Files
alktype/fuzz/README.md
T
glm-5.3-flash ed41d77e72 fuzz: wave 1 — infra + bast_compile/data_access targets, seeds, corpus-replay gate
- fuzz/ workspace (nightly-pinned subtree, own [workspace]), copied
  from the alkhttp/alkcall pattern: thin fuzz_target wrappers,
  stable-toolchain shared crate holding the invariant logic, detached
  runner, seed generator, json.dict, README
- bast_compile: AlkTypeEngine::compile both modes over attacker BAST
  JSON; meta-schema gate ordering, always-Result, fixed-size leaf
  metadata partition, json_schema lane
- data_access: the hand-rolled decode core over raw bytes at
  attacker-chosen offsets; bool strictness, UTF-8 discipline, bounds
  partitions, indirect {offset,length} pair contract, write-side
  no-touch-on-failure + write/read round trips
- 136 committed seeds (38 + 98) via fuzz/gen_fuzz_seeds.py
- root Cargo.toml: explicit [workspace] exclude=[fuzz]; publish
  exclude gains fuzz/
- AGENTS.md verification checklist gains the corpus-replay gate
- .gitignore: fuzz artifacts + grown-corpus pattern

Verification: cargo test 569 pass; clippy -D warnings clean; corpus
replay 4/4 green (136 seeds); cargo fuzz build clean (nightly
confined to fuzz/)
2026-09-30 05:03:07 +00:00

2.3 KiB

alktype fuzzing

cargo-fuzz targets for the binary struct engine's untrusted-input surfaces. The design and operating rules live in docs/plans/fuzzing.md (adopted from alkhttp's docs/plans/fuzzing.md; rationale in alkcall's docs/research/fuzzing.md) — this README is the operational cheat-sheet.

Layout

  • fuzz_targets/ — nightly-only fuzz_target! binaries (thin wrappers).
  • shared/ — stable-toolchain library holding the invariant logic; the corpus replay tests run here on plain cargo test.
  • corpus/<target>/ — committed seeds (regenerate with python3 fuzz/gen_fuzz_seeds.py).
  • artifacts/ — gitignored crash/oom/timeout artifacts + campaign logs.

Targets

Target Drives
bast_compile AlkTypeEngine::compile in both layout modes over attacker-shaped BAST JSON (the whole schema side through one choke point) + validate_bast_doc + build_validator
data_access the hand-rolled decode core (src/data_access.rs): fixed-width kinds, bool strictness, length-prefixed and indirect string/bytes, enums — over raw bytes with attacker-chosen offsets and endianness

Running a campaign — always detached

Agent sessions must never run fuzzing in the foreground (an OOM in a target can take down the session host; see docs/plans/fuzzing.md §2). Use the detached runner:

fuzz/run-detached.sh bast_compile
# poll:
tail -n 50 fuzz/artifacts/bast_compile-*.log
ls fuzz/artifacts/bast_compile/
pgrep -f "cargo fuzz run bast_compile"

FUZZ_RUNTIME_SECS=1800 fuzz/run-detached.sh bast_compile for a longer campaign. The runner pins -fork=1 -rss_limit_mb=2048 -malloc_limit_mb=2048 -timeout=25 and detaches via setsid + nohup.

Corpus replay (the standing fuzz gate)

cargo test --manifest-path fuzz/shared/Cargo.toml

replays every committed seed through the same invariant functions the fuzz targets run — on stable, without nightly, no cargo-fuzz. Part of the release verification checklist (AGENTS.md).

Toolchain

fuzz/rust-toolchain.toml pins nightly (+ llvm-tools-preview) for this subtree only; the main crate stays stable at MSRV 1.85. cargo fuzz build works from any CWD inside fuzz/ (rustup resolves the toolchain per directory). Build:

cd fuzz && cargo fuzz build
# or from the repo root — the toolchain file is picked up by path:
cargo fuzz build -D