The CI workflow only builds the fuzz targets but never runs them
There is no cmake --build build-fuzz --target fuzz step that executes the fuzzers
There is no fuzzing corpus checked into the repository
No regression tests for previously-found fuzz crashes
No OSS-Fuzz integration
Suggested improvements
Add a CI job that runs each fuzz target for a short duration (e.g., 30 seconds each) to catch regressions
Check in a minimal seed corpus for each fuzz target
Add a CIFuzz GitHub Action or Gitea equivalent for regression fuzzing on PRs
Consider OSS-Fuzz integration for continuous fuzzing
Add coverage-guided fuzzing with -runs=N and -max_total_time=N flags
The build already works (cmake -B build-fuzz -S . -DENABLE_FUZZ=ON && cmake --build build-fuzz), just the run step is missing.
Labels: testing, security, fuzzing, ci
The project has **6 fuzz targets** in `tests/fuzz/`:
- `fuzz_chunk_deserialize.c`
- `fuzz_compress_decompress.c`
- `fuzz_delta_deserialize.c`
- `fuzz_delta_signature_deserialize.c`
- `fuzz_glob_match.c`
- `fuzz_metadata_from_buf.c`
However:
1. The CI workflow only **builds** the fuzz targets but never runs them
2. There is no `cmake --build build-fuzz --target fuzz` step that executes the fuzzers
3. There is no fuzzing corpus checked into the repository
4. No regression tests for previously-found fuzz crashes
5. No OSS-Fuzz integration
## Suggested improvements
1. Add a CI job that runs each fuzz target for a short duration (e.g., 30 seconds each) to catch regressions
2. Check in a minimal seed corpus for each fuzz target
3. Add a CIFuzz GitHub Action or Gitea equivalent for regression fuzzing on PRs
4. Consider OSS-Fuzz integration for continuous fuzzing
5. Add coverage-guided fuzzing with `-runs=N` and `-max_total_time=N` flags
The build already works (`cmake -B build-fuzz -S . -DENABLE_FUZZ=ON && cmake --build build-fuzz`), just the run step is missing.
**Labels**: testing, security, fuzzing, ci
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
The project has 6 fuzz targets in
tests/fuzz/:fuzz_chunk_deserialize.cfuzz_compress_decompress.cfuzz_delta_deserialize.cfuzz_delta_signature_deserialize.cfuzz_glob_match.cfuzz_metadata_from_buf.cHowever:
cmake --build build-fuzz --target fuzzstep that executes the fuzzersSuggested improvements
-runs=Nand-max_total_time=NflagsThe build already works (
cmake -B build-fuzz -S . -DENABLE_FUZZ=ON && cmake --build build-fuzz), just the run step is missing.Labels: testing, security, fuzzing, ci