release_contents.rs

fuzz/fuzz_targets/release_contents.rs

fuzz · 86 lines · read the source here · or on GitHub

The release contents list parser, coverage-guided.

Roadmap item 97. CONTENTS.sha256 lists every file inside every release archive with its SHA-256, and a verifier reads it to decide which paths on disk to open and what to compare them against. It is covered by the signed SHA256SUMS, and every caller is told to check that before parsing.

"Every caller is told to" is not a property of the code. A caller can get the order wrong, a future front end can be written by somebody who did not read the note, and the consequence would be a file of somebody else's choosing deciding which paths a verifier opens. So the parser is fuzzed as though nothing had checked it, which is the only assumption that stays true.

What this is looking for, specifically: a path that escapes the release directory, a panic on a line that is not what the release job writes, and a digest that is accepted without being one.

WHAT CALLS WHAT

This file defines no functions of its own.