mirror of
https://github.com/trailofbits/buttercup
synced 2026-06-21 14:11:39 +00:00
143a59c236
Before this commit, the fuzzer dependend on clusterfuzz, which uses protobuf 3.20. Since fuzzer-bot depended on common subpackage as well and also common (and the other packages) require protobuf, we had to use protobuf 3.20 everywhere. This old dependency however means that a lot of packages can't be used in their "newer" versions, because they depend on newer protobuf versions. This commit splits the fuzzer into a separate fuzzer-runner that is executed in a separate process inside a separate venv. fuzzer-runner executes the clusterfuzz-heavy operations (e.g. fuzzing) and isolates the clusterfuzz dependency, so that the rest of the system can use newer protobuf version. * split `fuzzer-bot` in `fuzzer-runner` and `fuzzer-bot` * have a "full" optional dependency group in `common`, including `openlit` and `protobuf`, so that `fuzzer-runner` can use the lite version of `common` without bringing those heavy deps * move `FuzzConfiguration`/`BuildConfiguration` in a separate common file that doesn't require to load all protobuf files. Again, in this way other components can just depend on the `common` "lite" version and not require protobuf stuff * add `fuzzer-runner` as a separate venv inside the `fuzzer-bot` container * add `RunnerProxy` class in fuzzer package to provide an interface to interact with the fuzzer-runner binary.
79 lines
1.7 KiB
TOML
79 lines
1.7 KiB
TOML
[project]
|
|
name = "program-model"
|
|
version = "0.1.0"
|
|
description = "Buttercup contextualizer"
|
|
readme = "README.md"
|
|
authors = [{ name = "Trail of Bits", email = "opensource@trailofbits.com" }]
|
|
license = "AGPL-3.0-only"
|
|
requires-python = ">=3.12,<3.13"
|
|
dependencies = [
|
|
"common[full]",
|
|
"tree-sitter ~=0.24.0",
|
|
"tree-sitter-language-pack ~=0.9.0",
|
|
"rapidfuzz ~=3.12.2",
|
|
]
|
|
|
|
[project.scripts]
|
|
buttercup-program-model = "buttercup.program_model.__cli__:main"
|
|
|
|
[tool.uv.sources]
|
|
common = { path = "../common", editable = true }
|
|
|
|
[tool.hatch.build.targets.wheel]
|
|
packages = ["src/buttercup"]
|
|
|
|
[build-system]
|
|
requires = ["hatchling"]
|
|
build-backend = "hatchling.build"
|
|
|
|
|
|
[project.urls]
|
|
Repository = "https://github.com/trailofbits/buttercup"
|
|
Issues = "https://github.com/trailofbits/buttercup/issues"
|
|
|
|
[dependency-groups]
|
|
dev = [
|
|
# Testing tools
|
|
"pytest ~=8.3.4",
|
|
"pytest-cov ~=6.0.0",
|
|
# Linting and type checking
|
|
"ruff ~=0.12.8",
|
|
"mypy ~=1.17.1",
|
|
# Type stubs
|
|
"types-redis ~=4.6.0",
|
|
]
|
|
|
|
[tool.ruff]
|
|
line-length = 120
|
|
target-version = "py312"
|
|
|
|
[tool.ruff.lint]
|
|
select = ["E", "F", "I", "W", "UP"]
|
|
ignore = [
|
|
"COM812", "ISC001", # Formatter conflicts
|
|
]
|
|
|
|
[tool.ruff.lint.per-file-ignores]
|
|
"tests/**/*.py" = ["S101", "D"] # Allow asserts, no docstrings in tests
|
|
|
|
[tool.mypy]
|
|
plugins = ["pydantic.mypy"]
|
|
mypy_path = "src"
|
|
packages = "buttercup"
|
|
allow_redefinition = true
|
|
check_untyped_defs = true
|
|
disallow_incomplete_defs = true
|
|
disallow_untyped_defs = true
|
|
ignore_missing_imports = true
|
|
no_implicit_optional = true
|
|
show_error_codes = true
|
|
sqlite_cache = true
|
|
strict_equality = true
|
|
warn_no_return = true
|
|
warn_redundant_casts = true
|
|
warn_return_any = true
|
|
warn_unreachable = true
|
|
warn_unused_configs = true
|
|
warn_unused_ignores = true
|
|
exclude = []
|