Add CI fuzz workflow - #13628
Add CI fuzz workflow#13628Dreamsorcerer wants to merge 1 commit into
Conversation
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## master #13628 +/- ##
=======================================
Coverage 99.02% 99.02%
=======================================
Files 135 135
Lines 50769 50769
Branches 2669 2669
=======================================
Hits 50276 50276
Misses 370 370
Partials 123 123
Flags with carried forward coverage won't be shown. Click here to find out more. ☔ View full report in Codecov by Harness. |
Confidence Score: 2/5Not safe to merge until backport coverage is restored and mutable external actions no longer receive issue-writing access. The workflow directly contains both the nonmatching numeric-backport glob and mutable external action references in the issue-writing job. Focused checks exercised those conditions, but the environment could not publish the captured evidence artifacts. Files Needing Attention: .github/workflows/cifuzz.yml needs updates to both event branch filters and the job/action permission boundary.
|
| - '[0-9].[0-9]+' # matches to backport branches, e.g. 3.6 | ||
| pull_request: | ||
| branches: | ||
| - 'master' | ||
| - '[0-9].[0-9]+' |
There was a problem hiding this comment.
Backport branch glob does not match
The [0-9].[0-9]+ filters on both the push and pull-request triggers do not match a normal backport branch such as 3.6: + is literal in this glob syntax. CIFuzz is therefore not scheduled for those maintained backport branches. Use a matching glob such as [0-9].[0-9]* in both trigger lists.
| permissions: | ||
| contents: read # For build_fuzzers to check out the code | ||
| issues: write # To create a new issue in the last step | ||
| strategy: | ||
| fail-fast: false | ||
| matrix: | ||
| sanitizer: [address, undefined] | ||
| steps: | ||
| - name: Build Fuzzers | ||
| id: build | ||
| uses: google/oss-fuzz/infra/cifuzz/actions/build_fuzzers@master | ||
| with: | ||
| oss-fuzz-project-name: 'aiohttp' | ||
| language: python | ||
| sanitizer: ${{ matrix.sanitizer }} | ||
| - name: Run Fuzzers | ||
| uses: google/oss-fuzz/infra/cifuzz/actions/run_fuzzers@master |
There was a problem hiding this comment.
Mutable actions inherit issue-write access
The Fuzzing job grants issues: write before running the OSS-Fuzz build and run actions from mutable @master references. An upstream change to either action would execute with this repository's issue-writing token. Pin the actions to immutable full commit SHAs and move issue creation to a separately scoped write-capable job.
Merging this PR will degrade performance by 10.19%
|
| Benchmark | BASE |
HEAD |
Efficiency | |
|---|---|---|---|---|
| ❌ | test_link_param_pattern_redos_payload[embedded_newlines] |
35.2 µs | 39.1 µs | -10.19% |
Tip
Investigate this regression by commenting @codspeedbot fix this regression on this PR, or directly use the CodSpeed MCP with your agent.
Comparing Dreamsorcerer-patch-2 (2d66dab) with master (bffb2f1)
Footnotes
-
83 benchmarks were skipped, so the baseline results were used instead. If they were deleted from the codebase, click here and archive them to remove them from the performance reports. ↩
Follow up to #12887.