Fuzz NewManifestFromReader and cap the zstd decoder (closes #65)
check / check (push) Successful in 1m4s
check / check (push) Successful in 1m4s
FuzzNewManifestFromReader fails when the parser returns both or neither of a manifest and an error, or allocates more than sixteen times its input plus MaxDecompressedSize. make test runs the committed seed corpus; make fuzz fuzzes for one minute, by hand only. Parser bug: MaxDecompressedSize did not bound decompression. The zstd decoder kept its own 64 GiB limit, set aside whatever size a frame header claimed, and decoded payloads under 128 KiB in full before the LimitReader read any of it, so a 92-byte manifest claiming 8 GiB made the parser allocate 8 GiB. The decoder now has MaxDecompressedSize as its limit; that manifest is a regression seed. Model: opus-5-5
This commit is contained in:
@@ -13,7 +13,7 @@ GOLDFLAGS += -X main.Version=$(VERSION)
|
||||
GOLDFLAGS += -X main.Gitrev=$(GITREV_BUILD)
|
||||
GOFLAGS := -ldflags "$(GOLDFLAGS)"
|
||||
|
||||
.PHONY: bootstrap setup docker default run ci test check lint fmt fmt-check fmt-check-go fmt-check-md hooks fixme
|
||||
.PHONY: bootstrap setup docker default run ci test fuzz check lint fmt fmt-check fmt-check-go fmt-check-md hooks fixme
|
||||
|
||||
default: fmt test
|
||||
|
||||
@@ -32,6 +32,9 @@ ci: test
|
||||
test:
|
||||
@script/test
|
||||
|
||||
fuzz:
|
||||
@script/fuzz
|
||||
|
||||
$(PROTOC_GEN_GO):
|
||||
test -e $(PROTOC_GEN_GO) || go install -v google.golang.org/protobuf/cmd/protoc-gen-go@v1.28.1
|
||||
|
||||
|
||||
Reference in New Issue
Block a user