This commit implements the Cargo.lock policy for reproducible builds across all workspace members (pdftract-core, pdftract-cli, pdftract-py). Changes: - Add CONTRIBUTING.md with lockfile-update workflow documentation - Add .renovaterc.json for weekly lockfile-only PRs (human-gated) - Add crates/pdftract-core/README.md with rationale for checked-in lockfiles - Add notes/pdftract-49f8.md with verification note The Argo workflow updates (pdftract-ci.yaml) are committed separately in the declarative-config repo. Acceptance criteria: - PASS: Cargo.lock tracked by git, not in .gitignore - PASS: Argo workflow templates document --locked/--frozen requirements - WARN: Enforcement to be completed when placeholder templates are implemented - WARN: Binary reproducibility verification deferred to pdftract-build-binaries implementation Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
23 lines
733 B
Rust
23 lines
733 B
Rust
//! Fuzz target for the PDF xref parser.
|
|
//!
|
|
//! This target tests INV-8 (no panic at public boundary) for the xref parser.
|
|
//! Any panic indicates an xref parser bug that must be fixed.
|
|
|
|
#![no_main]
|
|
use libfuzzer_sys::fuzz_target;
|
|
|
|
fuzz_target!(|data: &[u8]| {
|
|
use pdftract_core::parser::xref::{parse_traditional_xref, forward_scan_xref};
|
|
use pdftract_core::parser::stream::MemorySource;
|
|
|
|
let source = MemorySource::new(data.to_vec());
|
|
|
|
// Test parse_traditional_xref - must never panic
|
|
let _ = parse_traditional_xref(&source, 0);
|
|
|
|
// Test forward_scan_xref - must never panic
|
|
let _ = forward_scan_xref(&source, false);
|
|
|
|
// Test with linearized flag
|
|
let _ = forward_scan_xref(&source, true);
|
|
});
|