test: cover cursor decoding and script integrity metrics

This commit is contained in:
2026-09-11 09:39:33 +00:00
parent 0e18af02bb
commit c5e9bc8b35
6 changed files with 39 additions and 5 deletions
+21
View File
@@ -72,3 +72,24 @@ func TestCursorInputBounds_BH_CTL_01(t *testing.T) {
}
}
}
// FuzzDecodeCursorBounded_SEC_CTL_02 exercises the token boundary shared by
// every cursor-resumable control read. Decode must reject malformed or forged
// input without panicking or allocating past its documented token ceiling.
func FuzzDecodeCursorBounded_SEC_CTL_02(f *testing.F) {
codec, err := NewCursorCodec(bytes.Repeat([]byte{0x42}, 32))
if err != nil {
f.Fatal(err)
}
filters := HashCursorFilters([]byte("client=host-1\x00streams=stdout"))
valid, err := codec.Encode(Cursor{Kind: CursorKindOutput, FilterHash: filters, Position: []byte("event/offset"), SnapshotBoundary: []byte("upper-event")})
if err != nil {
f.Fatal(err)
}
for _, seed := range []string{"", "***", valid, strings.Repeat("a", 4096)} {
f.Add(seed)
}
f.Fuzz(func(t *testing.T, token string) {
_, _ = codec.Decode(token, CursorKindOutput, filters)
})
}