Add fuzzing for JAR code
Categories
(Core :: Networking: JAR, task, P2)
Tracking
()
People
(Reporter: valentin, Assigned: valentin)
References
Details
(Keywords: sec-other, Whiteboard: [necko-triaged][adv-main118-])
Attachments
(1 file)
We've been looking at some JAR security bugs lately, and considering how old the code is, it isn't really tested well enough.
It would be great to have some fuzzing for this.
Chris, what's the usual approach here?
| Assignee | ||
Updated•3 years ago
|
| Assignee | ||
Updated•3 years ago
|
| Assignee | ||
Comment 1•3 years ago
|
||
Add back nsIZipReader.openMemory - Backed out changeset 1b442368d567
Updated•3 years ago
|
Comment 2•3 years ago
|
||
There's a r+ patch which didn't land and no activity in this bug for 2 weeks.
:valentin, could you have a look please?
If you still have some work to do, you can add an action "Plan Changes" in Phabricator.
For more information, please visit auto_nag documentation.
Updated•3 years ago
|
| Assignee | ||
Comment 3•3 years ago
|
||
I want to run this for a couple more days next week before we can land it.
Comment 4•3 years ago
|
||
I have been able to run the fuzzer with the patch for bug 1838117 applied for over 48h (running 5 instances) without hitting any issues on an ASan build. I think this is ready to land and I can get it running in automation.
Comment 6•2 years ago
|
||
Updated•2 years ago
|
Updated•2 years ago
|
Updated•2 years ago
|
Updated•2 years ago
|
Description
•