Skip to content

Navigation Menu

Sign in
Appearance settings

Search code, repositories, users, issues, pull requests...

Provide feedback

We read every piece of feedback, and take your input very seriously.

Saved searches

Use saved searches to filter your results more quickly

Appearance settings

Correctly implement fuzzers for new encryption streams - #131306

#131306
Open
alinpahontu2912 wants to merge 3 commits into
dotnet:maindotnet/runtime:mainfrom
alinpahontu2912:zipstream_fuzzersalinpahontu2912/runtime:zipstream_fuzzersCopy head branch name to clipboard
Open

Correctly implement fuzzers for new encryption streams#131306
alinpahontu2912 wants to merge 3 commits into
dotnet:maindotnet/runtime:mainfrom
alinpahontu2912:zipstream_fuzzersalinpahontu2912/runtime:zipstream_fuzzersCopy head branch name to clipboard

Conversation

@alinpahontu2912

@alinpahontu2912 alinpahontu2912 commented Jul 24, 2026

Copy link
Copy Markdown
Member

Correctly implement fuzzers fro the new encryption streams: zipcryptostream and winzipaesstream

@dotnet-policy-service

Copy link
Copy Markdown
Contributor

Tagging subscribers to this area: @dotnet/area-meta
See info in area-owners.md if you want to be subscribed.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR updates the fuzzers for the new ZIP encryption streams to exercise the actual ZipArchive encryption/decryption paths (ZipCrypto and WinZip AES) rather than constructing the internal crypto streams via reflection.

Changes:

  • Replace reflection-based stream construction with ZipArchive.CreateEntry(..., password, ZipEncryptionMethod) + Open/OpenAsync(password) round-trip workflows.
  • Add validation that the entry is encrypted and the expected encryption method is recorded, and verify plaintext round-trips correctly (sync + async).
  • Add a “wrong password” scenario intended to ensure failures are handled as InvalidDataException (but it currently doesn’t assert failure if no exception is thrown).

Reviewed changes

Copilot reviewed 2 out of 2 changed files in this pull request and generated 2 comments.

File Description
src/libraries/Fuzzing/DotnetFuzzing/Fuzzers/ZipCryptoStreamFuzzer.cs Moves from reflected ZipCryptoStream.Create to ZipArchive-based encrypt/decrypt round-trip for ZipCrypto (sync + async).
src/libraries/Fuzzing/DotnetFuzzing/Fuzzers/WinZipAesStreamFuzzer.cs Moves from reflected WinZipAesStream.Create to ZipArchive-based encrypt/decrypt round-trip for AES128/192/256 (sync + async).
Comments suppressed due to low confidence (2)

src/libraries/Fuzzing/DotnetFuzzing/Fuzzers/ZipCryptoStreamFuzzer.cs:101

  • The “wrong password must fail” check currently passes even if decryption succeeds without throwing. Use Assert.Throws so the fuzzer reliably flags regressions where a wrong password is accepted.
        // Decrypting with a wrong password must fail cleanly with InvalidDataException, never crash.
        try
        {
            using Stream stream = readEntry.Open("wrong-password".AsSpan());
            stream.CopyTo(Stream.Null);
        }
        catch (InvalidDataException)
        {
            // Expected: the header password verifier rejects the wrong key.
        }

src/libraries/Fuzzing/DotnetFuzzing/Fuzzers/WinZipAesStreamFuzzer.cs:113

  • The “wrong password must fail” check currently passes even if decryption succeeds without throwing. Use Assert.Throws so the fuzzer reliably flags regressions where a wrong password is accepted.
        // Decrypting with a wrong password must fail cleanly with InvalidDataException, never crash.
        try
        {
            using Stream stream = readEntry.Open("wrong-password".AsSpan());
            stream.CopyTo(Stream.Null);
        }
        catch (InvalidDataException)
        {
            // Expected: the AES password verifier / HMAC rejects the wrong key.
        }

Copilot AI review requested due to automatic review settings July 24, 2026 09:20
@alinpahontu2912 alinpahontu2912 changed the title Correctly implement fuzzers fro new encryption streams Correctly implement fuzzers for new encryption streams Jul 24, 2026

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 3 out of 3 changed files in this pull request and generated 2 comments.

Comment thread src/libraries/Fuzzing/DotnetFuzzing/Fuzzers/ZipCryptoStreamFuzzer.cs Outdated
Comment thread src/libraries/Fuzzing/DotnetFuzzing/Fuzzers/WinZipAesStreamFuzzer.cs Outdated
Copilot AI review requested due to automatic review settings July 27, 2026 09:44

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 3 out of 3 changed files in this pull request and generated 2 comments.

Comment on lines +99 to +113
Stream wrongStream = async
? await readEntry.OpenAsync("wrong-password".AsSpan())
: readEntry.Open("wrong-password".AsSpan());
using (wrongStream)
{
if (async)
{
await wrongStream.CopyToAsync(Stream.Null);
}
else
{
wrongStream.CopyTo(Stream.Null);
}
}
}
Comment on lines +109 to +123
Stream wrongStream = async
? await readEntry.OpenAsync("wrong-password".AsSpan())
: readEntry.Open("wrong-password".AsSpan());
using (wrongStream)
{
if (async)
{
await wrongStream.CopyToAsync(Stream.Null);
}
else
{
wrongStream.CopyTo(Stream.Null);
}
}
}
@alinpahontu2912

Copy link
Copy Markdown
Member Author

@MihuBot fuzz WinZipAesStreamFuzzer

@MihuBot

MihuBot commented Jul 28, 2026

Copy link
Copy Markdown

Ran the fuzzer(s) successfully. Code coverage reports:

@alinpahontu2912

Copy link
Copy Markdown
Member Author

@MihuBot fuzz ZipCryptoStreamFuzzer

@MihuBot

MihuBot commented Jul 28, 2026

Copy link
Copy Markdown

Ran the fuzzer(s) successfully. Code coverage reports:

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

Morty Proxy This is a proxified and sanitized view of the page, visit original site.