Files
wickra/fuzz/fuzz_targets/binance_envelope.rs
T
kingchenc 78c31d1bed E16: add a cargo-fuzz harness
The repository had no fuzzing setup despite several natural targets —
the CSV parser, the Binance envelope deserializer, and the stateful
indicator/aggregator update paths.

Add a fuzz/ cargo-fuzz crate (detached from the workspace via its own
[workspace] table and the parent's exclude) with four targets:

- csv_reader      — CandleReader over arbitrary bytes
- binance_envelope — RawWsEnvelope deserialization from arbitrary strings
- indicator_update — RSI/EMA streaming + batch over arbitrary f64 series
- tick_aggregator — TickAggregator over arbitrary tick triples

Each target asserts the no-panic contract: malformed input must surface
as an Err. fuzz/README.md documents running them (nightly + cargo-fuzz).
2026-05-22 16:44:19 +02:00

14 lines
462 B
Rust

#![no_main]
//! Fuzz the Binance combined-stream envelope deserializer.
//!
//! `RawWsEnvelope` is what a kline frame is decoded into; feeding it
//! arbitrary strings exercises the serde path that runs on every WebSocket
//! frame. It must reject malformed input with an `Err`, never panic.
use libfuzzer_sys::fuzz_target;
use wickra_data::live::binance::RawWsEnvelope;
fuzz_target!(|data: &str| {
let _ = serde_json::from_str::<RawWsEnvelope>(data);
});