From 75cc63a6699a3b0222149ab5132aff223d0c9e84 Mon Sep 17 00:00:00 2001 From: Bruno Postle Date: Sun, 19 Jul 2026 22:12:27 +0100 Subject: [PATCH] fuzz: update harness for ifcopenshell::file rename ifcviewer-wgpu renamed IfcParse::IfcFile to ifcopenshell::file (header moved to ifcparse/file.h) and Base::toString to Base::to_string. Update the harness and README to match; verified with a syntax-only compile against this branch's headers. --- src/ifcfuzz/README.md | 9 +++++---- src/ifcfuzz/ifcparse_fuzzer.cpp | 16 ++++++++-------- 2 files changed, 13 insertions(+), 12 deletions(-) diff --git a/src/ifcfuzz/README.md b/src/ifcfuzz/README.md index df1a07d157..a6bbe04aac 100644 --- a/src/ifcfuzz/README.md +++ b/src/ifcfuzz/README.md @@ -1,10 +1,11 @@ # ifcparse_fuzzer -A libFuzzer harness for `IfcParse::IfcFile`. It parses fuzzer input entirely +A libFuzzer harness for `ifcopenshell::file`. It parses fuzzer input entirely in-memory (no subprocess, no temp files), then walks every parsed instance -and calls `toString()` on it to force full lazy attribute evaluation - -IfcOpenShell only tokenizes/evaluates on demand, so just constructing -`IfcFile` barely exercises the parser. +and calls `to_string()` on it. Constructing the file already tokenizes, +type-checks, and resolves every attribute of every instance, so +`to_string()` mainly adds coverage of the reserialization/formatting code +path rather than the parser itself. Disabled by default (`BUILD_FUZZERS=OFF`); building it needs Clang, not GCC. diff --git a/src/ifcfuzz/ifcparse_fuzzer.cpp b/src/ifcfuzz/ifcparse_fuzzer.cpp index e7075b1288..2b4468e5b8 100644 --- a/src/ifcfuzz/ifcparse_fuzzer.cpp +++ b/src/ifcfuzz/ifcparse_fuzzer.cpp @@ -17,12 +17,12 @@ * * ********************************************************************************/ -// libFuzzer entry point for IfcParse::IfcFile. Parses the input entirely +// libFuzzer entry point for ifcopenshell::file. Parses the input entirely // in-memory (no subprocess, no temp files) so a coverage-guided fuzzer can // reach the tokenizer and argument parser directly instead of only ever // observing IfcConvert's exit code. -#include "ifcparse/IfcFile.h" +#include "ifcparse/file.h" #include #include @@ -35,19 +35,19 @@ extern "C" int LLVMFuzzerTestOneInput(const uint8_t* data, size_t size) { } try { - IfcParse::IfcFile file(const_cast(static_cast(data)), static_cast(size)); + ifcopenshell::file ifc_file(const_cast(static_cast(data)), static_cast(size)); - if (file.good()) { - // Constructing IfcFile already tokenizes and type-checks every + if (ifc_file.good()) { + // Constructing the file already tokenizes and type-checks every // attribute of every instance (and resolves references), so // most tokenizer/argument bugs are reachable without going any - // further. toString() is still exercised here since + // further. to_string() is still exercised here since // reserialization walks a different code path and may surface // additional faults. std::ostringstream discard; - for (const auto& entity : file) { + for (const auto& entity : ifc_file) { try { - entity.second->toString(discard); + entity.second.to_string(discard); } catch (const std::exception&) { // Malformed attributes are expected on fuzzed input. }