Hacktoberfest 2026: những issue maintainer đã đánh dấu cho tháng Mười, đang mở và phù hợp người mới. Xem issue Hacktoberfest

Fuzzing for cups-filters could have higher coverage with low effort

Đang mở
#47 4 bình luận 1 reaction 0 người được giao Xem trên GitHub

Chưa có ai nhận issue này.

Đánh giá

Độ khó
5/5
Thời gian dự kiến
Hơn một tuần
Mức phù hợp với người mới
35/100
Loại issue
Tính năng
Độ rõ ràng
Khá rõ ràng
Mức độ hoạt động
Đình trệ
Công nghệ
c
Lĩnh vực
testing

Hướng nghiên cứu

Bắt đầu bằng cách xem xét các dự án cups-filters và libcupsfilters hiện có trong fuzzing/projects, sau đó kiểm tra cupsfilters/filter.h và các Containerfiles Podman hiện có. Công việc hoàn tất khi các fuzzer chấp nhận các tệp phương tiện thô, sử dụng các đầu vào crash thông thường và trong lịch sử làm seed, đồng thời thực thi các công cụ cups-filters hoặc các hàm cfFilter* được yêu cầu.

Do mô hình lập chỉ mục viết ra từ nội dung của issue.

Mô tả

Hello @fish98!

I hear that OpenPrinting is soon hosting Winter-of-Code participants again, maybe it is the right time to pitch this:

CUPS-Filters does a lot of media parsing, and media parsing code is diverse and sometimes complicated.

I think it would be good to fuzz it like this:

  • Make the fuzzer generate the raw media files as input for the cups-filters tools (or the cfFilter* functions from filter.h).
  • For seeding the fuzzer with good starting points, normal media files can be used, and ideally also a variety of crash inputs from past bugs and vulnerabilities.

I am raising this because I noticed that the existing fuzzers for cups-filters and libcupsfilters only exercise a small subset of the functionality of these libraries (PDF output helpers and dithering utilities, to be precise). You do not need to have individual fuzzers for these - If the exercised helpers are also used by any of the CUPS-filters tools, it is enough to give an input seed file to the fuzzer which reaches this code, and a modern coverage-guided fuzzer is then able to exercise it.

(P.S., I am unfortunately short on time to do anything on this myself, but I have some Podman Containerfiles that can serve as a starting point to make the cups-filters projects build again. (Although I remember I had trouble linking it statically.) I can happily share that over email if you are interested. Let me know.)

Ngôn ngữ chính
C
Star
8
Fork
18
Chỉ số merge pull request
Không có pull request nào được merge trong 30 ngày

Chuẩn bị môi trường

Dự án này không cung cấp dev container, Dockerfile hay hướng dẫn đóng góp, nên bạn cần tự thiết lập môi trường: hãy bắt đầu từ README và xem hướng dẫn đóng góp lần đầu của chúng tôi để biết các bước chung.

Bắt đầu từ đâu

  1. Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
  2. Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
  3. Fork repository và làm thay đổi trên một nhánh.
  4. Mở pull request có tham chiếu số hiệu của issue.

Issue khác của OpenPrinting/fuzzing

Tất cả issue của OpenPrinting/fuzzing

Issue tương tự

Thêm issue về C

Nhận issue mới trong hộp thư của bạn

Bản tóm tắt ngắn những issue GitHub phù hợp với người mới.