GithubHelp home page GithubHelp logo

cncf / cncf-fuzzing Goto Github PK

View Code? Open in Web Editor NEW
108.0 108.0 38.0 876 KB

✨🔐 CNCF Fuzzers

Home Page: https://cncf.io/projects

License: Apache License 2.0

Go 73.43% Shell 9.42% Python 0.70% Dockerfile 0.07% Java 16.39%

cncf-fuzzing's People

Contributors

adamkorcz avatar arthurscchan avatar baijiaruo1 avatar caniszczyk avatar catenacyber avatar corhere avatar davidkorczynski avatar fish98 avatar happy-qop avatar huiwq1990 avatar jannfis avatar joestringer avatar killianmuldoon avatar kleimkuhler avatar kyakdan avatar kzys avatar milosgajdos avatar phisco avatar terrytangyuan avatar thajeztah avatar wackxu avatar

Stargazers

 avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar

Watchers

 avatar  avatar  avatar  avatar  avatar  avatar

cncf-fuzzing's Issues

building fuzzers failed after bumping quic-go version

Building fuzzers failed after bumping quic-go version.
Errors are /root/go/pkg/mod/github.com/lucas-clemente/[email protected]/internal/qtls/go118.go:6:13: cannot use "quic-go doesn't build on Go 1.18 yet." (untyped string constant) as int value in variable declaration, but it is normal when we build our artifacts manually.
More details show as follows.
https://github.com/kubeedge/kubeedge/actions/runs/3359066312/jobs/5566711345

cc @AdamKorcz

conmon fuzz target

I ran into containers/conmon#315 (comment) the other day and then I found https://ostif.org/wp-content/uploads/2022/06/CRI-O-audit-by-ada-logics-chainguard-ostif.pdf where scenarios like that were included in the threat model

... and
input from the container’s are also handled in Conmon. These are areas of potential attack
surface against Conmon.

and as far as I understand there should be a fuzz target:

We also developed a fuzzer for Conmon to analyse the logging and parsing routines in conmon/src/ctr_logging.c.

@DavidKorczynski I can't seem to find that fuzz target anywhere. Is there any chance you could point me in the right direction?

Support ARM images

I am on a Mac M1 (arm64) and seeing the following when pulling the images:

Unable to find image 'gcr.io/oss-fuzz-base/base-runner:latest' locally
latest: Pulling from oss-fuzz-base/base-runner
08c01a0ec47e: Pull complete 
26db2b7fb236: Pull complete 
1f44b92c8dd8: Pull complete 
48a0f87d472e: Pull complete 
987ef13f0fe0: Pull complete 
70c9ed524714: Pull complete 
5ec98123cb3e: Pull complete 
6be990f73bc1: Pull complete 
293df89222b6: Pull complete 
f74545e6eee4: Pull complete 
a9b0edd055b9: Pull complete 
065de64d84f6: Pull complete 
ef7ffe221187: Pull complete 
ee755a457c4d: Pull complete 
Digest: sha256:dde0612a1cefe5fc8fbac9e7046afbbd555553f5392a779ef96fa590bf13e964
Status: Downloaded newer image for gcr.io/oss-fuzz-base/base-runner:latest
WARNING: The requested image's platform (linux/amd64) does not match the detected host platform (linux/arm64/v8) and no specific platform was requested

Note that even though this looks just like an warning. I am running into segfaults when trying to test the pulled image.

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. 📊📈🎉

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google ❤️ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.