[RESEND] Proposal: Continuous fuzzing support via OSS-Fuzz
[email protected] Fri, 13 Feb 2026 02:06:34 -0000
| Newsgroups | gmane.network.openldap.devel |
|---|---|
| Message-ID | <[email protected]> |
Dear OpenLDAP team, Apologies if this is a duplicate — I’m resending this message in case my previous post did not reach the list. I’m writing to ask for guidance on potential ongoing fuzzing and security contributions for OpenLDAP. This is not a bug report or patch submission. Brief context: we recently reported Bug 10429, which was fixed in MR 826 (thank you). We have since been applying our fuzzing infrastructure to OpenLDAP and integrated a set of LibFuzzer-based harnesses into OSS-Fuzz. Draft OSS-Fuzz integration: https://github.com/google/oss-fuzz/pull/14872 In addition to Bug 10429, several related issues identified through fuzzing have recently been reported to the Issue Tracking System by my collaborator Kang Yang (Issues 10445, 10446, 10447, 10448, 10449, and 10450), which further motivates broader and continuous fuzzing coverage. At present, this work lives entirely in OSS-Fuzz and does not modify the OpenLDAP source tree. We are continuing to verify additional harnesses and investigate findings; any confirmed bugs and patches will be submitted via the Issue Tracking System in accordance with the contribution guidelines. We would appreciate guidance on whether this OSS-Fuzz integration approach aligns with OpenLDAP’s expectations, and whether there are preferences regarding API scope or future in-tree fuzzing work. Thanks for your time. Best regards, Yunhang Zhang University of Utah