Fuzz NewManifestFromReader and cap the zstd decoder (closes #65)
check / check (push) Successful in 1m4s
check / check (push) Successful in 1m4s
FuzzNewManifestFromReader fails when the parser returns both or neither of a manifest and an error, or allocates more than sixteen times its input plus MaxDecompressedSize. make test runs the committed seed corpus; make fuzz fuzzes for one minute, by hand only. Parser bug: MaxDecompressedSize did not bound decompression. The zstd decoder kept its own 64 GiB limit, set aside whatever size a frame header claimed, and decoded payloads under 128 KiB in full before the LimitReader read any of it, so a 92-byte manifest claiming 8 GiB made the parser allocate 8 GiB. The decoder now has MaxDecompressedSize as its limit; that manifest is a regression seed. Model: opus-5-5
This commit is contained in:
Executable
+17
@@ -0,0 +1,17 @@
|
||||
#!/bin/sh
|
||||
# script/fuzz: fuzz the manifest parser for one minute. Run by hand only:
|
||||
# script/test already runs the committed seed corpus as ordinary tests,
|
||||
# and CI never fuzzes. An input that fails is written to
|
||||
# mfer/testdata/fuzz/FuzzNewManifestFromReader/; once the parser is fixed,
|
||||
# commit it there as a regression seed.
|
||||
set -eu
|
||||
|
||||
ROOT="$(cd "$(dirname "$0")/.." && pwd -P)"
|
||||
|
||||
main() {
|
||||
cd "$ROOT"
|
||||
go test -run '^$' -fuzz '^FuzzNewManifestFromReader$' \
|
||||
-fuzztime 1m -parallel 2 ./mfer
|
||||
}
|
||||
|
||||
main "$@"
|
||||
Reference in New Issue
Block a user