Fuzz introspector
For issues and ideas: https://github.com/ossf/fuzz-introspector/issues

Project functions overview

The following table shows data about each function in the project. The functions included in this table correspond to all functions that exist in the executables of the fuzzers. As such, there may be functions that are from third-party libraries.

For further technical details on the meaning of columns in the below table, please see the Glossary .

Func name Functions filename Args Function call depth Reached by Fuzzers Runtime reached by Fuzzers Combined reached by Fuzzers Fuzzers runtime hit Func lines hit % I Count BB Count Cyclomatic complexity Functions reached Reached by functions Accumulated cyclomatic complexity Undiscovered complexity

Fuzzer details

Fuzzer: zxc_fuzzer_pstream

Call tree

The calltree shows the control flow of the fuzzer. This is overlaid with coverage information to display how much of the potential code a fuzzer can reach is in fact covered at runtime. In the following there is a link to a detailed calltree visualisation as well as a bitmap showing a high-level view of the calltree. For further information about these topics please see the glossary for full calltree and calltree overview

Call tree overview bitmap:

The distribution of callsites in terms of coloring is
Color Runtime hitcount Callsite count Percentage
red 0 39 31.2%
gold [1:9] 0 0.0%
yellow [10:29] 2 1.6%
greenyellow [30:49] 0 0.0%
lawngreen 50+ 84 67.2%
All colors 125 100

Fuzz blockers

The following nodes represent call sites where fuzz blockers occur.

Amount of callsites blocked Calltree index Parent function Callsite Largest blocked function
9 40 zxc_compress_block_at call site: 00040 zxc_cctx_attach_dict_huf
3 57 LLVMFuzzerTestOneInput call site: 00057 cs_stage_file_header
3 109 ds_drain_decoded call site: 00109 ds_pull
3 113 zxc_dstream_decompress call site: 00113 zxc_dstream_free
2 14 zxc_cctx_init_in_workspace call site: 00014 zxc_free_cctx
2 18 zxc_cctx_free call site: 00018 zxc_free_cctx
2 24 LLVMFuzzerTestOneInput call site: 00024 zxc_cstream_free
2 37 zxc_compress_block_at call site: 00037 zxc_cctx_init
2 54 zxc_cstream_compress call site: 00054 zxc_cstream_free
2 102 ds_handle_need_block_header call site: 00102 realloc
1 9 zxc_cctx_init call site: 00009 zxc_dctx_entropy_sizes
1 21 LLVMFuzzerTestOneInput call site: 00021 zxc_cstream_free

Runtime coverage analysis

Covered functions
100
Functions that are reachable but not covered
13
Reachable functions
56
Percentage of reachable functions covered
76.79%
NB: The sum of covered functions and functions that are reachable but not covered need not be equal to Reachable functions . This is because the reachability analysis is an approximation and thus at runtime some functions may be covered that are not included in the reachability analysis. This is a limitation of our static analysis capabilities.
Warning: The number of covered functions are larger than the number of reachable functions. This means that there are more functions covered at runtime than are extracted using static analysis. This is likely a result of the static analysis component failing to extract the right call graph or the coverage runtime being compiled with sanitizers in code that the static analysis has not analysed. This can happen if lto/gold is not used in all places that coverage instrumentation is used.
Function name source code lines source lines hit percentage hit

Files reached

filename functions hit
tests/fuzz_pstream.c 3
src/lib/zxc_pstream.c 21
src/lib/zxc_internal.h 1
src/lib/zxc_dispatch.c 6
src/lib/zxc_common.c 13
src/lib/zxc_deps.h 2
src/lib/zxc_huffman.c 5

Fuzzer: zxc_fuzzer_decompress

Call tree

The calltree shows the control flow of the fuzzer. This is overlaid with coverage information to display how much of the potential code a fuzzer can reach is in fact covered at runtime. In the following there is a link to a detailed calltree visualisation as well as a bitmap showing a high-level view of the calltree. For further information about these topics please see the glossary for full calltree and calltree overview

Call tree overview bitmap:

The distribution of callsites in terms of coloring is
Color Runtime hitcount Callsite count Percentage
red 0 14 31.1%
gold [1:9] 2 4.44%
yellow [10:29] 1 2.22%
greenyellow [30:49] 2 4.44%
lawngreen 50+ 26 57.7%
All colors 45 100

Fuzz blockers

The following nodes represent call sites where fuzz blockers occur.

Amount of callsites blocked Calltree index Parent function Callsite Largest blocked function
3 5 zxc_decompress call site: 00005 zxc_decompress_frame
3 31 zxc_decompress_frame call site: 00031 zxc_huf_dict_tree_build
3 35 zxc_pivco_tree_build call site: 00035 zxc_cctx_free
1 9 zxc_decompress_frame call site: 00009 zxc_dict_id
1 18 zxc_decompress_frame call site: 00018 zxc_read_block_header
1 20 zxc_decompress_frame call site: 00020 zxc_cctx_free
1 24 zxc_cctx_init call site: 00024 zxc_dctx_entropy_sizes
1 29 zxc_cctx_init_in_workspace call site: 00029 zxc_aligned_free

Runtime coverage analysis

Covered functions
71
Functions that are reachable but not covered
6
Reachable functions
25
Percentage of reachable functions covered
76.0%
NB: The sum of covered functions and functions that are reachable but not covered need not be equal to Reachable functions . This is because the reachability analysis is an approximation and thus at runtime some functions may be covered that are not included in the reachability analysis. This is a limitation of our static analysis capabilities.
Warning: The number of covered functions are larger than the number of reachable functions. This means that there are more functions covered at runtime than are extracted using static analysis. This is likely a result of the static analysis component failing to extract the right call graph or the coverage runtime being compiled with sanitizers in code that the static analysis has not analysed. This can happen if lto/gold is not used in all places that coverage instrumentation is used.
Function name source code lines source lines hit percentage hit

Files reached

filename functions hit
tests/fuzz_decompress.c 1
src/lib/zxc_dispatch.c 7
src/lib/zxc_common.c 8
src/lib/zxc_dict.c 1
src/lib/zxc_deps.h 2
src/lib/zxc_huffman.c 5

Fuzzer: zxc_fuzzer_seekable

Call tree

The calltree shows the control flow of the fuzzer. This is overlaid with coverage information to display how much of the potential code a fuzzer can reach is in fact covered at runtime. In the following there is a link to a detailed calltree visualisation as well as a bitmap showing a high-level view of the calltree. For further information about these topics please see the glossary for full calltree and calltree overview

Call tree overview bitmap:

The distribution of callsites in terms of coloring is
Color Runtime hitcount Callsite count Percentage
red 0 29 21.9%
gold [1:9] 0 0.0%
yellow [10:29] 0 0.0%
greenyellow [30:49] 0 0.0%
lawngreen 50+ 103 78.0%
All colors 132 100

Fuzz blockers

The following nodes represent call sites where fuzz blockers occur.

Amount of callsites blocked Calltree index Parent function Callsite Largest blocked function
6 20 zxc_compress call site: 00020 zxc_huf_dict_tree_build
4 5 zxc_compress call site: 00005 zxc_write_empty_frame
4 29 zxc_compress call site: 00029 zxc_cctx_free
4 102 zxc_seek_mt_worker call site: 00102 zxc_cctx_free
3 128 LLVMFuzzerTestOneInput call site: 00128 zxc_seekable_decompress_range
1 10 zxc_seek_table_header call site: 00010 zxc_write_file_footer
1 13 zxc_cctx_init call site: 00013 zxc_dctx_entropy_sizes
1 18 zxc_cctx_init_in_workspace call site: 00018 zxc_aligned_free
1 27 zxc_cctx_free call site: 00027 zxc_aligned_free
1 34 zxc_compress call site: 00034 zxc_cctx_free
1 67 LLVMFuzzerTestOneInput call site: 00067 zxc_seekable_free
1 76 zxc_seekable_decompress_range call site: 00076 zxc_cctx_free

Runtime coverage analysis

Covered functions
117
Functions that are reachable but not covered
21
Reachable functions
61
Percentage of reachable functions covered
65.57%
NB: The sum of covered functions and functions that are reachable but not covered need not be equal to Reachable functions . This is because the reachability analysis is an approximation and thus at runtime some functions may be covered that are not included in the reachability analysis. This is a limitation of our static analysis capabilities.
Warning: The number of covered functions are larger than the number of reachable functions. This means that there are more functions covered at runtime than are extracted using static analysis. This is likely a result of the static analysis component failing to extract the right call graph or the coverage runtime being compiled with sanitizers in code that the static analysis has not analysed. This can happen if lto/gold is not used in all places that coverage instrumentation is used.
Function name source code lines source lines hit percentage hit

Files reached

filename functions hit
tests/fuzz_seekable.c 1
src/lib/zxc_common.c 16
src/lib/zxc_dispatch.c 4
src/lib/zxc_internal.h 1
src/lib/zxc_dict.c 1
src/lib/zxc_deps.h 2
src/lib/zxc_huffman.c 5
src/lib/zxc_seekable.c 19

Fuzzer: zxc_fuzzer_roundtrip

Call tree

The calltree shows the control flow of the fuzzer. This is overlaid with coverage information to display how much of the potential code a fuzzer can reach is in fact covered at runtime. In the following there is a link to a detailed calltree visualisation as well as a bitmap showing a high-level view of the calltree. For further information about these topics please see the glossary for full calltree and calltree overview

Call tree overview bitmap:

The distribution of callsites in terms of coloring is
Color Runtime hitcount Callsite count Percentage
red 0 40 52.6%
gold [1:9] 0 0.0%
yellow [10:29] 0 0.0%
greenyellow [30:49] 0 0.0%
lawngreen 50+ 36 47.3%
All colors 76 100

Fuzz blockers

The following nodes represent call sites where fuzz blockers occur.

Amount of callsites blocked Calltree index Parent function Callsite Largest blocked function
8 54 zxc_decompress_frame call site: 00054 zxc_cctx_free
6 6 zxc_compress call site: 00006 zxc_write_empty_frame
4 30 zxc_compress call site: 00030 zxc_cctx_free
4 38 zxc_compress call site: 00038 zxc_write_seek_table
4 46 zxc_decompress call site: 00046 zxc_decompress_frame
3 21 zxc_compress call site: 00021 zxc_huf_dict_tree_build
2 25 zxc_pivco_tree_build call site: 00025 zxc_cctx_free
2 51 zxc_decompress_frame call site: 00051 zxc_dict_id
2 64 zxc_decompress_frame call site: 00064 zxc_cctx_free
2 68 zxc_decompress_frame call site: 00068 zxc_cctx_free
1 14 zxc_cctx_init call site: 00014 zxc_dctx_entropy_sizes
1 19 zxc_cctx_init_in_workspace call site: 00019 zxc_aligned_free

Runtime coverage analysis

Covered functions
136
Functions that are reachable but not covered
14
Reachable functions
40
Percentage of reachable functions covered
65.0%
NB: The sum of covered functions and functions that are reachable but not covered need not be equal to Reachable functions . This is because the reachability analysis is an approximation and thus at runtime some functions may be covered that are not included in the reachability analysis. This is a limitation of our static analysis capabilities.
Warning: The number of covered functions are larger than the number of reachable functions. This means that there are more functions covered at runtime than are extracted using static analysis. This is likely a result of the static analysis component failing to extract the right call graph or the coverage runtime being compiled with sanitizers in code that the static analysis has not analysed. This can happen if lto/gold is not used in all places that coverage instrumentation is used.
Function name source code lines source lines hit percentage hit

Files reached

filename functions hit
tests/fuzz_roundtrip.c 1
src/lib/zxc_common.c 17
src/lib/zxc_dispatch.c 9
src/lib/zxc_internal.h 1
src/lib/zxc_dict.c 1
src/lib/zxc_deps.h 2
src/lib/zxc_huffman.c 5

Fuzzer: zxc_fuzzer_stream

Call tree

The calltree shows the control flow of the fuzzer. This is overlaid with coverage information to display how much of the potential code a fuzzer can reach is in fact covered at runtime. In the following there is a link to a detailed calltree visualisation as well as a bitmap showing a high-level view of the calltree. For further information about these topics please see the glossary for full calltree and calltree overview

Call tree overview bitmap:

The distribution of callsites in terms of coloring is
Color Runtime hitcount Callsite count Percentage
red 0 39 22.5%
gold [1:9] 0 0.0%
yellow [10:29] 0 0.0%
greenyellow [30:49] 0 0.0%
lawngreen 50+ 134 77.4%
All colors 173 100

Fuzz blockers

The following nodes represent call sites where fuzz blockers occur.

Amount of callsites blocked Calltree index Parent function Callsite Largest blocked function
10 35 zxc_stream_engine_run call site: 00035 zxc_stream_engine_fail
6 94 zxc_async_writer call site: 00094 pthread_mutex_lock
4 63 zxc_cctx_free call site: 00063 pthread_mutex_lock
3 55 zxc_stream_worker call site: 00055 zxc_huf_dict_tree_build
3 101 zxc_async_writer call site: 00101 pthread_mutex_lock
2 59 zxc_pivco_tree_build call site: 00059 zxc_cctx_free
2 78 zxc_stream_worker call site: 00078 pthread_cond_broadcast
2 83 zxc_stream_worker call site: 00083 zxc_stream_engine_fail
1 10 zxc_stream_get_decompressed_size call site: 00010 fseeko64
1 13 zxc_stream_get_decompressed_size call site: 00013 fseeko64
1 16 zxc_stream_get_decompressed_size call site: 00016 fseeko64
1 18 zxc_stream_get_decompressed_size call site: 00018 zxc_stream_decompress

Runtime coverage analysis

Covered functions
167
Functions that are reachable but not covered
28
Reachable functions
65
Percentage of reachable functions covered
56.92%
NB: The sum of covered functions and functions that are reachable but not covered need not be equal to Reachable functions . This is because the reachability analysis is an approximation and thus at runtime some functions may be covered that are not included in the reachability analysis. This is a limitation of our static analysis capabilities.
Warning: The number of covered functions are larger than the number of reachable functions. This means that there are more functions covered at runtime than are extracted using static analysis. This is likely a result of the static analysis component failing to extract the right call graph or the coverage runtime being compiled with sanitizers in code that the static analysis has not analysed. This can happen if lto/gold is not used in all places that coverage instrumentation is used.
Function name source code lines source lines hit percentage hit

Files reached

filename functions hit
tests/fuzz_stream.c 3
src/lib/zxc_common.c 15
src/lib/zxc_driver.c 10
src/lib/zxc_dict.c 1
src/lib/zxc_deps.h 2
src/lib/zxc_huffman.c 5
src/lib/zxc_dispatch.c 2
src/lib/zxc_internal.h 1

Fuzzer: zxc_fuzzer_inplace

Call tree

The calltree shows the control flow of the fuzzer. This is overlaid with coverage information to display how much of the potential code a fuzzer can reach is in fact covered at runtime. In the following there is a link to a detailed calltree visualisation as well as a bitmap showing a high-level view of the calltree. For further information about these topics please see the glossary for full calltree and calltree overview

Call tree overview bitmap:

The distribution of callsites in terms of coloring is
Color Runtime hitcount Callsite count Percentage
red 0 35 36.8%
gold [1:9] 0 0.0%
yellow [10:29] 0 0.0%
greenyellow [30:49] 0 0.0%
lawngreen 50+ 60 63.1%
All colors 95 100

Fuzz blockers

The following nodes represent call sites where fuzz blockers occur.

Amount of callsites blocked Calltree index Parent function Callsite Largest blocked function
5 15 zxc_decompress_frame call site: 00015 zxc_cctx_free
4 49 zxc_compress call site: 00049 zxc_write_empty_frame
4 59 zxc_compress call site: 00059 zxc_cctx_free
4 82 zxc_compress_block_at call site: 00082 zxc_cctx_attach_dict_huf
3 32 zxc_decompress_frame call site: 00032 zxc_huf_dict_tree_build
3 36 zxc_pivco_tree_build call site: 00036 zxc_cctx_free
2 10 zxc_decompress_frame call site: 00010 zxc_dict_id
2 21 zxc_decompress_frame call site: 00021 zxc_cctx_free
2 79 zxc_compress_block_at call site: 00079 zxc_cctx_init
1 25 zxc_cctx_init call site: 00025 zxc_dctx_entropy_sizes
1 30 zxc_cctx_init_in_workspace call site: 00030 zxc_aligned_free
1 42 zxc_decompress_frame call site: 00042 zxc_cctx_free

