-
Notifications
You must be signed in to change notification settings - Fork 0
93 lines (89 loc) · 2.92 KB
/
Copy pathfuzz.yml
File metadata and controls
93 lines (89 loc) · 2.92 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
name: Fuzz
on:
push:
branches: [main]
paths:
- 'core/**'
- 'fuzz/**'
- 'extern/geozl'
- 'extern/karu'
- 'Makefile'
- '.github/workflows/fuzz.yml'
pull_request:
paths:
- 'core/**'
- 'fuzz/**'
- 'extern/geozl'
- 'extern/karu'
- 'Makefile'
- '.github/workflows/fuzz.yml'
schedule:
- cron: '41 3 * * *'
workflow_dispatch: {}
permissions:
contents: read
concurrency:
group: fuzz-${{ github.workflow }}-${{ github.ref }}
cancel-in-progress: true
jobs:
fuzz:
runs-on: ubuntu-24.04
timeout-minutes: 60
env:
CLANG: /usr/bin/clang-19
CLANGXX: /usr/bin/clang++-19
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
submodules: true
persist-credentials: false
- name: Install fuzz toolchain and transport dependencies
run: |
sudo rm -f /etc/apt/sources.list.d/google-chrome.list \
/etc/apt/sources.list.d/google-chrome.sources
sudo apt-get update
sudo apt-get install -y --no-install-recommends \
clang-19 libclang-rt-19-dev libcurl4-openssl-dev libssl-dev
- name: Init OpenZL dependencies
run: |
git -C extern/geozl submodule update --init extern/openzl
git -C extern/geozl/extern/openzl submodule update --init deps/zstd deps/lz4
- name: Restore corpora
uses: actions/cache/restore@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6
with:
path: fuzz/corpus
key: rumi-fuzz-corpus-${{ github.run_id }}
restore-keys: rumi-fuzz-corpus-
- name: Check C++23 toolchain
run: |
"$CLANG" --version
"$CLANGXX" --version
printf '#include <expected>\nint main() { std::expected<int, int> value(1); return *value; }\n' |
"$CLANGXX" -std=c++23 -x c++ -fsyntax-only -
- name: Replay saved inputs
if: github.event_name == 'push' || github.event_name == 'pull_request'
run: make fuzz-replay
- name: Run fuzzers
if: github.event_name == 'schedule' || github.event_name == 'workflow_dispatch'
env:
FUZZ_TIME: '420'
run: make fuzz-check
- name: Save corpora
if: success() && (github.event_name == 'schedule' || github.event_name == 'workflow_dispatch')
uses: actions/cache/save@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6
with:
path: fuzz/corpus
key: rumi-fuzz-corpus-${{ github.run_id }}
- name: Upload findings
if: failure()
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
with:
name: fuzz-findings
path: |
fuzz/out/report.txt
fuzz/out/*.log
fuzz/out/crash-*
fuzz/out/oom-*
fuzz/out/leak-*
fuzz/out/timeout-*
if-no-files-found: warn