Skip to content

Conversation

@maflcko
Copy link
Member

@maflcko maflcko commented Jul 15, 2021

Without a size limit on the input data, the runtime is unbounded. Fix this by picking an upper bound on the maximum number of fuzz operations.

Reproducer from OSS-Fuzz (without bug report):
clusterfuzz-testcase-tx_pool_standard-5963992253202432.log

@DrahtBot
Copy link
Contributor

DrahtBot commented Jul 21, 2021

The following sections might be updated with supplementary metadata relevant to reviewers and maintainers.

Conflicts

No conflicts as of last run.

@practicalswift
Copy link
Contributor

cr ACK fa33ed4

@maflcko maflcko merged commit 1488f55 into bitcoin:master Jul 25, 2021
@maflcko maflcko deleted the 2107-fuzzPool branch July 25, 2021 10:43
sidhujag pushed a commit to syscoin/syscoin that referenced this pull request Jul 28, 2021
fa33ed4 fuzz: Limit max ops in tx_pool fuzz targets (MarcoFalke)

Pull request description:

  Without a size limit on the input data, the runtime is unbounded. Fix this by picking an upper bound on the maximum number of fuzz operations.

  Reproducer from OSS-Fuzz (without bug report):
  [clusterfuzz-testcase-tx_pool_standard-5963992253202432.log](https://github.com/bitcoin/bitcoin/files/6822465/clusterfuzz-testcase-tx_pool_standard-5963992253202432.log)

ACKs for top commit:
  practicalswift:
    cr ACK fa33ed4

Tree-SHA512: 32098d573880afba12d510ac83519dc886a6c65d5207edb810f92c7c61edf5e2fc9c57e7b7a1ae656c02ce14e3595707dd6b93caf7956beb2bc817609e14d23d
@bitcoin bitcoin locked as resolved and limited conversation to collaborators Aug 18, 2022
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants