crypton-2.1.3: cbits/tests/fuzz/fuzz.h
/* Feeding generated bytes to the code that parses what comes off the wire.
*
* Each harness is an LLVMFuzzerTestOneInput, so a real fuzzer drives it.
* Where there is no fuzzer -- Apple's clang ships no libFuzzer runtime --
* standalone.c supplies a main that replays the committed corpus and then a
* deterministic stream of its own, which says the harness is wired up
* correctly and nothing about coverage.
*
* What is being looked for is memory safety, not wrong answers: these inputs
* are meant to be rejected, and the question is how they are rejected.
*/
#ifndef CRYPTON_TESTS_FUZZ_H
#define CRYPTON_TESTS_FUZZ_H
#include <stdint.h>
#include <stddef.h>
#include <string.h>
int LLVMFuzzerTestOneInput(const uint8_t *data, size_t size);
/* Carve a fixed-width field out of the input. Short input means the harness
* returns rather than reading past the end, which is the harness's own bug to
* avoid and not the library's to report. */
static int fz_take(const uint8_t **p, size_t *left, void *out, size_t n)
{
if (*left < n)
return 0;
memcpy(out, *p, n);
*p += n;
*left -= n;
return 1;
}
#endif