OSS-Fuzz Integration Request

Open
#2,431 1 comment 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Assessment

Difficulty
4/5
Estimated time
3-5 days
Newbie friendliness
35/100
Issue type
Feature
Clarity
Mostly clear
Activity status
Stale

Research direction

Start by reviewing the OSS-Fuzz project requirements and the Apache ORC repository's build scripts, since the issue names a fuzzing harness, integration configuration, and related components but no specific files. Done means preparing the ORC and OSS-Fuzz changes needed for continuous fuzzing, subject to Apache ORC PMC approval.

Written by the indexing model from the issue text.

Description

Background

Following the recent CVE-2025-47436 heap buffer overflow vulnerability discovery and fix, I would like to propose integrating Apache ORC with the OSS-Fuzz project to help identify potential security vulnerabilities earlier through continuous fuzzing.

Apache Projects Already Using OSS-Fuzz

Many Apache Software Foundation projects are already integrated with OSS-Fuzz, including:

  • apache-axis2
  • apache-commons-bcel
  • apache-commons-beanutils
  • apache-commons-cli
  • apache-commons-codec
  • apache-commons-collections
  • apache-commons-compress
  • apache-commons-configuration
  • apache-commons-csv
  • apache-commons-fileupload
  • apache-commons-geometry
  • apache-commons-imaging
  • apache-commons-io
  • apache-commons-jxpath
  • apache-commons-lang
  • apache-commons-logging
  • apache-commons-math
  • apache-commons-net
  • apache-commons-text
  • apache-commons-validator
  • apache-cxf
  • apache-doris
  • apache-felix-dev
  • apache-httpd
  • apache-logging-log4cxx
  • apache-poi
Integration

I would prepare a pull request that adds:

  1. Fuzzing harness to the Apache ORC repository
  2. Integration configuration for the OSS-Fuzz project
  3. Build scripts and related components

This proposal was previously discussed via email with @dongjoon-hyun, who suggested opening this issue for formal documentation before proceeding with the integration work.

I'm seeking formal approval from the Apache ORC PMC to proceed with the OSS-Fuzz integration. Once approved, I'll prepare the necessary pull requests for both the ORC and OSS-Fuzz repositories.

Thanks a lot!

Dominant language
Java
Stars
769
Forks
517
PR merge metrics
No merged PRs in 30d

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from apache/orc

All issues in apache/orc

Similar issues

More Java issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.