Skip to content

ClusterFuzzLite

ClusterFuzzLite #915

# SPDX-License-Identifier: MPL-2.0
# This workflow is managed by gh actions-lock.
# Consolidated workflow (behaviour-preserving merge).
# Merged from: cflite_batch.yml, cflite_pr.yml
name: ClusterFuzzLite
on:
pull_request:
paths:
- src/**
- crates/**
- fuzz/**
schedule:
- cron: '0 2 * * 0'
workflow_dispatch:
permissions: read-all
concurrency:
group: ${{ github.workflow }}-${{ github.ref }}
cancel-in-progress: true
jobs:
# `hashFiles()` is available ONLY in `jobs.<id>.steps.*`. Used in a job-level
# `if:` it does not merely evaluate false - GitHub rejects the WHOLE workflow
# file, which produces a run with zero jobs and no check run at all rather
# than a visible failure. Resolve the gate in a step here and publish it as a
# job output instead.
detect-fuzz-targets:
runs-on: ubuntu-latest
timeout-minutes: 5
outputs:
present: ${{ steps.check.outputs.present }}
steps:
# Sparse + blobless: this job only needs to know whether two paths exist,
# so fetching the tree is enough — no file contents, no history.
- uses: actions/checkout@v7.0.1
with:
sparse-checkout: |
fuzz
.clusterfuzzlite
sparse-checkout-cone-mode: false
filter: blob:none
persist-credentials: false
- id: check
run: |
if [ -f fuzz/Cargo.toml ] || [ -f .clusterfuzzlite/build.sh ]; then
echo "present=true" >> "$GITHUB_OUTPUT"
else
echo "present=false" >> "$GITHUB_OUTPUT"
echo "No fuzz targets (fuzz/Cargo.toml or .clusterfuzzlite/build.sh); fuzzing jobs will skip."
fi
pr-fuzzing:
runs-on: ubuntu-latest
timeout-minutes: 60
# Gated on the presence of fuzz targets — without `fuzz/` (cargo-fuzz)
# or a ClusterFuzzLite OSS-Fuzz-style harness, the build_fuzzers step
# has nothing to compile and fails. Job re-activates the moment the
# fuzz tree lands.
needs: detect-fuzz-targets
if: needs.detect-fuzz-targets.outputs.present == 'true'
steps:
- uses: actions/checkout@v7.0.1
with:
fetch-depth: 0
- uses: google/clusterfuzzlite/actions/build_fuzzers@v1
with:
language: rust
sanitizer: address
- uses: google/clusterfuzzlite/actions/run_fuzzers@v1
with:
github-token: ${{ secrets.GITHUB_TOKEN }}
fuzz-seconds: 300
mode: prune
sanitizer: address
batch-fuzzing:
runs-on: ubuntu-latest
timeout-minutes: 60
# Was UNGATED: on the weekly cron this ran regardless of whether any fuzz
# target existed, hitting exactly the failure pr-fuzzing's comment describes.
needs: detect-fuzz-targets
if: needs.detect-fuzz-targets.outputs.present == 'true'
steps:
- uses: actions/checkout@v7.0.1
- uses: google/clusterfuzzlite/actions/build_fuzzers@v1
with:
language: rust
sanitizer: address
- uses: google/clusterfuzzlite/actions/run_fuzzers@v1
with:
github-token: ${{ secrets.GITHUB_TOKEN }}
fuzz-seconds: 1800
mode: batch
sanitizer: address