mirror of
https://github.com/rustfs/rustfs.git
synced 2026-07-26 08:18:18 +00:00
0a00d8d500
* refactor(server): split internode dispatch scaffold
* test(server): cover internode dispatch prefix split
* refactor(server): name internode stack boundaries
* perf(server): skip internode request logging layer
* perf(server): skip internode trace layer
* perf(server): use lite internode request context
* feat(metrics): track internode rpc duration
* feat(ecstore): add put object stage summary logs
* test(metrics): update internode descriptor expectations
* fix(server): tighten internode path matching
* fix(pr): address review follow-up comments
* style(ecstore): simplify commit tail duration field
* refactor(ecstore): group put stage summary fields
* refactor(ecstore): inline put stage summary log
* fix(s3): return storage class for object attributes
* merge: sync latest main and resolve object attributes conflict
* fmt
* fix(server): remove duplicate rpc imports
* build(deps): bump memmap2 for RUSTSEC-2026-0186
* fix(s3select): align object_store with datafusion
* chore(deps): prune workspace dependencies
* perf(fuzz): optimize CI runtime with build/run split and matrix parallelization
Separate fuzz harness compilation from execution to eliminate redundant
builds across targets. Introduce matrix-based parallel execution for
PR smoke and nightly fuzz jobs.
Changes:
- Split CI workflow into `fuzz-build` (compile once) and matrix run jobs
(`pr-fuzz-smoke`, `nightly-fuzz-corpus`) that execute targets in parallel
- Add `BUILD_ONLY` mode to run_ci_targets.sh / run_nightly_targets.sh
- Add run_single_target.sh for matrix jobs (no build phase)
- Optimize `local_metadata` fuzz target: reduce prefix iterations from
8-10 (4 functions each) to 5 critical prefixes (parser-only), cutting
per-iteration cost by ~3-5x
- Move archive path validation (`validate_extract_relative_path`,
`normalize_extract_entry_key`) from `rustfs` to `rustfs-utils::path`,
eliminating `rustfs` binary crate dependency from fuzz harness
- Remove `rustfs` from fuzz/Cargo.toml (drops significant transitive deps)
- Add unit tests for archive path validation in rustfs-utils
- Update fuzz/README.md with new workflow and script documentation
Expected CI improvement: PR smoke wall-clock from ~120min (frequent
timeout) to ~40min; nightly from ~180min to ~60min.
* refactor(fuzz): consolidate scripts and fix prefix test alignment
Replace three duplicated shell scripts (run_ci_targets.sh,
run_nightly_targets.sh, run_single_target.sh) with a single
parameterized run.sh that supports BUILD_ONLY, SKIP_BUILD, and
MAX_TOTAL_TIME environment variables.
Fix local_metadata fuzz target prefix testing: replace always-true
'len > 0' guard with lengths aligned to xl.meta binary layout
(4/5/8/12 bytes for magic+version+header fields). Remove redundant
empty-slice test.
Hoist RUSTFLAGS to workflow top-level env to eliminate per-job
duplication. Update README with unified script documentation.
Net: -118 lines, zero functionality loss.
* perf(fuzz): optimize CI runtime with build/run split and matrix parallelization
Restructure fuzz CI workflow to eliminate redundant compilation and
run targets in parallel via matrix strategy.
Workflow changes:
- Split into fuzz-build (compile once) and matrix run jobs
- PR smoke: 3 targets parallel, 60s each, timeout 30min (was 120min)
- Nightly: 3 targets parallel, 300s each, timeout 60min (was 180min)
- Pass compiled harness via actions/artifact between jobs
- Hoist RUSTFLAGS to workflow top-level env
Script consolidation:
- Replace 3 duplicated scripts with single parameterized run.sh
- Supports BUILD_ONLY, SKIP_BUILD, MAX_TOTAL_TIME env vars
Target optimizations:
- Remove rustfs binary crate from fuzz dependencies (was pulling
979 transitive deps); move archive path validation to rustfs-utils
- Optimize local_metadata: reduce prefix iterations from 8-10x4
calls to 5 prefixes with parser-only (no decompress), aligned
with xl.meta binary layout (4/5/8/12 bytes)
- Add unit tests for archive path validation in rustfs-utils
- Update fuzz/README.md with unified script documentation
Expected: PR smoke wall-clock from ~120min (frequent timeout)
to ~40min; nightly from ~180min to ~60min.
* fix(rpc): resolve internode metrics via app context
* fmt
* ci: speed up fuzz smoke artifact restore
---------
Signed-off-by: houseme <housemecn@gmail.com>
93 lines
3.0 KiB
Rust
93 lines
3.0 KiB
Rust
#![no_main]
|
|
|
|
use libfuzzer_sys::fuzz_target;
|
|
use rustfs_utils::path::{normalize_extract_entry_key, validate_extract_relative_path};
|
|
|
|
fn parse_case(data: &[u8]) -> (String, Option<String>, bool, Vec<String>) {
|
|
let text = String::from_utf8_lossy(data);
|
|
let mut parts = text.splitn(4, '\n');
|
|
let path = parts.next().unwrap_or_default().to_string();
|
|
let prefix = parts
|
|
.next()
|
|
.map(str::trim)
|
|
.filter(|value| !value.is_empty())
|
|
.map(ToOwned::to_owned);
|
|
let is_dir = parts.next().unwrap_or_default().trim().eq_ignore_ascii_case("dir");
|
|
let flags = parts
|
|
.next()
|
|
.unwrap_or_default()
|
|
.split(',')
|
|
.map(str::trim)
|
|
.filter(|flag| !flag.is_empty())
|
|
.map(ToOwned::to_owned)
|
|
.collect();
|
|
|
|
(path, prefix, is_dir, flags)
|
|
}
|
|
|
|
fn apply_flag(mut path: String, mut prefix: Option<String>, flag: &str) -> (String, Option<String>) {
|
|
match flag {
|
|
"path_parent" => path.push_str("/../escape.txt"),
|
|
"path_current" => path.push_str("/./child"),
|
|
"path_backslash_parent" => path.push_str("\\..\\escape.txt"),
|
|
"path_leading_slash" => path = format!("/{path}"),
|
|
"path_empty" => path.clear(),
|
|
"path_long" => path = format!("{path}/{}", "segment".repeat(256)),
|
|
"prefix_parent" => prefix = Some("../victim-bucket".to_string()),
|
|
"prefix_trimmed" => prefix = prefix.map(|value| format!(" /{value}/ ")),
|
|
"prefix_empty" => prefix = Some(String::new()),
|
|
_ => {}
|
|
}
|
|
|
|
(path, prefix)
|
|
}
|
|
|
|
fn materialize_case(path: String, prefix: Option<String>, flags: &[String]) -> (String, Option<String>) {
|
|
flags
|
|
.iter()
|
|
.fold((path, prefix), |(path, prefix), flag| apply_flag(path, prefix, flag))
|
|
}
|
|
|
|
fn has_dot_segments(path: &str) -> bool {
|
|
path.split(['/', '\\']).any(|segment| {
|
|
let trimmed = segment.trim();
|
|
trimmed == "." || trimmed == ".."
|
|
})
|
|
}
|
|
|
|
fuzz_target!(|data: &[u8]| {
|
|
let (path, prefix, is_dir, flags) = parse_case(data);
|
|
let (path, prefix) = materialize_case(path, prefix, &flags);
|
|
|
|
let _ = validate_extract_relative_path(&path);
|
|
if let Some(prefix) = prefix.as_deref() {
|
|
let _ = validate_extract_relative_path(prefix);
|
|
}
|
|
|
|
if let Ok(key) = normalize_extract_entry_key(&path, prefix.as_deref(), is_dir) {
|
|
assert!(
|
|
!has_dot_segments(&key),
|
|
"accepted archive entry retained dot segments: path={:?} prefix={:?} key={:?}",
|
|
path,
|
|
prefix,
|
|
key
|
|
);
|
|
assert!(
|
|
!key.starts_with('/'),
|
|
"accepted archive entry escaped bucket namespace: path={:?} prefix={:?} key={:?}",
|
|
path,
|
|
prefix,
|
|
key
|
|
);
|
|
if is_dir {
|
|
assert!(
|
|
key.ends_with('/'),
|
|
"accepted archive directory lost trailing slash: path={:?} prefix={:?} key={:?}",
|
|
path,
|
|
prefix,
|
|
key
|
|
);
|
|
}
|
|
}
|
|
});
|