Target 5 (§3): compile an attacker schema (10-lane menu incl. raw JSON bytes lane) in both modes, then hammer the hostile buffer through validate_bytes, an independent materialize_packed/materialize_aligned, read_field over every offset-map leaf, junk field paths, and the packed sequential walk under the spin bound. Invariants coded (per §3 target 5): mode agreement (aligned Ok ⇒ packed Ok; packed-Ok/aligned-Err only for the documented ADR-006/ADR-008/ offset-indirect rejections), the materialize⇄validate_bytes verdict lattice with verbatim error propagation, unknown-path echo, serde round-trip of materialized output, non-finite-float Access pinning, out-of-range enum Validation pinning, and the record-count spin bound. 44 committed seeds (menu/raw lanes × valid/valid, hostile-schema/ valid-bytes, valid-schema/hostile-bytes incl. a per-prefix truncation sweep, NaN/Inf, enum 99, spin fixtures, mode-agreement pins), hand- encoded against the pinned arbitrary 1.4.2 derive layout and pinned by decode tests. The aligned maxLength-reservation offset pin (s@8..72, tail@72, total 76) caught a fixture assumption error pre-commit. Verification: corpus replay 29/29 green (44 new seeds decode+replay), main crate 570 tests pass, clippy -D warnings clean (crate + shared), wasm clean, cargo fuzz build clean. Hand-run drives (indirect pair escape, enum-Validation, unknown discriminator, trailing garbage) all held.
52 lines
785 B
TOML
52 lines
785 B
TOML
[package]
|
|
name = "alktype-fuzz"
|
|
version = "0.0.0"
|
|
publish = false
|
|
edition = "2021"
|
|
|
|
[package.metadata]
|
|
cargo-fuzz = true
|
|
|
|
[dependencies]
|
|
libfuzzer-sys = "0.4"
|
|
alktype-fuzz-shared = { path = "shared" }
|
|
|
|
[dependencies.alktype]
|
|
path = ".."
|
|
|
|
[[bin]]
|
|
name = "bast_compile"
|
|
path = "fuzz_targets/bast_compile.rs"
|
|
test = false
|
|
doc = false
|
|
bench = false
|
|
|
|
[[bin]]
|
|
name = "data_access"
|
|
path = "fuzz_targets/data_access.rs"
|
|
test = false
|
|
doc = false
|
|
bench = false
|
|
|
|
[[bin]]
|
|
name = "read_opseq"
|
|
path = "fuzz_targets/read_opseq.rs"
|
|
test = false
|
|
doc = false
|
|
bench = false
|
|
|
|
[[bin]]
|
|
name = "layout_build"
|
|
path = "fuzz_targets/layout_build.rs"
|
|
test = false
|
|
doc = false
|
|
bench = false
|
|
|
|
[[bin]]
|
|
name = "validate_pair"
|
|
path = "fuzz_targets/validate_pair.rs"
|
|
test = false
|
|
doc = false
|
|
bench = false
|
|
|
|
[workspace] |