Upstream Contributions
Work in other people’s repositories. Every entry links to the project’s own issue tracker, so the record can be read there rather than taken on trust — including the parts written by the maintainers, not by me.
necessist — index panic in the span reader
necessist is Trail of Bits’ mutation-based tool for finding gaps in test suites: it removes statements from tests and reports the ones that can be removed while the suite still passes.
Span::source_text rebuilt a source fragment by indexing contents.as_bytes()[start..end] with no bounds test. A span whose file had since been shortened aborted the process instead of returning an error. No new code was needed to reach it: the existing --dump-candidates path does.
The cause sits a layer below the panic. ParseAdapter constructs a SourceFile, which reads the file and caches its contents, and then calls parse_source_file with a path — and each of the five backends reads that path again. Candidate coordinates and cached contents therefore need not come from the same read of the same bytes.
The patch makes the function total via contents.get(start..end). All five call sites already consumed a Result, so no signature and no caller changed; three of them now return an error where the process previously aborted, which is a behaviour change and was reported as one rather than glossed. Two files, +143/-3, with unit tests for the in-range and out-of-range branches and a regression test that drives the real --dump-candidates path and fails on the unpatched tree.
Repairing the double read itself would touch a public trait and six implementations, so it was reported as a separate observation for the maintainer rather than folded into the change.
Merged on September 14, 2026 in commit 6fae088, via pull request #1961 , after line-by-line review by maintainer Samuel Moelius. On the related issue #1834 he wrote:
changes to source files are something I have largely not considered while developing Necessist, as evident by #1961
asn1-rs — fuzzing harness and four defects in the legacy parse route
asn1-rs is an ASN.1 implementation for Rust.
At the time of this work the crate shipped no fuzzing harness, although its README lists fuzzing among the project’s goals. I wrote a libFuzzer harness targeting the BER/DER parse entry points and filed two reports covering four defects in the legacy FromDer route:
bool::from_derindexes the first content octet without checking the length, so a zero-length TLV crashes the parser. The ordering is what makes it reachable:check_constraintsruns beforeTryFrom<Any>validates the tag.decode_realaccumulates a REAL mantissa ini64, while X.690 §8.5.7.5 definesNas unsigned. A conforming positive value decodes as negative — silently, with no error and no diagnostic. Affects 0.1.0 through 0.7.2 and both 0.8.0 betas.
Patches were submitted for the first report and for two of the three defects in the second.
Issues #142 and #143 ; pull requests #144 , #145 , #146 . Status: open — not merged.
upower — composite battery reported above 100%
upower is the daemon that abstracts power devices for Linux desktop environments.
On a dual-battery laptop the composite DisplayDevice reported 204%. One battery’s firmware reports energy_full=0; upower summed the current energy of both batteries while that zero entered the sum of full energy, so the ratio was computed against half the capacity that was actually there.
Reported as issue #336 on January 5, 2026, with the root cause traced to up_daemon_update_display_battery() in src/up-daemon.c — including the assumption stated in the source itself:
ASSUMPTION: If one battery has energy data, then all batteries do
The report carried the system’s own data, the arithmetic, and a proposed patch. Hardware: Dell Latitude 7330 Rugged Extreme, upower 1.90.3, BIOS 1.40.0.
Fixed upstream on July 30, 2026 in commit b8e567a, written by maintainer Kate Hsuan (Red Hat). The fix landed a layer lower than the report proposed — in up-device-supply-battery, falling back to energy_full_design when energy_full is invalid. The commit carries the trailer Reported-by: Dmitrii Zatona <[email protected]>.