Runtime coverage analysis

Covered functions
164
Functions that are reachable but not covered
7
Reachable functions
47
Percentage of reachable functions covered
85.11%
NB: The sum of covered functions and functions that are reachable but not covered need not be equal to Reachable functions . This is because the reachability analysis is an approximation and thus at runtime some functions may be covered that are not included in the reachability analysis. This is a limitation of our static analysis capabilities.
Warning: The number of covered functions are larger than the number of reachable functions. This means that there are more functions covered at runtime than are extracted using static analysis. This is likely a result of the static analysis component failing to extract the right call graph or the coverage runtime being compiled with sanitizers in code that the static analysis has not analysed. This can happen if lto/gold is not used in all places that coverage instrumentation is used.
Function name source code lines source lines hit percentage hit

Files reached

filename functions hit
tests/fuzz_inplace.c 2
src/lib/zxc_dispatch.c 15
src/lib/zxc_common.c 17
src/lib/zxc_dict.c 1
src/lib/zxc_deps.h 2
src/lib/zxc_huffman.c 5
src/lib/zxc_internal.h 1

Fuzzer: zxc_fuzzer_dict

Call tree

The calltree shows the control flow of the fuzzer. This is overlaid with coverage information to display how much of the potential code a fuzzer can reach is in fact covered at runtime. In the following there is a link to a detailed calltree visualisation as well as a bitmap showing a high-level view of the calltree. For further information about these topics please see the glossary for full calltree and calltree overview

Call tree overview bitmap:

The distribution of callsites in terms of coloring is
Color Runtime hitcount Callsite count Percentage
red 0 57 29.8%
gold [1:9] 5 2.61%
yellow [10:29] 0 0.0%
greenyellow [30:49] 5 2.61%
lawngreen 50+ 124 64.9%
All colors 191 100

Fuzz blockers

The following nodes represent call sites where fuzz blockers occur.

Amount of callsites blocked Calltree index Parent function Callsite Largest blocked function
8 151 zxc_decompress_frame call site: 00151 zxc_cctx_free
6 2 zxc_dict_load call site: 00002 zxc_dict_id
6 89 zxc_compress call site: 00089 zxc_write_empty_frame
4 112 zxc_compress call site: 00112 zxc_write_seek_table
4 143 zxc_decompress call site: 00143 zxc_decompress_frame
4 163 zxc_decompress_frame call site: 00163 zxc_cctx_free
3 97 zxc_compress call site: 00097 zxc_huf_dict_tree_build
3 104 zxc_compress call site: 00104 zxc_cctx_free
3 129 zxc_compress_cctx call site: 00129 zxc_cctx_attach_dict_huf
2 101 zxc_pivco_tree_build call site: 00101 zxc_cctx_free
2 108 zxc_compress call site: 00108 zxc_cctx_free
2 176 zxc_decompress_dctx call site: 00176 zxc_probe_without_dst

Runtime coverage analysis

Covered functions
163
Functions that are reachable but not covered
15
Reachable functions
71
Percentage of reachable functions covered
78.87%
NB: The sum of covered functions and functions that are reachable but not covered need not be equal to Reachable functions . This is because the reachability analysis is an approximation and thus at runtime some functions may be covered that are not included in the reachability analysis. This is a limitation of our static analysis capabilities.
Warning: The number of covered functions are larger than the number of reachable functions. This means that there are more functions covered at runtime than are extracted using static analysis. This is likely a result of the static analysis component failing to extract the right call graph or the coverage runtime being compiled with sanitizers in code that the static analysis has not analysed. This can happen if lto/gold is not used in all places that coverage instrumentation is used.
Function name source code lines source lines hit percentage hit

Files reached

filename functions hit
tests/fuzz_dict.c 1
src/lib/zxc_dict.c 10
src/lib/zxc_common.c 17
src/lib/zxc_deps.h 2
src/lib/zxc_dispatch.c 17
src/lib/zxc_huffman.c 18
src/lib/zxc_internal.h 1

Fuzz engine guidance

This sections provides heuristics that can be used as input to a fuzz engine when running a given fuzz target. The current focus is on providing input that is usable by libFuzzer.

tests/fuzz_pstream.c

Dictionary

Use this with the libFuzzer -dict=DICT.file flag


Fuzzer function priority

Use one of these functions as input to libfuzzer with flag: -focus_function name

-focus_function=['zxc_compress_block_at', 'LLVMFuzzerTestOneInput', 'ds_drain_decoded', 'zxc_dstream_decompress', 'zxc_cctx_init_in_workspace', 'zxc_cctx_free', 'zxc_cstream_compress', 'ds_handle_need_block_header']

tests/fuzz_decompress.c

Dictionary

Use this with the libFuzzer -dict=DICT.file flag


Fuzzer function priority

Use one of these functions as input to libfuzzer with flag: -focus_function name

-focus_function=['zxc_decompress', 'zxc_decompress_frame', 'zxc_pivco_tree_build', 'zxc_cctx_init', 'zxc_cctx_init_in_workspace']

tests/fuzz_seekable.c

Dictionary

Use this with the libFuzzer -dict=DICT.file flag


Fuzzer function priority

Use one of these functions as input to libfuzzer with flag: -focus_function name

-focus_function=['zxc_compress', 'zxc_seek_mt_worker', 'LLVMFuzzerTestOneInput', 'zxc_seek_table_header', 'zxc_cctx_init', 'zxc_cctx_init_in_workspace', 'zxc_cctx_free']

tests/fuzz_roundtrip.c

Dictionary

Use this with the libFuzzer -dict=DICT.file flag


Fuzzer function priority

Use one of these functions as input to libfuzzer with flag: -focus_function name

-focus_function=['zxc_decompress_frame', 'zxc_compress', 'zxc_decompress', 'zxc_pivco_tree_build']

tests/fuzz_stream.c

Dictionary

Use this with the libFuzzer -dict=DICT.file flag


Fuzzer function priority

Use one of these functions as input to libfuzzer with flag: -focus_function name

-focus_function=['zxc_stream_engine_run', 'zxc_async_writer', 'zxc_cctx_free', 'zxc_stream_worker', 'zxc_pivco_tree_build', 'zxc_stream_get_decompressed_size']

tests/fuzz_inplace.c

Dictionary

Use this with the libFuzzer -dict=DICT.file flag


Fuzzer function priority

Use one of these functions as input to libfuzzer with flag: -focus_function name

-focus_function=['zxc_decompress_frame', 'zxc_compress', 'zxc_compress_block_at', 'zxc_pivco_tree_build', 'zxc_cctx_init']

tests/fuzz_dict.c

Dictionary

Use this with the libFuzzer -dict=DICT.file flag


Fuzzer function priority

Use one of these functions as input to libfuzzer with flag: -focus_function name

-focus_function=['zxc_decompress_frame', 'zxc_dict_load', 'zxc_compress', 'zxc_decompress', 'zxc_compress_cctx', 'zxc_pivco_tree_build']

Files and Directories in report

This section shows which files and directories are considered in this report. The main reason for showing this is fuzz introspector may include more code in the reasoning than is desired. This section helps identify if too many files/directories are included, e.g. third party code, which may be irrelevant for the threat model. In the event too much is included, fuzz introspector supports a configuration file that can exclude data from the report. See the following link for more information on how to create a config file: link

Files in report

Source file Reached by Covered by
[] []
/src/zxc/src/lib/zxc_common.c ['zxc_fuzzer_pstream', 'zxc_fuzzer_decompress', 'zxc_fuzzer_seekable', 'zxc_fuzzer_roundtrip', 'zxc_fuzzer_stream', 'zxc_fuzzer_inplace', 'zxc_fuzzer_dict'] ['zxc_fuzzer_pstream', 'zxc_fuzzer_decompress', 'zxc_fuzzer_seekable', 'zxc_fuzzer_roundtrip', 'zxc_fuzzer_stream', 'zxc_fuzzer_inplace', 'zxc_fuzzer_dict']
/src/zxc/src/lib/zxc_dict.c ['zxc_fuzzer_decompress', 'zxc_fuzzer_seekable', 'zxc_fuzzer_roundtrip', 'zxc_fuzzer_stream', 'zxc_fuzzer_inplace', 'zxc_fuzzer_dict'] ['zxc_fuzzer_stream', 'zxc_fuzzer_dict']
/src/zxc/src/lib/zxc_pstream.c ['zxc_fuzzer_pstream'] ['zxc_fuzzer_pstream']
/src/zxc/tests/fuzz_dict.c ['zxc_fuzzer_dict'] ['zxc_fuzzer_dict']
/src/zxc/tests/fuzz_decompress.c ['zxc_fuzzer_decompress'] ['zxc_fuzzer_decompress']
/src/zxc/tests/fuzz_pstream.c ['zxc_fuzzer_pstream'] ['zxc_fuzzer_pstream']
/src/zxc/src/lib/zxc_deps.h ['zxc_fuzzer_pstream', 'zxc_fuzzer_decompress', 'zxc_fuzzer_seekable', 'zxc_fuzzer_roundtrip', 'zxc_fuzzer_stream', 'zxc_fuzzer_inplace', 'zxc_fuzzer_dict'] ['zxc_fuzzer_pstream', 'zxc_fuzzer_decompress', 'zxc_fuzzer_seekable', 'zxc_fuzzer_roundtrip', 'zxc_fuzzer_stream', 'zxc_fuzzer_inplace', 'zxc_fuzzer_dict']
/src/zxc/src/lib/zxc_seekable.c ['zxc_fuzzer_seekable'] ['zxc_fuzzer_seekable']
/src/zxc/src/lib/zxc_compress.c [] []
/src/zxc/tests/fuzz_stream.c ['zxc_fuzzer_stream'] ['zxc_fuzzer_stream']
/src/zxc/tests/fuzz_seekable.c ['zxc_fuzzer_seekable'] ['zxc_fuzzer_seekable']
/src/zxc/src/lib/zxc_decompress.c [] []
/src/zxc/tests/fuzz_inplace.c ['zxc_fuzzer_inplace'] ['zxc_fuzzer_inplace']
/src/zxc/src/lib/zxc_internal.h ['zxc_fuzzer_pstream', 'zxc_fuzzer_seekable', 'zxc_fuzzer_roundtrip', 'zxc_fuzzer_stream', 'zxc_fuzzer_inplace', 'zxc_fuzzer_dict'] ['zxc_fuzzer_pstream', 'zxc_fuzzer_seekable', 'zxc_fuzzer_roundtrip', 'zxc_fuzzer_stream', 'zxc_fuzzer_inplace', 'zxc_fuzzer_dict']
/src/zxc/src/lib/zxc_driver.c ['zxc_fuzzer_stream'] ['zxc_fuzzer_stream']
/src/zxc/src/lib/zxc_dispatch.c ['zxc_fuzzer_pstream', 'zxc_fuzzer_decompress', 'zxc_fuzzer_seekable', 'zxc_fuzzer_roundtrip', 'zxc_fuzzer_stream', 'zxc_fuzzer_inplace', 'zxc_fuzzer_dict'] ['zxc_fuzzer_pstream', 'zxc_fuzzer_decompress', 'zxc_fuzzer_seekable', 'zxc_fuzzer_roundtrip', 'zxc_fuzzer_stream', 'zxc_fuzzer_inplace', 'zxc_fuzzer_dict']
/src/zxc/src/lib/zxc_huffman.c ['zxc_fuzzer_pstream', 'zxc_fuzzer_decompress', 'zxc_fuzzer_seekable', 'zxc_fuzzer_roundtrip', 'zxc_fuzzer_stream', 'zxc_fuzzer_inplace', 'zxc_fuzzer_dict'] ['zxc_fuzzer_decompress', 'zxc_fuzzer_roundtrip', 'zxc_fuzzer_stream', 'zxc_fuzzer_inplace', 'zxc_fuzzer_dict']
/src/zxc/tests/fuzz_roundtrip.c ['zxc_fuzzer_roundtrip'] ['zxc_fuzzer_roundtrip']

Directories in report

Directory
/src/zxc/src/lib/
/src/zxc/tests/