eventlog_free_contents:
   38|    411|{
   39|    411|    size_t i;
   40|    411|    debug_decl(eventlog_free_contents, SUDO_DEBUG_UTIL);
  ------------------
  |  |  119|    411|    debug_decl_vars((funcname), (subsys));				       \
  |  |  ------------------
  |  |  |  |  110|    411|    const unsigned int sudo_debug_subsys = (subsys)
  |  |  ------------------
  |  |  120|    411|    sudo_debug_enter(__func__, __FILE__, __LINE__, sudo_debug_subsys)
  |  |  ------------------
  |  |  |  |  236|    411|# define sudo_debug_enter(_a, _b, _c, _d)		((void)&(_d))
  |  |  ------------------
  ------------------
   41|       |
   42|    411|    free(evlog->iolog_path);
   43|    411|    free(evlog->command);
   44|    411|    free(evlog->cwd);
   45|    411|    free(evlog->runchroot);
   46|    411|    free(evlog->runcwd);
   47|    411|    free(evlog->rungroup);
   48|    411|    free(evlog->runuser);
   49|    411|    free(evlog->peeraddr);
   50|    411|    free(evlog->signal_name);
   51|    411|    free(evlog->source);
   52|    411|    if (evlog->submitenv != NULL) {
  ------------------
  |  Branch (52:9): [True: 0, False: 411]
  ------------------
   53|      0|	for (i = 0; evlog->submitenv[i] != NULL; i++)
  ------------------
  |  Branch (53:14): [True: 0, False: 0]
  ------------------
   54|      0|	    free(evlog->submitenv[i]);
   55|      0|	free(evlog->submitenv);
   56|      0|    }
   57|    411|    free(evlog->submithost);
   58|    411|    free(evlog->submituser);
   59|    411|    free(evlog->submitgroup);
   60|    411|    free(evlog->ttyname);
   61|    411|    if (evlog->runargv != NULL) {
  ------------------
  |  Branch (61:9): [True: 0, False: 411]
  ------------------
   62|      0|	for (i = 0; evlog->runargv[i] != NULL; i++)
  ------------------
  |  Branch (62:14): [True: 0, False: 0]
  ------------------
   63|      0|	    free(evlog->runargv[i]);
   64|      0|	free(evlog->runargv);
   65|      0|    }
   66|    411|    if (evlog->runenv != NULL) {
  ------------------
  |  Branch (66:9): [True: 0, False: 411]
  ------------------
   67|      0|	for (i = 0; evlog->runenv[i] != NULL; i++)
  ------------------
  |  Branch (67:14): [True: 0, False: 0]
  ------------------
   68|      0|	    free(evlog->runenv[i]);
   69|      0|	free(evlog->runenv);
   70|      0|    }
   71|    411|    if (evlog->env_add != NULL) {
  ------------------
  |  Branch (71:9): [True: 0, False: 411]
  ------------------
   72|      0|	for (i = 0; evlog->env_add[i] != NULL; i++)
  ------------------
  |  Branch (72:14): [True: 0, False: 0]
  ------------------
   73|      0|	    free(evlog->env_add[i]);
   74|      0|	free(evlog->env_add);
   75|      0|    }
   76|       |
   77|    411|    debug_return;
  ------------------
  |  |  257|    411|    do {								       \
  |  |  258|    411|	sudo_debug_exit(__func__, __FILE__, __LINE__, sudo_debug_subsys);      \
  |  |  ------------------
  |  |  |  |  237|    411|# define sudo_debug_exit(_a, _b, _c, _d)		((void)&(_d))
  |  |  ------------------
  |  |  259|    411|	return;								       \
  |  |  260|    411|    } while (0)
  |  |  ------------------
  |  |  |  Branch (260:14): [Folded, False: 0]
  |  |  ------------------
  ------------------
   78|    411|}
eventlog_free:
   85|    411|{
   86|    411|    debug_decl(eventlog_free, SUDO_DEBUG_UTIL);
  ------------------
  |  |  119|    411|    debug_decl_vars((funcname), (subsys));				       \
  |  |  ------------------
  |  |  |  |  110|    411|    const unsigned int sudo_debug_subsys = (subsys)
  |  |  ------------------
  |  |  120|    411|    sudo_debug_enter(__func__, __FILE__, __LINE__, sudo_debug_subsys)
  |  |  ------------------
  |  |  |  |  236|    411|# define sudo_debug_enter(_a, _b, _c, _d)		((void)&(_d))
  |  |  ------------------
  ------------------
   87|       |
   88|    411|    if (evlog != NULL) {
  ------------------
  |  Branch (88:9): [True: 411, False: 0]
  ------------------
   89|    411|	eventlog_free_contents(evlog);
   90|    411|	free(evlog);
   91|    411|    }
   92|       |
   93|    411|    debug_return;
  ------------------
  |  |  257|    411|    do {								       \
  |  |  258|    411|	sudo_debug_exit(__func__, __FILE__, __LINE__, sudo_debug_subsys);      \
  |  |  ------------------
  |  |  |  |  237|    411|# define sudo_debug_exit(_a, _b, _c, _d)		((void)&(_d))
  |  |  ------------------
  |  |  259|    411|	return;								       \
  |  |  260|    411|    } while (0)
  |  |  ------------------
  |  |  |  Branch (260:14): [Folded, False: 0]
  |  |  ------------------
  ------------------
   94|    411|}

iolog_parse_loginfo_legacy:
   44|    411|{
   45|    411|    char *buf = NULL, *cp, *ep;
   46|    411|    const char *errstr;
   47|    411|    size_t bufsize = 0, cwdsize = 0, cmdsize = 0;
   48|    411|    bool ret = false;
   49|    411|    debug_decl(iolog_parse_loginfo_legacy, SUDO_DEBUG_UTIL);
  ------------------
  |  |  119|    411|    debug_decl_vars((funcname), (subsys));				       \
  |  |  ------------------
  |  |  |  |  110|    411|    const unsigned int sudo_debug_subsys = (subsys)
  |  |  ------------------
  |  |  120|    411|    sudo_debug_enter(__func__, __FILE__, __LINE__, sudo_debug_subsys)
  |  |  ------------------
  |  |  |  |  236|    411|# define sudo_debug_enter(_a, _b, _c, _d)		((void)&(_d))
  |  |  ------------------
  ------------------
   50|       |
   51|       |    /*
   52|       |     * Info file has three lines:
   53|       |     *  1) a log info line
   54|       |     *  2) cwd
   55|       |     *  3) command with args
   56|       |     */
   57|    411|    if (getdelim(&buf, &bufsize, '\n', fp) == -1 ||
  ------------------
  |  Branch (57:9): [True: 0, False: 411]
  ------------------
   58|    411|	getdelim(&evlog->cwd, &cwdsize, '\n', fp) == -1 ||
  ------------------
  |  Branch (58:2): [True: 24, False: 387]
  ------------------
   59|    387|	getdelim(&evlog->command, &cmdsize, '\n', fp) == -1) {
  ------------------
  |  Branch (59:2): [True: 21, False: 366]
  ------------------
   60|     45|	sudo_warn(U_("%s: invalid log file"), iolog_dir);
  ------------------
  |  |   44|     45|# define sudo_warn sudo_warn_nodebug_v1
  ------------------
              	sudo_warn(U_("%s: invalid log file"), iolog_dir);
  ------------------
  |  |   59|     45|# define U_(String) sudo_warn_gettext(String)
  |  |  ------------------
  |  |  |  |  208|     45|# define sudo_warn_gettext(_a) sudo_warn_gettext_v1(NULL, (_a))
  |  |  ------------------
  ------------------
   61|     45|	goto done;
   62|     45|    }
   63|       |
   64|       |    /* Strip the newline from the cwd and command. */
   65|    366|    evlog->cwd[strcspn(evlog->cwd, "\n")] = '\0';
   66|    366|    evlog->command[strcspn(evlog->command, "\n")] = '\0';
   67|       |
   68|       |    /*
   69|       |     * Crack the log line (lines and cols not present in old versions).
   70|       |     *	timestamp:user:runas_user:runas_group:tty:lines:cols
   71|       |     * XXX - probably better to use strtok and switch on the state.
   72|       |     */
   73|    366|    buf[strcspn(buf, "\n")] = '\0';
   74|    366|    cp = buf;
   75|       |
   76|       |    /* timestamp */
   77|    366|    if ((ep = strchr(cp, ':')) == NULL) {
  ------------------
  |  Branch (77:9): [True: 19, False: 347]
  ------------------
   78|     19|	sudo_warn(U_("%s: time stamp field is missing"), iolog_dir);
  ------------------
  |  |   44|     19|# define sudo_warn sudo_warn_nodebug_v1
  ------------------
              	sudo_warn(U_("%s: time stamp field is missing"), iolog_dir);
  ------------------
  |  |   59|     19|# define U_(String) sudo_warn_gettext(String)
  |  |  ------------------
  |  |  |  |  208|     19|# define sudo_warn_gettext(_a) sudo_warn_gettext_v1(NULL, (_a))
  |  |  ------------------
  ------------------
   79|     19|	goto done;
   80|     19|    }
   81|    347|    *ep = '\0';
   82|    347|    evlog->event_time.tv_sec =
   83|    347|	(time_t)sudo_strtonum(cp, 0, TIME_T_MAX, &errstr);
  ------------------
  |  |   53|    347|#  define TIME_T_MAX	LLONG_MAX
  ------------------
   84|    347|    if (errstr != NULL) {
  ------------------
  |  Branch (84:9): [True: 111, False: 236]
  ------------------
   85|    111|	sudo_warn(U_("%s: time stamp %s: %s"), iolog_dir, cp, errstr);
  ------------------
  |  |   44|    111|# define sudo_warn sudo_warn_nodebug_v1
  ------------------
              	sudo_warn(U_("%s: time stamp %s: %s"), iolog_dir, cp, errstr);
  ------------------
  |  |   59|    111|# define U_(String) sudo_warn_gettext(String)
  |  |  ------------------
  |  |  |  |  208|    111|# define sudo_warn_gettext(_a) sudo_warn_gettext_v1(NULL, (_a))
  |  |  ------------------
  ------------------
   86|    111|	goto done;
   87|    111|    }
   88|       |
   89|       |    /* submit user */
   90|    236|    cp = ep + 1;
   91|    236|    if ((ep = strchr(cp, ':')) == NULL) {
  ------------------
  |  Branch (91:9): [True: 151, False: 85]
  ------------------
   92|    151|	sudo_warn(U_("%s: user field is missing"), iolog_dir);
  ------------------
  |  |   44|    151|# define sudo_warn sudo_warn_nodebug_v1
  ------------------
              	sudo_warn(U_("%s: user field is missing"), iolog_dir);
  ------------------
  |  |   59|    151|# define U_(String) sudo_warn_gettext(String)
  |  |  ------------------
  |  |  |  |  208|    151|# define sudo_warn_gettext(_a) sudo_warn_gettext_v1(NULL, (_a))
  |  |  ------------------
  ------------------
   93|    151|	goto done;
   94|    151|    }
   95|     85|    if ((evlog->submituser = strndup(cp, (size_t)(ep - cp))) == NULL) {
  ------------------
  |  Branch (95:9): [True: 0, False: 85]
  ------------------
   96|      0|	sudo_warnx(U_("%s: %s"), __func__, U_("unable to allocate memory"));
  ------------------
  |  |   45|      0|# define sudo_warnx sudo_warnx_nodebug_v1
  ------------------
              	sudo_warnx(U_("%s: %s"), __func__, U_("unable to allocate memory"));
  ------------------
  |  |   59|      0|# define U_(String) sudo_warn_gettext(String)
  |  |  ------------------
  |  |  |  |  208|      0|# define sudo_warn_gettext(_a) sudo_warn_gettext_v1(NULL, (_a))
  |  |  ------------------
  ------------------
              	sudo_warnx(U_("%s: %s"), __func__, U_("unable to allocate memory"));
  ------------------
  |  |   59|      0|# define U_(String) sudo_warn_gettext(String)
  |  |  ------------------
  |  |  |  |  208|      0|# define sudo_warn_gettext(_a) sudo_warn_gettext_v1(NULL, (_a))
  |  |  ------------------
  ------------------
   97|      0|	goto done;
   98|      0|    }
   99|       |
  100|       |    /* runas user */
  101|     85|    cp = ep + 1;
  102|     85|    if ((ep = strchr(cp, ':')) == NULL) {
  ------------------
  |  Branch (102:9): [True: 1, False: 84]
  ------------------
  103|      1|	sudo_warn(U_("%s: runas user field is missing"), iolog_dir);
  ------------------
  |  |   44|      1|# define sudo_warn sudo_warn_nodebug_v1
  ------------------
              	sudo_warn(U_("%s: runas user field is missing"), iolog_dir);
  ------------------
  |  |   59|      1|# define U_(String) sudo_warn_gettext(String)
  |  |  ------------------
  |  |  |  |  208|      1|# define sudo_warn_gettext(_a) sudo_warn_gettext_v1(NULL, (_a))
  |  |  ------------------
  ------------------
  104|      1|	goto done;
  105|      1|    }
  106|     84|    if ((evlog->runuser = strndup(cp, (size_t)(ep - cp))) == NULL) {
  ------------------
  |  Branch (106:9): [True: 0, False: 84]
  ------------------
  107|      0|	sudo_warnx(U_("%s: %s"), __func__, U_("unable to allocate memory"));
  ------------------
  |  |   45|      0|# define sudo_warnx sudo_warnx_nodebug_v1
  ------------------
              	sudo_warnx(U_("%s: %s"), __func__, U_("unable to allocate memory"));
  ------------------
  |  |   59|      0|# define U_(String) sudo_warn_gettext(String)
  |  |  ------------------
  |  |  |  |  208|      0|# define sudo_warn_gettext(_a) sudo_warn_gettext_v1(NULL, (_a))
  |  |  ------------------
  ------------------
              	sudo_warnx(U_("%s: %s"), __func__, U_("unable to allocate memory"));
  ------------------
  |  |   59|      0|# define U_(String) sudo_warn_gettext(String)
  |  |  ------------------
  |  |  |  |  208|      0|# define sudo_warn_gettext(_a) sudo_warn_gettext_v1(NULL, (_a))
  |  |  ------------------
  ------------------
  108|      0|	goto done;
  109|      0|    }
  110|       |
  111|       |    /* runas group */
  112|     84|    cp = ep + 1;
  113|     84|    if ((ep = strchr(cp, ':')) == NULL) {
  ------------------
  |  Branch (113:9): [True: 1, False: 83]
  ------------------
  114|      1|	sudo_warn(U_("%s: runas group field is missing"), iolog_dir);
  ------------------
  |  |   44|      1|# define sudo_warn sudo_warn_nodebug_v1
  ------------------
              	sudo_warn(U_("%s: runas group field is missing"), iolog_dir);
  ------------------
  |  |   59|      1|# define U_(String) sudo_warn_gettext(String)
  |  |  ------------------
  |  |  |  |  208|      1|# define sudo_warn_gettext(_a) sudo_warn_gettext_v1(NULL, (_a))
  |  |  ------------------
  ------------------
  115|      1|	goto done;
  116|      1|    }
  117|     83|    if (cp != ep) {
  ------------------
  |  Branch (117:9): [True: 1, False: 82]
  ------------------
  118|      1|	if ((evlog->rungroup = strndup(cp, (size_t)(ep - cp))) == NULL) {
  ------------------
  |  Branch (118:6): [True: 0, False: 1]
  ------------------
  119|      0|	    sudo_warnx(U_("%s: %s"), __func__, U_("unable to allocate memory"));
  ------------------
  |  |   45|      0|# define sudo_warnx sudo_warnx_nodebug_v1
  ------------------
              	    sudo_warnx(U_("%s: %s"), __func__, U_("unable to allocate memory"));
  ------------------
  |  |   59|      0|# define U_(String) sudo_warn_gettext(String)
  |  |  ------------------
  |  |  |  |  208|      0|# define sudo_warn_gettext(_a) sudo_warn_gettext_v1(NULL, (_a))
  |  |  ------------------
  ------------------
              	    sudo_warnx(U_("%s: %s"), __func__, U_("unable to allocate memory"));
  ------------------
  |  |   59|      0|# define U_(String) sudo_warn_gettext(String)
  |  |  ------------------
  |  |  |  |  208|      0|# define sudo_warn_gettext(_a) sudo_warn_gettext_v1(NULL, (_a))
  |  |  ------------------
  ------------------
  120|      0|	    goto done;
  121|      0|	}
  122|      1|    }
  123|       |
  124|       |    /* tty, followed by optional lines + cols */
  125|     83|    cp = ep + 1;
  126|     83|    if ((ep = strchr(cp, ':')) == NULL) {
  ------------------
  |  Branch (126:9): [True: 2, False: 81]
  ------------------
  127|       |	/* just the tty */
  128|      2|	if ((evlog->ttyname = strdup(cp)) == NULL) {
  ------------------
  |  Branch (128:6): [True: 0, False: 2]
  ------------------
  129|      0|	    sudo_warnx(U_("%s: %s"), __func__, U_("unable to allocate memory"));
  ------------------
  |  |   45|      0|# define sudo_warnx sudo_warnx_nodebug_v1
  ------------------
              	    sudo_warnx(U_("%s: %s"), __func__, U_("unable to allocate memory"));
  ------------------
  |  |   59|      0|# define U_(String) sudo_warn_gettext(String)
  |  |  ------------------
  |  |  |  |  208|      0|# define sudo_warn_gettext(_a) sudo_warn_gettext_v1(NULL, (_a))
  |  |  ------------------
  ------------------
              	    sudo_warnx(U_("%s: %s"), __func__, U_("unable to allocate memory"));
  ------------------
  |  |   59|      0|# define U_(String) sudo_warn_gettext(String)
  |  |  ------------------
  |  |  |  |  208|      0|# define sudo_warn_gettext(_a) sudo_warn_gettext_v1(NULL, (_a))
  |  |  ------------------
  ------------------
  130|      0|	    goto done;
  131|      0|	}
  132|     81|    } else {
  133|       |	/* tty followed by lines + cols */
  134|     81|	if ((evlog->ttyname = strndup(cp, (size_t)(ep - cp))) == NULL) {
  ------------------
  |  Branch (134:6): [True: 0, False: 81]
  ------------------
  135|      0|	    sudo_warnx(U_("%s: %s"), __func__, U_("unable to allocate memory"));
  ------------------
  |  |   45|      0|# define sudo_warnx sudo_warnx_nodebug_v1
  ------------------
              	    sudo_warnx(U_("%s: %s"), __func__, U_("unable to allocate memory"));
  ------------------
  |  |   59|      0|# define U_(String) sudo_warn_gettext(String)
  |  |  ------------------
  |  |  |  |  208|      0|# define sudo_warn_gettext(_a) sudo_warn_gettext_v1(NULL, (_a))
  |  |  ------------------
  ------------------
              	    sudo_warnx(U_("%s: %s"), __func__, U_("unable to allocate memory"));
  ------------------
  |  |   59|      0|# define U_(String) sudo_warn_gettext(String)
  |  |  ------------------
  |  |  |  |  208|      0|# define sudo_warn_gettext(_a) sudo_warn_gettext_v1(NULL, (_a))
  |  |  ------------------
  ------------------
  136|      0|	    goto done;
  137|      0|	}
  138|     81|	cp = ep + 1;
  139|       |	/* need to NULL out separator to use sudo_strtonum() */
  140|       |	/* XXX - use sudo_strtonumx */
  141|     81|	if ((ep = strchr(cp, ':')) != NULL) {
  ------------------
  |  Branch (141:6): [True: 12, False: 69]
  ------------------
  142|     12|	    *ep = '\0';
  143|     12|	}
  144|     81|	evlog->lines = (int)sudo_strtonum(cp, 1, INT_MAX, &errstr);
  145|     81|	if (errstr != NULL) {
  ------------------
  |  Branch (145:6): [True: 55, False: 26]
  ------------------
  146|     55|	    sudo_debug_printf(SUDO_DEBUG_ERROR|SUDO_DEBUG_LINENO,
  ------------------
  |  |  394|     55|    sudo_debug_printf2(__func__, __FILE__, __LINE__, (pri)|sudo_debug_subsys, \
  |  |  ------------------
  |  |  |  |  443|     55|#define sudo_debug_printf2 sudo_debug_printf2_v1
  |  |  ------------------
  |  |  395|     55|    __VA_ARGS__)
  ------------------
  147|     55|		"%s: tty lines %s: %s", iolog_dir, cp, errstr);
  148|     55|	}
  149|     81|	if (ep != NULL) {
  ------------------
  |  Branch (149:6): [True: 12, False: 69]
  ------------------
  150|     12|	    cp = ep + 1;
  151|     12|	    evlog->columns = (int)sudo_strtonum(cp, 1, INT_MAX, &errstr);
  152|     12|	    if (errstr != NULL) {
  ------------------
  |  Branch (152:10): [True: 8, False: 4]
  ------------------
  153|      8|		sudo_debug_printf(SUDO_DEBUG_ERROR|SUDO_DEBUG_LINENO,
  ------------------
  |  |  394|      8|    sudo_debug_printf2(__func__, __FILE__, __LINE__, (pri)|sudo_debug_subsys, \
  |  |  ------------------
  |  |  |  |  443|      8|#define sudo_debug_printf2 sudo_debug_printf2_v1
  |  |  ------------------
  |  |  395|      8|    __VA_ARGS__)
  ------------------
  154|      8|		    "%s: tty cols %s: %s", iolog_dir, cp, errstr);
  155|      8|	    }
  156|     12|	}
  157|     81|    }
  158|       |
  159|     83|    ret = true;
  160|       |
  161|    411|done:
  162|    411|    free(buf);
  163|       |    debug_return_bool(ret);
  ------------------
  |  |  335|    411|    do {								       \
  |  |  336|    411|	bool sudo_debug_ret = (ret);					       \
  |  |  337|    411|	sudo_debug_exit_bool(__func__, __FILE__, __LINE__, sudo_debug_subsys,  \
  |  |  ------------------
  |  |  |  |  247|    411|# define sudo_debug_exit_bool(_a, _b, _c, _d, _e)	((void)&(_d))
  |  |  ------------------
  |  |  338|    411|	    sudo_debug_ret);						       \
  |  |  339|    411|	return sudo_debug_ret;						       \
  |  |  340|    411|    } while (0)
  |  |  ------------------
  |  |  |  Branch (340:14): [Folded, False: 0]
  |  |  ------------------
  ------------------
  164|    411|}

LLVMFuzzerTestOneInput:
   93|    411|{
   94|    411|    struct eventlog *evlog = NULL;
   95|    411|    FILE *fp;
   96|       |
   97|    411|    initprogname("fuzz_iolog_legacy");
   98|    411|    if (getenv("SUDO_FUZZ_VERBOSE") == NULL)
  ------------------
  |  Branch (98:9): [True: 411, False: 0]
  ------------------
   99|    411|	sudo_warn_set_conversation(fuzz_conversation);
  ------------------
  |  |  203|    411|#define sudo_warn_set_conversation(_a) sudo_warn_set_conversation_v1(_a)
  ------------------
  100|       |
  101|    411|    fp = open_data(data, size);
  102|    411|    if (fp == NULL)
  ------------------
  |  Branch (102:9): [True: 0, False: 411]
  ------------------
  103|      0|        return 0;
  104|       |
  105|       |    /* Parsed contents of an I/O log info file are stored in evlog. */
  106|    411|    evlog = calloc(1, sizeof(*evlog));
  107|    411|    if (evlog != NULL) {
  ------------------
  |  Branch (107:9): [True: 411, False: 0]
  ------------------
  108|    411|	evlog->runuid = (uid_t)-1;
  109|    411|	evlog->rungid = (gid_t)-1;
  110|       |
  111|       |	/* Try to parse buffer as a legacy-format I/O log info file. */
  112|    411|	iolog_parse_loginfo_legacy(fp, "fuzz.legacy", evlog);
  113|    411|	eventlog_free(evlog);
  114|    411|    }
  115|    411|    fclose(fp);
  116|    411|    fflush(stdout);
  117|       |
  118|    411|    return 0;
  119|    411|}
fuzz_iolog_legacy.c:fuzz_conversation:
   68|    328|{
   69|    328|    int n;
   70|       |
   71|  2.29k|    for (n = 0; n < num_msgs; n++) {
  ------------------
  |  Branch (71:17): [True: 1.96k, False: 328]
  ------------------
   72|  1.96k|	const struct sudo_conv_message *msg = &msgs[n];
   73|       |
   74|  1.96k|	switch (msg->msg_type & 0xff) {
   75|      0|	    case SUDO_CONV_PROMPT_ECHO_ON:
  ------------------
  |  |   44|      0|#define SUDO_CONV_PROMPT_ECHO_ON    0x0002  /* echo user input */
  ------------------
  |  Branch (75:6): [True: 0, False: 1.96k]
  ------------------
   76|      0|	    case SUDO_CONV_PROMPT_MASK:
  ------------------
  |  |   47|      0|#define SUDO_CONV_PROMPT_MASK	    0x0005  /* mask user input */
  ------------------
  |  Branch (76:6): [True: 0, False: 1.96k]
  ------------------
   77|      0|	    case SUDO_CONV_PROMPT_ECHO_OFF:
  ------------------
  |  |   43|      0|#define SUDO_CONV_PROMPT_ECHO_OFF   0x0001  /* do not echo user input */
  ------------------
  |  Branch (77:6): [True: 0, False: 1.96k]
  ------------------
   78|       |		/* input not supported */
   79|      0|		return -1;
   80|  1.96k|	    case SUDO_CONV_ERROR_MSG:
  ------------------
  |  |   45|  1.96k|#define SUDO_CONV_ERROR_MSG	    0x0003  /* error message */
  ------------------
  |  Branch (80:6): [True: 1.96k, False: 0]
  ------------------
   81|  1.96k|	    case SUDO_CONV_INFO_MSG:
  ------------------
  |  |   46|  1.96k|#define SUDO_CONV_INFO_MSG	    0x0004  /* informational message */
  ------------------
  |  Branch (81:6): [True: 0, False: 1.96k]
  ------------------
   82|       |		/* no output for fuzzers */
   83|  1.96k|		break;
   84|      0|	    default:
  ------------------
  |  Branch (84:6): [True: 0, False: 1.96k]
  ------------------
   85|      0|		return -1;
   86|  1.96k|	}
   87|  1.96k|    }
   88|    328|    return 0;
   89|    328|}
fuzz_iolog_legacy.c:open_data:
   41|    411|{
   42|    411|#ifdef HAVE_FMEMOPEN
   43|       |    /* Operate in-memory. */
   44|    411|    return fmemopen((void *)data, size, "r");
   45|       |#else
   46|       |    char tempfile[] = "/tmp/legacy.XXXXXX";
   47|       |    size_t nwritten;
   48|       |    int fd;
   49|       |
   50|       |    /* Use (unlinked) temporary file. */
   51|       |    fd = mkstemp(tempfile);
   52|       |    if (fd == -1)
   53|       |	return NULL;
   54|       |    unlink(tempfile);
   55|       |    nwritten = write(fd, data, size);
   56|       |    if (nwritten != size) {
   57|       |	close(fd);
   58|       |	return NULL;
   59|       |    }
   60|       |    lseek(fd, 0, SEEK_SET);
   61|       |    return fdopen(fd, "r");
   62|       |#endif
   63|    411|}

sudo_warn_nodebug_v1:
  112|    328|{
  113|    328|    va_list ap;
  114|       |
  115|    328|    va_start(ap, fmt);
  116|    328|    warning(strerror(errno), fmt, ap);
  117|       |    va_end(ap);
  118|    328|}
sudo_warn_set_conversation_v1:
  306|    411|{
  307|    411|    sudo_warn_conversation = conv;
  308|    411|}
sudo_warn_gettext_v1:
  324|    328|{
  325|    328|    int cookie;
  326|    328|    char *msg;
  327|       |
  328|       |    /* Set user locale if setter was specified. */
  329|    328|    if (sudo_warn_setlocale != NULL)
  ------------------
  |  Branch (329:9): [True: 0, False: 328]
  ------------------
  330|      0|	sudo_warn_setlocale(false, &cookie);
