Skip to content

GH-51649: [C++][Parquet] Tell encoding fuzzer to skip inputs with invalid parameters - #51650

Open
pitrou wants to merge 3 commits into
apache:mainfrom
pitrou:fuzz-status
Open

pitrou wants to merge 3 commits into
apache:mainfrom
pitrou:fuzz-status

Conversation

@pitrou

@pitrou pitrou commented Sep 30, 2026 •

Copy link
Copy Markdown
Member

Rationale for this change

LLVMFuzzerTestOneInput allows two return values: 0 and -1. While 0 allows for the input to be (potentially) saved in the corpus, -1 tells the fuzzer not to save it.

In the words of the fine documentation:

It may be desirable to reject some inputs, i.e. to not add them to the corpus.
For example, when fuzzing an API consisting of parsing and other logic, one may want
to allow only those inputs into the corpus that parse successfully.
If the fuzz target returns -1 on a given input, libFuzzer will not add that
input to the corpus, regardless of what coverage it triggers.

What changes are included in this PR?

  1. Add a FuzzStatus type that allows telling the fuzzing engine whether an input should be skipped (i.e. not saved in the corpus).
  2. Skip inputs where the parameter header contains invalid values in the Parquet encoding fuzzer

Are these changes tested?

Manually, by running the fuzzer from the command line and watching logs with ARROW_FUZZING_VERBOSITY enabled.

Without a seed corpus and trying to generate 100k inputs (./build/out/arrow/parquet-encoding-fuzz -seed=42 -runs=100000), I get:

  • before:
#100000 DONE   cov: 1377 ft: 2265 corp: 46/3357b lim: 778 exec/s: 7142 rss: 201Mb
Done 100000 runs in 14 second(s)
  • after:
#100000 DONE   cov: 2051 ft: 3723 corp: 41/5725b lim: 832 exec/s: 50000 rss: 259Mb
Done 100000 runs in 2 second(s)

It seems that this PR allows the fuzzer to proceed much faster when mutation generates such inputs. Despite running faster, it also reaches more coverage (see doc about the cov: and ft: values).

(caveat: these measurements is with a fixed random seed, and without a seed corpus)

(of course, ideally the fuzzer would not produce such inputs at all, but ensuring that is more involved)

Are there any user-facing changes?

No.

Was AI used for this PR?

In accordance to the AI generation guidelines, please disclose below whether and how AI was used in this PR.

PR code and description written by:

  • Human
  • AI

Reviewed before submission by:

  • Human
  • AI
  • Not reviewed

…th invalid parameters

`LLVMFuzzerTestOneInput` allows two return values: 0 and -1.
While 0 allows for the input to be (potentially) saved in the corpus, -1 tells the fuzzer not to save it.

In the words of the [fine documentation](https://llvm.org/docs/LibFuzzer.html#rejecting-unwanted-inputs):

> It may be desirable to reject some inputs, i.e. to not add them to the corpus.
> For example, when fuzzing an API consisting of parsing and other logic, one may want
> to allow only those inputs into the corpus that parse successfully.
> If the fuzz target returns -1 on a given input, libFuzzer will not add that
> input to the corpus, regardless of what coverage it triggers.
@pitrou

pitrou commented Sep 30, 2026

Copy link
Copy Markdown
Member Author

@github-actions crossbow submit -g cpp

@pitrou
pitrou marked this pull request as ready for review September 30, 2026 08:58
@pitrou
pitrou requested a review from adamreeve September 30, 2026 08:58
@github-actions

Copy link
Copy Markdown

Revision: 389b79d

Submitted crossbow builds: ursacomputing/crossbow @ actions-199c3ed102

Task Status
example-cpp-minimal-build-static GitHub Actions
example-cpp-minimal-build-static-system-dependency GitHub Actions
example-cpp-tutorial GitHub Actions
test-build-cpp-fuzz GitHub Actions
test-conda-cpp GitHub Actions
test-conda-cpp-valgrind GitHub Actions
test-debian-13-cpp-amd64 GitHub Actions
test-debian-13-cpp-i386 GitHub Actions
test-debian-experimental-cpp-gcc-15 GitHub Actions
test-fedora-42-cpp GitHub Actions
test-ubuntu-22.04-cpp GitHub Actions
test-ubuntu-22.04-cpp-bundled GitHub Actions
test-ubuntu-22.04-cpp-emscripten GitHub Actions
test-ubuntu-22.04-cpp-no-threading GitHub Actions
test-ubuntu-24.04-cpp GitHub Actions
test-ubuntu-24.04-cpp-gcc-13-bundled GitHub Actions
test-ubuntu-24.04-cpp-gcc-14 GitHub Actions
test-ubuntu-24.04-cpp-minimal-with-formats GitHub Actions
test-ubuntu-24.04-cpp-thread-sanitizer GitHub Actions

@pitrou

pitrou commented Sep 30, 2026

Copy link
Copy Markdown
Member Author

CI failures are unrelated.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant