Add taglib project - #16067
Add taglib project#16067
Conversation
Integrate taglib (https://github.com/taglib/taglib), a widely used audio metadata library, into OSS-Fuzz. The fuzz target parses arbitrary in-memory input through TagLib::FileRef, exercising file type detection plus tag, audio property and complex property (picture) parsing for all supported formats: MP3/ID3v1/ID3v2, FLAC, Ogg/Vorbis/Opus/Speex, MP4/M4A, WAV/AIFF, APE/MPC/WavPack, DSF, DSDIFF, Matroska, Shorten, TrueAudio and tracker modules. Includes a format magic dictionary and a seed corpus built from taglib's own test data.
|
Reported the UBSan finding upstream: taglib/taglib#1429 (unchecked cast of the ASF attribute type word to |
|
youhaveme9 is integrating a new project: |
|
Coordination with the taglib maintainers is underway for hosting the fuzz target source in their repository: taglib/taglib#1431. Context: this integration's first run found undefined behavior in the ASF parser (taglib/taglib#1429, fixed in taglib/taglib#1430), which started the conversation with them. The build script here will be updated to compile the harness from the upstream tree once placement is agreed. |
DavidKorczynski
left a comment
There was a problem hiding this comment.
Project looks good. Waiting for targets to go upstream and coordination with maintainers.
The harness and dictionary now live in taglib's own repository under tests/fuzzing (merged in taglib/taglib#1433, agreed with the maintainers in taglib/taglib#1431), so the integration builds them from the upstream tree instead of carrying its own copy.
|
Following up on the upstream sourcing requirement: the fuzz target and dictionary now live in taglib's own repository under tests/fuzzing, agreed with the maintainer in taglib/taglib#1431 and merged as taglib/taglib#1433. The build script in this PR now compiles the harness from the upstream tree and no longer carries its own copy; both the address and undefined sanitizer builds were revalidated locally (build_fuzzers and check_build pass). |
| language: c++ | ||
| primary_contact: "ufleisch@users.sourceforge.net" | ||
| auto_ccs: | ||
| - "roshaen09@gmail.com" |
There was a problem hiding this comment.
can you please have the maintainers help review here, and confirm all the emails are okay to receive the reports with any issues found?
There was a problem hiding this comment.
I confirm that the "primary_contact" email is OK.
There was a problem hiding this comment.
Thanks @ufleisch -- can you also confirm you're happy the auto_ccs email receives details about any vulnerabilities found? Any emails in the project.yaml will have equal visibility into the vulnerabilities, including details on stack traces and reproducers.
There was a problem hiding this comment.
Yes, I agree that the email address currently listed under the auto_ccs key should receive the security reports.
|
Thanks. I've asked the taglib maintainer to review this PR and confirm the contact configuration in taglib/taglib#1431. Specifically to confirm that the primary contact address (ufleisch@users.sourceforge.net) is okay for receiving reports of any issues found, or to provide a preferred address; I'll update project.yaml accordingly once confirmed, and they may comment here directly as well. |
| language: c++ | ||
| primary_contact: "ufleisch@users.sourceforge.net" | ||
| auto_ccs: | ||
| - "roshaen09@gmail.com" |
There was a problem hiding this comment.
I confirm that the "primary_contact" email is OK.
|
Hello, a small ping: the taglib maintainer has since reviewed and approved this PR, and confirmed the contact email in the comments above. Thanks whenever you get a chance to look at it again. |
Integrates taglib — a widely used audio metadata library (deployed in KDE and countless players/tools) — into OSS-Fuzz.
Fuzz target:
taglib_fileref_fuzzerparses arbitrary in-memory input throughTagLib::FileRefwith aByteVectorStream, exercising file type detection plus tag, audio property and complex-property (picture) parsing for all supported formats: MP3/ID3v1/ID3v2, FLAC, Ogg Vorbis/Opus/Speex, MP4/M4A, WAV/AIFF, APE/MPC/WavPack, DSF/DSDIFF, Matroska/WebM, Shorten, TrueAudio and tracker modules (IT/XM/S3M/MOD).Extras: format magic dictionary and a seed corpus built from taglib's own test data (123 files covering every supported format).
Validation:
build_image,build_fuzzers(address + undefined) andcheck_buildall passlocal run: ~2,400 execs/s, 2.1M executions in a 15-minute campaign with no ASan crashes
the target already found a UBSan issue in the ASF parser within 60 seconds of fuzzing:
asfattribute.cpp:202:13: runtime error: load of value 55296, which is not a valid value for type 'AttributeTypes'ASF::Attribute::parse()casts an attacker-controlled WORD from the file toAttributeTypeswithout validating it; the subsequentswitch(d->type)is UB for out-of-range values. Reachable fromFileRefviaASF::File::read(). Will be reported upstream.