  331|       |
  332|    328|    msg = dgettext(domainname, msgid);
  333|       |
  334|       |    /* Restore old locale as needed. */
  335|    328|    if (sudo_warn_setlocale != NULL)
  ------------------
  |  Branch (335:9): [True: 0, False: 328]
  ------------------
  336|      0|	sudo_warn_setlocale(true, &cookie);
  337|       |
  338|    328|    return msg;
  339|    328|}
fatal.c:warning:
  179|    328|{
  180|    328|    int cookie;
  181|    328|    const int saved_errno = errno;
  182|       |
  183|       |    /* Set user locale if setter was specified. */
  184|    328|    if (sudo_warn_setlocale != NULL)
  ------------------
  |  Branch (184:9): [True: 0, False: 328]
  ------------------
  185|      0|	sudo_warn_setlocale(false, &cookie);
  186|       |
  187|    328|    if (sudo_warn_conversation != NULL) {
  ------------------
  |  Branch (187:9): [True: 328, False: 0]
  ------------------
  188|    328|	struct sudo_conv_message msgs[6];
  189|    328|	char static_buf[1024], *buf = static_buf;
  190|    328|	int nmsgs = 0;
  191|       |
  192|       |	/* Use conversation function. */
  193|    328|        msgs[nmsgs].msg_type = SUDO_CONV_ERROR_MSG;
  ------------------
  |  |   45|    328|#define SUDO_CONV_ERROR_MSG	    0x0003  /* error message */
  ------------------
  194|    328|	msgs[nmsgs++].msg = getprogname();
  ------------------
  |  |  540|    328|# define getprogname() sudo_getprogname()
  ------------------
  195|    328|        if (fmt != NULL) {
  ------------------
  |  Branch (195:13): [True: 328, False: 0]
  ------------------
  196|    328|		va_list ap2;
  197|    328|		int buflen;
  198|       |
  199|       |		/* Use static buffer if possible, else dynamic. */
  200|    328|		va_copy(ap2, ap);
  201|    328|		buflen = vsnprintf(static_buf, sizeof(static_buf), fmt, ap2);
  202|    328|		va_end(ap2);
  203|    328|		if (buflen >= ssizeof(static_buf)) {
  ------------------
  |  |  139|    328|#define ssizeof(_x)	((ssize_t)sizeof(_x))
  ------------------
  |  Branch (203:7): [True: 29, False: 299]
  ------------------
  204|       |		    /* Not enough room in static buf, allocate dynamically. */
  205|     29|		    if (vasprintf(&buf, fmt, ap) == -1)
  ------------------
  |  Branch (205:11): [True: 0, False: 29]
  ------------------
  206|      0|			buf = static_buf;
  207|     29|		}
  208|    328|		if (buflen > 0) {
  ------------------
  |  Branch (208:7): [True: 328, False: 0]
  ------------------
  209|    328|		    msgs[nmsgs].msg_type = SUDO_CONV_ERROR_MSG;
  ------------------
  |  |   45|    328|#define SUDO_CONV_ERROR_MSG	    0x0003  /* error message */
  ------------------
  210|    328|		    msgs[nmsgs++].msg = ": ";
  211|    328|		    msgs[nmsgs].msg_type = SUDO_CONV_ERROR_MSG;
  ------------------
  |  |   45|    328|#define SUDO_CONV_ERROR_MSG	    0x0003  /* error message */
  ------------------
  212|    328|		    msgs[nmsgs++].msg = buf;
  213|    328|		}
  214|    328|        }
  215|    328|        if (errstr != NULL) {
  ------------------
  |  Branch (215:13): [True: 328, False: 0]
  ------------------
  216|    328|	    msgs[nmsgs].msg_type = SUDO_CONV_ERROR_MSG;
  ------------------
  |  |   45|    328|#define SUDO_CONV_ERROR_MSG	    0x0003  /* error message */
  ------------------
  217|    328|	    msgs[nmsgs++].msg = ": ";
  218|    328|	    msgs[nmsgs].msg_type = SUDO_CONV_ERROR_MSG;
  ------------------
  |  |   45|    328|#define SUDO_CONV_ERROR_MSG	    0x0003  /* error message */
  ------------------
  219|    328|	    msgs[nmsgs++].msg = errstr;
  220|    328|        }
  221|    328|	msgs[nmsgs].msg_type = SUDO_CONV_ERROR_MSG;
  ------------------
  |  |   45|    328|#define SUDO_CONV_ERROR_MSG	    0x0003  /* error message */
  ------------------
  222|    328|	msgs[nmsgs++].msg = "\n";
  223|    328|	sudo_warn_conversation(nmsgs, msgs, NULL, NULL);
  224|    328|	if (buf != static_buf)
  ------------------
  |  Branch (224:6): [True: 29, False: 299]
  ------------------
  225|     29|	    free(buf);
  226|    328|    } else {
  227|       |	/* Write to the standard error. */
  228|      0|        fputs(getprogname(), stderr);
  ------------------
  |  |  540|      0|# define getprogname() sudo_getprogname()
  ------------------
  229|      0|        if (fmt != NULL) {
  ------------------
  |  Branch (229:13): [True: 0, False: 0]
  ------------------
  230|      0|                fputs(": ", stderr);
  231|      0|                vfprintf(stderr, fmt, ap);
  232|      0|        }
  233|      0|        if (errstr != NULL) {
  ------------------
  |  Branch (233:13): [True: 0, False: 0]
  ------------------
  234|      0|            fputs(": ", stderr);
  235|      0|            fputs(errstr, stderr);
  236|      0|        }
  237|       |#ifndef FUZZING_BUILD_MODE_UNSAFE_FOR_PRODUCTION
  238|       |        if (sudo_term_is_raw(fileno(stderr)))
  239|       |            putc('\r', stderr);
  240|       |#endif
  241|      0|        putc('\n', stderr);
  242|      0|    }
  243|       |
  244|       |    /* Restore old locale as needed. */
  245|    328|    if (sudo_warn_setlocale != NULL)
  ------------------
  |  Branch (245:9): [True: 0, False: 328]
  ------------------
  246|      0|	sudo_warn_setlocale(true, &cookie);
  247|       |
  248|       |    /* Do not clobber errno. */
  249|       |    errno = saved_errno;
  250|    328|}

sudo_getprogname:
   42|    739|{
   43|    739|    return __progname;
   44|    739|}
initprogname2:
   57|    411|{
   58|    411|    const char *progname;
   59|    411|    size_t i;
   60|       |
   61|       |    /* Fall back on "name" if getprogname() returns an empty string. */
   62|    411|    if ((progname = getprogname()) != NULL && *progname != '\0') {
  ------------------
  |  |  540|    411|# define getprogname() sudo_getprogname()
  ------------------
  |  Branch (62:9): [True: 411, False: 0]
  |  Branch (62:47): [True: 411, False: 0]
  ------------------
   63|    411|	name = progname;
   64|    411|    } else {
   65|       |	/* Make sure user-specified name is relative. */
   66|      0|	name = sudo_basename(name);
  ------------------
  |  |  189|      0|#define sudo_basename(_a) sudo_basename_v1(_a)
  ------------------
   67|      0|    }
   68|       |
   69|       |    /* Check for libtool prefix and strip it if present. */
   70|    411|    if (name[0] == 'l' && name[1] == 't' && name[2] == '-' && name[3] != '\0')
  ------------------
  |  Branch (70:9): [True: 0, False: 411]
  |  Branch (70:27): [True: 0, False: 0]
  |  Branch (70:45): [True: 0, False: 0]
  |  Branch (70:63): [True: 0, False: 0]
  ------------------
   71|      0|	name += 3;
   72|       |
   73|       |    /* Check allow list if present (first element is the default). */
   74|    411|    if (allowed != NULL) {
  ------------------
  |  Branch (74:9): [True: 0, False: 411]
  ------------------
   75|      0|	for (i = 0; ; i++) {
   76|      0|	    if (allowed[i] == NULL) {
  ------------------
  |  Branch (76:10): [True: 0, False: 0]
  ------------------
   77|      0|		name = allowed[0];
   78|      0|		break;
   79|      0|	    }
   80|      0|	    if (strcmp(allowed[i], name) == 0)
  ------------------
  |  Branch (80:10): [True: 0, False: 0]
  ------------------
   81|      0|		break;
   82|      0|	}
   83|      0|    }
   84|       |
   85|       |    /* Update internal progname if needed. */
   86|    411|    if (name != progname)
  ------------------
  |  Branch (86:9): [True: 0, False: 411]
  ------------------
   87|      0|	setprogname(name);
  ------------------
  |  |  545|      0|# define setprogname(_a) sudo_setprogname(_a)
  ------------------
   88|    411|    return;
   89|    411|}
initprogname:
   93|    411|{
   94|       |    initprogname2(name, NULL);
   95|    411|}

sudo_strtonumx:
   43|    440|{
   44|    440|    enum strtonum_err errval = STN_INITIAL;
   45|    440|    long long lastval, result = 0;
   46|    440|    const char *cp = str;
   47|    440|    int remainder;
   48|    440|    char ch, sign;
   49|       |
   50|    440|    if (minval > maxval) {
  ------------------
  |  Branch (50:9): [True: 0, False: 440]
  ------------------
   51|      0|	errval = STN_INVALID;
   52|      0|	goto done;
   53|      0|    }
   54|       |
   55|       |    /* Trim leading space and check sign, if any. */
   56|    670|    do {
   57|    670|	ch = *cp++;
   58|    670|    } while (isspace((unsigned char)ch));
  ------------------
  |  Branch (58:14): [True: 230, False: 440]
  ------------------
   59|    440|    switch (ch) {
   60|     54|    case '-':
  ------------------
  |  Branch (60:5): [True: 54, False: 386]
  ------------------
   61|     54|	sign = '-';
   62|     54|	ch = *cp++;
   63|     54|	break;
   64|      6|    case '+':
  ------------------
  |  Branch (64:5): [True: 6, False: 434]
  ------------------
   65|      6|	ch = *cp++;
   66|      6|	FALLTHROUGH;
  ------------------
  |  | 1642|      6|# define FALLTHROUGH		[[__fallthrough__]]
  ------------------
   67|    386|    default:
  ------------------
  |  Branch (67:5): [True: 380, False: 60]
  ------------------
   68|    386|	sign = '+';
   69|    386|	break;
   70|    440|    }
   71|       |
   72|       |    /*
   73|       |     * To prevent overflow we determine the highest (or lowest in
   74|       |     * the case of negative numbers) value result can have *before*
   75|       |     * if its multiplied (divided) by 10 as well as the remainder.
   76|       |     * If result matches this value and the next digit is larger than
   77|       |     * the remainder, we know the result is out of range.
   78|       |     * The remainder is always positive since it is compared against
   79|       |     * an unsigned digit.
   80|       |     */
   81|    440|    if (sign == '-') {
  ------------------
  |  Branch (81:9): [True: 54, False: 386]
  ------------------
   82|     54|	lastval = minval / 10;
   83|     54|	remainder = -(int)(minval % 10);
   84|     54|	if (remainder < 0) {
  ------------------
  |  Branch (84:6): [True: 9, False: 45]
  ------------------
   85|      9|	    lastval += 1;
   86|      9|	    remainder += 10;
   87|      9|	}
   88|    484|	for (;; ch = *cp++) {
   89|    484|	    if (!isdigit((unsigned char)ch))
  ------------------
  |  Branch (89:10): [True: 21, False: 463]
  ------------------
   90|     21|		break;
   91|    463|	    ch -= '0';
   92|    463|	    if (result < lastval || (result == lastval && ch > remainder)) {
  ------------------
  |  Branch (92:10): [True: 3, False: 460]
  |  Branch (92:31): [True: 460, False: 0]
  |  Branch (92:52): [True: 30, False: 430]
  ------------------
   93|       |		/* Skip remaining digits. */
   94|  3.12M|		do {
   95|  3.12M|		    ch = *cp++;
   96|  3.12M|		} while (isdigit((unsigned char)ch));
  ------------------
  |  Branch (96:12): [True: 3.12M, False: 33]
  ------------------
   97|     33|		errval = STN_TOOSMALL;
   98|     33|		break;
   99|    430|	    } else {
  100|    430|		result *= 10;
  101|    430|		result -= ch;
  102|    430|		errval = STN_VALID;
  103|    430|	    }
  104|    463|	}
  105|     54|	if (result > maxval)
  ------------------
  |  Branch (105:6): [True: 0, False: 54]
  ------------------
  106|      0|	    errval = STN_TOOBIG;
  107|    386|    } else {
  108|    386|	lastval = maxval / 10;
  109|    386|	remainder = (int)(maxval % 10);
  110|  10.8k|	for (;; ch = *cp++) {
  111|  10.8k|	    if (!isdigit((unsigned char)ch))
  ------------------
  |  Branch (111:10): [True: 279, False: 10.6k]
  ------------------
  112|    279|		break;
  113|  10.6k|	    ch -= '0';
  114|  10.6k|	    if (result > lastval || (result == lastval && ch > remainder)) {
  ------------------
  |  Branch (114:10): [True: 103, False: 10.5k]
  |  Branch (114:31): [True: 16, False: 10.4k]
  |  Branch (114:52): [True: 4, False: 12]
  ------------------
  115|       |		/* Skip remaining digits. */
  116|  1.07M|		do {
  117|  1.07M|		    ch = *cp++;
  118|  1.07M|		} while (isdigit((unsigned char)ch));
  ------------------
  |  Branch (118:12): [True: 1.07M, False: 107]
  ------------------
  119|    107|		errval = STN_TOOBIG;
  120|    107|		break;
  121|  10.5k|	    } else {
  122|  10.5k|		result *= 10;
  123|  10.5k|		result += ch;
  124|  10.5k|		errval = STN_VALID;
  125|  10.5k|	    }
  126|  10.6k|	}
  127|    386|	if (result < minval)
  ------------------
  |  Branch (127:6): [True: 7, False: 379]
  ------------------
  128|      7|	    errval = STN_TOOSMALL;
  129|    386|    }
  130|       |
  131|    440|done:
  132|    440|    switch (errval) {
  ------------------
  |  Branch (132:13): [True: 440, False: 0]
  ------------------
  133|     17|    case STN_INITIAL:
  ------------------
  |  Branch (133:5): [True: 17, False: 423]
  ------------------
  134|    293|    case STN_VALID:
  ------------------
  |  Branch (134:5): [True: 276, False: 164]
  ------------------
  135|    293|	if (errstrp != NULL)
  ------------------
  |  Branch (135:6): [True: 293, False: 0]
  ------------------
  136|    293|	    *errstrp = NULL;
  137|    293|	break;
  138|      0|    case STN_INVALID:
  ------------------
  |  Branch (138:5): [True: 0, False: 440]
  ------------------
  139|      0|	result = 0;
  140|      0|	errno = EINVAL;
  141|      0|	if (errstrp != NULL)
  ------------------
  |  Branch (141:6): [True: 0, False: 0]
  ------------------
  142|      0|	    *errstrp = N_("invalid value");
  ------------------
  |  |   58|      0|# define N_(String) gettext_noop(String)
  |  |  ------------------
  |  |  |  |   57|      0|# define gettext_noop(String) String
  |  |  ------------------
  ------------------
  143|      0|	break;
  144|     40|    case STN_TOOSMALL:
  ------------------
  |  Branch (144:5): [True: 40, False: 400]
  ------------------
  145|     40|	result = 0;
  146|     40|	errno = ERANGE;
  147|     40|	if (errstrp != NULL)
  ------------------
  |  Branch (147:6): [True: 40, False: 0]
  ------------------
  148|     40|	    *errstrp = N_("value too small");
  ------------------
  |  |   58|     40|# define N_(String) gettext_noop(String)
  |  |  ------------------
  |  |  |  |   57|     40|# define gettext_noop(String) String
  |  |  ------------------
  ------------------
  149|     40|	break;
  150|    107|    case STN_TOOBIG:
  ------------------
  |  Branch (150:5): [True: 107, False: 333]
  ------------------
  151|    107|	result = 0;
  152|    107|	errno = ERANGE;
  153|    107|	if (errstrp != NULL)
  ------------------
  |  Branch (153:6): [True: 107, False: 0]
  ------------------
  154|    107|	    *errstrp = N_("value too large");
  ------------------
  |  |   58|    107|# define N_(String) gettext_noop(String)
  |  |  ------------------
  |  |  |  |   57|    107|# define gettext_noop(String) String
  |  |  ------------------
  ------------------
  155|    107|	break;
  156|    440|    }
  157|    440|    if (endp != NULL) {
  ------------------
  |  Branch (157:9): [True: 440, False: 0]
  ------------------
  158|    440|	if (errval == STN_INITIAL || errval == STN_INVALID)
  ------------------
  |  Branch (158:6): [True: 17, False: 423]
  |  Branch (158:31): [True: 0, False: 423]
  ------------------
  159|     17|	    *endp = (char *)str;
  160|    423|	else
  161|    423|	    *endp = (char *)(cp - 1);
  162|    440|    }
  163|    440|    return result;
  164|    440|}
sudo_strtonum:
  172|    440|{
  173|    440|    const char *errstr;
  174|    440|    char *ep;
  175|    440|    long long ret;
  176|       |
  177|    440|    ret = sudo_strtonumx(str, minval, maxval, &ep, &errstr);
  178|       |    /* Check for empty string and terminating NUL. */
  179|    440|    if (str == ep || *ep != '\0') {
  ------------------
  |  Branch (179:9): [True: 21, False: 419]
  |  Branch (179:22): [True: 10, False: 409]
  ------------------
  180|     31|	errno = EINVAL;
  181|     31|	errstr = N_("invalid value");
  ------------------
  |  |   58|     31|# define N_(String) gettext_noop(String)
  |  |  ------------------
  |  |  |  |   57|     31|# define gettext_noop(String) String
  |  |  ------------------
  ------------------
  182|     31|	ret = 0;
  183|     31|    }
  184|    440|    if (errstrp != NULL)
  ------------------
  |  Branch (184:9): [True: 440, False: 0]
  ------------------
  185|    440|	*errstrp = errstr;
  186|    440|    return ret;
  187|    440|}

sudo_debug_printf2_v1:
 1149|     63|{
 1150|     63|}

