Re: [RESEND] Proposal: Continuous fuzzing support via OSS-Fuzz

Ondřej Kuzník <[email protected]> Mon, 23 Feb 2026 14:12:10 +0100
Newsgroups gmane.network.openldap.devel
Message-ID <[email protected]>
On Fri, Feb 13, 2026 at 02:06:34AM -0000, [email protected] wrote:
> Dear OpenLDAP team,
> 
> Apologies if this is a duplicate — I’m resending this message in case
> my previous post did not reach the list.
> 
> I’m writing to ask for guidance on potential ongoing fuzzing and
> security contributions for OpenLDAP. This is not a bug report or patch
> submission.
> 
> Brief context: we recently reported Bug 10429, which was fixed in MR
> 826 (thank you). We have since been applying our fuzzing
> infrastructure to OpenLDAP and integrated a set of LibFuzzer-based
> harnesses into OSS-Fuzz.
> 
> Draft OSS-Fuzz integration:
> https://github.com/google/oss-fuzz/pull/14872

Dear Mr. Zhang,
I had been wondering when we received a few bug reports that were either
acknowledged or looked to be coming from fuzzing. Whether some
universities started a course encouraging people find an open source
project and see if they can write a useful fuzzer. It's great to know
you are in charge of these efforts, they provide valuable testing.

I have done some fuzzing of liblber[0] a while ago that overlaps what
you have already proposed in OSS-Fuzz, have a look at my take and feel
free to expand your proposal accordingly if it feels useful.

> In addition to Bug 10429, several related issues identified through
> fuzzing have recently been reported to the Issue Tracking System by my
> collaborator Kang Yang (Issues 10445, 10446, 10447, 10448, 10449, and
> 10450), which further motivates broader and continuous fuzzing
> coverage.

Yes, those are touching parts that have not been fuzzed or not recently
and a bit more interesting. Would you be willing to add those somewhere
as well?

To give you more suggestions of where we would focus if we had the time:
- validators/normalisers for compiled syntaxes (might be able to trigger
  most via operation processing but many need specific configuration as
  they're not used by compiled in schemas) and if they decide the value
  passed, give it to the indexer etc. if available
- there are some lmdb tools[1] close to fuzzing (on the command stream,
  you can't expect to pass a random file in) but that's not as easy to
  generalise

If you need some changes to OpenLDAP, this is the right place to discuss
them and see how and what we can make happen. Also feel free propose
changes directly through the ITS system/Gitlab where you feel it's
appropriate.

In particular I suspect Kang Yang might have resurrected the no-threads
code from a long time ago to accomplish the above. We have removed it
for good reason but I understand that there might need to be something
that allows a fuzzer to dispatch in a controller manner. Some compile
time tweakables might still be a way to get there, not sure and Howard
might also have ideas once we can have a look at your take.

[0]. https://git.openldap.org/-/snippets/303
[1]. https://git.openldap.org/hyc/mtest_rand

Thank you,

-- 
Ondřej Kuzník
Senior Software Engineer
Symas Corporation                       http://www.symas.com
Packaged, certified, and supported LDAP solutions powered by OpenLDAP