TrinityCore / TrinityCore/TrinityCore

OSS-Fuzz integration

Open
#29,335 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Branch-master Invalid-IncompleteData/OrNotTrinityCore
Dominant language
C++
Stars
10.8k
Forks
6.4k
Avg merge
3d 16m
Merged PRs (30d)
6

Description

Description

Hi all,

Just enquiring to see if there is interest with regards to integrating this project into OSS-Fuzz? this would allow continuous testing of this project in order to identify memory corruption vulnerabilities using google's infrastructure with no monetary cost to this project. Google's OSS-Fuzz has identified 10,000 vulnerabilities and 36,000 bugs in 1000 open source projects as per https://google.github.io/oss-fuzz/#trophies. The process can be seen at https://google.github.io/oss-fuzz/architecture/ and I'm willing to integrate this project into OSS-Fuzz and write harnesses to test key functionalities of this project.

If this is something that everyone would like to see could you please let me know and provide me with an email or two in order to receive new issues found via fuzzing? I'm also happy to support with writing patches for any issues found.

Expected behaviour

n/a

Steps to reproduce the problem

n/a

Branch

master

TC rev. hash/commit

n/a

Operating system

n/a

Custom changes

n/a

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start by reviewing the linked OSS-Fuzz architecture and the project's integration requirements; the issue names no TrinityCore files, tests, or entry points. Done would mean an agreed OSS-Fuzz integration with harnesses for key functionality and a defined way to receive and address findings.

Written by the indexing model from the issue text.

Assessment

Tech stack
cpp
Domain
infrastructure, security, testing
Issue type
Feature
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.