From 920b84d13e56be9e1649d29b75bad689f3741a82 Mon Sep 17 00:00:00 2001 From: OSS-Fuzz Team Date: Thu, 10 Sep 2026 11:30:08 -0700 Subject: [PATCH 1/2] Integrate LLVM at llvm/llvm-project@e30271b35d8d Updates LLVM usage to match [e30271b35d8d](https://github.com/llvm/llvm-project/commit/e30271b35d8de51d9f398b0b4ae9d103c156a4a8) Indexer-PiperOrigin-RevId: 979297507 --- infra/indexer/frontend/ast_visitor.cc | 5 +++-- 1 file changed, 3 insertions(+), 2 deletions(-) diff --git a/infra/indexer/frontend/ast_visitor.cc b/infra/indexer/frontend/ast_visitor.cc index e413944d88a1..c5d79a9f8147 100644 --- a/infra/indexer/frontend/ast_visitor.cc +++ b/infra/indexer/frontend/ast_visitor.cc @@ -45,6 +45,7 @@ #include "clang/Sema/Sema.h" #include "llvm/ADT/APSInt.h" #include "llvm/ADT/ArrayRef.h" +#include "llvm/ADT/FoldingSet.h" #include "llvm/ADT/MapVector.h" #include "llvm/ADT/SmallPtrSet.h" #include "llvm/ADT/SmallSet.h" @@ -139,9 +140,9 @@ const clang::ClassTemplateSpecializationDecl* FindSpecialization( // lead to loading external specializations. Arguably this could have been // handled through `mutable` fields because logically this doesn't affect the // forthcoming behavior of the object. - void* insert_pos = nullptr; + llvm::FoldingSetInsertToken insert_token; return const_cast(class_template_decl) - ->findSpecialization(canonical_args, insert_pos); + ->findSpecialization(canonical_args, insert_token); } // Helper functions to find the closest explicit template specialization that From 46184c7b43cb1a97f1e219dc2a37f71eaa841b18 Mon Sep 17 00:00:00 2001 From: Mike Jensen Date: Thu, 10 Sep 2026 13:21:04 -0600 Subject: [PATCH 2/2] tailscale: Update build.sh to use fuzz script in tailscale repo (#15996) This updates our build script to reference a script contained within the Tailscale repo (see PR https://github.com/tailscale/tailscale/pull/20862 ). This will expand the fuzzing we are doing under oss-fuzz. --- projects/tailscale/Dockerfile | 14 ++++++++------ projects/tailscale/build.sh | 2 +- 2 files changed, 9 insertions(+), 7 deletions(-) diff --git a/projects/tailscale/Dockerfile b/projects/tailscale/Dockerfile index 58c3c0533bd3..0c928a08ad0b 100644 --- a/projects/tailscale/Dockerfile +++ b/projects/tailscale/Dockerfile @@ -15,13 +15,15 @@ ################################################################################ FROM gcr.io/oss-fuzz-base/base-builder-go -RUN apt-get update && apt-get install -y wget + +# The Go version is intentionally not pinned here. tailscale's go.mod (`go` +# directive) is the single source of truth; GOTOOLCHAIN=auto fetches a matching +# toolchain at build time if the base image's bundled Go is older, and +# fuzz/oss-fuzz.sh copies it to a writable dir so go-118-fuzz-build_v2 can +# overlay its testing/fuzz.go. Bumping Go = editing go.mod in the tailscale repo; +# this Dockerfile stays untouched. + RUN git clone --depth 1 https://github.com/tailscale/tailscale -RUN wget https://go.dev/dl/go1.23.1.linux-amd64.tar.gz \ - && mkdir temp-go \ - && rm -rf /root/.go/* \ - && tar -C temp-go/ -xzf go1.23.1.linux-amd64.tar.gz \ - && mv temp-go/go/* /root/.go/ COPY build.sh $SRC/ WORKDIR $SRC/tailscale diff --git a/projects/tailscale/build.sh b/projects/tailscale/build.sh index 47f281ad7798..c2507074d0ae 100644 --- a/projects/tailscale/build.sh +++ b/projects/tailscale/build.sh @@ -15,4 +15,4 @@ # ################################################################################ -compile_go_fuzzer tailscale.com/net/stun FuzzStunParser stun_parser_fuzzer +bash -x ./fuzz/oss-fuzz.sh