#include #include #include "wireframe/net/ipv6.hpp" extern "C" int LLVMFuzzerTestOneInput(const uint8_t* data, size_t size) { auto packet = wireframe::net::parse_ipv6({data, size}); if (packet) { // Also exercise the RFC 5952 address formatter - it does its // own byte manipulation (zero-run detection) independent of // parse_ipv6, worth fuzzing on whatever bytes made it through. wireframe::net::ipv6_to_string(packet->header.src); wireframe::net::ipv6_to_string(packet->header.dst); // Extension-header walking: a loop that repeatedly trusts an // attacker-controlled length field to advance through the // buffer, over up to 8 iterations - exactly the shape of bug // most worth fuzzing. header.next_header seeds which branch of // the walker runs first; the walker's own logic picks whatever // comes after based on each header's own next_header byte. wireframe::net::walk_ipv6_extension_headers(packet->header.next_header, packet->payload); } return 0; }