Fuzz NewManifestFromReader and cap the zstd decoder (closes #65)
check / check (push) Successful in 1m4s

FuzzNewManifestFromReader fails when the parser returns both or neither
of a manifest and an error, or allocates more than sixteen times its
input plus MaxDecompressedSize. make test runs the committed seed
corpus; make fuzz fuzzes for one minute, by hand only.

Parser bug: MaxDecompressedSize did not bound decompression. The zstd
decoder kept its own 64 GiB limit, set aside whatever size a frame
header claimed, and decoded payloads under 128 KiB in full before the
LimitReader read any of it, so a 92-byte manifest claiming 8 GiB made
the parser allocate 8 GiB. The decoder now has MaxDecompressedSize as
its limit; that manifest is a regression seed.

Model: opus-5-5
This commit is contained in:
2026-10-03 15:44:24 +00:00
parent a3749e9e9b
commit 99c1b936c3
20 changed files with 117 additions and 3 deletions
+5 -1
View File
@@ -24,6 +24,10 @@ only thing left of the `chore/align-repo-policies` branch is the list below.
# Completed Steps
- 2026-10-03: added `FuzzNewManifestFromReader` and its seed corpus, which
`make test` runs, plus `make fuzz` for a one-minute run by hand; the zstd
decoder now has `MaxDecompressedSize` as its limit, so a frame claiming a
large size can no longer make the parser allocate that size (#65)
- 2026-10-03: `script/cibuild` builds the image with the same command as
`script/docker`, `--no-cache` included, so the checks in the Dockerfile run on
every build, also on an unchanged tree (#89)
@@ -123,7 +127,7 @@ only thing left of the `chore/align-repo-policies` branch is the list below.
rate-limit Checker progress output; add --deterministic flag or default;
wire top-level --version properly
- Testing:
- Fuzz NewManifestFromReader; end-to-end tests for freshen and fetch
- End-to-end tests for freshen and fetch
- Documentation:
- Promote docs/FORMAT.md as primary spec reference; audit error messages;
document the signature scheme fully