Skip to content

actually fuzz utf8proc_normalize_utf32 in the fuzz target - #365

Merged
stevengj merged 1 commit into
JuliaStrings:masterfrom
shamsManna:fuzz-normalize-utf32-size-guard
Sep 28, 2026
Merged

stevengj merged 1 commit into
JuliaStrings:masterfrom
shamsManna:fuzz-normalize-utf32-size-guard

Conversation

@shamsManna

Copy link
Copy Markdown
Contributor

the fuzz target allocates its utf-32 scratch buffer as size >= 4 ? NULL : malloc(size), so copy is only non-null when the whole input is under 4 bytes, and the very next statement size /= 4 then drives the length to 0. every one of the six utf8proc_normalize_utf32 calls has run with length 0 since the target was added, so a public entry point that consumes untrusted utf-32 has effectively had no fuzz coverage. flip the guard to size >= 4 ? malloc(size) : NULL and copy size * sizeof(utf8proc_int32_t) bytes so normalize reads real, initialized code points. locally 0 of 6160 normalize calls had a non-zero length before this, all of them do after, and the corpus runs clean under asan/ubsan.

@stevengj
stevengj merged commit 8a7db0f into JuliaStrings:master Sep 28, 2026
14 checks passed
@stevengj

Copy link
Copy Markdown
Member

Thanks!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants