78c31d1bed
The repository had no fuzzing setup despite several natural targets — the CSV parser, the Binance envelope deserializer, and the stateful indicator/aggregator update paths. Add a fuzz/ cargo-fuzz crate (detached from the workspace via its own [workspace] table and the parent's exclude) with four targets: - csv_reader — CandleReader over arbitrary bytes - binance_envelope — RawWsEnvelope deserialization from arbitrary strings - indicator_update — RSI/EMA streaming + batch over arbitrary f64 series - tick_aggregator — TickAggregator over arbitrary tick triples Each target asserts the no-panic contract: malformed input must surface as an Err. fuzz/README.md documents running them (nightly + cargo-fuzz).
14 lines
462 B
Rust
14 lines
462 B
Rust
#![no_main]
|
|
//! Fuzz the Binance combined-stream envelope deserializer.
|
|
//!
|
|
//! `RawWsEnvelope` is what a kline frame is decoded into; feeding it
|
|
//! arbitrary strings exercises the serde path that runs on every WebSocket
|
|
//! frame. It must reject malformed input with an `Err`, never panic.
|
|
|
|
use libfuzzer_sys::fuzz_target;
|
|
use wickra_data::live::binance::RawWsEnvelope;
|
|
|
|
fuzz_target!(|data: &str| {
|
|
let _ = serde_json::from_str::<RawWsEnvelope>(data);
|
|
});
|