- fuzz/ workspace (nightly-pinned subtree, own [workspace]), copied
from the alkhttp/alkcall pattern: thin fuzz_target wrappers,
stable-toolchain shared crate holding the invariant logic, detached
runner, seed generator, json.dict, README
- bast_compile: AlkTypeEngine::compile both modes over attacker BAST
JSON; meta-schema gate ordering, always-Result, fixed-size leaf
metadata partition, json_schema lane
- data_access: the hand-rolled decode core over raw bytes at
attacker-chosen offsets; bool strictness, UTF-8 discipline, bounds
partitions, indirect {offset,length} pair contract, write-side
no-touch-on-failure + write/read round trips
- 136 committed seeds (38 + 98) via fuzz/gen_fuzz_seeds.py
- root Cargo.toml: explicit [workspace] exclude=[fuzz]; publish
exclude gains fuzz/
- AGENTS.md verification checklist gains the corpus-replay gate
- .gitignore: fuzz artifacts + grown-corpus pattern
Verification: cargo test 569 pass; clippy -D warnings clean; corpus
replay 4/4 green (136 seeds); cargo fuzz build clean (nightly
confined to fuzz/)
29 lines
1.1 KiB
Bash
Executable File
29 lines
1.1 KiB
Bash
Executable File
#!/usr/bin/env bash
|
|
# Detached fuzzing runner for agent sessions: the fuzz campaign never
|
|
# runs as a foreground child of the session (OOM in a target must not
|
|
# take down the agent host), and survives the session ending.
|
|
#
|
|
# Usage: fuzz/run-detached.sh <target> [extra libfuzzer args...]
|
|
# (works from the repo root or from fuzz/; CWD-independent)
|
|
# FUZZ_RUNTIME_SECS overrides the per-campaign budget (default 600 s).
|
|
#
|
|
# Poll instead of waiting:
|
|
# tail -n 50 fuzz/artifacts/<target>-*.log
|
|
# ls fuzz/artifacts/<target>/ (crash-* / oom-* / timeout-* files)
|
|
# pgrep -f "cargo fuzz run <target>"
|
|
set -euo pipefail
|
|
target="${1:?usage: run-detached.sh <target> [extra libfuzzer args...]}"
|
|
shift
|
|
|
|
root="$(git rev-parse --show-toplevel)"
|
|
fuzz_dir="$root/fuzz"
|
|
mkdir -p "$fuzz_dir/artifacts"
|
|
runtime="${FUZZ_RUNTIME_SECS:-600}"
|
|
log="$fuzz_dir/artifacts/${target}-$(date -u +%Y%m%d-%H%M%S).log"
|
|
|
|
cd "$fuzz_dir"
|
|
setsid nohup cargo fuzz run "$target" -- \
|
|
-fork=1 -rss_limit_mb=2048 -malloc_limit_mb=2048 -timeout=25 \
|
|
-max_total_time="$runtime" "$@" \
|
|
>"$log" 2>&1 < /dev/null &
|
|
echo "pid=$! log=$log" |