test: property-based fuzzing (proptest) for every untrusted-input parser — message line, PROXY header, WebSocket frame, regex engine, ban-mask, duration; asserts no-panic + round-trip/idempotence/bounds invariants
This commit is contained in:
parent
cf2b157842
commit
621f06448d
7 changed files with 85 additions and 0 deletions
|
|
@ -640,6 +640,18 @@ fn header(head: &str, name: &str) -> Option<String> {
|
|||
#[cfg(test)]
|
||||
mod tests {
|
||||
use super::*;
|
||||
use proptest::prelude::*;
|
||||
|
||||
proptest! {
|
||||
// Fuzz the WebSocket frame parser: arbitrary bytes must not panic, and a
|
||||
// decoded frame must never report consuming past the buffer.
|
||||
#[test]
|
||||
fn ws_parse_frame_never_panics_and_bounds(buf in prop::collection::vec(any::<u8>(), 0..600)) {
|
||||
if let Ok(Some((_f, n))) = parse_frame(&buf) {
|
||||
prop_assert!(n <= buf.len());
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn accept_key_matches_rfc_example() {
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue