Skip to content

[OC-032] Add continuous fuzz and property suites #33

Description

@tcballard

Gate: G2 — Public BLE mesh and gossip

Planning source: validated implementation plan PR #1


  • Depends on: OC-027OC-031.
  • Deliverable: cargo-fuzz targets for packet, announce, fragment, request-sync, Noise-inner, and Nostr-envelope parsers; property tests for canonical round trips.
  • Acceptance: CI smoke fuzzing runs on every PR; scheduled jobs retain crash artifacts; a seeded malformed corpus covers every optional branch and size limit.
  • Excludes: claiming a time-limited fuzz run proves absence of vulnerabilities.

Maintainer reconciliation — 2026-09-04

Scheduling: retained/deferred G2–G4 compatibility work, not a current Nostr/account release blocker. Original acceptance criteria remain intact; deferred does not mean completed.

Next closure evidence/work: Add PR smoke fuzzing and retained crash artifacts: current workflow is nightly/manual only. Complete parser/seeded optional-branch/size-limit corpus and property coverage. This security infrastructure can proceed despite mesh deferral.

Baseline reviewed: main 87c3bcb7d65e3e2ab8ae317694b751f8efe9a8ed. Implementation presence is not a live conformance claim.

Current release scope — 2026-09-05

The active scope is Nostr/IPC parser fuzzing, bounds, malformed-input corpora and retained crash artifacts. Bluetooth packet, announce, fragment, request-sync and Noise-inner targets are deferred with #28–32. This cross-cutting security issue remains open; the older G2 scheduling label does not make current Nostr hardening optional.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions