|
|
Log in / Subscribe / Register

A fuzzy issue of responsible disclosure

A fuzzy issue of responsible disclosure

Posted Aug 14, 2022 2:15 UTC (Sun) by bferrell (subscriber, #624)
In reply to: A fuzzy issue of responsible disclosure by bferrell
Parent article: A fuzzy issue of responsible disclosure

I went back and re-read it VERY SLOWLY AND CAREFULLY. There is one developer who has been doing it and gotten some results.

The complaint (I think valid) from the rest of the devs that the flood of raw data is ridiculous and impossible. "The fizkiddies" need to triage the junk they're spewing... IMHO, it seems fuzzing has the come to look like:

"... would be a giant diesel-smoking BUS with hundreds of EBOLA victims and a TOILET spewing out on the road behind it. Throwing DEAD WOMBATS and rotten cabbage at the other cars most of which have been ASSEMBLED AT HOME from kits. Some are 2.5 horsepower LAWNMOWER ENGINES with a top speed of nine miles an hour. Others burn NITROGLYCERINE and IDLE at 120. "

Stolen shamelessly from The "Information Superhighway" Highway


to post comments

A fuzzy issue of responsible disclosure

Posted Aug 15, 2022 17:16 UTC (Mon) by randomguy3 (subscriber, #71063) [Link]

I was referring to this bit:
the fstests suite contains a set of XFS-specific fuzzing tests, so the sorts of bugs that fuzz testers can find have already been fixed in XFS.

A fuzzy issue of responsible disclosure

Posted Aug 19, 2022 1:15 UTC (Fri) by giraffedata (guest, #1954) [Link] (1 responses)

According to the article, XFS developer Darrick Wong (at least) believes these fuzzers should do a lot more than triage - he thinks they should debug (i.e. diagnose the bugs).

(Or maybe that's what you meant, but triage normally is a metaphor for the battlefield medicine practice of sorting patients into priority order based on prognosis, and I don't think sorting the bugs would satisfy Darrick Wong at all).

A fuzzy issue of responsible disclosure

Posted Aug 19, 2022 13:51 UTC (Fri) by mathstuf (subscriber, #69389) [Link]

Sorting and deduplication could certainly help though. Probably not a *solution*, but I'd consider it progress. Such triage also helps less experienced developers have a shot at fixing it too.

I know there are certainly issues on the projects I work on that I've done the "here's where the code that needs changed lives" diagnosis publicly and sometimes contributors step up to actually do the work.


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds