fuzz: fix multipart fuzzer imports (StreamReader, CIMultiDict) - #13410
Merged
Dreamsorcerer merged 4 commits intoAug 13, 2026
Merged
Conversation
for more information, see https://pre-commit.ci
Confidence Score: 5/5The PR appears safe to merge. No blocking failure remains. Reviews (2): Last reviewed commit: "Apply suggestion from @Dreamsorcerer" | Re-trigger Greptile |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What do these changes do?
Fix the
fuzzers/multipart.pyfuzzer so it actually runs. As written, itcrashes at startup, which would make the CIFuzz CI job (added in #12887) fail
its run step.
Two fixes:
class FuzzStream(StreamReader)usesStreamReaderbut never imported it.Added
from aiohttp.streams import StreamReader.HeadersDictProxywas constructed with a plaindict, but its__getitem__callsself._md.getall(key), which only exists onCIMultiDict— so any header lookup crashed withAttributeError: 'dict' object has no attribute 'getall'.Wrapped the dict in
CIMultiDictand added the import.Are there changes in behavior for the user?
No.
The fix only touches a test/fuzzing harness under
fuzzers/; it doesn't change aiohttp's runtime behavior or public API.Is it a substantial burden for the maintainers to support this?
Not at all.
It is three lines added and one line changed in a single fuzzer file, using APIs already used elsewhere in the aiohttp codebase (
aiohttp.streams.StreamReader,multidict.CIMultiDict). Both fixes are verifiable with the OSS-Fuzz build; no new dependencies or maintenance surface.Related issue number
Complements google/oss-fuzz#15791 (the OSS-Fuzz migration ticket).
Full test details are in my comments on that issue and on PR #12887.
Checklist
CONTRIBUTORS.txtCHANGES/foldername it
<issue_or_pr_num>.<type>.rst(e.g.588.bugfix.rst)if you don't have an issue number, change it to the pull request
number after creating the PR
.bugfix: A bug fix for something the maintainers deemed animproper undesired behavior that got corrected to match
pre-agreed expectations.
.feature: A new behavior, public APIs. That sort of stuff..deprecation: A declaration of future API removals and breakingchanges in behavior.
.breaking: When something public is removed in a breaking way.Could be deprecated in an earlier release.
.doc: Notable updates to the documentation structure or buildprocess.
.packaging: Notes for downstreams about unobvious side effectsand tooling. Changes in the test invocation considerations and
runtime assumptions.
.contrib: Stuff that affects the contributor experience. e.g.Running tests, building the docs, setting up the development
environment.
.misc: Changes that are hard to assign to any of the abovecategories.
Make sure to use full sentences with correct case and punctuation,
for example:
Use the past tense or the present tense a non-imperative mood,
referring to what's changed compared to the last released version
of this project.