Fuzz NewManifestFromReader and cap the zstd decoder (closes #65)
check / check (push) Successful in 1m35s

FuzzNewManifestFromReader fails when the parser returns both or neither
of a manifest and an error, or allocates more than sixteen times its
input and the decompressed data it may read, plus room for the decoder's
window buffers. make test runs the seed corpus; make fuzz fuzzes for one
minute.

Parser bug: MaxDecompressedSize did not bound decompression. The zstd
decoder decoded a payload under 128 KiB in full before the LimitReader
read any of it. It now decodes synchronously, only what the LimitReader
reads, and refuses windows over the 8 MiB mfer writes with, since each
frame asking for a larger window gets a new buffer. Seeds: a frame
claiming 8 GiB, two frames together over the limit, empty frames with
growing windows.

Model: opus-5-5
This commit is contained in:
2026-10-04 01:36:30 +00:00
parent 1adad7d3bc
commit 00803243de
24 changed files with 182 additions and 3 deletions
+4 -1
View File
@@ -13,7 +13,7 @@ GOLDFLAGS += -X main.Version=$(VERSION)
GOLDFLAGS += -X main.Gitrev=$(GITREV_BUILD)
GOFLAGS := -ldflags "$(GOLDFLAGS)"
.PHONY: bootstrap setup docker default run ci test check lint fmt fmt-check fmt-check-go fmt-check-md hooks fixme
.PHONY: bootstrap setup docker default run ci test fuzz check lint fmt fmt-check fmt-check-go fmt-check-md hooks fixme
default: fmt test
@@ -32,6 +32,9 @@ ci: test
test:
@script/test
fuzz:
@script/fuzz
$(PROTOC_GEN_GO):
test -e $(PROTOC_GEN_GO) || go install -v google.golang.org/protobuf/cmd/protoc-gen-go@v1.28.1