build: make fuzz actually fuzz (DSPX-4903) - #4096
Open
dmihalcik-virtru wants to merge 1 commit into
Open
dmihalcik-virtru wants to merge 1 commit into
dmihalcik-virtru wants to merge 1 commit into
Conversation
|
Warning Review limit reachedNext included review available in 8 seconds. View limit detailsLimit details: You’ve used the included review currently available. You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository. Review configuration: ⚙️ Run configurationConfiguration used: Repository UI Review profile: ASSERTIVE Plan: Advanced Run ID: 📒 Files selected for processing (2)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Contributor
Benchmark results, click to expandBenchmark authorization.GetDecisions Results:
Benchmark authorization.v2.GetMultiResourceDecision Results:
Benchmark Statistics
Bulk Benchmark Results
TDF3 Benchmark Results:
|
Contributor
|
Contributor
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Fixes DSPX-4903.
Problem
make fuzzhas never fuzzed anything.Without
-fuzz=<regexp>,go testtreats aFuzzXxxfunction as an ordinary test that replays only its seed corpus. No mutation, no coverage-guided exploration.-fuzztimeis silently ignored when-fuzzis absent:A 20-second budget returned in 0.3 seconds.
Two more defects in the same two lines:
-fuzztakes one package and one target per invocation.go test ./... -fuzz=...is rejected outright, so this needs a loop, not just an extra flag.sdkonly, missinglib/ocrypto'sFuzzUncompressECPubKey. The siblingtestandbenchtargets both iterate$(HAND_MODS).Change
Rewrites the target to discover every
FuzzXxxacross$(HAND_MODS)and run each one with-fuzz. Discovery is dynamic, so a new target is picked up without editing the Makefile. Agrepnarrows to candidate packages first, becausego test -listbuilds a test binary per package and nearly all of them have no fuzz targets.Adds
FUZZTIME(default30s, per target) andfuzzto.PHONY, and documents the target inAGENTS.md— including the crasher workflow, which is a real footgun: Go writes a crasher totestdata/fuzz/<Target>/<hash>, and every later plaingo testreplays it as a seed, so committing one before its fix turns the whole suite red.No production code changes. No new fuzz targets, no seed-corpus additions.
Verification
All six targets are now discovered and fuzzed, in both modules:
make fuzz FUZZTIME=2sconfirms real fuzzing rather than seed replay:and a failing target propagates a non-zero exit (
make: *** [fuzz] Error 1).Heads-up: this makes
make fuzzfail onmaintodayWithin ~1 second of actually fuzzing,
FuzzReaderfinds a live panic:A ZIP64 size field ≥ 2^63 converts to a negative
int64atreader.go:173, passes the upper-bound-only check atreader.go:350, and reachesmake([]byte, negative).That bug is already fixed by #4043 / DSPX-4590 (in review), whose code comment describes this exact failure mode. It is deliberately not fixed here — this PR is the runner only. So
make fuzzwill fail onmainuntil DSPX-4590 lands. That is the target doing its job, and it is safe:make fuzzis not referenced anywhere in.github/, so nothing in CI depends on it and this cannot turn CI red.Wiring fuzzing into CI is intentionally out of scope; it needs corpus persistence and a triage story first, and should be its own ticket.
Testing notes
make fuzz FUZZTIME=2s— discovery, real fuzzing, non-zero exit on failure, all verified above.make test/make lintare unaffected.testdata/fuzzfiles.