Skip to content

Unblock the last two fuzz targets; the pin lived in two places - #12

Merged
3 commits merged into
mainfrom
phase-6d-fuzz-unblock
Sep 19, 2026
Merged

3 commits merged into
mainfrom
phase-6d-fuzz-unblock

Conversation

@USCMig

@USCMig USCMig commented Sep 10, 2026

Copy link
Copy Markdown
Collaborator

forest_decode and snapshot_decode had been excluded from the campaign for four phases because both reach MemForest::deserialize, which panicked on a bad node-type byte and overflowed the stack on nested input (D33). The fork fix is now pushed, so the pin moves to 8931ab8 and both targets go back in.

All five committed crash artifacts replay clean. A smoke run took forest_decode's corpus from 8 inputs to 514 over 10M runs with no crashes, and snapshot_decode's from 100 to 361. Eight inputs after four phases is the measure of how thoroughly the exclusion had blinded the campaign. Throughput differs by 20x between the two -- 48k exec/s against 2.5k -- which is what the next campaign should be budgeted from rather than the clock.

The fix walked into its own trap first. fuzz/ sits outside the workspace and so carries a second [patch.crates-io] block; bumping only the workspace pin left the fuzzer on dc368cc, and every artifact still reproduced -- against a bug already fixed. That reads as a falsified fix rather than a stale pin, and the only give-away was the rev in the panic path. tests/pins_agree.rs now fails if the two revs diverge, or if either is abbreviated. Confirmed to fire by reverting one.

Coverage floors: utreexo.rs lines 91.5 -> 91.1, the one figure the pin bump moved. Also found that nightly-2026-09-06 installs rustc f248f4038 2026-09-05, which is not the plain nightly of that date and does not report the same region counts -- so floors are now the minimum across all three configurations measured, less 0.3, and verified green against each.

USCMig and others added 3 commits September 8, 2026 05:16
forest_decode and snapshot_decode had been excluded from the campaign for four
phases because both reach MemForest::deserialize, which panicked on a bad
node-type byte and overflowed the stack on nested input (D33). The fork fix is
now pushed, so the pin moves to 8931ab8 and both targets go back in.

All five committed crash artifacts replay clean. A smoke run took
forest_decode's corpus from 8 inputs to 514 over 10M runs with no crashes, and
snapshot_decode's from 100 to 361. Eight inputs after four phases is the
measure of how thoroughly the exclusion had blinded the campaign. Throughput
differs by 20x between the two -- 48k exec/s against 2.5k -- which is what the
next campaign should be budgeted from rather than the clock.

The fix walked into its own trap first. fuzz/ sits outside the workspace and so
carries a second [patch.crates-io] block; bumping only the workspace pin left
the fuzzer on dc368cc, and every artifact still reproduced -- against a bug
already fixed. That reads as a falsified fix rather than a stale pin, and the
only give-away was the rev in the panic path. tests/pins_agree.rs now fails if
the two revs diverge, or if either is abbreviated. Confirmed to fire by
reverting one.

Coverage floors: utreexo.rs lines 91.5 -> 91.1, the one figure the pin bump
moved. Also found that nightly-2026-09-06 installs rustc f248f4038 2026-09-05,
which is not the plain `nightly` of that date and does not report the same
region counts -- so floors are now the minimum across all three configurations
measured, less 0.3, and verified green against each.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
…es it

fuzz-runs/*.log are tracked, and scripts/fuzz_72h.sh writes them in place. The
2026-08-25 run is what D36's budget conclusions are read off -- notably that
bundle_decode was still finding edges at 71.5 h -- so it moves to a dated
subdirectory rather than being overwritten by the run that supersedes it.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
@USCMig USCMig closed this pull request by merging all changes into main in b3cd23d Sep 19, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant