mirror of
https://github.com/outbackdingo/optimclaw.git
synced 2026-08-25 14:53:34 +00:00
- Use std::sync::LazyLock to construct Sanitizer, Validator, and LeakDetector once instead of on every fuzz iteration (they compile regex/Aho-Corasick) - Remove fuzz_config_env assertion that panics on null-byte-only input - Remove no-op length check with misleading comment in fuzz_config_env - Update fuzz_config_env description in README to match actual behavior Co-Authored-By: Claude Opus 4.6 <[email protected]>
IronClaw Fuzz Targets
Fuzz testing for security-critical input parsing paths using cargo-fuzz (libFuzzer).
Targets
| Target | What it exercises |
|---|---|
fuzz_safety_sanitizer |
Prompt injection pattern detection (Aho-Corasick + regex) |
fuzz_safety_validator |
Input validation (length, encoding, forbidden patterns) |
fuzz_leak_detector |
Secret leak detection (API keys, tokens, credentials) |
fuzz_tool_params |
Tool parameter and schema JSON validation |
fuzz_config_env |
Combined safety primitives (sanitize, validate, leak detect) |
Setup
cargo install cargo-fuzz
rustup install nightly
Running
# Run a specific target (runs until stopped or crash found)
cargo +nightly fuzz run fuzz_safety_sanitizer
# Run with a time limit (5 minutes)
cargo +nightly fuzz run fuzz_leak_detector -- -max_total_time=300
# Run all targets for 60 seconds each
for target in fuzz_safety_sanitizer fuzz_safety_validator fuzz_leak_detector fuzz_tool_params fuzz_config_env; do
echo "==> $target"
cargo +nightly fuzz run "$target" -- -max_total_time=60
done
Adding New Targets
- Create
fuzz/fuzz_targets/fuzz_<name>.rsfollowing the existing pattern - Add a
[[bin]]entry infuzz/Cargo.toml - Create
fuzz/corpus/fuzz_<name>/for seed inputs - Exercise real IronClaw code paths, not just generic serde