internal/gitd/fuzz_test.go
24 lines · 662 bytes
1 symbol in this file
1package gitd
2
3import (
4 "bytes"
5 "testing"
6)
7
8// FuzzReadPktLine hammers the only parser in the anonymous git:// path
9// with attacker-controlled bytes: it must never panic and never return a
10// line longer than the pkt-line format allows.
11func FuzzReadPktLine(f *testing.F) {
12 f.Add([]byte("003egit-upload-pack /a/b\x00host=example.com\x00"))
13 f.Add([]byte("0000"))
14 f.Add([]byte("0004"))
15 f.Add([]byte("ffff" + "x"))
16 f.Add([]byte("00zz"))
17 f.Add([]byte(""))
18 f.Fuzz(func(t *testing.T, data []byte) {
19 line, err := readPktLine(bytes.NewReader(data))
20 if err == nil && len(line) > 65516 {
21 t.Fatalf("line longer than pkt-line max: %d", len(line))
22 }
23 })
24}