# Fuzz smoke, Go. A nightly time-boxed run of the fuzz targets, and a hand # dispatch when a change asks for it. # # Fuzzing is exploration, so it never belongs to the push pipeline; a 30 second # smoke per target, run nightly, is the compromise that catches a new crash # within a day without holding the shared box. The targets run the seeds and # whatever the corpus has gathered; a failure leaves its crashing input in # testdata/fuzz, which the ordinary suite then reproduces on every push. # # Every step is one command, so the step that fails is the gate that failed. name: Fuzz on: workflow_dispatch: schedule: # Nightly at 03:30 UTC, after the race sweep has had the box first. - cron: "30 3 * * *" env: # One core: parallelism buys no speed here and costs memory the box does not have. GOFLAGS: -p=1 GOMAXPROCS: "2" jobs: fuzz: runs-on: fedora timeout-minutes: 10 steps: - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7 - uses: actions/setup-go@924ae3a1cded613372ab5595356fb5720e22ba16 # v6 with: go-version-file: go.mod cache: true - name: Fuzz the parser run: go test -run '^$' -fuzz FuzzParse -fuzztime=30s -timeout 10m . - name: Fuzz the encoder run: go test -run '^$' -fuzz FuzzMarshal -fuzztime=30s -timeout 10m .