]> git.ipfire.org Git - thirdparty/kea.git/commitdiff
[#4272] Remove the fuzzing from Gitlab CI
authorAndrei Pavel <andrei@isc.org>
Tue, 3 Mar 2026 12:01:25 +0000 (14:01 +0200)
committerAndrei Pavel <andrei@isc.org>
Thu, 6 Aug 2026 07:34:24 +0000 (10:34 +0300)
.clusterfuzzlite/Dockerfile [deleted file]
.clusterfuzzlite/build.sh [deleted file]
.clusterfuzzlite/project.yaml [deleted file]
.clusterfuzzlite/run-locally.sh [deleted file]
.gitlab-ci.yml

diff --git a/.clusterfuzzlite/Dockerfile b/.clusterfuzzlite/Dockerfile
deleted file mode 100644 (file)
index 472bf1f..0000000
+++ /dev/null
@@ -1,6 +0,0 @@
-FROM registry.gitlab.isc.org/isc-projects/kea:fuzz-latest
-
-# Copy repo and link build.sh so that it runs from a location relative to the Kea repo.
-WORKDIR "${SRC}"
-COPY . "${SRC}/kea"
-RUN ln -s "${SRC}/kea/.clusterfuzzlite/build.sh" "${SRC}/build.sh"
diff --git a/.clusterfuzzlite/build.sh b/.clusterfuzzlite/build.sh
deleted file mode 100755 (executable)
index 337748b..0000000
+++ /dev/null
@@ -1,60 +0,0 @@
-#!/bin/bash
-
-# SC2156 (warning): Injecting filenames is fragile and insecure. Use parameters.
-# shellcheck disable=SC2156
-
-set -eu
-
-script_path="$(dirname "$(readlink -f "${0}")")"
-cd "${script_path}/.."
-
-# Use a wrapper function to allow "return 1" instead of "exit 1" which may have
-# unforeseen consequences in case this script is sourced.
-install_kea() {
-  # ccache
-  export CCACHE_DIR=/cache
-  export PATH="/usr/lib/ccache:$PATH"
-  export KEA_BUILD_DIR="${KEA_BUILD_DIR-/builds/isc-projects/kea}"
-
-  cxxflags='-gdwarf-4'
-  export CXX='g++'
-  export CXXFLAGS="${cxxflags}"
-  export LDFLAGS="${cxxflags}"
-  if ! meson setup build --prefix "${OUT}" -D b_lundef=false -D "b_sanitize=${SANITIZER}" -D fuzz=enabled -D tests=enabled; then
-    printf 'meson setup failed. Here is meson-log.txt:\n'
-    cat build/meson-logs/meson-log.txt
-    return 1
-  fi
-  meson compile -C build
-  meson install -C build
-
-  echo "${OUT}/lib" | sudo tee -a /etc/ld.so.conf.d/kea.conf
-  echo "${OUT}/lib/x86_64-linux-gnu" | sudo tee -a /etc/ld.so.conf.d/kea.conf
-  ldconfig
-  sudo ldconfig
-
-  # Copy internal libraries.
-  find "${OUT}/lib/" -name 'libkea-*.so*'
-  find "${OUT}/lib/" -name 'libkea-*.so*' -exec sh -c "cp {} ${KEA_BUILD_DIR}" ';'
-  find "${OUT}/lib/" -name 'libkea-*.so*' -exec sh -c "cp {} ${OUT}" ';'
-  find "${OUT}/lib/" -name 'libkea-*.so*' -exec sh -c "cp {} /lib/x86_64-linux-gnu/" ';'
-
-  # Copy the binaries.
-  for fuzzer in fuzz_config_kea_dhcp4 fuzz_http_endpoint_kea_dhcp4 fuzz_packets_kea_dhcp4 fuzz_unix_socket_kea_dhcp4 \
-                fuzz_config_kea_dhcp6 fuzz_http_endpoint_kea_dhcp6 fuzz_packets_kea_dhcp6 fuzz_unix_socket_kea_dhcp6 \
-      ; do
-    cp "${OUT}/sbin/${fuzzer}" "${OUT}/${fuzzer}"
-
-    # Display some information for debugging.
-    ldd "${OUT}/${fuzzer}"
-    readelf -d "${OUT}/${fuzzer}" | grep -Ei 'R.*PATH' || true
-
-    # Copy all required libraries, although we want to specifically target external libraries.
-    for i in $(ldd "${OUT}/${fuzzer}" | cut -f 2 | cut -d ' ' -f 3); do
-      cp "${i}" "${KEA_BUILD_DIR}"
-      cp "${i}" "${OUT}"
-    done
-  done
-}
-
-install_kea
diff --git a/.clusterfuzzlite/project.yaml b/.clusterfuzzlite/project.yaml
deleted file mode 100644 (file)
index b478801..0000000
+++ /dev/null
@@ -1 +0,0 @@
-language: c++
diff --git a/.clusterfuzzlite/run-locally.sh b/.clusterfuzzlite/run-locally.sh
deleted file mode 100755 (executable)
index b62fc0b..0000000
+++ /dev/null
@@ -1,36 +0,0 @@
-#!/bin/sh
-
-# Change to parent directory, so that the script can be called from anywhere.
-parent_path=$(cd "$(dirname "${0}")" && pwd)
-cd "${parent_path}" || exit 1
-
-mkdir -p build/out
-mkdir -p build/work
-
-cd .. || exit 2
-
-docker build -t kea-fuzzing -f .clusterfuzzlite/Dockerfile .
-
-docker_run() {
-  docker run \
-    --interactive \
-    --privileged \
-    --platform linux/amd64 \
-    --rm \
-    --shm-size=2g \
-    -e ARCHITECTURE=x86_64 \
-    -e CIFUZZ=true \
-    -e FUZZING_ARGS='-rss_limit_mb=8192' \
-    -e FUZZING_ENGINE=libfuzzer \
-    -e FUZZING_LANGUAGE=c++ \
-    -e KEA_BUILD_DIR=/src \
-    -e SANITIZER=address \
-    -v "${parent_path}/build/out:/out" \
-    -v "${parent_path}/build/work:/work" \
-    kea-fuzzing \
-    "${@}"
-}
-
-docker_run
-
-docker_run compile
index 4e7e13ed2227540d38530465be9e4c1b59fb392a..dc6488615094424654c17c9722f349b9aaf85045 100644 (file)
@@ -4,18 +4,6 @@ variables:
 
   CI_REGISTRY_IMAGE: registry.gitlab.isc.org/isc-projects/kea
 
-  # Fuzzing
-  CFL_ARTIFACTS_DIR: '/tmp/cfl-artifacts'
-  CFL_CACHE_DIR: '/ccache/cfl-cache'
-  CFL_IMAGE: 'gcr.io/oss-fuzz-base/clusterfuzzlite-run-fuzzers'
-  CFL_PLATFORM: gitlab
-  FUZZ_SECONDS: 600  # 10 min (ClusterFuzzLite defaults)
-  FUZZING_ARGS: '-rss_limit_mb=8192'
-  LD_LIBRARY_PATH: "/opt/kea/lib:/usr/lib/x86_64-linux-gnu:/lib/x86_64-linux-gnu:/builds/isc-projects/kea"
-  PARALLEL_FUZZING: true
-  CCACHE_BASEDIR: "${CI_PROJECT_DIR}"
-  CCACHE_DIR: "${CI_PROJECT_DIR}/ccache"
-
   # SAST
   SECURE_ANALYZERS_PREFIX: "registry.gitlab.com/gitlab-org/security-products/analyzers"
   # Leave only bandit, flawfinder, semgrep.
@@ -31,7 +19,6 @@ default:
 
 stages:
   - test
-  - fuzz
 
 .base_rules_for_test_jobs: &rules_for_test_stage
   rules:
@@ -157,144 +144,6 @@ pylint:
     - pylint --jobs "$(nproc || gnproc || echo 1)" --rcfile ./.gitlab/ci/pylint.rc --enable all ${PYTHON_SCRIPTS} || true
 
 
-############################## Fuzzing ##############################
-
-# Fuzz code changes. Fuzzes all merge requests.
-fuzz:
-  image:
-    name: "${CFL_IMAGE}"
-    entrypoint: ['']
-  stage: fuzz
-  tags:
-    - docker-fuzz
-  needs: []
-  parallel:
-    matrix:
-      - SANITIZER: [address, undefined]
-  variables:
-    MODE: "code-change"
-  rules:
-    # Prevent duplicate pipelines.
-    - if: $CI_OPEN_MERGE_REQUESTS && $CI_COMMIT_BRANCH == null
-      when: never
-    # Not used anymore. Change "when" to "manual" to make it appear in MRs again.
-    - when: never
-      allow_failure: true
-  before_script:
-    # Get GitLab's container id.
-    - export CFL_CONTAINER_ID=`docker ps -q -f "label=com.gitlab.gitlab-runner.job.id=$CI_JOB_ID" -f "label=com.gitlab.gitlab-runner.type=build"`
-  script:
-    # local cfl-cache to mounted volume
-    - if ! test -L cfl-cache; then ln -s /cfl-cache cfl-cache; fi
-    # Will build and run the fuzzers.
-    - python3 "/opt/oss-fuzz/infra/cifuzz/cifuzz_combined_entrypoint.py"
-  artifacts:
-    # Upload artifacts when a crash makes the job fail.
-    when: always
-    expire_in: 30 days
-    paths:
-      - "${CFL_ARTIFACTS_DIR}"
-
-# Batch fuzzing enables continuous, regular fuzzing on your latest HEAD
-# and allows a corpus of inputs to build up over time, which greatly improves
-# the effectiveness of fuzzing. Batch fuzzing should be run on a schedule.
-fuzz-batch:
-  image:
-    name: "${CFL_IMAGE}"
-    entrypoint: ['']
-  stage: fuzz
-  needs: []
-  tags:
-    - docker-fuzz
-  variables:
-    FUZZ_SECONDS: 86400 # 24 hours
-  rules:
-    - if: $MODE == "batch"
-  before_script:
-    - export CFL_CONTAINER_ID=`docker ps -q -f "label=com.gitlab.gitlab-runner.job.id=$CI_JOB_ID" -f "label=com.gitlab.gitlab-runner.type=build"`
-  script:
-    - python3 "/opt/oss-fuzz/infra/cifuzz/cifuzz_combined_entrypoint.py"
-  artifacts:
-    when: always
-    expire_in: 30 days
-    paths:
-      - "${CFL_ARTIFACTS_DIR}"
-
-# Corpus pruning is a helper function that minimizes the corpuses by
-# removing corpus files (testcases) that do not increase the fuzzer’s
-# code coverage.
-fuzz-prune:
-  image:
-    name: "${CFL_IMAGE}"
-    entrypoint: ['']
-  stage: fuzz
-  needs: []
-  tags:
-    - docker-fuzz
-  rules:
-    - if: $MODE == "prune"
-  before_script:
-    - export CFL_CONTAINER_ID=`docker ps -q -f "label=com.gitlab.gitlab-runner.job.id=$CI_JOB_ID" -f "label=com.gitlab.gitlab-runner.type=build"`
-  script:
-    - python3 "/opt/oss-fuzz/infra/cifuzz/cifuzz_combined_entrypoint.py"
-  artifacts:
-    when: always
-    expire_in: 30 days
-    paths:
-      - "${CFL_ARTIFACTS_DIR}"
-
-# Continuous builds are used when a crash is found during MR fuzzing to determine
-# whether the crash was newly introduced. If the crash was not newly introduced,
-# MR fuzzing will not report it. This means that there will be fewer unrelated
-# failures when running code change fuzzing.
-fuzz-build:
-  image:
-    name: "${CFL_IMAGE}"
-    entrypoint: ['']
-  stage: fuzz
-  needs: []
-  tags:
-    - docker-fuzz
-  rules:
-    - when: never
-  before_script:
-    - export CFL_CONTAINER_ID=`docker ps -q -f "label=com.gitlab.gitlab-runner.job.id=$CI_JOB_ID" -f "label=com.gitlab.gitlab-runner.type=build"`
-  script:
-    - python3 "/opt/oss-fuzz/infra/cifuzz/cifuzz_combined_entrypoint.py"
-  artifacts:
-    when: always
-    expire_in: 30 days
-    paths:
-      - "${CFL_ARTIFACTS_DIR}"
-
-# scheduled job - generates periodic coverage reports
-fuzz-coverage:
-  image:
-    name: "${CFL_IMAGE}"
-    entrypoint: ['']
-  stage: fuzz
-  needs: []
-  tags:
-    - docker-fuzz
-  variables:
-    SANITIZER: "coverage"
-  rules:
-    - if: $MODE == "coverage"
-  before_script:
-    - export CFL_CONTAINER_ID=`cut -c9- < /proc/1/cpuset`
-  script:
-    - python3 "/opt/oss-fuzz/infra/cifuzz/cifuzz_combined_entrypoint.py"
-  after_script:
-    - shasum /opt/kea/sbin/*
-    - shasum /tmp/not-out/*/*
-    - shasum ${OUT}/*/*
-  artifacts:
-    when: always
-    expire_in: 30 days
-    paths:
-      - "${CFL_ARTIFACTS_DIR}"
-
-
 ############################### SAST ################################
 # Read more about this feature here: https://docs.gitlab.com/ee/user/application_security/sast/
 #