz_client', 'fuzz_pubsub_json']
/src/open62541/deps/mp_printf.c ['fuzz_server_services', 'fuzz_process_request', 'fuzz_tcp_message', 'fuzz_config_json', 'fuzz_binary_message', 'fuzz_client'] ['fuzz_server_services', 'fuzz_process_request', 'fuzz_tcp_message', 'fuzz_config_json', 'fuzz_binary_message']
/src/open62541/tests/fuzz/fuzz_parse_string.cc ['fuzz_parse_string'] ['fuzz_parse_string']
/src/open62541/deps/dtoa.c ['fuzz_server_services', 'fuzz_process_request', 'fuzz_tcp_message', 'fuzz_config_json', 'fuzz_binary_message', 'fuzz_client'] []
/src/open62541/src/server/ua_server_config.c ['fuzz_server_services', 'fuzz_process_request', 'fuzz_tcp_message', 'fuzz_config_json', 'fuzz_binary_message'] ['fuzz_server_services', 'fuzz_process_request', 'fuzz_tcp_message', 'fuzz_config_json', 'fuzz_binary_message']
/src/open62541/src/client/../util/ua_util_internal.h ['fuzz_client'] ['fuzz_parse_string', 'fuzz_attributeoperand', 'fuzz_eventfilter_parse']
/src/open62541/src/util/nodeset_loader/ua_nodeset.c [] []
/src/open62541/src/util/ua_encryptedsecret.c ['fuzz_server_services', 'fuzz_process_request', 'fuzz_tcp_message', 'fuzz_config_json', 'fuzz_binary_message', 'fuzz_client'] []
/src/open62541/plugins/historydata/ua_history_data_gathering_default.c [] []
/src/open62541/src/server/ua_services_subscription.c ['fuzz_server_services', 'fuzz_process_request', 'fuzz_tcp_message', 'fuzz_config_json', 'fuzz_binary_message'] ['fuzz_server_services', 'fuzz_process_request', 'fuzz_tcp_message', 'fuzz_config_json', 'fuzz_binary_message']
/work/open62541/src_generated/mdnsd/log.c ['fuzz_mdns_message'] ['fuzz_mdns_message']
/src/open62541/deps/utf8.h ['fuzz_config_json'] ['fuzz_config_json']
/work/open62541/src_generated/mdnsd/inet.c ['fuzz_mdns_message'] ['fuzz_mdns_message']
/src/open62541/src/util/nodeset_loader/ua_nodeset_loader_apply.c [] []
/src/open62541/src/server/ua_server_ns0_diagnostics.c ['fuzz_server_services', 'fuzz_process_request', 'fuzz_tcp_message', 'fuzz_config_json', 'fuzz_binary_message'] ['fuzz_server_services', 'fuzz_process_request']
/src/open62541/tests/fuzz/fuzz_tcp_message.cc ['fuzz_tcp_message'] ['fuzz_tcp_message']
/src/open62541/plugins/ua_log_stdout.c ['fuzz_server_services', 'fuzz_process_request', 'fuzz_tcp_message', 'fuzz_config_json', 'fuzz_binary_message', 'fuzz_client'] ['fuzz_server_services', 'fuzz_process_request', 'fuzz_tcp_message', 'fuzz_config_json', 'fuzz_binary_message', 'fuzz_client']
/src/open62541/src/ua_securechannel.c ['fuzz_server_services', 'fuzz_process_request', 'fuzz_tcp_message', 'fuzz_config_json', 'fuzz_binary_message', 'fuzz_client'] ['fuzz_server_services', 'fuzz_process_request', 'fuzz_tcp_message', 'fuzz_binary_message', 'fuzz_client']
/src/open62541/plugins/crypto/openssl/securitypolicy_eccbrainpoolp384r1.c [] []
/src/open62541/plugins/crypto/openssl/securitypolicy_basic256sha256.c ['fuzz_config_json'] []
/src/open62541/src/pubsub/ua_pubsub_reader.c ['fuzz_server_services', 'fuzz_process_request', 'fuzz_tcp_message', 'fuzz_config_json', 'fuzz_binary_message'] []
/src/open62541/plugins/crypto/openssl/securitypolicy_basic256.c ['fuzz_config_json'] []
/src/open62541/plugins/crypto/openssl/securitypolicy_pubsub_aesctr.c [] []
/src/open62541/src/pubsub/ua_pubsub_connection.c ['fuzz_server_services', 'fuzz_process_request', 'fuzz_tcp_message', 'fuzz_config_json', 'fuzz_pubsub_connection_config', 'fuzz_binary_message'] ['fuzz_pubsub_connection_config']
/src/open62541/plugins/crypto/ua_securitypolicy_filestore.c [] []
/src/open62541/tests/fuzz/fuzz_binary_decode.cc ['fuzz_binary_decode'] ['fuzz_binary_decode']
/src/open62541/tests/fuzz/fuzz_server_services.cc ['fuzz_server_services'] ['fuzz_server_services']
/src/open62541/src/server/ua_subscription_datachange.c ['fuzz_server_services', 'fuzz_process_request', 'fuzz_tcp_message', 'fuzz_config_json', 'fuzz_binary_message'] []
/src/open62541/src/pubsub/ua_pubsub_internal.h ['fuzz_server_services', 'fuzz_process_request', 'fuzz_tcp_message', 'fuzz_config_json', 'fuzz_binary_message'] []
/src/open62541/include/open62541/server.h ['fuzz_server_services', 'fuzz_process_request', 'fuzz_tcp_message', 'fuzz_binary_message'] []
/src/open62541/src/server/ua_server_internal.h ['fuzz_parse_string', 'fuzz_server_services', 'fuzz_process_request', 'fuzz_tcp_message', 'fuzz_config_json', 'fuzz_attributeoperand', 'fuzz_eventfilter_parse', 'fuzz_binary_message'] ['fuzz_server_services', 'fuzz_process_request', 'fuzz_tcp_message', 'fuzz_config_json', 'fuzz_binary_message']
/src/open62541/plugins/historydata/ua_history_data_backend_memory.c [] []
/src/open62541/src/ua_types_encoding_xml.c ['fuzz_server_services', 'fuzz_process_request', 'fuzz_tcp_message', 'fuzz_config_json', 'fuzz_xml_decode_encode', 'fuzz_binary_message'] ['fuzz_server_services', 'fuzz_process_request', 'fuzz_tcp_message', 'fuzz_config_json', 'fuzz_xml_decode_encode', 'fuzz_binary_message']
/src/open62541/arch/posix/eventloop_posix_eth.c ['fuzz_server_services', 'fuzz_process_request', 'fuzz_tcp_message', 'fuzz_config_json', 'fuzz_binary_message'] ['fuzz_server_services', 'fuzz_process_request', 'fuzz_tcp_message', 'fuzz_config_json', 'fuzz_binary_message']
/src/open62541/plugins/crypto/openssl/securitypolicy_eccnistp384.c [] []
/src/open62541/plugins/ua_log_syslog.c [] []
/src/open62541/src/util/nodeset_loader/ua_nodeset_loader.c [] []
/src/open62541/src/ua_securechannel_http.c ['fuzz_server_services', 'fuzz_process_request', 'fuzz_tcp_message', 'fuzz_config_json', 'fuzz_binary_message', 'fuzz_client'] []
/src/open62541/tests/fuzz/fuzz_config_json.cc ['fuzz_config_json'] ['fuzz_config_json']
/src/open62541/deps/cj5.c ['fuzz_json_decode_encode', 'fuzz_config_json', 'fuzz_json_decode', 'fuzz_eventfilter_parse', 'fuzz_client', 'fuzz_pubsub_json'] ['fuzz_json_decode_encode', 'fuzz_config_json', 'fuzz_json_decode', 'fuzz_eventfilter_parse', 'fuzz_pubsub_json']
/src/open62541/src/pubsub/ua_pubsub_readergroup.c ['fuzz_server_services', 'fuzz_process_request', 'fuzz_tcp_message', 'fuzz_config_json', 'fuzz_binary_message'] []
/src/open62541/plugins/crypto/ua_filestore_common.c ['fuzz_config_json'] []
/src/open62541/plugins/crypto/openssl/securitypolicy_eccnistp256.c ['fuzz_config_json'] []
/work/open62541/src_generated/mdnsd/mdnsd.c ['fuzz_mdns_message'] ['fuzz_mdns_message']
/src/open62541/arch/posix/eventloop_posix_udp.c ['fuzz_server_services', 'fuzz_process_request', 'fuzz_tcp_message', 'fuzz_config_json', 'fuzz_binary_message', 'fuzz_client'] ['fuzz_server_services', 'fuzz_process_request', 'fuzz_tcp_message', 'fuzz_config_json', 'fuzz_binary_message', 'fuzz_client']
/src/open62541/deps/ziptree.c ['fuzz_parse_string', 'fuzz_server_services', 'fuzz_process_request', 'fuzz_tcp_message', 'fuzz_config_json', 'fuzz_attributeoperand', 'fuzz_eventfilter_parse', 'fuzz_binary_message', 'fuzz_client'] ['fuzz_server_services', 'fuzz_process_request', 'fuzz_tcp_message', 'fuzz_config_json', 'fuzz_binary_message']
/src/open62541/src/client/ua_client_subscriptions.c ['fuzz_client'] ['fuzz_client']
/src/open62541/arch/posix/eventloop_posix_interrupt.c ['fuzz_server_services', 'fuzz_process_request', 'fuzz_tcp_message', 'fuzz_config_json', 'fuzz_binary_message', 'fuzz_client'] ['fuzz_server_services', 'fuzz_process_request', 'fuzz_tcp_message', 'fuzz_config_json', 'fuzz_binary_message', 'fuzz_client']
/work/open62541/src_generated/mdnsd/1035.c ['fuzz_mdns_message'] ['fuzz_mdns_message']
/src/open62541/arch/posix/eventloop_posix.c ['fuzz_server_services', 'fuzz_process_request', 'fuzz_tcp_message', 'fuzz_config_json', 'fuzz_binary_message', 'fuzz_client'] ['fuzz_server_services', 'fuzz_process_request', 'fuzz_tcp_message', 'fuzz_config_json', 'fuzz_binary_message', 'fuzz_client']
/src/open62541/src/client/ua_client_connect_http.c ['fuzz_client'] []
/usr/include/openssl/x509v3.h ['fuzz_certificate_parse', 'fuzz_server_services', 'fuzz_process_request', 'fuzz_tcp_message', 'fuzz_config_json', 'fuzz_binary_message', 'fuzz_client'] []
/src/open62541/plugins/ua_accesscontrol_default.c ['fuzz_server_services', 'fuzz_process_request', 'fuzz_tcp_message', 'fuzz_config_json', 'fuzz_binary_message'] ['fuzz_server_services', 'fuzz_process_request', 'fuzz_tcp_message', 'fuzz_config_json', 'fuzz_binary_message']
/src/open62541/src/server/ua_subscription.h ['fuzz_server_services', 'fuzz_process_request', 'fuzz_tcp_message', 'fuzz_config_json', 'fuzz_binary_message'] ['fuzz_server_services', 'fuzz_process_request', 'fuzz_tcp_message', 'fuzz_config_json', 'fuzz_binary_message']
/src/open62541/tests/fuzz/fuzz_mdns_xht.cc ['fuzz_mdns_xht'] ['fuzz_mdns_xht']
/src/open62541/deps/parse_num.c ['fuzz_parse_string'] ['fuzz_parse_string']
/src/open62541/src/server/ua_services_discovery.c ['fuzz_server_services', 'fuzz_process_request', 'fuzz_tcp_message', 'fuzz_config_json', 'fuzz_binary_message'] ['fuzz_server_services', 'fuzz_process_request']
/src/open62541/src/ua_securechannel_crypto.c ['fuzz_server_services', 'fuzz_process_request', 'fuzz_tcp_message', 'fuzz_config_json', 'fuzz_binary_message', 'fuzz_client'] ['fuzz_binary_message']
/src/open62541/plugins/include/open62541/server_config_default.h ['fuzz_server_services', 'fuzz_process_request', 'fuzz_tcp_message', 'fuzz_config_json', 'fuzz_binary_message'] ['fuzz_server_services', 'fuzz_process_request', 'fuzz_tcp_message', 'fuzz_config_json', 'fuzz_binary_message']
/src/open62541/tests/fuzz/fuzz_json_decode_encode.cc ['fuzz_json_decode_encode'] ['fuzz_json_decode_encode']
/src/open62541/deps/yxml.h [] []
/src/open62541/include/open62541/client_subscriptions.h [] []
/src/open62541/tests/testing-plugins/testing_clock.c [] []
/src/open62541/src/pubsub/../util/ua_util_internal.h ['fuzz_pubsub_binary', 'fuzz_server_services', 'fuzz_process_request', 'fuzz_tcp_message', 'fuzz_config_json', 'fuzz_binary_message'] ['fuzz_parse_string', 'fuzz_attributeoperand', 'fuzz_eventfilter_parse']
/src/open62541/deps/itoa.c ['fuzz_parse_string', 'fuzz_server_services', 'fuzz_process_request', 'fuzz_tcp_message', 'fuzz_config_json', 'fuzz_attributeoperand', 'fuzz_binary_message', 'fuzz_datatype_description', 'fuzz_client'] ['fuzz_parse_string', 'fuzz_server_services', 'fuzz_process_request', 'fuzz_attributeoperand', 'fuzz_datatype_description']
/src/open62541/tests/fuzz/fuzz_xml_decode_encode.cc ['fuzz_xml_decode_encode'] ['fuzz_xml_decode_encode']

Directories in report

Directory
/src/open62541/tests/testing-plugins/
/src/open62541/src/client/../
/src/open62541/src/pubsub/../server/
/src/open62541/src/server/
/src/open62541/plugins/crypto/openssl/
/src/open62541/tests/fuzz/
/work/open62541/src_generated/mdnsd/
/src/open62541/src/util/
/src/open62541/deps/
/src/open62541/plugins/historydata/
/src/open62541/src/pubsub/../util/
/src/open62541/drivers/
/src/open62541/src/util/nodeset_loader/
/src/open62541/plugins/
/src/open62541/src/client/
/src/open62541/plugins/crypto/
/work/open62541/src_generated/open62541/
/src/open62541/arch/common/
/src/open62541/src/pubsub/
/src/open62541/src/pubsub/../
/src/open62541/arch/posix/
/src/open62541/src/
/src/open62541/include/open62541/plugin/
/src/open62541/plugins/include/open62541/
/src/open62541/src/client/../util/
/src/open62541/include/open62541/
/usr/include/openssl/

Metadata section

This sections shows the raw data that is used to produce this report. This is mainly used for further processing and developer debugging.

Fuzzer Calltree file Program data file Coverage file
fuzz_json_decode_encode fuzzerLogFile-0-NgbAFrZcgF.data fuzzerLogFile-0-NgbAFrZcgF.data.yaml fuzz_json_decode_encode.covreport
fuzz_pubsub_binary fuzzerLogFile-0-cw5QwjZtx9.data fuzzerLogFile-0-cw5QwjZtx9.data.yaml fuzz_pubsub_binary.covreport
fuzz_certificate_parse fuzzerLogFile-0-YgyN81pdsH.data fuzzerLogFile-0-YgyN81pdsH.data.yaml fuzz_certificate_parse.covreport
fuzz_mdns_xht fuzzerLogFile-0-dyxX5t9auJ.data fuzzerLogFile-0-dyxX5t9auJ.data.yaml fuzz_mdns_xht.covreport
fuzz_base64_decode fuzzerLogFile-0-f3KLAoZX4b.data fuzzerLogFile-0-f3KLAoZX4b.data.yaml fuzz_base64_decode.covreport
fuzz_parse_string fuzzerLogFile-0-MGCMWyoZeo.data fuzzerLogFile-0-MGCMWyoZeo.data.yaml fuzz_parse_string.covreport
fuzz_binary_decode fuzzerLogFile-0-QhiV4zsr1v.data fuzzerLogFile-0-QhiV4zsr1v.data.yaml fuzz_binary_decode.covreport
fuzz_server_services fuzzerLogFile-0-UhcyZ3sgDM.data fuzzerLogFile-0-UhcyZ3sgDM.data.yaml fuzz_server_services.covreport
fuzz_process_request fuzzerLogFile-0-J1XXEwtRoy.data fuzzerLogFile-0-J1XXEwtRoy.data.yaml fuzz_process_request.covreport
fuzz_tcp_message fuzzerLogFile-0-8FZfTYUGtf.data fuzzerLogFile-0-8FZfTYUGtf.data.yaml fuzz_tcp_message.covreport
fuzz_config_json fuzzerLogFile-0-1czu0nzClG.data fuzzerLogFile-0-1czu0nzClG.data.yaml fuzz_config_json.covreport
fuzz_mdns_message fuzzerLogFile-0-lTwgLBJUDU.data fuzzerLogFile-0-lTwgLBJUDU.data.yaml fuzz_mdns_message.covreport
fuzz_json_decode fuzzerLogFile-0-8qcVaNSHzW.data fuzzerLogFile-0-8qcVaNSHzW.data.yaml fuzz_json_decode.covreport
fuzz_xml_decode_encode fuzzerLogFile-0-wrjl3BXbfy.data fuzzerLogFile-0-wrjl3BXbfy.data.yaml fuzz_xml_decode_encode.covreport
fuzz_pubsub_connection_config fuzzerLogFile-0-nCEjj6smnX.data fuzzerLogFile-0-nCEjj6smnX.data.yaml fuzz_pubsub_connection_config.covreport
fuzz_src_ua_util fuzzerLogFile-0-pXyR68JM7u.data fuzzerLogFile-0-pXyR68JM7u.data.yaml fuzz_src_ua_util.covreport
fuzz_attributeoperand fuzzerLogFile-0-69JfvUp9aR.data fuzzerLogFile-0-69JfvUp9aR.data.yaml fuzz_attributeoperand.covreport
fuzz_eventfilter_parse fuzzerLogFile-0-HluJJIGuAm.data fuzzerLogFile-0-HluJJIGuAm.data.yaml fuzz_eventfilter_parse.covreport
fuzz_binary_message fuzzerLogFile-0-YAMUiJTddn.data fuzzerLogFile-0-YAMUiJTddn.data.yaml fuzz_binary_message.covreport
fuzz_datatype_description fuzzerLogFile-0-qF8AQbN08x.data fuzzerLogFile-0-qF8AQbN08x.data.yaml fuzz_datatype_description.covreport
fuzz_client fuzzerLogFile-0-OGbKOH23EX.data fuzzerLogFile-0-OGbKOH23EX.data.yaml fuzz_client.covreport
fuzz_base64_encode fuzzerLogFile-0-b4l5qYfU6b.data fuzzerLogFile-0-b4l5qYfU6b.data.yaml fuzz_base64_encode.covreport
fuzz_pubsub_json fuzzerLogFile-0-s9cSzsHRBb.data fuzzerLogFile-0-s9cSzsHRBb.data.yaml fuzz_pubsub_json.covreport