Add two libFuzzer harnesses (GLOBbed from tests/fuzz/*.c) and deterministic
P8 config-frame receive tests:
- fuzz_config_receive.c drives config_receive() from arbitrary bytes. It
captures one canonical valid frame with the production sender and feeds the
receiver four shapes: raw bytes, valid-version-prefix + fuzz bytes, valid
frame minus the P8 tail (super_mode + copy-as) + fuzz bytes, and valid frame
minus the usermap count + fuzz bytes. This reaches the --super/--copy-as and
huge/negative map-count paths that random bytes cannot get through the
preceding wire-bool gate.
- fuzz_identity_parse.c fuzzes identity_parse_copy_as/map/chown plus the
identity_wire_valid/identity_ownership_requested predicates on a fresh
config per input.
- test_fuzz_smoke.c gains deterministic malformed-frame cases: out-of-range
super_mode, negative/extreme copy-as ids, non-bool copy-as presence, tail
truncation, huge/negative usermap counts, version mismatch and a
wrong-order field after the version gate.
Unit build (STRICT_WARNINGS) and the fuzz build are clean; both targets run
3000+ iterations with no crash. No production code changed.