Skip to content

fix: throw FormatException on malformed commit/tree output and add fuzz workflow - #110

Merged
kevmoo merged 1 commit into
mainfrom
fix-parser-exceptions-and-fuzz
Oct 7, 2026
Merged

kevmoo merged 1 commit into
mainfrom
fix-parser-exceptions-and-fuzz

Conversation

@kevmoo

@kevmoo kevmoo commented Oct 6, 2026

Copy link
Copy Markdown
Owner

Rationale

Coverage-guided fuzzing of package:git uncovered 4 cases where TreeEntry.fromLsTree, Commit.parse, and Commit.parseRawRevList threw StateError, null-check TypeError, ArgumentError, or AssertionError instead of FormatException when given malformed git ls-tree or git rev-list --header output.

Summary of Changes

  • Replace _lsTreeRegEx.allMatches(value).single in TreeEntry.fromLsTree (lib/src/tree_entry.dart) with _lsTreeRegEx.firstMatch(value) and throw FormatException when no match is found.
  • Validate required single headers (tree, author, committer, and commit in rev-list mode), SHA-1 header format, and trailing commit message newline in Commit._parse (lib/src/commit.dart) via scanner.error (FormatException) instead of throwing null-check TypeError, StateError, ArgumentError, or AssertionError.
  • Pass --no-sign when creating a lightweight tag in test/tag_test.dart so global tag.gpgSign=true configurations do not prompt for an annotated tag message.
  • Add unit test regressions in test/parse_test.dart, a coverage-guided fuzz target in test/fuzz/git_parser_fuzz.dart, and .github/workflows/fuzz.yaml (instrument-packages: string_scanner,source_span).

Verification

  • Executed dart test (100% pass).
  • Executed 5s CGF fuzz run with --instrument-packages=string_scanner,source_span (149,978 executions, ~25,000 exec/s, 0 crashes, 71.0% AST coverage on commit.dart and 60.0% on tree_entry.dart).
  • Executed kscripts pr-check with 0 issues.

…zz workflow

- Throw `FormatException` in `TreeEntry.fromLsTree` when a line does not match `_lsTreeRegEx` instead of `StateError` from `.single`.
- Validate required single headers (`tree`, `author`, `committer`, and `commit` in rev-list mode) and trailing newline in `Commit._parse` via `scanner.error` (`FormatException`) instead of throwing null-check `TypeError`, `StateError`, or `AssertionError`.
- Pass `--no-sign` in `test/tag_test.dart` lightweight tag test so global `tag.gpgSign=true` does not force an annotated tag editor prompt.
- Add unit test regressions in `test/parse_test.dart`, fuzz harness in `test/fuzz/git_parser_fuzz.dart`, and `.github/workflows/fuzz.yaml`.
@github-actions

github-actions Bot commented Oct 6, 2026

Copy link
Copy Markdown

📊 Cognitive Complexity Analysis

Net Delta: +8 | Added: 1 | Increased: 2 | Improved: 0 | Removed: 0 | Violations: 0

Status Declaration Location Delta Score
🟡 Commit._parse lib/src/commit.dart:L57-121 +2 11 -> 13
🔵 Commit._singleHeader lib/src/commit.dart:L123-141 +5 new -> 5
🟡 TreeEntry.fromLsTree lib/src/tree_entry.dart:L35-42 +1 0 -> 1

@kevmoo
kevmoo merged commit 0248dab into main Oct 7, 2026
15 of 16 checks passed
@kevmoo
kevmoo deleted the fix-parser-exceptions-and-fuzz branch October 7, 2026 00:25
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant