Skip to content

[test] add SD tbor command fuzz targets - #770

Open
David Zimmermann (zimmy87) wants to merge 14 commits into
mainfrom
user/v-davidz/add_tbor_sd
Open

David Zimmermann (zimmy87) wants to merge 14 commits into
mainfrom
user/v-davidz/add_tbor_sd

Conversation

@zimmy87

Copy link
Copy Markdown
Contributor

No description provided.

Copilot AI balanced review requested due to automatic review settings October 6, 2026 04:42

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

The large security-sensitive cryptographic fuzz fixtures warrant final human validation and execution against supported backends.

Review effort: Balanced
Findings: None

What changed in this PR

Adds structured fuzz coverage for four Security Domain TBOR backup commands, including valid, lifecycle, evidence, policy, and tampering scenarios.

Changes:

  • Adds fuzz targets for peer creation, remote creation, local restoration, and remote resealing.
  • Registers targets and adds peer-backup corpus generation.
  • Extends peer-backup integration coverage for repetition and policy mismatch.
File Description
fuzz/​scripts/​generate_sd_create_peer_backup_corpus.ps1 Generates peer-backup scenario seeds.
fuzz/​fuzz_targets/​ddi/​tbor/​fuzz_tbor_sd_restore_local_backup.rs Fuzzes local backup restoration.
fuzz/​fuzz_targets/​ddi/​tbor/​fuzz_tbor_sd_reseal_remote_backup.rs Fuzzes remote backup resealing.
fuzz/​fuzz_targets/​ddi/​tbor/​fuzz_tbor_sd_create_remote_backup.rs Fuzzes remote backup creation.
fuzz/​fuzz_targets/​ddi/​tbor/​fuzz_tbor_sd_create_peer_backup.rs Fuzzes peer backup creation.
fuzz/​fuzz_targets/​common.rs Reformats policy fixture construction.
fuzz/​Cargo.toml Registers the four fuzz binaries.
ddi/​tbor/​types/​tests/​commands/​sd_create_peer_backup.rs Tests repeatability and policy rejection.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Copilot AI balanced review requested due to automatic review settings October 6, 2026 18:33

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

The stateful cryptographic fixtures and hardware-facing fuzz paths require successful build and runtime validation before approval.

Review effort: Balanced
Findings: None

Copilot AI balanced review requested due to automatic review settings October 6, 2026 19:07

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

A rustfmt violation must be corrected before the required formatting check can pass.

Review effort: Balanced
Findings: 1 Low severity

Open (1)

Comment thread fuzz/fuzz_targets/ddi/tbor/fuzz_tbor_sd_create_peer_backup.rs Outdated
Copilot AI balanced review requested due to automatic review settings October 6, 2026 20:26

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

The extensive stateful cryptographic fuzz workflows require final human validation on supported fuzz backends.

Review effort: Balanced
Findings: None

Resolved since last review (1)

@zimmy87
David Zimmermann (zimmy87) marked this pull request as ready for review October 6, 2026 20:41
Comment thread fuzz/fuzz_targets/ddi/tbor/fuzz_tbor_sd_reseal_remote_backup.rs Outdated
Copilot AI balanced review requested due to automatic review settings October 7, 2026 20:36

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Changes recommended

Ephemeral-scope peer-backup cases reuse a masked key after its masking key is regenerated.

1 open finding

🧠 Review effort: Balanced


Give feedback about Copilot approvals in this survey to enter a drawing for a $150 gift card.

Comment thread fuzz/fuzz_targets/ddi/tbor/fuzz_tbor_sd_create_peer_backup.rs Outdated
Co-authored-by: zimmy87 <5205889+zimmy87@users.noreply.github.com>
Copilot AI balanced review requested due to automatic review settings October 7, 2026 20:45

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟢 Approval recommended

The new fuzz targets cover valid, lifecycle, scope, evidence, and tampering paths without unresolved correctness issues.

0 open findings

1 resolved since last review

🧠 Review effort: Balanced


Give feedback about Copilot approvals in this survey to enter a drawing for a $150 gift card.

Copilot AI balanced review requested due to automatic review settings October 9, 2026 18:44

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟢 Approval recommended

The fuzz workflows are coherent and registered correctly; only a minor misleading comment remains.

1 open finding

🧠 Review effort: Balanced

Comment thread fuzz/fuzz_targets/ddi/tbor/fuzz_tbor_sd_create_peer_backup.rs Outdated
Update comment to clarify that SdSealingKeyGen returns a partition-scoped masked-key.

Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
Copilot AI balanced review requested due to automatic review settings October 9, 2026 19:01

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟢 Approval recommended

The fixtures and expected outcomes align with the firmware command contracts and lifecycle behavior.

0 open findings

1 resolved since last review

🧠 Review effort: Balanced

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants