Skip to content

feat(fuzz): add cargo-fuzz harnesses for roundtrip + decoder coverage - #304

Open
liqdmetal wants to merge 2 commits into
jamesmunns:mainfrom
liqdmetal:feat/add-oss-fuzz-harnesses
Open

liqdmetal wants to merge 2 commits into
jamesmunns:mainfrom
liqdmetal:feat/add-oss-fuzz-harnesses

Conversation

@liqdmetal

Copy link
Copy Markdown

Summary

Adds a fuzz/ workspace with two libFuzzer targets to support OSS-Fuzz onboarding:

  • postcard_roundtrip_fuzzer — decode arbitrary bytes → re-encode → re-decode → assert equal. Catches encode/decode asymmetry and stack overflows on deeply-nested input.
  • postcard_decoder_fuzzer — pure deserialization coverage over arbitrary (mostly malformed) bytes, plus the COBS framing path.

Both drive a recursive FuzzValue enum covering every serde type path (bool/int/uint/float/str/bytes/seq/map). postcard is a binary, non-self-describing format, so attacker-controlled varint length prefixes, string/map/sequence lengths, and COBS framing are the correct fuzz surface.

Verification

Compile-validated against the local postcard crate (v1.1.3, use-std feature) — cargo check passes on all API usage (from_bytes, to_stdvec, to_slice, from_bytes_cobs).

Notes

  • fuzz/ is its own workspace so it does not collide with the root workspace.
  • The postcard dependency is referenced via path = "../source/postcard" to match the repo layout.
  • This is the first step toward OSS-Fuzz integration (harness PR first, then projects/postcard/ config in google/oss-fuzz).

Add a fuzz/ workspace with two libFuzzer harnesses:
- postcard_roundtrip_fuzzer: decode -> re-encode -> re-decode -> assert equal
- postcard_decoder_fuzzer: pure deserialization + COBS framing over arbitrary bytes

Compile-validated against the local postcard crate (v1.1.3, use-std).
@netlify

netlify Bot commented Aug 31, 2026 •

Copy link
Copy Markdown

✅ Deploy Preview for cute-starship-2d9c9b canceled.

Name Link
🔨 Latest commit 01f40f4
🔍 Latest deploy log https://app.netlify.com/projects/cute-starship-2d9c9b/deploys/6a9b41dc5367a000085c5bae

- extract duplicated FuzzValue enum into fuzz_targets/common.rs
- roundtrip: assert all three framing paths stable (varint heap, varint
  slice, COBS) instead of one dead to_slice call on raw input
- decoder: use shared FuzzValue, keep payload-shape + COBS coverage
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant