Closed Bug 1798631 Opened 3 years ago Closed 2 years ago

Add fuzzing for JAR code

Categories

(Core :: Networking: JAR, task, P2)

task

Tracking

()

RESOLVED FIXED
118 Branch
Tracking Status
firefox-esr102 --- wontfix
firefox-esr115 --- wontfix
firefox116 --- wontfix
firefox117 --- wontfix
firefox118 --- fixed

People

(Reporter: valentin, Assigned: valentin)

References

Details

(Keywords: sec-other, Whiteboard: [necko-triaged][adv-main118-])

Attachments

(1 file)

We've been looking at some JAR security bugs lately, and considering how old the code is, it isn't really tested well enough.
It would be great to have some fuzzing for this.

Chris, what's the usual approach here?

Flags: needinfo?(choller)
Severity: -- → N/A
Priority: -- → P2
Whiteboard: [necko-triaged]
Keywords: sec-other
Flags: needinfo?(choller)
See Also: → CVE-2026-2779, 1797370

Add back nsIZipReader.openMemory - Backed out changeset 1b442368d567

Assignee: nobody → valentin.gosu
Status: NEW → ASSIGNED

There's a r+ patch which didn't land and no activity in this bug for 2 weeks.
:valentin, could you have a look please?
If you still have some work to do, you can add an action "Plan Changes" in Phabricator.
For more information, please visit auto_nag documentation.

Flags: needinfo?(valentin.gosu)
Flags: needinfo?(kershaw)
Flags: needinfo?(kershaw)

I want to run this for a couple more days next week before we can land it.

Flags: needinfo?(valentin.gosu)

I have been able to run the fuzzer with the patch for bug 1838117 applied for over 48h (running 5 instances) without hitting any issues on an ASan build. I think this is ready to land and I can get it running in automation.

Pushed by valentin.gosu@gmail.com: https://hg.mozilla.org/integration/autoland/rev/bfcf1b0a05b4 Add zip reader fuzzer r=decoder,necko-reviewers,kershaw
Group: network-core-security → core-security-release
Status: ASSIGNED → RESOLVED
Closed: 2 years ago
Resolution: --- → FIXED
Target Milestone: --- → 118 Branch
QA Whiteboard: [post-critsmash-triage]
Whiteboard: [necko-triaged] → [necko-triaged][adv-main118-]
Group: core-security-release
You need to log in before you can comment on or make changes to this bug.

Attachment

General

Created:
Updated:
Size: