Skip to content

Add CI fuzz workflow - #13628

Open
Dreamsorcerer wants to merge 1 commit into
masterfrom
Dreamsorcerer-patch-2
Open

Dreamsorcerer wants to merge 1 commit into
masterfrom
Dreamsorcerer-patch-2

Conversation

@Dreamsorcerer

Copy link
Copy Markdown
Member

Follow up to #12887.

@Dreamsorcerer Dreamsorcerer added bot:chronographer:skip This PR does not need to include a change note backport-3.15 Trigger automatic backporting to the 3.15 release branch by Patchback robot labels Sep 2, 2026
@codecov

codecov Bot commented Sep 2, 2026 •

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 99.02%. Comparing base (bffb2f1) to head (2d66dab).
✅ All tests successful. No failed tests found.

Additional details and impacted files
@@           Coverage Diff           @@
##           master   #13628   +/-   ##
=======================================
  Coverage   99.02%   99.02%           
=======================================
  Files         135      135           
  Lines       50769    50769           
  Branches     2669     2669           
=======================================
  Hits        50276    50276           
  Misses        370      370           
  Partials      123      123           
Flag Coverage Δ
Autobahn 21.97% <ø> (ø)
CI-GHA 98.92% <ø> (ø)
OS-Linux 98.69% <ø> (ø)
OS-Windows 97.30% <ø> (ø)
OS-macOS 98.18% <ø> (-0.01%) ⬇️
Py-3.10 98.12% <ø> (ø)
Py-3.11 98.35% <ø> (ø)
Py-3.12 98.43% <ø> (ø)
Py-3.13 98.42% <ø> (-0.01%) ⬇️
Py-3.14 98.45% <ø> (-0.01%) ⬇️
Py-3.14t 97.83% <ø> (+<0.01%) ⬆️
Py-pypy-3.11 97.39% <ø> (-0.01%) ⬇️
VM-macos 98.18% <ø> (-0.01%) ⬇️
VM-ubuntu 98.69% <ø> (ø)
VM-windows 97.30% <ø> (ø)
cython-coverage 83.17% <ø> (ø)

Flags with carried forward coverage won't be shown. Click here to find out more.

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

@greptile-apps

greptile-apps Bot commented Sep 2, 2026

Copy link
Copy Markdown

Confidence Score: 2/5

Not safe to merge until backport coverage is restored and mutable external actions no longer receive issue-writing access.

The workflow directly contains both the nonmatching numeric-backport glob and mutable external action references in the issue-writing job. Focused checks exercised those conditions, but the environment could not publish the captured evidence artifacts.

Files Needing Attention: .github/workflows/cifuzz.yml needs updates to both event branch filters and the job/action permission boundary.

Security Review

The CIFuzz job grants issues: write while invoking external OSS-Fuzz actions from mutable master references. Pinning those actions to immutable commit SHAs and performing issue creation in a separately scoped job prevents a future upstream action revision from inheriting repository issue-writing authority.

T-Rex T-Rex Logs

What T-Rex did

  • We exercised the CIFuzz branch-filter validation path and inspected the workflow's mutable action references and job permissions before attempting to upload evidence.
  • The environment lacked the Greptile artifact-upload tool, so the evidence could not be uploaded and validator source and output could not be attached.
  • Existing local evidence files cifuzz-branch-glob-validation.js, cifuzz-branch-glob-01-before.log, and cifuzz-branch-glob-02-after.log remain available for review.
  • The blocker is the absence of a Greptile artifact-upload mechanism, which prevents producing verbatim artifact references.

T-Rex Ran code and verified through T-Rex

Reviews (1): Last reviewed commit: "Add CI fuzz workflow" | Re-trigger Greptile

Comment on lines +7 to +11
- '[0-9].[0-9]+' # matches to backport branches, e.g. 3.6
pull_request:
branches:
- 'master'
- '[0-9].[0-9]+'

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Backport branch glob does not match

The [0-9].[0-9]+ filters on both the push and pull-request triggers do not match a normal backport branch such as 3.6: + is literal in this glob syntax. CIFuzz is therefore not scheduled for those maintained backport branches. Use a matching glob such as [0-9].[0-9]* in both trigger lists.

Comment on lines +19 to +35
permissions:
contents: read # For build_fuzzers to check out the code
issues: write # To create a new issue in the last step
strategy:
fail-fast: false
matrix:
sanitizer: [address, undefined]
steps:
- name: Build Fuzzers
id: build
uses: google/oss-fuzz/infra/cifuzz/actions/build_fuzzers@master
with:
oss-fuzz-project-name: 'aiohttp'
language: python
sanitizer: ${{ matrix.sanitizer }}
- name: Run Fuzzers
uses: google/oss-fuzz/infra/cifuzz/actions/run_fuzzers@master

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 security Mutable actions inherit issue-write access

The Fuzzing job grants issues: write before running the OSS-Fuzz build and run actions from mutable @master references. An upstream change to either action would execute with this repository's issue-writing token. Pin the actions to immutable full commit SHAs and move issue creation to a separately scoped write-capable job.

@codspeed

codspeed Bot commented Sep 2, 2026

Copy link
Copy Markdown

Merging this PR will degrade performance by 10.19%

⚠️ Different runtime environments detected

Some benchmarks with significant performance changes were compared across different runtime environments,
which may affect the accuracy of the results.

Open the report in CodSpeed to investigate

❌ 1 regressed benchmark
✅ 96 untouched benchmarks
⏩ 83 skipped benchmarks1

Warning

Please fix the performance issues or acknowledge them on CodSpeed.

Performance Changes

Benchmark BASE HEAD Efficiency
❌ test_link_param_pattern_redos_payload[embedded_newlines] 35.2 µs 39.1 µs -10.19%

Tip

Investigate this regression by commenting @codspeedbot fix this regression on this PR, or directly use the CodSpeed MCP with your agent.


Comparing Dreamsorcerer-patch-2 (2d66dab) with master (bffb2f1)

Open in CodSpeed

Footnotes

  1. 83 benchmarks were skipped, so the baseline results were used instead. If they were deleted from the codebase, click here and archive them to remove them from the performance reports. ↩

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

backport-3.15 Trigger automatic backporting to the 3.15 release branch by Patchback robot bot:chronographer:skip This PR does not need to include a change note

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant