[ech] ECH PR reviews...

Stephen Farrell stephen.farrell at cs.tcd.ie
Mon Dec 11 14:17:29 UTC 2023


Hiya,

On 11/12/2023 12:47, Kurt Roeckx wrote:
> I haven't looked at the PR, but if you have time, it would be nice
> that you could look at fuzzing. One option for that is disabling the
> encryption in a fuzz build so that the normal fuzzers can reach the
> new functions. That would be done based on the
> FUZZING_BUILD_MODE_UNSAFE_FOR_PRODUCTION define.

Sure, that's on my TODO list. Since I have a bit of time today
I built it following [1] and am now running ``fuzz/helper.py client``

Is there a HOWTO for pointing the fuzzer at new APIs or does it
pick 'em up automagically or something? I guess if not I'd need
to add a call to ``SSL_CTX_ech_set1_echconfig()`` to an equivalent
of ``fuzz/client.c`` or something?

Ta,
S.

[1] https://github.com/openssl/openssl/blob/master/fuzz/README.md

> 
> Kurt
-------------- next part --------------
A non-text attachment was scrubbed...
Name: OpenPGP_0xE4D8E9F997A833DD.asc
Type: application/pgp-keys
Size: 1197 bytes
Desc: OpenPGP public key
URL: <https://mta.openssl.org/pipermail/ech/attachments/20231211/8d49c1e7/attachment.asc>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: OpenPGP_signature.asc
Type: application/pgp-signature
Size: 236 bytes
Desc: OpenPGP digital signature
URL: <https://mta.openssl.org/pipermail/ech/attachments/20231211/8d49c1e7/attachment.sig>


More information about the ech mailing list