Correctly implement fuzzers for new encryption streams - #131306
#131306Correctly implement fuzzers for new encryption streams#131306alinpahontu2912 wants to merge 3 commits intodotnet:maindotnet/runtime:mainfrom alinpahontu2912:zipstream_fuzzersalinpahontu2912/runtime:zipstream_fuzzersCopy head branch name to clipboard
Conversation
|
Tagging subscribers to this area: @dotnet/area-meta |
There was a problem hiding this comment.
Pull request overview
This PR updates the fuzzers for the new ZIP encryption streams to exercise the actual ZipArchive encryption/decryption paths (ZipCrypto and WinZip AES) rather than constructing the internal crypto streams via reflection.
Changes:
- Replace reflection-based stream construction with
ZipArchive.CreateEntry(..., password, ZipEncryptionMethod)+Open/OpenAsync(password)round-trip workflows. - Add validation that the entry is encrypted and the expected encryption method is recorded, and verify plaintext round-trips correctly (sync + async).
- Add a “wrong password” scenario intended to ensure failures are handled as
InvalidDataException(but it currently doesn’t assert failure if no exception is thrown).
Reviewed changes
Copilot reviewed 2 out of 2 changed files in this pull request and generated 2 comments.
| File | Description |
|---|---|
| src/libraries/Fuzzing/DotnetFuzzing/Fuzzers/ZipCryptoStreamFuzzer.cs | Moves from reflected ZipCryptoStream.Create to ZipArchive-based encrypt/decrypt round-trip for ZipCrypto (sync + async). |
| src/libraries/Fuzzing/DotnetFuzzing/Fuzzers/WinZipAesStreamFuzzer.cs | Moves from reflected WinZipAesStream.Create to ZipArchive-based encrypt/decrypt round-trip for AES128/192/256 (sync + async). |
Comments suppressed due to low confidence (2)
src/libraries/Fuzzing/DotnetFuzzing/Fuzzers/ZipCryptoStreamFuzzer.cs:101
- The “wrong password must fail” check currently passes even if decryption succeeds without throwing. Use Assert.Throws so the fuzzer reliably flags regressions where a wrong password is accepted.
// Decrypting with a wrong password must fail cleanly with InvalidDataException, never crash.
try
{
using Stream stream = readEntry.Open("wrong-password".AsSpan());
stream.CopyTo(Stream.Null);
}
catch (InvalidDataException)
{
// Expected: the header password verifier rejects the wrong key.
}
src/libraries/Fuzzing/DotnetFuzzing/Fuzzers/WinZipAesStreamFuzzer.cs:113
- The “wrong password must fail” check currently passes even if decryption succeeds without throwing. Use Assert.Throws so the fuzzer reliably flags regressions where a wrong password is accepted.
// Decrypting with a wrong password must fail cleanly with InvalidDataException, never crash.
try
{
using Stream stream = readEntry.Open("wrong-password".AsSpan());
stream.CopyTo(Stream.Null);
}
catch (InvalidDataException)
{
// Expected: the AES password verifier / HMAC rejects the wrong key.
}
| Stream wrongStream = async | ||
| ? await readEntry.OpenAsync("wrong-password".AsSpan()) | ||
| : readEntry.Open("wrong-password".AsSpan()); | ||
| using (wrongStream) | ||
| { | ||
| if (async) | ||
| { | ||
| await wrongStream.CopyToAsync(Stream.Null); | ||
| } | ||
| else | ||
| { | ||
| wrongStream.CopyTo(Stream.Null); | ||
| } | ||
| } | ||
| } |
| Stream wrongStream = async | ||
| ? await readEntry.OpenAsync("wrong-password".AsSpan()) | ||
| : readEntry.Open("wrong-password".AsSpan()); | ||
| using (wrongStream) | ||
| { | ||
| if (async) | ||
| { | ||
| await wrongStream.CopyToAsync(Stream.Null); | ||
| } | ||
| else | ||
| { | ||
| wrongStream.CopyTo(Stream.Null); | ||
| } | ||
| } | ||
| } |
|
@MihuBot fuzz WinZipAesStreamFuzzer |
|
Ran the fuzzer(s) successfully. Code coverage reports: |
|
@MihuBot fuzz ZipCryptoStreamFuzzer |
|
Ran the fuzzer(s) successfully. Code coverage reports: |
Correctly implement fuzzers fro the new encryption streams: zipcryptostream and winzipaesstream