ci: integrate with OSS-Fuzz for continuous distributed fuzzing
还没有人认领这个 Issue。
评估
调研方向
Start with the OSS-Fuzz Rust new-project guide and review the existing fuzz targets: fuzz_parse_eager, fuzz_parse_lazy, fuzz_depth, and fuzz_ffi_ops. Prepare projects/qjson/ in google/oss-fuzz with its Dockerfile and project.yaml, then submit the PR. Done means all four targets run successfully, the project is approved, and the first OSS-Fuzz run completes with maintainer dashboard access.
由索引模型根据 Issue 内容生成。
描述
Background
qjson currently runs timed fuzzing weekly (60 seconds per target), which is sufficient for corpus regression but insufficient for discovering deep bugs. OSS-Fuzz provides free continuous distributed fuzzing for open-source projects, running thousands of CPU hours daily.
Production JSON parsers like simdjson and serde_json have found multiple security-relevant bugs through OSS-Fuzz that local fuzzing would never discover.
Goal
Integrate qjson with Google's OSS-Fuzz for continuous, large-scale fuzz testing.
Why OSS-Fuzz
| Aspect | Current (local timed fuzz) | OSS-Fuzz |
|---|---|---|
| Runtime | 60s/target weekly | Continuous, thousands of CPU-hours/day |
| Hardware | 1 GitHub runner | Google distributed cluster |
| Coverage depth | Shallow exploration | Deep path discovery |
| Corpus | Manual maintenance | Auto-accumulated, cross-version |
| Cost | Free | Free (Google-sponsored) |
Scope
Integration Steps
- Create
projects/qjson/ingoogle/oss-fuzzrepository - Write
Dockerfileto build qjson fuzz targets - Write
project.yamlwith project metadata - Adapt existing fuzz targets (
fuzz_parse_eager,fuzz_parse_lazy,fuzz_depth,fuzz_ffi_ops) - Submit PR to
google/oss-fuzz, await approval (typically 1-2 weeks)
Requirements for Acceptance
- Open-source with OSI-approved license (Apache-2.0 ✓)
- Active maintenance ✓
- Real user base (API7/APISIX ecosystem ✓)
- Commitment to fix reported vulnerabilities within 90-day disclosure deadline
Acceptance Criteria
- PR submitted to
google/oss-fuzzrepository - All 4 existing fuzz targets integrated
- Project approved and running on OSS-Fuzz infrastructure
- ClusterFuzz dashboard accessible to maintainers
- First fuzzing run completes successfully
References
- OSS-Fuzz: https://github.com/google/oss-fuzz
- New project guide: https://google.github.io/oss-fuzz/getting-started/new-project-guide/
- Rust integration: https://google.github.io/oss-fuzz/getting-started/new-project-guide/rust-lang/
- Example Rust project: https://github.com/google/oss-fuzz/tree/master/projects/serde_json
- 主要语言
- Rust
- 星标
- 2
- 派生
- 0
- PR 合并指标
- 30 天内没有已合并 PR
环境准备
- 没有 Dockerfile 或 Docker Compose 文件
- 没有 Pull Request 模板
- 阅读贡献指南
从这里开始
- 先读完整个 Issue,再读项目的贡献指南。
- 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
- Fork 仓库,在一个分支上完成修改。
- 提交 Pull Request,并在描述里引用这个 Issue 编号。
api7/lua-qjson 的其他 Issue
-
docs: fix malformed benchmark throughput table可能重新可做 关联的 PR 已关闭且未合并。 未关闭
难度 1/5 1 小时以内 新手友好度 90/100
-
enhancement
难度 5/5 一周以上 新手友好度 30/100
相似的 Issue
-
[Misdetection] `text/tab-separated-values` file misdetected as `text/tsv`可能已有人在做 @bact 今天认领。 未关闭misdetection needs triage
难度 2/5 1-3 小时 新手友好度 70/100
维护者通常 1 天内回复
-
C-bug
难度 2/5 1-3 小时 新手友好度 72/100
维护者通常 2 天内回复
-
vxc prints a debug line '[flat-codegen] emitted module via the flat path' on every compile可能已有人在做 @YodHeVauHe 今天认领。 未关闭devex good first issue
难度 2/5 1-3 小时 新手友好度 82/100
维护者通常 1 天内回复
-
难度 2/5 1-3 小时 新手友好度 68/100
维护者通常 3 天内回复
-
难度 2/5 1-3 小时 新手友好度 72/100
维护者通常 1 天内回复