Files

30 lines
880 B
Go
Raw Permalink Normal View History

// Copyright (c) 2026 Petr Balvín <opensource@petrbalvin.org> (https://petrbalvin.org)
// SPDX-License-Identifier: MIT
package krb5
import (
"testing"
)
// FuzzAcceptInit feeds arbitrary context establishment tokens through
// the acceptor: no input may panic the DER walk or the crypto, and a
// forged token must fail closed.
func FuzzAcceptInit(f *testing.F) {
key := make([]byte, 32)
_, token, err := ClientInit(EtypeAES256, key, "EXAMPLE.ORG", "nfs", "probe")
if err != nil {
f.Fatal(err)
}
f.Add(token)
f.Add([]byte{0x6e, 0x00})
f.Add([]byte{0x6e, 0x20, 0x30, 0x1d, 0x02})
f.Add(make([]byte, 32))
f.Fuzz(func(t *testing.T, data []byte) {
// The property under test is that the acceptor never panics;
// anything but a genuine token is an error.
_, _, _ = AcceptInit(data, key)
_ = (&Context{Etype: EtypeAES256, Key: key}).ClientAcceptRep(data)
})
}