Skip to content

Add taglib project - #16067

Merged
DavidKorczynski merged 3 commits into
google:masterfrom
youhaveme9:add-taglib
Sep 6, 2026
Merged

DavidKorczynski merged 3 commits into
google:masterfrom
youhaveme9:add-taglib

Conversation

@youhaveme9

@youhaveme9 youhaveme9 commented Aug 25, 2026 •

Copy link
Copy Markdown
Contributor

Integrates taglib — a widely used audio metadata library (deployed in KDE and countless players/tools) — into OSS-Fuzz.

Fuzz target: taglib_fileref_fuzzer parses arbitrary in-memory input through TagLib::FileRef with a ByteVectorStream, exercising file type detection plus tag, audio property and complex-property (picture) parsing for all supported formats: MP3/ID3v1/ID3v2, FLAC, Ogg Vorbis/Opus/Speex, MP4/M4A, WAV/AIFF, APE/MPC/WavPack, DSF/DSDIFF, Matroska/WebM, Shorten, TrueAudio and tracker modules (IT/XM/S3M/MOD).

Extras: format magic dictionary and a seed corpus built from taglib's own test data (123 files covering every supported format).

Validation:

  • build_image, build_fuzzers (address + undefined) and check_build all pass

  • local run: ~2,400 execs/s, 2.1M executions in a 15-minute campaign with no ASan crashes

  • the target already found a UBSan issue in the ASF parser within 60 seconds of fuzzing:

    asfattribute.cpp:202:13: runtime error: load of value 55296, which is not a valid value for type 'AttributeTypes'

    ASF::Attribute::parse() casts an attacker-controlled WORD from the file to AttributeTypes without validating it; the subsequent switch(d->type) is UB for out-of-range values. Reachable from FileRef via ASF::File::read(). Will be reported upstream.

Integrate taglib (https://github.com/taglib/taglib), a widely used audio
metadata library, into OSS-Fuzz.

The fuzz target parses arbitrary in-memory input through TagLib::FileRef,
exercising file type detection plus tag, audio property and complex
property (picture) parsing for all supported formats: MP3/ID3v1/ID3v2,
FLAC, Ogg/Vorbis/Opus/Speex, MP4/M4A, WAV/AIFF, APE/MPC/WavPack, DSF,
DSDIFF, Matroska, Shorten, TrueAudio and tracker modules.

Includes a format magic dictionary and a seed corpus built from taglib's
own test data.
@youhaveme9

Copy link
Copy Markdown
Contributor Author

Reported the UBSan finding upstream: taglib/taglib#1429 (unchecked cast of the ASF attribute type word to AttributeTypes).

@github-actions

Copy link
Copy Markdown

youhaveme9 is integrating a new project:
- Main repo: https://github.com/taglib/taglib.git
- Criticality score: 0.54720

@youhaveme9

Copy link
Copy Markdown
Contributor Author

Coordination with the taglib maintainers is underway for hosting the fuzz target source in their repository: taglib/taglib#1431. Context: this integration's first run found undefined behavior in the ASF parser (taglib/taglib#1429, fixed in taglib/taglib#1430), which started the conversation with them. The build script here will be updated to compile the harness from the upstream tree once placement is agreed.

@DavidKorczynski DavidKorczynski left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Project looks good. Waiting for targets to go upstream and coordination with maintainers.

The harness and dictionary now live in taglib's own repository under
tests/fuzzing (merged in taglib/taglib#1433, agreed with the maintainers
in taglib/taglib#1431), so the integration builds them from the upstream
tree instead of carrying its own copy.
@youhaveme9

Copy link
Copy Markdown
Contributor Author

Following up on the upstream sourcing requirement: the fuzz target and dictionary now live in taglib's own repository under tests/fuzzing, agreed with the maintainer in taglib/taglib#1431 and merged as taglib/taglib#1433. The build script in this PR now compiles the harness from the upstream tree and no longer carries its own copy; both the address and undefined sanitizer builds were revalidated locally (build_fuzzers and check_build pass).

language: c++
primary_contact: "ufleisch@users.sourceforge.net"
auto_ccs:
- "roshaen09@gmail.com"

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

can you please have the maintainers help review here, and confirm all the emails are okay to receive the reports with any issues found?

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I confirm that the "primary_contact" email is OK.

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks @ufleisch -- can you also confirm you're happy the auto_ccs email receives details about any vulnerabilities found? Any emails in the project.yaml will have equal visibility into the vulnerabilities, including details on stack traces and reproducers.

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Yes, I agree that the email address currently listed under the auto_ccs key should receive the security reports.

@youhaveme9

Copy link
Copy Markdown
Contributor Author

Thanks. I've asked the taglib maintainer to review this PR and confirm the contact configuration in taglib/taglib#1431. Specifically to confirm that the primary contact address (ufleisch@users.sourceforge.net) is okay for receiving reports of any issues found, or to provide a preferred address; I'll update project.yaml accordingly once confirmed, and they may comment here directly as well.

language: c++
primary_contact: "ufleisch@users.sourceforge.net"
auto_ccs:
- "roshaen09@gmail.com"

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I confirm that the "primary_contact" email is OK.

@youhaveme9

Copy link
Copy Markdown
Contributor Author

Hello, a small ping: the taglib maintainer has since reviewed and approved this PR, and confirmed the contact email in the comments above. Thanks whenever you get a chance to look at it again.

@DavidKorczynski
DavidKorczynski merged commit e314e85 into google:master Sep 6, 2026
21 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants