test: fuzz bounded protocol parsers
This commit is contained in:
@@ -15,6 +15,18 @@ Run focused unit tests with:
|
||||
scripts/test-unit --package ./internal/domain --run UUIDv7 --race
|
||||
```
|
||||
|
||||
Run one bounded hostile-input fuzz target in the same pinned container with:
|
||||
|
||||
```sh
|
||||
scripts/test-fuzz --package ./internal/agentproto --name FuzzDecodeEnvelopeBounded_SEC_PROTO_01 --time 30s
|
||||
scripts/test-fuzz --package ./internal/server/control --name FuzzDecodeJSONRPCRequestBounded_SEC_CTL_01 --time 30s
|
||||
```
|
||||
|
||||
The fuzz command disables ordinary tests for that invocation and runs exactly
|
||||
one target. A crash stores Go's minimized reproducer in the affected package's
|
||||
fuzz corpus, so the normal test gate exercises it as a deterministic seed
|
||||
after it is reviewed and committed.
|
||||
|
||||
Build all supported binaries without installing `make` or Go on the host:
|
||||
|
||||
```sh
|
||||
|
||||
Reference in New Issue
Block a user