Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Add simple fuzz test #34

Merged
merged 3 commits into from
Jun 22, 2023
Merged

Add simple fuzz test #34

merged 3 commits into from
Jun 22, 2023

Conversation

imjasonh
Copy link
Contributor

@imjasonh imjasonh commented Jul 5, 2022

Signed-off-by: Jason Hall imjasonh@gmail.com

This adds a simple Go fuzz test that checks for inputs that cause FromString to panic. Returned errors are not considered interesting fuzzing inputs, only inputs that panic.

The result is output in testdata/fuzz/FuzzFromString that cause FromString to panic, among them, the string "0", and "?A".

We should fix these panics so that these inputs don't panic, then add them to the repo so that future fuzz attempts know to start with those inputs when generating new potentially interesting inputs.

Signed-off-by: Jason Hall <imjasonh@gmail.com>
@imjasonh imjasonh marked this pull request as draft July 5, 2022 19:48
@imjasonh imjasonh marked this pull request as ready for review July 5, 2022 21:19
@imjasonh
Copy link
Contributor Author

Friendly ping.

@imjasonh
Copy link
Contributor Author

Rebased and resolved conflicts.

@shibumi
Copy link
Collaborator

shibumi commented Jun 22, 2023

thx @imjasonh

@shibumi shibumi merged commit bdcb431 into package-url:master Jun 22, 2023
2 checks passed
another-rex pushed a commit to google/osv-scanner that referenced this pull request Oct 11, 2023
[![Mend
Renovate](https://app.renovatebot.com/images/banner.svg)](https://renovatebot.com)

This PR contains the following updates:

| Package | Type | Update | Change |
|---|---|---|---|
| [github.com/google/go-cmp](https://togithub.com/google/go-cmp) |
require | minor | `v0.5.9` -> `v0.6.0` |
|
[github.com/jedib0t/go-pretty/v6](https://togithub.com/jedib0t/go-pretty)
| require | patch | `v6.4.7` -> `v6.4.8` |
|
[github.com/package-url/packageurl-go](https://togithub.com/package-url/packageurl-go)
| require | patch | `v0.1.1` -> `v0.1.2` |
| golang.org/x/exp | require | digest | `9212866` -> `7918f67` |
| golang.org/x/mod | require | minor | `v0.12.0` -> `v0.13.0` |
| golang.org/x/sync | require | minor | `v0.3.0` -> `v0.4.0` |
| golang.org/x/term | require | minor | `v0.12.0` -> `v0.13.0` |

---

### Release Notes

<details>
<summary>google/go-cmp (github.com/google/go-cmp)</summary>

### [`v0.6.0`](https://togithub.com/google/go-cmp/releases/tag/v0.6.0)

[Compare
Source](https://togithub.com/google/go-cmp/compare/v0.5.9...v0.6.0)

New API:

- ([#&#8203;340](https://togithub.com/google/go-cmp/issues/340)) Add
`cmpopts.EquateComparable`

Documentation changes:

- ([#&#8203;337](https://togithub.com/google/go-cmp/issues/337)) Use of
hotlinking of Go identifiers

Build changes:

- ([#&#8203;325](https://togithub.com/google/go-cmp/issues/325)) Remove
purego fallbacks

Testing changes:

- ([#&#8203;322](https://togithub.com/google/go-cmp/issues/322)) Run
tests for Go 1.20 version
- ([#&#8203;332](https://togithub.com/google/go-cmp/issues/332)) Pin
GitHub action versions
- ([#&#8203;327](https://togithub.com/google/go-cmp/issues/327)) set
workflow permission to read-only

</details>

<details>
<summary>jedib0t/go-pretty (github.com/jedib0t/go-pretty/v6)</summary>

###
[`v6.4.8`](https://togithub.com/jedib0t/go-pretty/releases/tag/v6.4.8)

[Compare
Source](https://togithub.com/jedib0t/go-pretty/compare/v6.4.7...v6.4.8)

### Features

-   **table**
- `RenderTSV()` to render table in TSV format
([#&#8203;277](https://togithub.com/jedib0t/go-pretty/issues/277)) //
thanks [@&#8203;rafiramadhana](https://togithub.com/rafiramadhana)

</details>

<details>
<summary>package-url/packageurl-go
(github.com/package-url/packageurl-go)</summary>

###
[`v0.1.2`](https://togithub.com/package-url/packageurl-go/releases/tag/v0.1.2)

[Compare
Source](https://togithub.com/package-url/packageurl-go/compare/v0.1.1...v0.1.2)

#### What's Changed

- Add Julia by [@&#8203;Octogonapus](https://togithub.com/Octogonapus)
in
[package-url/packageurl-go#44
- feat: add missing purl types by
[@&#8203;mcombuechen](https://togithub.com/mcombuechen) in
[package-url/packageurl-go#43
- Pull test data from upstream instead of maintaining a local copy by
[@&#8203;Octogonapus](https://togithub.com/Octogonapus) in
[package-url/packageurl-go#49
- Add simple fuzz test by
[@&#8203;imjasonh](https://togithub.com/imjasonh) in
[package-url/packageurl-go#34
- Test using supported Go versions by
[@&#8203;imjasonh](https://togithub.com/imjasonh) in
[package-url/packageurl-go#50
- Remove deprecated usage of ioutil by
[@&#8203;noqcks](https://togithub.com/noqcks) in
[package-url/packageurl-go#40
- fix: use url.URL to encode and decode PURLs by
[@&#8203;tommyknows](https://togithub.com/tommyknows) in
[package-url/packageurl-go#52
- fix: escape and unescape name by
[@&#8203;tommyknows](https://togithub.com/tommyknows) in
[package-url/packageurl-go#55
- fix: escape everything with modified QueryEscape by
[@&#8203;tommyknows](https://togithub.com/tommyknows) in
[package-url/packageurl-go#58
- Add `pub` and `bitnami` types by
[@&#8203;antgamdia](https://togithub.com/antgamdia) in
[package-url/packageurl-go#60
- Add known types and candidate types by
[@&#8203;antgamdia](https://togithub.com/antgamdia) in
[package-url/packageurl-go#61
- Add PackageURL.Normalize by
[@&#8203;wetterjames4](https://togithub.com/wetterjames4) in
[package-url/packageurl-go#65

#### New Contributors

- [@&#8203;mcombuechen](https://togithub.com/mcombuechen) made their
first contribution in
[package-url/packageurl-go#43
- [@&#8203;imjasonh](https://togithub.com/imjasonh) made their first
contribution in
[package-url/packageurl-go#34
- [@&#8203;noqcks](https://togithub.com/noqcks) made their first
contribution in
[package-url/packageurl-go#40
- [@&#8203;tommyknows](https://togithub.com/tommyknows) made their first
contribution in
[package-url/packageurl-go#52
- [@&#8203;antgamdia](https://togithub.com/antgamdia) made their first
contribution in
[package-url/packageurl-go#60
- [@&#8203;wetterjames4](https://togithub.com/wetterjames4) made their
first contribution in
[package-url/packageurl-go#65

**Full Changelog**:
package-url/packageurl-go@v0.1.1...v0.1.2

</details>

---

### Configuration

📅 **Schedule**: Branch creation - "before 6am on monday" in timezone
Australia/Sydney, Automerge - At any time (no schedule defined).

🚦 **Automerge**: Disabled by config. Please merge this manually once you
are satisfied.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

👻 **Immortal**: This PR will be recreated if closed unmerged. Get
[config help](https://togithub.com/renovatebot/renovate/discussions) if
that's undesired.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR has been generated by [Mend
Renovate](https://www.mend.io/free-developer-tools/renovate/). View
repository job log
[here](https://developer.mend.io/github/google/osv-scanner).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiIzNy4wLjMiLCJ1cGRhdGVkSW5WZXIiOiIzNy44LjEiLCJ0YXJnZXRCcmFuY2giOiJtYWluIn0=-->
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants