From cac766d434ba8ee3dd310453f42f2e34cd16ec45 Mon Sep 17 00:00:00 2001 From: Arjun <36335769+0x34d@users.noreply.github.com> Date: Wed, 4 Oct 2023 23:57:25 +0530 Subject: [PATCH] [Fuzzing] add cifuzz (#10462) * [Fuzzing] add cifuzz Signed-off-by: Arjun Singh * [Fuzzing] fix i'm stupid Signed-off-by: Arjun Singh * [cifuzz] update pr Signed-off-by: Arjun Singh --------- Signed-off-by: Arjun Singh --- .github/workflows/cifuzz.yml | 38 ++++++++++++++++++++++++++++++++++++ tests/fuzzing/oss-fuzz.sh | 4 ++-- 2 files changed, 40 insertions(+), 2 deletions(-) create mode 100644 .github/workflows/cifuzz.yml diff --git a/.github/workflows/cifuzz.yml b/.github/workflows/cifuzz.yml new file mode 100644 index 00000000000..9e906cbd1b2 --- /dev/null +++ b/.github/workflows/cifuzz.yml @@ -0,0 +1,38 @@ +name: CIFuzz +on: + schedule: + - cron: '0 0 * * 0' +permissions: {} +jobs: + Fuzzing: + runs-on: ubuntu-latest + permissions: + security-events: write + steps: + - name: Build Fuzzers + id: build + uses: google/oss-fuzz/infra/cifuzz/actions/build_fuzzers@master + with: + oss-fuzz-project-name: 'trafficserver' + language: c++ + - name: Run Fuzzers + uses: google/oss-fuzz/infra/cifuzz/actions/run_fuzzers@master + with: + oss-fuzz-project-name: 'trafficserver' + language: c++ + fuzz-seconds: 300 + output-sarif: true + - name: Upload Crash + uses: actions/upload-artifact@v3 + if: failure() && steps.build.outcome == 'success' + with: + name: artifacts + path: ./out/artifacts + - name: Upload Sarif + if: always() && steps.build.outcome == 'success' + uses: github/codeql-action/upload-sarif@v2 + with: + # Path to SARIF file relative to the root of the repository + sarif_file: cifuzz-sarif/results.sarif + checkout_path: cifuzz-sarif + category: CIFuzz diff --git a/tests/fuzzing/oss-fuzz.sh b/tests/fuzzing/oss-fuzz.sh index ac4640cde12..2fcac3704c9 100644 --- a/tests/fuzzing/oss-fuzz.sh +++ b/tests/fuzzing/oss-fuzz.sh @@ -39,6 +39,6 @@ cp $SRC/trafficserver/tests/fuzzing/*.zip $OUT/ if [[ $SANITIZER = undefined ]] then - rm $OUT/fuzz_http - rm $OUT/fuzz_hpack + rm -f $OUT/fuzz_http + rm -f $OUT/fuzz_hpack fi