[Rpm-maint] [rpm-software-management/rpm] Fuzzing integration by way of OSS-Fuzz (Issue #1822)

DavidKorczynski notifications at github.com
Fri Nov 5 16:22:21 UTC 2021


Hi!

I was wondering if you would be interested in getting rpm fuzzed by OSS-Fuzz? Fuzzing is a technique for stress-testing applications and OSS-Fuzz is a service run by Google for fuzzing important open source projects. It would be great to get rpm integrated with OSS-Fuzz. OSS-Fuzz will run the fuzzers continuously and report back with bug reports when bugs are found. These reports will have full stack traces, input triggers and more (i.e. Sanitizer reports). If you are interested, then the only thing needed is an email(s) connected to a Google account that can be used for receiving the bugs reports, which can be put in the configuration file (project.yaml) over at the OSS-Fuzz repository.

I have set up an initial integration with OSS-Fuzz here: https://github.com/google/oss-fuzz/pull/6778 which includes a simple initial fuzzer targetting `headerRead`. Am happy to extend with more fuzzers if you are happy to integrate.

-- 
You are receiving this because you are subscribed to this thread.
Reply to this email directly or view it on GitHub:
https://github.com/rpm-software-management/rpm/issues/1822
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.rpm.org/pipermail/rpm-maint/attachments/20211105/dbaf0c41/attachment.html>


More information about the Rpm-maint mailing list