Test / test (push) Successful in 2m4s
Release / gates (push) Successful in 2m5s
Release / build (amd64, freebsd) (push) Successful in 1m27s
Release / build (amd64, linux) (push) Successful in 1m22s
Release / build (amd64, netbsd) (push) Successful in 1m19s
Release / build (amd64, openbsd) (push) Successful in 1m20s
Release / build (arm64, darwin) (push) Successful in 1m21s
Release / build (arm64, freebsd) (push) Successful in 1m26s
Release / build (arm64, linux) (push) Successful in 1m25s
Release / build (arm64, netbsd) (push) Successful in 1m31s
Release / build (arm64, openbsd) (push) Successful in 1m27s
Release / build (loong64, linux) (push) Successful in 1m37s
Release / build (riscv64, linux) (push) Successful in 1m21s
Release / release (push) Successful in 40s
Assisted-by: GLM 5.3 Flash
30 lines
880 B
Go
30 lines
880 B
Go
// Copyright (c) 2026 Petr Balvín <opensource@petrbalvin.org> (https://petrbalvin.org)
|
|
// SPDX-License-Identifier: MIT
|
|
|
|
package krb5
|
|
|
|
import (
|
|
"testing"
|
|
)
|
|
|
|
// FuzzAcceptInit feeds arbitrary context establishment tokens through
|
|
// the acceptor: no input may panic the DER walk or the crypto, and a
|
|
// forged token must fail closed.
|
|
func FuzzAcceptInit(f *testing.F) {
|
|
key := make([]byte, 32)
|
|
_, token, err := ClientInit(EtypeAES256, key, "EXAMPLE.ORG", "nfs", "probe")
|
|
if err != nil {
|
|
f.Fatal(err)
|
|
}
|
|
f.Add(token)
|
|
f.Add([]byte{0x6e, 0x00})
|
|
f.Add([]byte{0x6e, 0x20, 0x30, 0x1d, 0x02})
|
|
f.Add(make([]byte, 32))
|
|
f.Fuzz(func(t *testing.T, data []byte) {
|
|
// The property under test is that the acceptor never panics;
|
|
// anything but a genuine token is an error.
|
|
_, _, _ = AcceptInit(data, key)
|
|
_ = (&Context{Etype: EtypeAES256, Key: key}).ClientAcceptRep(data)
|
|
})
|
|
}
|