bytecodealliance / bytecodealliance/wit-bindgen
Test Suggestion: Add Fuzzing Tests
- Lingua principale
- Rust
- Stelle
- 1.5k
- Fork
- 286
- Merge medio
- 6h 32m
- PR unite (30g)
- 19
Descrizione
Fuzz testing is testing mechanism that involves providing pseudo-random data as input into the generators to find correctness issues. There are multiple Bytecode Alliance projects that heavily leverage fuzz testing to improve code quality and find security and correctness issues (e.g. `wasmtime` and `wasm-tools`). So far, there is no fuzz testing existing in this repo. Part of the reasons applying fuzz testing against `wit-bindgen` repo is to raise the bar for generator code quality across multiple languages.
The goal of this issue is to suggest a fuzz framework adding to this repo. It could be as simply as feeding generated valid WIT packages to each `wit-bindgen` generator and check if the generated code are buildable. As the `wit-bindgen-go` maintainer, I hope there is a continuous fuzzing running in the background and invokes `TinyGo` compiler to compile generated WIT bindings. It could go as difficult as making sure the generated code is "correct" - the compiled Wasm modules / components are correct to our expectations.
To get started, I propose to use [`wit-smith`](https://github.com/bytecodealliance/wasm-tools/tree/main/crates/wit-smith) and [`libfuzzer-sys`](https://github.com/rust-fuzz/libfuzzer) crate and `cargo-fuzz` tool for fuzz testing.
Guida per i contributori
Nessuna guida per i contributori indicizzata per questo repository
Direzione di ricerca
Inizia esaminando l’approccio proposto con wit-smith, libfuzzer-sys e cargo-fuzz, quindi analizza come questo repository esegue ogni generatore wit-bindgen e i relativi controlli di build esistenti. Definisci un ambito iniziale mirato, ad esempio generare pacchetti WIT validi e compilare i bindings generati con TinyGo; il completamento dovrebbe includere un target di fuzzing ripetibile e un’esecuzione continua.
Scritto dal modello di indicizzazione a partire dal testo della issue.
Valutazione
- Stack tecnologico
- go, rust
- Ambito
- compilers, testing-qa
- Tipo di issue
- Funzionalità
- Difficoltà
- 5/5
- Tempo stimato
- Più di una settimana
- Stato di attività
- Ferma
- Chiarezza
- Da chiarire
- Idoneità per principianti
- 25/100