Repository navigation
ClusterFuzzLite #915
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| # SPDX-License-Identifier: MPL-2.0 | |
| # This workflow is managed by gh actions-lock. | |
| # Consolidated workflow (behaviour-preserving merge). | |
| # Merged from: cflite_batch.yml, cflite_pr.yml | |
| name: ClusterFuzzLite | |
| on: | |
| pull_request: | |
| paths: | |
| - src/** | |
| - crates/** | |
| - fuzz/** | |
| schedule: | |
| - cron: '0 2 * * 0' | |
| workflow_dispatch: | |
| permissions: read-all | |
| concurrency: | |
| group: ${{ github.workflow }}-${{ github.ref }} | |
| cancel-in-progress: true | |
| jobs: | |
| # `hashFiles()` is available ONLY in `jobs.<id>.steps.*`. Used in a job-level | |
| # `if:` it does not merely evaluate false - GitHub rejects the WHOLE workflow | |
| # file, which produces a run with zero jobs and no check run at all rather | |
| # than a visible failure. Resolve the gate in a step here and publish it as a | |
| # job output instead. | |
| detect-fuzz-targets: | |
| runs-on: ubuntu-latest | |
| timeout-minutes: 5 | |
| outputs: | |
| present: ${{ steps.check.outputs.present }} | |
| steps: | |
| # Sparse + blobless: this job only needs to know whether two paths exist, | |
| # so fetching the tree is enough — no file contents, no history. | |
| - uses: actions/checkout@v7.0.1 | |
| with: | |
| sparse-checkout: | | |
| fuzz | |
| .clusterfuzzlite | |
| sparse-checkout-cone-mode: false | |
| filter: blob:none | |
| persist-credentials: false | |
| - id: check | |
| run: | | |
| if [ -f fuzz/Cargo.toml ] || [ -f .clusterfuzzlite/build.sh ]; then | |
| echo "present=true" >> "$GITHUB_OUTPUT" | |
| else | |
| echo "present=false" >> "$GITHUB_OUTPUT" | |
| echo "No fuzz targets (fuzz/Cargo.toml or .clusterfuzzlite/build.sh); fuzzing jobs will skip." | |
| fi | |
| pr-fuzzing: | |
| runs-on: ubuntu-latest | |
| timeout-minutes: 60 | |
| # Gated on the presence of fuzz targets — without `fuzz/` (cargo-fuzz) | |
| # or a ClusterFuzzLite OSS-Fuzz-style harness, the build_fuzzers step | |
| # has nothing to compile and fails. Job re-activates the moment the | |
| # fuzz tree lands. | |
| needs: detect-fuzz-targets | |
| if: needs.detect-fuzz-targets.outputs.present == 'true' | |
| steps: | |
| - uses: actions/checkout@v7.0.1 | |
| with: | |
| fetch-depth: 0 | |
| - uses: google/clusterfuzzlite/actions/build_fuzzers@v1 | |
| with: | |
| language: rust | |
| sanitizer: address | |
| - uses: google/clusterfuzzlite/actions/run_fuzzers@v1 | |
| with: | |
| github-token: ${{ secrets.GITHUB_TOKEN }} | |
| fuzz-seconds: 300 | |
| mode: prune | |
| sanitizer: address | |
| batch-fuzzing: | |
| runs-on: ubuntu-latest | |
| timeout-minutes: 60 | |
| # Was UNGATED: on the weekly cron this ran regardless of whether any fuzz | |
| # target existed, hitting exactly the failure pr-fuzzing's comment describes. | |
| needs: detect-fuzz-targets | |
| if: needs.detect-fuzz-targets.outputs.present == 'true' | |
| steps: | |
| - uses: actions/checkout@v7.0.1 | |
| - uses: google/clusterfuzzlite/actions/build_fuzzers@v1 | |
| with: | |
| language: rust | |
| sanitizer: address | |
| - uses: google/clusterfuzzlite/actions/run_fuzzers@v1 | |
| with: | |
| github-token: ${{ secrets.GITHUB_TOKEN }} | |
| fuzz-seconds: 1800 | |
| mode: batch | |
| sanitizer: address |