lwip-devel
[Top][All Lists]
Advanced

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[lwip-devel] [bug #64010] oss-fuzz integration


From: Simon Goldschmidt
Subject: [lwip-devel] [bug #64010] oss-fuzz integration
Date: Fri, 14 Apr 2023 14:11:13 -0400 (EDT)

Follow-up Comment #13, bug #64010 (project lwip):

To come back to this issue from a project leader point of view, I'm now not
sure what to say.

I can repeat what I said in comment #3 ("We do have fuzzing, only we don't
have the computing power to extensively run it..."), but I guess for the
"hardcore" GNU guys, that doesn't count?

Otoh, we (as lwIP) do not even provide our sources as GPL but "only" as BSD,
so we're probably part of the "bad guys" as well?

And finally, let's face reality: we do have a github mirror as well. We even
use it for our CI. And we do so because we're lazy and github "just works".
Does that make us even more bad?

That being said, I'm thankful for jne's work on fuzzing, but I'm still not
sure oss-fuzz is a good idea, both because of the mentioned "free XYZ" issues
(the question for me here is "why do we get that service for free?") and
because I'm afraid to get too many reports I have to handle. However, I'd
still be willing to try some kind of "fuzzing-CI".


    _______________________________________________________

Reply to this item at:

  <https://savannah.nongnu.org/bugs/?64010>

_______________________________________________
Message sent via Savannah
https://savannah.nongnu.org/




reply via email to

[Prev in Thread] Current Thread [Next in Thread]