fuzz: Cover block filter P2P messages #36337

pull maflcko wants to merge 1 commits into bitcoin:master from maflcko:2609-fuzz-block-filter-p2p changing 4 files +27 −6
  1. maflcko commented at 5:34 PM on September 25, 2026: member

    The BIP157 P2P messages are not covered by any fuzz targets at all.

    Fix this to cover them via the P2P targets.

    Should be possible to test by verifying the integer sanitizer is triggered (https://github.com/bitcoin/bitcoin/pull/36321#issuecomment-5810977529):

    $ echo 'FwAAAAEAAABcX2dldGNmY2hlY2twdAAftOvdD0sFqXEx6US5VIknlsOJqZ5goMwtmwZBPdCxQVxf
    AfkGKP39/f0v/Q/9E1AP/f2ybAT1Af39A/399wEAuXEAAAAAAAAAAAB1z3QAbgAAQAHm/f39/f39
    /f39/S8/D/0B/f3IAAcBBWNmaf8DAAAA' | base64 --decode > /tmp/msg.bin
    
    $ UBSAN_OPTIONS="suppressions=$(pwd)/test/sanitizer_suppressions/ubsan:print_stacktrace=0:halt_on_error=0:report_error_type=1" FUZZ=process_messages ./bld-cmake/bin/fuzz /tmp/msg.bin 
    
    ./bld-cmake/bin/fuzz: Running 1 inputs 1 time(s) each.
    /src/net_processing.cpp:3662:33: runtime error: unsigned integer overflow: 0 - 1 cannot be represented in type 'size_type' (aka 'unsigned long')
    /src/net_processing.cpp:3662:18: runtime error: implicit conversion from type 'size_type' (aka 'unsigned long') of value 18446744073709551615 (64-bit, unsigned) to type 'int' changed the value to -1 (32-bit, signed)
    
  2. fuzz: Cover block filter P2P messages fa488f53c3
  3. DrahtBot added the label Fuzzing on Sep 25, 2026
  4. DrahtBot commented at 5:34 PM on September 25, 2026: contributor

    <!--e57a25ab6845829454e8d69fc972939a-->

    The following sections might be updated with supplementary metadata relevant to reviewers and maintainers.

    <!--006a51241073e994b41acfe9ec718e94-->

    Code Coverage & Benchmarks

    For details see: https://corecheck.dev/bitcoin/bitcoin/pulls/36337.

    <!--021abf342d371248e50ceaed478a90ca-->

    Reviews

    See the guideline and AI policy for information on the review process. A summary of reviews will appear here.

    <!--5faf32d7da4f0f540f40219e4f7537a3-->

  5. DrahtBot added the label CI failed on Sep 25, 2026
  6. DrahtBot commented at 6:34 PM on September 25, 2026: contributor

    <!--85328a0da195eb286784d51f73fa0af9-->

    🚧 At least one of the CI tasks failed. <sub>Task MSan, fuzz: https://github.com/bitcoin/bitcoin/actions/runs/36168019330/job/108180422242</sub> <sub>LLM reason (✨ experimental): MemorySanitizer (fuzz test) reported a use of an uninitialized value in BaseIndex::Stop() (base.cpp:479), causing exit code 1 and the CI failure.</sub>

    <details><summary>Hints</summary>

    Try to run the tests locally, according to the documentation. However, a CI failure may still happen due to a number of reasons, for example:

    • Possibly due to a silent merge conflict (the changes in this pull request being incompatible with the current code in the target branch). If so, make sure to rebase on the latest commit of the target branch.

    • A sanitizer issue, which can only be found by compiling with the sanitizer and running the affected test.

    • An intermittent issue.

    Leave a comment here, if you need help tracking down a confusing failure.

    </details>

  7. Crypt-iQ commented at 3:37 PM on September 26, 2026: contributor

    I think CI failures are because in process_message(s) the static testing_setup is destructed before static g_filter_indexes so BaseIndex::Stop will try to access testing_setup.m_node.

  8. in src/test/util/validation.cpp:150 in fa488f53c3
     145 | +        Assert(index.Init());
     146 | +        index.Sync();
     147 | +        // The index serves the static setup chain only. Leaving it registered
     148 | +        // deadlocks with ImmediateBackgroundTaskRunner when a fuzzed block
     149 | +        // connects under cs_main.
     150 | +        index.Stop();
    


    Crypt-iQ commented at 4:28 PM on September 26, 2026:

    Can you explain why it deadlocks? I couldn't figure this bit out


github-metadata-mirror

This is a metadata mirror of the GitHub repository bitcoin/bitcoin. This site is not affiliated with GitHub. Content is generated from a GitHub metadata backup.
generated: 2026-09-28 10:51 UTC

This site is hosted by @0xB10C
More mirrored repositories can be found on mirror.b10c.me