Repository navigation
🐛 fix(xsd): reject unresolvable and cyclic schemas #1914
Workflow file for this run
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: 🔒 fuzz | |
| on: | |
| workflow_dispatch: | |
| push: | |
| branches: ["main"] | |
| tags-ignore: ["**"] | |
| pull_request: | |
| schedule: | |
| - cron: "0 6 * * *" # daily deep run, 06:00 UTC | |
| - cron: "0 4 * * 1" # weekly extended run, Monday 04:00 UTC | |
| concurrency: | |
| group: fuzz-${{ github.ref }} | |
| cancel-in-progress: true | |
| permissions: | |
| contents: read | |
| jobs: | |
| smoke: | |
| name: 💨 ASan/UBSan smoke (benign corpus) | |
| runs-on: ubuntu-24.04 | |
| # the per-PR gate: build every harness under -fsanitize=address,undefined and replay the benign seed corpus. It is | |
| # fast and deterministic, so a red run means a real regression, not a flaky fuzz find. The deep hunt is the job below. | |
| steps: | |
| - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 | |
| with: | |
| fetch-depth: 0 # meson project() derives the version from git history | |
| persist-credentials: false | |
| - name: 🔄 Install uv | |
| uses: astral-sh/setup-uv@c18668ad3cf93ea998bef934396af7bb5c839dc7 # v10.2.0 | |
| with: | |
| enable-cache: false | |
| - name: ✅ Run fuzz-smoke | |
| run: uvx --with tox-uv tox run -e fuzz-smoke | |
| env: | |
| UV_PYTHON_PREFERENCE: only-managed | |
| deep: | |
| name: 🕳️ ASan/UBSan deep (mutation + structural) | |
| runs-on: ubuntu-24.04 | |
| if: github.event_name == 'schedule' || github.event_name == 'workflow_dispatch' | |
| # the continuous hunt: mutation and escalating-depth probes for a wall-clock budget per target. It is not a PR gate | |
| # and is allowed to surface a fault (which fails the job by design), so a maintainer triages new finds from the log. | |
| steps: | |
| - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 | |
| with: | |
| fetch-depth: 0 | |
| persist-credentials: false | |
| - name: 🔄 Install uv | |
| uses: astral-sh/setup-uv@c18668ad3cf93ea998bef934396af7bb5c839dc7 # v10.2.0 | |
| with: | |
| enable-cache: false | |
| - name: ✅ Run fuzz (deep) | |
| # the Monday 04:00 slot runs each target longer; the daily 06:00 slot and manual dispatch use the shorter budget | |
| run: uvx --with tox-uv tox run -e fuzz -- --minutes "${MINUTES}" | |
| env: | |
| UV_PYTHON_PREFERENCE: only-managed | |
| MINUTES: ${{ github.event.schedule == '0 4 * * 1' && '20' || '8' }} | |
| - name: 📤 Upload crash corpus | |
| if: failure() | |
| uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 | |
| with: | |
| name: fuzz-crashes | |
| path: | | |
| **/crash-* | |
| **/*.crash | |
| if-no-files-found: ignore | |
| retention-days: 14 |