Shaleen Jain

· 1 min read

Fuzzing libVLC - The Architecture

<blockquote> <p><em>Introduction to this blog post <a href="https://shaleenjain.com/blog/why-fuzz-vlc/">here</a></em></p> </blockquote> <h3 id="the-architecture"><a class="zola-anchor" href="#the-architecture" aria-label="Anchor link for: the-architecture">🔗</a> The Architecture</h3> <p>I met with the VLC developers and my mentor at the VideoLabs office in Paris and after a few meetings and discussions we had a pretty good idea on how we could fuzz test libVLC and the VLC core most appropriately.</p> <p>In VLC, except the core, everything is a module. There are over 200+ modules in VLC along with libVLCCore and libVLC.</p> <p>The main module categories that take an input are:</p> <ul> <li>Access</li> <li>Access-demuxer</li> <li>Demuxer</li> <li>Packetizer</li> <li>Decoder</li> <li>Video filter</li> </ul> <span id="continue-reading"></span> <p>The VLC core tries to load the modules of these categories in the following order:</p> <pre class="giallo" style="color: #657B83; background-color: #FDF6E3;" ><code data-lang="plain"><span class="giallo-l"><span>Access =&gt; Demux =&gt; [Packetizer] =&gt; Decoder =&gt; [Filter] =&gt; Out</span></span></code></pre> <p>We decided we would fuzz test at least the demux <abbr title="Application Programming Interface">API</abbr>, the decoder API, the packetizer API and possibly the video filter API’s which loads modules with these capabilities.</p> <p>Along with writing the fuzz targets for these API’s, I also need to provide a corpus of sample input so that libfuzzer can provide a structured input according to the video format/codec and not trip up the parse just because the basic headers and magic numbers were not in place.</p> <p>We have an end goal of eventually setting up an continuous fuzzing server either on ClusterFuzz by OSS-Fuzz or a server hosted by VideoLan. Using OSS-Fuzz has a lot of advantages such as their 1000+ CPU infrastructure, streamlined process, automated issue tracker, well tested and good documentation. But we have yet to decided which direction we’ll go from here.</p>
Liked this article? Share this with others

Got any questions or comments? Drop me a message on Twitter @shalzzj

Sign up for my newsletter to be the first to know about a new post