Skip to content

Commit fc0a03e

Browse files
committed
docs(testing): document binary corpus preparation and path guards
1 parent 9ca7568 commit fc0a03e

3 files changed

Lines changed: 16 additions & 8 deletions

File tree

‎TODO.md‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -51,7 +51,7 @@ default ordinal 不受污染。post-binding normalization 补齐 default-input
5151
- [x] 当前支持的分支、循环、loop-else、`break`/`continue` 与 `SELECT CASE` 使用 MIR basic block、terminator、block argument/edge actual;shape stride、storage view/lifetime/intent 可验证,独立 alias/effect table 提供保守 `alias_between` 查询
5252
- [x] JavaScript/`cpp` representation、ABI、type/shape、名称、runtime 与 binding 决策在目标 lowering/renderer 完成;emitter 只序列化最终 chunk
5353
- [x] 公共 output bundle 提供代码、source map v3、确定性 dependency manifest 与逐阶段 `CompilationReport`;CLI 支持 `--source-map`
54-
- [x] 四语言/双目标 fuzz smoke、Clang/libFuzzer、资源耗尽、确定性重放、崩溃复现与最小化工作流落地;libFuzzer 构建必须插桩 production core/backend/facade,而非仅 driver。文本 seed 经受保护的 preparer 生成语言/目标双控制字节,两个目标均保留完整源 payload;未 framing 的文本重放不作为编译路径验收
54+
- [x] 四语言/双目标 fuzz smoke、Clang/libFuzzer、资源耗尽、确定性重放、崩溃复现与最小化工作流落地;libFuzzer 构建必须插桩 production core/backend/facade,而非仅 driver。文本 seed 经受保护的 C++17 二进制 preparer 生成语言/目标双控制字节,两个目标均保留完整源 payload;契约覆盖 Windows 换行字节、UTF-8、含空格路径和可用平台上的嵌套符号链接逃逸;未 framing 的文本重放不作为编译路径验收
5555
- [x] 延迟、吞吐、深 CFG、大 shape、函数图、八路并发、峰值 arena 和产物大小纳入版本化 JSON 发布门禁与 CI 报告
5656

5757
这里的“完成”只指上述架构与工程闭环;各语言官方 grammar、完整对象模型、跨语言动态 shape 传播与 NDArray 表示、一般 view/pointer 的完整 overlap/alias 和稳定插件 ABI 仍由后续条目跟踪。

‎docs/TESTING.md‎

Lines changed: 6 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -103,8 +103,10 @@ source map/确定性和 query/frame/call/private-plan 的独立损坏拒绝(
103103

104104
libFuzzer 模式将 production core、启用的 backend 和 facade 以
105105
`fuzzer-no-link,address,undefined` 插桩,不能仅给 driver 加 coverage counters。
106-
`prepare_corpus.cmake` 为每个文本 seed 生成两个目标的两字节 framed payload,独立
107-
`mpf.fuzz.corpus-contract` 逐字节复核并拒绝写入 source corpus;具体构建/重放格式见
106+
`prepare_corpus.cmake` 调用独立的 C++17 二进制 framing 工具,为每个文本 seed 生成两个
107+
目标的两字节 framed payload,避免 Windows 文本模式改变换行字节。独立
108+
`mpf.fuzz.corpus-contract` 逐字节复核,包括 CRLF/LF/UTF-8 fixture,并拒绝写入 source
109+
corpus 或通过输出目录的符号链接逃出根 `build/`;具体构建/重放格式见
108110
[fuzz 指南](../tests/fuzz/README.md)。旧的未插桩库或未 framing 的 1,000 次 driver 运行
109111
不能作为生产编译路径 fuzz 验收证据。
110112
Memory Safety workflow 独立执行固定 seed 的 coverage-guided fuzz job;其 required
@@ -227,8 +229,9 @@ Clang 环境可运行覆盖引导 fuzz:
227229

228230
```sh
229231
cmake -S . -B build/fuzz -DMPF_BUILD_FUZZERS=ON -DCMAKE_CXX_COMPILER=clang++
230-
cmake --build build/fuzz --target mpf-transpiler-fuzzer
232+
cmake --build build/fuzz --target mpf-transpiler-fuzzer mpf-fuzz-corpus-preparer
231233
cmake -DSOURCE_DIR="$PWD" -DCORPUS_DIR="$PWD/build/fuzz/framed-corpus" \
234+
-DPREPARER="$PWD/build/fuzz/tests/mpf-fuzz-corpus-preparer" \
232235
-P tests/fuzz/prepare_corpus.cmake
233236
build/fuzz/tests/mpf-transpiler-fuzzer build/fuzz/framed-corpus \
234237
-runs=1000 -seed=420800 -max_len=4096 -artifact_prefix=build/fuzz/

‎tests/fuzz/README.md‎

Lines changed: 9 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -20,12 +20,15 @@ the driver does not provide coverage-guided testing of the compiler.
2020

2121
Prepare the checked-in text seeds beneath root `build/` before running. The driver consumes
2222
two control bytes (source language modulo four; target low bit), followed by the unchanged
23-
source bytes. The preparer makes both JavaScript and cpp variants for every source seed and
24-
refuses output outside `build/`. Do not feed unframed text to the driver or write mutations
25-
into the checked-in source corpus:
23+
source bytes. The C++17 preparer uses binary streams to preserve CRLF, LF, and UTF-8 bytes on
24+
every platform. It makes both JavaScript and cpp variants for every source seed and refuses
25+
output outside `build/`, including nested symlink escapes. Do not feed unframed text to the
26+
driver or write mutations into the checked-in source corpus:
2627

2728
```sh
29+
cmake --build build/fuzz --target mpf-transpiler-fuzzer mpf-fuzz-corpus-preparer
2830
cmake -DSOURCE_DIR="$PWD" -DCORPUS_DIR="$PWD/build/fuzz/framed-corpus" \
31+
-DPREPARER="$PWD/build/fuzz/tests/mpf-fuzz-corpus-preparer" \
2932
-P tests/fuzz/prepare_corpus.cmake
3033
build/fuzz/tests/mpf-transpiler-fuzzer build/fuzz/framed-corpus \
3134
-runs=1000 -max_len=4096 -artifact_prefix=build/fuzz/
@@ -35,4 +38,6 @@ A framed crashing input can be replayed by passing the file to `mpf-transpiler-f
3538
minimized into `build/fuzz/` with libFuzzer's
3639
`-minimize_crash=1 -exact_artifact_path=<output>` workflow. `mpf-fuzz-smoke` consumes the
3740
original language-directory text format, not framed libFuzzer artifacts. The corpus contract
38-
checks every language/target prefix and payload byte plus source-directory write rejection.
41+
checks every language/target prefix and payload byte, mixed CRLF/LF and UTF-8 fixtures, and
42+
source-directory write rejection. Where symlinks are supported, it also checks nested output
43+
symlink escapes. CMake orchestrates the preparer; it does not perform text-mode seed encoding.

0 commit comments

Comments
 (0)