Fuzz NewManifestFromReader and cap the zstd decoder (closes #65)
check / check (push) Successful in 1m4s
check / check (push) Successful in 1m4s
FuzzNewManifestFromReader fails when the parser returns both or neither of a manifest and an error, or allocates more than sixteen times its input plus MaxDecompressedSize. make test runs the committed seed corpus; make fuzz fuzzes for one minute, by hand only. Parser bug: MaxDecompressedSize did not bound decompression. The zstd decoder kept its own 64 GiB limit, set aside whatever size a frame header claimed, and decoded payloads under 128 KiB in full before the LimitReader read any of it, so a 92-byte manifest claiming 8 GiB made the parser allocate 8 GiB. The decoder now has MaxDecompressedSize as its limit; that manifest is a regression seed. Model: opus-5-5
This commit is contained in:
@@ -44,6 +44,9 @@ provide:
|
||||
such as `script/docker`
|
||||
- `script/test` — run the test suite (`go test`), regenerating the protobuf code
|
||||
first if it is stale
|
||||
- `script/fuzz` — fuzz the manifest parser for one minute; run by hand
|
||||
(`make fuzz`), never by CI, while `script/test` runs its committed seed corpus
|
||||
as ordinary tests
|
||||
- `script/lint` — run `golangci-lint` and verify `gofmt` cleanliness
|
||||
- `script/fmt` — format all code and docs (writes): `gofumpt`,
|
||||
`golangci-lint run --fix`, and `script/prettier --write`
|
||||
|
||||
Reference in New Issue
Block a user