Fuzz NewManifestFromReader and cap the zstd decoder (closes #65)
check / check (push) Successful in 1m46s

FuzzNewManifestFromReader fails when the parser returns both or neither
of a manifest and an error, or allocates more than sixteen times its
input and the decompressed data it may read, plus room for the decoder's
window. make test runs the committed seed corpus; make fuzz fuzzes for
one minute, by hand only.

Parser bug: MaxDecompressedSize did not bound decompression. The zstd
decoder decoded a payload under 128 KiB in full, each frame up to its
own 64 GiB limit, before the LimitReader read any of it. It now decodes
synchronously, only what the LimitReader reads, with MaxDecompressedSize
as its limit. Regression seeds: a frame claiming 8 GiB, and two frames
each under the limit and together over it.

Model: opus-5-5
This commit is contained in:
2026-10-03 23:59:56 +00:00
parent c31796998f
commit 49a7b96e2c
21 changed files with 144 additions and 3 deletions
+6 -1
View File
@@ -24,6 +24,11 @@ only thing left of the `chore/align-repo-policies` branch is the list below.
# Completed Steps
- 2026-10-03: added `FuzzNewManifestFromReader` and its seed corpus, which
`make test` runs, plus `make fuzz` for a one-minute run by hand; the zstd
decoder now decodes only as many bytes as the parser reads, and has
`MaxDecompressedSize` as its limit, so neither a frame claiming a large size
nor several frames together can make the parser allocate past that limit (#65)
- 2026-10-03: pinned the CLI error messages by driving the functions that emit
them in `internal/cli/errmsg_test.go`, and made the freshen mtime-presence
test distinguish an absent mtime from the epoch (#87)
@@ -126,7 +131,7 @@ only thing left of the `chore/align-repo-policies` branch is the list below.
rate-limit Checker progress output; add --deterministic flag or default;
wire top-level --version properly
- Testing:
- Fuzz NewManifestFromReader; end-to-end tests for freshen and fetch
- End-to-end tests for freshen and fetch
- Documentation:
- Promote docs/FORMAT.md as primary spec reference; audit error messages;
document the signature scheme fully