From 0f4d4d3004beb4946db46905163b1638777395a9 Mon Sep 17 00:00:00 2001 From: OSS-Fuzz Team Date: Thu, 30 Jul 2026 11:20:32 -0700 Subject: [PATCH 1/5] Integrate LLVM at llvm/llvm-project@6d1ace547c9f Updates LLVM usage to match [6d1ace547c9f](https://github.com/llvm/llvm-project/commit/6d1ace547c9f) Indexer-PiperOrigin-RevId: 956634975 --- infra/indexer/frontend/ast_visitor.cc | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/infra/indexer/frontend/ast_visitor.cc b/infra/indexer/frontend/ast_visitor.cc index dca1e0206407..e413944d88a1 100644 --- a/infra/indexer/frontend/ast_visitor.cc +++ b/infra/indexer/frontend/ast_visitor.cc @@ -36,11 +36,11 @@ #include "clang/AST/PrettyPrinter.h" #include "clang/AST/TemplateBase.h" #include "clang/AST/Type.h" +#include "clang/Basic/BuiltinTraits.h" #include "clang/Basic/FileEntry.h" #include "clang/Basic/OperatorKinds.h" #include "clang/Basic/SourceLocation.h" #include "clang/Basic/Specifiers.h" -#include "clang/Basic/TypeTraits.h" #include "clang/Sema/Lookup.h" #include "clang/Sema/Sema.h" #include "llvm/ADT/APSInt.h" From 43a11ed5de62ff310c04b4bf6bb919bee276893c Mon Sep 17 00:00:00 2001 From: Dmytro Shteflyuk Date: Thu, 30 Jul 2026 16:28:36 -0400 Subject: [PATCH 2/5] Fix thrift-rb source revision attribution (#15931) MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit The build source map records Apache Thrift as https://github.com/apache/thrift.git, while `project.yaml` used the equivalent URL without `.git`. ClusterFuzz compares these URLs exactly when selecting the main component; the mismatch made it fall back to alphabetical ordering and report Ruzzy’s revision as the tested/regressed revision. Using the canonical .git URL lets ClusterFuzz prioritize Apache Thrift and report its revision correctly. https://oss-fuzz.com/testcase-detail/4583322718896128 CleanShot 2026-07-30 at 11 59 09@2x --- projects/thrift-rb/project.yaml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/projects/thrift-rb/project.yaml b/projects/thrift-rb/project.yaml index 20af8d8c114f..222eec496583 100644 --- a/projects/thrift-rb/project.yaml +++ b/projects/thrift-rb/project.yaml @@ -9,4 +9,4 @@ fuzzing_engines: sanitizers: - address -main_repo: "https://github.com/apache/thrift" +main_repo: "https://github.com/apache/thrift.git" From 55fee414145b8f95394787213291fd3835f10429 Mon Sep 17 00:00:00 2001 From: Jonathan Hedley Date: Fri, 31 Jul 2026 06:30:57 +1000 Subject: [PATCH 3/5] jsoup: catch re2j runtime pattern complexity errors (#15925) Update jsoup's CSS/HTML fuzzer to treat selector validation failures as rejected inputs. jsoup now normalizes re2j runtime pattern-complexity errors into `ValidationException`. The fuzzer should ignore these expected validation failures alongside selector parse errors. Validation: - `python3 infra/helper.py check_build jsoup CssHtmlFuzzer` --- projects/jsoup/CssHtmlFuzzer.java | 15 +++++++-------- 1 file changed, 7 insertions(+), 8 deletions(-) diff --git a/projects/jsoup/CssHtmlFuzzer.java b/projects/jsoup/CssHtmlFuzzer.java index 04589c98d6da..48e2e18d542c 100644 --- a/projects/jsoup/CssHtmlFuzzer.java +++ b/projects/jsoup/CssHtmlFuzzer.java @@ -23,16 +23,15 @@ public class CssHtmlFuzzer { public static void fuzzerTestOneInput(FuzzedDataProvider data) { - String css = data.consumeString(100); - Evaluator query; try { - query = Selector.evaluatorOf(css); + String css = data.consumeString(100); + Evaluator query = Selector.evaluatorOf(css); + + String html = data.consumeRemainingAsString(); + Document doc = Jsoup.parse(html, "https://example.com"); + doc.select(query); } catch (ValidationException | Selector.SelectorParseException ignored) { - return; + // invalid or overly complex selector } - - String html = data.consumeRemainingAsString(); - Document doc = Jsoup.parse(html, "https://example.com"); - doc.select(query); } } From 618b075b428b124efca9a7fbd48e7181e1b354e6 Mon Sep 17 00:00:00 2001 From: "Adi (Suissa) Peleg" Date: Thu, 30 Jul 2026 16:31:28 -0400 Subject: [PATCH 4/5] [envoy] using docker-local glibc (#15921) This PR updates the compiler used when building the fuzzers to be the one provided by the underlying ubuntu image. Prior to this PR, the build process would use Envoy's hermetic LLVM to build the fuzzers. However, the required glibc version by the LLVM is incompatible with the one provided by the underlying image. We get the following error: ``` Step #3 - "compile-honggfuzz-address-x86_64": # Execution platform: @@internal_platforms_do_not_use//host:host Step #3 - "compile-honggfuzz-address-x86_64": external/llvm_toolchain_llvm/bin/clang: /lib/x86_64-linux-gnu/libstdc++.so.6: version `GLIBCXX_3.4.29' not found (required by external/llvm_toolchain_llvm/bin/clang) Step #3 - "compile-honggfuzz-address-x86_64": external/llvm_toolchain_llvm/bin/clang: /lib/x86_64-linux-gnu/libstdc++.so.6: version `GLIBCXX_3.4.30' not found (required by external/llvm_toolchain_llvm/bin/clang) Step #3 - "compile-honggfuzz-address-x86_64": external/llvm_toolchain_llvm/bin/clang: /lib/x86_64-linux-gnu/libstdc++.so.6: version `CXXABI_1.3.13' not found (required by external/llvm_toolchain_llvm/bin/clang) Step #3 - "compile-honggfuzz-address-x86_64": external/llvm_toolchain_llvm/bin/clang: /lib/x86_64-linux-gnu/libc.so.6: version `GLIBC_2.32' not found (required by external/llvm_toolchain_llvm/bin/clang) Step #3 - "compile-honggfuzz-address-x86_64": external/llvm_toolchain_llvm/bin/clang: /lib/x86_64-linux-gnu/libc.so.6: version `GLIBC_2.33' not found (required by external/llvm_toolchain_llvm/bin/clang) Step #3 - "compile-honggfuzz-address-x86_64": external/llvm_toolchain_llvm/bin/clang: /lib/x86_64-linux-gnu/libc.so.6: version `GLIBC_2.34' not found (required by external/llvm_toolchain_llvm/bin/clang) ``` We tried to upgrade the underlying ubuntu image to v24.04, however other version incompatibilities were observed. --- projects/envoy/Dockerfile | 7 ++++++- projects/envoy/build.sh | 4 ++++ 2 files changed, 10 insertions(+), 1 deletion(-) diff --git a/projects/envoy/Dockerfile b/projects/envoy/Dockerfile index 124becda6a3f..39762b987b5d 100644 --- a/projects/envoy/Dockerfile +++ b/projects/envoy/Dockerfile @@ -30,7 +30,12 @@ RUN apt-get update && apt-get -y install \ golang \ rsync \ python3 \ - libtinfo5 + libtinfo5 \ + libunwind-dev \ + libclang-dev + +RUN ln -s /usr/lib/x86_64-linux-gnu/libunwind.a /usr/local/lib/libunwind.a && \ + ln -s /usr/lib/llvm-10/lib/libclang.so /usr/local/lib/libclang.so RUN git clone https://github.com/envoyproxy/envoy.git WORKDIR $SRC/envoy/ diff --git a/projects/envoy/build.sh b/projects/envoy/build.sh index 00ae668fdee5..bc1cc5991823 100755 --- a/projects/envoy/build.sh +++ b/projects/envoy/build.sh @@ -33,6 +33,9 @@ declare -r EXTRA_BAZEL_FLAGS="$( # Disabling layering_check because it breaks the abseil build. See # https://github.com/google/oss-fuzz/blob/f0fa8b5cd3f99b5905e91b336d07a870ca1bc2e3/projects/abseil-cpp/build.sh#L17-L21. echo "--features=-layering_check" +echo "--repo_env=BAZEL_LLVM_PATH=/usr/local" +echo "--repo_env=BAZEL_USE_LIBSTDCPP=True" +echo "--copt=-Wno-nullability-completeness" if [ -n "$CC" ]; then echo "--action_env=CC=${CC}" fi @@ -40,6 +43,7 @@ if [ -n "$CXX" ]; then echo "--action_env=CXX=${CXX}" fi echo "--host_action_env=CC=gcc" +echo "--host_action_env=CXX=g++" echo "--copt=-gz=zlib" echo "--linkopt=-Wl,--compress-debug-sections=zlib" echo "--linkopt=-Wl,--icf=all" From 29be6d35464598707a01542c17b7acd1c358a0fd Mon Sep 17 00:00:00 2001 From: Stephen Smalley Date: Thu, 30 Jul 2026 16:31:54 -0400 Subject: [PATCH 5/5] projects/selinux/project.yaml: add other selinux maintainers (#15932) Add Paul Moore (@pcmoore) and Jason Zaman (@perfinion), both active SELinux maintainers, to the cc list. These addresses are allegedly Google mail accounts despite not being @gmail.com; let us know if these won't work and we will provide gmail ones. Signed-off-by: Stephen Smalley --- projects/selinux/project.yaml | 2 ++ 1 file changed, 2 insertions(+) diff --git a/projects/selinux/project.yaml b/projects/selinux/project.yaml index fac681dee68d..2fe7499696ed 100644 --- a/projects/selinux/project.yaml +++ b/projects/selinux/project.yaml @@ -12,6 +12,8 @@ auto_ccs: - jwcart2@gmail.com - cgzones@googlemail.com - stephen.smalley.work@gmail.com + - paul@paul-moore.com + - jason@perfinion.com main_repo: 'https://github.com/SELinuxProject/selinux' fuzzing_engines: