This series adds integrated AFL++ fuzzing support for passt, extending the earlier work by AbdAlRahman Gad with persistent mode, bidirectional protocol fuzzing, and real TCP connection coverage via a companion test server. Each testcase is a flat buffer split into four regions: epoll events, raw L2 tap frames, test-server payloads, and getsockopt(TCP_INFO) overrides. AFL++ controls all four through mutation of a 10-byte header. Fuzz-injected epoll events are interleaved with real kernel events so protocol handshakes can complete. A standalone test server (fuzz-server) attaches to AFL++'s shared memory and sends fuzzer-controlled payload on every accepted TCP connection. AnyIP routing in a rootless user+network namespace makes every destination local, so the test server intercepts all outbound traffic from passt without mocking recv(). Deterministic wrappers replace clock_gettime(), getsockopt() and assert() to eliminate non-determinism from kernel state. Sandboxing (seccomp, namespaces, close_range, capabilities) is bypassed under FUZZING builds since AFL++ needs its own fds and syscalls. *** BLURB HERE *** Anshu Kumari (7): fuzz: Add AFL++ shared memory testcase buffer layout fuzz: Add deterministic wrappers for assert, clock and getsockopt fuzz: Guard protocol handlers against invalid fuzz-injected state fuzz: Bypass sandboxing for fuzzing builds fuzz: Add AFL++ persistent mode fuzz loop fuzz: Add host-side test server for bidirectional fuzzing fuzz: Add build targets, namespace setup and documentation Makefile | 35 +++- flow.c | 52 +++++ fuzz-server.c | 343 +++++++++++++++++++++++++++++++++ fuzz-testbuf.h | 135 +++++++++++++ fuzz.c | 102 ++++++++++ fuzz.h | 38 ++++ fuzzing/README.fuzzing.md | 129 +++++++++++++ fuzzing/fuzz-setup.sh | 24 +++ fuzzing/testcase_dir/empty.bin | Bin 0 -> 12 bytes icmp.c | 8 +- isolation.c | 23 +++ passt.c | 198 +++++++++++++++++++ tap.c | 13 ++ tcp.c | 18 +- tcp_buf.c | 1 + tcp_splice.c | 4 +- udp.c | 29 ++- udp_flow.c | 3 +- util.c | 1 + 19 files changed, 1131 insertions(+), 25 deletions(-) create mode 100644 fuzz-server.c create mode 100644 fuzz-testbuf.h create mode 100644 fuzz.c create mode 100644 fuzz.h create mode 100644 fuzzing/README.fuzzing.md create mode 100755 fuzzing/fuzz-setup.sh create mode 100644 fuzzing/testcase_dir/empty.bin -- 2.55.0