Skip to content

feat(audit-guard): setup automated mutation fuzzing (#105)#149

Closed
codewithzubair07 wants to merge 1 commit into
Vero-protocol:mainfrom
codewithzubair07:feat/audit-guard-implementation
Closed

feat(audit-guard): setup automated mutation fuzzing (#105)#149
codewithzubair07 wants to merge 1 commit into
Vero-protocol:mainfrom
codewithzubair07:feat/audit-guard-implementation

Conversation

@codewithzubair07

Copy link
Copy Markdown
  • Refactor scanner-engine into lib.rs + main.rs split so fuzz targets can call internal functions without spawning a process
  • Expose scan_content() for in-memory fuzzing (no disk I/O)
  • Add cargo-fuzz workspace under scanner-engine/fuzz/ with three libFuzzer targets:
    • fuzz_scan_file – drives scan_content() with arbitrary UTF-8
    • fuzz_sha256 – asserts sha256_of() output is always 64-char hex
    • fuzz_rule_regex – runs every compiled regex against arbitrary input
  • Add .github/workflows/mutation-fuzzing.yml:
    • Triggers on PR/push to scanner-engine/** and nightly schedule
    • Runs each fuzz target for 30s on PRs, 300s on schedule
    • Uploads crash artifacts (30-day retention) and corpus (7-day)
    • Posts PR comment on crash with local reproduction command
    • Generates job step summary with per-target status

Closes #105

- Refactor scanner-engine into lib.rs + main.rs split so fuzz
  targets can call internal functions without spawning a process
- Expose scan_content() for in-memory fuzzing (no disk I/O)
- Add cargo-fuzz workspace under scanner-engine/fuzz/ with three
  libFuzzer targets:
    * fuzz_scan_file  – drives scan_content() with arbitrary UTF-8
    * fuzz_sha256     – asserts sha256_of() output is always 64-char hex
    * fuzz_rule_regex – runs every compiled regex against arbitrary input
- Add .github/workflows/mutation-fuzzing.yml:
    * Triggers on PR/push to scanner-engine/** and nightly schedule
    * Runs each fuzz target for 30s on PRs, 300s on schedule
    * Uploads crash artifacts (30-day retention) and corpus (7-day)
    * Posts PR comment on crash with local reproduction command
    * Generates job step summary with per-target status

Closes Vero-protocol#105
@N-thnI N-thnI closed this Jul 10, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[Audit-Guard] Setup automated mutation fuzzing

2 participants