Hacktoberfest 2026: những issue maintainer đã đánh dấu cho tháng Mười, đang mở và phù hợp người mới. Xem issue Hacktoberfest

ci: integrate with OSS-Fuzz for continuous distributed fuzzing

Đang mở
#156 1 bình luận 1 reaction 0 người được giao Xem trên GitHub

Chưa có ai nhận issue này.

Đánh giá

Độ khó
5/5
Thời gian dự kiến
Hơn một tuần
Mức phù hợp với người mới
35/100
Loại issue
Tính năng
Độ rõ ràng
Khá rõ ràng
Mức độ hoạt động
Ít trao đổi
Công nghệ
rust
Lĩnh vực
ci-cd, security, testing

Hướng nghiên cứu

Start with the OSS-Fuzz Rust new-project guide and review the existing fuzz targets: fuzz_parse_eager, fuzz_parse_lazy, fuzz_depth, and fuzz_ffi_ops. Prepare projects/qjson/ in google/oss-fuzz with its Dockerfile and project.yaml, then submit the PR. Done means all four targets run successfully, the project is approved, and the first OSS-Fuzz run completes with maintainer dashboard access.

Do mô hình lập chỉ mục viết ra từ nội dung của issue.

Mô tả

enhancement

Background

qjson currently runs timed fuzzing weekly (60 seconds per target), which is sufficient for corpus regression but insufficient for discovering deep bugs. OSS-Fuzz provides free continuous distributed fuzzing for open-source projects, running thousands of CPU hours daily.

Production JSON parsers like simdjson and serde_json have found multiple security-relevant bugs through OSS-Fuzz that local fuzzing would never discover.

Goal

Integrate qjson with Google's OSS-Fuzz for continuous, large-scale fuzz testing.

Why OSS-Fuzz

Aspect Current (local timed fuzz) OSS-Fuzz
Runtime 60s/target weekly Continuous, thousands of CPU-hours/day
Hardware 1 GitHub runner Google distributed cluster
Coverage depth Shallow exploration Deep path discovery
Corpus Manual maintenance Auto-accumulated, cross-version
Cost Free Free (Google-sponsored)

Scope

Integration Steps
  1. Create projects/qjson/ in google/oss-fuzz repository
  2. Write Dockerfile to build qjson fuzz targets
  3. Write project.yaml with project metadata
  4. Adapt existing fuzz targets (fuzz_parse_eager, fuzz_parse_lazy, fuzz_depth, fuzz_ffi_ops)
  5. Submit PR to google/oss-fuzz, await approval (typically 1-2 weeks)
Requirements for Acceptance
  • Open-source with OSI-approved license (Apache-2.0 ✓)
  • Active maintenance ✓
  • Real user base (API7/APISIX ecosystem ✓)
  • Commitment to fix reported vulnerabilities within 90-day disclosure deadline

Acceptance Criteria

  • PR submitted to google/oss-fuzz repository
  • All 4 existing fuzz targets integrated
  • Project approved and running on OSS-Fuzz infrastructure
  • ClusterFuzz dashboard accessible to maintainers
  • First fuzzing run completes successfully

References

Ngôn ngữ chính
Rust
Star
2
Fork
0
Chỉ số merge pull request
Không có pull request nào được merge trong 30 ngày

Chuẩn bị môi trường

Bắt đầu từ đâu

  1. Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
  2. Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
  3. Fork repository và làm thay đổi trên một nhánh.
  4. Mở pull request có tham chiếu số hiệu của issue.

Issue khác của api7/lua-qjson

Tất cả issue của api7/lua-qjson

Issue tương tự

Thêm issue về Rust

Nhận issue mới trong hộp thư của bạn

Bản tóm tắt ngắn những issue GitHub phù hợp với người mới.