Skip to content

fix(fuzz): reject documented Atheris input errors - #1190

Open
gaborbernat wants to merge 3 commits into
tox-dev:mainfrom
gaborbernat:fix/fuzz-atheris-bridge-1014
Open

gaborbernat wants to merge 3 commits into
tox-dev:mainfrom
gaborbernat:fix/fuzz-atheris-bridge-1014

Conversation

@gaborbernat

Copy link
Copy Markdown
Member

Atheris ignores Python callback return values, so returning -1 cannot exclude inputs that raise documented API errors. Its pinned callback implementation returns zero after invoking Python. The native bridge forwards the documented rejection result to libFuzzer and resets that state before each input.

The bridge links the released Atheris 3.1.0 runtime archive into one preloaded shared library, following Atheris's external-runtime requirements. It forwards optional custom mutations and preserves unexpected exceptions. Qualified export validation rejects duplicate and missing callback ownership before fuzzing starts.

Refs #1014. This slice supplies the runtime and ownership-validation mechanism. The concrete 209-export callback inventory, protected input layout and incremental target contracts remain separate acceptance work.

Atheris discards Python callback return values. Preload one runtime ELF
that forwards documented errors as native rejections and resets that
state for the next input. Preserve unexpected exceptions and optional
custom mutations.

Validate qualified callback ownership before loading Atheris. Concrete
whole-API targets remain follow-up work for tox-dev#1014.
@gaborbernat gaborbernat added the bug Something isn't working label Oct 7, 2026
@gaborbernat
gaborbernat marked this pull request as ready for review October 7, 2026 00:09
@codspeed

codspeed Bot commented Oct 7, 2026

Copy link
Copy Markdown

Merging this PR will not alter performance

✅ 581 untouched benchmarks
⏩ 32 skipped benchmarks1


Comparing gaborbernat:fix/fuzz-atheris-bridge-1014 (bdcfe51) with main (6cbeeb7)

Open in CodSpeed

Footnotes

  1. 32 benchmarks were skipped, so the baseline results were used instead. If they were deleted from the codebase, click here and archive them to remove them from the performance reports. ↩

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bug Something isn't working

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant