E16: add a cargo-fuzz harness
The repository had no fuzzing setup despite several natural targets — the CSV parser, the Binance envelope deserializer, and the stateful indicator/aggregator update paths. Add a fuzz/ cargo-fuzz crate (detached from the workspace via its own [workspace] table and the parent's exclude) with four targets: - csv_reader — CandleReader over arbitrary bytes - binance_envelope — RawWsEnvelope deserialization from arbitrary strings - indicator_update — RSI/EMA streaming + batch over arbitrary f64 series - tick_aggregator — TickAggregator over arbitrary tick triples Each target asserts the no-panic contract: malformed input must surface as an Err. fuzz/README.md documents running them (nightly + cargo-fuzz).
This commit is contained in:
@@ -0,0 +1,41 @@
|
||||
# Fuzzing Wickra
|
||||
|
||||
[`cargo-fuzz`](https://rust-fuzz.github.io/book/cargo-fuzz.html) harnesses for
|
||||
the parsing and stateful entry points of Wickra. Fuzzing requires a nightly
|
||||
Rust toolchain.
|
||||
|
||||
## Setup
|
||||
|
||||
```bash
|
||||
cargo install cargo-fuzz
|
||||
rustup toolchain install nightly
|
||||
```
|
||||
|
||||
## Targets
|
||||
|
||||
| Target | What it exercises |
|
||||
| --- | --- |
|
||||
| `csv_reader` | `CandleReader` over arbitrary bytes — headers, cells, BOM, binary noise. |
|
||||
| `binance_envelope` | `RawWsEnvelope` deserialization from arbitrary strings. |
|
||||
| `indicator_update` | RSI / EMA streaming + batch over arbitrary `f64` sequences (NaN, ±inf, jumps). |
|
||||
| `tick_aggregator` | `TickAggregator` over arbitrary `(price, volume, timestamp)` triples. |
|
||||
|
||||
## Run
|
||||
|
||||
```bash
|
||||
# From the repository root:
|
||||
cargo +nightly fuzz run csv_reader
|
||||
cargo +nightly fuzz run binance_envelope
|
||||
cargo +nightly fuzz run indicator_update
|
||||
cargo +nightly fuzz run tick_aggregator
|
||||
```
|
||||
|
||||
Each run continues until a crash is found or it is interrupted. A short
|
||||
time-boxed smoke run is useful in CI:
|
||||
|
||||
```bash
|
||||
cargo +nightly fuzz run csv_reader -- -max_total_time=60
|
||||
```
|
||||
|
||||
The expectation for every target is that it never panics: malformed or
|
||||
adversarial input must surface as an `Err`, never a crash.
|
||||
Reference in New Issue
Block a user