Target 4 from the fuzzing plan (the alkcall-bug-class hunt): a #[derive(Arbitrary)] op sequence drives the producer session pump (drive_session_pre_negotiated) over a duplex pair against a fuzz-local mock backend. - fuzz/shared/src/session_opseq.rs: op vocabulary (client writes incl. invalid-type/oversize-length barrier probes, backend production/EOF, exit resolve/fail/drop, control messages, bounded reads, yields), kill-guard exit future (ADR-005 observability), delivery model, and the invariants: kill-on-Drop (kill_fired == !exit_resolved), exit chunk is last with first-issued code -1 on wait-failure (ADR-004), lossless per-stream FIFO + single stdout sentinel, stdin prefix-losslessness (post-shutdown chunks never delivered), control dispatch bounds, take-once allocation, teardown termination. - Harness-model correction caught by a 60s smoke run before the campaign (the alkcall §7.7 pattern, third time): a failed client write can mean the session completed and dropped the server duplex half while the write was in flight - the harness now drains and requires the exit chunk on any write/shutdown error (premature close without it is a finding). No adapter code changed. - 12 committed seeds via the deterministic generator, hand-encoded against the arbitrary 1.4.x derive layout; the encoding is pinned by a seed-decode test. Existing chunk_frame/negotiation_frame/ control_json seed corpora are byte-identical to before. - fuzz/.gitignore: the per-target seed negations never matched (corpus/* excludes the parent dir; git cannot re-include beneath an excluded dir). Fixed with the !corpus/*/ + corpus/*/* + !corpus/*/seed-* recipe - new seed files were silently ignored until now. - Campaign: 10 min detached via run-detached.sh, exited 0, artifact dir empty - 42.3k execs across 33 fork jobs, 0 crash/oom/timeout, cov 3934 -> 4075 edges. Grown corpus excised per the corpus policy. Verification: corpus replay green on stable (9 tests), cargo test 113 + --all-features 156, clippy stable/wasm/fuzz-shared, fmt, doc, publish dry-run, wasm check - all pass.
45 lines
688 B
TOML
45 lines
688 B
TOML
[package]
|
|
name = "alktty-fuzz"
|
|
version = "0.0.0"
|
|
publish = false
|
|
edition = "2021"
|
|
|
|
[package.metadata]
|
|
cargo-fuzz = true
|
|
|
|
[dependencies]
|
|
libfuzzer-sys = "0.4"
|
|
alktty-fuzz-shared = { path = "shared" }
|
|
|
|
[dependencies.alktty]
|
|
path = ".."
|
|
|
|
[[bin]]
|
|
name = "chunk_frame"
|
|
path = "fuzz_targets/chunk_frame.rs"
|
|
test = false
|
|
doc = false
|
|
bench = false
|
|
|
|
[[bin]]
|
|
name = "negotiation_frame"
|
|
path = "fuzz_targets/negotiation_frame.rs"
|
|
test = false
|
|
doc = false
|
|
bench = false
|
|
|
|
[[bin]]
|
|
name = "control_json"
|
|
path = "fuzz_targets/control_json.rs"
|
|
test = false
|
|
doc = false
|
|
bench = false
|
|
|
|
[[bin]]
|
|
name = "session_opseq"
|
|
path = "fuzz_targets/session_opseq.rs"
|
|
test = false
|
|
doc = false
|
|
bench = false
|
|
|
|
[workspace] |