This repository was archived by the owner on Aug 7, 2026. It is now read-only.
-
Notifications
You must be signed in to change notification settings - Fork 0
115 lines (100 loc) · 3.99 KB
/
Copy pathfuzz.yml
File metadata and controls
115 lines (100 loc) · 3.99 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
name: Fuzz
# Fuzzing the untrusted-input seam (QF-2026-06-24-06). Three modes:
# - pull_request (paths-scoped): a short, time-boxed smoke of the hottest target
# so a regression that crashes a known input surfaces on the PR, not overnight.
# - schedule (nightly) + workflow_dispatch: the full matrix, longer runs.
# Every run reads the committed seed corpus (seeds/<target>) and writes any new
# units to the scratch corpus/<target> (gitignored). A discovered crash fails the
# job and uploads the reproducer as an artifact.
on:
schedule:
- cron: "0 4 * * *" # 04:00 UTC nightly
workflow_dispatch:
inputs:
max_total_time:
description: Seconds to fuzz each target
default: "120"
pull_request:
# Only when the fuzzed code (or the harness itself) changes — keeps the
# nightly-toolchain + cargo-fuzz build off unrelated PRs.
paths:
- "crates/mobile-core/**"
- "apps/marquee/quorum-sense/ffi/**"
- ".github/workflows/fuzz.yml"
permissions:
contents: read
env:
CARGO_TERM_COLOR: always
jobs:
smoke:
# PR-time guard: the hottest target only, time-boxed, replaying the seed
# corpus so a known-good input that now panics fails the PR immediately.
name: cargo-fuzz smoke (draft_field_signal)
if: github.event_name == 'pull_request'
runs-on: ubuntu-latest
timeout-minutes: 15
defaults:
run:
working-directory: reflective/mobile-apps
steps:
- uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
with:
sparse-checkout: |
.github/actions/checkout-helms-deps
sparse-checkout-cone-mode: false
- uses: ./.github/actions/checkout-helms-deps
- name: Install nightly toolchain
run: rustup toolchain install nightly --profile minimal
- name: Install cargo-fuzz
run: cargo install cargo-fuzz --locked
- name: Smoke draft_field_signal (bounded, seed corpus)
working-directory: reflective/mobile-apps/crates/mobile-core/fuzz
run: |
mkdir -p corpus/draft_field_signal
cargo +nightly fuzz run draft_field_signal \
corpus/draft_field_signal seeds/draft_field_signal \
-- -max_total_time=30
- name: Upload crash reproducer
if: failure()
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
with:
name: fuzz-smoke-artifacts
path: reflective/mobile-apps/crates/mobile-core/fuzz/artifacts/
if-no-files-found: ignore
fuzz:
name: cargo-fuzz (mobile-core)
if: github.event_name != 'pull_request'
runs-on: ubuntu-latest
timeout-minutes: 20
strategy:
fail-fast: false
matrix:
target: [draft_field_signal, parse_enums, confidence_roundtrip]
defaults:
run:
working-directory: reflective/mobile-apps
steps:
- uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
with:
sparse-checkout: |
.github/actions/checkout-helms-deps
sparse-checkout-cone-mode: false
- uses: ./.github/actions/checkout-helms-deps
- name: Install nightly toolchain
run: rustup toolchain install nightly --profile minimal
- name: Install cargo-fuzz
run: cargo install cargo-fuzz --locked
- name: Fuzz ${{ matrix.target }}
working-directory: reflective/mobile-apps/crates/mobile-core/fuzz
run: |
mkdir -p corpus/${{ matrix.target }}
cargo +nightly fuzz run ${{ matrix.target }} \
corpus/${{ matrix.target }} seeds/${{ matrix.target }} \
-- -max_total_time=${{ github.event.inputs.max_total_time || '120' }}
- name: Upload crash reproducer
if: failure()
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
with:
name: fuzz-artifacts-${{ matrix.target }}
path: reflective/mobile-apps/crates/mobile-core/fuzz/artifacts/
if-no-files-found: ignore