- version 0.8.0 -> 0.8.1 (bug-fix release; semver-checks 196 pass vs 0.8.0) - CHANGELOG 0.8.1: the manager_routing-found duplicate adopt/open fix, the fuzz harness, and the verification summary - publish exclude gains docs/research/ (internal research notes; fuzz/ was already excluded — package verified clean of both) - fuzzing.md §7.9: standing no-hosted-CI policy — corpus replay is the release-verification fuzz gate; campaigns manual via the detached runner; OSS-Fuzz out; no workflow files in this repo - AGENTS.md: corpus replay added to the verification checklist - lockfiles: alkcall 0.8.1 (root + fuzz) Verification: 684 tests; clippy -D warnings (main, wasm, fuzz/shared); fmt clean; doc clean; wasm32-unknown-unknown check+clippy clean; semver-checks 196 pass; publish --dry-run 116 files (no fuzz/research/ reviews/sdd/AGENTS in the tarball); fuzz corpus replay 5/5 green
alkcall fuzzing
libFuzzer targets for alkcall's wire formats (see
docs/research/fuzzing.md for the full rationale and campaign plan).
Layout
fuzz_targets/— one binary per target; thinfuzz_target!wrappers.shared/— the invariant logic, as a plain library so normalcargo test(stable toolchain) can replay the committed corpora through the same invariants (fuzz/shared/src/*.rs#[cfg(test)]modules; quinn's CI pattern). The fuzz binaries are nightly-only; the shared crate is stable-clean.corpus/<target>/— committed hand-made seeds (regenerate withpython3 fuzz/gen_fuzz_seeds.pyfrom the repo root). Grown corpora and artifacts are gitignored.run-detached.sh— mandatory runner for agent sessions: wrapscargo fuzz runinsetsid+nohup+ log redirection so an OOM in a target can never take down the agent host (research doc §7.6).json.dict— JSON token dictionary for the envelope targets.
Targets
| Target | Drives | Invariants |
|---|---|---|
chunk_header |
parse_header / write_header (channels/wire.rs) |
no-panic; round-trip identity; TooLarge iff length > MAX_CHUNK_LEN; consumption accounting (8 bytes); input never mutated |
envelope_frame |
FrameFramedReader::new(Cursor).read_frame() on a current-thread runtime |
no-panic; never allocates > MAX_FRAME_SIZE; clean FrameError on truncation/oversize/zero-length; exact consumption; structural write_frame round-trip |
Commands
cargo fuzz build and cargo fuzz run must be executed with fuzz/
(or deeper) as the working directory so rustup selects the pinned
nightly toolchain — the detached runner handles that itself.
# build (nightly, pinned by rust-toolchain.toml inside fuzz/; run from fuzz/)
cargo fuzz build
# agent sessions: detached campaign (never foreground; CWD-independent)
FUZZ_RUNTIME_SECS=600 fuzz/run-detached.sh chunk_header
FUZZ_RUNTIME_SECS=600 fuzz/run-detached.sh envelope_frame -max_len=65536 -dict=json.dict
# corpus replay through the invariants (stable toolchain, no nightly)
cargo test --manifest-path fuzz/shared/Cargo.toml
# coverage
cargo fuzz coverage <target>
The fuzz workspace is excluded from the main workspace and from the
published package (exclude in the root Cargo.toml); it pins its own
nightly toolchain via rust-toolchain.toml and does not affect the
crate's stable MSRV.