fix(verify): arm64 stack save, adaptive canary and host gating

Assisted-by: GLM 5.3
This commit is contained in:
2026-09-19 23:49:19 +02:00
parent 87b1081c53
commit 375182ef1f
25 changed files with 651 additions and 57 deletions
+71 -4
View File
@@ -90,6 +90,16 @@ func TestParamsSize(t *testing.T) {
if got := paramsSize(sig); got != 32 {
t.Errorf("paramsSize = %d, want 32 (24 for slice + 8 for int)", got)
}
// ABI0 strings are ptr+len (16), complex64 packs two float32s (8),
// complex128 two float64s (16).
sig = funcSig{
name: "hdr",
params: []param{{name: "s", typ: "string"}, {name: "c64", typ: "complex64"}, {name: "c128", typ: "complex128"}},
}
if got := paramsSize(sig); got != 40 {
t.Errorf("paramsSize = %d, want 40 (16 string + 8 complex64 + 16 complex128)", got)
}
}
func TestBlockCount(t *testing.T) {
@@ -103,11 +113,34 @@ func TestBlockCount(t *testing.T) {
}
}
// TestNewRNGDeterministic pins the reproducibility contract of the fuzz
// seeds: the same seed must rebuild the same PCG stream, including the
// sub-word tail of fillRandom.
func TestNewRNGDeterministic(t *testing.T) {
draw := func() []byte {
rng := newRNG(7)
out := make([]byte, 20) // 8+8+4: exercises a full word and a tail
fillRandom(rng, out)
return out
}
a, b := draw(), draw()
for i := range a {
if a[i] != b[i] {
t.Fatalf("seed 7 produced different bytes at %d: %02x vs %02x", i, a[i], b[i])
}
}
if newRNG(0) == nil {
t.Fatal("newRNG(0) must build a generator")
}
}
func TestFillBuffer(t *testing.T) {
t.Run("zero", func(t *testing.T) {
// fillBuffer("zero") is a no-op; relies on make already zeroing.
buf := make([]byte, 16)
fillBuffer(buf, "zero")
if err := fillBuffer(buf, "zero"); err != nil {
t.Fatalf("fillBuffer(zero): %v", err)
}
for _, b := range buf {
if b != 0 {
t.Error("zero pattern: make should produce zeroed buffer")
@@ -117,7 +150,9 @@ func TestFillBuffer(t *testing.T) {
})
t.Run("ones", func(t *testing.T) {
buf := make([]byte, 16)
fillBuffer(buf, "ones")
if err := fillBuffer(buf, "ones"); err != nil {
t.Fatalf("fillBuffer(ones): %v", err)
}
for _, b := range buf {
if b != 0xFF {
t.Error("ones pattern should fill with 0xFF")
@@ -127,7 +162,9 @@ func TestFillBuffer(t *testing.T) {
})
t.Run("seq", func(t *testing.T) {
buf := make([]byte, 256)
fillBuffer(buf, "seq")
if err := fillBuffer(buf, "seq"); err != nil {
t.Fatalf("fillBuffer(seq): %v", err)
}
for i, b := range buf {
if b != byte(i) {
t.Errorf("seq[%d] = %d, want %d", i, b, i)
@@ -137,7 +174,9 @@ func TestFillBuffer(t *testing.T) {
})
t.Run("hex", func(t *testing.T) {
buf := make([]byte, 6)
fillBuffer(buf, "deadbeef")
if err := fillBuffer(buf, "deadbeef"); err != nil {
t.Fatalf("fillBuffer(deadbeef): %v", err)
}
want := []byte{0xDE, 0xAD, 0xBE, 0xEF, 0xDE, 0xAD}
for i, b := range buf {
if b != want[i] {
@@ -146,6 +185,34 @@ func TestFillBuffer(t *testing.T) {
}
}
})
t.Run("unknown-pattern", func(t *testing.T) {
buf := make([]byte, 8)
if err := fillBuffer(buf, "wibble"); err == nil {
t.Error("fillBuffer(wibble): expected an error for an unknown pattern name")
}
})
t.Run("bad-hex", func(t *testing.T) {
buf := make([]byte, 8)
if err := fillBuffer(buf, "zz"); err == nil {
t.Error("fillBuffer(zz): expected an error for undecodable hex")
}
})
t.Run("empty-hex", func(t *testing.T) {
buf := make([]byte, 8)
if err := fillBuffer(buf, ""); err == nil {
t.Error("fillBuffer(\"\"): expected an error for an empty pattern")
}
})
}
// TestBufPoolAllocBadPattern checks that Alloc surfaces fill errors under
// the buffer's name, so hand-built specs fail as loudly as parsed ones.
func TestBufPoolAllocBadPattern(t *testing.T) {
var pool BufPool
defer pool.Close()
if err := pool.Alloc([]BufSpec{{Name: "dst", Size: 16, Pattern: "nope"}}); err == nil {
t.Fatal("Alloc with an unknown pattern must fail")
}
}
func TestFuzzFuncChecked(t *testing.T) {