- fuzz/ workspace (nightly-pinned via rust-toolchain.toml, excluded from the main workspace and the published package): chunk_header and envelope_frame targets per fuzzing.md \u00a77.1 - invariant logic in fuzz/shared (stable-toolchain crate): committed corpus replay as plain cargo test (quinn CI pattern, \u00a77.2 tier 3) - envelope target adds FrameError shape-partition asserts, exact consumption accounting, structural write_frame round-trip, serde key-contract, and a trailing-byte probe (prefix counts body only) - chunk_header target adds round-trip identity, TooLarge/short error shape, is_eof, 8-byte consumption, input-never-mutated - committed seed corpora: 245 deterministic seeds via fuzz/gen_fuzz_seeds.py (truncations, len=0/MAX+1/u32::MAX, channel 0, invalid UTF-8, deep nesting); grown corpora + artifacts gitignored - fuzz/run-detached.sh: \u00a77.6 detached runner (setsid+nohup+log, fork mode, rss/malloc limits) \u2014 campaigns never share fate with a session - fuzz/json.dict; README; research doc \u00a77.7 records step-1 status Verification: cargo fuzz build clean; stable side green (cargo test 682 passed, clippy -D warnings, fmt --check incl. fuzz/shared); corpus replay 245 seeds green; detached 10-min campaigns on both targets completed with zero crashes/OOMs/timeouts
29 lines
1.1 KiB
Bash
Executable File
29 lines
1.1 KiB
Bash
Executable File
#!/usr/bin/env bash
|
|
# Detached fuzzing runner for agent sessions: the fuzz campaign never
|
|
# runs as a foreground child of the session (OOM in a target must not
|
|
# take down the agent host), and survives the session ending.
|
|
#
|
|
# Usage: fuzz/run-detached.sh <target> [extra libfuzzer args...]
|
|
# (works from the repo root or from fuzz/; CWD-independent)
|
|
# FUZZ_RUNTIME_SECS overrides the per-campaign budget (default 600 s).
|
|
#
|
|
# Poll instead of waiting:
|
|
# tail -n 50 fuzz/artifacts/<target>-*.log
|
|
# ls fuzz/artifacts/<target>/ (crash-* / oom-* / timeout-* files)
|
|
# pgrep -f "cargo fuzz run <target>"
|
|
set -euo pipefail
|
|
target="${1:?usage: run-detached.sh <target> [extra libfuzzer args...]}"
|
|
shift
|
|
|
|
root="$(git rev-parse --show-toplevel)"
|
|
fuzz_dir="$root/fuzz"
|
|
mkdir -p "$fuzz_dir/artifacts"
|
|
runtime="${FUZZ_RUNTIME_SECS:-600}"
|
|
log="$fuzz_dir/artifacts/${target}-$(date -u +%Y%m%d-%H%M%S).log"
|
|
|
|
cd "$fuzz_dir"
|
|
setsid nohup cargo fuzz run "$target" -- \
|
|
-fork=1 -rss_limit_mb=2048 -malloc_limit_mb=2048 -timeout=25 \
|
|
-max_total_time="$runtime" "$@" \
|
|
>"$log" 2>&1 < /dev/null &
|
|
echo "pid=$! log=$log" |