You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: CHANGELOG.md
+1Lines changed: 1 addition & 0 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -8,6 +8,7 @@ stricter subset of Keep a Changelog).
8
8
9
9
### Changed
10
10
11
+
- Auditing CRS type: does not require a target harness and produces bug-candidates
11
12
-`oss-crs export` and `oss-crs import` commands — imports/exports docker images/CRS source code to transfer to another host.
12
13
- Run-phase modules now default to `target_dependent: true`, so their images are built once per target during `build-target`. Set `target_dependent: false` for modules that can be built once during `prepare`.
13
14
-`--offline` flag for all subcommands: disables git fetch
| `architecture` | `Set[TargetArch]` | Yes | Supported CPU architectures (see [TargetArch](#targetarch)) |
234
+
| `sanitizer` | `Set[TargetSanitizer]` | No | Supported sanitizers (see [TargetSanitizer](#targetsanitizer)). Defaults to all sanitizers when omitted. |
235
+
| `architecture` | `Set[TargetArch]` | No | Supported CPU architectures (see [TargetArch](#targetarch)). Defaults to all architectures when omitted. |
236
236
| `fuzzing_engine` | `Set[FuzzingEngine]` | No | Supported fuzzing engines (see [FuzzingEngine](#fuzzingengine)). Defaults to all engines when omitted. |
237
237
238
238
### Example
@@ -271,6 +271,7 @@ Defines the type of CRS:
271
271
| `bug-fixing-ensemble` | Ensemble CRS that aggregates bug-fixing outputs |
272
272
| `bug-finding-triage` | Post-processor CRS that triages bug-finding results (e.g. deduplication, validation). Reads from the main exchange dir and writes to the processed exchange dir. |
273
273
| `seed-filter` | Post-processor CRS that filters or prioritizes seeds/inputs for downstream CRS. Reads from the main exchange dir and writes to the processed exchange dir. |
274
+
| `auditing` | Source-auditing CRS that analyzes `OSS_CRS_TARGET_SOURCE` and submits `bug-candidate` artifacts. It may run with or without a target harness. |
|`--fuzz-proj-path` (`--target-path`, `--target-proj-path`, deprecated aliases) | Yes | Path to the OSS-Fuzz target project directory (`Dockerfile`, `build.sh`; `project.yaml` optional). |
52
-
|`--target-source-path`| No | Optional local source override path. If set, source is synchronized with `rsync -a --delete` into the effective Dockerfile `WORKDIR`. |
Existing [OSS-Fuzz projects](https://github.com/google/oss-fuzz/tree/master/projects) can be used directly as `--fuzz-proj-path` without modification.
53
+
```bash
54
+
uv run oss-crs run \
55
+
--compose-file ./crs-compose.yaml \
56
+
--target-source-path /path/to/source
57
+
```
56
58
57
-
### Source Path Semantics
59
+
Source-only runs omit `--fuzz-proj-path` entirely. The source path is
60
+
directly bind-mounted to `OSS_CRS_TARGET_SOURCE`. There is no build step,
61
+
no `OSS_CRS_FUZZ_PROJ` mount, and `SANITIZER`, `ARCHITECTURE`, and
62
+
`FUZZING_LANGUAGE` are not injected into source-only containers.
58
63
59
-
-`OSS_CRS_PROJ_PATH` points to the copied target project directory.
60
-
-`OSS_CRS_REPO_PATH` points to the effective final Dockerfile `WORKDIR` inside
61
-
the target image.
62
-
-`WORKDIR` resolution follows Dockerfile semantics, with fallback chain:
63
-
final `WORKDIR` -> `$SRC` -> `/src` (when `SRC` is not provided).
64
-
-`libCRS download-source repo` prefers the live runtime source workspace
65
-
rooted at `$SRC`/`/src`. When `OSS_CRS_REPO_PATH` is inside that workspace,
66
-
the downloaded tree preserves the workspace layout rather than flattening a
67
-
nested `WORKDIR`.
68
-
- When `--target-source-path` is set, the override source is synchronized into
69
-
`OSS_CRS_REPO_PATH` via `rsync -a --delete`.
64
+
## Arguments
65
+
66
+
| Argument | Required | Description |
67
+
|----------|----------|-------------|
68
+
|`--fuzz-proj-path` (`--target-path`, `--target-proj-path`, deprecated aliases) | Yes for harnessed/harness-gen runs; omitted for source-only runs | Path to the OSS-Fuzz target project directory (`Dockerfile`, `build.sh`; `project.yaml` optional). |
69
+
|`--target-source-path`| Required for source-only runs; optional local source override otherwise | Path to the source tree. For source-only runs, this is directly bind-mounted. For harnessed runs, source is synchronized with `rsync -a --delete` into the effective Dockerfile `WORKDIR`. |
At least one of `--fuzz-proj-path` or `--target-source-path` is required.
73
+
If `--fuzz-proj-path` is specified, `--target-harness` is required.
70
74
71
-
### `--target-source-path` Sync Flow
75
+
Existing [OSS-Fuzz projects](https://github.com/google.com/oss-fuzz/tree/master/projects) can be used directly as `--fuzz-proj-path` without modification.
76
+
77
+
## Source Path Semantics
78
+
79
+
### Harnessed Runs with Source Override
72
80
73
81
`--target-source-path` is not bind-mounted directly to `OSS_CRS_REPO_PATH`.
74
82
Instead, during image build:
@@ -78,3 +86,20 @@ Instead, during image build:
78
86
3.`rsync -a --delete /OSS_CRS_REPO_OVERRIDE/ ./` runs from the effective
79
87
`WORKDIR`.
80
88
4.`OSS_CRS_REPO_PATH` points to that effective `WORKDIR` path.
89
+
90
+
### Source-Only Runs
91
+
92
+
For source-only runs, `--target-source-path` is directly bind-mounted to
93
+
`OSS_CRS_TARGET_SOURCE`. There is no image build, no `OSS_CRS_FUZZ_PROJ`
94
+
mount, and no `SANITIZER`, `ARCHITECTURE`, or `FUZZING_LANGUAGE` injection.
95
+
96
+
### Common Semantics
97
+
98
+
-`OSS_CRS_REPO_PATH` points to the effective final Dockerfile `WORKDIR`
99
+
inside the target image.
100
+
-`WORKDIR` resolution follows Dockerfile semantics, with fallback chain:
101
+
final `WORKDIR` -> `$SRC` -> `/src` (when `SRC` is not provided).
102
+
-`libCRS download-source repo` prefers the live runtime source workspace
103
+
rooted at `$SRC`/`/src`. When `OSS_CRS_REPO_PATH` is inside that workspace,
104
+
the downloaded tree preserves the workspace layout rather than flattening a
Copy file name to clipboardExpand all lines: docs/crs-development-guide.md
+10-3Lines changed: 10 additions & 3 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -66,7 +66,7 @@ The `crs.yaml` file is the central configuration for your CRS. It tells OSS-CRS
66
66
```yaml
67
67
name: my-crs
68
68
type:
69
-
- bug-finding # bug-finding, bug-fixing, or both
69
+
- bug-finding # bug-finding, bug-fixing, etc.
70
70
version: "1.0.0"
71
71
docker_registry: "ghcr.io/my-org/my-crs"
72
72
@@ -131,7 +131,7 @@ required_envs:
131
131
| Field | Description |
132
132
|---|---|
133
133
| `name` | Unique name for your CRS |
134
-
| `type` | Set of CRS types: `bug-finding`, `bug-fixing` |
134
+
| `type` | Set of CRS capabilities: `bug-finding`, `bug-fixing`, etc. |
135
135
| `version` | Version string (used as a Docker image tag) |
136
136
| `docker_registry` | Docker registry URL for your CRS images |
137
137
| `prepare_phase.hcl` | Path to the HCL file for `docker buildx bake` |
@@ -346,7 +346,7 @@ Your containers receive these environment variables automatically:
346
346
|`OSS_CRS_NAME`| CRS name (from `crs-compose.yaml`) |`my-crs`|
347
347
|`OSS_CRS_SERVICE_NAME`| Full service name |`my-crs_fuzzer`|
348
348
|`OSS_CRS_TARGET`| Target project name |`libxml2`|
349
-
|`OSS_CRS_TARGET_HARNESS`| Target harness binary name |`xml`|
349
+
|`OSS_CRS_TARGET_HARNESS`| Target harness binary name. Unset for no-harness source-level runs.|`xml`|
350
350
|`OSS_CRS_CPUSET`| Allocated CPU cores |`4-7`|
351
351
|`OSS_CRS_MEMORY_LIMIT`| Memory limit |`16G`|
352
352
|`OSS_CRS_BUILD_OUT_DIR`| Build output directory (read-only at run time) |`/OSS_CRS_BUILD_OUT_DIR`|
@@ -799,6 +799,12 @@ Your CRS should submit findings through libCRS:
799
799
- **`register-submit-dir`** — Best for high-volume output. Forks a daemon that watches the directory, deduplicates files by hash, and submits in batches. Use this for seeds and PoVs.
800
800
- **`submit`** — Best for one-off submissions. Submits a single file immediately.
801
801
802
+
### Source-Level Bug Finding Without A Harness
803
+
804
+
Source-only runs are invoked without `--fuzz-proj-path` and instead use `--target-source-path` to point at the source tree. They skip OSS-Fuzz target image builds and require every run module to set `target_dependent: false`; run `oss-crs prepare` first to build those target-independent images. They do not mount `OSS_CRS_BUILD_OUT_DIR` or `OSS_CRS_FUZZ_PROJ`, but still receive `OSS_CRS_SUBMIT_DIR`, `OSS_CRS_FETCH_DIR`, `OSS_CRS_SHARED_DIR`, `OSS_CRS_LOG_DIR`, and `OSS_CRS_TARGET_SOURCE`. They do not receive `OSS_CRS_TARGET_HARNESS`, `SANITIZER`, `ARCHITECTURE`, or `FUZZING_LANGUAGE`.
805
+
806
+
Source-only runs require all CRSs to be of type `auditing`. This ensures that only CRSs designed to analyze source code without a compiled target can run in source-only mode. An `auditing` CRS is a regular producer that reads `OSS_CRS_TARGET_SOURCE` and submits `bug-candidate` artifacts. The type is a capability label rather than a source-only restriction: auditors may run alone without `--target-harness` or alongside harness-based CRSs.
807
+
802
808
---
803
809
804
810
## Fetching Data
@@ -914,6 +920,7 @@ Before publishing your CRS, verify:
Copy file name to clipboardExpand all lines: docs/registry.md
+1-1Lines changed: 1 addition & 1 deletion
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -18,7 +18,7 @@ source:
18
18
| Field | Description |
19
19
|---|---|
20
20
| `name` | Unique identifier for the CRS |
21
-
| `type` | List of CRS capabilities — `bug-finding`, `bug-fixing`, `bug-finding-triage`, `seed-filter`, `bug-fixing-ensemble`, or a combination |
21
+
| `type` | List of CRS capabilities — `bug-finding`, `bug-fixing`, `auditing`, `bug-finding-triage`, `seed-filter`, `bug-fixing-ensemble`, or a combination |
0 commit comments