Hacktoberfest 2026:维护者为十月标记出来的 issue,仍然开放、适合新手。 浏览 Hacktoberfest issue

ci: integrate with OSS-Fuzz for continuous distributed fuzzing

未关闭
#156 1 条评论 1 个 reaction 已指派 0 人 在 GitHub 查看

还没有人认领这个 Issue。

评估

难度
5/5
预计耗时
一周以上
新手友好度
35/100
Issue 类型
功能
描述清晰度
基本清楚
活跃度
冷清
技术栈
rust

调研方向

Start with the OSS-Fuzz Rust new-project guide and review the existing fuzz targets: fuzz_parse_eager, fuzz_parse_lazy, fuzz_depth, and fuzz_ffi_ops. Prepare projects/qjson/ in google/oss-fuzz with its Dockerfile and project.yaml, then submit the PR. Done means all four targets run successfully, the project is approved, and the first OSS-Fuzz run completes with maintainer dashboard access.

由索引模型根据 Issue 内容生成。

描述

enhancement

Background

qjson currently runs timed fuzzing weekly (60 seconds per target), which is sufficient for corpus regression but insufficient for discovering deep bugs. OSS-Fuzz provides free continuous distributed fuzzing for open-source projects, running thousands of CPU hours daily.

Production JSON parsers like simdjson and serde_json have found multiple security-relevant bugs through OSS-Fuzz that local fuzzing would never discover.

Goal

Integrate qjson with Google's OSS-Fuzz for continuous, large-scale fuzz testing.

Why OSS-Fuzz

Aspect Current (local timed fuzz) OSS-Fuzz
Runtime 60s/target weekly Continuous, thousands of CPU-hours/day
Hardware 1 GitHub runner Google distributed cluster
Coverage depth Shallow exploration Deep path discovery
Corpus Manual maintenance Auto-accumulated, cross-version
Cost Free Free (Google-sponsored)

Scope

Integration Steps
  1. Create projects/qjson/ in google/oss-fuzz repository
  2. Write Dockerfile to build qjson fuzz targets
  3. Write project.yaml with project metadata
  4. Adapt existing fuzz targets (fuzz_parse_eager, fuzz_parse_lazy, fuzz_depth, fuzz_ffi_ops)
  5. Submit PR to google/oss-fuzz, await approval (typically 1-2 weeks)
Requirements for Acceptance
  • Open-source with OSI-approved license (Apache-2.0 ✓)
  • Active maintenance ✓
  • Real user base (API7/APISIX ecosystem ✓)
  • Commitment to fix reported vulnerabilities within 90-day disclosure deadline

Acceptance Criteria

  • PR submitted to google/oss-fuzz repository
  • All 4 existing fuzz targets integrated
  • Project approved and running on OSS-Fuzz infrastructure
  • ClusterFuzz dashboard accessible to maintainers
  • First fuzzing run completes successfully

References

主要语言
Rust
星标
2
派生
0
PR 合并指标
30 天内没有已合并 PR

环境准备

  • 没有 Dockerfile 或 Docker Compose 文件
  • 没有 Pull Request 模板
  • 阅读贡献指南

从这里开始

  1. 先读完整个 Issue,再读项目的贡献指南。
  2. 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
  3. Fork 仓库,在一个分支上完成修改。
  4. 提交 Pull Request,并在描述里引用这个 Issue 编号。

api7/lua-qjson 的其他 Issue

查看 api7/lua-qjson 的全部 Issue

相似的 Issue

更多 Rust Issue

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。