fuzz: new parser findings 2026-07-13 - #1288
Merged
Merged
Conversation
keithamus
enabled auto-merge (squash)
July 14, 2026 08:54
keithamus
force-pushed
the
fuzz/findings-20260713-030545
branch
from
July 14, 2026 08:58
e68f809 to
4542d71
Compare
✅ CI passed
|
github-actions Bot
pushed a commit
that referenced
this pull request
Jul 25, 2026
## [0.0.28] - 2026-07-25 ### Other Changes - Chore(deps): update dependencies (patch) (#1300) ([#1300](#1300)) ### Css_ast - csskit_derives: Add peek(skip) attribute (#1266) ([#1266](#1266)) - Regenerate css_ast/src/values from csswg drafts (#1267) ([#1267](#1267)) - css_parse/csskit_derives: Add semantic_eq(skip) to derive(SemanticEq) (#1272) ([#1272](#1272)) - css_ast: Implement various shape functions for clip-path, etc (#1275) ([#1275](#1275)) - css_ast: Use blocks for Container & Style at rules (#1276) ([#1276](#1276)) - css_ast: Add more -moz-meter-* pseudo elements/classes (#1277) ([#1277](#1277)) - css_ast: Refactor and improve `@supports` parsing (#1278) ([#1278](#1278)) - css_ast: Implement fill & stroke (#1279) ([#1279](#1279)) - css_ast: Implement webkit-text-stroek (#1280) ([#1280](#1280)) - css_ast Implement grid functions, track, line, etc (#1281) ([#1281](#1281)) - css_ast/css_parse: Implement ToNormalisedValue trait (#1284) ([#1284](#1284)) - Regenerate css_ast/src/values from csswg drafts (#1285) ([#1285](#1285)) - Regenerate css_ast/src/values from csswg drafts (#1294) ([#1294](#1294)) - csskit_derives: Allow multiple fields to delegate metadata (#1295) ([#1295](#1295)) - css_parse: Reimplement computed value declaration peeking/parsing in DeclarationValue (#1298) ([#1298](#1298)) - css_parse: Refactor BumpBox into generic Arena allocating Box. (#1304) ([#1304](#1304)) - css_parse: Implement an Arena allocated Vec. (#1306) ([#1306](#1306)) - css_ast: Build out substitution function architecture (#1308) ([#1308](#1308)) - css_ast: Use Value/CalcableValue in most manual types (#1309) ([#1309](#1309)) ### Css_feature_data - Regenerate css_ast/src/values from csswg drafts (#1299) ([#1299](#1299)) ### Css_lexer - css_lexer/csskit: Implement LineIndex, precomputing line offsets (#1264) ([#1264](#1264)) - css_lexer: Use a boxed slice in LineIndex, dropping Bumpalo's Vec. (#1305) ([#1305](#1305)) - css_lexer: Implement fearless_simd paths for scanning (#1307) ([#1307](#1307)) ### Css_parse - fuzz: new parser findings 2026-07-13 (#1288) ([#1288](#1288)) - css_parse: Drop CursorSource trait (#1296) ([#1296](#1296)) - css_parse: Drop PreludeList, DeclarationRuleList (#1297) ([#1297](#1297)) ### Csskit - chore(deps): update dependencies (patch) (#1268) ([#1268](#1268)) ### Csskit_derives - csskit_derives: Ensure atom checks properly peek (#1282) ([#1282](#1282)) ### Csskit_spec_generator - csskit_spec_generator: Ensure property atoms includes the extra properties (#1283) ([#1283](#1283)) ### Csskit_vscode - chore(deps): update dependency @types/node to v24.13.2 (#1269) ([#1269](#1269)) - chore(deps): update dependency @types/vscode to v1.125.0 (#1270) ([#1270](#1270)) - chore(deps): update dependency typescript to v7 (#1273) ([#1273](#1273)) - chore(deps): update dependencies (patch) (#1286) ([#1286](#1286)) - chore(deps): update dependency oxlint to v1.69.0 (#1303) ([#1303](#1303)) [forcebuild]
Merged
github-actions Bot
pushed a commit
that referenced
this pull request
Jul 25, 2026
## [0.0.28] - 2026-07-25 ### Other Changes - Chore(deps): update dependencies (patch) (#1300) ([#1300](#1300)) ### Css_ast - csskit_derives: Add peek(skip) attribute (#1266) ([#1266](#1266)) - Regenerate css_ast/src/values from csswg drafts (#1267) ([#1267](#1267)) - css_parse/csskit_derives: Add semantic_eq(skip) to derive(SemanticEq) (#1272) ([#1272](#1272)) - css_ast: Implement various shape functions for clip-path, etc (#1275) ([#1275](#1275)) - css_ast: Use blocks for Container & Style at rules (#1276) ([#1276](#1276)) - css_ast: Add more -moz-meter-* pseudo elements/classes (#1277) ([#1277](#1277)) - css_ast: Refactor and improve `@supports` parsing (#1278) ([#1278](#1278)) - css_ast: Implement fill & stroke (#1279) ([#1279](#1279)) - css_ast: Implement webkit-text-stroek (#1280) ([#1280](#1280)) - css_ast Implement grid functions, track, line, etc (#1281) ([#1281](#1281)) - css_ast/css_parse: Implement ToNormalisedValue trait (#1284) ([#1284](#1284)) - Regenerate css_ast/src/values from csswg drafts (#1285) ([#1285](#1285)) - Regenerate css_ast/src/values from csswg drafts (#1294) ([#1294](#1294)) - csskit_derives: Allow multiple fields to delegate metadata (#1295) ([#1295](#1295)) - css_parse: Reimplement computed value declaration peeking/parsing in DeclarationValue (#1298) ([#1298](#1298)) - css_parse: Refactor BumpBox into generic Arena allocating Box. (#1304) ([#1304](#1304)) - css_parse: Implement an Arena allocated Vec. (#1306) ([#1306](#1306)) - css_ast: Build out substitution function architecture (#1308) ([#1308](#1308)) - css_ast: Use Value/CalcableValue in most manual types (#1309) ([#1309](#1309)) ### Css_feature_data - Regenerate css_ast/src/values from csswg drafts (#1299) ([#1299](#1299)) ### Css_lexer - css_lexer/csskit: Implement LineIndex, precomputing line offsets (#1264) ([#1264](#1264)) - css_lexer: Use a boxed slice in LineIndex, dropping Bumpalo's Vec. (#1305) ([#1305](#1305)) - css_lexer: Implement fearless_simd paths for scanning (#1307) ([#1307](#1307)) ### Css_parse - fuzz: new parser findings 2026-07-13 (#1288) ([#1288](#1288)) - css_parse: Drop CursorSource trait (#1296) ([#1296](#1296)) - css_parse: Drop PreludeList, DeclarationRuleList (#1297) ([#1297](#1297)) ### Csskit - chore(deps): update dependencies (patch) (#1268) ([#1268](#1268)) ### Csskit_derives - csskit_derives: Ensure atom checks properly peek (#1282) ([#1282](#1282)) ### Csskit_spec_generator - csskit_spec_generator: Ensure property atoms includes the extra properties (#1283) ([#1283](#1283)) ### Csskit_vscode - chore(deps): update dependency @types/node to v24.13.2 (#1269) ([#1269](#1269)) - chore(deps): update dependency @types/vscode to v1.125.0 (#1270) ([#1270](#1270)) - chore(deps): update dependency typescript to v7 (#1273) ([#1273](#1273)) - chore(deps): update dependencies (patch) (#1286) ([#1286](#1286)) - chore(deps): update dependency oxlint to v1.69.0 (#1303) ([#1303](#1303))
keithamus
added a commit
that referenced
this pull request
Jul 25, 2026
## [0.0.28] - 2026-07-25 ### Other Changes - Chore(deps): update dependencies (patch) (#1300) ([#1300](#1300)) ### Css_ast - csskit_derives: Add peek(skip) attribute (#1266) ([#1266](#1266)) - Regenerate css_ast/src/values from csswg drafts (#1267) ([#1267](#1267)) - css_parse/csskit_derives: Add semantic_eq(skip) to derive(SemanticEq) (#1272) ([#1272](#1272)) - css_ast: Implement various shape functions for clip-path, etc (#1275) ([#1275](#1275)) - css_ast: Use blocks for Container & Style at rules (#1276) ([#1276](#1276)) - css_ast: Add more -moz-meter-* pseudo elements/classes (#1277) ([#1277](#1277)) - css_ast: Refactor and improve `@supports` parsing (#1278) ([#1278](#1278)) - css_ast: Implement fill & stroke (#1279) ([#1279](#1279)) - css_ast: Implement webkit-text-stroek (#1280) ([#1280](#1280)) - css_ast Implement grid functions, track, line, etc (#1281) ([#1281](#1281)) - css_ast/css_parse: Implement ToNormalisedValue trait (#1284) ([#1284](#1284)) - Regenerate css_ast/src/values from csswg drafts (#1285) ([#1285](#1285)) - Regenerate css_ast/src/values from csswg drafts (#1294) ([#1294](#1294)) - csskit_derives: Allow multiple fields to delegate metadata (#1295) ([#1295](#1295)) - css_parse: Reimplement computed value declaration peeking/parsing in DeclarationValue (#1298) ([#1298](#1298)) - css_parse: Refactor BumpBox into generic Arena allocating Box. (#1304) ([#1304](#1304)) - css_parse: Implement an Arena allocated Vec. (#1306) ([#1306](#1306)) - css_ast: Build out substitution function architecture (#1308) ([#1308](#1308)) - css_ast: Use Value/CalcableValue in most manual types (#1309) ([#1309](#1309)) ### Css_feature_data - Regenerate css_ast/src/values from csswg drafts (#1299) ([#1299](#1299)) ### Css_lexer - css_lexer/csskit: Implement LineIndex, precomputing line offsets (#1264) ([#1264](#1264)) - css_lexer: Use a boxed slice in LineIndex, dropping Bumpalo's Vec. (#1305) ([#1305](#1305)) - css_lexer: Implement fearless_simd paths for scanning (#1307) ([#1307](#1307)) ### Css_parse - fuzz: new parser findings 2026-07-13 (#1288) ([#1288](#1288)) - css_parse: Drop CursorSource trait (#1296) ([#1296](#1296)) - css_parse: Drop PreludeList, DeclarationRuleList (#1297) ([#1297](#1297)) ### Csskit - chore(deps): update dependencies (patch) (#1268) ([#1268](#1268)) ### Csskit_derives - csskit_derives: Ensure atom checks properly peek (#1282) ([#1282](#1282)) ### Csskit_spec_generator - csskit_spec_generator: Ensure property atoms includes the extra properties (#1283) ([#1283](#1283)) ### Csskit_vscode - chore(deps): update dependency @types/node to v24.13.2 (#1269) ([#1269](#1269)) - chore(deps): update dependency @types/vscode to v1.125.0 (#1270) ([#1270](#1270)) - chore(deps): update dependency typescript to v7 (#1273) ([#1273](#1273)) - chore(deps): update dependencies (patch) (#1286) ([#1286](#1286)) - chore(deps): update dependency oxlint to v1.69.0 (#1303) ([#1303](#1303))
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Nightly fuzz run found new findings.
We skip debug asserts to check if a dashed Ident or Function holds the atom bits for its relevant name, but we don't do that for AtRules, causing a panic when presented with a dashed AtRule.
This change refactors the debug assert to always assert on Dashed idents also, but tweaks the dashed-ident to ignore the preceeding
--so it can correctly assert on the value. This not only avoids the panic but adds extra safeguards that all ident-like functions correctly hold atom bits for their name.Findings
minimized-from-712bbffad97f73bfde6ab3f2f1d408ba2862ef77(5 bytes){@--rminimized-from-7c2ac8682c1dea7b981d01d794ec9c4ffa9e3f88(165 bytes)minimized-from-6c42e7282657e697d6d29098823884c6f3824b83(247 bytes)minimized-from-793bd2bbdc3c5c52964dc7628305a2555aa676a0(9 bytes)minimized-from-d6e3a8c076108c4509056e9e8b849e897dcbf2d6(18 bytes)minimized-from-b803f98fff888c1ef4f64cc682d2a22dacd1f085(376 bytes)minimized-from-03caeb9225e91044cb9d2321ea2e7dfbcc21b397(42 bytes)minimized-from-2a6e0769bab31e9a65793b5e8d3d8aac5d63f239(455 bytes)minimized-from-36d772ad74cc04fcfde116fc06234ea0e3df08b5(4 bytes)@--rminimized-from-8ee0363784e3bc477ed765677f413651debc268f(45 bytes)minimized-from-4381141ceb0bf0463134c6dc48d6eaab03d96ea5(73 bytes)minimized-from-298957970b68add53a86da7b7f9855cbf8dac23f(749 bytes)minimized-from-5b70942c1f4f90a21f17f287aa31199856b2fcab(920 bytes)minimized-from-ad4e327fcd4506527b55426149db5d06afecf9c0(452 bytes)minimized-from-d4f7378232b2e3bfa6f5fd63e46868b2384b5771(202 bytes)minimized-from-b6d021b5e5df80588d1924fcc2dda309cc1d8758(104 bytes)minimized-from-4d2dcbf1515d4df675d96475fe055ec0b4a2070f(1681 bytes)minimized-from-65e96e689ef1e4cdad8e9091f8fc4cf294b6e6a4(413 bytes)minimized-from-b934e4bcd2b7757e2ef081f2f81e429394d7561e(1831 bytes)minimized-from-e05001cc4a3ff401b7e76352515dd8accec3b9c4(15 bytes)minimized-from-bec26878414b976e7cb5b7f5ad6864c4ac8ba9ac(6 bytes){@--trminimized-from-bd97ec1739e8222521c833beb7042a73e9402662(132 bytes)minimized-from-42a5c703e94836bf6144b5a516b49846df393c06(64 bytes)minimized-from-48f3407f7fa9a29cc10432bf0af8ed361483fb4d(92 bytes)minimized-from-c5a5332a21616a3a7d02092064788df1b24af403(62 bytes)minimized-from-c387cc4e7ba857c3ca03ba67008e8aef579081dd(23 bytes)