Unblock the last two fuzz targets; the pin lived in two places - #12
Merged
3 commits merged intoSep 19, 2026
Merged
3 commits merged into
3 commits merged into
Conversation
forest_decode and snapshot_decode had been excluded from the campaign for four phases because both reach MemForest::deserialize, which panicked on a bad node-type byte and overflowed the stack on nested input (D33). The fork fix is now pushed, so the pin moves to 8931ab8 and both targets go back in. All five committed crash artifacts replay clean. A smoke run took forest_decode's corpus from 8 inputs to 514 over 10M runs with no crashes, and snapshot_decode's from 100 to 361. Eight inputs after four phases is the measure of how thoroughly the exclusion had blinded the campaign. Throughput differs by 20x between the two -- 48k exec/s against 2.5k -- which is what the next campaign should be budgeted from rather than the clock. The fix walked into its own trap first. fuzz/ sits outside the workspace and so carries a second [patch.crates-io] block; bumping only the workspace pin left the fuzzer on dc368cc, and every artifact still reproduced -- against a bug already fixed. That reads as a falsified fix rather than a stale pin, and the only give-away was the rev in the panic path. tests/pins_agree.rs now fails if the two revs diverge, or if either is abbreviated. Confirmed to fire by reverting one. Coverage floors: utreexo.rs lines 91.5 -> 91.1, the one figure the pin bump moved. Also found that nightly-2026-09-06 installs rustc f248f4038 2026-09-05, which is not the plain `nightly` of that date and does not report the same region counts -- so floors are now the minimum across all three configurations measured, less 0.3, and verified green against each. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
…es it fuzz-runs/*.log are tracked, and scripts/fuzz_72h.sh writes them in place. The 2026-08-25 run is what D36's budget conclusions are read off -- notably that bundle_decode was still finding edges at 71.5 h -- so it moves to a dated subdirectory rather than being overwritten by the run that supersedes it. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
forest_decode and snapshot_decode had been excluded from the campaign for four phases because both reach MemForest::deserialize, which panicked on a bad node-type byte and overflowed the stack on nested input (D33). The fork fix is now pushed, so the pin moves to 8931ab8 and both targets go back in.
All five committed crash artifacts replay clean. A smoke run took forest_decode's corpus from 8 inputs to 514 over 10M runs with no crashes, and snapshot_decode's from 100 to 361. Eight inputs after four phases is the measure of how thoroughly the exclusion had blinded the campaign. Throughput differs by 20x between the two -- 48k exec/s against 2.5k -- which is what the next campaign should be budgeted from rather than the clock.
The fix walked into its own trap first. fuzz/ sits outside the workspace and so carries a second [patch.crates-io] block; bumping only the workspace pin left the fuzzer on dc368cc, and every artifact still reproduced -- against a bug already fixed. That reads as a falsified fix rather than a stale pin, and the only give-away was the rev in the panic path. tests/pins_agree.rs now fails if the two revs diverge, or if either is abbreviated. Confirmed to fire by reverting one.
Coverage floors: utreexo.rs lines 91.5 -> 91.1, the one figure the pin bump moved. Also found that nightly-2026-09-06 installs rustc f248f4038 2026-09-05, which is not the plain
nightlyof that date and does not report the same region counts -- so floors are now the minimum across all three configurations measured, less 0.3, and verified green against each.