Repository navigation
feat(fuzz): add qualified public consumers - #1197
Merged
gaborbernat merged 2 commits intoOct 7, 2026
Merged
Conversation
Qualified names need executable consumers before the driver can detect unowned APIs. Register checked parser, reference, content and DOM paths with target-specific corpus directories and documented input errors. Keep native rejection and coverage hooks in the released Atheris path. Remaining protected-header and buffer requirements stay tracked in tox-dev#1014.
gaborbernat
marked this pull request as ready for review
October 7, 2026 03:54
Merging this PR will regress 2 benchmarks
|
| Benchmark | BASE |
HEAD |
Efficiency | |
|---|---|---|---|---|
| ❌ | test_feature[serialize-inner] |
5.1 ms | 5.4 ms | -5.64% |
| ❌ | test_feature[serialize-inner-indent] |
5.5 ms | 5.9 ms | -5.33% |
| ⚡ | test_feature[shadow-slot-comments] |
137.9 µs | 83.9 µs | +64.3% |
Tip
Investigate this regression by commenting @codspeedbot fix this regression on this PR, or directly use the CodSpeed MCP with your agent.
Comparing gaborbernat:fix/atheris-public-owners-1014 (a48d596) with main (59b515e)
Footnotes
-
32 benchmarks were skipped, so the baseline results were used instead. If they were deleted from the codebase, click here and archive them to remove them from the performance reports. ↩
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
The Atheris registry can name a public export without calling it. This adds concrete consumers for the current 209 qualified exports across 20 modules, with separate parser, reference, content and ordinary DOM targets. Missing or duplicate ownership stops the driver before it starts. Refs #1014.
The callbacks compare public results against literal controls or independent entry points. Incremental consumers feed empty chunks and split multibyte input; serialization consumers compare supported output paths. Content callbacks reuse the existing bounded minifier, encoding, IDNA and URL invariants. Target-specific documented input errors reach the native rejection runtime; other exceptions remain findings.
The driver uses Atheris's loaded-function instrumentation and native extension coverage hooks. Each target has a byte corpus directory and a separate qualified-owner manifest. Protected failure headers, exact-size wide-buffer boundaries, complete one-shot/incremental corpus integration and the remaining invariant requirements stay outside this executable ownership slice.