Skip to content

feat(fuzz): add qualified public consumers - #1197

Merged
gaborbernat merged 2 commits into
tox-dev:mainfrom
gaborbernat:fix/atheris-public-owners-1014
Oct 7, 2026
Merged

gaborbernat merged 2 commits into
tox-dev:mainfrom
gaborbernat:fix/atheris-public-owners-1014

Conversation

@gaborbernat

Copy link
Copy Markdown
Member

The Atheris registry can name a public export without calling it. This adds concrete consumers for the current 209 qualified exports across 20 modules, with separate parser, reference, content and ordinary DOM targets. Missing or duplicate ownership stops the driver before it starts. Refs #1014.

The callbacks compare public results against literal controls or independent entry points. Incremental consumers feed empty chunks and split multibyte input; serialization consumers compare supported output paths. Content callbacks reuse the existing bounded minifier, encoding, IDNA and URL invariants. Target-specific documented input errors reach the native rejection runtime; other exceptions remain findings.

The driver uses Atheris's loaded-function instrumentation and native extension coverage hooks. Each target has a byte corpus directory and a separate qualified-owner manifest. Protected failure headers, exact-size wide-buffer boundaries, complete one-shot/incremental corpus integration and the remaining invariant requirements stay outside this executable ownership slice.

Qualified names need executable consumers before the driver can detect
unowned APIs. Register checked parser, reference, content and DOM paths
with target-specific corpus directories and documented input errors.

Keep native rejection and coverage hooks in the released Atheris path.
Remaining protected-header and buffer requirements stay tracked in tox-dev#1014.
@gaborbernat gaborbernat added the enhancement New feature or request label Oct 7, 2026
@gaborbernat
gaborbernat marked this pull request as ready for review October 7, 2026 03:54
@codspeed

codspeed Bot commented Oct 7, 2026

Copy link
Copy Markdown

Merging this PR will regress 2 benchmarks

⚠️ Different runtime environments detected

Some benchmarks with significant performance changes were compared across different runtime environments,
which may affect the accuracy of the results.

Open the report in CodSpeed to investigate

⚡ 1 improved benchmark
❌ 2 regressed benchmarks
✅ 578 untouched benchmarks
⏩ 32 skipped benchmarks1

Warning

Please fix the performance issues or acknowledge them on CodSpeed.

Performance Changes

Benchmark BASE HEAD Efficiency
❌ test_feature[serialize-inner] 5.1 ms 5.4 ms -5.64%
❌ test_feature[serialize-inner-indent] 5.5 ms 5.9 ms -5.33%
⚡ test_feature[shadow-slot-comments] 137.9 µs 83.9 µs +64.3%

Tip

Investigate this regression by commenting @codspeedbot fix this regression on this PR, or directly use the CodSpeed MCP with your agent.


Comparing gaborbernat:fix/atheris-public-owners-1014 (a48d596) with main (59b515e)

Open in CodSpeed

Footnotes

  1. 32 benchmarks were skipped, so the baseline results were used instead. If they were deleted from the codebase, click here and archive them to remove them from the performance reports. ↩

@gaborbernat
gaborbernat merged commit 990dae3 into tox-dev:main Oct 7, 2026
55 of 56 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

enhancement New feature or request

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant