diff --git a/.gitignore b/.gitignore index ed2d55c..260b9aa 100644 --- a/.gitignore +++ b/.gitignore @@ -1,3 +1,12 @@ target/ node_modules/ -.worktrees/ \ No newline at end of file +.worktrees/ + +fuzz/target/ +fuzz/artifacts/ +fuzz/coverage/ +# Grown corpora: the hash-named files the campaigns drop into +# fuzz/corpus// are gitignored (the quinn/h2 policy); the +# committed seeds are the seed-* files, kept via the per-dir +# .gitignore un-ignores. +fuzz/corpus/*/[0-9a-f][0-9a-f]* \ No newline at end of file diff --git a/AGENTS.md b/AGENTS.md index 031f7c2..61be3ef 100644 --- a/AGENTS.md +++ b/AGENTS.md @@ -165,8 +165,18 @@ cargo clippy --all-targets -- -D warnings cargo doc --no-deps # if docs changed cargo build --target wasm32-unknown-unknown --release # if layout/wasm-relevant code changed cargo publish --dry-run --allow-dirty # before a release +cargo test --manifest-path fuzz/shared/Cargo.toml # fuzz corpus replay (the fuzz gate) ``` +The corpus replay is the standing fuzz gate (the alkcall +`docs/research/fuzzing.md` §7.9 posture): it replays every committed +seed through the same invariant functions the fuzz targets run, on +stable, without nightly. Campaigns (nightly, cargo-fuzz) run manually +via `fuzz/run-detached.sh` — never as a foreground child of an agent +session — before releases, after touching `src/data_access.rs`, +`src/schema.rs`, the compile walks, or the sequential reader. See +`docs/plans/fuzzing.md` and `fuzz/README.md`. + ## Architecture Context - `docs/architecture/` — the authoritative spec. Read it before diff --git a/Cargo.toml b/Cargo.toml index 9e5c9bb..4387eff 100644 --- a/Cargo.toml +++ b/Cargo.toml @@ -9,11 +9,15 @@ repository = "https://git.alk.dev/alkdev/alktype" readme = "README.md" keywords = ["binary", "jsonschema", "wire-format", "serialization", "layout"] categories = ["encoding", "data-structures", "parsing"] -exclude = [".opencode/", "docs/reviews/", "docs/research/", "docs/sdd_process.md", "Cargo.lock", "AGENTS.md"] +exclude = [".opencode/", "docs/reviews/", "docs/research/", "docs/sdd_process.md", "Cargo.lock", "AGENTS.md", "fuzz/"] [lib] name = "alktype" +[workspace] +members = ["."] +exclude = ["fuzz"] + [features] default = [] diff --git a/fuzz/Cargo.lock b/fuzz/Cargo.lock new file mode 100644 index 0000000..3014b5f --- /dev/null +++ b/fuzz/Cargo.lock @@ -0,0 +1,1049 @@ +# This file is automatically @generated by Cargo. +# It is not intended for manual editing. +version = 4 + +[[package]] +name = "ahash" +version = "0.8.12" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "5a15f179cd60c4584b8a8c596927aadc462e27f2ca70c04e0071964a73ba7a75" +dependencies = [ + "cfg-if", + "getrandom 0.3.4", + "once_cell", + "serde", + "version_check", + "zerocopy", +] + +[[package]] +name = "aho-corasick" +version = "1.1.5" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "c982642fa9e8606056828ee9a8505737230110bb1099153c79efe865c59d12ba" +dependencies = [ + "memchr", +] + +[[package]] +name = "alktype" +version = "0.3.0" +dependencies = [ + "jsonschema", + "serde_json", +] + +[[package]] +name = "alktype-fuzz" +version = "0.0.0" +dependencies = [ + "alktype", + "alktype-fuzz-shared", + "libfuzzer-sys", +] + +[[package]] +name = "alktype-fuzz-shared" +version = "0.0.0" +dependencies = [ + "alktype", + "arbitrary", + "serde_json", +] + +[[package]] +name = "allocator-api2" +version = "0.2.21" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "683d7910e743518b0e34f1186f92494becacb047c7b6bf616c96772180fef923" + +[[package]] +name = "arbitrary" +version = "1.4.2" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "c3d036a3c4ab069c7b410a2ce876bd74808d2d0888a82667669f8e783a898bf1" +dependencies = [ + "derive_arbitrary", +] + +[[package]] +name = "autocfg" +version = "1.5.1" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "f2032f911046de80f0a198e0901378627c33f59ea0ac00e363d481118bd70a53" + +[[package]] +name = "bit-set" +version = "0.8.0" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "08807e080ed7f9d5433fa9b275196cfc35414f66a0c79d864dc51a0d825231a3" +dependencies = [ + "bit-vec", +] + +[[package]] +name = "bit-vec" +version = "0.8.0" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "5e764a1d40d510daf35e07be9eb06e75770908c27d411ee6c92109c9840eaaf7" + +[[package]] +name = "bitflags" +version = "2.13.2" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "3ded4057c258ba199e2d26386d3af3780957ecaee6c4ef4041c6b4b8b97c0b06" + +[[package]] +name = "borrow-or-share" +version = "0.2.4" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "dc0b364ead1874514c8c2855ab558056ebfeb775653e7ae45ff72f28f8f3166c" + +[[package]] +name = "bumpalo" +version = "3.20.3" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "72f5acc6cb2ba439de613abc23857ec3d78374d8ed5ac84e9d11336e87da8649" + +[[package]] +name = "bytecount" +version = "0.6.9" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "175812e0be2bccb6abe50bb8d566126198344f707e304f45c648fd8f2cc0365e" + +[[package]] +name = "cc" +version = "1.5.1" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "f360145194ee8e21db5ee7f3fcd4fe52210864c75c985dae33218202c8bbe040" +dependencies = [ + "find-msvc-tools", + "jobserver", + "libc", + "shlex", +] + +[[package]] +name = "cfg-if" +version = "1.0.5" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "4e7648175b45a9a48536d676f68d918270699102aa8dab5496df06904c914600" + +[[package]] +name = "data-encoding" +version = "2.11.1" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "4583a4551df46e2792f82ceeac45e850d2e2d5debba0b91f102385cda5b11f06" + +[[package]] +name = "derive_arbitrary" +version = "1.4.2" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "1e567bd82dcff979e4b03460c307b3cdc9e96fde3d73bed1496d2bc75d9dd62a" +dependencies = [ + "proc-macro2", + "quote", + "syn 2.0.119", +] + +[[package]] +name = "displaydoc" +version = "0.2.7" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "c6232dd377dcc64799954cbd3a9bb882e9cdc1308ccd87b1c098f1fb2eaf82a8" +dependencies = [ + "proc-macro2", + "quote", + "syn 3.0.6", +] + +[[package]] +name = "email_address" +version = "0.2.9" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "e079f19b08ca6239f47f8ba8509c11cf3ea30095831f7fed61441475edd8c449" +dependencies = [ + "serde", +] + +[[package]] +name = "equivalent" +version = "1.0.2" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "877a4ace8713b0bcf2a4e7eec82529c029f1d0619886d18145fea96c3ffe5c0f" + +[[package]] +name = "fancy-regex" +version = "0.18.0" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "e1e1dacd0d2082dfcf1351c4bdd566bbe89a2b263235a2b50058f1e130a47277" +dependencies = [ + "bit-set", + "regex-automata", + "regex-syntax", +] + +[[package]] +name = "find-msvc-tools" +version = "0.1.14" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "aedcfb3409746eddb02b9e19ebda1c3394f759a152e48ee875a0844d1b955484" + +[[package]] +name = "fluent-uri" +version = "0.4.1" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "bc74ac4d8359ae70623506d512209619e5cf8f347124910440dbc221714b328e" +dependencies = [ + "borrow-or-share", + "ref-cast", + "serde", +] + +[[package]] +name = "foldhash" +version = "0.2.0" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "77ce24cb58228fbb8aa041425bb1050850ac19177686ea6e0f41a70416f56fdb" + +[[package]] +name = "fraction" +version = "0.15.4" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "e076045bb43dac435333ed5f04caf35c7463631d0dae2deb2638d94dd0a5b872" +dependencies = [ + "lazy_static", + "num", +] + +[[package]] +name = "getrandom" +version = "0.3.4" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "899def5c37c4fd7b2664648c28120ecec138e4d395b459e5ca34f9cce2dd77fd" +dependencies = [ + "cfg-if", + "js-sys", + "libc", + "r-efi 5.3.0", + "wasip2", + "wasm-bindgen", +] + +[[package]] +name = "getrandom" +version = "0.4.3" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "300e883d756b2e4ec94e02791f39b04b522276138852cfc41d9fb7e904106099" +dependencies = [ + "cfg-if", + "libc", + "r-efi 6.0.0", +] + +[[package]] +name = "hashbrown" +version = "0.16.1" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "841d1cc9bed7f9236f321df977030373f4a4163ae1a7dbfe1a51a2c1a51d9100" +dependencies = [ + "allocator-api2", + "equivalent", + "foldhash", +] + +[[package]] +name = "hashbrown" +version = "0.17.1" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "ed5909b6e89a2db4456e54cd5f673791d7eca6732202bbf2a9cc504fe2f9b84a" + +[[package]] +name = "icu_collections" +version = "2.3.0" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "fa68d21081c4a05d5a901a1c62add574c77048b6a1c67be3b50ce0b60d4ca513" +dependencies = [ + "displaydoc", + "potential_utf", + "utf8_iter", + "yoke", + "zerofrom", + "zerovec", +] + +[[package]] +name = "icu_locale_core" +version = "2.3.0" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "d56e28588da92eee5c3201a6eff33fabdd49b62269c8938d4ff050ce4d900deb" +dependencies = [ + "displaydoc", + "litemap", + "tinystr", + "writeable", + "zerovec", +] + +[[package]] +name = "icu_normalizer" +version = "2.3.0" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "12f9cf5f235641ed274641dd81c3f28d870e276763d0797aeeab72317b1c646f" +dependencies = [ + "icu_collections", + "icu_normalizer_data", + "icu_properties", + "icu_provider", + "smallvec", + "zerovec", +] + +[[package]] +name = "icu_normalizer_data" +version = "2.3.0" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "1563da1ed3e0b3bf3d74c9b85917ac9c56464d2f57242270c09c9e752f8021a0" + +[[package]] +name = "icu_properties" +version = "2.3.0" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "7e7ca276ad3145661a65914e6daf131ca5120cd3dcee8f8f3214b8875184a148" +dependencies = [ + "displaydoc", + "icu_collections", + "icu_locale_core", + "icu_properties_data", + "icu_provider", + "zerotrie", + "zerovec", +] + +[[package]] +name = "icu_properties_data" +version = "2.3.0" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "e590f038c1464a96894fd6d10127e90a8be4509f56ff7ecef851b15cee0b7caa" + +[[package]] +name = "icu_provider" +version = "2.3.1" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "d27bbb9d3abbefac45d55f647c9de1d44aafcd1186eb91879afef17c396c3e73" +dependencies = [ + "displaydoc", + "icu_locale_core", + "writeable", + "yoke", + "zerofrom", + "zerotrie", + "zerovec", +] + +[[package]] +name = "idna" +version = "1.1.0" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "3b0875f23caa03898994f6ddc501886a45c7d3d62d04d2d90788d47be1b1e4de" +dependencies = [ + "idna_adapter", + "smallvec", + "utf8_iter", +] + +[[package]] +name = "idna_adapter" +version = "1.2.2" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "cb68373c0d6620ef8105e855e7745e18b0d00d3bdb07fb532e434244cdb9a714" +dependencies = [ + "icu_normalizer", + "icu_properties", +] + +[[package]] +name = "indexmap" +version = "2.14.2" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "cc4e190f5d26ca7051642629da2c52fc03bde85a03197c99408dcd291734c855" +dependencies = [ + "equivalent", + "hashbrown 0.17.1", +] + +[[package]] +name = "itoa" +version = "1.0.18" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "8f42a60cbdf9a97f5d2305f08a87dc4e09308d1276d28c869c684d7777685682" + +[[package]] +name = "jobserver" +version = "0.1.35" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "1c00acbd29eabad4a2392fa0e921c874934dbbf4194312ad20f04a0ed67a3cb3" +dependencies = [ + "getrandom 0.4.3", + "libc", +] + +[[package]] +name = "js-sys" +version = "0.3.106" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "7883d941dae510fb2d978fc3fe018c71c9e2892fd38854de3e8b92c2e5ad9cc5" +dependencies = [ + "cfg-if", + "wasm-bindgen", +] + +[[package]] +name = "jsonschema" +version = "0.46.10" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "f0a699d3e77675e6aa4bfffe3b907c8b5f7ed3241f9965bffb25475ad4b08d05" +dependencies = [ + "ahash", + "bytecount", + "data-encoding", + "email_address", + "fancy-regex", + "fraction", + "getrandom 0.3.4", + "idna", + "itoa", + "jsonschema-regex", + "num-cmp", + "num-traits", + "percent-encoding", + "referencing", + "regex", + "serde", + "serde_json", + "unicode-general-category", + "uuid-simd", +] + +[[package]] +name = "jsonschema-regex" +version = "0.46.10" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "6dbd1086b01b9349fd4ef9a07433965af64c8ce8159abe633a189e4ff817bd13" +dependencies = [ + "regex-syntax", +] + +[[package]] +name = "lazy_static" +version = "1.5.0" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "bbd2bcb4c963f2ddae06a2efc7e9f3591312473c50c6685e1f298068316e66fe" + +[[package]] +name = "libc" +version = "0.2.189" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "3eaf3ede3fee6db1a4c2ee091bf8a8b4dccdc6d17f656fb07896ee72867612f2" + +[[package]] +name = "libfuzzer-sys" +version = "0.4.13" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "a9fd2f41a1cba099f79a0b6b6c35656cf7c03351a7bae8ff0f28f25270f929d2" +dependencies = [ + "arbitrary", + "cc", +] + +[[package]] +name = "litemap" +version = "0.8.3" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "47d9d19d1d6efa0109d2f65ff4c85cddd50bd572e5a00127ab10987290bcefae" + +[[package]] +name = "lock_api" +version = "0.4.14" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "224399e74b87b5f3557511d98dff8b14089b3dadafcab6bb93eab67d3aace965" +dependencies = [ + "scopeguard", +] + +[[package]] +name = "memchr" +version = "2.8.3" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "cf8baf1c55e62ffcace7a9f06f4bd9cd3f0c4beb022d3b367256b91b87513d98" + +[[package]] +name = "micromap" +version = "0.3.0" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "c2a86d3146ed3995b5913c414f6664344b9617457320782e64f0bb44afd49d74" + +[[package]] +name = "num" +version = "0.4.3" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "35bd024e8b2ff75562e5f34e7f4905839deb4b22955ef5e73d2fea1b9813cb23" +dependencies = [ + "num-bigint", + "num-complex", + "num-integer", + "num-iter", + "num-rational", + "num-traits", +] + +[[package]] +name = "num-bigint" +version = "0.4.8" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "c89e69e7e0f03bea5ef08013795c25018e101932225a656383bd384495ecc367" +dependencies = [ + "num-integer", + "num-traits", +] + +[[package]] +name = "num-cmp" +version = "0.1.0" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "63335b2e2c34fae2fb0aa2cecfd9f0832a1e24b3b32ecec612c3426d46dc8aaa" + +[[package]] +name = "num-complex" +version = "0.4.6" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "73f88a1307638156682bada9d7604135552957b7818057dcef22705b4d509495" +dependencies = [ + "num-traits", +] + +[[package]] +name = "num-integer" +version = "0.1.47" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "7ce2d95d4b3734dc35aa2f45e1aa22cd416814592a4f9d9205e11affd5b8e10b" +dependencies = [ + "num-traits", +] + +[[package]] +name = "num-iter" +version = "0.1.46" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "c92800bd69a1eac91786bcfe9da64a897eb72911b8dc3095decbd07429e8048b" +dependencies = [ + "num-integer", + "num-traits", +] + +[[package]] +name = "num-rational" +version = "0.4.2" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "f83d14da390562dca69fc84082e73e548e1ad308d24accdedd2720017cb37824" +dependencies = [ + "num-bigint", + "num-integer", + "num-traits", +] + +[[package]] +name = "num-traits" +version = "0.2.19" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "071dfc062690e90b734c0b2273ce72ad0ffa95f0c74596bc250dcfd960262841" +dependencies = [ + "autocfg", +] + +[[package]] +name = "once_cell" +version = "1.21.4" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "9f7c3e4beb33f85d45ae3e3a1792185706c8e16d043238c593331cc7cd313b50" + +[[package]] +name = "outref" +version = "0.5.2" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "1a80800c0488c3a21695ea981a54918fbb37abf04f4d0720c453632255e2ff0e" + +[[package]] +name = "parking_lot" +version = "0.12.5" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "93857453250e3077bd71ff98b6a65ea6621a19bb0f559a85248955ac12c45a1a" +dependencies = [ + "lock_api", + "parking_lot_core", +] + +[[package]] +name = "parking_lot_core" +version = "0.9.12" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "2621685985a2ebf1c516881c026032ac7deafcda1a2c9b7850dc81e3dfcb64c1" +dependencies = [ + "cfg-if", + "libc", + "redox_syscall", + "smallvec", + "windows-link", +] + +[[package]] +name = "percent-encoding" +version = "2.3.2" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "9b4f627cb1b25917193a259e49bdad08f671f8d9708acfd5fe0a8c1455d87220" + +[[package]] +name = "potential_utf" +version = "0.1.6" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "d83eb9bc6d8e5cf568e7a1101d60ee05e81ed50ea106026f3d18deeb046d7661" +dependencies = [ + "zerovec", +] + +[[package]] +name = "proc-macro2" +version = "1.0.107" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "985e7ec9bb745e6ce6535b544d84d6cd6f7ad8bd711c398938ae983b91a766d9" +dependencies = [ + "unicode-ident", +] + +[[package]] +name = "quote" +version = "1.0.47" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "1fbf4db142a473a8d80c26bbf18454ed458bf8d26c8219c331daecfdbd079001" +dependencies = [ + "proc-macro2", +] + +[[package]] +name = "r-efi" +version = "5.3.0" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "69cdb34c158ceb288df11e18b4bd39de994f6657d83847bdffdbd7f346754b0f" + +[[package]] +name = "r-efi" +version = "6.0.0" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "f8dcc9c7d52a811697d2151c701e0d08956f92b0e24136cf4cf27b57a6a0d9bf" + +[[package]] +name = "redox_syscall" +version = "0.5.18" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "ed2bf2547551a7053d6fdfafda3f938979645c44812fbfcda098faae3f1a362d" +dependencies = [ + "bitflags", +] + +[[package]] +name = "ref-cast" +version = "1.0.27" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "7e440fb4e4b4147295338efb76001ab9e4efc0e5839df2c47fc5ac2381d365c3" +dependencies = [ + "ref-cast-impl", +] + +[[package]] +name = "ref-cast-impl" +version = "1.0.27" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "92ecd8964f8453721699a1ed72037b0db49ce2f5a5138486ee89bed6f67cdf3a" +dependencies = [ + "proc-macro2", + "quote", + "syn 3.0.6", +] + +[[package]] +name = "referencing" +version = "0.46.10" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "0fbf332a2f81899f6836f22c03da73dae8a664c32e3016b84692c23cddadc95d" +dependencies = [ + "ahash", + "fluent-uri", + "getrandom 0.3.4", + "hashbrown 0.16.1", + "itoa", + "micromap", + "parking_lot", + "percent-encoding", + "serde_json", +] + +[[package]] +name = "regex" +version = "1.13.1" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "f020237b6c8eed93db2e2cb53c00c60a8e1bc73da7d073199a1180401450218d" +dependencies = [ + "aho-corasick", + "memchr", + "regex-automata", + "regex-syntax", +] + +[[package]] +name = "regex-automata" +version = "0.4.18" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "ad8553b9b26413251cbf30e620595c7a41b3887f03da04579c0e6b0d6a06b4b2" +dependencies = [ + "aho-corasick", + "memchr", + "regex-syntax", +] + +[[package]] +name = "regex-syntax" +version = "0.8.11" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "d6f6ff9a378485b298a5286656da665ba74413d36db0979633275d2e708145d4" + +[[package]] +name = "rustversion" +version = "1.0.23" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "cf54715a573b99ac80df0bc206da022bcd442c974952c7b9720069370852e21f" + +[[package]] +name = "scopeguard" +version = "1.2.0" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "94143f37725109f92c262ed2cf5e59bce7498c01bcc1502d7b9afe439a4e9f49" + +[[package]] +name = "serde" +version = "1.0.229" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "4148590afebada386688f18773da617792bf2ef03ffc1e4cbd2b1d45b023e0ba" +dependencies = [ + "serde_core", + "serde_derive", +] + +[[package]] +name = "serde_core" +version = "1.0.229" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "67dca2c9c51e58a4791a4b1ed58308b39c64224d349a935ab5039aa360942a48" +dependencies = [ + "serde_derive", +] + +[[package]] +name = "serde_derive" +version = "1.0.229" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "e7a5d71263a5a7d47b41f6b3f06ba276f10cc18b0931f1799f710578e2309348" +dependencies = [ + "proc-macro2", + "quote", + "syn 3.0.6", +] + +[[package]] +name = "serde_json" +version = "1.0.151" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "c841b55ecdae098c80dcae9cf767f6f8a0c2cdb3416bbef72181df4d0fe73f14" +dependencies = [ + "indexmap", + "itoa", + "memchr", + "serde", + "serde_core", + "zmij", +] + +[[package]] +name = "shlex" +version = "2.0.1" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "f8fadd59c855ef2080decdef8ff161eb6661b86933c9d82e5ba29dc602a55aba" + +[[package]] +name = "smallvec" +version = "1.16.2" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "f9395f0f0eee849a9b707b2f06bb92a6a422090e2123bb2ef8e87a0e61892a8e" + +[[package]] +name = "stable_deref_trait" +version = "1.2.1" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "6ce2be8dc25455e1f91df71bfa12ad37d7af1092ae736f3a6cd0e37bc7810596" + +[[package]] +name = "syn" +version = "2.0.119" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "872831b642d1a07999a962a351ed35b955ea2cfc8f3862091e2a240a84f17297" +dependencies = [ + "proc-macro2", + "quote", + "unicode-ident", +] + +[[package]] +name = "syn" +version = "3.0.6" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "8593e8e72159ed2257d083c7a454a85cbf854f37a0966d8d483aff8c8a3ebcee" +dependencies = [ + "proc-macro2", + "quote", + "unicode-ident", +] + +[[package]] +name = "synstructure" +version = "0.14.0" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "901704edd0dfe137f1987838ee4f259e4e063c31371bdb423f7ae38ec6f77f02" +dependencies = [ + "proc-macro2", + "quote", + "syn 3.0.6", +] + +[[package]] +name = "tinystr" +version = "0.8.4" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "b1e27c91459209c2986af3dcf603a5a74a4368754ce37414f59acc971167f643" +dependencies = [ + "displaydoc", + "zerovec", +] + +[[package]] +name = "unicode-general-category" +version = "1.1.0" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "0b993bddc193ae5bd0d623b49ec06ac3e9312875fdae725a975c51db1cc1677f" + +[[package]] +name = "unicode-ident" +version = "1.0.26" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "d245f478577f809a851594d02313b640fb437e0bb33866753cff937863096954" + +[[package]] +name = "utf8_iter" +version = "1.0.4" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "b6c140620e7ffbb22c2dee59cafe6084a59b5ffc27a8859a5f0d494b5d52b6be" + +[[package]] +name = "uuid-simd" +version = "0.8.0" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "23b082222b4f6619906941c17eb2297fff4c2fb96cb60164170522942a200bd8" +dependencies = [ + "outref", + "vsimd", +] + +[[package]] +name = "version_check" +version = "0.9.5" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "0b928f33d975fc6ad9f86c8f283853ad26bdd5b10b7f1542aa2fa15e2289105a" + +[[package]] +name = "vsimd" +version = "0.8.0" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "5c3082ca00d5a5ef149bb8b555a72ae84c9c59f7250f013ac822ac2e49b19c64" + +[[package]] +name = "wasip2" +version = "1.0.4+wasi-0.2.12" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "b67efb37e106e55ce722a510d6b5f9c17f083e5fc79afc2badeb12cc313d9487" +dependencies = [ + "wit-bindgen", +] + +[[package]] +name = "wasm-bindgen" +version = "0.2.129" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "9bb54f33acc68fd454578d9820b0bde1a1a3d17aa17bb7b6595806d02886d409" +dependencies = [ + "cfg-if", + "once_cell", + "rustversion", + "wasm-bindgen-macro", + "wasm-bindgen-shared", +] + +[[package]] +name = "wasm-bindgen-macro" +version = "0.2.129" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "2e29d0c35b16e224a7eeb5cd2d25e3e1968fbd65604117b44d3b789d00ee8535" +dependencies = [ + "quote", + "wasm-bindgen-macro-support", +] + +[[package]] +name = "wasm-bindgen-macro-support" +version = "0.2.129" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "6f501a8bc3719dba86ef8ae4728879c08001bea749eb1333ac5b91e040e2a6b7" +dependencies = [ + "bumpalo", + "proc-macro2", + "quote", + "syn 3.0.6", + "wasm-bindgen-shared", +] + +[[package]] +name = "wasm-bindgen-shared" +version = "0.2.129" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "23f0c9c52aa7cd7d77769a4cfe2a9adb1b331f489a41d912ce14513d5ab995c6" +dependencies = [ + "unicode-ident", +] + +[[package]] +name = "windows-link" +version = "0.2.1" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "f0805222e57f7521d6a62e36fa9163bc891acd422f971defe97d64e70d0a4fe5" + +[[package]] +name = "wit-bindgen" +version = "0.57.1" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "1ebf944e87a7c253233ad6766e082e3cd714b5d03812acc24c318f549614536e" + +[[package]] +name = "writeable" +version = "0.6.4" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "3ad82d2a33cdc9674dc7465672f271e096168fcdbe0f799d9e6db8c5892679dc" + +[[package]] +name = "yoke" +version = "0.8.3" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "709fe23a0424b6a435d82152b1bd3fdfb0833487d5fa90d05d42762a9891fef5" +dependencies = [ + "stable_deref_trait", + "yoke-derive", + "zerofrom", +] + +[[package]] +name = "yoke-derive" +version = "0.8.3" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "33811428bee40dbceb6d545e95754741d17a6aef9a4849f0fd62e2ba4f412a78" +dependencies = [ + "proc-macro2", + "quote", + "syn 3.0.6", + "synstructure", +] + +[[package]] +name = "zerocopy" +version = "0.8.59" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "6df92bf3d9227be3d53173901ddbffac2babc27ae50f397776ffd6dc33f800cb" +dependencies = [ + "zerocopy-derive", +] + +[[package]] +name = "zerocopy-derive" +version = "0.8.59" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "ac4f328cf2f05d084e496c3e9c3f33ed0a183656a16e1fcec4d464d8373aec82" +dependencies = [ + "proc-macro2", + "quote", + "syn 2.0.119", +] + +[[package]] +name = "zerofrom" +version = "0.1.8" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "0ec05a11813ea801ff6d75110ad09cd0824ddba17dfe17128ea0d5f68e6c5272" +dependencies = [ + "zerofrom-derive", +] + +[[package]] +name = "zerofrom-derive" +version = "0.1.8" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "f75b4683f6c7f45248d4d64056a24298c6281e0993356d7d1b4a1a962ef10d4a" +dependencies = [ + "proc-macro2", + "quote", + "syn 3.0.6", + "synstructure", +] + +[[package]] +name = "zerotrie" +version = "0.2.5" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "4ea269c3bd32f0a32c321907a2ae912ba6f4649bb0fc764a15627e99a7095a3f" +dependencies = [ + "displaydoc", + "yoke", + "zerofrom", +] + +[[package]] +name = "zerovec" +version = "0.11.8" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "bb0464e17806c1d976d5cba29399c7f08e516e279e2ba493f63123b5fca67dd8" +dependencies = [ + "yoke", + "zerofrom", + "zerovec-derive", +] + +[[package]] +name = "zerovec-derive" +version = "0.11.6" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "34df6fc39dbd26ddc9c10e6a2984476e13acce22e64e4487636ef494369225da" +dependencies = [ + "proc-macro2", + "quote", + "syn 3.0.6", +] + +[[package]] +name = "zmij" +version = "1.0.23" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "29666d0abbfad1e3dc4dcf6144730dd3a3ab225bbbdac83319345b1b44ccfc1b" diff --git a/fuzz/Cargo.toml b/fuzz/Cargo.toml new file mode 100644 index 0000000..16bc11e --- /dev/null +++ b/fuzz/Cargo.toml @@ -0,0 +1,31 @@ +[package] +name = "alktype-fuzz" +version = "0.0.0" +publish = false +edition = "2021" + +[package.metadata] +cargo-fuzz = true + +[dependencies] +libfuzzer-sys = "0.4" +alktype-fuzz-shared = { path = "shared" } + +[dependencies.alktype] +path = ".." + +[[bin]] +name = "bast_compile" +path = "fuzz_targets/bast_compile.rs" +test = false +doc = false +bench = false + +[[bin]] +name = "data_access" +path = "fuzz_targets/data_access.rs" +test = false +doc = false +bench = false + +[workspace] \ No newline at end of file diff --git a/fuzz/README.md b/fuzz/README.md new file mode 100644 index 0000000..16af51c --- /dev/null +++ b/fuzz/README.md @@ -0,0 +1,65 @@ +# alktype fuzzing + +cargo-fuzz targets for the binary struct engine's untrusted-input +surfaces. The design and operating rules live in +`docs/plans/fuzzing.md` (adopted from alkhttp's +`docs/plans/fuzzing.md`; rationale in alkcall's +`docs/research/fuzzing.md`) — this README is the operational +cheat-sheet. + +## Layout + +- `fuzz_targets/` — nightly-only `fuzz_target!` binaries (thin wrappers). +- `shared/` — stable-toolchain library holding the invariant logic; the + corpus replay tests run here on plain `cargo test`. +- `corpus//` — committed seeds (regenerate with + `python3 fuzz/gen_fuzz_seeds.py`). +- `artifacts/` — gitignored crash/oom/timeout artifacts + campaign logs. + +## Targets + +| Target | Drives | +|---|---| +| `bast_compile` | `AlkTypeEngine::compile` in both layout modes over attacker-shaped BAST JSON (the whole schema side through one choke point) + `validate_bast_doc` + `build_validator` | +| `data_access` | the hand-rolled decode core (`src/data_access.rs`): fixed-width kinds, bool strictness, length-prefixed and indirect string/bytes, enums — over raw bytes with attacker-chosen offsets and endianness | + +## Running a campaign — always detached + +Agent sessions must never run fuzzing in the foreground (an OOM in a +target can take down the session host; see docs/plans/fuzzing.md §2). +Use the detached runner: + +```bash +fuzz/run-detached.sh bast_compile +# poll: +tail -n 50 fuzz/artifacts/bast_compile-*.log +ls fuzz/artifacts/bast_compile/ +pgrep -f "cargo fuzz run bast_compile" +``` + +`FUZZ_RUNTIME_SECS=1800 fuzz/run-detached.sh bast_compile` for a longer +campaign. The runner pins `-fork=1 -rss_limit_mb=2048 +-malloc_limit_mb=2048 -timeout=25` and detaches via `setsid` + `nohup`. + +## Corpus replay (the standing fuzz gate) + +```bash +cargo test --manifest-path fuzz/shared/Cargo.toml +``` + +replays every committed seed through the same invariant functions the +fuzz targets run — on stable, without nightly, no cargo-fuzz. Part of +the release verification checklist (AGENTS.md). + +## Toolchain + +`fuzz/rust-toolchain.toml` pins nightly (+ `llvm-tools-preview`) for +this subtree only; the main crate stays stable at MSRV 1.85. `cargo +fuzz build` works from any CWD inside `fuzz/` (rustup resolves the +toolchain per directory). Build: + +```bash +cd fuzz && cargo fuzz build +# or from the repo root — the toolchain file is picked up by path: +cargo fuzz build -D +``` \ No newline at end of file diff --git a/fuzz/corpus/bast_compile/seed-000 b/fuzz/corpus/bast_compile/seed-000 new file mode 100644 index 0000000..d89da24 --- /dev/null +++ b/fuzz/corpus/bast_compile/seed-000 @@ -0,0 +1 @@ +{"$defs": {"S": {"kind": "struct", "fields": [{"name": "x", "kind": "uint8"}]}, "root": "S"}} \ No newline at end of file diff --git a/fuzz/corpus/bast_compile/seed-001 b/fuzz/corpus/bast_compile/seed-001 new file mode 100644 index 0000000..a3fcae7 --- /dev/null +++ b/fuzz/corpus/bast_compile/seed-001 @@ -0,0 +1 @@ +{"$defs": {"S": {"kind": "struct", "endian": "big", "fields": [{"name": "x", "kind": "uint8"}]}}} \ No newline at end of file diff --git a/fuzz/corpus/bast_compile/seed-002 b/fuzz/corpus/bast_compile/seed-002 new file mode 100644 index 0000000..7a9917b --- /dev/null +++ b/fuzz/corpus/bast_compile/seed-002 @@ -0,0 +1 @@ +{"$defs": {"S": {"kind": "struct", "fields": [{"name": "x", "kind": "uint8"}]}}} \ No newline at end of file diff --git a/fuzz/corpus/bast_compile/seed-003 b/fuzz/corpus/bast_compile/seed-003 new file mode 100644 index 0000000..355cd93 --- /dev/null +++ b/fuzz/corpus/bast_compile/seed-003 @@ -0,0 +1 @@ +{"$defs": {"S": {"kind": "struct", "fields": []}}} \ No newline at end of file diff --git a/fuzz/corpus/bast_compile/seed-004 b/fuzz/corpus/bast_compile/seed-004 new file mode 100644 index 0000000..f25bd6b --- /dev/null +++ b/fuzz/corpus/bast_compile/seed-004 @@ -0,0 +1 @@ +{"$defs": {"S": {"kind": "struct", "fields": [{"name": "f0", "kind": "int8"}, {"name": "f1", "kind": "int16"}, {"name": "f2", "kind": "int32"}, {"name": "f3", "kind": "int64"}, {"name": "f4", "kind": "uint8"}, {"name": "f5", "kind": "uint16"}, {"name": "f6", "kind": "uint32"}, {"name": "f7", "kind": "uint64"}, {"name": "f8", "kind": "float32"}, {"name": "f9", "kind": "float64"}, {"name": "f10", "kind": "bool"}, {"name": "f11", "kind": "string"}, {"name": "f12", "kind": "bytes"}]}}} \ No newline at end of file diff --git a/fuzz/corpus/bast_compile/seed-005 b/fuzz/corpus/bast_compile/seed-005 new file mode 100644 index 0000000..d910581 --- /dev/null +++ b/fuzz/corpus/bast_compile/seed-005 @@ -0,0 +1 @@ +{"$defs": {"S": {"kind": "struct", "endian": "little", "fields": [{"name": "a", "kind": "uint32", "endian": "big"}, {"name": "b", "kind": "string", "encoding": "length-prefixed", "maxLength": 64}, {"name": "c", "kind": "bytes", "encoding": "offset-indirect", "maxLength": 128}, {"name": "d", "kind": "string", "encoding": "offset-indirect"}]}}} \ No newline at end of file diff --git a/fuzz/corpus/bast_compile/seed-006 b/fuzz/corpus/bast_compile/seed-006 new file mode 100644 index 0000000..3649067 --- /dev/null +++ b/fuzz/corpus/bast_compile/seed-006 @@ -0,0 +1 @@ +{"$defs": {"S": {"kind": "struct", "fields": [{"name": "child", "kind": {"$ref": "#/$defs/Nested"}}, {"name": "arr", "kind": {"kind": "array", "element": "uint32", "count": 3}}, {"name": "arr0", "kind": {"kind": "array", "element": "uint8", "count": 0}}, {"name": "rec", "kind": {"kind": "record", "values": "string"}}, {"name": "en", "kind": {"$ref": "#/$defs/E"}}, {"name": "un", "kind": {"$ref": "#/$defs/U1"}}, {"name": "un2", "kind": {"$ref": "#/$defs/U2"}}]}, "Nested": {"kind": "struct", "fields": [{"name": "y", "kind": "int16"}]}, "E": {"kind": "enum", "values": ["a", "b", "c"]}, "U1": {"kind": "union", "discriminator": {"kind": "byte", "offset": 0, "type": "uint8"}, "mapping": {"0": "uint8", "1": {"$ref": "#/$defs/Nested"}}}, "U2": {"kind": "union", "discriminator": {"kind": "field", "name": "tag"}, "fields": [{"name": "tag", "kind": "uint32"}], "mapping": {"0": "uint8", "7": "string"}}}} \ No newline at end of file diff --git a/fuzz/corpus/bast_compile/seed-007 b/fuzz/corpus/bast_compile/seed-007 new file mode 100644 index 0000000..f017672 --- /dev/null +++ b/fuzz/corpus/bast_compile/seed-007 @@ -0,0 +1 @@ +{"$defs": {"S": {"kind": "struct", "fields": [{"name": "inl", "kind": {"kind": "struct", "fields": [{"name": "z", "kind": "uint8"}]}}, {"name": "inle", "kind": {"kind": "enum", "values": ["x"]}}]}}} \ No newline at end of file diff --git a/fuzz/corpus/bast_compile/seed-008 b/fuzz/corpus/bast_compile/seed-008 new file mode 100644 index 0000000..50630c0 --- /dev/null +++ b/fuzz/corpus/bast_compile/seed-008 @@ -0,0 +1 @@ +{"$defs": {"S": {"kind": "struct", "fields": [{"name": "l", "kind": {"$ref": "#/$defs/N"}}, {"name": "r", "kind": {"$ref": "#/$defs/N"}}]}, "N": {"kind": "struct", "fields": [{"name": "v", "kind": "uint8"}]}}} \ No newline at end of file diff --git a/fuzz/corpus/bast_compile/seed-009 b/fuzz/corpus/bast_compile/seed-009 new file mode 100644 index 0000000..aa91788 --- /dev/null +++ b/fuzz/corpus/bast_compile/seed-009 @@ -0,0 +1 @@ +{"$defs": {"S": {"kind": "struct", "fields": [{"name": "x", "kind": "uint8"}], "align": 4096}}} \ No newline at end of file diff --git a/fuzz/corpus/bast_compile/seed-010 b/fuzz/corpus/bast_compile/seed-010 new file mode 100644 index 0000000..f2b3d29 --- /dev/null +++ b/fuzz/corpus/bast_compile/seed-010 @@ -0,0 +1 @@ +{"$defs": {"S": {"kind": "struct", "fields": [{"name": "a", "kind": "uint32", "align": 16}, {"name": "b", "kind": "uint8", "align": 1}]}}} \ No newline at end of file diff --git a/fuzz/corpus/bast_compile/seed-011 b/fuzz/corpus/bast_compile/seed-011 new file mode 100644 index 0000000..ed2bb2c --- /dev/null +++ b/fuzz/corpus/bast_compile/seed-011 @@ -0,0 +1 @@ +{"$defs": {"S": {"kind": "struct", "fields": [{"name": "s", "kind": "string", "maxLength": 67108864}]}}} \ No newline at end of file diff --git a/fuzz/corpus/bast_compile/seed-012 b/fuzz/corpus/bast_compile/seed-012 new file mode 100644 index 0000000..c95af24 --- /dev/null +++ b/fuzz/corpus/bast_compile/seed-012 @@ -0,0 +1 @@ +{"$defs": {"S": {"kind": "struct", "fields": [{"name": "s", "kind": "string", "maxLength": 0}]}}} \ No newline at end of file diff --git a/fuzz/corpus/bast_compile/seed-013 b/fuzz/corpus/bast_compile/seed-013 new file mode 100644 index 0000000..7d11376 --- /dev/null +++ b/fuzz/corpus/bast_compile/seed-013 @@ -0,0 +1 @@ +{"$defs": {"S": {"kind": "struct", "align": 4097, "fields": []}}} \ No newline at end of file diff --git a/fuzz/corpus/bast_compile/seed-014 b/fuzz/corpus/bast_compile/seed-014 new file mode 100644 index 0000000..aa5c4b1 --- /dev/null +++ b/fuzz/corpus/bast_compile/seed-014 @@ -0,0 +1 @@ +{"$defs": {"S": {"kind": "struct", "align": 65536, "fields": []}}} \ No newline at end of file diff --git a/fuzz/corpus/bast_compile/seed-015 b/fuzz/corpus/bast_compile/seed-015 new file mode 100644 index 0000000..4312df0 --- /dev/null +++ b/fuzz/corpus/bast_compile/seed-015 @@ -0,0 +1 @@ +{"$defs": {"S": {"kind": "struct", "align": 18446744073709551615, "fields": []}}} \ No newline at end of file diff --git a/fuzz/corpus/bast_compile/seed-016 b/fuzz/corpus/bast_compile/seed-016 new file mode 100644 index 0000000..76a56cc --- /dev/null +++ b/fuzz/corpus/bast_compile/seed-016 @@ -0,0 +1 @@ +{"$defs": {"S": {"kind": "struct", "fields": [{"name": "a", "kind": {"kind": "array", "element": "uint8", "count": 65537}}]}}} \ No newline at end of file diff --git a/fuzz/corpus/bast_compile/seed-017 b/fuzz/corpus/bast_compile/seed-017 new file mode 100644 index 0000000..383e50d --- /dev/null +++ b/fuzz/corpus/bast_compile/seed-017 @@ -0,0 +1 @@ +{"$defs": {"S": {"kind": "struct", "fields": [{"name": "a", "kind": {"kind": "array", "element": "uint8", "count": 18446744073709551615}}]}}} \ No newline at end of file diff --git a/fuzz/corpus/bast_compile/seed-018 b/fuzz/corpus/bast_compile/seed-018 new file mode 100644 index 0000000..870f86a --- /dev/null +++ b/fuzz/corpus/bast_compile/seed-018 @@ -0,0 +1 @@ +{"$defs": {"S": {"kind": "struct", "fields": [{"name": "s", "kind": "string", "maxLength": 67108865}]}}} \ No newline at end of file diff --git a/fuzz/corpus/bast_compile/seed-019 b/fuzz/corpus/bast_compile/seed-019 new file mode 100644 index 0000000..3d158d6 --- /dev/null +++ b/fuzz/corpus/bast_compile/seed-019 @@ -0,0 +1 @@ +{"$defs": {"S": {"kind": "struct", "fields": [{"name": "x", "kind": "nonsense"}]}}} \ No newline at end of file diff --git a/fuzz/corpus/bast_compile/seed-020 b/fuzz/corpus/bast_compile/seed-020 new file mode 100644 index 0000000..4cbe145 --- /dev/null +++ b/fuzz/corpus/bast_compile/seed-020 @@ -0,0 +1 @@ +{"$defs": {"S": {"kind": "uint8", "fields": []}}} \ No newline at end of file diff --git a/fuzz/corpus/bast_compile/seed-021 b/fuzz/corpus/bast_compile/seed-021 new file mode 100644 index 0000000..4a8d5c5 --- /dev/null +++ b/fuzz/corpus/bast_compile/seed-021 @@ -0,0 +1 @@ +{"$defs": {"S": {"kind": "struct"}}} \ No newline at end of file diff --git a/fuzz/corpus/bast_compile/seed-022 b/fuzz/corpus/bast_compile/seed-022 new file mode 100644 index 0000000..fb34e6a --- /dev/null +++ b/fuzz/corpus/bast_compile/seed-022 @@ -0,0 +1 @@ +{"$defs": {"S": {"kind": "struct", "fields": [{"name": "a", "kind": {"$ref": "#/$defs/S"}}]}}} \ No newline at end of file diff --git a/fuzz/corpus/bast_compile/seed-023 b/fuzz/corpus/bast_compile/seed-023 new file mode 100644 index 0000000..641076a --- /dev/null +++ b/fuzz/corpus/bast_compile/seed-023 @@ -0,0 +1 @@ +{"$defs": {"S": {"kind": "struct", "fields": [{"name": "a", "kind": {"$ref": "#/$defs/Missing"}}]}}} \ No newline at end of file diff --git a/fuzz/corpus/bast_compile/seed-024 b/fuzz/corpus/bast_compile/seed-024 new file mode 100644 index 0000000..0816766 --- /dev/null +++ b/fuzz/corpus/bast_compile/seed-024 @@ -0,0 +1 @@ +{"$defs": {}} \ No newline at end of file diff --git a/fuzz/corpus/bast_compile/seed-025 b/fuzz/corpus/bast_compile/seed-025 new file mode 100644 index 0000000..6001c44 --- /dev/null +++ b/fuzz/corpus/bast_compile/seed-025 @@ -0,0 +1 @@ +[1, 2, 3] \ No newline at end of file diff --git a/fuzz/corpus/bast_compile/seed-026 b/fuzz/corpus/bast_compile/seed-026 new file mode 100644 index 0000000..9e26dfe --- /dev/null +++ b/fuzz/corpus/bast_compile/seed-026 @@ -0,0 +1 @@ +{} \ No newline at end of file diff --git a/fuzz/corpus/bast_compile/seed-027 b/fuzz/corpus/bast_compile/seed-027 new file mode 100644 index 0000000..09f6830 --- /dev/null +++ b/fuzz/corpus/bast_compile/seed-027 @@ -0,0 +1 @@ +{"$defs": {"S": {"kind": "struct", "fields": [{"name": "a", "kind": 123}]}}} \ No newline at end of file diff --git a/fuzz/corpus/bast_compile/seed-028 b/fuzz/corpus/bast_compile/seed-028 new file mode 100644 index 0000000..136411f --- /dev/null +++ b/fuzz/corpus/bast_compile/seed-028 @@ -0,0 +1 @@ +{"$defs": {"S": {"kind": "struct", "fields": [{"name": "9bad", "kind": "uint8"}]}}} \ No newline at end of file diff --git a/fuzz/corpus/bast_compile/seed-029 b/fuzz/corpus/bast_compile/seed-029 new file mode 100644 index 0000000..ba30848 --- /dev/null +++ b/fuzz/corpus/bast_compile/seed-029 @@ -0,0 +1 @@ +{"$defs": {"S": {"kind": "struct", "fields": [{"name": "a", "kind": "uint8", "bogus": true}]}}} \ No newline at end of file diff --git a/fuzz/corpus/bast_compile/seed-030 b/fuzz/corpus/bast_compile/seed-030 new file mode 100644 index 0000000..6d67b9f --- /dev/null +++ b/fuzz/corpus/bast_compile/seed-030 @@ -0,0 +1 @@ +{"$defs": {"S": {"kind": "union", "discriminator": {"kind": "byte", "offset": 0, "type": "uint8"}}}} \ No newline at end of file diff --git a/fuzz/corpus/bast_compile/seed-031 b/fuzz/corpus/bast_compile/seed-031 new file mode 100644 index 0000000..e7c3e7f --- /dev/null +++ b/fuzz/corpus/bast_compile/seed-031 @@ -0,0 +1 @@ +not json at all \ No newline at end of file diff --git a/fuzz/corpus/bast_compile/seed-032 b/fuzz/corpus/bast_compile/seed-032 new file mode 100644 index 0000000..e079260 --- /dev/null +++ b/fuzz/corpus/bast_compile/seed-032 @@ -0,0 +1 @@ +{"$defs": {"S": \ No newline at end of file diff --git a/fuzz/corpus/bast_compile/seed-033 b/fuzz/corpus/bast_compile/seed-033 new file mode 100644 index 0000000..716455d --- /dev/null +++ b/fuzz/corpus/bast_compile/seed-033 @@ -0,0 +1 @@ +{"$defs": {"S": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": []}}]}}]}}]}}]}}]}}]}}]}}]}}]}}]}}]}}]}}]}}]}}]}}]}}]}}]}}]}}]}}]}}]}}]}}]}}]}}]}}]}}]}}]}}]}}]}}]}}]}}]}}]}}]}}]}}]}}]}}]}}]}}]}}]}}]}}]}}]}}]}}]}}]}}]}}]}}]}}]}}]}}]}}]}}]}}]}}]}}]}}]}}]}}]}}]}}]}}]}}]}}]}}]}}]}}]}}]}}]}}]}}]}}]}}]}}]}}]}}]}}]}}]}}]}}]}}]}}]}}]}}]}}]}}]}}]}}]}}]}}]}}]}}]}}]}}]}}]}}]}}]}}]}}]}}]}}]}}]}}]}}]}}]}}]}}]}}]}}]}}]}}]}}]}}]}}]}}]}}]}}} \ No newline at end of file diff --git a/fuzz/corpus/bast_compile/seed-034 b/fuzz/corpus/bast_compile/seed-034 new file mode 100644 index 0000000..bf01eb6 --- /dev/null +++ b/fuzz/corpus/bast_compile/seed-034 @@ -0,0 +1 @@ +{"$defs": {"S": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": [{"name": "n", "kind": {"kind": "struct", "fields": []}}]}}]}}]}}]}}]}}]}}]}}]}}]}}]}}]}}]}}]}}]}}]}}]}}]}}]}}]}}]}}]}}]}}]}}]}}]}}]}}]}}]}}]}}]}}]}}]}}]}}]}}]}}]}}]}}]}}]}}]}}]}}]}}]}}]}}]}}]}}]}}]}}]}}]}}]}}]}}]}}]}}]}}]}}]}}]}}]}}]}}]}}]}}]}}]}}]}}]}}]}}]}}]}}]}}]}}]}}]}}]}}]}}]}}]}}]}}]}}]}}]}}]}}]}}]}}]}}]}}]}}]}}]}}]}}]}}]}}]}}]}}]}}]}}]}}]}}]}}]}}]}}]}}]}}]}}]}}]}}]}}]}}]}}]}}]}}]}}]}}]}}]}}]}}]}}]}}]}}]}}]}}]}}]}}]}}]}}]}}]}}]}}]}}} \ No newline at end of file diff --git a/fuzz/corpus/bast_compile/seed-035 b/fuzz/corpus/bast_compile/seed-035 new file mode 100644 index 0000000..a0febee --- /dev/null +++ b/fuzz/corpus/bast_compile/seed-035 @@ -0,0 +1 @@ +{"$defs": {"S": {"kind": "struct", "fields": [{"name": "x", "kind": "uint8"}]}, "D100": {"kind": "struct", "fields": [{"name": "n", "kind": {"$ref": "#/$defs/S"}}]}, "D99": {"kind": "struct", "fields": [{"name": "n", "kind": {"$ref": "#/$defs/D100"}}]}, "D98": {"kind": "struct", "fields": [{"name": "n", "kind": {"$ref": "#/$defs/D99"}}]}, "D97": {"kind": "struct", "fields": [{"name": "n", "kind": {"$ref": "#/$defs/D98"}}]}, "D96": {"kind": "struct", "fields": [{"name": "n", "kind": {"$ref": "#/$defs/D97"}}]}, "D95": {"kind": "struct", "fields": [{"name": "n", "kind": {"$ref": "#/$defs/D96"}}]}, "D94": {"kind": "struct", "fields": [{"name": "n", "kind": {"$ref": "#/$defs/D95"}}]}, "D93": {"kind": "struct", "fields": [{"name": "n", "kind": {"$ref": "#/$defs/D94"}}]}, "D92": {"kind": "struct", "fields": [{"name": "n", "kind": {"$ref": "#/$defs/D93"}}]}, "D91": {"kind": "struct", "fields": [{"name": "n", "kind": {"$ref": "#/$defs/D92"}}]}, "D90": {"kind": "struct", "fields": [{"name": "n", "kind": {"$ref": "#/$defs/D91"}}]}, "D89": {"kind": "struct", "fields": [{"name": "n", "kind": {"$ref": "#/$defs/D90"}}]}, "D88": {"kind": "struct", "fields": [{"name": "n", "kind": {"$ref": "#/$defs/D89"}}]}, "D87": {"kind": "struct", "fields": [{"name": "n", "kind": {"$ref": "#/$defs/D88"}}]}, "D86": {"kind": "struct", "fields": [{"name": "n", "kind": {"$ref": "#/$defs/D87"}}]}, "D85": {"kind": "struct", "fields": [{"name": "n", "kind": {"$ref": "#/$defs/D86"}}]}, "D84": {"kind": "struct", "fields": [{"name": "n", "kind": {"$ref": "#/$defs/D85"}}]}, "D83": {"kind": "struct", "fields": [{"name": "n", "kind": {"$ref": "#/$defs/D84"}}]}, "D82": {"kind": "struct", "fields": [{"name": "n", "kind": {"$ref": "#/$defs/D83"}}]}, "D81": {"kind": "struct", "fields": [{"name": "n", "kind": {"$ref": "#/$defs/D82"}}]}, "D80": {"kind": "struct", "fields": [{"name": "n", "kind": {"$ref": "#/$defs/D81"}}]}, "D79": {"kind": "struct", "fields": [{"name": "n", "kind": {"$ref": "#/$defs/D80"}}]}, "D78": {"kind": "struct", "fields": [{"name": "n", "kind": {"$ref": "#/$defs/D79"}}]}, "D77": {"kind": "struct", "fields": [{"name": "n", "kind": {"$ref": "#/$defs/D78"}}]}, "D76": {"kind": "struct", "fields": [{"name": "n", "kind": {"$ref": "#/$defs/D77"}}]}, "D75": {"kind": "struct", "fields": [{"name": "n", "kind": {"$ref": "#/$defs/D76"}}]}, "D74": {"kind": "struct", "fields": [{"name": "n", "kind": {"$ref": "#/$defs/D75"}}]}, "D73": {"kind": "struct", "fields": [{"name": "n", "kind": {"$ref": "#/$defs/D74"}}]}, "D72": {"kind": "struct", "fields": [{"name": "n", "kind": {"$ref": "#/$defs/D73"}}]}, "D71": {"kind": "struct", "fields": [{"name": "n", "kind": {"$ref": "#/$defs/D72"}}]}, "D70": {"kind": "struct", "fields": [{"name": "n", "kind": {"$ref": "#/$defs/D71"}}]}, "D69": {"kind": "struct", "fields": [{"name": "n", "kind": {"$ref": "#/$defs/D70"}}]}, "D68": {"kind": "struct", "fields": [{"name": "n", "kind": {"$ref": "#/$defs/D69"}}]}, "D67": {"kind": "struct", "fields": [{"name": "n", "kind": {"$ref": "#/$defs/D68"}}]}, "D66": {"kind": "struct", "fields": [{"name": "n", "kind": {"$ref": "#/$defs/D67"}}]}, "D65": {"kind": "struct", "fields": [{"name": "n", "kind": {"$ref": "#/$defs/D66"}}]}, "D64": {"kind": "struct", "fields": [{"name": "n", "kind": {"$ref": "#/$defs/D65"}}]}, "D63": {"kind": "struct", "fields": [{"name": "n", "kind": {"$ref": "#/$defs/D64"}}]}, "D62": {"kind": "struct", "fields": [{"name": "n", "kind": {"$ref": "#/$defs/D63"}}]}, "D61": {"kind": "struct", "fields": [{"name": "n", "kind": {"$ref": "#/$defs/D62"}}]}, "D60": {"kind": "struct", "fields": [{"name": "n", "kind": {"$ref": "#/$defs/D61"}}]}, "D59": {"kind": "struct", "fields": [{"name": "n", "kind": {"$ref": "#/$defs/D60"}}]}, "D58": {"kind": "struct", "fields": [{"name": "n", "kind": {"$ref": "#/$defs/D59"}}]}, "D57": {"kind": "struct", "fields": [{"name": "n", "kind": {"$ref": "#/$defs/D58"}}]}, "D56": {"kind": "struct", "fields": [{"name": "n", "kind": {"$ref": "#/$defs/D57"}}]}, "D55": {"kind": "struct", "fields": [{"name": "n", "kind": {"$ref": "#/$defs/D56"}}]}, "D54": {"kind": "struct", "fields": [{"name": "n", "kind": {"$ref": "#/$defs/D55"}}]}, "D53": {"kind": "struct", "fields": [{"name": "n", "kind": {"$ref": "#/$defs/D54"}}]}, "D52": {"kind": "struct", "fields": [{"name": "n", "kind": {"$ref": "#/$defs/D53"}}]}, "D51": {"kind": "struct", "fields": [{"name": "n", "kind": {"$ref": "#/$defs/D52"}}]}, "D50": {"kind": "struct", "fields": [{"name": "n", "kind": {"$ref": "#/$defs/D51"}}]}, "D49": {"kind": "struct", "fields": [{"name": "n", "kind": {"$ref": "#/$defs/D50"}}]}, "D48": {"kind": "struct", "fields": [{"name": "n", "kind": {"$ref": "#/$defs/D49"}}]}, "D47": {"kind": "struct", "fields": [{"name": "n", "kind": {"$ref": "#/$defs/D48"}}]}, "D46": {"kind": "struct", "fields": [{"name": "n", "kind": {"$ref": "#/$defs/D47"}}]}, "D45": {"kind": "struct", "fields": [{"name": "n", "kind": {"$ref": "#/$defs/D46"}}]}, "D44": {"kind": "struct", "fields": [{"name": "n", "kind": {"$ref": "#/$defs/D45"}}]}, "D43": {"kind": "struct", "fields": [{"name": "n", "kind": {"$ref": "#/$defs/D44"}}]}, "D42": {"kind": "struct", "fields": [{"name": "n", "kind": {"$ref": "#/$defs/D43"}}]}, "D41": {"kind": "struct", "fields": [{"name": "n", "kind": {"$ref": "#/$defs/D42"}}]}, "D40": {"kind": "struct", "fields": [{"name": "n", "kind": {"$ref": "#/$defs/D41"}}]}, "D39": {"kind": "struct", "fields": [{"name": "n", "kind": {"$ref": "#/$defs/D40"}}]}, "D38": {"kind": "struct", "fields": [{"name": "n", "kind": {"$ref": "#/$defs/D39"}}]}, "D37": {"kind": "struct", "fields": [{"name": "n", "kind": {"$ref": "#/$defs/D38"}}]}, "D36": {"kind": "struct", "fields": [{"name": "n", "kind": {"$ref": "#/$defs/D37"}}]}, "D35": {"kind": "struct", "fields": [{"name": "n", "kind": {"$ref": "#/$defs/D36"}}]}, "D34": {"kind": "struct", "fields": [{"name": "n", "kind": {"$ref": "#/$defs/D35"}}]}, "D33": {"kind": "struct", "fields": [{"name": "n", "kind": {"$ref": "#/$defs/D34"}}]}, "D32": {"kind": "struct", "fields": [{"name": "n", "kind": {"$ref": "#/$defs/D33"}}]}, "D31": {"kind": "struct", "fields": [{"name": "n", "kind": {"$ref": "#/$defs/D32"}}]}, "D30": {"kind": "struct", "fields": [{"name": "n", "kind": {"$ref": "#/$defs/D31"}}]}, "D29": {"kind": "struct", "fields": [{"name": "n", "kind": {"$ref": "#/$defs/D30"}}]}, "D28": {"kind": "struct", "fields": [{"name": "n", "kind": {"$ref": "#/$defs/D29"}}]}, "D27": {"kind": "struct", "fields": [{"name": "n", "kind": {"$ref": "#/$defs/D28"}}]}, "D26": {"kind": "struct", "fields": [{"name": "n", "kind": {"$ref": "#/$defs/D27"}}]}, "D25": {"kind": "struct", "fields": [{"name": "n", "kind": {"$ref": "#/$defs/D26"}}]}, "D24": {"kind": "struct", "fields": [{"name": "n", "kind": {"$ref": "#/$defs/D25"}}]}, "D23": {"kind": "struct", "fields": [{"name": "n", "kind": {"$ref": "#/$defs/D24"}}]}, "D22": {"kind": "struct", "fields": [{"name": "n", "kind": {"$ref": "#/$defs/D23"}}]}, "D21": {"kind": "struct", "fields": [{"name": "n", "kind": {"$ref": "#/$defs/D22"}}]}, "D20": {"kind": "struct", "fields": [{"name": "n", "kind": {"$ref": "#/$defs/D21"}}]}, "D19": {"kind": "struct", "fields": [{"name": "n", "kind": {"$ref": "#/$defs/D20"}}]}, "D18": {"kind": "struct", "fields": [{"name": "n", "kind": {"$ref": "#/$defs/D19"}}]}, "D17": {"kind": "struct", "fields": [{"name": "n", "kind": {"$ref": "#/$defs/D18"}}]}, "D16": {"kind": "struct", "fields": [{"name": "n", "kind": {"$ref": "#/$defs/D17"}}]}, "D15": {"kind": "struct", "fields": [{"name": "n", "kind": {"$ref": "#/$defs/D16"}}]}, "D14": {"kind": "struct", "fields": [{"name": "n", "kind": {"$ref": "#/$defs/D15"}}]}, "D13": {"kind": "struct", "fields": [{"name": "n", "kind": {"$ref": "#/$defs/D14"}}]}, "D12": {"kind": "struct", "fields": [{"name": "n", "kind": {"$ref": "#/$defs/D13"}}]}, "D11": {"kind": "struct", "fields": [{"name": "n", "kind": {"$ref": "#/$defs/D12"}}]}, "D10": {"kind": "struct", "fields": [{"name": "n", "kind": {"$ref": "#/$defs/D11"}}]}, "D9": {"kind": "struct", "fields": [{"name": "n", "kind": {"$ref": "#/$defs/D10"}}]}, "D8": {"kind": "struct", "fields": [{"name": "n", "kind": {"$ref": "#/$defs/D9"}}]}, "D7": {"kind": "struct", "fields": [{"name": "n", "kind": {"$ref": "#/$defs/D8"}}]}, "D6": {"kind": "struct", "fields": [{"name": "n", "kind": {"$ref": "#/$defs/D7"}}]}, "D5": {"kind": "struct", "fields": [{"name": "n", "kind": {"$ref": "#/$defs/D6"}}]}, "D4": {"kind": "struct", "fields": [{"name": "n", "kind": {"$ref": "#/$defs/D5"}}]}, "D3": {"kind": "struct", "fields": [{"name": "n", "kind": {"$ref": "#/$defs/D4"}}]}, "D2": {"kind": "struct", "fields": [{"name": "n", "kind": {"$ref": "#/$defs/D3"}}]}, "D1": {"kind": "struct", "fields": [{"name": "n", "kind": {"$ref": "#/$defs/D2"}}]}}} \ No newline at end of file diff --git a/fuzz/corpus/bast_compile/seed-036 b/fuzz/corpus/bast_compile/seed-036 new file mode 100644 index 0000000..705a081 --- /dev/null +++ b/fuzz/corpus/bast_compile/seed-036 @@ -0,0 +1 @@ +{"$defs": {"S": {"kind": "struct", "fields": [{"name": "a", "kind": "uint8"}, {"name": "a", "kind": "uint16"}]}}} \ No newline at end of file diff --git a/fuzz/corpus/bast_compile/seed-037 b/fuzz/corpus/bast_compile/seed-037 new file mode 100644 index 0000000..a14cf3b --- /dev/null +++ b/fuzz/corpus/bast_compile/seed-037 @@ -0,0 +1 @@ +{"$defs": {"S": {"kind": "enum", "values": ["only"]}, "root": "S"}} \ No newline at end of file diff --git a/fuzz/corpus/data_access/seed-000 b/fuzz/corpus/data_access/seed-000 new file mode 100644 index 0000000..6b2aaa7 --- /dev/null +++ b/fuzz/corpus/data_access/seed-000 @@ -0,0 +1 @@ + \ No newline at end of file diff --git a/fuzz/corpus/data_access/seed-001 b/fuzz/corpus/data_access/seed-001 new file mode 100644 index 0000000..f76dd23 Binary files /dev/null and b/fuzz/corpus/data_access/seed-001 differ diff --git a/fuzz/corpus/data_access/seed-002 b/fuzz/corpus/data_access/seed-002 new file mode 100644 index 0000000..16e0e90 --- /dev/null +++ b/fuzz/corpus/data_access/seed-002 @@ -0,0 +1 @@ + \ No newline at end of file diff --git a/fuzz/corpus/data_access/seed-003 b/fuzz/corpus/data_access/seed-003 new file mode 100644 index 0000000..5416677 --- /dev/null +++ b/fuzz/corpus/data_access/seed-003 @@ -0,0 +1 @@ +€ \ No newline at end of file diff --git a/fuzz/corpus/data_access/seed-004 b/fuzz/corpus/data_access/seed-004 new file mode 100644 index 0000000..ce542ef --- /dev/null +++ b/fuzz/corpus/data_access/seed-004 @@ -0,0 +1 @@ +ÿ \ No newline at end of file diff --git a/fuzz/corpus/data_access/seed-005 b/fuzz/corpus/data_access/seed-005 new file mode 100644 index 0000000..09f370e Binary files /dev/null and b/fuzz/corpus/data_access/seed-005 differ diff --git a/fuzz/corpus/data_access/seed-006 b/fuzz/corpus/data_access/seed-006 new file mode 100644 index 0000000..09f370e Binary files /dev/null and b/fuzz/corpus/data_access/seed-006 differ diff --git a/fuzz/corpus/data_access/seed-007 b/fuzz/corpus/data_access/seed-007 new file mode 100644 index 0000000..35a0387 Binary files /dev/null and b/fuzz/corpus/data_access/seed-007 differ diff --git a/fuzz/corpus/data_access/seed-008 b/fuzz/corpus/data_access/seed-008 new file mode 100644 index 0000000..bdc955b Binary files /dev/null and b/fuzz/corpus/data_access/seed-008 differ diff --git a/fuzz/corpus/data_access/seed-009 b/fuzz/corpus/data_access/seed-009 new file mode 100644 index 0000000..409038e --- /dev/null +++ b/fuzz/corpus/data_access/seed-009 @@ -0,0 +1 @@ +4 \ No newline at end of file diff --git a/fuzz/corpus/data_access/seed-010 b/fuzz/corpus/data_access/seed-010 new file mode 100644 index 0000000..f06eb89 --- /dev/null +++ b/fuzz/corpus/data_access/seed-010 @@ -0,0 +1 @@ +4 \ No newline at end of file diff --git a/fuzz/corpus/data_access/seed-011 b/fuzz/corpus/data_access/seed-011 new file mode 100644 index 0000000..f98025e Binary files /dev/null and b/fuzz/corpus/data_access/seed-011 differ diff --git a/fuzz/corpus/data_access/seed-012 b/fuzz/corpus/data_access/seed-012 new file mode 100644 index 0000000..438e74a Binary files /dev/null and b/fuzz/corpus/data_access/seed-012 differ diff --git a/fuzz/corpus/data_access/seed-013 b/fuzz/corpus/data_access/seed-013 new file mode 100644 index 0000000..f96c401 --- /dev/null +++ b/fuzz/corpus/data_access/seed-013 @@ -0,0 +1 @@ +ÿÿ \ No newline at end of file diff --git a/fuzz/corpus/data_access/seed-014 b/fuzz/corpus/data_access/seed-014 new file mode 100644 index 0000000..f96c401 --- /dev/null +++ b/fuzz/corpus/data_access/seed-014 @@ -0,0 +1 @@ +ÿÿ \ No newline at end of file diff --git a/fuzz/corpus/data_access/seed-015 b/fuzz/corpus/data_access/seed-015 new file mode 100644 index 0000000..593f470 Binary files /dev/null and b/fuzz/corpus/data_access/seed-015 differ diff --git a/fuzz/corpus/data_access/seed-016 b/fuzz/corpus/data_access/seed-016 new file mode 100644 index 0000000..593f470 Binary files /dev/null and b/fuzz/corpus/data_access/seed-016 differ diff --git a/fuzz/corpus/data_access/seed-017 b/fuzz/corpus/data_access/seed-017 new file mode 100644 index 0000000..f66c9cf Binary files /dev/null and b/fuzz/corpus/data_access/seed-017 differ diff --git a/fuzz/corpus/data_access/seed-018 b/fuzz/corpus/data_access/seed-018 new file mode 100644 index 0000000..720d64f Binary files /dev/null and b/fuzz/corpus/data_access/seed-018 differ diff --git a/fuzz/corpus/data_access/seed-019 b/fuzz/corpus/data_access/seed-019 new file mode 100644 index 0000000..9233ae5 --- /dev/null +++ b/fuzz/corpus/data_access/seed-019 @@ -0,0 +1 @@ +D3" \ No newline at end of file diff --git a/fuzz/corpus/data_access/seed-020 b/fuzz/corpus/data_access/seed-020 new file mode 100644 index 0000000..3b715c8 --- /dev/null +++ b/fuzz/corpus/data_access/seed-020 @@ -0,0 +1 @@ +"3D \ No newline at end of file diff --git a/fuzz/corpus/data_access/seed-021 b/fuzz/corpus/data_access/seed-021 new file mode 100644 index 0000000..68cbac1 Binary files /dev/null and b/fuzz/corpus/data_access/seed-021 differ diff --git a/fuzz/corpus/data_access/seed-022 b/fuzz/corpus/data_access/seed-022 new file mode 100644 index 0000000..e914f83 Binary files /dev/null and b/fuzz/corpus/data_access/seed-022 differ diff --git a/fuzz/corpus/data_access/seed-023 b/fuzz/corpus/data_access/seed-023 new file mode 100644 index 0000000..7bde864 --- /dev/null +++ b/fuzz/corpus/data_access/seed-023 @@ -0,0 +1 @@ +ÿÿÿÿ \ No newline at end of file diff --git a/fuzz/corpus/data_access/seed-024 b/fuzz/corpus/data_access/seed-024 new file mode 100644 index 0000000..7bde864 --- /dev/null +++ b/fuzz/corpus/data_access/seed-024 @@ -0,0 +1 @@ +ÿÿÿÿ \ No newline at end of file diff --git a/fuzz/corpus/data_access/seed-025 b/fuzz/corpus/data_access/seed-025 new file mode 100644 index 0000000..e2207a2 --- /dev/null +++ b/fuzz/corpus/data_access/seed-025 @@ -0,0 +1 @@ +ˆwfUD3" \ No newline at end of file diff --git a/fuzz/corpus/data_access/seed-026 b/fuzz/corpus/data_access/seed-026 new file mode 100644 index 0000000..0f7674d --- /dev/null +++ b/fuzz/corpus/data_access/seed-026 @@ -0,0 +1 @@ +"3DUfwˆ \ No newline at end of file diff --git a/fuzz/corpus/data_access/seed-027 b/fuzz/corpus/data_access/seed-027 new file mode 100644 index 0000000..dfbda32 Binary files /dev/null and b/fuzz/corpus/data_access/seed-027 differ diff --git a/fuzz/corpus/data_access/seed-028 b/fuzz/corpus/data_access/seed-028 new file mode 100644 index 0000000..8a23d01 Binary files /dev/null and b/fuzz/corpus/data_access/seed-028 differ diff --git a/fuzz/corpus/data_access/seed-029 b/fuzz/corpus/data_access/seed-029 new file mode 100644 index 0000000..8ccb807 Binary files /dev/null and b/fuzz/corpus/data_access/seed-029 differ diff --git a/fuzz/corpus/data_access/seed-030 b/fuzz/corpus/data_access/seed-030 new file mode 100644 index 0000000..913b51b Binary files /dev/null and b/fuzz/corpus/data_access/seed-030 differ diff --git a/fuzz/corpus/data_access/seed-031 b/fuzz/corpus/data_access/seed-031 new file mode 100644 index 0000000..593f470 Binary files /dev/null and b/fuzz/corpus/data_access/seed-031 differ diff --git a/fuzz/corpus/data_access/seed-032 b/fuzz/corpus/data_access/seed-032 new file mode 100644 index 0000000..b067e0d Binary files /dev/null and b/fuzz/corpus/data_access/seed-032 differ diff --git a/fuzz/corpus/data_access/seed-033 b/fuzz/corpus/data_access/seed-033 new file mode 100644 index 0000000..29fa86e Binary files /dev/null and b/fuzz/corpus/data_access/seed-033 differ diff --git a/fuzz/corpus/data_access/seed-034 b/fuzz/corpus/data_access/seed-034 new file mode 100644 index 0000000..8c611b8 Binary files /dev/null and b/fuzz/corpus/data_access/seed-034 differ diff --git a/fuzz/corpus/data_access/seed-035 b/fuzz/corpus/data_access/seed-035 new file mode 100644 index 0000000..a95bd60 Binary files /dev/null and b/fuzz/corpus/data_access/seed-035 differ diff --git a/fuzz/corpus/data_access/seed-036 b/fuzz/corpus/data_access/seed-036 new file mode 100644 index 0000000..7bde864 --- /dev/null +++ b/fuzz/corpus/data_access/seed-036 @@ -0,0 +1 @@ +ÿÿÿÿ \ No newline at end of file diff --git a/fuzz/corpus/data_access/seed-037 b/fuzz/corpus/data_access/seed-037 new file mode 100644 index 0000000..7718539 Binary files /dev/null and b/fuzz/corpus/data_access/seed-037 differ diff --git a/fuzz/corpus/data_access/seed-038 b/fuzz/corpus/data_access/seed-038 new file mode 100644 index 0000000..b0b2b1c --- /dev/null +++ b/fuzz/corpus/data_access/seed-038 @@ -0,0 +1 @@ + \ No newline at end of file diff --git a/fuzz/corpus/data_access/seed-039 b/fuzz/corpus/data_access/seed-039 new file mode 100644 index 0000000..19b3e94 Binary files /dev/null and b/fuzz/corpus/data_access/seed-039 differ diff --git a/fuzz/corpus/data_access/seed-040 b/fuzz/corpus/data_access/seed-040 new file mode 100644 index 0000000..22736d7 Binary files /dev/null and b/fuzz/corpus/data_access/seed-040 differ diff --git a/fuzz/corpus/data_access/seed-041 b/fuzz/corpus/data_access/seed-041 new file mode 100644 index 0000000..a786e12 Binary files /dev/null and b/fuzz/corpus/data_access/seed-041 differ diff --git a/fuzz/corpus/data_access/seed-042 b/fuzz/corpus/data_access/seed-042 new file mode 100644 index 0000000..c0e136d Binary files /dev/null and b/fuzz/corpus/data_access/seed-042 differ diff --git a/fuzz/corpus/data_access/seed-043 b/fuzz/corpus/data_access/seed-043 new file mode 100644 index 0000000..c5530ef Binary files /dev/null and b/fuzz/corpus/data_access/seed-043 differ diff --git a/fuzz/corpus/data_access/seed-044 b/fuzz/corpus/data_access/seed-044 new file mode 100644 index 0000000..c244626 Binary files /dev/null and b/fuzz/corpus/data_access/seed-044 differ diff --git a/fuzz/corpus/data_access/seed-045 b/fuzz/corpus/data_access/seed-045 new file mode 100644 index 0000000..643478c Binary files /dev/null and b/fuzz/corpus/data_access/seed-045 differ diff --git a/fuzz/corpus/data_access/seed-046 b/fuzz/corpus/data_access/seed-046 new file mode 100644 index 0000000..593f470 Binary files /dev/null and b/fuzz/corpus/data_access/seed-046 differ diff --git a/fuzz/corpus/data_access/seed-047 b/fuzz/corpus/data_access/seed-047 new file mode 100644 index 0000000..1d785e9 Binary files /dev/null and b/fuzz/corpus/data_access/seed-047 differ diff --git a/fuzz/corpus/data_access/seed-048 b/fuzz/corpus/data_access/seed-048 new file mode 100644 index 0000000..ca3bd58 Binary files /dev/null and b/fuzz/corpus/data_access/seed-048 differ diff --git a/fuzz/corpus/data_access/seed-049 b/fuzz/corpus/data_access/seed-049 new file mode 100644 index 0000000..c31e8fc Binary files /dev/null and b/fuzz/corpus/data_access/seed-049 differ diff --git a/fuzz/corpus/data_access/seed-050 b/fuzz/corpus/data_access/seed-050 new file mode 100644 index 0000000..2503859 Binary files /dev/null and b/fuzz/corpus/data_access/seed-050 differ diff --git a/fuzz/corpus/data_access/seed-051 b/fuzz/corpus/data_access/seed-051 new file mode 100644 index 0000000..7bde864 --- /dev/null +++ b/fuzz/corpus/data_access/seed-051 @@ -0,0 +1 @@ +ÿÿÿÿ \ No newline at end of file diff --git a/fuzz/corpus/data_access/seed-052 b/fuzz/corpus/data_access/seed-052 new file mode 100644 index 0000000..191f79b Binary files /dev/null and b/fuzz/corpus/data_access/seed-052 differ diff --git a/fuzz/corpus/data_access/seed-053 b/fuzz/corpus/data_access/seed-053 new file mode 100644 index 0000000..b0b2b1c --- /dev/null +++ b/fuzz/corpus/data_access/seed-053 @@ -0,0 +1 @@ + \ No newline at end of file diff --git a/fuzz/corpus/data_access/seed-054 b/fuzz/corpus/data_access/seed-054 new file mode 100644 index 0000000..19b3e94 Binary files /dev/null and b/fuzz/corpus/data_access/seed-054 differ diff --git a/fuzz/corpus/data_access/seed-055 b/fuzz/corpus/data_access/seed-055 new file mode 100644 index 0000000..22736d7 Binary files /dev/null and b/fuzz/corpus/data_access/seed-055 differ diff --git a/fuzz/corpus/data_access/seed-056 b/fuzz/corpus/data_access/seed-056 new file mode 100644 index 0000000..a786e12 Binary files /dev/null and b/fuzz/corpus/data_access/seed-056 differ diff --git a/fuzz/corpus/data_access/seed-057 b/fuzz/corpus/data_access/seed-057 new file mode 100644 index 0000000..c0e136d Binary files /dev/null and b/fuzz/corpus/data_access/seed-057 differ diff --git a/fuzz/corpus/data_access/seed-058 b/fuzz/corpus/data_access/seed-058 new file mode 100644 index 0000000..c5530ef Binary files /dev/null and b/fuzz/corpus/data_access/seed-058 differ diff --git a/fuzz/corpus/data_access/seed-059 b/fuzz/corpus/data_access/seed-059 new file mode 100644 index 0000000..c244626 Binary files /dev/null and b/fuzz/corpus/data_access/seed-059 differ diff --git a/fuzz/corpus/data_access/seed-060 b/fuzz/corpus/data_access/seed-060 new file mode 100644 index 0000000..643478c Binary files /dev/null and b/fuzz/corpus/data_access/seed-060 differ diff --git a/fuzz/corpus/data_access/seed-061 b/fuzz/corpus/data_access/seed-061 new file mode 100644 index 0000000..1b1cb4d Binary files /dev/null and b/fuzz/corpus/data_access/seed-061 differ diff --git a/fuzz/corpus/data_access/seed-062 b/fuzz/corpus/data_access/seed-062 new file mode 100644 index 0000000..5142c79 Binary files /dev/null and b/fuzz/corpus/data_access/seed-062 differ diff --git a/fuzz/corpus/data_access/seed-063 b/fuzz/corpus/data_access/seed-063 new file mode 100644 index 0000000..eeed71e Binary files /dev/null and b/fuzz/corpus/data_access/seed-063 differ diff --git a/fuzz/corpus/data_access/seed-064 b/fuzz/corpus/data_access/seed-064 new file mode 100644 index 0000000..dfee5d1 Binary files /dev/null and b/fuzz/corpus/data_access/seed-064 differ diff --git a/fuzz/corpus/data_access/seed-065 b/fuzz/corpus/data_access/seed-065 new file mode 100644 index 0000000..872219f Binary files /dev/null and b/fuzz/corpus/data_access/seed-065 differ diff --git a/fuzz/corpus/data_access/seed-066 b/fuzz/corpus/data_access/seed-066 new file mode 100644 index 0000000..a89e966 Binary files /dev/null and b/fuzz/corpus/data_access/seed-066 differ diff --git a/fuzz/corpus/data_access/seed-067 b/fuzz/corpus/data_access/seed-067 new file mode 100644 index 0000000..94ed689 Binary files /dev/null and b/fuzz/corpus/data_access/seed-067 differ diff --git a/fuzz/corpus/data_access/seed-068 b/fuzz/corpus/data_access/seed-068 new file mode 100644 index 0000000..8663f7d --- /dev/null +++ b/fuzz/corpus/data_access/seed-068 @@ -0,0 +1 @@ +ÿÿÿÿÿÿÿÿ \ No newline at end of file diff --git a/fuzz/corpus/data_access/seed-069 b/fuzz/corpus/data_access/seed-069 new file mode 100644 index 0000000..b21f460 --- /dev/null +++ b/fuzz/corpus/data_access/seed-069 @@ -0,0 +1 @@ +ÿÿÿÿÿÿ \ No newline at end of file diff --git a/fuzz/corpus/data_access/seed-070 b/fuzz/corpus/data_access/seed-070 new file mode 100644 index 0000000..bb8e186 Binary files /dev/null and b/fuzz/corpus/data_access/seed-070 differ diff --git a/fuzz/corpus/data_access/seed-071 b/fuzz/corpus/data_access/seed-071 new file mode 100644 index 0000000..51a509b Binary files /dev/null and b/fuzz/corpus/data_access/seed-071 differ diff --git a/fuzz/corpus/data_access/seed-072 b/fuzz/corpus/data_access/seed-072 new file mode 100644 index 0000000..1b1cb4d Binary files /dev/null and b/fuzz/corpus/data_access/seed-072 differ diff --git a/fuzz/corpus/data_access/seed-073 b/fuzz/corpus/data_access/seed-073 new file mode 100644 index 0000000..2b2b2ce Binary files /dev/null and b/fuzz/corpus/data_access/seed-073 differ diff --git a/fuzz/corpus/data_access/seed-074 b/fuzz/corpus/data_access/seed-074 new file mode 100644 index 0000000..d9e6aa6 Binary files /dev/null and b/fuzz/corpus/data_access/seed-074 differ diff --git a/fuzz/corpus/data_access/seed-075 b/fuzz/corpus/data_access/seed-075 new file mode 100644 index 0000000..0491049 Binary files /dev/null and b/fuzz/corpus/data_access/seed-075 differ diff --git a/fuzz/corpus/data_access/seed-076 b/fuzz/corpus/data_access/seed-076 new file mode 100644 index 0000000..3663b78 Binary files /dev/null and b/fuzz/corpus/data_access/seed-076 differ diff --git a/fuzz/corpus/data_access/seed-077 b/fuzz/corpus/data_access/seed-077 new file mode 100644 index 0000000..a89e966 Binary files /dev/null and b/fuzz/corpus/data_access/seed-077 differ diff --git a/fuzz/corpus/data_access/seed-078 b/fuzz/corpus/data_access/seed-078 new file mode 100644 index 0000000..94ed689 Binary files /dev/null and b/fuzz/corpus/data_access/seed-078 differ diff --git a/fuzz/corpus/data_access/seed-079 b/fuzz/corpus/data_access/seed-079 new file mode 100644 index 0000000..8663f7d --- /dev/null +++ b/fuzz/corpus/data_access/seed-079 @@ -0,0 +1 @@ +ÿÿÿÿÿÿÿÿ \ No newline at end of file diff --git a/fuzz/corpus/data_access/seed-080 b/fuzz/corpus/data_access/seed-080 new file mode 100644 index 0000000..de95473 --- /dev/null +++ b/fuzz/corpus/data_access/seed-080 @@ -0,0 +1 @@ +ÿÿÿÿÿÿ \ No newline at end of file diff --git a/fuzz/corpus/data_access/seed-081 b/fuzz/corpus/data_access/seed-081 new file mode 100644 index 0000000..bb8e186 Binary files /dev/null and b/fuzz/corpus/data_access/seed-081 differ diff --git a/fuzz/corpus/data_access/seed-082 b/fuzz/corpus/data_access/seed-082 new file mode 100644 index 0000000..51a509b Binary files /dev/null and b/fuzz/corpus/data_access/seed-082 differ diff --git a/fuzz/corpus/data_access/seed-083 b/fuzz/corpus/data_access/seed-083 new file mode 100644 index 0000000..59c36c6 Binary files /dev/null and b/fuzz/corpus/data_access/seed-083 differ diff --git a/fuzz/corpus/data_access/seed-084 b/fuzz/corpus/data_access/seed-084 new file mode 100644 index 0000000..fde1ac1 Binary files /dev/null and b/fuzz/corpus/data_access/seed-084 differ diff --git a/fuzz/corpus/data_access/seed-085 b/fuzz/corpus/data_access/seed-085 new file mode 100644 index 0000000..f76dd23 Binary files /dev/null and b/fuzz/corpus/data_access/seed-085 differ diff --git a/fuzz/corpus/data_access/seed-086 b/fuzz/corpus/data_access/seed-086 new file mode 100644 index 0000000..6b2aaa7 --- /dev/null +++ b/fuzz/corpus/data_access/seed-086 @@ -0,0 +1 @@ + \ No newline at end of file diff --git a/fuzz/corpus/data_access/seed-087 b/fuzz/corpus/data_access/seed-087 new file mode 100644 index 0000000..25cb955 --- /dev/null +++ b/fuzz/corpus/data_access/seed-087 @@ -0,0 +1 @@ + \ No newline at end of file diff --git a/fuzz/corpus/data_access/seed-088 b/fuzz/corpus/data_access/seed-088 new file mode 100644 index 0000000..16e0e90 --- /dev/null +++ b/fuzz/corpus/data_access/seed-088 @@ -0,0 +1 @@ + \ No newline at end of file diff --git a/fuzz/corpus/data_access/seed-089 b/fuzz/corpus/data_access/seed-089 new file mode 100644 index 0000000..ce542ef --- /dev/null +++ b/fuzz/corpus/data_access/seed-089 @@ -0,0 +1 @@ +ÿ \ No newline at end of file diff --git a/fuzz/corpus/data_access/seed-090 b/fuzz/corpus/data_access/seed-090 new file mode 100644 index 0000000..aae823e Binary files /dev/null and b/fuzz/corpus/data_access/seed-090 differ diff --git a/fuzz/corpus/data_access/seed-091 b/fuzz/corpus/data_access/seed-091 new file mode 100644 index 0000000..7e2ed78 Binary files /dev/null and b/fuzz/corpus/data_access/seed-091 differ diff --git a/fuzz/corpus/data_access/seed-092 b/fuzz/corpus/data_access/seed-092 new file mode 100644 index 0000000..0fbe574 Binary files /dev/null and b/fuzz/corpus/data_access/seed-092 differ diff --git a/fuzz/corpus/data_access/seed-093 b/fuzz/corpus/data_access/seed-093 new file mode 100644 index 0000000..ba66624 Binary files /dev/null and b/fuzz/corpus/data_access/seed-093 differ diff --git a/fuzz/corpus/data_access/seed-094 b/fuzz/corpus/data_access/seed-094 new file mode 100644 index 0000000..e69de29 diff --git a/fuzz/corpus/data_access/seed-095 b/fuzz/corpus/data_access/seed-095 new file mode 100644 index 0000000..705f954 --- /dev/null +++ b/fuzz/corpus/data_access/seed-095 @@ -0,0 +1 @@ +ªªª \ No newline at end of file diff --git a/fuzz/corpus/data_access/seed-096 b/fuzz/corpus/data_access/seed-096 new file mode 100644 index 0000000..f3aaa71 --- /dev/null +++ b/fuzz/corpus/data_access/seed-096 @@ -0,0 +1 @@ +ªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªª \ No newline at end of file diff --git a/fuzz/corpus/data_access/seed-097 b/fuzz/corpus/data_access/seed-097 new file mode 100644 index 0000000..c866266 Binary files /dev/null and b/fuzz/corpus/data_access/seed-097 differ diff --git a/fuzz/fuzz_targets/bast_compile.rs b/fuzz/fuzz_targets/bast_compile.rs new file mode 100644 index 0000000..6209f6b --- /dev/null +++ b/fuzz/fuzz_targets/bast_compile.rs @@ -0,0 +1,7 @@ +#![no_main] + +use libfuzzer_sys::fuzz_target; + +fuzz_target!(|data: &[u8]| { + alktype_fuzz_shared::bast_compile::fuzz_bast_compile(data); +}); diff --git a/fuzz/fuzz_targets/data_access.rs b/fuzz/fuzz_targets/data_access.rs new file mode 100644 index 0000000..17c7eef --- /dev/null +++ b/fuzz/fuzz_targets/data_access.rs @@ -0,0 +1,7 @@ +#![no_main] + +use libfuzzer_sys::fuzz_target; + +fuzz_target!(|data: &[u8]| { + alktype_fuzz_shared::data_access::fuzz_data_access(data); +}); diff --git a/fuzz/gen_fuzz_seeds.py b/fuzz/gen_fuzz_seeds.py new file mode 100644 index 0000000..f8a6112 --- /dev/null +++ b/fuzz/gen_fuzz_seeds.py @@ -0,0 +1,268 @@ +#!/usr/bin/env python3 +"""Regenerate the committed seed corpora for alktype's fuzz targets. + +Writes into fuzz/corpus//. Deterministic: fixed inputs only, no +randomness. Run from the repo root: + + python3 fuzz/gen_fuzz_seeds.py +""" + +import json +import os +import struct + + +def seed_name(target, i): + return os.path.join("fuzz", "corpus", target, f"seed-{i:03d}") + + +def write_seed(target, i, data): + if isinstance(data, str): + data = data.encode() + if isinstance(data, dict) or isinstance(data, list): + data = json.dumps(data).encode() + path = seed_name(target, i) + os.makedirs(os.path.dirname(path), exist_ok=True) + with open(path, "wb") as f: + f.write(data) + + +# --------------------------------------------------------------------------- +# bast_compile: BAST document seeds +# --------------------------------------------------------------------------- + +def minimal_struct(field, name="S", extra=None): + node = {"kind": "struct", "fields": [field]} + if extra: + node.update(extra) + return {"$defs": {name: node}} + + +def bast_compile_seeds(): + i = 0 + + def w(doc): + nonlocal i + write_seed("bast_compile", i, doc) + i += 1 + + # Minimal valid docs: packed-relevant and aligned-relevant shapes. + w({"$defs": {"S": {"kind": "struct", "fields": [{"name": "x", "kind": "uint8"}]}, + "root": "S"}}) + w({"$defs": {"S": {"kind": "struct", "endian": "big", + "fields": [{"name": "x", "kind": "uint8"}]}}}) + w(minimal_struct({"name": "x", "kind": "uint8"})) + w({"$defs": {"S": {"kind": "struct", "fields": []}}}) + + # Every primitive kind once. + primitive_fields = [ + {"name": f"f{j}", "kind": k} + for j, k in enumerate([ + "int8", "int16", "int32", "int64", + "uint8", "uint16", "uint32", "uint64", + "float32", "float64", "bool", "string", "bytes", + ]) + ] + w({"$defs": {"S": {"kind": "struct", "fields": primitive_fields}}}) + + # Per-kind endian overrides and encodings. + w({"$defs": {"S": {"kind": "struct", "endian": "little", "fields": [ + {"name": "a", "kind": "uint32", "endian": "big"}, + {"name": "b", "kind": "string", "encoding": "length-prefixed", "maxLength": 64}, + {"name": "c", "kind": "bytes", "encoding": "offset-indirect", "maxLength": 128}, + {"name": "d", "kind": "string", "encoding": "offset-indirect"}, + ]}}}) + + # Composite kinds: nested struct, array, record, enum, union + # (byte, field, and enum-form discriminators). + w({"$defs": { + "S": {"kind": "struct", "fields": [ + {"name": "child", "kind": {"$ref": "#/$defs/Nested"}}, + {"name": "arr", "kind": {"kind": "array", "element": "uint32", "count": 3}}, + {"name": "arr0", "kind": {"kind": "array", "element": "uint8", "count": 0}}, + {"name": "rec", "kind": {"kind": "record", "values": "string"}}, + {"name": "en", "kind": {"$ref": "#/$defs/E"}}, + {"name": "un", "kind": {"$ref": "#/$defs/U1"}}, + {"name": "un2", "kind": {"$ref": "#/$defs/U2"}}, + ]}, + "Nested": {"kind": "struct", "fields": [{"name": "y", "kind": "int16"}]}, + "E": {"kind": "enum", "values": ["a", "b", "c"]}, + "U1": {"kind": "union", + "discriminator": {"kind": "byte", "offset": 0, "type": "uint8"}, + "mapping": {"0": "uint8", "1": {"$ref": "#/$defs/Nested"}}}, + "U2": {"kind": "union", + "discriminator": {"kind": "field", "name": "tag"}, + "fields": [{"name": "tag", "kind": "uint32"}], + "mapping": {"0": "uint8", "7": "string"}}, + }}) + + # Inline struct / union / enum in a field kind. + w({"$defs": {"S": {"kind": "struct", "fields": [ + {"name": "inl", "kind": {"kind": "struct", "fields": [{"name": "z", "kind": "uint8"}]}}, + {"name": "inle", "kind": {"kind": "enum", "values": ["x"]}}, + ]}}}) + + # $ref diamond (legal): two refs to the same def. + w({"$defs": { + "S": {"kind": "struct", "fields": [ + {"name": "l", "kind": {"$ref": "#/$defs/N"}}, + {"name": "r", "kind": {"$ref": "#/$defs/N"}}, + ]}, + "N": {"kind": "struct", "fields": [{"name": "v", "kind": "uint8"}]}, + }}) + + # Struct-level align at the cap and field-level align. + w(minimal_struct({"name": "x", "kind": "uint8"}, extra={"align": 4096})) + w({"$defs": {"S": {"kind": "struct", "fields": [ + {"name": "a", "kind": "uint32", "align": 16}, + {"name": "b", "kind": "uint8", "align": 1}, + ]}}}) + + # maxLength at the cap and at zero. + w(minimal_struct({"name": "s", "kind": "string", "maxLength": 67108864})) + w(minimal_struct({"name": "s", "kind": "string", "maxLength": 0})) + + # Reject classes (compile must fail cleanly in both modes): + w({"$defs": {"S": {"kind": "struct", "align": 4097, "fields": []}}}) # align over cap + w({"$defs": {"S": {"kind": "struct", "align": 65536, "fields": []}}}) + w({"$defs": {"S": {"kind": "struct", "align": 18446744073709551615, "fields": []}}}) + w({"$defs": {"S": {"kind": "struct", "fields": [ + {"name": "a", "kind": {"kind": "array", "element": "uint8", "count": 65537}}]}}}) + w({"$defs": {"S": {"kind": "struct", "fields": [ + {"name": "a", "kind": {"kind": "array", "element": "uint8", + "count": 18446744073709551615}}]}}}) + w({"$defs": {"S": {"kind": "struct", "fields": [ + {"name": "s", "kind": "string", "maxLength": 67108865}]}}}) # maxLength over cap + w({"$defs": {"S": {"kind": "struct", "fields": [ + {"name": "x", "kind": "nonsense"}]}}}) # unknown kind + w({"$defs": {"S": {"kind": "uint8", "fields": []}}}) # root not struct + w({"$defs": {"S": {"kind": "struct"}}}) # missing fields + w({"$defs": {"S": {"kind": "struct", "fields": [ + {"name": "a", "kind": {"$ref": "#/$defs/S"}}]}}}) # $ref cycle + w({"$defs": {"S": {"kind": "struct", "fields": [ + {"name": "a", "kind": {"$ref": "#/$defs/Missing"}}]}}}) # $ref missing + w({"$defs": {}}) # no root def + w([1, 2, 3]) # non-object doc + w({}) # missing $defs + w({"$defs": {"S": {"kind": "struct", "fields": [{"name": "a", "kind": 123}]}}}) + w({"$defs": {"S": {"kind": "struct", "fields": [ + {"name": "9bad", "kind": "uint8"}]}}}) # name pattern + w({"$defs": {"S": {"kind": "struct", "fields": [ + {"name": "a", "kind": "uint8", "bogus": True}]}}}) # extra props + w({"$defs": {"S": {"kind": "union", "discriminator": {"kind": "byte", "offset": 0, + "type": "uint8"}}}}) # no mapping + w("not json at all") # invalid JSON + w('{"$defs": {"S": ') # truncated JSON + # Deep inline nesting near the walk-guard cap (128) — legal but deep. + deep = {"kind": "struct", "fields": []} + for _ in range(120): + deep = {"kind": "struct", "fields": [{"name": "n", "kind": deep}]} + w({"$defs": {"S": deep}}) + # Deep nesting one layer past the cap (via inline, no $ref) — reject. + deep_over = {"kind": "struct", "fields": []} + for _ in range(129): + deep_over = {"kind": "struct", "fields": [{"name": "n", "kind": deep_over}]} + w({"$defs": {"S": deep_over}}) + # Deep $ref chain near the cap. + chain = {"$defs": {"S": {"kind": "struct", "fields": [{"name": "x", "kind": "uint8"}]}}} + for d in range(100, 0, -1): + chain["$defs"][f"D{d}"] = {"kind": "struct", "fields": [ + {"name": "n", "kind": {"$ref": f"#/$defs/D{d + 1}" if d < 100 and d < 100 else "#/$defs/S"}}]} + w(chain) + # Duplicate field names (first-wins documented probe). + w({"$defs": {"S": {"kind": "struct", "fields": [ + {"name": "a", "kind": "uint8"}, + {"name": "a", "kind": "uint16"}]}}}) + # A doc with the fuzz-harness "root" selector naming a non-struct. + w({"$defs": {"S": {"kind": "enum", "values": ["only"]}, "root": "S"}}) + + return i + + +# --------------------------------------------------------------------------- +# data_access: decode-core seeds +# --------------------------------------------------------------------------- + +def data_access_seeds(): + i = 0 + + def w(data): + nonlocal i + write_seed("data_access", i, data) + i += 1 + + # Fixed-width minimal valid encodings, both endians. + for v in [0x01, 0x00, 0x7F, 0x80, 0xFF]: + w(bytes([v])) + for v in [0, 1, 0x1234, 0x8000, 0xFFFF]: + w(struct.pack("H", v)) + for v in [0, 1, 0x11223344, 0x80000000, 0xFFFFFFFF]: + w(struct.pack("I", v)) + w(struct.pack("Q", 0x1122334455667788)) + w(struct.pack("f", -1.5)) + w(struct.pack("d", 1e300)) + + # Length-prefixed shapes: [len: u32][payload]. + for endian_fmt in ["<", ">"]: + w(struct.pack(f"{endian_fmt}I", 0)) + w(struct.pack(f"{endian_fmt}I", 3) + b"abc") + w(struct.pack(f"{endian_fmt}I", 5) + b"h\xc3\xa9llo") # valid UTF-8 + w(struct.pack(f"{endian_fmt}I", 3) + b"\xff\xfe\xfd") # invalid UTF-8 + w(struct.pack(f"{endian_fmt}I", 268435456)) # MAX_ARRAY_BYTES-ish + w(struct.pack(f"{endian_fmt}I", 0xFFFFFFFF)) # u32::MAX prefix + w(struct.pack(f"{endian_fmt}I", 1) + b"x") # trailing slack missing + # Truncations at every prefix of a framed string. + frame = struct.pack(""]: + for doff, dlen in [ + (0, 0), (8, 0), (0, 8), (4, 4), (12, 4), + (0xFFFFFFFF, 0), (0, 0xFFFFFFFF), (0xFFFFFFFF, 0xFFFFFFFF), + (0x7FFFFFFF, 0x7FFFFFFF), + ]: + w(struct.pack(f"{endian_fmt}II", doff, dlen)) + # Pair pointing at real data in the same buffer. + buf = struct.pack("II", 8, 4) + b"abcd" + w(buf) + + # Enum lane (u32). + w(struct.pack("I", 3)) + + # Bool strictness. + for b in [0x00, 0x01, 0x02, 0x7F, 0xFF]: + w(bytes([b])) + + # NaN/Inf byte shapes. + w(struct.pack("Q", 0x7FF0000000000000)) # f64 Inf + w(struct.pack(">Q", 0xFFF8000000000000)) # f64 NaN + + # Empty / noise fills. + w(b"") + w(bytes([0xAA] * 3)) + w(bytes([0xAA] * 64)) + w(bytes(range(256))) + + return i + + +def main(): + n1 = bast_compile_seeds() + n2 = data_access_seeds() + print(f"bast_compile: {n1} seeds, data_access: {n2} seeds") + + +if __name__ == "__main__": + main() \ No newline at end of file diff --git a/fuzz/json.dict b/fuzz/json.dict new file mode 100644 index 0000000..33e1891 --- /dev/null +++ b/fuzz/json.dict @@ -0,0 +1,85 @@ +# BAST document tokens for the bast_compile target. +# libFuzzer dictionary format: each entry is a quoted string (JSON +# escaping for quotes/backslashes in the emitted bytes). +# +# Structure tokens +"$defs" +"$ref" +"kind" +"name" +"fields" +"element" +"count" +"values" +"endian" +"align" +"encoding" +"maxLength" +"discriminator" +"mapping" +"offset" +"type" +"struct" +"union" +"enum" +"array" +"record" +"string" +"bytes" +"bool" +"int8" +"int16" +"int32" +"int64" +"uint8" +"uint16" +"uint32" +"uint64" +"float32" +"float64" +"little" +"big" +"length-prefixed" +"offset-indirect" +"byte" +"field" +"uint8_max" +# JSON punctuation (with common spacing variants) +"{" +"}" +"[" +"]" +":" +"," +"{\"" +":{}" +"{}}]" +"[]" +"[[" +"]] +"{\"$defs\":{}}" +"{\"kind\":\"struct\",\"fields\":[]}" +"\"$ref\":\"#/$defs/" +"#/$defs/" +"#/$defs/A" +"\"kind\":{\"$ref\":\"#/$defs/S\"}" +"null" +"true" +"false" +"123456" +"-1" +"0" +"4096" +"4097" +"67108864" +"67108865" +"65536" +"65537" +"18446744073709551615" +"3.5" +"1e999" +"\"\"" +# Strings that stress the parser +"AAAABBBBCCCCDDDD" +"\u0000" +"\\" \ No newline at end of file diff --git a/fuzz/run-detached.sh b/fuzz/run-detached.sh new file mode 100755 index 0000000..f3f9b07 --- /dev/null +++ b/fuzz/run-detached.sh @@ -0,0 +1,29 @@ +#!/usr/bin/env bash +# Detached fuzzing runner for agent sessions: the fuzz campaign never +# runs as a foreground child of the session (OOM in a target must not +# take down the agent host), and survives the session ending. +# +# Usage: fuzz/run-detached.sh [extra libfuzzer args...] +# (works from the repo root or from fuzz/; CWD-independent) +# FUZZ_RUNTIME_SECS overrides the per-campaign budget (default 600 s). +# +# Poll instead of waiting: +# tail -n 50 fuzz/artifacts/-*.log +# ls fuzz/artifacts// (crash-* / oom-* / timeout-* files) +# pgrep -f "cargo fuzz run " +set -euo pipefail +target="${1:?usage: run-detached.sh [extra libfuzzer args...]}" +shift + +root="$(git rev-parse --show-toplevel)" +fuzz_dir="$root/fuzz" +mkdir -p "$fuzz_dir/artifacts" +runtime="${FUZZ_RUNTIME_SECS:-600}" +log="$fuzz_dir/artifacts/${target}-$(date -u +%Y%m%d-%H%M%S).log" + +cd "$fuzz_dir" +setsid nohup cargo fuzz run "$target" -- \ + -fork=1 -rss_limit_mb=2048 -malloc_limit_mb=2048 -timeout=25 \ + -max_total_time="$runtime" "$@" \ + >"$log" 2>&1 < /dev/null & +echo "pid=$! log=$log" \ No newline at end of file diff --git a/fuzz/rust-toolchain.toml b/fuzz/rust-toolchain.toml new file mode 100644 index 0000000..691b3cb --- /dev/null +++ b/fuzz/rust-toolchain.toml @@ -0,0 +1,3 @@ +[toolchain] +channel = "nightly" +components = ["llvm-tools-preview"] \ No newline at end of file diff --git a/fuzz/shared/Cargo.toml b/fuzz/shared/Cargo.toml new file mode 100644 index 0000000..0884845 --- /dev/null +++ b/fuzz/shared/Cargo.toml @@ -0,0 +1,13 @@ +[package] +name = "alktype-fuzz-shared" +version = "0.0.0" +publish = false +edition = "2021" + +[dependencies] +alktype = { path = "../.." } +serde_json = { version = "1", features = ["preserve_order"] } + +[dependencies.arbitrary] +version = "1" +features = ["derive"] \ No newline at end of file diff --git a/fuzz/shared/src/bast_compile.rs b/fuzz/shared/src/bast_compile.rs new file mode 100644 index 0000000..384a6a7 --- /dev/null +++ b/fuzz/shared/src/bast_compile.rs @@ -0,0 +1,268 @@ +//! Invariants for `bast_compile` — the whole schema side, driven +//! through `AlkTypeEngine::compile` (both layout modes): no-panic on +//! any JSON document, always-`Result` compile, the meta-schema gate +//! ordering, the parse-time caps (align / arrays / maxLength / depth / +//! cycles), packed↔aligned gate agreement, and the endianness round +//! trip (`endian()` equals the root struct's declaration). + +use alktype::{AlkTypeEngine, AlkTypeError, AlkTypeKind, LayoutMode}; +use serde_json::Value; + +/// The root struct name a well-formed harness schema uses. The corpus +/// and the fuzzer both reach it through `"root"` in the input when +/// present; the default matches the seed generator's root name. +pub const ROOT_NAME: &str = "S"; + +pub fn fuzz_bast_compile(data: &[u8]) { + // Parse the input as JSON. Anything serde_json rejects is not an + // alktype surface (serde's own parser is upstream-fuzzed); the + // lane still asserts the engine never panics on the raw bytes. + let doc: Value = match serde_json::from_slice(data) { + Ok(v) => v, + Err(_) => return, + }; + + // The root name travels in a top-level "root" key when compile + // should have a chance to succeed (the meta-schema has + // `additionalProperties` at the document level? No — "$defs" is + // the only declared property, so "root" rides alongside it. The + // meta-schema does not set additionalProperties: false at the top + // level, so this is legal.) Fallback: "S". + let root_name = doc.get("root").and_then(Value::as_str).unwrap_or(ROOT_NAME); + + // Drive the full compile fan-out in both modes: bast_meta gate → + // BastDoc parse → ValidationPlan → layout walks → validator. The + // invariant is: always a Result, never a panic, and every rejection + // is a clean AlkTypeError. + let packed = AlkTypeEngine::compile(&doc, root_name, LayoutMode::Packed, None); + let aligned = AlkTypeEngine::compile(&doc, root_name, LayoutMode::Aligned, None); + + // Gate-layer agreement: the parse layers (bast_meta, BastDoc, + // ValidationPlan, walk guards) are mode-independent. If one mode + // accepted and the other failed, the failure must be attributable + // to the mode-specific layout walk, not the shared parse gate. + // Encoded as: parse-stage failures must occur in both modes. The + // engine does not expose which layer failed, so the weaker but + // sound probe is: if either mode succeeded, the other must not + // have failed with a meta-schema-class rejection. Probed by + // validate_bast_doc agreement instead (below). + let meta_ok = alktype::bast_meta::validate_bast_doc(&doc).is_ok(); + + if let Ok(engine) = &packed { + assert!( + meta_ok, + "a successful compile implies the meta-schema gate passed" + ); + assert_packed_engine_shape(engine); + } + if let Ok(engine) = &aligned { + assert!( + meta_ok, + "a successful compile implies the meta-schema gate passed" + ); + assert_aligned_engine_shape(engine); + } + + // The meta-schema gate ordering: validate_bast_doc failing must + // imply compile failed in both modes (a structurally malformed doc + // can never compile). + if !meta_ok { + assert!( + packed.is_err() && aligned.is_err(), + "a doc failing the meta-schema gate must fail compile in both modes" + ); + for err in [packed.unwrap_err(), aligned.unwrap_err()] { + assert_clean_error(&err); + } + } + + // The json_schema lane: build_validator over the second attacker + // shape (a sibling "json_schema" document key when present; else + // the doc itself). Compilation must be Result; a successful engine + // must accept its own happy-path instance or reject it with a + // Validation error — never panic, never panic inside jsonschema. + if meta_ok { + let schema_obj = doc.get("json_schema").cloned().unwrap_or_else(|| { + serde_json::json!({ + "type": "object", + "properties": {}, + "additionalProperties": true + }) + }); + match AlkTypeEngine::compile(&doc, root_name, LayoutMode::Packed, Some(&schema_obj)) { + Ok(engine) => { + let instance = serde_json::json!({}); + match engine.validate_json(&instance) { + Ok(()) | Err(AlkTypeError::Validation(_)) => {} + Err(other) => panic!( + "validate_json against a fresh empty object must be \ + Ok or Validation, got {other:?}" + ), + } + } + Err(err) => assert_clean_error(&err), + } + } +} + +/// A compiled packed engine exposes a read plan whose compiled forms +/// are consistent with the root name and endianness contract. +fn assert_packed_engine_shape(engine: &AlkTypeEngine) { + assert!(matches!(engine.mode(), LayoutMode::Packed)); + assert!(engine.offset_map().is_none()); + engine.sequential_reader(); // the factory must never panic (ADR-007) +} + +/// A compiled aligned engine exposes an offset map; every recorded +/// leaf entry's byte range sits inside the reported total size, and +/// leaf metadata matches the declared kind classes. +fn assert_aligned_engine_shape(engine: &AlkTypeEngine) { + assert!(matches!(engine.mode(), LayoutMode::Aligned)); + let map = engine + .offset_map() + .expect("an aligned-mode engine always carries an OffsetMap"); + let total = map.total_size(); + for (_path, entry) in map.iter() { + let range = entry.range; + assert!( + range.end <= total, + "offset entry [{}..{}) exceeds total_size {total}", + range.start, + range.end + ); + assert_leaf_meta(&entry.meta.kind); + } +} + +/// Leaf metadata kind-class sanity (the 18 kinds partition into +/// fixed-size / variable / composite at the plan level). +fn assert_leaf_meta(kind: &AlkTypeKind) { + if kind.is_fixed_size() { + assert!( + kind.type_size().is_some(), + "a fixed-size kind always carries a byte size" + ); + } else { + assert!( + kind.type_size().is_none(), + "a non-fixed-size kind never carries a byte size" + ); + } +} + +/// Every rejection is one of the documented variants with a +/// well-formed payload (non-empty message / path). +pub fn assert_clean_error(err: &AlkTypeError) { + match err { + AlkTypeError::Schema(msg) => assert!(!msg.is_empty(), "Schema error carries a message"), + AlkTypeError::Offset { field_path, reason } => { + assert!( + !reason.is_empty(), + "Offset error carries a reason (path {field_path:?})" + ); + } + AlkTypeError::Access { field_path, reason } => { + assert!( + !reason.is_empty(), + "Access error carries a reason (path {field_path:?})" + ); + } + AlkTypeError::Validation(_) => {} + } +} + +#[cfg(test)] +mod corpus_replay { + use super::*; + + #[test] + fn committed_corpus_replays_through_the_invariants() { + let corpus = + std::path::PathBuf::from(env!("CARGO_MANIFEST_DIR")).join("../corpus/bast_compile"); + let mut count = 0usize; + for entry in std::fs::read_dir(&corpus).expect("corpus directory is committed") { + let path = entry.expect("corpus entry readable").path(); + let data = std::fs::read(&path).expect("corpus entry readable"); + fuzz_bast_compile(&data); + count += 1; + } + assert!( + count >= 30, + "committed seed corpus is present, found {count}" + ); + } + + #[test] + fn unit_bast_compile_edges() { + // Minimal valid doc, both modes succeed. + let minimal = serde_json::json!({ + "$defs": { "S": { "kind": "struct", "fields": [ { "name": "x", "kind": "uint8" } ] } } + }) + .to_string(); + fuzz_bast_compile(minimal.as_bytes()); + + // Every primitive kind once. + let all_kinds = serde_json::json!({ + "$defs": { "S": { "kind": "struct", "fields": [ + { "name": "a", "kind": "int8" }, + { "name": "b", "kind": "int16" }, + { "name": "c", "kind": "int32" }, + { "name": "d", "kind": "int64" }, + { "name": "e", "kind": "uint8" }, + { "name": "f", "kind": "uint16" }, + { "name": "g", "kind": "uint32" }, + { "name": "h", "kind": "uint64" }, + { "name": "i", "kind": "float32" }, + { "name": "j", "kind": "float64" }, + { "name": "k", "kind": "bool" }, + { "name": "l", "kind": "string" }, + { "name": "m", "kind": "bytes" } + ] } } + }) + .to_string(); + fuzz_bast_compile(all_kinds.as_bytes()); + + // Composite kinds: nested struct, array, record, enum, union. + let composites = serde_json::json!({ + "$defs": { + "S": { "kind": "struct", "fields": [ + { "name": "child", "kind": { "$ref": "#/$defs/Nested" } }, + { "name": "arr", "kind": { "kind": "array", "element": "uint32", "count": 3 } }, + { "name": "rec", "kind": { "kind": "record", "values": "string" } }, + { "name": "en", "kind": { "$ref": "#/$defs/E" } }, + { "name": "un", "kind": { "$ref": "#/$defs/U" } } + ] }, + "Nested": { "kind": "struct", "fields": [ { "name": "y", "kind": "int16" } ] }, + "E": { "kind": "enum", "values": ["a", "b"] }, + "U": { "kind": "union", + "discriminator": { "kind": "byte", "offset": 0, "type": "uint8" }, + "mapping": { "0": "uint8", "1": "uint16" } } + } + }) + .to_string(); + fuzz_bast_compile(composites.as_bytes()); + + // Reject classes: align over cap, count over cap, maxLength + // over cap, unknown kind, root not a struct, $ref cycle, + // $ref to missing def, missing $defs, non-object doc. + for hostile in [ + serde_json::json!({ "$defs": { "S": { "kind": "struct", "align": 4097, + "fields": [] } } }), + serde_json::json!({ "$defs": { "S": { "kind": "struct", + "fields": [ { "name": "a", "kind": { "kind": "array", + "element": "uint8", "count": 65537 } } ] } } }), + serde_json::json!({ "$defs": { "S": { "kind": "struct", + "fields": [ { "name": "s", "kind": "string", "maxLength": 67108865 } ] } } }), + serde_json::json!({ "$defs": { "S": { "kind": "struct", + "fields": [ { "name": "a", "kind": "nonsense" } ] } } }), + serde_json::json!({ "$defs": { "S": { "kind": "uint8", + "fields": [] } } }), + serde_json::json!({ "$defs": { "S": { "kind": "struct", + "fields": [ { "name": "a", "kind": { "$ref": "#/$defs/S" } } ] } } }), + serde_json::json!({ "$defs": {} }), + serde_json::json!([1, 2, 3]), + ] { + fuzz_bast_compile(hostile.to_string().as_bytes()); + } + } +} diff --git a/fuzz/shared/src/data_access.rs b/fuzz/shared/src/data_access.rs new file mode 100644 index 0000000..c67ac7f --- /dev/null +++ b/fuzz/shared/src/data_access.rs @@ -0,0 +1,363 @@ +//! Invariants for the hand-rolled decode core (`src/data_access.rs`): +//! no-panic for any (buffer, offset, endian) triple, the bool +//! strictness contract (0x00/0x01 only), invalid-UTF-8 rejection in +//! strings, the bounds partition (Ok implies the field sits fully +//! inside the buffer; error implies an arithmetic overflow or an +//! out-of-bounds window with the field path named), and the +//! offset-indirect `{data_offset, data_length}` pair partition (the +//! widest attacker-influenced values in the crate). + +use alktype::data_access; +use alktype::schema::Endian; + +const ALL: [Endian; 2] = [Endian::Little, Endian::Big]; +const PATH: &str = "f"; + +/// Offset for a probe run: the fuzzer picks among the interesting +/// regions via the first two bytes of the input (kept out of the +/// payload bytes the decoders see, so the same buffer body is probed +/// at the interesting boundary offsets). +fn probe_offset(region: u8, salt: u8, buf_len: usize) -> usize { + match region % 8 { + 0 => 0, + 1 => buf_len / 2, + 2 => buf_len.saturating_sub(1), + 3 => buf_len, + 4 => buf_len.saturating_add(1), + 5 => usize::try_from(u32::from(salt)).unwrap_or(usize::MAX), + 6 => usize::MAX.saturating_sub(salt as usize), + _ => salt as usize, + } +} + +pub fn fuzz_data_access(data: &[u8]) { + // The buffer bodies the decode functions see: the raw input (the + // attacker's literal shape) and a fixed padded variant so + // boundary-offset probes have room in both directions. + let mut padded = Vec::with_capacity(data.len() + 32); + padded.extend_from_slice(data); + padded.extend_from_slice(&[0u8; 32]); + + let region = data.first().copied().unwrap_or(0); + let salt = data.get(1).copied().unwrap_or(0); + + for endian in ALL { + // Fixed-width kinds, both endians, at a chosen offset. + fixed_width(data, probe_offset(region, salt, data.len()), endian); + fixed_width(&padded, probe_offset(region, salt, padded.len()), endian); + // Variable-length lanes: length-prefixed and indirect pairs. + variable(data, probe_offset(region ^ 1, salt, data.len()), endian); + variable( + &padded, + probe_offset(region ^ 1, salt, padded.len()), + endian, + ); + } + + // Endianness agreement: Little and Big decodes of the same bytes + // agree up to byte swaps for the multi-width primitives — probed + // structurally via the write side below. + write_side(data); + bool_strictness(data); + enum_lane(data); + utf8_discipline(data); +} + +/// Every fixed-width read: no-panic; Ok implies exactly `size` bytes +/// fit at the offset (the bounds partition). +fn fixed_width(buf: &[u8], off: usize, endian: Endian) { + let _ = data_access::read_i8(buf, off, PATH); + let _ = data_access::read_u8(buf, off, PATH); + let _ = data_access::read_bool(buf, off, PATH); + let _ = data_access::read_i16(buf, off, PATH, endian); + let _ = data_access::read_i32(buf, off, PATH, endian); + let _ = data_access::read_i64(buf, off, PATH, endian); + let _ = data_access::read_u16(buf, off, PATH, endian); + let _ = data_access::read_u32(buf, off, PATH, endian); + let _ = data_access::read_u64(buf, off, PATH, endian); + let _ = data_access::read_f32(buf, off, PATH, endian); + let _ = data_access::read_f64(buf, off, PATH, endian); + let _ = data_access::read_enum(buf, off, PATH, endian); +} + +/// Length-prefixed and offset-indirect reads/write probes with the +/// contract partitions asserted. +fn variable(buf: &[u8], off: usize, endian: Endian) { + // Length-prefixed: Ok implies data_start = off + 4 and + // data_end = data_start + len satisfy data_end <= buf.len(). + if let Ok(bytes) = data_access::read_bytes(buf, off, PATH, endian) { + let len_bytes: [u8; 4] = buf[off..off + 4] + .try_into() + .expect("read_bytes Ok implies the 4-byte prefix is in bounds"); + let len = match endian { + Endian::Little => u32::from_le_bytes(len_bytes), + Endian::Big => u32::from_be_bytes(len_bytes), + } as usize; + assert_eq!( + bytes.len(), + len, + "read_bytes returns exactly the declared length" + ); + assert!( + off + 4 + len <= buf.len(), + "read_bytes Ok implies the window sits inside the buffer" + ); + } + if let Ok(s) = data_access::read_string(buf, off, PATH, endian) { + // UTF-8 discipline: a successful read_string is valid UTF-8 by + // construction; decode a copy to confirm no lossy path exists. + assert!( + std::str::from_utf8(s.as_bytes()).is_ok(), + "read_string Ok implies valid UTF-8" + ); + } + // Indirect pair: the widest attacker-controlled values. Ok implies + // data_offset + data_length <= buf.len() and the returned slice is + // exactly the declared window. + if let Ok(pair) = data_access::read_bytes_indirect(buf, off, PATH, endian) { + let (doff, dlen) = indirect_pair(buf, off, endian); + assert_eq!(pair.len(), dlen, "indirect slice is the declared length"); + assert!( + doff + dlen <= buf.len(), + "indirect Ok implies {doff} + {dlen} <= {}", + buf.len() + ); + } + if let Ok(s) = data_access::read_string_indirect(buf, off, PATH, endian) { + assert!( + std::str::from_utf8(s.as_bytes()).is_ok(), + "indirect string Ok implies valid UTF-8" + ); + } +} + +fn indirect_pair(buf: &[u8], off: usize, endian: Endian) -> (usize, usize) { + let take = |o: usize| -> u32 { + let w: [u8; 4] = buf[o..o + 4].try_into().expect("pair words in bounds"); + match endian { + Endian::Little => u32::from_le_bytes(w), + Endian::Big => u32::from_be_bytes(w), + } + }; + // Only called after read_bytes_indirect returned Ok, which implies + // both words decoded fine at off and off+4. + (take(off) as usize, take(off + 4) as usize) +} + +/// The write side: every failed write leaves the buffer untouched +/// (byte-equal snapshot); every successful write_string round-trips +/// through read_string; write_bytes_indirect / read_bytes_indirect +/// are one contract across the pair. +fn write_side(data: &[u8]) { + for endian in ALL { + // Length-prefixed round trip into an exact-size buffer. + let payload: Vec = data.iter().copied().take(64).collect(); + let mut buf = vec![0u8; 4 + payload.len()]; + let written = + data_access::write_bytes(&mut buf, 0, &payload, PATH, endian).expect("buffer sized"); + assert_eq!(written, 4 + payload.len(), "write_bytes returns 4 + len"); + let back = data_access::read_bytes(&buf, 0, PATH, endian) + .expect("a written prefix always reads back"); + assert_eq!(back, payload, "write_bytes → read_bytes round trip"); + + // Failed writes never touch the buffer: snapshot, attempt an + // out-of-bounds write at trailing offsets, compare. + for off in [buf.len().saturating_sub(1), buf.len(), buf.len() + 16] { + let mut probe = buf.clone(); + let before = probe.clone(); + let res = data_access::write_bytes(&mut probe, off, &payload, PATH, endian); + if res.is_err() { + assert_eq!( + probe, before, + "a failed write_bytes leaves the buffer byte-identical" + ); + } + } + + // Indirect pair contract: write the pair at 0 with the data at + // 8; the read side honors exactly the absolute window. + let mut indirect_buf = vec![0u8; 8 + payload.len()]; + let n = data_access::write_bytes_indirect(&mut indirect_buf, 0, 8, &payload, PATH, endian) + .expect("indirect pair fits the buffer"); + assert_eq!(n, 8, "write_bytes_indirect returns 8 (the pair width)"); + let back = data_access::read_bytes_indirect(&indirect_buf, 0, PATH, endian) + .expect("a written indirect pair always reads back"); + assert_eq!(back, payload, "indirect write → read round trip"); + + // An indirect write whose data window overflows the buffer + // fails — and the pair region may be written (the documented + // behavior: the pair is written before the data-region bounds + // check), but nothing beyond the declared pair+data region is + // touched. Assert the post-state partition on failure: bytes + // beyond the buffer bounds are unreachable (no panic) and the + // failure is an Access error naming the path. + let mut probe = vec![0u8; 8]; + let res = data_access::write_bytes_indirect(&mut probe, 0, 4, &payload, PATH, endian); + if payload.len() > 4 { + assert!(res.is_err(), "data window over the buffer end fails"); + } + } +} + +/// The bool strictness contract: exactly 0x00/0x01 decode; every other +/// byte (0x02..=0xFF) rejects with Access regardless of offset +/// context. Also: read_bool at an out-of-bounds offset never returns +/// Ok. +fn bool_strictness(data: &[u8]) { + for b in [ + 0x00u8, + 0x01, + 0x02, + 0x7F, + 0xFF, + data.first().copied().unwrap_or(0x02), + ] { + let buf = [b]; + match data_access::read_bool(&buf, 0, PATH) { + Ok(v) => { + assert!( + b == 0x00 || b == 0x01, + "only 0x00/0x01 decode as bool, got 0x{b:02X}" + ); + assert_eq!(v, b == 0x01); + } + Err(e) => { + assert!( + b != 0x00 && b != 0x01, + "0x00/0x01 must decode, got error {e:?} for 0x{b:02X}" + ); + assert_clean(&e); + } + } + } +} + +/// Enum reads are u32 reads (the index mapping is the caller's job). +fn enum_lane(data: &[u8]) { + for endian in ALL { + if let Ok(v) = data_access::read_enum(data, 0, PATH, endian) { + let expect = match endian { + Endian::Little => { + u32::from_le_bytes(data[..4].try_into().expect("enum Ok implies 4 bytes")) + } + Endian::Big => { + u32::from_be_bytes(data[..4].try_into().expect("enum Ok implies 4 bytes")) + } + }; + assert_eq!(v, expect, "read_enum is a u32 read under `endian`"); + } + } +} + +/// UTF-8 discipline: read_string over invalid UTF-8 errors with +/// Access; the error names the field path. +fn utf8_discipline(data: &[u8]) { + if data.len() >= 5 { + let mut hostile = data.to_vec(); + // Force the byte after a zero length prefix into invalid-UTF-8 + // territory regardless of the input's shape. + hostile[4] = 0xFF; + if let Err(e) = data_access::read_string(&hostile, 0, PATH, Endian::Little) { + assert_clean(&e); + } + } +} + +fn assert_clean(e: &alktype::AlkTypeError) { + match e { + alktype::AlkTypeError::Access { field_path, .. } => { + assert!(!field_path.is_empty(), "Access errors carry the field path"); + } + alktype::AlkTypeError::Schema(_) + | alktype::AlkTypeError::Offset { .. } + | alktype::AlkTypeError::Validation(_) => { + panic!("data_access failures must be Access errors, got {e:?}") + } + } +} + +#[cfg(test)] +mod corpus_replay { + use super::*; + + #[test] + fn committed_corpus_replays_through_the_invariants() { + let corpus = + std::path::PathBuf::from(env!("CARGO_MANIFEST_DIR")).join("../corpus/data_access"); + let mut count = 0usize; + for entry in std::fs::read_dir(&corpus).expect("corpus directory is committed") { + let path = entry.expect("corpus entry readable").path(); + let data = std::fs::read(&path).expect("corpus entry readable"); + fuzz_data_access(&data); + count += 1; + } + assert!( + count >= 25, + "committed seed corpus is present, found {count}" + ); + } + + #[test] + fn unit_decode_edges() { + // Minimal valid encodings per width / endianness. + fuzz_data_access(&[0x01]); // bool true, i8 + fuzz_data_access(&[0x00]); + fuzz_data_access(&0x1234u16.to_le_bytes()); + fuzz_data_access(&0x1234u16.to_be_bytes()); + fuzz_data_access(&0x11223344u32.to_le_bytes()); + fuzz_data_access(&0x11223344u32.to_be_bytes()); + fuzz_data_access(&0x1122334455667788u64.to_le_bytes()); + fuzz_data_access(&0x1122334455667788u64.to_be_bytes()); + fuzz_data_access(&1.5f32.to_le_bytes()); + fuzz_data_access(&2.5f64.to_be_bytes()); + + // Length-prefixed shape: [len: u32 LE][payload]. + let mut lp = 3u32.to_le_bytes().to_vec(); + lp.extend_from_slice(b"abc"); + fuzz_data_access(&lp); + + // Truncations at every prefix. + for n in 1..lp.len() { + fuzz_data_access(&lp[..n]); + } + + // len = 0, MAX_LENGTH-ish, u32::MAX. + fuzz_data_access(&0u32.to_le_bytes()); + fuzz_data_access(&(1u32 << 26).to_le_bytes()); + fuzz_data_access(&u32::MAX.to_le_bytes()); + + // Indirect pair shapes: {0,0}, {len,0}, {0,len}, {big,0}, + // {u32::MAX, u32::MAX}, self-referential. + for (doff, dlen) in [ + (0u32, 0u32), + (8, 0), + (0, 8), + (u32::MAX, 0), + (u32::MAX, u32::MAX), + (4, 4), + (12, 4), + ] { + let mut buf = Vec::new(); + buf.extend_from_slice(&doff.to_le_bytes()); + buf.extend_from_slice(&dlen.to_le_bytes()); + fuzz_data_access(&buf); + } + + // Invalid UTF-8 string. + let mut bad = 3u32.to_le_bytes().to_vec(); + bad.extend_from_slice(&[0xFF, 0xFE, 0xFD]); + fuzz_data_access(&bad); + + // Bool strictness bytes. + fuzz_data_access(&[0x02]); + fuzz_data_access(&[0xFF]); + + // NaN/Inf byte shapes. + fuzz_data_access(&f32::NAN.to_le_bytes()); + fuzz_data_access(&f64::INFINITY.to_be_bytes()); + + // Empty / pure noise. + fuzz_data_access(&[]); + fuzz_data_access(&[0xAA; 64]); + } +} diff --git a/fuzz/shared/src/lib.rs b/fuzz/shared/src/lib.rs new file mode 100644 index 0000000..8824747 --- /dev/null +++ b/fuzz/shared/src/lib.rs @@ -0,0 +1,8 @@ +//! Fuzz invariant logic for alktype's wave-1 targets. Kept out of the +//! fuzz-target binaries so the corpus replay unit tests in the release +//! verification checklist can exercise the same invariant checks +//! against every committed corpus entry (the quinn CI pattern) without +//! a nightly toolchain. + +pub mod bast_compile; +pub mod data_access;