mirror of
https://github.com/outbackdingo/optimclaw.git
synced 2026-08-30 08:17:53 +00:00
- Use std::sync::LazyLock to construct Sanitizer, Validator, and LeakDetector once instead of on every fuzz iteration (they compile regex/Aho-Corasick) - Remove fuzz_config_env assertion that panics on null-byte-only input - Remove no-op length check with misleading comment in fuzz_config_env - Update fuzz_config_env description in README to match actual behavior Co-Authored-By: Claude Opus 4.6 <[email protected]>
45 lines
1.7 KiB
Rust
45 lines
1.7 KiB
Rust
#![no_main]
|
|
use libfuzzer_sys::fuzz_target;
|
|
use std::sync::LazyLock;
|
|
|
|
use ironclaw::safety::{LeakDetector, Sanitizer, Validator};
|
|
|
|
static SANITIZER: LazyLock<Sanitizer> = LazyLock::new(Sanitizer::new);
|
|
static VALIDATOR: LazyLock<Validator> = LazyLock::new(Validator::new);
|
|
static LEAK_DETECTOR: LazyLock<LeakDetector> = LazyLock::new(LeakDetector::new);
|
|
|
|
fuzz_target!(|data: &[u8]| {
|
|
if let Ok(input) = std::str::from_utf8(data) {
|
|
// Exercise Sanitizer: detect and neutralize prompt injection attempts.
|
|
let sanitized = SANITIZER.sanitize(input);
|
|
// If no modification occurred, content must equal input.
|
|
if !sanitized.was_modified {
|
|
assert_eq!(sanitized.content, input);
|
|
}
|
|
|
|
// Exercise Validator: input validation (length, encoding, patterns).
|
|
let result = VALIDATOR.validate(input);
|
|
// ValidationResult must always be well-formed: if valid, no errors.
|
|
if result.is_valid {
|
|
assert!(
|
|
result.errors.is_empty(),
|
|
"valid result should have no errors"
|
|
);
|
|
}
|
|
|
|
// Exercise LeakDetector: secret detection (API keys, tokens, etc.).
|
|
let scan = LEAK_DETECTOR.scan(input);
|
|
// scan_and_clean must not panic and must return valid UTF-8.
|
|
let cleaned = LEAK_DETECTOR.scan_and_clean(input);
|
|
// If scan found no matches, scan_and_clean should return the input unchanged.
|
|
if scan.matches.is_empty() {
|
|
if let Ok(ref clean_str) = cleaned {
|
|
assert_eq!(
|
|
clean_str, input,
|
|
"scan_and_clean changed content despite no matches"
|
|
);
|
|
}
|
|
}
|
|
}
|
|
});
|