Skip to content

fuzz: add cargo-fuzz targets for the bead sync decoders - #551

Open
Atishyy27 wants to merge 1 commit into
braidpool:devfrom
Atishyy27:fuzz/bead-decode-targets
Open

Atishyy27 wants to merge 1 commit into
braidpool:devfrom
Atishyy27:fuzz/bead-decode-targets

Conversation

@Atishyy27

@Atishyy27 Atishyy27 commented Sep 16, 2026 •

Copy link
Copy Markdown

Adds a cargo-fuzz workspace under node/fuzz with one target each for Bead, BeadRequest and BeadResponse, decoding raw bytes the way a peer would send them. bead_response_decode found #550 on its first run. Fixes stay in their own PRs (#548, #552); this only adds the harness and a short README.

Relates to #133. cargo-fuzz needs nightly, so node/fuzz is its own workspace and stays out of the default build. cargo fuzz run bead_response_decode hits #550 within a minute on dev.

Adds a cargo-fuzz workspace under node/fuzz with three targets, one per
network-facing decoder: Bead, BeadRequest and BeadResponse. Each mirrors
the call shape in BeadCodec, which reads a peer's bytes into a buffer and
hands them to consensus_decode unmodified, so any panic a target finds is
reachable by a remote peer. A README covers running them and adding more.

Targets are kept thin, decode-only, so they can be retargeted as the core
structures change. On its first run bead_response_decode surfaced an
uncapped length-prefix preallocation in the vec decoders; that and the
timestamp unwrap fixed in braidpool#548 are exactly the class this is meant to
catch. Addresses braidpool#133.
@Sansh2356

Copy link
Copy Markdown
Contributor

This is already on checklist but we should ideally wait for fuzzing to be introduced .

@zaidmstrr

Copy link
Copy Markdown
Contributor

As told by Sansh2356, we haven't introduced the fuzz testing right now, but we will introduce this in the future for sure. Our current aim is to strengthen the other testing methodologies. I appreciate you created this PR but you can keep these changes in your local system until we have introduced the fuzz testing framework.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants