Swift Fuzz

I've just released Swift Fuzz 1.0, a library to make it easy to write fuzz testing for Swift packages.

Fuzzing has been possible in Swift for a while, and there are blog posts about how to do it, and some projects have already adopted it. However, it's not super easy to use. The setup can be convoluted - the toolchain that ships with Xcode does not include libFuzzer, you need an open source toolchain - and building fuzz targets, supplying the correct compiler flags, managing inputs, and reproducing failures also requires a fair amount of manual work.

So I've built Swift Fuzz, modelled after the great Benchmark Package, to make it easy to add fuzzing to your library. A simple fuzz would look like:

import Foundation
import Fuzzing

let fuzzTargets: @Sendable () -> Void = {
    FuzzTarget.bytes("JSONParsing") { bytes in
        _ = try? JSONSerialization.jsonObject(with: Data(bytes), options: .fragmentsAllowed)
    }
}

The README covers setup, running fuzzing campaigns, CI, corpus management, and OSS-Fuzz submission.

Hopefully this makes it simpler for people to make their packages safer! I've already caught around 15 issues in the few Vapor projects that we've added it to and a few of my own.

15 Likes