Skip to content

security: add ClusterFuzzLite fuzzing for the SQL-safety kernel #3

security: add ClusterFuzzLite fuzzing for the SQL-safety kernel

security: add ClusterFuzzLite fuzzing for the SQL-safety kernel #3

Workflow file for this run

name: ClusterFuzzLite PR fuzzing
on:
pull_request:
paths:
- "src/mcpg/sql/**"
- ".clusterfuzzlite/**"
permissions: read-all
jobs:
PR:
runs-on: ubuntu-latest
concurrency:
group: ${{ github.workflow }}-${{ matrix.sanitizer }}-${{ github.ref }}
cancel-in-progress: true
strategy:
fail-fast: false
matrix:
sanitizer:
- address
- undefined
steps:
- name: Build Fuzzers (${{ matrix.sanitizer }})
id: build
uses: google/clusterfuzzlite/actions/build_fuzzers@884713a6c30a92e5e8544c39945cd7cb630abcd1 # v1
with:
language: python
github-token: ${{ secrets.GITHUB_TOKEN }}
sanitizer: ${{ matrix.sanitizer }}
# Without this, build_fuzzers tries to diff against a coverage
# baseline (a `cifuzz-coverage-latest` artifact) to prune
# "unaffected" targets before running — which doesn't exist yet
# on a fresh integration (chicken-and-egg on the very first
# fuzzing PR) and fails the build outright. There's only one
# fuzz target in this repo, so the optimization has no upside
# anyway; always keep it.
keep-unaffected-fuzz-targets: true
- name: Run Fuzzers (${{ matrix.sanitizer }})
id: run
uses: google/clusterfuzzlite/actions/run_fuzzers@884713a6c30a92e5e8544c39945cd7cb630abcd1 # v1
with:
github-token: ${{ secrets.GITHUB_TOKEN }}
fuzz-seconds: 300
mode: "code-change"
sanitizer: ${{ matrix.sanitizer }}
output-sarif: true