The followings are the branches where fuzzer fails to bypass.
Unique non-covered Complexity | Unique Reachable Complexities | Unique Reachable Functions | All non-covered Complexity | All Reachable Complexity | Function Name | Function Callsite | Blocked Branch |
---|---|---|---|---|---|---|---|
886 | 886 |
2 :
['sshkey_free', 'cert_new'] |
886 | 886 | sshkey_new | call site: 00010 | /src/openssh/sshkey.c:722 |
440 | 440 |
1 :
['sshkey_free'] |
440 | 440 | sshkey_generate | call site: 00007 | /src/openssh/sshkey.c:1525 |
165 | 165 |
1 :
['_getentropy_fail'] |
169 | 230 | _rs_stir | call site: 00000 | /src/openssh/openbsd-compat/arc4random.c:116 |
165 | 165 |
2 :
['sshfatal', 'ERR_get_error'] |
165 | 165 | _ssh_compat_getentropy | call site: 00000 | /src/openssh/openbsd-compat/bsd-getentropy.c:45 |
158 | 158 |
5 :
['do_log', 'getpid', 'strrchr', 'strlcpy', 'match_pattern_list'] |
158 | 158 | sshlogv | call site: 00030 | /src/openssh/log.c:462 |
73 | 73 |
2 :
['ssh_err', 'abort'] |
73 | 73 | generate_or_die(int,unsignedint) | call site: 00000 | /src/openssh/regress/misc/fuzz-harness/sig_fuzz.cc:18 |
13 | 13 |
1 :
['ssh_rsa_hash_id_from_keyname'] |
23 | 674 | ssh_rsa_verify | call site: 00000 | /src/openssh/ssh-rsa.c:528 |
2 | 2 |
1 :
['_exit'] |
2 | 2 | _rs_init | call site: 00000 | /src/openssh/openbsd-compat/arc4random.c:102 |
2 | 2 |
1 :
['memset'] |
2 | 2 | _rs_forkdetect | call site: 00000 | /src/openssh/openbsd-compat/./arc4random.h:60 |
2 | 2 |
1 :
['munmap'] |
2 | 2 | _rs_allocate | call site: 00000 | /src/openssh/openbsd-compat/./arc4random.h:73 |
2 | 2 |
1 :
['BN_clear_free'] |
2 | 2 | sshbuf_get_bignum2 | call site: 00000 | /src/openssh/sshbuf-getput-crypto.c:48 |
0 | 199 |
1 :
['sshbuf_free'] |
0 | 199 | sshbuf_froms | call site: 00000 | /src/openssh/sshbuf-getput-basic.c:561 |
LLVMFuzzerTestOneInput
[function]
[call site]
00000
__cxa_guard_acquire
[call site]
00001
generate_or_die(int, unsigned int)
[function]
[call site]
00002
sshkey_generate
[function]
[call site]
00003
sshkey_type_is_cert
[function]
[call site]
00004
sshkey_impl_from_type
[function]
[call site]
00005
sshkey_impl_from_type
[function]
[call site]
00006
sshkey_new
[function]
[call site]
00007
sshkey_impl_from_type
[function]
[call site]
00008
calloc
[call site]
00009
sshkey_is_cert
[function]
[call site]
00010
sshkey_type_is_cert
[function]
[call site]
00011
cert_new
[function]
[call site]
00012
calloc
[call site]
00013
sshbuf_new
[function]
[call site]
00014
calloc
[call site]
00015
calloc
[call site]
00016
sshbuf_new
[function]
[call site]
00017
sshbuf_new
[function]
[call site]
00018
cert_free
[function]
[call site]
00019
sshbuf_free
[function]
[call site]
00020
sshbuf_check_sanity
[function]
[call site]
00021
ssh_signal
[function]
[call site]
00022
memset
[call site]
00023
sigfillset
[call site]
00024
sigaction
[call site]
00025
strsignal
[call site]
00026
__errno_location
[call site]
00027
strerror
[call site]
00028
sshlog
[function]
[call site]
00029
sshlogv
[function]
[call site]
00030
strrchr
[call site]
00031
getpid
[call site]
00032
snprintf
[call site]
00033
match_pattern_list
[function]
[call site]
00034
strlen
[call site]
00035
__ctype_b_loc
[call site]
00036
tolower
[call site]
00037
match_pattern
[function]
[call site]
00038
match_pattern
[function]
[call site]
00039
match_pattern
[function]
[call site]
00040
snprintf
[call site]
00041
snprintf
[call site]
00042
strlcpy
[function]
[call site]
00043
do_log
[function]
[call site]
00044
__errno_location
[call site]
00045
snprintf
[call site]
00046
vsnprintf
[call site]
00047
vsnprintf
[call site]
00048
snprintf
[call site]
00049
strlcpy
[function]
[call site]
00050
strnvis
[function]
[call site]
00051
__ctype_b_loc
[call site]
00052
vis
[function]
[call site]
00053
__ctype_b_loc
[call site]
00054
__ctype_b_loc
[call site]
00055
vis
[function]
[call site]
00056
snprintf
[call site]
00057
strlen
[call site]
00058
write
[call site]
00059
openlog
[call site]
00060
syslog
[call site]
00061
closelog
[call site]
00062
__errno_location
[call site]
00063
raise
[call site]
00064
sshbuf_free
[function]
[call site]
00065
freezero
[function]
[call site]
00066
explicit_bzero
[call site]
00067
freezero
[function]
[call site]
00068
sshbuf_free
[function]
[call site]
00069
sshbuf_free
[function]
[call site]
00070
sshkey_free
[function]
[call site]
00071
sshkey_free_contents
[function]
[call site]
00072
pkcs11_key_free
[function]
[call site]
00073
sshkey_type
[function]
[call site]
00074
sshkey_impl_from_key
[function]
[call site]
00075
sshkey_impl_from_type_nid
[function]
[call site]
00076
sshlog
[function]
[call site]
00077
helper_by_key
[function]
[call site]
00078
sshbuf_new
[function]
[call site]
00079
sshfatal
[function]
[call site]
00080
sshlogv
[function]
[call site]
00081
cleanup_exit
[function]
[call site]
00082
_exit
[call site]
00083
sshkey_putb
[function]
[call site]
00084
to_blob_buf
[function]
[call site]
00085
sshkey_type_plain
[function]
[call site]
00086
sshkey_type_is_cert
[function]
[call site]
00087
sshbuf_len
[function]
[call site]
00088
sshbuf_check_sanity
[function]
[call site]
00089
sshbuf_putb
[function]
[call site]
00090
sshbuf_ptr
[function]
[call site]
00091
sshbuf_check_sanity
[function]
[call site]
00092
sshbuf_len
[function]
[call site]
00093
sshbuf_put
[function]
[call site]
00094
sshbuf_reserve
[function]
[call site]
00095
sshbuf_allocate
[function]
[call site]
00096
sshbuf_check_reserve
[function]
[call site]
00097
sshbuf_check_sanity
[function]
[call site]
00098
sshbuf_maybe_pack
[function]
[call site]
00099
recallocarray
[function]
[call site]
00100
calloc
[call site]
00101
__errno_location
[call site]
00102
__errno_location
[call site]
00103
getpagesize
[call site]
00104
memset
[call site]
00105
memset
[call site]
00106
explicit_bzero
[call site]
00107
sshbuf_check_reserve
[function]
[call site]
00108
sshkey_impl_from_type
[function]
[call site]
00109
sshkey_ssh_name_from_type_nid
[function]
[call site]
00110
sshkey_impl_from_type_nid
[function]
[call site]
00111
sshbuf_put_cstring
[function]
[call site]
00112
strlen
[call site]
00113
sshbuf_put_string
[function]
[call site]
00114
sshbuf_reserve
[function]
[call site]
00115
ssh_err
[function]
[call site]
00116
__errno_location
[call site]
00117
strerror
[call site]
00118
sshfatal
[function]
[call site]
00119
sshbuf_equals
[function]
[call site]
00120
sshbuf_ptr
[function]
[call site]
00121
sshbuf_len
[function]
[call site]
00122
sshbuf_len
[function]
[call site]
00123
sshbuf_ptr
[function]
[call site]
00124
sshbuf_len
[function]
[call site]
00125
memcmp
[call site]
00126
sshbuf_free
[function]
[call site]
00127
sshbuf_free
[function]
[call site]
00128
sshkey_type
[function]
[call site]
00129
sshfatal
[function]
[call site]
00130
sshbuf_new
[function]
[call site]
00131
sshfatal
[function]
[call site]
00132
sshkey_putb
[function]
[call site]
00133
ssh_err
[function]
[call site]
00134
sshfatal
[function]
[call site]
00135
sshbuf_equals
[function]
[call site]
00136
sshfatal
[function]
[call site]
00137
xrecallocarray
[function]
[call site]
00138
recallocarray
[function]
[call site]
00139
sshfatal
[function]
[call site]
00140
helper_terminate
[function]
[call site]
00141
sshfatal
[function]
[call site]
00142
sshlog
[function]
[call site]
00143
close
[call site]
00144
sshfatal
[function]
[call site]
00145
xrecallocarray
[function]
[call site]
00146
sshbuf_free
[function]
[call site]
00147
sshkey_impl_from_type
[function]
[call site]
00148
sshkey_is_cert
[function]
[call site]
00149
cert_free
[function]
[call site]
00150
freezero
[function]
[call site]
00151
freezero
[function]
[call site]
00152
sshkey_prekey_free
[function]
[call site]
00153
munmap
[call site]
00154
freezero
[function]
[call site]
00155
sshkey_free
[function]
[call site]
00156
sshkey_free
[function]
[call site]
00157
ssh_err
[function]
[call site]
00158
fprintf
[call site]
00159
abort
[call site]
00160
__cxa_guard_release
[call site]
00161
__cxa_guard_acquire
[call site]
00162
generate_or_die(int, unsigned int)
[function]
[call site]
00163
__cxa_guard_release
[call site]
00164
__cxa_guard_acquire
[call site]
00165
generate_or_die(int, unsigned int)
[function]
[call site]
00166
__cxa_guard_release
[call site]
00167
__cxa_guard_acquire
[call site]
00168
generate_or_die(int, unsigned int)
[function]
[call site]
00169
__cxa_guard_release
[call site]
00170
__cxa_guard_acquire
[call site]
00171
generate_or_die(int, unsigned int)
[function]
[call site]
00172
__cxa_guard_release
[call site]
00173
__cxa_guard_acquire
[call site]
00174
strlen
[call site]
00175
__cxa_guard_release
[call site]
00176
sshkey_verify
[function]
[call site]
00177
sshkey_impl_from_key
[function]
[call site]
00178
sshkey_sig_details_free
[function]
[call site]
00179
freezero
[function]
[call site]
00180
sshkey_verify
[function]
[call site]
00181
sshkey_sig_details_free
[function]
[call site]
00182
sshkey_verify
[function]
[call site]
00183
sshkey_sig_details_free
[function]
[call site]
00184
sshkey_verify
[function]
[call site]
00185
sshkey_sig_details_free
[function]
[call site]
00186
sshkey_verify
[function]
[call site]
00187
sshkey_sig_details_free
[function]
[call site]
00188
__cxa_guard_abort
[call site]
00189
__cxa_guard_abort
[call site]
00190
__cxa_guard_abort
[call site]
00191
__cxa_guard_abort
[call site]
00192
__cxa_guard_abort
[call site]
00193