test: fuzz bounded protocol parsers

This commit is contained in:
2026-09-11 08:21:24 +00:00
parent 418681d38e
commit f6f900e597
6 changed files with 132 additions and 14 deletions
+12
View File
@@ -15,6 +15,18 @@ Run focused unit tests with:
scripts/test-unit --package ./internal/domain --run UUIDv7 --race
```
Run one bounded hostile-input fuzz target in the same pinned container with:
```sh
scripts/test-fuzz --package ./internal/agentproto --name FuzzDecodeEnvelopeBounded_SEC_PROTO_01 --time 30s
scripts/test-fuzz --package ./internal/server/control --name FuzzDecodeJSONRPCRequestBounded_SEC_CTL_01 --time 30s
```
The fuzz command disables ordinary tests for that invocation and runs exactly
one target. A crash stores Go's minimized reproducer in the affected package's
fuzz corpus, so the normal test gate exercises it as a deterministic seed
after it is reviewed and committed.
Build all supported binaries without installing `make` or Go on the host:
```sh