google / google/oss-fuzz

Question About Initial Input Seeds for Fuzzing Libraries in OSS-Fuzz

Open
#12,422 4 comments 0 reactions 0 assignees View on GitHub
Dominant language
Shell
Stars
12.6k
Forks
2.9k
Avg merge
2d 2h
Merged PRs (30d)
62

Description

I have some questions regarding the initial input seeds used for fuzzing these libraries.
The libraries in question are binutils, cairo, libzip, llvm, mupdf, and sqlite3.
I would like to know:

1. Are the initial input seeds used by OSS-Fuzz manually created by humans, or are they generated through fuzzing campaigns?

2. If there are human-made initial input seeds, can the most recent versions be accessed?

3. Alternatively, if only seeds from fuzzing campaigns are available, could I obtain the oldest initial input seeds that have undergone the fewest fuzzing iterations?

Contributor guide

Open the contributing guide

Research direction

This is an information request about initial fuzzing seeds for binutils, cairo, libzip, llvm, mupdf, and sqlite3 rather than a code change. Start by locating each library's OSS-Fuzz project configuration and tracing how its initial corpus is sourced. Done means documenting seed provenance and access paths, or stating that the requested seeds are unavailable; no file or test is named.

Written by the indexing model from the issue text.

Assessment

Domain
security, testing
Issue type
Documentation
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.