Files
optimclaw/fuzz/README.md
T
5a62ceaa99 refactor: extract safety module into ironclaw_safety crate (#1024)
* refactor: extract safety module into ironclaw_safety crate

Move prompt injection defense, input validation, secret leak detection,
and safety policy enforcement into a standalone crate under crates/.
The safety module was a leaf dependency with no async, no database, and
no other ironclaw traits — only pure computation with pattern matching.

SafetyConfig (2 fields) moves into the crate; env-var resolution stays
in ironclaw's config module as a free function. src/safety/mod.rs becomes
a thin re-export so all existing `crate::safety::*` imports keep working.

Co-Authored-By: Claude Opus 4.6 <[email protected]>

* docs: update CLAUDE.md for ironclaw_safety crate extraction

Add guidance to migrate imports from crate::safety to ironclaw_safety
when touching files. Update project structure to reflect crates/ dir.

Co-Authored-By: Claude Opus 4.6 <[email protected]>

* refactor: move safety fuzz targets into ironclaw_safety crate

Split fuzz infrastructure:
- crates/ironclaw_safety/fuzz/ — 5 safety-only targets (sanitizer,
  validator, leak_detector, credential_detect, config_env) depending
  only on ironclaw_safety for faster builds
- fuzz/ — keeps fuzz_tool_params which needs ironclaw::tools

Add seed corpus files (51 total) covering each pattern family:
sanitizer injection patterns, validator edge cases, leak detector
secret formats, credential detect HTTP param shapes.

Add new fuzz_credential_detect target exercising
params_contain_manual_credentials with arbitrary JSON.

Co-Authored-By: Claude Opus 4.6 <[email protected]>

* fix: address PR review — single-pass XML escaping and versioned path dep

Rewrite escape_xml_attr from chained .replace() to single-pass char
iteration (O(n) instead of O(4n) with intermediate allocations). Add
version = "0.1.0" to ironclaw_safety path dep to satisfy cargo-deny
wildcards = "deny".

Co-Authored-By: Claude Opus 4.6 <[email protected]>

---------

Co-authored-by: Claude Opus 4.6 <[email protected]>
2026-03-12 17:54:24 +00:00

1.1 KiB

IronClaw Fuzz Targets

Fuzz testing for IronClaw code paths that depend on the full crate, using cargo-fuzz (libFuzzer).

Note: Safety-specific fuzz targets (sanitizer, validator, leak detector, credential detect) have moved to crates/ironclaw_safety/fuzz/. See that directory's README for details.

Targets

Target What it exercises
fuzz_tool_params Tool parameter and schema JSON validation

Setup

cargo install cargo-fuzz
rustup install nightly

Running

# Run a specific target (runs until stopped or crash found)
cargo +nightly fuzz run fuzz_tool_params

# Run with a time limit (5 minutes)
cargo +nightly fuzz run fuzz_tool_params -- -max_total_time=300

Adding New Targets

  1. Create fuzz/fuzz_targets/fuzz_<name>.rs following the existing pattern
  2. Add a [[bin]] entry in fuzz/Cargo.toml
  3. Create fuzz/corpus/fuzz_<name>/ for seed inputs
  4. Exercise real IronClaw code paths, not just generic serde

For safety-only targets, add them to crates/ironclaw_safety/fuzz/ instead.