Bugs that survive the heat of continuous fuzzing

Learn why some long-enrolled OSS-Fuzz projects still contain vulnerabilities and how you can find them.

The GitHub Blog

I have a draft PR open to improve coverage of #ApachePDFBox in #ossfuzz

For future reference, the current harnesses cover <10% of the codebase.

https://introspector.oss-fuzz.com/projects-overview

#OpenPrinting as part of the #linuxfoundation will again mentor 11 contributors in this year's Google Summer of Code! #GSoC

Our projects cover CUPS 3.x support for #KDE Print Manager, #GNOME Control Center, system-config-printer, pyCUPS, CUPS on #Zephyr, visual analysis of print output for testing, #Rust bindings for libcups/cpdb-libs, utilizing #OSSFuzz Gen, OSS-Fuzz for Go/Python projects, modernize #GTK print dialog, web site improvement with #Nextjs.

More soon on
https://openprinting.github.io/news/

News and Events

Making Printing Just Work.

OpenPrinting

At OpenPrinting we are full steam in the preparations for the Google Summer of Code 2025!

Many enthusiastic contributor candidates are already chatting with us, watching our videos, reading our introductions, studying our code, doing onboarding exercises ...

And what about you? We have listed 15 exciting project ideas, or you bring your own.

Introduction to read and to what, and the project ideas are here:

https://wiki.linuxfoundation.org/gsoc/google-summer-code-2025-openprinting-projects

#OpenPrinting #GSoC #CUPS #OSSfuzz #KDE #GNOME

gsoc:google-summer-code-2025-openprinting-projects [Wiki]

Woohoo! Many thanks to Oliver Chang and the #ossfuzz team!

First pr on google's #ossfuzz! Let's hope it doesn't break anything.

https://github.com/google/oss-fuzz/pull/12649

Build in stages to shed 9gb from the jvm base builder image by tballison · Pull Request #12649 · google/oss-fuzz

This PR reduces the final base-builder-jvm image by 9GB. Careful review and full integration testing across oss-fuzz projects is required before merging, obviously. This worked on two projects I wa...

GitHub
@varx
off topic but might be useful Google’s #ossfuzz project is a pretty amazing resource for fuzzing to find vulns in open source projects.

The schedules for the second #OpportunityOpenSource in the IIT Kanpur in India onn August 24-26 are ready!

3 rooms (2 talks/panels, 1 workshops) are packed with 50 amazing sessions!

There are:
- #OpenPrinting, with Michael Sweet, author of #CUPS
- #Zephyr
- #Snap, incl. workshop
- Hands-on with #firmware programming
- #BlendOS
- Workshop to make your own #Ubuntu flavor
- #OSSfuzz testing
- Population AI
- GSoC panel
- "Work at #Canonical" panel
- a lot more ...

https://events.canonical.com/event/89/timetable

Opportunity Open Source Conference

Conference web site Call for Abstracts extended until July 30!! Be a part of it! Are you astonished by what one can accomplish with free and open-source software? Are you amazed by what open-source communities put together with great enthusiasm? Would you like to know how this all relates to our daily life? Would you also like to become one of these individuals? Are you interested in coding for one of the many great free software projects? Applications? Desktop environments? System...

Canonical / Ubuntu Events (Indico)

If you need a pick me up, look no further than the tidbit that the maintainer who put the back door into xz got #ossfuzz to turn off the functionality that would have revealed the exploit.

This is not schadenfreude. I’ve made numerous lgtm mistakes in my work in open source.

This is just pure, unadulterated, gobsmacking hilarity.

https://social.treehouse.systems/@Aissen/112180302735030319

Anisse (@[email protected])

Looks like they even went and disabled the feature the exploit relied on on ossfuzz to prevent accidental discovery 😱​: https://github.com/google/oss-fuzz/pull/10667

Treehouse Mastodon

#OpenPrinting as a part of the #LinuxFoundation is participating in the 20th #GSoC, #GSoC2024!!

https://wiki.linuxfoundation.org/gsoc/google-summer-code-2024-openprinting-projects

We have lots of amazing project ideas this year:

- Desktop Integration of the new all-IPP printing architecture and #OAuth2: system-config-printer, #LibreOffice, #Thunderbird, #Firefox

- #OSSFuzz testing of OpenPrinting's components

- Printer Applications: #Gutenprint, #Braille

Contact us ASAP to get onboarded at OpenPrinting and to work out your proposal.

gsoc:google-summer-code-2024-openprinting-projects [Wiki]