fuzz: Make large chunk size more likely

This now detects issues like 3eced32e in about 30 seconds.
This commit is contained in:
Nick Wellnhofer 2025-01-31 19:02:33 +01:00
parent cdfb54ff7b
commit d2fb68ed24

View File

@ -52,7 +52,7 @@ LLVMFuzzerTestOneInput(const char *data, size_t size) {
~XML_PARSE_SAX1;
failurePos = xmlFuzzReadInt(4) % (size + 100);
maxChunkSize = xmlFuzzReadInt(4) % (size + 1);
maxChunkSize = xmlFuzzReadInt(4) % (size + size / 8 + 1);
if (maxChunkSize == 0)
maxChunkSize = 1;