srdusr
aboutsummaryrefslogtreecommitdiffstats
path: root/fuzz/fuzz_tls.cpp
diff options
context:
space:
mode:
Diffstat (limited to 'fuzz/fuzz_tls.cpp')
-rw-r--r--fuzz/fuzz_tls.cpp17
1 files changed, 17 insertions, 0 deletions
diff --git a/fuzz/fuzz_tls.cpp b/fuzz/fuzz_tls.cpp
new file mode 100644
index 0000000..7860426
--- /dev/null
+++ b/fuzz/fuzz_tls.cpp
@@ -0,0 +1,17 @@
+#include <cstddef>
+#include <cstdint>
+
+#include "wireframe/l7/tls.hpp"
+
+// The nested TLV walk (record -> handshake -> extensions -> SNI, each
+// level bounds-checked against attacker-influenced length fields) is
+// the most structurally complex hand-rolled parser in the project so
+// far - exactly the kind of code most likely to have an off-by-one or
+// an unchecked length feeding a read past the buffer.
+extern "C" int LLVMFuzzerTestOneInput(const uint8_t* data, size_t size) {
+ wireframe::net::parse_tls_client_hello({data, size});
+
+ wireframe::net::TlsSniDissector dissector;
+ dissector.summarize({data, size});
+ return 0;
+}