Hacktoberfest 2026:メンテナが10月に向けて印を付けた、オープンで初心者向けの issue。 Hacktoberfest の issue を見る

Fuzzing for cups-filters could have higher coverage with low effort

オープン
#47 コメント 4 件 リアクション 1 件 担当者 0 名 GitHub で見る

まだ誰も着手していません。

評価

難易度
5/5
見積もり時間
1週間以上
初心者へのやさしさ
35/100
issue の種類
機能追加
明瞭さ
おおむね明確
活発さ
停滞
技術スタック
c
領域
testing

調査の方向性

まず fuzzing/projects 配下にある既存の cups-filters プロジェクトと libcupsfilters プロジェクトを確認し、次に cupsfilters/filter.h と利用可能な Podman Containerfiles を調べます。fuzzer が生のメディアファイルを受け付け、通常のクラッシュ入力と過去のクラッシュ入力を seed として使用し、要求された cups-filters ツールまたは cfFilter* 関数を実行できれば、作業は完了です。

索引モデルが issue の本文から書いたものです。

説明

Hello @fish98!

I hear that OpenPrinting is soon hosting Winter-of-Code participants again, maybe it is the right time to pitch this:

CUPS-Filters does a lot of media parsing, and media parsing code is diverse and sometimes complicated.

I think it would be good to fuzz it like this:

  • Make the fuzzer generate the raw media files as input for the cups-filters tools (or the cfFilter* functions from filter.h).
  • For seeding the fuzzer with good starting points, normal media files can be used, and ideally also a variety of crash inputs from past bugs and vulnerabilities.

I am raising this because I noticed that the existing fuzzers for cups-filters and libcupsfilters only exercise a small subset of the functionality of these libraries (PDF output helpers and dithering utilities, to be precise). You do not need to have individual fuzzers for these - If the exercised helpers are also used by any of the CUPS-filters tools, it is enough to give an input seed file to the fuzzer which reaches this code, and a modern coverage-guided fuzzer is then able to exercise it.

(P.S., I am unfortunately short on time to do anything on this myself, but I have some Podman Containerfiles that can serve as a starting point to make the cups-filters projects build again. (Although I remember I had trouble linking it statically.) I can happily share that over email if you are interested. Let me know.)

主要言語
C
スター
8
フォーク
18
PR マージ指標
30日以内にマージされた PR はありません

環境構築

このプロジェクトには開発コンテナ、Dockerfile、コントリビューションガイドがありません。まず README を読み、一般的な手順ははじめてのコントリビューションガイドを参照してください。

はじめの一歩

  1. issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
  2. 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
  3. リポジトリをフォークし、ブランチを切って変更します。
  4. issue 番号を参照したプルリクエストを送ります。

OpenPrinting/fuzzing のほかの issue

OpenPrinting/fuzzing の issue をすべて見る

似ている issue

C の issue をもっと見る

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。