Closed Bug 1720866 Opened 4 years ago Closed 3 years ago

Integrate wasm-smith in the JS engine as a fuzzing target

Categories

(Core :: JavaScript: WebAssembly, task, P3)

All
Linux
task

Tracking

()

RESOLVED FIXED
94 Branch
Tracking Status
firefox-esr78 --- wontfix
firefox-esr91 --- wontfix
firefox92 --- wontfix
firefox93 --- wontfix
firefox94 --- fixed

People

(Reporter: decoder, Assigned: decoder)

References

Details

(Keywords: sec-want, Whiteboard: [post-critsmash-triage][adv-main94-])

Attachments

(1 file)

The wasm-smith fuzzer [1] is a public high-logic WebAssembly module generator that we should integrate into our engine for additional WebAssembly coverage.

Keeping this bug locked until we had enough time to shake out initial bugs.

[1] https://github.com/bytecodealliance/wasm-tools/tree/main/crates/wasm-smith

Severity: -- → N/A
Priority: -- → P3
Status: ASSIGNED → RESOLVED
Closed: 3 years ago
Resolution: --- → FIXED
Target Milestone: --- → 94 Branch

Since the status are different for nightly and release, what's the status for beta?
For more information, please visit auto_nag documentation.

Flags: qe-verify-
Whiteboard: [post-critsmash-triage]
Group: core-security-release
Blocks: 1733903
Whiteboard: [post-critsmash-triage] → [post-critsmash-triage][adv-main94-]
You need to log in before you can comment on or make changes to this bug.

Attachment

General

Created:
Updated:
Size: