Fuzz NewManifestFromReader and cap the zstd decoder (closes #65)
check / check (push) Successful in 1m46s
check / check (push) Successful in 1m46s
FuzzNewManifestFromReader fails when the parser returns both or neither of a manifest and an error, or allocates more than sixteen times its input and the decompressed data it may read, plus room for the decoder's window. make test runs the committed seed corpus; make fuzz fuzzes for one minute, by hand only. Parser bug: MaxDecompressedSize did not bound decompression. The zstd decoder decoded a payload under 128 KiB in full, each frame up to its own 64 GiB limit, before the LimitReader read any of it. It now decodes synchronously, only what the LimitReader reads, with MaxDecompressedSize as its limit. Regression seeds: a frame claiming 8 GiB, and two frames each under the limit and together over it. Model: opus-5-5
This commit is contained in:
Executable
+17
@@ -0,0 +1,17 @@
|
||||
#!/bin/sh
|
||||
# script/fuzz: fuzz the manifest parser for one minute. Run by hand only:
|
||||
# script/test already runs the committed seed corpus as ordinary tests,
|
||||
# and CI never fuzzes. An input that fails is written to
|
||||
# mfer/testdata/fuzz/FuzzNewManifestFromReader/; once the parser is fixed,
|
||||
# commit it there as a regression seed.
|
||||
set -eu
|
||||
|
||||
ROOT="$(cd "$(dirname "$0")/.." && pwd -P)"
|
||||
|
||||
main() {
|
||||
cd "$ROOT"
|
||||
go test -run '^$' -fuzz '^FuzzNewManifestFromReader$' \
|
||||
-fuzztime 1m -parallel 2 ./mfer
|
||||
}
|
||||
|
||||
main "$@"
|
||||
Reference in New Issue
Block a user