diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index 20ce6b74..c4930a5a 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -133,3 +133,35 @@ jobs: - name: Run python binding tests run: PYO3_PYTHON="$(which python)" make test-python + # 9 + fuzz: + name: Fuzz smoke test (sql_exec) + runs-on: ubuntu-latest + env: + # The fuzz crate is a standalone workspace; keep its build out of the shared target dir. + CARGO_TARGET_DIR: ${{ github.workspace }}/fuzz/target + steps: + - uses: actions/checkout@v4 + # Pinned; keep in sync with FUZZ_TOOLCHAIN in the Makefile. + - uses: dtolnay/rust-toolchain@master + with: + toolchain: nightly-2026-10-04 + - uses: Swatinem/rust-cache@v2 + with: + workspaces: fuzz + - uses: taiki-e/install-action@v2 + with: + tool: cargo-fuzz + + - name: Run sql_exec fuzzer + run: make fuzz FUZZ_TARGET=sql_exec FUZZ_TIME=150 + + - name: Run sql_gen fuzzer + run: make fuzz FUZZ_TARGET=sql_gen FUZZ_TIME=150 + + - name: Upload crash artifacts + if: failure() + uses: actions/upload-artifact@v4 + with: + name: fuzz-artifacts + path: fuzz/artifacts diff --git a/Cargo.lock b/Cargo.lock index 759df72a..cf0640c2 100644 --- a/Cargo.lock +++ b/Cargo.lock @@ -87,7 +87,22 @@ source = "registry+https://github.com/rust-lang/crates.io-index" checksum = "301af1932e46185686725e0fad2f8f2aa7da69dd70bf6ecc44d6b703844a3933" dependencies = [ "anstyle", - "anstyle-parse", + "anstyle-parse 0.2.7", + "anstyle-query", + "anstyle-wincon", + "colorchoice", + "is_terminal_polyfill", + "utf8parse", +] + +[[package]] +name = "anstream" +version = "1.0.0" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "824a212faf96e9acacdbd09febd34438f8f711fb84e09a8916013cd7815ca28d" +dependencies = [ + "anstyle", + "anstyle-parse 1.0.0", "anstyle-query", "anstyle-wincon", "colorchoice", @@ -110,6 +125,15 @@ dependencies = [ "utf8parse", ] +[[package]] +name = "anstyle-parse" +version = "1.0.0" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "52ce7f38b242319f7cabaa6813055467063ecdc9d355bbb4ce0c68908cd8130e" +dependencies = [ + "utf8parse", +] + [[package]] name = "anstyle-query" version = "1.1.3" @@ -412,7 +436,7 @@ version = "4.5.41" source = "registry+https://github.com/rust-lang/crates.io-index" checksum = "707eab41e9622f9139419d573eca0900137718000c517d47da73045f54331c3d" dependencies = [ - "anstream", + "anstream 0.6.19", "anstyle", "clap_lex", "strsim", @@ -643,14 +667,14 @@ dependencies = [ [[package]] name = "educe" -version = "0.4.23" +version = "0.6.0" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "0f0042ff8246a363dbe77d2ceedb073339e85a804b9a47636c6e016a9a32c05f" +checksum = "1d7bc049e1bd8cdeb31b68bbd586a9464ecf9f3944af3958a7a9d0f8b9799417" dependencies = [ "enum-ordinalize", "proc-macro2", "quote", - "syn 1.0.109", + "syn 2.0.104", ] [[package]] @@ -667,15 +691,22 @@ checksum = "34aa73646ffb006b8f5147f3dc182bd4bcb190227ce861fc4a4844bf8e3cb2c0" [[package]] name = "enum-ordinalize" -version = "3.1.15" +version = "4.4.2" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "1bf1fa3f06bbff1ea5b1a9c7b14aa992a39657db60a2759457328d7e058f49ee" +checksum = "89dd01549b09589510cf0647475075d12071456586d70f5c75c98ae2a5537677" +dependencies = [ + "enum-ordinalize-derive", +] + +[[package]] +name = "enum-ordinalize-derive" +version = "4.4.2" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "a65863d15a4ce2888bd2f0f543cc963d3879c3a022c8ee43f6141d479a3ac815" dependencies = [ - "num-bigint", - "num-traits", "proc-macro2", "quote", - "syn 2.0.104", + "syn 3.0.6", ] [[package]] @@ -720,6 +751,12 @@ version = "3.3.2" source = "registry+https://github.com/rust-lang/crates.io-index" checksum = "dea2df4cf52843e0452895c455a1a2cfbb842a1e7329671acf418fdc53ed4c59" +[[package]] +name = "escape8259" +version = "0.5.3" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "5692dd7b5a1978a5aeb0ce83b7655c58ca8efdcb79d21036ea249da95afec2c6" + [[package]] name = "fastrand" version = "2.3.0" @@ -746,9 +783,9 @@ checksum = "3f9eec918d3f24069decb9af1554cad7c880e2da24a9afd88aca000531ab82c1" [[package]] name = "fs-err" -version = "2.11.0" +version = "3.3.2" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "88a41f105fe1d5b6b34b2055e3dc59bb79b46b48b2040b9e6c7b4b5de097aa41" +checksum = "b5c95b673b8f6f7235229ae11c5642d81b04c2e64c1e2fb417bc0cf73ca45f29" dependencies = [ "autocfg", ] @@ -1061,6 +1098,15 @@ dependencies = [ "either", ] +[[package]] +name = "itertools" +version = "0.13.0" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "413ee7dfc52ee1a4949ceeb7dbc8a33f2d6c088194d9f922fb8318faf1f01186" +dependencies = [ + "either", +] + [[package]] name = "itoa" version = "1.0.15" @@ -1089,7 +1135,7 @@ dependencies = [ [[package]] name = "kite_sql" -version = "0.4.1" +version = "0.5.0" dependencies = [ "bumpalo", "chrono", @@ -1175,13 +1221,14 @@ dependencies = [ [[package]] name = "libtest-mimic" -version = "0.6.1" +version = "0.8.2" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "6d8de370f98a6cb8a4606618e53e802f93b094ddec0f96988eaec2c27e6e9ce7" +checksum = "14e6ba06f0ade6e504aff834d7c34298e5155c6baca353cc6a4aaff2f9fd7f33" dependencies = [ + "anstream 1.0.0", + "anstyle", "clap", - "termcolor", - "threadpool", + "escape8259", ] [[package]] @@ -1348,17 +1395,7 @@ version = "0.50.3" source = "registry+https://github.com/rust-lang/crates.io-index" checksum = "7957b9740744892f114936ab4a57b3f487491bbeafaf8083688b16841a4240e5" dependencies = [ - "windows-sys 0.59.0", -] - -[[package]] -name = "num-bigint" -version = "0.4.6" -source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "a5e44f723f1133c9deac646763579fdb3ac745e418f2a7af9cd0c431da1f20b9" -dependencies = [ - "num-integer", - "num-traits", + "windows-sys 0.60.2", ] [[package]] @@ -1371,15 +1408,6 @@ dependencies = [ "itoa", ] -[[package]] -name = "num-integer" -version = "0.1.46" -source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "7969661fd2958a5cb096e56c8e1ad0444ac2bbcd0061bd28660485a44879858f" -dependencies = [ - "num-traits", -] - [[package]] name = "num-traits" version = "0.2.19" @@ -1390,16 +1418,6 @@ dependencies = [ "libm", ] -[[package]] -name = "num_cpus" -version = "1.17.0" -source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "91df4bbde75afed763b708b7eee1e8e7651e02d97f6d5dd763e89367e957b23b" -dependencies = [ - "hermit-abi", - "libc", -] - [[package]] name = "number_prefix" version = "0.4.0" @@ -1444,9 +1462,9 @@ dependencies = [ [[package]] name = "owo-colors" -version = "3.5.0" +version = "4.4.0" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "c1b04fb49957986fdce4d6ee7a65027d55d4b6d2265e5848bbb507b58ccfdb6f" +checksum = "13c45bb4a6ae1280ec0803b1ef9d3455eb50f01efbbe1447ab020f1d54fba9d8" [[package]] name = "paste" @@ -1526,7 +1544,7 @@ dependencies = [ "spin", "symbolic-demangle", "tempfile", - "thiserror 2.0.12", + "thiserror", ] [[package]] @@ -2001,9 +2019,9 @@ dependencies = [ [[package]] name = "sqllogictest" -version = "0.14.0" +version = "0.29.1" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "556b08485afb80bb29ed93a0a364641dbfdb65d832c0d08f5b16cb3b750696e5" +checksum = "d03b2262a244037b0b510edbd25a8e6c9fb8d73ee0237fc6cc95a54c16f94a82" dependencies = [ "async-trait", "educe", @@ -2011,14 +2029,16 @@ dependencies = [ "futures", "glob", "humantime", - "itertools 0.10.5", + "itertools 0.13.0", "libtest-mimic", "md-5", "owo-colors", + "rand", "regex", "similar", + "subst", "tempfile", - "thiserror 1.0.69", + "thiserror", "tracing", ] @@ -2060,6 +2080,16 @@ version = "0.11.1" source = "registry+https://github.com/rust-lang/crates.io-index" checksum = "7da8b5736845d9f2fcb837ea5d9e2628564b3b043a70948a3f0b778838c5fb4f" +[[package]] +name = "subst" +version = "0.3.8" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "0a9a86e5144f63c2d18334698269a8bfae6eece345c70b64821ea5b35054ec99" +dependencies = [ + "memchr", + "unicode-width 0.1.14", +] + [[package]] name = "symbolic-common" version = "12.15.5" @@ -2105,6 +2135,17 @@ dependencies = [ "unicode-ident", ] +[[package]] +name = "syn" +version = "3.0.6" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "8593e8e72159ed2257d083c7a454a85cbf854f37a0966d8d483aff8c8a3ebcee" +dependencies = [ + "proc-macro2", + "quote", + "unicode-ident", +] + [[package]] name = "tap" version = "1.0.1" @@ -2130,42 +2171,13 @@ dependencies = [ "windows-sys 0.59.0", ] -[[package]] -name = "termcolor" -version = "1.4.1" -source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "06794f8f6c5c898b3275aebefa6b8a1cb24cd2c6c79397ab15774837a0bc5755" -dependencies = [ - "winapi-util", -] - -[[package]] -name = "thiserror" -version = "1.0.69" -source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "b6aaf5339b578ea85b50e080feb250a3e8ae8cfcdff9a461c9ec2904bc923f52" -dependencies = [ - "thiserror-impl 1.0.69", -] - [[package]] name = "thiserror" version = "2.0.12" source = "registry+https://github.com/rust-lang/crates.io-index" checksum = "567b8a2dae586314f7be2a752ec7474332959c6460e02bde30d702a66d488708" dependencies = [ - "thiserror-impl 2.0.12", -] - -[[package]] -name = "thiserror-impl" -version = "1.0.69" -source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "4fee6c4efc90059e10f81e6d42c60a18f76588c3d74cb83a0b242a2b6c7504c1" -dependencies = [ - "proc-macro2", - "quote", - "syn 2.0.104", + "thiserror-impl", ] [[package]] @@ -2179,15 +2191,6 @@ dependencies = [ "syn 2.0.104", ] -[[package]] -name = "threadpool" -version = "1.8.1" -source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "d050e60b33d41c19108b32cea32164033a9013fe3b46cbd4457559bfbf77afaa" -dependencies = [ - "num_cpus", -] - [[package]] name = "tinytemplate" version = "1.2.1" diff --git a/Cargo.toml b/Cargo.toml index 61fb17c9..7cf94757 100644 --- a/Cargo.toml +++ b/Cargo.toml @@ -2,7 +2,7 @@ [package] name = "kite_sql" -version = "0.4.1" +version = "0.5.0" edition = "2021" build = "build.rs" authors = ["Kould ", "Xwg "] diff --git a/Makefile b/Makefile index f8600bb3..ed1d71fa 100644 --- a/Makefile +++ b/Makefile @@ -15,9 +15,28 @@ COVERAGE_PROFILE_DIR ?= target/grcov/profraw COVERAGE_HTML_DIR ?= target/grcov/html COVERAGE_RUSTFLAGS ?= -Cinstrument-coverage COVERAGE_TEST_FEATURES ?= copy,decimal,orm +# Pinned nightly for fuzzing; keep in sync with the `fuzz` job in .github/workflows/ci.yml. +FUZZ_TOOLCHAIN ?= nightly-2026-10-04 +FUZZ_TARGET ?= sql_exec +FUZZ_TIME ?= 60 +# Pass the host triple explicitly: prebuilt (musl) cargo-fuzz binaries otherwise default to musl. +FUZZ_TRIPLE ?= $(shell rustc -vV | sed -n 's/^host: //p') +FUZZ_TARGET_DIR ?= $(CURDIR)/fuzz/target +FUZZ_BIN = $(FUZZ_TARGET_DIR)/$(FUZZ_TRIPLE)/release/$(FUZZ_TARGET) +# Per-target libFuzzer args and the exit code that still counts as a pass. +# sql_exec: tests/slt as read-only seeds (libFuzzer only writes to the FIRST dir); fork mode +# so timeouts are skipped (TODO in fuzz/fuzz_targets/sql_exec.rs). Fork mode ignores OOMs by +# default, hence -ignore_ooms=0, and exits with the LAST child's code, so a trailing ignored +# timeout (70) is not a failure. +FUZZ_ARGS_sql_exec = tests/slt -dict=fuzz/sql.dict -max_len=32768 \ + -fork=1 -ignore_timeouts=1 -ignore_ooms=0 -timeout_exitcode=70 +FUZZ_PASS_EXIT_sql_exec = 70 +# sql_gen: bounded generated queries, so crashes, timeouts and OOMs all fail. +FUZZ_ARGS_sql_gen = -max_len=4096 +FUZZ_PASS_EXIT_sql_gen = 0 COVERAGE_REPORT_ARGS ?= --llvm --ignore-not-existing --keep-only 'src/**' --ignore 'src/**/tests/**' --ignore 'tests/**' --ignore 'tpcc/**' --excl-start 'GRCOV_EXCL_START' --excl-stop 'GRCOV_EXCL_STOP' -.PHONY: test test-python test-wasm test-slt test-all codecov codecov-html wasm-build check tpcc tpcc-kitesql-rocksdb tpcc-kitesql-lmdb tpcc-lmdb-flamegraph tpcc-lmdb-heaptrack tpcc-sqlite tpcc-sqlite-practical tpcc-sqlite-balanced tpcc-dual cargo-check build wasm-examples native-examples fmt clippy +.PHONY: test test-python test-wasm test-slt test-all codecov codecov-html wasm-build check tpcc tpcc-kitesql-rocksdb tpcc-kitesql-lmdb tpcc-lmdb-flamegraph tpcc-lmdb-heaptrack tpcc-sqlite tpcc-sqlite-practical tpcc-sqlite-balanced tpcc-dual cargo-check build wasm-examples native-examples fmt clippy fuzz ## Run default Rust tests in the current environment (non-WASM). test: @@ -71,6 +90,20 @@ codecov-html: $(GRCOV) . --binary-path \"$${CARGO_TARGET_DIR:-target}/debug\" -s . -t html $(COVERAGE_REPORT_ARGS) -o '$(COVERAGE_HTML_DIR)'" @echo "Coverage report: $(COVERAGE_HTML_DIR)/index.html" +## Run fuzz target FUZZ_TARGET (sql_exec | sql_gen) for FUZZ_TIME seconds +## (needs a nightly toolchain and cargo-fuzz). The binary is run directly because +## `cargo fuzz run` turns every non-zero exit into a failure. +fuzz: + @mkdir -p fuzz/corpus/$(FUZZ_TARGET) fuzz/artifacts/$(FUZZ_TARGET) + $(CARGO) +$(FUZZ_TOOLCHAIN) fuzz build --target $(FUZZ_TRIPLE) --target-dir $(FUZZ_TARGET_DIR) $(FUZZ_TARGET) + @status=0; $(FUZZ_BIN) fuzz/corpus/$(FUZZ_TARGET) $(FUZZ_ARGS_$(FUZZ_TARGET)) \ + -artifact_prefix=fuzz/artifacts/$(FUZZ_TARGET)/ \ + -timeout=10 -rss_limit_mb=4096 -max_total_time=$(FUZZ_TIME) || status=$$?; \ + rm -rf "$${TMPDIR:-/tmp}"/kitesql-fuzz-$(FUZZ_TARGET)-*; \ + if [ $$status -ne 0 ] && [ $$status -ne $(FUZZ_PASS_EXIT_$(FUZZ_TARGET)) ]; then \ + echo "fuzz: $(FUZZ_TARGET) failed (exit $$status), see fuzz/artifacts/$(FUZZ_TARGET)/"; exit $$status; \ + fi + ## Run formatting (check mode) across the workspace. fmt: $(CARGO) fmt --all -- --check diff --git a/fuzz/.gitignore b/fuzz/.gitignore new file mode 100644 index 00000000..1a45eee7 --- /dev/null +++ b/fuzz/.gitignore @@ -0,0 +1,4 @@ +target +corpus +artifacts +coverage diff --git a/fuzz/Cargo.lock b/fuzz/Cargo.lock new file mode 100644 index 00000000..7671c039 --- /dev/null +++ b/fuzz/Cargo.lock @@ -0,0 +1,841 @@ +# This file is automatically @generated by Cargo. +# It is not intended for manual editing. +version = 4 + +[[package]] +name = "android_system_properties" +version = "0.1.6" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "ae221649c9976a6f6c56ae1facf410f3ddb33cc661c4b7b61020a912d4237fbc" +dependencies = [ + "libc", +] + +[[package]] +name = "arbitrary" +version = "1.4.2" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "c3d036a3c4ab069c7b410a2ce876bd74808d2d0888a82667669f8e783a898bf1" + +[[package]] +name = "arrayvec" +version = "0.7.8" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "d3fb67a6e08acf24fdeccbac2cb6ac4305825bd1f117462e0e6f2f193345ad56" + +[[package]] +name = "autocfg" +version = "1.5.1" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "f2032f911046de80f0a198e0901378627c33f59ea0ac00e363d481118bd70a53" + +[[package]] +name = "bitflags" +version = "1.3.2" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "bef38d45163c2f1dde094a7dfd33ccf595c92905c8f8f4fdc18d06fb1037718a" + +[[package]] +name = "borsh" +version = "1.8.1" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "553c5d846a6ba5150c65e3b1b8ec073bcf1abc20f9b7220de384a4443ea4e20a" +dependencies = [ + "borsh-derive", + "bytes", + "cfg_aliases", +] + +[[package]] +name = "borsh-derive" +version = "1.8.1" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "12cdfe656708a01f89b451a7d36466e6fe6c414de0aa18fc54f864f6f9ca9f56" +dependencies = [ + "once_cell", + "proc-macro-crate", + "proc-macro2", + "quote", + "syn 3.0.6", +] + +[[package]] +name = "bumpalo" +version = "3.20.3" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "72f5acc6cb2ba439de613abc23857ec3d78374d8ed5ac84e9d11336e87da8649" + +[[package]] +name = "bytes" +version = "1.12.1" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "fc652a48c352aef3ea3aed32080501cf3ef6ed5da78602a020c991775b0aff04" + +[[package]] +name = "cc" +version = "1.6.0" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "f74872d07caf508b30a21f6836e7d7016a2eaf7d9ff4f48deaa58cd8a0407630" +dependencies = [ + "find-msvc-tools", + "jobserver", + "libc", + "shlex", +] + +[[package]] +name = "cfg-if" +version = "1.0.5" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "4e7648175b45a9a48536d676f68d918270699102aa8dab5496df06904c914600" + +[[package]] +name = "cfg_aliases" +version = "0.2.2" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "f079e83a288787bcd14a6aea84cee5c87a67c5a3e660c30f557a3d24761b3527" + +[[package]] +name = "chrono" +version = "0.4.45" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "1aa79e62e7697b8e29b513a68abacf485adcd1fe8284a4316c5ae868e6633327" +dependencies = [ + "iana-time-zone", + "js-sys", + "num-traits", + "wasm-bindgen", + "windows-link", +] + +[[package]] +name = "core-foundation-sys" +version = "0.8.7" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "773648b94d0e5d620f64f280777445740e61fe701025087ec8b57f45c791888b" + +[[package]] +name = "darling" +version = "0.20.11" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "fc7f46116c46ff9ab3eb1597a45688b6715c6e628b5c133e288e709a29bcb4ee" +dependencies = [ + "darling_core", + "darling_macro", +] + +[[package]] +name = "darling_core" +version = "0.20.11" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "0d00b9596d185e565c2207a0b01f8bd1a135483d02d9b7b0a54b11da8d53412e" +dependencies = [ + "fnv", + "ident_case", + "proc-macro2", + "quote", + "strsim", + "syn 2.0.119", +] + +[[package]] +name = "darling_macro" +version = "0.20.11" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "fc34b93ccb385b40dc71c6fceac4b2ad23662c7eeb248cf10d529b7e055b6ead" +dependencies = [ + "darling_core", + "quote", + "syn 2.0.119", +] + +[[package]] +name = "equivalent" +version = "1.0.2" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "877a4ace8713b0bcf2a4e7eec82529c029f1d0619886d18145fea96c3ffe5c0f" + +[[package]] +name = "find-msvc-tools" +version = "0.1.14" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "aedcfb3409746eddb02b9e19ebda1c3394f759a152e48ee875a0844d1b955484" + +[[package]] +name = "fnv" +version = "1.0.7" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "3f9eec918d3f24069decb9af1554cad7c880e2da24a9afd88aca000531ab82c1" + +[[package]] +name = "futures-core" +version = "0.3.34" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "92d699e522242e69e3003b94ecc1f960f3a5e015aa7c5d7486e65ad01dd94f5e" + +[[package]] +name = "futures-task" +version = "0.3.34" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "cd417de3d1d015fc3bfd2b1ea46dfc7bab72ef86f1cc7cc9c78e728b34a6d1fd" + +[[package]] +name = "futures-util" +version = "0.3.34" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "0d50a92467f8ba5dd6e3ee5d4bd04d73ab2e4e1c44474a0674821dfce14b79bc" +dependencies = [ + "futures-core", + "futures-task", + "pin-project-lite", + "slab", +] + +[[package]] +name = "getrandom" +version = "0.2.17" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "ff2abc00be7fca6ebc474524697ae276ad847ad0a6b3faa4bcb027e9a4614ad0" +dependencies = [ + "cfg-if", + "libc", + "wasi", +] + +[[package]] +name = "getrandom" +version = "0.3.4" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "899def5c37c4fd7b2664648c28120ecec138e4d395b459e5ca34f9cce2dd77fd" +dependencies = [ + "cfg-if", + "libc", + "r-efi 5.3.0", + "wasip2", +] + +[[package]] +name = "getrandom" +version = "0.4.3" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "300e883d756b2e4ec94e02791f39b04b522276138852cfc41d9fb7e904106099" +dependencies = [ + "cfg-if", + "libc", + "r-efi 6.0.0", +] + +[[package]] +name = "hashbrown" +version = "0.17.1" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "ed5909b6e89a2db4456e54cd5f673791d7eca6732202bbf2a9cc504fe2f9b84a" + +[[package]] +name = "iana-time-zone" +version = "0.1.65" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "e31bc9ad994ba00e440a8aa5c9ef0ec67d5cb5e5cb0cc7f8b744a35b389cc470" +dependencies = [ + "android_system_properties", + "core-foundation-sys", + "iana-time-zone-haiku", + "js-sys", + "log", + "wasm-bindgen", + "windows-core", +] + +[[package]] +name = "iana-time-zone-haiku" +version = "0.1.2" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "f31827a206f56af32e590ba56d5d2d085f558508192593743f16b2306495269f" +dependencies = [ + "cc", +] + +[[package]] +name = "ident_case" +version = "1.0.1" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "b9e0384b61958566e926dc50660321d12159025e767c18e043daf26b70104c39" + +[[package]] +name = "indexmap" +version = "2.14.2" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "cc4e190f5d26ca7051642629da2c52fc03bde85a03197c99408dcd291734c855" +dependencies = [ + "equivalent", + "hashbrown", +] + +[[package]] +name = "itoa" +version = "1.0.18" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "8f42a60cbdf9a97f5d2305f08a87dc4e09308d1276d28c869c684d7777685682" + +[[package]] +name = "jobserver" +version = "0.1.35" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "1c00acbd29eabad4a2392fa0e921c874934dbbf4194312ad20f04a0ed67a3cb3" +dependencies = [ + "getrandom 0.4.3", + "libc", +] + +[[package]] +name = "js-sys" +version = "0.3.106" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "7883d941dae510fb2d978fc3fe018c71c9e2892fd38854de3e8b92c2e5ad9cc5" +dependencies = [ + "cfg-if", + "futures-util", + "wasm-bindgen", +] + +[[package]] +name = "kite_sql" +version = "0.5.0" +dependencies = [ + "bumpalo", + "chrono", + "kite_sql_serde_macros", + "lmdb", + "lmdb-sys", + "ordered-float", + "paste", + "rust_decimal", + "sqlparser", +] + +[[package]] +name = "kite_sql-fuzz" +version = "0.0.0" +dependencies = [ + "kite_sql", + "libfuzzer-sys", +] + +[[package]] +name = "kite_sql_serde_macros" +version = "0.2.4" +dependencies = [ + "darling", + "proc-macro2", + "quote", + "syn 2.0.119", +] + +[[package]] +name = "libc" +version = "0.2.190" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "ce5d3ddc6d3fa000eb1536d85e147bfe31aacaba692ed6a876f95cb7c855be78" + +[[package]] +name = "libfuzzer-sys" +version = "0.4.10" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "5037190e1f70cbeef565bd267599242926f724d3b8a9f510fd7e0b540cfa4404" +dependencies = [ + "arbitrary", + "cc", +] + +[[package]] +name = "lmdb" +version = "0.8.0" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "5b0908efb5d6496aa977d96f91413da2635a902e5e31dbef0bfb88986c248539" +dependencies = [ + "bitflags", + "libc", + "lmdb-sys", +] + +[[package]] +name = "lmdb-sys" +version = "0.8.0" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "d5b392838cfe8858e86fac37cf97a0e8c55cc60ba0a18365cadc33092f128ce9" +dependencies = [ + "cc", + "libc", + "pkg-config", +] + +[[package]] +name = "log" +version = "0.4.34" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "f9f8bd3e56ce4dfc153cf470fffbfa98c7620958b312ca5c3a4b8d5181fd13c6" + +[[package]] +name = "memchr" +version = "2.8.3" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "cf8baf1c55e62ffcace7a9f06f4bd9cd3f0c4beb022d3b367256b91b87513d98" + +[[package]] +name = "num-traits" +version = "0.2.19" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "071dfc062690e90b734c0b2273ce72ad0ffa95f0c74596bc250dcfd960262841" +dependencies = [ + "autocfg", +] + +[[package]] +name = "once_cell" +version = "1.21.4" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "9f7c3e4beb33f85d45ae3e3a1792185706c8e16d043238c593331cc7cd313b50" + +[[package]] +name = "ordered-float" +version = "4.6.0" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "7bb71e1b3fa6ca1c61f383464aaf2bb0e2f8e772a1f01d486832464de363b951" +dependencies = [ + "num-traits", +] + +[[package]] +name = "paste" +version = "1.0.15" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "57c0d7b74b563b49d38dae00a0c37d4d6de9b432382b2892f0574ddcae73fd0a" + +[[package]] +name = "pin-project-lite" +version = "0.2.17" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "a89322df9ebe1c1578d689c92318e070967d1042b512afbe49518723f4e6d5cd" + +[[package]] +name = "pkg-config" +version = "0.3.34" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "f6b464fbc74e149a392436b17d523f769e057cb6877f6a5c4618bc6f11800548" + +[[package]] +name = "ppv-lite86" +version = "0.2.21" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "85eae3c4ed2f50dcfe72643da4befc30deadb458a9b590d720cde2f2b1e97da9" +dependencies = [ + "zerocopy", +] + +[[package]] +name = "proc-macro-crate" +version = "3.5.0" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "e67ba7e9b2b56446f1d419b1d807906278ffa1a658a8a5d8a39dcb1f5a78614f" +dependencies = [ + "toml_edit", +] + +[[package]] +name = "proc-macro2" +version = "1.0.107" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "985e7ec9bb745e6ce6535b544d84d6cd6f7ad8bd711c398938ae983b91a766d9" +dependencies = [ + "unicode-ident", +] + +[[package]] +name = "quote" +version = "1.0.47" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "1fbf4db142a473a8d80c26bbf18454ed458bf8d26c8219c331daecfdbd079001" +dependencies = [ + "proc-macro2", +] + +[[package]] +name = "r-efi" +version = "5.3.0" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "69cdb34c158ceb288df11e18b4bd39de994f6657d83847bdffdbd7f346754b0f" + +[[package]] +name = "r-efi" +version = "6.0.0" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "f8dcc9c7d52a811697d2151c701e0d08956f92b0e24136cf4cf27b57a6a0d9bf" + +[[package]] +name = "rand" +version = "0.8.8" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "e058c7de0b26af77780c769414d6257830bb240f3c38477dbc2c16e5f54d6d4c" +dependencies = [ + "libc", + "rand_chacha 0.3.1", + "rand_core 0.6.4", +] + +[[package]] +name = "rand" +version = "0.9.5" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "b9ef1d0d795eb7d84685bca4f72f3649f064e6641543d3a8c415898726a57b41" +dependencies = [ + "rand_chacha 0.9.0", + "rand_core 0.9.5", +] + +[[package]] +name = "rand_chacha" +version = "0.3.1" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "e6c10a63a0fa32252be49d21e7709d4d4baf8d231c2dbce1eaa8141b9b127d88" +dependencies = [ + "ppv-lite86", + "rand_core 0.6.4", +] + +[[package]] +name = "rand_chacha" +version = "0.9.0" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "d3022b5f1df60f26e1ffddd6c66e8aa15de382ae63b3a0c1bfc0e4d3e3f325cb" +dependencies = [ + "ppv-lite86", + "rand_core 0.9.5", +] + +[[package]] +name = "rand_core" +version = "0.6.4" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "ec0be4795e2f6a28069bec0b5ff3e2ac9bafc99e6a9a7dc3547996c5c816922c" +dependencies = [ + "getrandom 0.2.17", +] + +[[package]] +name = "rand_core" +version = "0.9.5" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "76afc826de14238e6e8c374ddcc1fa19e374fd8dd986b0d2af0d02377261d83c" +dependencies = [ + "getrandom 0.3.4", +] + +[[package]] +name = "rust_decimal" +version = "1.43.0" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "7653272e75dcac41dc199fbea6f5797633994fafd339943c06c9af16bf29cd3a" +dependencies = [ + "arrayvec", + "borsh", + "bytes", + "num-traits", + "rand 0.8.8", + "rand 0.9.5", + "serde", + "serde_json", + "wasm-bindgen", +] + +[[package]] +name = "rustversion" +version = "1.0.23" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "cf54715a573b99ac80df0bc206da022bcd442c974952c7b9720069370852e21f" + +[[package]] +name = "serde" +version = "1.0.229" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "4148590afebada386688f18773da617792bf2ef03ffc1e4cbd2b1d45b023e0ba" +dependencies = [ + "serde_core", +] + +[[package]] +name = "serde_core" +version = "1.0.229" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "67dca2c9c51e58a4791a4b1ed58308b39c64224d349a935ab5039aa360942a48" +dependencies = [ + "serde_derive", +] + +[[package]] +name = "serde_derive" +version = "1.0.229" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "e7a5d71263a5a7d47b41f6b3f06ba276f10cc18b0931f1799f710578e2309348" +dependencies = [ + "proc-macro2", + "quote", + "syn 3.0.6", +] + +[[package]] +name = "serde_json" +version = "1.0.151" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "c841b55ecdae098c80dcae9cf767f6f8a0c2cdb3416bbef72181df4d0fe73f14" +dependencies = [ + "itoa", + "memchr", + "serde", + "serde_core", + "zmij", +] + +[[package]] +name = "shlex" +version = "2.0.1" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "f8fadd59c855ef2080decdef8ff161eb6661b86933c9d82e5ba29dc602a55aba" + +[[package]] +name = "slab" +version = "0.4.12" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "0c790de23124f9ab44544d7ac05d60440adc586479ce501c1d6d7da3cd8c9cf5" + +[[package]] +name = "sqlparser" +version = "0.61.0" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "dbf5ea8d4d7c808e1af1cbabebca9a2abe603bcefc22294c5b95018d53200cb7" +dependencies = [ + "log", +] + +[[package]] +name = "strsim" +version = "0.11.1" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "7da8b5736845d9f2fcb837ea5d9e2628564b3b043a70948a3f0b778838c5fb4f" + +[[package]] +name = "syn" +version = "2.0.119" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "872831b642d1a07999a962a351ed35b955ea2cfc8f3862091e2a240a84f17297" +dependencies = [ + "proc-macro2", + "quote", + "unicode-ident", +] + +[[package]] +name = "syn" +version = "3.0.6" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "8593e8e72159ed2257d083c7a454a85cbf854f37a0966d8d483aff8c8a3ebcee" +dependencies = [ + "proc-macro2", + "quote", + "unicode-ident", +] + +[[package]] +name = "toml_datetime" +version = "1.1.1+spec-1.1.0" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "3165f65f62e28e0115a00b2ebdd37eb6f3b641855f9d636d3cd4103767159ad7" +dependencies = [ + "serde_core", +] + +[[package]] +name = "toml_edit" +version = "0.25.15+spec-1.1.0" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "1340ea94a5856333492c9064b02c778b191dd2c853778d9609debdcdfea3a614" +dependencies = [ + "indexmap", + "toml_datetime", + "toml_parser", + "winnow", +] + +[[package]] +name = "toml_parser" +version = "1.1.3+spec-1.1.0" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "1d38ac1cf9b95face32296c0a3ede1fdc270627c9d9c02a7274dd6d960dc4d56" +dependencies = [ + "winnow", +] + +[[package]] +name = "unicode-ident" +version = "1.0.26" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "d245f478577f809a851594d02313b640fb437e0bb33866753cff937863096954" + +[[package]] +name = "wasi" +version = "0.11.1+wasi-snapshot-preview1" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "ccf3ec651a847eb01de73ccad15eb7d99f80485de043efb2f370cd654f4ea44b" + +[[package]] +name = "wasip2" +version = "1.0.4+wasi-0.2.12" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "b67efb37e106e55ce722a510d6b5f9c17f083e5fc79afc2badeb12cc313d9487" +dependencies = [ + "wit-bindgen", +] + +[[package]] +name = "wasm-bindgen" +version = "0.2.129" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "9bb54f33acc68fd454578d9820b0bde1a1a3d17aa17bb7b6595806d02886d409" +dependencies = [ + "cfg-if", + "once_cell", + "rustversion", + "wasm-bindgen-macro", + "wasm-bindgen-shared", +] + +[[package]] +name = "wasm-bindgen-macro" +version = "0.2.129" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "2e29d0c35b16e224a7eeb5cd2d25e3e1968fbd65604117b44d3b789d00ee8535" +dependencies = [ + "quote", + "wasm-bindgen-macro-support", +] + +[[package]] +name = "wasm-bindgen-macro-support" +version = "0.2.129" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "6f501a8bc3719dba86ef8ae4728879c08001bea749eb1333ac5b91e040e2a6b7" +dependencies = [ + "bumpalo", + "proc-macro2", + "quote", + "syn 3.0.6", + "wasm-bindgen-shared", +] + +[[package]] +name = "wasm-bindgen-shared" +version = "0.2.129" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "23f0c9c52aa7cd7d77769a4cfe2a9adb1b331f489a41d912ce14513d5ab995c6" +dependencies = [ + "unicode-ident", +] + +[[package]] +name = "windows-core" +version = "0.62.2" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "b8e83a14d34d0623b51dce9581199302a221863196a1dde71a7663a4c2be9deb" +dependencies = [ + "windows-implement", + "windows-interface", + "windows-link", + "windows-result", + "windows-strings", +] + +[[package]] +name = "windows-implement" +version = "0.60.2" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "053e2e040ab57b9dc951b72c264860db7eb3b0200ba345b4e4c3b14f67855ddf" +dependencies = [ + "proc-macro2", + "quote", + "syn 2.0.119", +] + +[[package]] +name = "windows-interface" +version = "0.59.3" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "3f316c4a2570ba26bbec722032c4099d8c8bc095efccdc15688708623367e358" +dependencies = [ + "proc-macro2", + "quote", + "syn 2.0.119", +] + +[[package]] +name = "windows-link" +version = "0.2.1" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "f0805222e57f7521d6a62e36fa9163bc891acd422f971defe97d64e70d0a4fe5" + +[[package]] +name = "windows-result" +version = "0.4.1" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "7781fa89eaf60850ac3d2da7af8e5242a5ea78d1a11c49bf2910bb5a73853eb5" +dependencies = [ + "windows-link", +] + +[[package]] +name = "windows-strings" +version = "0.5.1" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "7837d08f69c77cf6b07689544538e017c1bfcf57e34b4c0ff58e6c2cd3b37091" +dependencies = [ + "windows-link", +] + +[[package]] +name = "winnow" +version = "1.0.4" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "23b97319f7b8343df12cc98938e5c3eb436064524c8d2b4e30a1d3a36eecdf81" +dependencies = [ + "memchr", +] + +[[package]] +name = "wit-bindgen" +version = "0.57.1" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "1ebf944e87a7c253233ad6766e082e3cd714b5d03812acc24c318f549614536e" + +[[package]] +name = "zerocopy" +version = "0.8.59" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "6df92bf3d9227be3d53173901ddbffac2babc27ae50f397776ffd6dc33f800cb" +dependencies = [ + "zerocopy-derive", +] + +[[package]] +name = "zerocopy-derive" +version = "0.8.59" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "ac4f328cf2f05d084e496c3e9c3f33ed0a183656a16e1fcec4d464d8373aec82" +dependencies = [ + "proc-macro2", + "quote", + "syn 2.0.119", +] + +[[package]] +name = "zmij" +version = "1.0.23" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "29666d0abbfad1e3dc4dcf6144730dd3a3ab225bbbdac83319345b1b44ccfc1b" diff --git a/fuzz/Cargo.toml b/fuzz/Cargo.toml new file mode 100644 index 00000000..6d3469bd --- /dev/null +++ b/fuzz/Cargo.toml @@ -0,0 +1,34 @@ +[package] +name = "kite_sql-fuzz" +version = "0.0.0" +publish = false +edition = "2021" + +[package.metadata] +cargo-fuzz = true + +[dependencies] +libfuzzer-sys = { version = "=0.4.10" } +# LMDB storage; no RocksDB build, no `copy`/`spill` file IO. +kite_sql = { path = "..", default-features = false, features = ["parser", "macros", "time", "decimal", "lmdb"] } + +# Standalone workspace: fuzzing needs nightly, the main workspace stays on stable. +[workspace] +members = ["."] + +[profile.release] +debug = 1 + +[[bin]] +name = "sql_exec" +path = "fuzz_targets/sql_exec.rs" +test = false +doc = false +bench = false + +[[bin]] +name = "sql_gen" +path = "fuzz_targets/sql_gen.rs" +test = false +doc = false +bench = false diff --git a/fuzz/fuzz_targets/sql_exec.rs b/fuzz/fuzz_targets/sql_exec.rs new file mode 100644 index 00000000..71be8fe3 --- /dev/null +++ b/fuzz/fuzz_targets/sql_exec.rs @@ -0,0 +1,182 @@ +// Copyright 2024 KipData/KiteSQL +// +// Licensed under the Apache License, Version 2.0 (the "License"); +// you may not use this file except in compliance with the License. +// You may obtain a copy of the License at +// +// http://www.apache.org/licenses/LICENSE-2.0 +// +// Unless required by applicable law or agreed to in writing, software +// distributed under the License is distributed on an "AS IS" BASIS, +// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +// See the License for the specific language governing permissions and +// limitations under the License. + +//! End-to-end SQL fuzzing against an LMDB database. +//! +//! The input is treated as a `;`-separated SQL script. Every chunk is run on +//! its own, so a mutation that breaks one statement does not discard the rest +//! of the script (e.g. the `CREATE TABLE` / `INSERT` that later queries need). +//! +//! sqllogictest syntax is stripped first, so `tests/slt` can be used directly +//! as the seed corpus; plain SQL inputs pass through unchanged. +//! +//! `Err` results are expected and ignored. Any panic, sanitizer report or OOM +//! is a bug. +//! +//! TODO: timeouts are skipped (`make fuzz` runs libFuzzer in fork mode with +//! `-ignore_timeouts=1`). Mutations easily produce legitimately unbounded +//! queries, e.g. a recursive CTE that never converges, and KiteSQL cannot +//! interrupt a running statement, so they are indistinguishable from real +//! hangs. Revisit once the executor has a cheap interrupt point or the +//! structured generator avoids unbounded queries. + +#![no_main] + +use kite_sql::binder::{command_type, CommandType}; +use kite_sql::db::{prepare_all, DataBaseBuilder, Database, Statement}; +use kite_sql::storage::lmdb::LmdbStorage; +use kite_sql::types::value::DataValue; +use libfuzzer_sys::fuzz_target; +use std::cell::RefCell; + +fuzz_target!(|data: &[u8]| { + let Ok(script) = std::str::from_utf8(data) else { + return; + }; + DB.with_borrow_mut(|db| { + reset(db); + for sql in strip_slt(script).split(';') { + run_one(db, sql); + } + }); +}); + +thread_local! { + // One database per process, reused by every input (emptied before each). + static DB: RefCell> = RefCell::new(open_db()); +} + +fn open_db() -> Database { + let path = std::env::temp_dir().join(format!("kitesql-fuzz-sql_exec-{}", std::process::id())); + let _ = std::fs::remove_dir_all(&path); + DataBaseBuilder::path(path) + .lmdb_no_sync(true) + .build_lmdb() + .expect("lmdb database") +} + +/// Drops every view and table the previous input left behind. +fn reset(db: &mut Database) { + for (show, drop) in [("show views", "drop view"), ("show tables", "drop table")] { + let mut names = Vec::new(); + if let Ok(mut iter) = db.run(show) { + while let Ok(Some(())) = iter.next_tuple(|_, tuple| { + if let Some(DataValue::Utf8 { value, .. }) = tuple.values.first() { + names.push(value.clone()); + } + }) {} + } + for name in names { + let _ = db.ddl(format!("{drop} {name}")); + } + } +} + +/// sqllogictest record headers and directives; such lines never start SQL. +const SLT_DIRECTIVES: &[&str] = &[ + "statement", + "query", + "onlyif", + "skipif", + "control", + "halt", + "hash-threshold", + "subtest", + "sleep", + "include", +]; + +/// Keeps only the SQL of an sqllogictest script. +/// +/// Directives, comments and blank lines become `;` (a record ends at a blank +/// line and `query` SQL usually has no trailing `;`). Expected results, from +/// `----` up to the next blank line, are dropped. +fn strip_slt(script: &str) -> String { + let mut sql = String::with_capacity(script.len()); + let mut in_results = false; + + for line in script.lines() { + let trimmed = line.trim(); + if in_results { + if trimmed.is_empty() { + in_results = false; + sql.push(';'); + } + continue; + } + if trimmed.starts_with("----") { + in_results = true; + sql.push(';'); + } else if trimmed.is_empty() + || trimmed.starts_with('#') + || trimmed + .split_whitespace() + .next() + .is_some_and(|word| SLT_DIRECTIVES.contains(&word)) + { + sql.push(';'); + } else { + sql.push_str(line); + sql.push('\n'); + } + } + sql +} + +fn run_one(db: &mut Database, sql: &str) { + let Ok(statements) = prepare_all(sql) else { + return; + }; + // `split(';')` leaves one statement per chunk except for `;` inside + // string literals; such chunks usually fail to parse and are skipped. + let [statement] = statements.as_slice() else { + return; + }; + let Ok(kind) = command_type(statement) else { + return; + }; + + match kind { + CommandType::DDL => { + let _ = db.ddl(sql); + } + CommandType::Analyze => { + if let Statement::Analyze(analyze) = statement { + if let Some(table_name) = analyze.table_name.as_ref() { + let _ = db.analyze(table_name.to_string()); + } + } + } + _ => { + let Ok(mut iter) = db.run(sql) else { + return; + }; + // Drain and render every value, like the sqllogictest harness does. + loop { + match iter.next_tuple(|_, tuple| { + for value in tuple.values.iter() { + let _ = value.to_string(); + } + }) { + Ok(Some(())) => continue, + Ok(None) => { + let _ = iter.done(); + break; + } + Err(_) => break, + } + } + } + } +} diff --git a/fuzz/fuzz_targets/sql_gen.rs b/fuzz/fuzz_targets/sql_gen.rs new file mode 100644 index 00000000..c6d06d4a --- /dev/null +++ b/fuzz/fuzz_targets/sql_gen.rs @@ -0,0 +1,828 @@ +// Copyright 2024 KipData/KiteSQL +// +// Licensed under the Apache License, Version 2.0 (the "License"); +// you may not use this file except in compliance with the License. +// You may obtain a copy of the License at +// +// http://www.apache.org/licenses/LICENSE-2.0 +// +// Unless required by applicable law or agreed to in writing, software +// distributed under the License is distributed on an "AS IS" BASIS, +// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +// See the License for the specific language governing permissions and +// limitations under the License. + +//! Structured SQL fuzzing over a fixed schema. +//! +//! The input is not SQL text: it drives the choices (rows, tables, columns, +//! expression shapes, literals) of a generator that only emits well-typed +//! queries, so nearly every query binds and reaches the optimizer and executor. +//! +//! Sizes are bounded (three tables of at most `MAX_ROWS` rows, at most 3-way +//! joins, at most one uncorrelated subquery per query, no recursive CTEs or +//! `numbers()`), so unlike `sql_exec` any panic, sanitizer report, timeout or +//! OOM is a bug. `Err` results are expected and ignored. +//! +//! The WHERE predicate is kept apart from the rest of the query so a later +//! oracle (e.g. TLP) can re-render the same query with derived predicates. +//! +//! Set `KITESQL_FUZZ_DEBUG=1` to print every statement before it runs, e.g. +//! when reproducing an artifact. + +#![no_main] + +use kite_sql::db::{DataBaseBuilder, Database}; +use kite_sql::errors::DatabaseError; +use kite_sql::storage::lmdb::LmdbStorage; +use kite_sql::types::value::DataValue; +use libfuzzer_sys::arbitrary::{self, Unstructured}; +use libfuzzer_sys::fuzz_target; +use std::collections::HashMap; +use std::fmt::{Display, Write}; +use std::sync::OnceLock; + +const SCHEMA: &[&str] = &[ + "create table t0(id int primary key, a int, b bigint, c varchar, d double)", + "create table t1(id int primary key, a int, b bigint, c varchar, d double)", + "create table t2(id int primary key, a int, b bigint, c varchar, d double)", + "create index t0_a on t0(a)", + "create unique index t1_b on t1(b)", + "create index t1_ac on t1(a, c)", +]; +const TABLES: &[&str] = &["t0", "t1", "t2"]; +const MAX_ROWS: usize = 8; +const MAX_QUERIES: usize = 8; +const MAX_DEPTH: u32 = 3; + +#[derive(Clone, Copy, PartialEq)] +enum Ty { + Num, + Str, +} + +// Every table has the same columns; `id` is the primary key. +const COLUMNS: &[(&str, Ty)] = &[ + ("id", Ty::Num), + ("a", Ty::Num), + ("b", Ty::Num), + ("c", Ty::Str), + ("d", Ty::Num), +]; + +// Small domains so predicates, joins and GROUP BY actually match rows, +// plus NULL and type boundaries. +const INT_VALUES: &[&str] = &[ + "null", + "0", + "1", + "2", + "3", + "-1", + "2147483647", + "-2147483648", +]; +const BIGINT_VALUES: &[&str] = &[ + "null", + "0", + "1", + "2", + "-1", + "9223372036854775807", + "-9223372036854775808", +]; +const DOUBLE_VALUES: &[&str] = &["null", "0.0", "1.5", "-2.5", "1e300", "-0.0"]; +const STR_VALUES: &[&str] = &["null", "''", "'a'", "'b'", "'ab'", "'A'", "'%'", "'a b'"]; +const NUM_LITERALS: &[&str] = &["null", "0", "1", "2", "-1", "3", "2147483647", "1.5"]; +const INT_LITERALS: &[&str] = &["null", "0", "1", "2", "-1", "3", "2147483647"]; +const LIKE_PATTERNS: &[&str] = &["'a%'", "'%b'", "'_'", "'%'", "''", "'a_'"]; + +const CMP_OPS: &[&str] = &["=", "<>", "<", "<=", ">", ">="]; +const ARITH_OPS: &[&str] = &["+", "-", "*", "/", "%"]; +// `/` always yields a double. +const INT_ARITH_OPS: &[&str] = &["+", "-", "*", "%"]; +const JOINS: &[&str] = &[ + "inner join", + "left join", + "right join", + "full join", + "cross join", +]; +const AGGS: &[&str] = &["count", "sum", "min", "max", "avg"]; + +/// An aggregate call, kept structured so the TLP oracle can point its argument +/// at a column of the partitioned derived table. +struct Agg { + func: &'static str, + distinct: bool, + // `None` is `count(*)`. + arg: Option, +} + +impl Agg { + fn render(&self, arg: Option<&str>) -> String { + match arg { + None => format!("{}(*)", self.func), + Some(arg) if self.distinct => format!("{}(distinct {arg})", self.func), + Some(arg) => format!("{}({arg})", self.func), + } + } +} + +enum Body { + Plain { + distinct: bool, + items: Vec, + }, + Grouped { + keys: Vec, + aggs: Vec, + // `having ` + having: Option<(Agg, &'static str, &'static str)>, + }, +} + +/// A generated query. The WHERE predicate is kept apart so the TLP oracle can +/// re-render the query with derived predicates. +struct Select { + from: String, + predicate: Option, + body: Body, + // (output column, descending) + order_by: Option<(usize, bool)>, + // (limit, offset) + limit: Option<(usize, Option)>, +} + +impl Select { + /// The query as generated, optionally without its WHERE clause and/or its + /// LIMIT / OFFSET. + fn render(&self, with_predicate: bool, with_limit: bool) -> String { + let mut sql = String::from("select "); + let mut tail = String::new(); + match &self.body { + Body::Plain { distinct, items } => { + if *distinct { + sql.push_str("distinct "); + } + aliased(&mut sql, items.iter()); + } + Body::Grouped { keys, aggs, having } => { + let outputs = keys + .iter() + .cloned() + .chain(aggs.iter().map(|agg| agg.render(agg.arg.as_deref()))); + aliased(&mut sql, outputs); + if !keys.is_empty() { + let _ = write!(tail, " group by {}", keys.join(", ")); + } + if let Some((agg, op, literal)) = having { + let _ = write!( + tail, + " having {} {op} {literal}", + agg.render(agg.arg.as_deref()) + ); + } + } + } + let _ = write!(sql, " from {}", self.from); + if let (true, Some(predicate)) = (with_predicate, &self.predicate) { + let _ = write!(sql, " where {predicate}"); + } + sql.push_str(&tail); + sql.push_str(&self.order_limit(with_limit)); + sql + } + + /// ORDER BY / LIMIT over the output columns `c0, c1, ...`. + fn order_limit(&self, with_limit: bool) -> String { + let mut sql = String::new(); + if let Some((column, desc)) = self.order_by { + let _ = write!( + sql, + " order by c{column}{}", + if desc { " desc" } else { "" } + ); + } + if let (true, Some((limit, offset))) = (with_limit, self.limit) { + let _ = write!(sql, " limit {limit}"); + if let Some(offset) = offset { + let _ = write!(sql, " offset {offset}"); + } + } + sql + } + /// TLP form: rows are split by `p`, `not p` and `p is null` (exactly one + /// holds per row), recombined with UNION ALL in a derived table, and the + /// rest of the query (DISTINCT, GROUP BY, aggregates, HAVING, ORDER BY, + /// LIMIT) is applied on top. It must return what the query without the + /// WHERE clause returns. + fn render_tlp(&self, predicate: &str, with_limit: bool) -> String { + // Columns each partition exposes, and the outer select over them. + let mut inner = Vec::new(); + let mut outer = String::from("select "); + let mut tail = String::new(); + match &self.body { + Body::Plain { distinct, items } => { + if *distinct { + outer.push_str("distinct "); + } + for (i, item) in items.iter().enumerate() { + inner.push(format!("{item} as x{i}")); + } + aliased(&mut outer, (0..items.len()).map(|i| format!("u.x{i}"))); + } + Body::Grouped { keys, aggs, having } => { + let mut outputs = Vec::new(); + for (i, key) in keys.iter().enumerate() { + inner.push(format!("{key} as x{i}")); + outputs.push(format!("u.x{i}")); + } + let key_refs = outputs.clone(); + // Moves an aggregate's argument into the partitions and + // aggregates the matching derived-table column instead. + let mut retarget = |agg: &Agg| match &agg.arg { + None => agg.render(None), + Some(arg) => { + let column = format!("x{}", inner.len()); + inner.push(format!("{arg} as {column}")); + agg.render(Some(&format!("u.{column}"))) + } + }; + for agg in aggs { + outputs.push(retarget(agg)); + } + if !key_refs.is_empty() { + let _ = write!(tail, " group by {}", key_refs.join(", ")); + } + if let Some((agg, op, literal)) = having { + let _ = write!(tail, " having {} {op} {literal}", retarget(agg)); + } + aliased(&mut outer, outputs.iter()); + } + } + // e.g. `select count(*) ...`: the partitions still need a column. + if inner.is_empty() { + inner.push("1 as x0".to_string()); + } + let columns = inner.join(", "); + let parts = [ + predicate.to_string(), + format!("not ({predicate})"), + format!("({predicate}) is null"), + ] + .map(|p| format!("select {columns} from {} where {p}", self.from)) + .join(" union all "); + format!( + "{outer} from ({parts}) as u{tail}{}", + self.order_limit(with_limit) + ) + } +} + +/// `e0 as c0, e1 as c1, ...` +fn aliased(sql: &mut String, exprs: impl Iterator) { + for (i, expr) in exprs.enumerate() { + let sep = if i == 0 { "" } else { ", " }; + let _ = write!(sql, "{sep}{expr} as c{i}"); + } +} + +struct Gen<'a, 'b> { + u: &'b mut Unstructured<'a>, + // Remaining subqueries for the current query (KiteSQL rejects some mixes). + subqueries: u32, + // KiteSQL only accepts EXISTS / IN subqueries in WHERE. + in_where: bool, + // Numeric expressions stay integral (no `d`, float literals or `/`). + ints_only: bool, + next_alias: u32, +} + +impl<'a, 'b> Gen<'a, 'b> { + fn pick<'x, T: Copy + 'x>( + &mut self, + items: impl IntoIterator, + ) -> arbitrary::Result { + let mut items = items.into_iter(); + let i = self.below(items.clone().count())?; + Ok(*items.nth(i).expect("index below the item count")) + } + + fn below(&mut self, n: usize) -> arbitrary::Result { + // Exhausted input yields 0, which is always the simplest choice. + self.u.choose_index(n) + } + + fn alias(&mut self) -> String { + self.next_alias += 1; + format!("q{}", self.next_alias) + } + + fn flag(&mut self, one_in: usize) -> arbitrary::Result { + // Exhausted input yields false (`Unstructured::ratio` would yield true). + Ok(self.below(one_in)? == 1) + } + + fn column(&mut self, scope: &[String], ty: Ty) -> arbitrary::Result { + let alias = &scope[self.below(scope.len())?]; + let ints_only = self.ints_only; + let name = self.pick( + COLUMNS + .iter() + .filter(|(name, t)| *t == ty && !(ints_only && *name == "d")) + .map(|(name, _)| name), + )?; + Ok(format!("{alias}.{name}")) + } + + /// Runs `f` with subqueries disabled (e.g. inside aggregates or ON). + fn without_subqueries( + &mut self, + f: impl FnOnce(&mut Self) -> arbitrary::Result, + ) -> arbitrary::Result { + let saved = std::mem::replace(&mut self.subqueries, 0); + let result = f(self); + self.subqueries = saved; + result + } + + fn num_expr(&mut self, scope: &[String], depth: u32) -> arbitrary::Result { + let choices = if depth == 0 { 2 } else { 8 }; + let next = depth.saturating_sub(1); + Ok(match self.below(choices)? { + 0 => self.column(scope, Ty::Num)?, + 1 => { + let literals = if self.ints_only { + INT_LITERALS + } else { + NUM_LITERALS + }; + self.pick(literals)?.to_string() + } + 2 => { + let l = self.num_expr(scope, next)?; + let ops = if self.ints_only { + INT_ARITH_OPS + } else { + ARITH_OPS + }; + let op = self.pick(ops)?; + let r = self.num_expr(scope, next)?; + format!("({l} {op} {r})") + } + // The space matters: `--1` would start a comment. + 3 => format!("(- {})", self.num_expr(scope, next)?), + 4 => { + let c = self.bool_expr(scope, next)?; + let t = self.num_expr(scope, next)?; + let e = self.num_expr(scope, next)?; + format!("(case when {c} then {t} else {e} end)") + } + 5 => { + let f = self.pick(&["coalesce", "nullif"])?; + let l = self.num_expr(scope, next)?; + let r = self.num_expr(scope, next)?; + format!("{f}({l}, {r})") + } + 6 => format!("char_length({})", self.str_expr(scope, next)?), + _ => match self.scalar_subquery()? { + Some(subquery) => subquery, + None => self.column(scope, Ty::Num)?, + }, + }) + } + + fn str_expr(&mut self, scope: &[String], depth: u32) -> arbitrary::Result { + let choices = if depth == 0 { 2 } else { 5 }; + let next = depth.saturating_sub(1); + Ok(match self.below(choices)? { + 0 => self.column(scope, Ty::Str)?, + 1 => self.pick(STR_VALUES)?.to_string(), + 2 => { + let f = self.pick(&["lower", "upper"])?; + format!("{f}({})", self.str_expr(scope, next)?) + } + 3 => { + let c = self.bool_expr(scope, next)?; + let t = self.str_expr(scope, next)?; + let e = self.str_expr(scope, next)?; + format!("(case when {c} then {t} else {e} end)") + } + _ => { + let l = self.str_expr(scope, next)?; + let r = self.str_expr(scope, next)?; + format!("coalesce({l}, {r})") + } + }) + } + + fn bool_expr(&mut self, scope: &[String], depth: u32) -> arbitrary::Result { + let choices = if depth == 0 { 3 } else { 10 }; + let next = depth.saturating_sub(1); + Ok(match self.below(choices)? { + 0 => { + let l = self.num_expr(scope, next)?; + let op = self.pick(CMP_OPS)?; + let r = self.num_expr(scope, next)?; + format!("({l} {op} {r})") + } + 1 => { + let l = self.str_expr(scope, next)?; + let op = self.pick(CMP_OPS)?; + let r = self.str_expr(scope, next)?; + format!("({l} {op} {r})") + } + 2 => { + let ty = if self.flag(2)? { Ty::Str } else { Ty::Num }; + let not = if self.flag(2)? { " not" } else { "" }; + format!("({} is{not} null)", self.column(scope, ty)?) + } + 3 => format!("(not {})", self.bool_expr(scope, next)?), + 4 | 5 => { + let l = self.bool_expr(scope, next)?; + let op = self.pick(&["and", "or"])?; + let r = self.bool_expr(scope, next)?; + format!("({l} {op} {r})") + } + 6 => { + let e = self.num_expr(scope, next)?; + let not = if self.flag(2)? { " not" } else { "" }; + let lo = self.pick(NUM_LITERALS)?; + let hi = self.pick(NUM_LITERALS)?; + format!("({e}{not} between {lo} and {hi})") + } + 7 => { + let e = self.num_expr(scope, next)?; + let not = if self.flag(2)? { " not" } else { "" }; + let len = self.below(3)? + 1; + let mut list = Vec::with_capacity(len); + for _ in 0..len { + list.push(self.pick(NUM_LITERALS)?); + } + format!("({e}{not} in ({}))", list.join(", ")) + } + 8 => { + let e = self.str_expr(scope, next)?; + let not = if self.flag(2)? { " not" } else { "" }; + format!("({e}{not} like {})", self.pick(LIKE_PATTERNS)?) + } + _ => match self.subquery_predicate(scope)? { + Some(predicate) => predicate, + None => format!("({} is not null)", self.column(scope, Ty::Num)?), + }, + }) + } + + /// Consumes one unit of the subquery budget; `false` if none is left. + fn take_subquery(&mut self) -> bool { + if self.subqueries == 0 { + return false; + } + self.subqueries -= 1; + true + } + + fn single_table(&mut self) -> arbitrary::Result<(String, String)> { + let table = self.pick(TABLES)?; + let alias = self.alias(); + Ok((format!("{table} as {alias}"), alias)) + } + + /// Uncorrelated `(select agg(expr) from t where p)`. + fn scalar_subquery(&mut self) -> arbitrary::Result> { + if !self.take_subquery() { + return Ok(None); + } + let (from, alias) = self.single_table()?; + let scope = [alias]; + let agg = self.pick(&["count", "sum", "min", "max"])?; + let arg = self.num_expr(&scope, 1)?; + let mut sql = format!("(select {agg}({arg}) from {from}"); + if self.flag(2)? { + let _ = write!(sql, " where {}", self.bool_expr(&scope, 1)?); + } + sql.push(')'); + Ok(Some(sql)) + } + + /// Uncorrelated `[not] exists (...)` or `expr [not] in (select ...)`. + fn subquery_predicate(&mut self, outer: &[String]) -> arbitrary::Result> { + if !self.in_where || !self.take_subquery() { + return Ok(None); + } + let (from, alias) = self.single_table()?; + let scope = [alias]; + let predicate = self.bool_expr(&scope, 1)?; + let not = if self.flag(2)? { "not " } else { "" }; + Ok(Some(if self.flag(2)? { + format!("({not}exists (select 1 from {from} where {predicate}))") + } else { + let e = self.num_expr(outer, 1)?; + let column = self.column(&scope, Ty::Num)?; + format!("({e} {not}in (select {column} from {from} where {predicate}))") + })) + } + + /// `t as q1 [join t as q2 on ...] [join ...]`, at most 3 tables. + fn from(&mut self) -> arbitrary::Result<(String, Vec)> { + let (mut from, alias) = self.single_table()?; + let mut scope = vec![alias]; + for _ in 0..self.below(3)? { + let join = self.pick(JOINS)?; + let (table, alias) = self.single_table()?; + let left = scope[self.below(scope.len())?].clone(); + scope.push(alias.clone()); + let _ = write!(from, " {join} {table}"); + if join != "cross join" { + // Bias towards equi-joins so hash joins are exercised. + let on = if self.flag(3)? { + self.without_subqueries(|g| g.bool_expr(&scope, 1))? + } else { + let l = self.pick(&["id", "a", "b"])?; + let r = self.pick(&["id", "a", "b"])?; + format!("{left}.{l} = {alias}.{r}") + }; + let _ = write!(from, " on {on}"); + } + } + Ok((from, scope)) + } + + fn aggregate(&mut self, scope: &[String]) -> arbitrary::Result { + Ok(match self.below(3)? { + 0 => Agg { + func: "count", + distinct: false, + arg: None, + }, + 1 => Agg { + func: "count", + distinct: true, + arg: Some(self.column(scope, Ty::Num)?), + }, + _ => { + let func = self.pick(AGGS)?; + // Integral arguments keep `sum` / `avg` exact whatever the row + // order, which differs between a query and its TLP form. + let saved = std::mem::replace(&mut self.ints_only, matches!(func, "sum" | "avg")); + let arg = self.without_subqueries(|g| g.num_expr(scope, 1)); + self.ints_only = saved; + Agg { + func, + distinct: false, + arg: Some(arg?), + } + } + }) + } + + fn select(&mut self) -> arbitrary::Result