You can not select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.
DateKeys/scripts/fuzz.sh

48 lines
1.6 KiB

#!/usr/bin/env bash
# Runs every parser fuzz target for the given duration each (default 20s).
# FUZZ_PARALLEL limits the number of fuzzing workers; each one keeps a
# 100 MB shared-memory file in the temporary directory.
# FUZZ_MINIMIZE is the time spent minimising each new input (default 0):
# minimisation stalls FuzzInspect for minutes, so short runs skip it; a
# failing input is still saved under testdata/fuzz as found.
set -euo pipefail
duration="${1:-20s}"
parallel=(-fuzzminimizetime="${FUZZ_MINIMIZE:-0}")
if [[ -n "${FUZZ_PARALLEL:-}" ]]; then
parallel+=(-parallel "$FUZZ_PARALLEL")
fi
targets=(
"./codec FuzzDecoder"
"./codec FuzzWalk"
"./codec FuzzPeek"
"./codec FuzzUnmarshal"
"./codec FuzzEncodeImpliesWalk"
"./extension FuzzDecodeArray"
"./profile FuzzDecode"
Release object, release in hand and step 9.c option B (spec v0.15 draft) The release of a round becomes a file, .dkr: a release object in deterministic CBOR, {0: "datekeys-release", 1: 1, 2: chain_hash, 3: round, 4: signature}, which provider.EncodeRelease writes and DecodeRelease reads with its layers (size, type and version, schema). provider.ParseRelease also reads drand's JSON as the input of the caller. Verify checks the chain hash a release names before its round and its signature, with ERR_PROFILE_MISMATCH. provider.Archive reads a local release archive, the informative format of the draft. capsule.OpenOptions.Release takes a release in hand, a provider.Supplier, exclusive with Source: Open does not compare it with the clock (step 9.c, option B) and reports a clock behind it in Opened.ClockBehind; a network source is still never asked before the round time. The CLI gains decrypt -release FILE (.dkr, drand's JSON or a local archive), decrypt -save-release FILE.dkr and the command release, which fetches, verifies and saves the .dkr without opening the capsule. Test data: vectors/release.json, releases/<round>.dkr for rounds 1000, 1001, 1004 and 2000, and a local archive of rounds 1000 to 1004. In mutations.json every case says its source, "supplied" or "network"; the case "round not reached yet", a release in hand, now opens, and four cases are added: the same with a network source, a release of another round from a network source, and two release objects of another chain. SpecVersion stays 0.14 until the author approves the draft. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
1 day ago
"./provider FuzzDecodeRelease"
"./datekey FuzzParse"
"./agewrap FuzzStanzas"
"./accesskey FuzzDecode"
"./capsule FuzzParsePrelude"
"./capsule FuzzDecodeHeader"
"./capsule FuzzDecodeControl"
"./capsule FuzzDecodeHead"
"./capsule FuzzEvaluateSecurity"
"./internal/pathrule FuzzCheckPath"
"./locator FuzzUnmarshal"
"./locator FuzzParseInfo"
"./locator FuzzCheckURI"
"./locator FuzzCheckResolvedIP"
"./internal/der FuzzDERCheck"
"./internal/cms FuzzParseSignature"
"./internal/cms FuzzParseToken"
"./internal/cms FuzzParseCert"
"./capsule FuzzInspect"
"./capsule FuzzEncodeImpliesDecode"
)
for t in "${targets[@]}"; do
read -r pkg name <<<"$t"
echo "== $pkg $name ($duration)"
go test -run='^$' -fuzz="^${name}\$" -fuzztime="$duration" "${parallel[@]}" "$pkg"
done

Powered by TurnKey Linux.