Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
4 changes: 2 additions & 2 deletions projects/cel-go/Dockerfile
Original file line number Diff line number Diff line change
Expand Up @@ -15,7 +15,7 @@
################################################################################

FROM gcr.io/oss-fuzz-base/base-builder-go
RUN git clone --depth 1 https://github.com/google/cel-go
RUN git clone --depth 1 https://github.com/cel-expr/cel-go

RUN apt-get update && apt-get install -y protobuf-compiler libprotobuf-dev binutils cmake \
ninja-build liblzma-dev libz-dev pkg-config autoconf libtool
Expand All @@ -31,7 +31,7 @@ RUN go install google.golang.org/protobuf/cmd/protoc-gen-go@latest

COPY go-lpm.cc $SRC/

COPY fuzz*.go $SRC/cel-go/cel/
COPY fuzz*.go $SRC/
COPY build.sh $SRC/
COPY *.proto $SRC/
WORKDIR $SRC/cel-go
56 changes: 56 additions & 0 deletions projects/cel-go/README.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,56 @@
# CEL-Go Fuzzing

This directory contains OSS-Fuzz integration and fuzz targets for CEL-Go:

- `fuzz_compile`: Fuzzes expression compilation and program creation.
- `fuzz_eval`: Structure-aware libprotobuf-mutator fuzzer for variable evaluation.
- `fuzz_pratt_parser`: Differential fuzzer comparing ANTLR and Pratt parser outputs.

---

## Requirements & Setup

OSS-Fuzz uses Docker (or Podman) via `infra/helper.py`.

### Using Podman as an Alternative to Docker

If using `podman` instead of `docker`, create a `docker` symlink on your `PATH`:

```bash
mkdir -p /tmp/bin
ln -sf $(which podman) /tmp/bin/docker
export PATH="/tmp/bin:$PATH"
```

---

## Running Fuzzers Locally

To build and run fuzzers against the remote `cel-expr/cel-go` repository:

```bash
# Navigate to oss-fuzz root directory
cd /local/oss-fuzz

# 1. Build the fuzzer container image and compile fuzz binaries
python3 infra/helper.py build_fuzzers cel-go

# 2. Run a fuzzer (e.g. fuzz_pratt_parser for 30 seconds)
python3 infra/helper.py run_fuzzer cel-go fuzz_pratt_parser -- -max_total_time=30
```

---

## Running Fuzzers Against a Local Clone of `cel-expr/cel-go`

To test local changes or feature branches in your working tree without pushing to GitHub, mount your local repository path (e.g. `/local/cel-go`) into the build container via `build_fuzzers`:

```bash
cd /local/oss-fuzz

# 1. Build fuzzers mounting local /local/cel-go
python3 infra/helper.py build_fuzzers cel-go /local/cel-go

# 2. Run the differential fuzzer
python3 infra/helper.py run_fuzzer cel-go fuzz_pratt_parser -- -max_total_time=30
```
11 changes: 7 additions & 4 deletions projects/cel-go/build.sh
Original file line number Diff line number Diff line change
Expand Up @@ -15,7 +15,9 @@
#
################################################################################

mkdir fuzzlpm
cp $SRC/fuzz*.go cel/

mkdir -p fuzzlpm
$SRC/LPM/external.protobuf/bin/protoc --cpp_out=fuzzlpm/ -I$SRC/ $SRC/cel-go-lpm.proto

$CXX $CXXFLAGS -DNDEBUG -c -I fuzzlpm/ -I $SRC/LPM/external.protobuf/include fuzzlpm/cel-go-lpm.pb.cc
Expand All @@ -28,14 +30,15 @@ go build
)

$SRC/LPM/external.protobuf/bin/protoc --go_out=fuzzlpm/ -I$SRC/ $SRC/cel-go-lpm.proto
cp fuzzlpm/github.com/google/cel-go/cel/*.pb.go cel/
cp fuzzlpm/cel.dev/cel-go/cel/*.pb.go cel/

$SRC/go114-fuzz-build/go114-fuzz-build -func FuzzEval -o fuzz_lpm.a github.com/google/cel-go/cel
$SRC/go114-fuzz-build/go114-fuzz-build -func FuzzEval -o fuzz_lpm.a cel.dev/cel-go/cel
$CXX $CXXFLAGS $LIB_FUZZING_ENGINE cel-go-lpm.pb.o go-lpm.o \
fuzz_lpm.a \
$SRC/LPM/src/libfuzzer/libprotobuf-mutator-libfuzzer.a \
$SRC/LPM/src/libprotobuf-mutator.a \
-Wl,--start-group $SRC/LPM/external.protobuf/lib/lib*.a -Wl,--end-group \
-o $OUT/fuzz_lpm

compile_go_fuzzer github.com/google/cel-go/cel FuzzCompile fuzz_compile
compile_go_fuzzer cel.dev/cel-go/cel FuzzCompile fuzz_compile
compile_go_fuzzer cel.dev/cel-go/cel FuzzPrattParser fuzz_pratt_parser
2 changes: 1 addition & 1 deletion projects/cel-go/cel-go-lpm.proto
Original file line number Diff line number Diff line change
Expand Up @@ -17,7 +17,7 @@
syntax = "proto3";
package celgolpm;

option go_package = "github.com/google/cel-go/cel";
option go_package = "cel.dev/cel-go/cel";

message FuzzVariables {
string expr = 1;
Expand Down
16 changes: 15 additions & 1 deletion projects/cel-go/fuzz_eval.go
Original file line number Diff line number Diff line change
@@ -1,9 +1,23 @@
// Copyright 2021 Google LLC
//
// Licensed under the Apache License, Version 2.0 (the "License");
// you may not use this file except in compliance with the License.
// You may obtain a copy of the License at
//
// http://www.apache.org/licenses/LICENSE-2.0
//
// Unless required by applicable law or agreed to in writing, software
// distributed under the License is distributed on an "AS IS" BASIS,
// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
// See the License for the specific language governing permissions and
// limitations under the License.

package cel

import (
"google.golang.org/protobuf/proto"

"github.com/google/cel-go/checker/decls"
"cel.dev/cel-go/checker/decls"
exprpb "google.golang.org/genproto/googleapis/api/expr/v1alpha1"
)

Expand Down
Loading
Loading