ci: integrate with OSS-Fuzz for continuous distributed fuzzing
Chưa có ai nhận issue này.
Đánh giá
- Độ khó
- 5/5
- Thời gian dự kiến
- Hơn một tuần
- Mức phù hợp với người mới
- 35/100
Hướng nghiên cứu
Start with the OSS-Fuzz Rust new-project guide and review the existing fuzz targets: fuzz_parse_eager, fuzz_parse_lazy, fuzz_depth, and fuzz_ffi_ops. Prepare projects/qjson/ in google/oss-fuzz with its Dockerfile and project.yaml, then submit the PR. Done means all four targets run successfully, the project is approved, and the first OSS-Fuzz run completes with maintainer dashboard access.
Do mô hình lập chỉ mục viết ra từ nội dung của issue.
Mô tả
Background
qjson currently runs timed fuzzing weekly (60 seconds per target), which is sufficient for corpus regression but insufficient for discovering deep bugs. OSS-Fuzz provides free continuous distributed fuzzing for open-source projects, running thousands of CPU hours daily.
Production JSON parsers like simdjson and serde_json have found multiple security-relevant bugs through OSS-Fuzz that local fuzzing would never discover.
Goal
Integrate qjson with Google's OSS-Fuzz for continuous, large-scale fuzz testing.
Why OSS-Fuzz
| Aspect | Current (local timed fuzz) | OSS-Fuzz |
|---|---|---|
| Runtime | 60s/target weekly | Continuous, thousands of CPU-hours/day |
| Hardware | 1 GitHub runner | Google distributed cluster |
| Coverage depth | Shallow exploration | Deep path discovery |
| Corpus | Manual maintenance | Auto-accumulated, cross-version |
| Cost | Free | Free (Google-sponsored) |
Scope
Integration Steps
- Create
projects/qjson/ingoogle/oss-fuzzrepository - Write
Dockerfileto build qjson fuzz targets - Write
project.yamlwith project metadata - Adapt existing fuzz targets (
fuzz_parse_eager,fuzz_parse_lazy,fuzz_depth,fuzz_ffi_ops) - Submit PR to
google/oss-fuzz, await approval (typically 1-2 weeks)
Requirements for Acceptance
- Open-source with OSI-approved license (Apache-2.0 ✓)
- Active maintenance ✓
- Real user base (API7/APISIX ecosystem ✓)
- Commitment to fix reported vulnerabilities within 90-day disclosure deadline
Acceptance Criteria
- PR submitted to
google/oss-fuzzrepository - All 4 existing fuzz targets integrated
- Project approved and running on OSS-Fuzz infrastructure
- ClusterFuzz dashboard accessible to maintainers
- First fuzzing run completes successfully
References
- OSS-Fuzz: https://github.com/google/oss-fuzz
- New project guide: https://google.github.io/oss-fuzz/getting-started/new-project-guide/
- Rust integration: https://google.github.io/oss-fuzz/getting-started/new-project-guide/rust-lang/
- Example Rust project: https://github.com/google/oss-fuzz/tree/master/projects/serde_json
- Ngôn ngữ chính
- Rust
- Star
- 2
- Fork
- 0
- Chỉ số merge pull request
- Không có pull request nào được merge trong 30 ngày
Chuẩn bị môi trường
- Không có Dockerfile hay tệp Docker Compose
- Không có mẫu pull request
- Đọc hướng dẫn đóng góp
Bắt đầu từ đâu
- Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
- Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
- Fork repository và làm thay đổi trên một nhánh.
- Mở pull request có tham chiếu số hiệu của issue.
Issue khác của api7/lua-qjson
-
Độ khó 1/5 Dưới một giờ Mức phù hợp với người mới 90/100
-
enhancement
Độ khó 5/5 Hơn một tuần Mức phù hợp với người mới 30/100
Tất cả issue của api7/lua-qjson
Issue tương tự
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 84/100
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 82/100
canonical/opentelemetry-collector-operator#409 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
codegen: memref.collapse_shape in an mlir! block leaves an affine.apply that is never loweredĐang mởbug
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 74/100
Maintainer thường phản hồi trong vòng 1 ngày
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 84/100
Maintainer thường phản hồi trong vòng 1 ngày
-
bug CLI exec tool-calls
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 85/100
Maintainer thường phản hồi trong vòng 1 ngày