first commit
This commit is contained in:
@@ -0,0 +1,32 @@
|
||||
package sieve
|
||||
|
||||
import "testing"
|
||||
|
||||
func FuzzParse(f *testing.F) {
|
||||
f.Add(`if header :contains "subject" "invoice" { fileinto "Invoices"; stop; }`)
|
||||
f.Add(`if header :is "from" "boss@example.com" { fileinto "Important"; } elsif header :contains "subject" "urgent" { fileinto "Important"; } else { keep; }`)
|
||||
f.Add("")
|
||||
f.Add("keep;")
|
||||
f.Add("if true { discard; }")
|
||||
f.Add(`if header :contains "subject" { fileinto "X" }`)
|
||||
f.Add("if header { }")
|
||||
f.Add("{{{{{{{")
|
||||
f.Add(`if header :contains "a" "b`)
|
||||
f.Add("if header :bogus \"x\" \"y\" { keep; }")
|
||||
f.Add("fileinto;")
|
||||
|
||||
f.Fuzz(func(t *testing.T, data string) {
|
||||
// This is the fuzz target most directly exposed to untrusted input
|
||||
// in production — every ManageSieve PUTSCRIPT is parsed by this
|
||||
// exact function before storage. A crash here would be a remotely
|
||||
// triggerable DoS against an authenticated user's own session, so
|
||||
// "never panics" matters more here than for the calendar/contact
|
||||
// parsers.
|
||||
defer func() {
|
||||
if r := recover(); r != nil {
|
||||
t.Fatalf("Parse panicked on input %q: %v", data, r)
|
||||
}
|
||||
}()
|
||||
Parse(data)
|
||||
})
|
||||
}
|
||||
Reference in New Issue
Block a user