decode.rs
| 1 | //! Fuzzes the decoder against arbitrary datagrams — the exact input an open UDP |
| 2 | //! port receives from the internet. |
| 3 | //! |
| 4 | //! ```sh |
| 5 | //! cargo +nightly fuzz run decode |
| 6 | //! ``` |
| 7 | //! |
| 8 | //! Note the deliberate limitation: without the key, almost nothing here gets |
| 9 | //! past the AEAD, so this target mostly exercises `Header::peek` and the |
| 10 | //! ChaCha20-Poly1305 layer. The payload decoders — where the interesting |
| 11 | //! structural parsing lives — are reached by the `decode_payload` target |
| 12 | //! instead. Fuzzing only this one would give a comforting but nearly meaningless |
| 13 | //! coverage number. |
| 14 | |
| 15 | #![no_main] |
| 16 | |
| 17 | use libfuzzer_sys::fuzz_target; |
| 18 | |
| 19 | /// Fixed key: a fuzzer cannot forge a tag either way, so varying it would only |
| 20 | /// waste the corpus. |
| 21 | const KEY: [u8; 32] = [0x11; 32]; |
| 22 | |
| 23 | fuzz_target!(|data: &[u8]| { |
| 24 | let _ = otproto::Header::peek(data); |
| 25 | let _ = otproto::open_message(&KEY, data); |
| 26 | }); |
| 27 |