Fuzz NewManifestFromReader and cap the zstd decoder (closes #65)
check / check (push) Successful in 1m46s

FuzzNewManifestFromReader fails when the parser returns both or neither
of a manifest and an error, or allocates more than sixteen times its
input and the decompressed data it may read, plus room for the decoder's
window. make test runs the committed seed corpus; make fuzz fuzzes for
one minute, by hand only.

Parser bug: MaxDecompressedSize did not bound decompression. The zstd
decoder decoded a payload under 128 KiB in full, each frame up to its
own 64 GiB limit, before the LimitReader read any of it. It now decodes
synchronously, only what the LimitReader reads, with MaxDecompressedSize
as its limit. Regression seeds: a frame claiming 8 GiB, and two frames
each under the limit and together over it.

Model: opus-5-5
This commit is contained in:
2026-10-03 23:59:56 +00:00
parent c31796998f
commit 49a7b96e2c
21 changed files with 144 additions and 3 deletions
+4 -1
View File
@@ -13,7 +13,7 @@ GOLDFLAGS += -X main.Version=$(VERSION)
GOLDFLAGS += -X main.Gitrev=$(GITREV_BUILD)
GOFLAGS := -ldflags "$(GOLDFLAGS)"
.PHONY: bootstrap setup docker default run ci test check lint fmt fmt-check fmt-check-go fmt-check-md hooks fixme
.PHONY: bootstrap setup docker default run ci test fuzz check lint fmt fmt-check fmt-check-go fmt-check-md hooks fixme
default: fmt test
@@ -32,6 +32,9 @@ ci: test
test:
@script/test
fuzz:
@script/fuzz
$(PROTOC_GEN_GO):
test -e $(PROTOC_GEN_GO) || go install -v google.golang.org/protobuf/cmd/protoc-gen-go@v1.28.1