fuzz/fuzz_targets/guard_manifest.rs
fuzz · 53 lines · read the source here · or on GitHub
The integrity manifest parser, coverage-guided.
A text format rather than a packed one, which removes a whole class of length-field bug and introduces a different one: it is split on a delimiter, indexed by byte offset, and sliced for display. Change::describe takes &digest[..8], and slicing a String at a byte offset that is not a character boundary panics.
The manifest is normally the user's own record, but "normally" is not a security property: veilvoice guard check will read whichever file is at the path, and a record is exactly the kind of thing somebody hands you.
WHAT CALLS WHAT
This file defines no functions of its own.