diff --git a/.clusterfuzzlite/Dockerfile b/.clusterfuzzlite/Dockerfile new file mode 100644 index 0000000..3503cee --- /dev/null +++ b/.clusterfuzzlite/Dockerfile @@ -0,0 +1,21 @@ +# SPDX-License-Identifier: MPL-2.0 +# ClusterFuzzLite build image for rpa-elysium (language: rust). +# +# Per ClusterFuzzLite's build-integration docs, this file MUST be named +# `Dockerfile` inside `.clusterfuzzlite/` — the build action looks for +# exactly that path. The repo previously shipped the same content as +# `.clusterfuzzlite/Containerfile`, which the action never reads; every +# fuzz run failed with "failed to read dockerfile: open Dockerfile: no +# such file or directory". +FROM gcr.io/oss-fuzz-base/base-builder-rust + +RUN apt-get update && apt-get install -y make autoconf automake libtool + +# base-builder-rust ships the pinned nightly toolchain and cargo-fuzz +# pre-installed (see CFL docs, "Integrating a Rust project"); nothing +# else to install for this project. + +COPY . $SRC/project +WORKDIR $SRC/project + +COPY .clusterfuzzlite/build.sh $SRC/ diff --git a/.clusterfuzzlite/build.sh b/.clusterfuzzlite/build.sh index 12c912a..576b795 100755 --- a/.clusterfuzzlite/build.sh +++ b/.clusterfuzzlite/build.sh @@ -8,7 +8,7 @@ # 'nightly' is not installed". # * $SANITIZER is exported by ClusterFuzzLite (address | undefined) and must # be forwarded so each matrix build instruments for its own sanitizer. -# * cargo-fuzz is installed by the root Dockerfile. +# * cargo-fuzz ships pre-installed in base-builder-rust (CFL rust docs). cd "$SRC/project" cargo fuzz build --release --sanitizer "$SANITIZER" # Copy only the fuzz binary — the `fuzz_*` glob also matched .d files. diff --git a/Dockerfile b/Dockerfile deleted file mode 100644 index 97e9de0..0000000 --- a/Dockerfile +++ /dev/null @@ -1,21 +0,0 @@ -# SPDX-License-Identifier: MPL-2.0 -# ClusterFuzzLite build image for rpa-elysium (language: rust). -# -# ClusterFuzzLite's build_fuzzers action requires this file at the repository -# ROOT, named exactly `Dockerfile`. A previous copy lived at -# .clusterfuzzlite/Containerfile, which the action never reads — every fuzz -# run failed with "failed to read dockerfile: open Dockerfile: no such file -# or directory". This file supersedes it. -FROM gcr.io/oss-fuzz-base/base-builder-rust - -RUN apt-get update && apt-get install -y make autoconf automake libtool - -# base-builder-rust ships the pinned nightly toolchain (RUSTUP_TOOLCHAIN) but -# not cargo-fuzz itself; install it so .clusterfuzzlite/build.sh can run -# `cargo fuzz build`. -RUN cargo install cargo-fuzz --locked - -COPY . $SRC/project -WORKDIR $SRC/project - -COPY .clusterfuzzlite/build.sh $SRC/