srdusr
aboutsummaryrefslogtreecommitdiffstats
path: root/fuzz/fuzz_tls.cpp
blob: 7860426635f4a2b1f9ec078edd6991f16c476fba (plain) (blame)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
#include <cstddef>
#include <cstdint>

#include "wireframe/l7/tls.hpp"

// The nested TLV walk (record -> handshake -> extensions -> SNI, each
// level bounds-checked against attacker-influenced length fields) is
// the most structurally complex hand-rolled parser in the project so
// far - exactly the kind of code most likely to have an off-by-one or
// an unchecked length feeding a read past the buffer.
extern "C" int LLVMFuzzerTestOneInput(const uint8_t* data, size_t size) {
    wireframe::net::parse_tls_client_hello({data, size});

    wireframe::net::TlsSniDissector dissector;
    dissector.summarize({data, size});
    return 0;
}