Repository navigation
Fuzz #3959
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: Fuzz | |
| on: | |
| schedule: | |
| - cron: "0 */3 * * *" # every 3 hours | |
| workflow_dispatch: { } | |
| jobs: | |
| build_cpu_fuzzers: | |
| name: "Build CPU fuzzers" | |
| uses: ./.github/workflows/build-fuzzers.yml | |
| # ============================================================================ | |
| # IO Fuzzer | |
| # ============================================================================ | |
| io_fuzz: | |
| name: "IO Fuzz" | |
| needs: build_cpu_fuzzers | |
| uses: ./.github/workflows/run-fuzzer.yml | |
| with: | |
| fuzz_target: file_io | |
| jobs: 4 | |
| fuzzer_artifact: ${{ needs.build_cpu_fuzzers.outputs.artifact_name }} | |
| secrets: | |
| R2_FUZZ_ACCESS_KEY_ID: ${{ secrets.R2_FUZZ_ACCESS_KEY_ID }} | |
| R2_FUZZ_SECRET_ACCESS_KEY: ${{ secrets.R2_FUZZ_SECRET_ACCESS_KEY }} | |
| report-io-fuzz-failures: | |
| name: "Report IO Fuzz Failures" | |
| needs: io_fuzz | |
| if: always() && needs.io_fuzz.outputs.crashes_found == 'true' | |
| permissions: | |
| issues: write | |
| contents: read | |
| id-token: write | |
| pull-requests: read | |
| uses: ./.github/workflows/report-fuzz-crash.yml | |
| with: | |
| fuzz_target: file_io | |
| crash_file: ${{ needs.io_fuzz.outputs.first_crash_name }} | |
| artifact_url: ${{ needs.io_fuzz.outputs.artifact_url }} | |
| artifact_name: file_io-crash-artifacts | |
| logs_artifact_name: file_io-logs | |
| branch: ${{ github.ref_name }} | |
| commit: ${{ github.sha }} | |
| secrets: | |
| gh_token: ${{ secrets.GITHUB_TOKEN }} | |
| incident_io_alert_token: ${{ secrets.INCIDENT_IO_ALERT_TOKEN }} | |
| attempt-fix-io: | |
| name: "Attempt Fix for IO Fuzz Crash" | |
| needs: report-io-fuzz-failures | |
| if: needs.report-io-fuzz-failures.outputs.issue_number != '' | |
| permissions: | |
| # actions: read is needed for `gh run download` of the crash artifact. | |
| actions: read | |
| contents: write | |
| issues: write | |
| pull-requests: write | |
| id-token: write | |
| uses: ./.github/workflows/fuzzer-fix-automation.yml | |
| with: | |
| issue_number: ${{ needs.report-io-fuzz-failures.outputs.issue_number }} | |
| secrets: inherit | |
| # ============================================================================ | |
| # Array Operations Fuzzer | |
| # ============================================================================ | |
| ops_fuzz: | |
| name: "Array Operations Fuzz" | |
| needs: build_cpu_fuzzers | |
| uses: ./.github/workflows/run-fuzzer.yml | |
| with: | |
| fuzz_target: array_ops | |
| jobs: 4 | |
| fuzzer_artifact: ${{ needs.build_cpu_fuzzers.outputs.artifact_name }} | |
| secrets: | |
| R2_FUZZ_ACCESS_KEY_ID: ${{ secrets.R2_FUZZ_ACCESS_KEY_ID }} | |
| R2_FUZZ_SECRET_ACCESS_KEY: ${{ secrets.R2_FUZZ_SECRET_ACCESS_KEY }} | |
| report-ops-fuzz-failures: | |
| name: "Report Array Operations Fuzz Failures" | |
| needs: ops_fuzz | |
| if: always() && needs.ops_fuzz.outputs.crashes_found == 'true' | |
| permissions: | |
| issues: write | |
| contents: read | |
| id-token: write | |
| pull-requests: read | |
| uses: ./.github/workflows/report-fuzz-crash.yml | |
| with: | |
| fuzz_target: array_ops | |
| crash_file: ${{ needs.ops_fuzz.outputs.first_crash_name }} | |
| artifact_url: ${{ needs.ops_fuzz.outputs.artifact_url }} | |
| artifact_name: array_ops-crash-artifacts | |
| logs_artifact_name: array_ops-logs | |
| branch: ${{ github.ref_name }} | |
| commit: ${{ github.sha }} | |
| secrets: | |
| gh_token: ${{ secrets.GITHUB_TOKEN }} | |
| incident_io_alert_token: ${{ secrets.INCIDENT_IO_ALERT_TOKEN }} | |
| # ============================================================================ | |
| # FSST LIKE Fuzzer | |
| # ============================================================================ | |
| fsst_like_fuzz: | |
| name: "FSST LIKE Fuzz" | |
| needs: build_cpu_fuzzers | |
| uses: ./.github/workflows/run-fuzzer.yml | |
| with: | |
| fuzz_target: fsst_like | |
| jobs: 4 | |
| fuzzer_artifact: ${{ needs.build_cpu_fuzzers.outputs.artifact_name }} | |
| secrets: | |
| R2_FUZZ_ACCESS_KEY_ID: ${{ secrets.R2_FUZZ_ACCESS_KEY_ID }} | |
| R2_FUZZ_SECRET_ACCESS_KEY: ${{ secrets.R2_FUZZ_SECRET_ACCESS_KEY }} | |
| report-fsst-like-fuzz-failures: | |
| name: "Report FSST LIKE Fuzz Failures" | |
| needs: fsst_like_fuzz | |
| if: always() && needs.fsst_like_fuzz.outputs.crashes_found == 'true' | |
| permissions: | |
| issues: write | |
| contents: read | |
| id-token: write | |
| pull-requests: read | |
| uses: ./.github/workflows/report-fuzz-crash.yml | |
| with: | |
| fuzz_target: fsst_like | |
| crash_file: ${{ needs.fsst_like_fuzz.outputs.first_crash_name }} | |
| artifact_url: ${{ needs.fsst_like_fuzz.outputs.artifact_url }} | |
| artifact_name: fsst_like-crash-artifacts | |
| logs_artifact_name: fsst_like-logs | |
| branch: ${{ github.ref_name }} | |
| commit: ${{ github.sha }} | |
| secrets: | |
| gh_token: ${{ secrets.GITHUB_TOKEN }} | |
| incident_io_alert_token: ${{ secrets.INCIDENT_IO_ALERT_TOKEN }} | |
| # ============================================================================ | |
| # Row Encoding Fuzzer | |
| # ============================================================================ | |
| row_encode_fuzz: | |
| name: "Row Encoding Fuzz" | |
| needs: build_cpu_fuzzers | |
| uses: ./.github/workflows/run-fuzzer.yml | |
| with: | |
| fuzz_target: row_encode | |
| jobs: 4 | |
| fuzzer_artifact: ${{ needs.build_cpu_fuzzers.outputs.artifact_name }} | |
| secrets: | |
| R2_FUZZ_ACCESS_KEY_ID: ${{ secrets.R2_FUZZ_ACCESS_KEY_ID }} | |
| R2_FUZZ_SECRET_ACCESS_KEY: ${{ secrets.R2_FUZZ_SECRET_ACCESS_KEY }} | |
| report-row-encode-fuzz-failures: | |
| name: "Report Row Encoding Fuzz Failures" | |
| needs: row_encode_fuzz | |
| if: always() && needs.row_encode_fuzz.outputs.crashes_found == 'true' | |
| permissions: | |
| issues: write | |
| contents: read | |
| id-token: write | |
| pull-requests: read | |
| uses: ./.github/workflows/report-fuzz-crash.yml | |
| with: | |
| fuzz_target: row_encode | |
| crash_file: ${{ needs.row_encode_fuzz.outputs.first_crash_name }} | |
| artifact_url: ${{ needs.row_encode_fuzz.outputs.artifact_url }} | |
| artifact_name: row_encode-crash-artifacts | |
| logs_artifact_name: row_encode-logs | |
| branch: ${{ github.ref_name }} | |
| commit: ${{ github.sha }} | |
| secrets: | |
| gh_token: ${{ secrets.GITHUB_TOKEN }} | |
| incident_io_alert_token: ${{ secrets.INCIDENT_IO_ALERT_TOKEN }} | |
| # ============================================================================ | |
| # Compress Roundtrip Fuzzer | |
| # ============================================================================ | |
| compress_fuzz: | |
| name: "Compress Roundtrip Fuzz" | |
| needs: build_cpu_fuzzers | |
| uses: ./.github/workflows/run-fuzzer.yml | |
| with: | |
| fuzz_target: compress_roundtrip | |
| jobs: 4 | |
| fuzzer_artifact: ${{ needs.build_cpu_fuzzers.outputs.artifact_name }} | |
| secrets: | |
| R2_FUZZ_ACCESS_KEY_ID: ${{ secrets.R2_FUZZ_ACCESS_KEY_ID }} | |
| R2_FUZZ_SECRET_ACCESS_KEY: ${{ secrets.R2_FUZZ_SECRET_ACCESS_KEY }} | |
| report-compress-fuzz-failures: | |
| name: "Report Compress Roundtrip Fuzz Failures" | |
| needs: compress_fuzz | |
| if: always() && needs.compress_fuzz.outputs.crashes_found == 'true' | |
| permissions: | |
| issues: write | |
| contents: read | |
| id-token: write | |
| pull-requests: read | |
| uses: ./.github/workflows/report-fuzz-crash.yml | |
| with: | |
| fuzz_target: compress_roundtrip | |
| crash_file: ${{ needs.compress_fuzz.outputs.first_crash_name }} | |
| artifact_url: ${{ needs.compress_fuzz.outputs.artifact_url }} | |
| artifact_name: compress_roundtrip-crash-artifacts | |
| logs_artifact_name: compress_roundtrip-logs | |
| branch: ${{ github.ref_name }} | |
| commit: ${{ github.sha }} | |
| secrets: | |
| gh_token: ${{ secrets.GITHUB_TOKEN }} | |
| incident_io_alert_token: ${{ secrets.INCIDENT_IO_ALERT_TOKEN }} | |
| # ============================================================================ | |
| # GPU Compress Fuzzer (CUDA) | |
| # ============================================================================ | |
| gpu_compress_fuzz: | |
| name: "GPU Compress Fuzz" | |
| uses: ./.github/workflows/run-fuzzer.yml | |
| with: | |
| fuzz_target: compress_gpu | |
| runner: gpu | |
| extra_features: "cuda" | |
| # ASan mprotects the shadow gap PROT_NONE by default, which collides with the large | |
| # virtual-address range the CUDA driver reserves and makes device init fail with an | |
| # OOM-style error. protect_shadow_gap=0 frees that VA range for CUDA. | |
| extra_env: "ASAN_OPTIONS=protect_shadow_gap=0" | |
| jobs: 1 | |
| secrets: | |
| R2_FUZZ_ACCESS_KEY_ID: ${{ secrets.R2_FUZZ_ACCESS_KEY_ID }} | |
| R2_FUZZ_SECRET_ACCESS_KEY: ${{ secrets.R2_FUZZ_SECRET_ACCESS_KEY }} | |
| # report-gpu-compress-fuzz-failures: | |
| # name: "Report GPU Compress Fuzz Failures" | |
| # needs: gpu_compress_fuzz | |
| # if: always() && needs.gpu_compress_fuzz.outputs.crashes_found == 'true' | |
| # permissions: | |
| # issues: write | |
| # contents: read | |
| # id-token: write | |
| # pull-requests: read | |
| # uses: ./.github/workflows/report-fuzz-crash.yml | |
| # with: | |
| # fuzz_target: compress_gpu | |
| # crash_file: ${{ needs.gpu_compress_fuzz.outputs.first_crash_name }} | |
| # artifact_url: ${{ needs.gpu_compress_fuzz.outputs.artifact_url }} | |
| # artifact_name: compress_gpu-crash-artifacts | |
| # logs_artifact_name: compress_gpu-logs | |
| # branch: ${{ github.ref_name }} | |
| # commit: ${{ github.sha }} | |
| # secrets: | |
| # gh_token: ${{ secrets.GITHUB_TOKEN }} |