Fuzz introspector: RekorVerifierFuzzer
For issues and ideas: https://github.com/ossf/fuzz-introspector/issues

Fuzz blockers

The following nodes represent call sites where fuzz blockers occur.

Amount of callsites blocked Calltree index Parent function Callsite Largest blocked function
121 0 EP call site: 00000 [dev.sigstore.rekor.client.RekorVerifier].verifyEntry(dev.sigstore.rekor.client.RekorEntry)

Fuzzer calltree

0 [fuzzing.RekorVerifierFuzzer].fuzzerTestOneInput(com.code_intelligence.jazzer.api.FuzzedDataProvider) [function] [call site] 00000
1 [util.Tuf].transparencyLogsFrom(com.code_intelligence.jazzer.api.FuzzedDataProvider) [function] [call site] 00001
2 [util.Tuf].genTlog(com.code_intelligence.jazzer.api.FuzzedDataProvider) [function] [call site] 00002
3 [dev.sigstore.trustroot.ImmutablePublicKey].builder() [function] [call site] 00003
3 [util.Tuf].keyDetails(String) [function] [call site] 00004
3 [com.code_intelligence.jazzer.api.FuzzedDataProvider].consumeBytes(int) [function] [call site] 00005
3 [util.Tuf].rawBytes(byte[]) [function] [call site] 00006
3 [dev.sigstore.trustroot.ImmutableValidFor].builder() [function] [call site] 00007
3 [util.Tuf].start(util.Tuf) [function] [call site] 00008
3 [util.Tuf].build() [function] [call site] 00009
3 [util.Tuf].validFor(util.Tuf) [function] [call site] 00010
3 [util.Tuf].build() [function] [call site] 00011
3 [com.google.common.hash.Hashing].sha256() [function] [call site] 00012
3 [util.Tuf].getRawBytes() [function] [call site] 00013
3 [util.Tuf].hashBytes(util.Tuf) [function] [call site] 00014
3 [util.Tuf].asBytes() [function] [call site] 00015
3 [dev.sigstore.trustroot.ImmutableTransparencyLog].builder() [function] [call site] 00016
3 [java.net.URI].create(String) [function] [call site] 00017
3 [util.Tuf].baseUrl(util.Tuf) [function] [call site] 00018
3 [util.Tuf].hashAlgorithm(String) [function] [call site] 00019
3 [util.Tuf].publicKey(util.Tuf) [function] [call site] 00020
3 [dev.sigstore.trustroot.ImmutableLogId].builder() [function] [call site] 00021
3 [util.Tuf].keyId(util.Tuf) [function] [call site] 00022
3 [util.Tuf].build() [function] [call site] 00023
3 [util.Tuf].logId(util.Tuf) [function] [call site] 00024
3 [util.Tuf].build() [function] [call site] 00025
2 [java.util.List].of(dev.sigstore.trustroot.TransparencyLog) [function] [call site] 00026
1 [com.code_intelligence.jazzer.api.FuzzedDataProvider].consumeRemainingAsBytes() [function] [call site] 00027
1 [String].<init>(byte[],fuzzing.RekorVerifierFuzzer) [function] [call site] 00028
1 [java.net.URI].<init>(String) [function] [call site] 00029
1 [dev.sigstore.rekor.client.RekorResponse].newRekorResponse(java.net.URI,String) [function] [call site] 00030
2 [com.google.common.reflect.TypeToken].<init>() [function] [call site] 00031
2 [com.google.common.reflect.TypeToken].getType() [function] [call site] 00032
2 [dev.sigstore.json.GsonSupplier.GSON].get() [function] [call site] 00033
2 [dev.sigstore.rekor.client.RekorResponse].fromJson(String,dev.sigstore.rekor.client.RekorResponse) [function] [call site] 00034
2 [dev.sigstore.rekor.client.RekorParseException].<init>(String,dev.sigstore.rekor.client.RekorResponse) [function] [call site] 00035
2 [dev.sigstore.rekor.client.RekorParseException].<init>(String) [function] [call site] 00036
3 [Exception].<init>(String) [function] [call site] 00037
2 [dev.sigstore.rekor.client.RekorResponse].size() [function] [call site] 00038
2 [dev.sigstore.rekor.client.RekorResponse].size() [function] [call site] 00039
2 [dev.sigstore.rekor.client.RekorParseException].<init>(String) [function] [call site] 00040
2 [dev.sigstore.rekor.client.RekorResponse].entrySet() [function] [call site] 00041
2 [dev.sigstore.rekor.client.RekorResponse].iterator() [function] [call site] 00042
2 [dev.sigstore.rekor.client.RekorResponse].next() [function] [call site] 00043
2 [dev.sigstore.rekor.client.RekorResponse].getKey() [function] [call site] 00044
2 [dev.sigstore.rekor.client.RekorResponse].getValue() [function] [call site] 00045
2 [dev.sigstore.rekor.client.RekorParseException].<init>(String) [function] [call site] 00046
2 [dev.sigstore.rekor.client.RekorResponse].entryLocation(java.net.URI) [function] [call site] 00047
2 [dev.sigstore.rekor.client.RekorResponse].raw(String) [function] [call site] 00048
2 [dev.sigstore.rekor.client.RekorResponse].getKey() [function] [call site] 00049
2 [dev.sigstore.rekor.client.RekorResponse].uuid(dev.sigstore.rekor.client.RekorResponse) [function] [call site] 00050
2 [dev.sigstore.rekor.client.RekorResponse].getValue() [function] [call site] 00051
2 [dev.sigstore.rekor.client.RekorResponse].entry(dev.sigstore.rekor.client.RekorResponse) [function] [call site] 00052
2 [dev.sigstore.rekor.client.RekorResponse].build() [function] [call site] 00053
1 [dev.sigstore.rekor.client.RekorResponse].getEntry() [function] [call site] 00054
1 [dev.sigstore.rekor.client.RekorVerifier].newRekorVerifier(java.util.List<dev.sigstore.trustroot.TransparencyLog>) [function] [call site] 00055
2 [dev.sigstore.rekor.client.RekorVerifier].<init>(java.util.List<dev.sigstore.trustroot.TransparencyLog>) [function] [call site] 00056
1 [dev.sigstore.rekor.client.RekorVerifier].verifyEntry(dev.sigstore.rekor.client.RekorEntry) [function] [call site] 00057
2 [dev.sigstore.rekor.client.RekorEntry].getVerification() [function] [call site] 00058
2 [dev.sigstore.rekor.client.RekorVerificationException].<init>(String) [function] [call site] 00059
3 [Exception].<init>(String) [function] [call site] 00060
2 [dev.sigstore.rekor.client.RekorEntry].getVerification() [function] [call site] 00061
2 [dev.sigstore.rekor.client.RekorEntry.Verification].getSignedEntryTimestamp() [function] [call site] 00062
2 [dev.sigstore.rekor.client.RekorVerificationException].<init>(String) [function] [call site] 00063
2 [dev.sigstore.rekor.client.RekorEntry].getLogID() [function] [call site] 00064
2 [org.bouncycastle.util.encoders.Hex].decode(String) [function] [call site] 00065
2 [dev.sigstore.rekor.client.RekorEntry].getIntegratedTimeInstant() [function] [call site] 00066
3 [dev.sigstore.rekor.client.RekorEntry].getIntegratedTime() [function] [call site] 00067
3 [java.time.Instant].ofEpochSecond(long) [function] [call site] 00068
2 [dev.sigstore.trustroot.TransparencyLog].find(java.util.List<dev.sigstore.trustroot.TransparencyLog>,dev.sigstore.rekor.client.RekorVerifier,java.time.Instant) [function] [call site] 00069
2 [java.util.Optional<dev.sigstore.trustroot.TransparencyLog>].orElseThrow() [function] [call site] 00070
2 [dev.sigstore.rekor.client.RekorVerifier].getPublicKey() [function] [call site] 00071
2 [dev.sigstore.rekor.client.RekorVerifier].toJavaPublicKey() [function] [call site] 00072
2 [dev.sigstore.encryption.signers.Verifiers].newVerifier(dev.sigstore.rekor.client.RekorVerifier) [function] [call site] 00073
2 [dev.sigstore.rekor.client.RekorEntry].getSignableContent() [function] [call site] 00074
3 [HashMap].<init>() [function] [call site] 00075
3 [dev.sigstore.rekor.client.RekorEntry].getBody() [function] [call site] 00076
3 [HashMap].put(String,String) [function] [call site] 00077
3 [dev.sigstore.rekor.client.RekorEntry].getIntegratedTime() [function] [call site] 00078
3 [HashMap].put(String,long) [function] [call site] 00079
3 [dev.sigstore.rekor.client.RekorEntry].getLogID() [function] [call site] 00080
3 [HashMap].put(String,String) [function] [call site] 00081
3 [dev.sigstore.rekor.client.RekorEntry].getLogIndex() [function] [call site] 00082
3 [HashMap].put(String,long) [function] [call site] 00083
3 [dev.sigstore.json.GsonSupplier.GSON].get() [function] [call site] 00084
3 [dev.sigstore.rekor.client.RekorEntry].toJson(HashMap) [function] [call site] 00085
3 [org.erdtman.jcs.JsonCanonicalizer].<init>(dev.sigstore.rekor.client.RekorEntry) [function] [call site] 00086
3 [org.erdtman.jcs.JsonCanonicalizer].getEncodedUTF8() [function] [call site] 00087
3 [RuntimeException].<init>(String) [function] [call site] 00088
2 [java.util.Base64].getDecoder() [function] [call site] 00089
2 [dev.sigstore.rekor.client.RekorEntry].getVerification() [function] [call site] 00090
2 [dev.sigstore.rekor.client.RekorEntry.Verification].getSignedEntryTimestamp() [function] [call site] 00091
2 [dev.sigstore.rekor.client.RekorVerifier].decode(dev.sigstore.rekor.client.RekorVerifier) [function] [call site] 00092
2 [dev.sigstore.tuf.encryption.Verifier].verify(byte[],dev.sigstore.rekor.client.RekorVerifier) [function] [call site] 00093
2 [dev.sigstore.rekor.client.RekorVerificationException].<init>(String) [function] [call site] 00094
2 [dev.sigstore.rekor.client.RekorVerificationException].<init>(String,dev.sigstore.rekor.client.RekorVerifier) [function] [call site] 00095
2 [dev.sigstore.rekor.client.RekorVerificationException].<init>(String,dev.sigstore.rekor.client.RekorVerifier) [function] [call site] 00096
2 [dev.sigstore.rekor.client.RekorVerificationException].<init>(String,dev.sigstore.rekor.client.RekorVerifier) [function] [call site] 00097
2 [AssertionError].<init>(String) [function] [call site] 00098
2 [dev.sigstore.rekor.client.RekorVerifier].verifyInclusionProof(dev.sigstore.rekor.client.RekorEntry) [function] [call site] 00099
3 [dev.sigstore.rekor.client.RekorEntry].getVerification() [function] [call site] 00100
3 [dev.sigstore.rekor.client.RekorEntry.Verification].getInclusionProof() [function] [call site] 00101
3 [com.google.common.hash.Hashing].sha256() [function] [call site] 00102
3 [dev.sigstore.rekor.client.RekorVerifier].newHasher() [function] [call site] 00103
3 [dev.sigstore.rekor.client.RekorVerifier].putByte(byte) [function] [call site] 00104
3 [java.util.Base64].getDecoder() [function] [call site] 00105
3 [dev.sigstore.rekor.client.RekorEntry].getBody() [function] [call site] 00106
3 [dev.sigstore.rekor.client.RekorVerifier].decode(String) [function] [call site] 00107
3 [dev.sigstore.rekor.client.RekorVerifier].putBytes(dev.sigstore.rekor.client.RekorVerifier) [function] [call site] 00108
3 [dev.sigstore.rekor.client.RekorVerifier].hash() [function] [call site] 00109
3 [dev.sigstore.rekor.client.RekorVerifier].asBytes() [function] [call site] 00110
3 [java.util.ArrayList].<init>() [function] [call site] 00111
3 [dev.sigstore.rekor.client.RekorVerifier].getHashes() [function] [call site] 00112
3 [org.bouncycastle.util.encoders.Hex].decode(dev.sigstore.rekor.client.RekorVerifier) [function] [call site] 00113
3 [java.util.ArrayList].add(dev.sigstore.rekor.client.RekorVerifier) [function] [call site] 00114
3 [dev.sigstore.rekor.client.RekorVerifier].getRootHash() [function] [call site] 00115
3 [org.bouncycastle.util.encoders.Hex].decode(dev.sigstore.rekor.client.RekorVerifier) [function] [call site] 00116
3 [dev.sigstore.rekor.client.RekorVerifier].getLogIndex() [function] [call site] 00117
3 [dev.sigstore.rekor.client.RekorVerifier].getTreeSize() [function] [call site] 00118
3 [dev.sigstore.merkle.InclusionProofVerifier].verify(dev.sigstore.rekor.client.RekorVerifier,dev.sigstore.rekor.client.RekorVerifier,dev.sigstore.rekor.client.RekorVerifier,java.util.ArrayList,dev.sigstore.rekor.client.RekorVerifier) [function] [call site] 00119
3 [dev.sigstore.rekor.client.RekorVerificationException].<init>(String,dev.sigstore.rekor.client.RekorVerifier) [function] [call site] 00120
2 [dev.sigstore.rekor.client.RekorVerifier].verifyCheckpoint(dev.sigstore.rekor.client.RekorEntry,dev.sigstore.rekor.client.RekorVerifier) [function] [call site] 00121