JSON fuzzer: use options for handling invalid UTF-8 and big strings - #23877
Open
DanielEScherzer wants to merge 1 commit into
Open
DanielEScherzer wants to merge 1 commit into
DanielEScherzer wants to merge 1 commit into
Conversation
Previously, the fuzzer only used the default options (`0`) and the `PHP_JSON_OBJECT_AS_ARRAY` option (`1`). After running the fuzzer on its existing corpus with `-reduce_inputs=0`, `-runs=100000`, and `-seed=1`, it failed to reach the code paths for handling big integers and strings, or for dealing with invalid UTF8, within the allotted 100,000 runs. Those 100,000 runs resulted in coverage of roughly 2,020 code blocks or edges, and roughly 5,400 "features". Expand the fuzzer to also run with options that include the `PHP_JSON_BIGINT_AS_STRING`, `PHP_JSON_INVALID_UTF8_IGNORE`, and `PHP_JSON_INVALID_UTF8_SUBSTITUTE` flags. The two flags for handling UTF-8 are not applied used together, since invalid UTF-8 can only be handled one way, but other than that all combinations of these flags and `PHP_JSON_OBJECT_AS_ARRAY` are now tested. Repeating the same fuzzing as earlier with the expanded options results in roughly 2,150 code blocks or edges, and roughly 5,700 "features", being covered.
TimWolla
approved these changes
Sep 24, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Previously, the fuzzer only used the default options (
0) and thePHP_JSON_OBJECT_AS_ARRAYoption (1). After running the fuzzer on its existing corpus with-reduce_inputs=0,-runs=100000, and-seed=1, it failed to reach the code paths for handling big integers and strings, or for dealing with invalid UTF8, within the allotted 100,000 runs. Those 100,000 runs resulted in coverage of roughly 2,020 code blocks or edges, and roughly 5,400 "features".Expand the fuzzer to also run with options that include the
PHP_JSON_BIGINT_AS_STRING,PHP_JSON_INVALID_UTF8_IGNORE, andPHP_JSON_INVALID_UTF8_SUBSTITUTEflags. The two flags for handling UTF-8 are not applied used together, since invalid UTF-8 can only be handled one way, but other than that all combinations of these flags andPHP_JSON_OBJECT_AS_ARRAYare now tested. Repeating the same fuzzing as earlier with the expanded options results in roughly 2,150 code blocks or edges, and roughly 5,700 "features", being covered.