Skip to content

Fuzzing Ollama

Ollama is a downstream product, not a permanent alias for one upstream llama.cpp checkout. Audit the exact source and dependency revision in the Ollama build being tested, then compare a reproducer against the relevant upstream revision.

1. Pin the build

git -C /path/to/ollama rev-parse HEAD
crucible provenance --strict /path/to/ollama

Record submodules, generated sources, downloaded native libraries, build tags, and dirty state. Do not use VERSIONS.env as proof of affected versions; it is local build bookkeeping.

2. Locate the live parser

Inspect the pinned tree and build output to determine which native parser or loader actually ships. Paths and vendoring arrangements change. Prove the translation unit is built and the symbol is in the artifact before adapting a harness to a source copy.

3. Build the shallow and natural paths

Use the target Makefile when it matches the pinned tree:

make -C targets/ollama build-fuzz OLLAMA_SRC=/path/to/ollama
make -C targets/ollama libfuzzer OLLAMA_SRC=/path/to/ollama

Treat these targets as build recipes, not evidence that every current Ollama revision has the same layout. Run sanitizer canaries and the harness smoke/preflight checks after the build.

4. Run matched campaigns

Start with minimal and real model controls, then use the mutator appropriate to the actual format. If comparing structured and byte-only arms, keep target objects, corpus bytes, seed, limits, and environment matched and bank both binary hashes.

5. Attribute downstream versus upstream

For each unique Exact identity:

  1. replay on the pinned Ollama artifact;
  2. read the live source site;
  3. replay against the corresponding upstream dependency revision;
  4. test current upstream HEAD separately; and
  5. record whether the defect is downstream-only, inherited, already fixed upstream, or unknown.

Do not route a report from repository popularity or remembered policy. Read the current SECURITY.md and enabled private-reporting channels for the affected repository at disclosure time. The operator chooses and submits the channel.