Release Notes

Release Notes#

This document lists major changes across releases.

Added in version 1.2: (August 2026)

  • Grammars gained a permutation operator: [[ <a> <b> <c> ]] produces and parses the enclosed symbols in any order. It works for protocol messages too, so a spec can state that two packets may arrive in either order.

  • Timers for protocol testing. A spec can now start and cancel timers and react to them expiring, so interactions that hinge on timeouts can be tested.

  • Two new ways to stop a fuzzing run once it has done its job:

    • --stop-criterion takes a Python lambda that is evaluated on every new solution, for instance --stop-criterion 'lambda t: t.to_string().startswith("abc")'.

    • --stop-after-seconds stops at the start of the first generation after the given number of seconds.

  • Experimental support for guidance by code coverage. Against a program compiled with fcc, fandango fuzz --fcc steers input generation towards code that has not been reached yet.

  • Submodules under fandango.experimental.* are now marked as experimental: they can change without notice, and importing one emits a warning. --enable-experimental-module MODULE opts you in to a module and silences its warning.

  • Internal caches are now bounded, so long runs no longer grow without limit. Set their size with the FANDANGO_CACHE_SIZE environment variable.

  • --format=1 prints the constant 1 for every output, which is useful for testing.

  • New DerivationTree.find_subtrees(), which also accepts a symbol name as a plain string. It replaces find_all_trees().

  • Further improved protocol fuzzing: a dedicated protocol algorithm, \(k\)-path coverage tracking of the interactions produced so far, and a packet selector that plans which message to send next.

  • We have added new PNG and MP3 case studies.

  • New hands-on tutorial, which builds one protocol from random bytes up to a stateful conversation.

  • New style guide for writing specs that are reusable, extensible, and efficient.

  • Lots of minor bug fixes.

  • [development] Python 3.14 is now supported, and tested in CI alongside 3.11, 3.12, and 3.13.

  • [development] Fandango now builds with scikit-build-core alone, and setup.py is gone. Set FANDANGO_SKIP_CPP_PARSER=1 to skip the C++ parser, or FANDANGO_REQUIRE_BINARY_BUILD=1 to insist on it.

  • [development] We now ship a pylock.toml next to uv.lock, so tools other than uv can consume our dependency set.

  • [development] Ruff replaces black for formatting and linting.

  • [development] The project now has a contribution guide, a code of conduct, a support policy, a security policy, issue and pull request templates, and a CITATION.cff.

Changed in version 1.2:

  • Fandango now requires Python 3.11 or later. Python 3.10 is no longer supported.

  • DerivationTree.find_all_trees() is deprecated. Use find_subtrees() instead.

Added in version 1.1: (February 2026)

  • Much enhanced protocol fuzzing:

    • Protocol fuzzing is now out of beta.

    • fandango talk now keeps on producing diverse interactions, systematically covering states and messages until stopped or 100% coverage is reached.

    • Detailed documentation with FTP and DNS case studies.

    • fandango convert can now produce state diagrams from grammars.

  • We have added a new GIF case study.

  • You can now download the documentation as a PDF from the upper-right download icon.

  • Lots of minor bug fixes.

  • [development] Major internal refactorings and code quality improvements.

  • [development] Added support for the uv package manager, including appropriate lock files to ensure compatible and fixed dependency versions

Added in version 1.0: (June 2025)

Changed in version 1.0:

  • We now apply Python end-of-line rules to grammar parsing. End continuation lines with \ or use parentheses.

  • Fuzzing by default is now “infinite”, producing results until stopped. Specify -n N to obtain N outputs.

Added in version 0.8: (April 2025)

  • First public beta release.

  • fandango fuzz and fandango parse commands.