Skip to content

More info on oss-fuzz fuzzer improvement / initial incorporation rewards? #14260

@personnumber3377

Description

@personnumber3377

Hi!

I noticed that there is this bounty program in place. I also noticed that the fuzzing code coverage for the cairo graphics project is quite poor and I want to potentially improve it.

I have a couple of questions:

  1. What qualifies as an issue? I mean is a null pointer dereference considered or must it be a memory corruption bug (use after free, controllable buffer overflow etc)? Do out of memory bugs count?
  2. The "50% across the entire project"? There is some functionality that is not included by default but can be included via some compile time options, so does the "across the entire project" mean all the code or what is included in most common configurations? (I assume that it means ALL the code, but just to be sure).
  3. The CIFuzz integration. Do I need to convince the upstream maintainers to add the project to clusterfuzzlite?
  4. "Finding a critical vulnerability that has widespread impact as a result of fuzzing integration." How popular must be the target be? I assume it must be very common like OpenSSL or something like that. Of course these rewards are at the discretion of the oss-fuzz team but can you be a bit more specific (for example a list of eligible projects for this reward)?

Thanks in advance and thank you for your time!

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions