Skip to content

fix(fuzzing): return 0 (not 1) from the size guard in every harness - #3579

Merged
wasphin merged 1 commit into
apache:masterfrom
li-lizhe:fix/fuzz-harness-size-guard-return
Oct 5, 2026
Merged

wasphin merged 1 commit into
apache:masterfrom
li-lizhe:fix/fuzz-harness-size-guard-return

Conversation

@li-lizhe

@li-lizhe li-lizhe commented Oct 4, 2026

Copy link
Copy Markdown
Contributor

LLVMFuzzerTestOneInput may only return 0 (input consumed) or -1 (input rejected). libFuzzer enforces this after every call — assert(CBRes == 0 || CBRes == -1) in compiler-rt/lib/fuzzer/FuzzerLoop.cpp:622 — and its first input is the empty one, so every harness here aborts an assert-enabled libFuzzer at startup.

All 18 harnesses under test/fuzzing/ open with

if (size < kMinInputLength || size > kMaxInputLength){
    return 1;          // not a legal return value
}

Fixes #3578 — return 1; becomes return 0; in all 18 files.

return -1 would also satisfy the contract if these inputs should be rejected outright; return 0 is used here because it matches what the newer harnesses already do (test/fuzzing/fuzz_rtmp.cpp in #3516). Either way the body is still skipped, so behaviour for in-range inputs is unchanged.

Verification

Standalone driver asserting the exact contract libFuzzer enforces (assert(r == 0 || r == -1), clang 17.0.6, openEuler 24.03, aarch64):

build LLVMFuzzerTestOneInput(empty, 0) result
before (return 1) 1 `Assertion 'r == 0
after (return 0) 0 return-value contract satisfied: CBRes=0, exit 0

The fixed harness also links and runs under a real libFuzzer (clang++ -std=c++17 -fsanitize=fuzzer, ./fuzz -runs=5 → Done 5 runs in 0 second(s), exit 0).

Not tested: a full brpc build + OSS-Fuzz run — the harnesses link the brpc libraries, which were not built here. The change is a single return value per file and touches no harness logic.

LLVMFuzzerTestOneInput may only return 0 (input consumed) or -1 (input
rejected); libFuzzer asserts this after every call
(compiler-rt/lib/fuzzer/FuzzerLoop.cpp:622) and runs the empty input first,
so every harness here aborts an assert-enabled libFuzzer at startup.
Returning 0 keeps out-of-range inputs out of the corpus (the harness body is
still skipped) and matches the convention newer harnesses already use.
All 18 test/fuzzing/fuzz_*.cpp harnesses share the same guard.

Signed-off-by: li-lizhe <147392333@qq.com>

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

All affected harnesses now satisfy libFuzzer’s callback contract without changing in-range processing.

Review effort: Balanced
Findings: None

What changed in this PR

Updates all fuzzing harness size guards to return a valid libFuzzer result, preventing startup assertions on empty input.

Changes:

  • Replaces invalid return 1 with return 0 in all 18 harnesses.
  • Leaves in-range fuzzing logic unchanged.
File Description
test/​fuzzing/​fuzz_uri.cpp Fixes size-guard return value.
test/​fuzzing/​fuzz_thrift.cpp Fixes size-guard return value.
test/​fuzzing/​fuzz_streaming.cpp Fixes size-guard return value.
test/​fuzzing/​fuzz_sofa.cpp Fixes size-guard return value.
test/​fuzzing/​fuzz_shead.cpp Fixes size-guard return value.
test/​fuzzing/​fuzz_redis.cpp Fixes size-guard return value.
test/​fuzzing/​fuzz_mongo.cpp Fixes size-guard return value.
test/​fuzzing/​fuzz_memcache.cpp Fixes size-guard return value.
test/​fuzzing/​fuzz_json.cpp Fixes size-guard return value.
test/​fuzzing/​fuzz_hulu.cpp Fixes size-guard return value.
test/​fuzzing/​fuzz_http.cpp Fixes size-guard return value.
test/​fuzzing/​fuzz_http_parser.cpp Fixes size-guard return value.
test/​fuzzing/​fuzz_hpack.cpp Fixes size-guard return value.
test/​fuzzing/​fuzz_esp.cpp Fixes size-guard return value.
test/​fuzzing/​fuzz_couchbase.cpp Fixes size-guard return value.
test/​fuzzing/​fuzz_butil.cpp Fixes size-guard return value.
test/​fuzzing/​fuzz_baidu_rpc.cpp Fixes size-guard return value.
test/​fuzzing/​fuzz_amf.cpp Fixes size-guard return value.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

All fuzz targets now return a valid libFuzzer result without altering their in-range processing.

Review effort: Balanced
Findings: None

@wwbmmm

wwbmmm commented Oct 4, 2026

Copy link
Copy Markdown
Contributor

LGTM

@wasphin
wasphin merged commit 3ee7ef6 into apache:master Oct 5, 2026
25 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

test/fuzzing: LLVMFuzzerTestOneInput returns 1 for out-of-range sizes

4 participants