// Copyright (c) 2026 Petr BalvĂ­n (https://petrbalvin.org) // SPDX-License-Identifier: MIT package krb5 import ( "testing" ) // FuzzAcceptInit feeds arbitrary context establishment tokens through // the acceptor: no input may panic the DER walk or the crypto, and a // forged token must fail closed. func FuzzAcceptInit(f *testing.F) { key := make([]byte, 32) _, token, err := ClientInit(EtypeAES256, key, "EXAMPLE.ORG", "nfs", "probe") if err != nil { f.Fatal(err) } f.Add(token) f.Add([]byte{0x6e, 0x00}) f.Add([]byte{0x6e, 0x20, 0x30, 0x1d, 0x02}) f.Add(make([]byte, 32)) f.Fuzz(func(t *testing.T, data []byte) { // The property under test is that the acceptor never panics; // anything but a genuine token is an error. _, _, _ = AcceptInit(data, key) _ = (&Context{Etype: EtypeAES256, Key: key}).ClientAcceptRep(data) }) }