Repository navigation
[test] add SD tbor command fuzz targets - #770
David Zimmermann (zimmy87) wants to merge 14 commits into
Conversation
There was a problem hiding this comment.
Copilot review overview
🔵 Needs a closer look
The large security-sensitive cryptographic fuzz fixtures warrant final human validation and execution against supported backends.
Review effort: Balanced
Findings: None
What changed in this PR
Adds structured fuzz coverage for four Security Domain TBOR backup commands, including valid, lifecycle, evidence, policy, and tampering scenarios.
Changes:
- Adds fuzz targets for peer creation, remote creation, local restoration, and remote resealing.
- Registers targets and adds peer-backup corpus generation.
- Extends peer-backup integration coverage for repetition and policy mismatch.
| File | Description |
|---|---|
fuzz/scripts/generate_sd_create_peer_backup_corpus.ps1 |
Generates peer-backup scenario seeds. |
fuzz/fuzz_targets/ddi/tbor/fuzz_tbor_sd_restore_local_backup.rs |
Fuzzes local backup restoration. |
fuzz/fuzz_targets/ddi/tbor/fuzz_tbor_sd_reseal_remote_backup.rs |
Fuzzes remote backup resealing. |
fuzz/fuzz_targets/ddi/tbor/fuzz_tbor_sd_create_remote_backup.rs |
Fuzzes remote backup creation. |
fuzz/fuzz_targets/ddi/tbor/fuzz_tbor_sd_create_peer_backup.rs |
Fuzzes peer backup creation. |
fuzz/fuzz_targets/common.rs |
Reformats policy fixture construction. |
fuzz/Cargo.toml |
Registers the four fuzz binaries. |
ddi/tbor/types/tests/commands/sd_create_peer_backup.rs |
Tests repeatability and policy rejection. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
…uzz_tbor_sd_reseal_remote_backup
There was a problem hiding this comment.
🟡 Changes recommended
Ephemeral-scope peer-backup cases reuse a masked key after its masking key is regenerated.
1 open finding
🧠 Review effort: Balanced
Give feedback about Copilot approvals in this survey to enter a drawing for a $150 gift card.
Co-authored-by: zimmy87 <5205889+zimmy87@users.noreply.github.com>
…azihsm-sdk into user/v-davidz/add_tbor_sd
There was a problem hiding this comment.
🟢 Approval recommended
The new fuzz targets cover valid, lifecycle, scope, evidence, and tampering paths without unresolved correctness issues.
0 open findings
1 resolved since last review
🧠 Review effort: Balanced
Give feedback about Copilot approvals in this survey to enter a drawing for a $150 gift card.
Update comment to clarify that SdSealingKeyGen returns a partition-scoped masked-key. Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>


No description provided.