Repository navigation
Coverage-guided fuzzing of both zone-byte parsers, weekly on a dated nightly - #182
Merged
Merged
Conversation
…s wire parser runs weekly, on a dated nightly cargo-fuzz targets for both parsers of zone bytes. compartments/kryptikd/fuzz builds the daemon's own main.rs with cfg(fuzzing), where the harness takes main's place, because the parser is private to a binary crate; it feeds parse_request any header line and holds every request it accepts to the bounds its refusals enforce. compositor/wlproxy/fuzz compiles wire.rs, protocol.rs and the generated tables as they are, since they name nothing else in the proxy, and reads a message stream against every signature, checking the string offsets and the writer the rewrites use. Each is a package with a workspace and lockfile of its own: libfuzzer-sys and what it pulls in (arbitrary, cc and cc's build helpers) are in neither shipped Cargo.lock nor either binary's dependencies, and the licence check and the source bundle read only the shipped lockfiles. kryptikd's Cargo.toml declares the fuzzing cfg so the ordinary build does not warn about it. .github/workflows/fuzz.yml runs both on Sundays and on dispatch: a nightly pinned by date from rustup, cargo-fuzz 0.13.2 installed --locked, the fuzz lockfile held with cargo fetch --locked, the broker seeded from fuzz-corpus/broker-requests one request per file, twenty minutes per target with no sanitizer (the parsers are safe Rust), and any crash input kept as an artifact for 30 days.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Coverage-guided fuzzing for the two hand-written parsers of zone bytes, as broker.md said it should be: a scheduled job on nightly Rust.
Targets.
compartments/kryptikd/fuzz(targetbroker_request) feedsbroker::parse_requestany header line, cut at the first newline and decoded lossily the wayserve_connectiondoes it. Every request it accepts is held to the bounds its refusals enforce: MIME type and clipboard length, zone-name alphabet and transfer name, the time claim's range and source count, and the update lengths. The parser is private to a binary crate, so the fuzz package builds kryptikd's ownmain.rswithcfg(fuzzing). There#![cfg_attr(fuzzing, no_main, ...)]and a#[cfg(fuzzing)] mod fuzzput the harness in place ofmain. The ordinary build never compiles either line, and kryptikd's Cargo.toml declares the cfg sounexpected_cfgsstays quiet.compositor/wlproxy/fuzz(targetwire) compileswire.rs,protocol.rsandprotocol_tables.rsunchanged through#[path], since they name nothing else in the proxy. It reads a stream of messages, each against the table signature its object id picks, and checks the header round trip, that a new object or bind version appears exactly when the signature has one, that every string sits at the offset a rewrite trusts, and thatMessageWriteroutput parses back to the same string. No proxy source changes.Supply chain (ADR-010). Each fuzz crate is a separate package with its own
[workspace]and its own committedCargo.lock.libfuzzer-sys0.4.13 and what it pulls in (arbitrary, pluscc,jobserver,shlex,find-msvc-tools,getrandom,cfg-ifandr-efiascc's build-time helpers) live only incompartments/kryptikd/fuzz/Cargo.lockandcompositor/wlproxy/fuzz/Cargo.lock. They are in neither shippedCargo.locknor either binary's dependency graph.tools/check-rust-licences.shandtools/source-bundle.shread only the two shipped lockfiles, so nothing new is owed a licence text or a vendored source.libcresolves to 0.2.189, the shipped version. The job also buildscargo-fuzz0.13.2 withcargo install --locked, a tool on the runner that ships nowhere.Workflow.
.github/workflows/fuzz.ymlruns Sundays at 04:00 UTC and onworkflow_dispatch, withpermissions: contents: read. Checkout and upload-artifact are pinned to the SHAs the other workflows use. It usesnightly-2026-09-28from rustup (rustc 1.101.0-nightly), pinned by date so a new finding is never a new compiler's.cargo fetch --lockedmust accept each fuzz lockfile before anything builds. The broker target is seeded fromfuzz-corpus/broker-requests, one request per file; the proxy has no corpus in the tree, so it starts empty. Each target runs for 20 minutes (-max_total_time=1200,-max_len4096 and 8192,-timeout=10) in parallel matrix jobs with a 60-minute job limit. There is no sanitizer, because the code under test is safe Rust; panics, the overflow checks and debug assertions the fuzz profiles turn on, and the harness's asserts are the oracle. Any crash, timeout or OOM input is uploaded as thefuzz-<target>artifact for 30 days.Dispatch result (run 36986534899, this branch): both targets built clean and ran their full 20 minutes with no crash, timeout or OOM, so no artifact was uploaded.
broker_request(26 seeds)wire(no seeds)GitHub only dispatches a workflow it already knows, and this one is not on
mainyet. A push to a short-lived branch registered it: run 36986437209 was cancelled at once and that branch is deleted. After that,gh workflow runon this branch worked. Once merged, the Sunday schedule and plaingh workflow run fuzz.ymlneed nothing more.CI on this branch is green: Commit identity, Shell lint, Source manifest, Compartment layer, Kernel currency and CodeQL. The compartment job builds kryptikd with the new
main.rsand Cargo.toml for glibc and for musl with no new warnings.