Skip to content

Phase 6e fuzz budget - #13

Merged
USCMig merged 6 commits into
mainfrom
phase-6e-fuzz-budget
Sep 19, 2026
Merged

USCMig merged 6 commits into
mainfrom
phase-6e-fuzz-budget

Conversation

@USCMig

@USCMig USCMig commented Sep 19, 2026

Copy link
Copy Markdown
Collaborator

fuzz budget

USCMig and others added 6 commits September 8, 2026 05:16
forest_decode and snapshot_decode had been excluded from the campaign for four
phases because both reach MemForest::deserialize, which panicked on a bad
node-type byte and overflowed the stack on nested input (D33). The fork fix is
now pushed, so the pin moves to 8931ab8 and both targets go back in.

All five committed crash artifacts replay clean. A smoke run took
forest_decode's corpus from 8 inputs to 514 over 10M runs with no crashes, and
snapshot_decode's from 100 to 361. Eight inputs after four phases is the
measure of how thoroughly the exclusion had blinded the campaign. Throughput
differs by 20x between the two -- 48k exec/s against 2.5k -- which is what the
next campaign should be budgeted from rather than the clock.

The fix walked into its own trap first. fuzz/ sits outside the workspace and so
carries a second [patch.crates-io] block; bumping only the workspace pin left
the fuzzer on dc368cc, and every artifact still reproduced -- against a bug
already fixed. That reads as a falsified fix rather than a stale pin, and the
only give-away was the rev in the panic path. tests/pins_agree.rs now fails if
the two revs diverge, or if either is abbreviated. Confirmed to fire by
reverting one.

Coverage floors: utreexo.rs lines 91.5 -> 91.1, the one figure the pin bump
moved. Also found that nightly-2026-09-06 installs rustc f248f4038 2026-09-05,
which is not the plain `nightly` of that date and does not report the same
region counts -- so floors are now the minimum across all three configurations
measured, less 0.3, and verified green against each.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
…es it

fuzz-runs/*.log are tracked, and scripts/fuzz_72h.sh writes them in place. The
2026-08-25 run is what D36's budget conclusions are read off -- notably that
bundle_decode was still finding edges at 71.5 h -- so it moves to a dated
subdirectory rather than being overwritten by the run that supersedes it.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
The logs were committed on 14 Sep while `bundle_decode` still had three days
to run, so `bundle_decode.log` stopped mid-stream and `driver.log` held only
the launch lines. These are the finished versions: the last stat line, the
per-target totals, and the driver's saturation analysis that D45 cites.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
…inished

The seven-target run (2026-09-10 to 09-17) found no crashes in 103 billion
executions. Its own saturation analysis says the budget went to the wrong
target. `bundle_decode` had 7 days on 8 forks and reached its ceiling in 2.1
hours. `snapshot_decode` had 24 hours on 1 worker and found its last new edge
at 18.1 h.

The next step was going to be a structured seed generator for the three
targets that gained no edges. Measured first instead: `cargo fuzz coverage`
shows every reachable region of all three decoders already executes. The
uncovered regions are error arms that an earlier bounds check makes
unreachable, plus the empty-input path, which libFuzzer runs at startup but the
coverage report never replays. A generator would reach nothing new, so it isn't
built. D36's "zero edges means re-seed" is corrected in fuzz/README.md.

scripts/fuzz_72h.sh:
- `snapshot_decode` gets the long slot and 8 forks. The rest get 72 h, the
  floor the Phase 6 DoD sets, rather than 24 h.
- Crash artifacts are counted against a run-start stamp. The last run reported
  the five August D33 files as `artifacts=2` and `artifacts=3`, which read as
  new crashes.

PLAN.md no longer claims the DoD's fuzzing half covers 7 of 7. Three targets
have never had 72 h on their current decoder.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
The analysis printed "These need seeds or a structured generator" for any
target that gained no edges. D45 found that false for all three such targets:
their decoders were fully covered. The message now says both explanations are
possible and names the command that distinguishes them.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
@USCMig
USCMig merged commit b3cd23d into main Sep 19, 2026
4 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant