Release Notes#
This document lists major changes across releases.
Added in version 1.2: (August 2026)
Grammars gained a permutation operator:
[[ <a> <b> <c> ]]produces and parses the enclosed symbols in any order. It works for protocol messages too, so a spec can state that two packets may arrive in either order.Timers for protocol testing. A spec can now start and cancel timers and react to them expiring, so interactions that hinge on timeouts can be tested.
Two new ways to stop a fuzzing run once it has done its job:
--stop-criteriontakes a Python lambda that is evaluated on every new solution, for instance--stop-criterion 'lambda t: t.to_string().startswith("abc")'.--stop-after-secondsstops at the start of the first generation after the given number of seconds.
Experimental support for guidance by code coverage. Against a program compiled with
fcc,fandango fuzz --fccsteers input generation towards code that has not been reached yet.Submodules under
fandango.experimental.*are now marked as experimental: they can change without notice, and importing one emits a warning.--enable-experimental-module MODULEopts you in to a module and silences its warning.Internal caches are now bounded, so long runs no longer grow without limit. Set their size with the
FANDANGO_CACHE_SIZEenvironment variable.--format=1prints the constant1for every output, which is useful for testing.New
DerivationTree.find_subtrees(), which also accepts a symbol name as a plain string. It replacesfind_all_trees().Further improved protocol fuzzing: a dedicated protocol algorithm, \(k\)-path coverage tracking of the interactions produced so far, and a packet selector that plans which message to send next.
New hands-on tutorial, which builds one protocol from random bytes up to a stateful conversation.
New style guide for writing specs that are reusable, extensible, and efficient.
Lots of minor bug fixes.
[development] Python 3.14 is now supported, and tested in CI alongside 3.11, 3.12, and 3.13.
[development] Fandango now builds with
scikit-build-corealone, andsetup.pyis gone. SetFANDANGO_SKIP_CPP_PARSER=1to skip the C++ parser, orFANDANGO_REQUIRE_BINARY_BUILD=1to insist on it.[development] We now ship a
pylock.tomlnext touv.lock, so tools other thanuvcan consume our dependency set.[development] Ruff replaces black for formatting and linting.
[development] The project now has a contribution guide, a code of conduct, a support policy, a security policy, issue and pull request templates, and a
CITATION.cff.
Changed in version 1.2:
Fandango now requires Python 3.11 or later. Python 3.10 is no longer supported.
DerivationTree.find_all_trees()is deprecated. Usefind_subtrees()instead.
Added in version 1.1: (February 2026)
Much enhanced protocol fuzzing:
Protocol fuzzing is now out of beta.
fandango talknow keeps on producing diverse interactions, systematically covering states and messages until stopped or 100% coverage is reached.fandango convertcan now produce state diagrams from grammars.
We have added a new GIF case study.
You can now download the documentation as a PDF from the upper-right download icon.
Lots of minor bug fixes.
[development] Major internal refactorings and code quality improvements.
[development] Added support for the
uvpackage manager, including appropriate lock files to ensure compatible and fixed dependency versions
Added in version 1.0: (June 2025)
New command
fandango talkfor checking outputs and testing protocols (beta).Much faster parser for
.fanfiles, using C++ code.Support for regular expressions for producing and parsing.
Support for soft constraints and optimization (
maximizing/minimizing).Using
*/**expressions for Python-style quantifiers is now operational.f-strings in Python code are now supported.
Support for
libfuzzerharnesses.New command
fandango convertfor converting ANTLR and other input specifications.New command
fandango clear-cachefor clearing the parser cache.Improved bit parser.
Lots of minor and major improvements and bug fixes across the board.
Changed in version 1.0:
We now apply Python end-of-line rules to grammar parsing. End continuation lines with
\or use parentheses.Fuzzing by default is now “infinite”, producing results until stopped. Specify
-n Nto obtainNoutputs.
Added in version 0.8: (April 2025)
First public beta release.
fandango fuzzandfandango parsecommands.