The Jazzer suite (src/test/net/jpountz/fuzz/) covers the block compressors, block decompressors and XXHash, but not the stream classes, which is where recent bugs have been found.
Following .clinerules/coding.md:
- one
@FuzzTest per stream class, decompressor and flag combination, each with its own <execution> in the fuzz profile;
- a fixed op prefix, then
consumeRemainingAsBytes();
- raw input with no round-trip.
Rules for the targets:
- Mix
read(), read(byte[]), skip() and available(), and keep going past EOF.
- Treat anything other than
IOException as a failure, including negative available()/skip() results.
- Enforce an allocation budget (e.g.
ThreadMXBean.getThreadAllocatedBytes ≤ 32 MiB + 4096 × input length) to catch allocation amplification.
@FuzzTest public void frame_multi(FuzzedDataProvider d) { drive(d, false, false); }
// frame_single, block_stop, block_nostop ...
This will immediately flag the NPE on skippable-only streams, the RuntimeException on bad descriptors, and the per-frame buffer reallocation in LZ4FrameInputStream, so land those fixes first or together. Deep recursion on empty blocks needs more input than libFuzzer's default max_len, so cover it with a deterministic regression test instead.
The Jazzer suite (
src/test/net/jpountz/fuzz/) covers the block compressors, block decompressors and XXHash, but not the stream classes, which is where recent bugs have been found.Following
.clinerules/coding.md:@FuzzTestper stream class, decompressor and flag combination, each with its own<execution>in thefuzzprofile;consumeRemainingAsBytes();Rules for the targets:
read(),read(byte[]),skip()andavailable(), and keep going past EOF.IOExceptionas a failure, including negativeavailable()/skip()results.ThreadMXBean.getThreadAllocatedBytes≤ 32 MiB + 4096 × input length) to catch allocation amplification.This will immediately flag the NPE on skippable-only streams, the
RuntimeExceptionon bad descriptors, and the per-frame buffer reallocation inLZ4FrameInputStream, so land those fixes first or together. Deep recursion on empty blocks needs more input than libFuzzer's defaultmax_len, so cover it with a deterministic regression test instead.