CI / test (push) Failing after 4s
- Add ensure_len(data, offset, needed) helper to chunked_read.rs, data_read.rs, and local_heap.rs (matching the existing btree_v1.rs/ object_header.rs convention) and use it at every plain-arithmetic offset+size bounds check found in these files, closing usize-overflow panics reachable from crafted near-usize::MAX offsets/addresses. - collect_chunk_info: add a depth-limited internal wrapper (collect_chunk_info_inner, MAX_CHUNK_BTREE_DEPTH=64) to reject a crafted self-referencing/cyclic B-tree v1 chunk index instead of recursing unboundedly (stack-overflow DoS). - read_compound_fields: validate byte_offset+field_size against the compound's declared element size before slicing, instead of an unguarded out-of-bounds panic on a crafted member offset. - read_chunked_data/_cached/_sweep/_indexed: guard `ndims - 1` against underflow for a degenerate zero-dimension chunked layout. - copy_chunk_to_output: rewrite all offset/stride arithmetic (both the 1-D fast path and the general N-D path) to use checked_add/checked_mul, skipping an out-of-range row/chunk instead of panicking on overflow. Add a new cargo-fuzz target, fuzz_dataset_read, that walks every dataset in a parsed file via the clawhdf5 facade and exercises the contiguous/ chunked/compact raw-data read paths that the existing fuzz_full_file target doesn't reach. Seeded with the chunked/VDS/compound-relevant test fixtures plus two crash regressions found during this pass (the copy_chunk_to_output overflow and the ndims-1 underflow, both fixed above — this target found real bugs within the first couple of runs). Not wired into CI (nightly-only, multi-minute runs); documented in fuzz/README.md as a manual/scheduled check instead. Also fixed the README's stale rustyhdf5-format naming while touching this file. Added regression tests for every fix (near-usize::MAX offsets, the self-referencing B-tree case, the compound byte_offset overrun, the zero-dim layout, and both copy_chunk_to_output overflow paths) so these are caught by `cargo test`, not just the fuzz corpus.
67 lines
1.1 KiB
TOML
67 lines
1.1 KiB
TOML
[package]
|
|
name = "clawhdf5-format-fuzz"
|
|
version = "0.0.0"
|
|
publish = false
|
|
edition = "2024"
|
|
|
|
[package.metadata]
|
|
cargo-fuzz = true
|
|
|
|
[dependencies]
|
|
libfuzzer-sys = "0.4"
|
|
|
|
[dependencies.clawhdf5-format]
|
|
path = ".."
|
|
features = ["std", "checksum", "deflate"]
|
|
|
|
[dependencies.clawhdf5]
|
|
path = "../../clawhdf5"
|
|
|
|
[workspace]
|
|
members = ["."]
|
|
|
|
[[bin]]
|
|
name = "fuzz_superblock"
|
|
path = "fuzz_targets/fuzz_superblock.rs"
|
|
doc = false
|
|
|
|
[[bin]]
|
|
name = "fuzz_object_header"
|
|
path = "fuzz_targets/fuzz_object_header.rs"
|
|
doc = false
|
|
|
|
[[bin]]
|
|
name = "fuzz_datatype"
|
|
path = "fuzz_targets/fuzz_datatype.rs"
|
|
doc = false
|
|
|
|
[[bin]]
|
|
name = "fuzz_dataspace"
|
|
path = "fuzz_targets/fuzz_dataspace.rs"
|
|
doc = false
|
|
|
|
[[bin]]
|
|
name = "fuzz_fractal_heap"
|
|
path = "fuzz_targets/fuzz_fractal_heap.rs"
|
|
doc = false
|
|
|
|
[[bin]]
|
|
name = "fuzz_btree_v2"
|
|
path = "fuzz_targets/fuzz_btree_v2.rs"
|
|
doc = false
|
|
|
|
[[bin]]
|
|
name = "fuzz_filter_pipeline"
|
|
path = "fuzz_targets/fuzz_filter_pipeline.rs"
|
|
doc = false
|
|
|
|
[[bin]]
|
|
name = "fuzz_full_file"
|
|
path = "fuzz_targets/fuzz_full_file.rs"
|
|
doc = false
|
|
|
|
[[bin]]
|
|
name = "fuzz_dataset_read"
|
|
path = "fuzz_targets/fuzz_dataset_read.rs"
|
|
doc = false
|