You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
I hope this message finds you well. I've been using xxHash without knowing it for some time as a third party dependency. I'd like to suggest and champion an effort to set up some basic fuzz-testing and combine it with google/oss-fuzz for continuous fuzzing. I'm fully aware that you are a busy person and I don't want to overload your review/maintenance capacity by introducing too many new ideas. Is this a bad time to discuss potential security/reliability improvements?
If your not familiar with fuzzing or google/oss-fuzz I've included a few brief notes below.
Benefits of Fuzz-Testing
Dynamic Code Testing: Fuzz-testing challenges systems with unexpected data, aiming to identify vulnerabilities. It’s akin to an exhaustive stress-test for the code.
Detecting Hidden Vulnerabilities: It can uncover potential weaknesses that may not be evident in routine tests.
Continuous and Automated Testing: With tools like Google’s OSS-Fuzz, fuzz-testing can be automated, running continuously on distributed systems, ensuring daily resilience checks.
Google/oss-fuzz for Continuous Fuzzing
Automated Fuzzing: OSS-Fuzz undertakes comprehensive fuzz-testing daily on a distributed cluster.
Security Boost: It provides enhanced security measures free of cost, thanks to Google’s backing.
Detailed Reporting: OSS-Fuzz offers exhaustive reports in case of detected anomalies, enabling effective action.
I’d be more than happy to lead the effort in integrating fuzz testing with the xxHash and assist in any way required.
As a proof of concept I created a super simple fuzz harness in #906.
The text was updated successfully, but these errors were encountered:
You to comment on the application/integration PR (that I'm yet to open) on oss-fuzz mentioning that you agree to the integration.
I should also note, that there is an application process which I can complete on your behalf, as it'll just be a PR of work that I've mostly already done. I'm reasonably confident that this project would be accepted as it's quite a popular project, but there is a non-zero chance that it'll be rejected.
Hey Yann,
I hope this message finds you well. I've been using xxHash without knowing it for some time as a third party dependency. I'd like to suggest and champion an effort to set up some basic fuzz-testing and combine it with google/oss-fuzz for continuous fuzzing. I'm fully aware that you are a busy person and I don't want to overload your review/maintenance capacity by introducing too many new ideas. Is this a bad time to discuss potential security/reliability improvements?
If your not familiar with fuzzing or google/oss-fuzz I've included a few brief notes below.
Benefits of Fuzz-Testing
Google/oss-fuzz for Continuous Fuzzing
I’d be more than happy to lead the effort in integrating fuzz testing with the xxHash and assist in any way required.
As a proof of concept I created a super simple fuzz harness in #906.
The text was updated successfully, but these errors were encountered: