Skip to content

test(api): add native fuzz test for version whitelist - #422

Merged
KeiaiLab-PHIL merged 1 commit into
mainfrom
test/fuzz-mongo-version
Oct 6, 2026
Merged

KeiaiLab-PHIL merged 1 commit into
mainfrom
test/fuzz-mongo-version

Conversation

@KeiaiLab-PHIL

Copy link
Copy Markdown
Contributor

What / why

Scorecard Fuzzing alert: no fuzz target. spec.version.version reaches the admission webhook as an arbitrary string, so FuzzIsSupportedMongoDBVersion (Go native fuzzing) checks:

  • no panic in IsSupportedMongoDBVersion, parseMongoVersion, IsValidUpgradePath
  • whitelist acceptance ⇒ parseMongoVersion succeeds and the parsed major.minor is in SupportedMongoDBVersions (the reverse does not hold by design: "08.0" parses to (8,0) but is rejected).

Seeds: 8.0, 8.3.1, 9.0.2, 7.0, "", x.y.

Verification

  • go test -run=^$ -fuzz=FuzzIsSupportedMongoDBVersion -fuzztime=5s ./api/v1alpha1/ → PASS (~900k execs)
  • seed corpus runs as a normal test in go test ./...

🤖 Generated with Claude Code

Scorecard reports no fuzzing. The version string reaches the
admission webhook unfiltered, so FuzzIsSupportedMongoDBVersion
checks it never panics and that whitelist acceptance implies
parseMongoVersion reads the same major.minor.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Signed-off-by: phil <phil@keiailab.com>
@KeiaiLab-PHIL
KeiaiLab-PHIL enabled auto-merge (squash) October 6, 2026 02:08
@KeiaiLab-PHIL
KeiaiLab-PHIL merged commit 82ac7ba into main Oct 6, 2026
10 checks passed
@KeiaiLab-PHIL
KeiaiLab-PHIL deleted the test/fuzz-mongo-version branch October 6, 2026 02:25
KeiaiLab-PHIL added a commit that referenced this pull request Oct 6, 2026
Security release, also a code release: tag, chart version and
appVersion are aligned so release.yml builds and publishes the image.

Includes: Go toolchain 1.26.8 and vulnerable module bumps (#411),
workflow hardening (#412), Dependabot (#413), MongoDB 9.0 support with
9.0.2 and exporter 0.53.0 as defaults (#414), fuzz test (#422).

Bundle regenerated with `make bundle VERSION=1.16.10` (ADR-0038
parity). artifacthub.io/images moves the operator to v1.16.10 and
keeps the upstream mongo/exporter images whitelisted;
containsSecurityUpdates is true.

Signed-off-by: phil <phil@keiailab.com>
Co-authored-by: Claude Fable 5.1 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant