[experimental] Add crash to Fuzzilli fuzzing to investigate ClusterFuzz [chromium/src : main]

0 views
Skip to first unread message

Tigran Bantikyan (Gerrit)

unread,
May 27, 2026, 5:08:14 PM (24 hours ago) May 27
to chromium...@chromium.org, ortuno...@chromium.org, titoua...@chromium.org

Message from Tigran Bantikyan

Set Ready For Review

Open in Gerrit

Related details

Attention set is empty
Submit Requirements:
  • requirement satisfiedCode-Coverage
  • requirement is not satisfiedCode-Owners
  • requirement is not satisfiedCode-Review
  • requirement is not satisfiedReview-Enforcement
Inspect html for hidden footers to help with email filtering. To unsubscribe visit settings. DiffyGerrit
Gerrit-MessageType: comment
Gerrit-Project: chromium/src
Gerrit-Branch: main
Gerrit-Change-Id: Ie1212b1bd5a559dc3e5361818ec0eb86d53cf515
Gerrit-Change-Number: 7878172
Gerrit-PatchSet: 1
Gerrit-Owner: Tigran Bantikyan <bant...@google.com>
Gerrit-Comment-Date: Wed, 27 May 2026 21:08:10 +0000
Gerrit-HasComments: No
Gerrit-Has-Labels: No
satisfied_requirement
unsatisfied_requirement
open
diffy

Tigran Bantikyan (Gerrit)

unread,
May 27, 2026, 5:08:32 PM (24 hours ago) May 27
to Giovanni Ortuno Urquidi, chromium...@chromium.org, ortuno...@chromium.org, titoua...@chromium.org
Attention needed from Giovanni Ortuno Urquidi

Tigran Bantikyan added 1 comment

Patchset-level comments
File-level comment, Patchset 1 (Latest):
Tigran Bantikyan . resolved

Hi Giovanni, PTAL.

Open in Gerrit

Related details

Attention is currently required from:
  • Giovanni Ortuno Urquidi
Submit Requirements:
  • requirement satisfiedCode-Coverage
  • requirement is not satisfiedCode-Owners
  • requirement is not satisfiedCode-Review
  • requirement is not satisfiedReview-Enforcement
Inspect html for hidden footers to help with email filtering. To unsubscribe visit settings. DiffyGerrit
Gerrit-MessageType: comment
Gerrit-Project: chromium/src
Gerrit-Branch: main
Gerrit-Change-Id: Ie1212b1bd5a559dc3e5361818ec0eb86d53cf515
Gerrit-Change-Number: 7878172
Gerrit-PatchSet: 1
Gerrit-Owner: Tigran Bantikyan <bant...@google.com>
Gerrit-Reviewer: Giovanni Ortuno Urquidi <ort...@chromium.org>
Gerrit-Attention: Giovanni Ortuno Urquidi <ort...@chromium.org>
Gerrit-Comment-Date: Wed, 27 May 2026 21:08:27 +0000
Gerrit-HasComments: Yes
Gerrit-Has-Labels: No
satisfied_requirement
unsatisfied_requirement
open
diffy

Giovanni Ortuno Urquidi (Gerrit)

unread,
May 27, 2026, 5:10:11 PM (24 hours ago) May 27
to Tigran Bantikyan, Giovanni Ortuno Urquidi, chromium...@chromium.org, ortuno...@chromium.org, titoua...@chromium.org

Giovanni Ortuno Urquidi voted Code-Review+1

Code-Review+1
Open in Gerrit

Related details

Attention set is empty
Submit Requirements:
  • requirement satisfiedCode-Coverage
  • requirement satisfiedCode-Owners
  • requirement is not satisfiedCode-Review
  • requirement satisfiedReview-Enforcement
Inspect html for hidden footers to help with email filtering. To unsubscribe visit settings. DiffyGerrit
Gerrit-MessageType: comment
Gerrit-Project: chromium/src
Gerrit-Branch: main
Gerrit-Change-Id: Ie1212b1bd5a559dc3e5361818ec0eb86d53cf515
Gerrit-Change-Number: 7878172
Gerrit-PatchSet: 1
Gerrit-Owner: Tigran Bantikyan <bant...@google.com>
Gerrit-Reviewer: Giovanni Ortuno Urquidi <ort...@chromium.org>
Gerrit-Comment-Date: Wed, 27 May 2026 21:10:04 +0000
Gerrit-HasComments: No
Gerrit-Has-Labels: Yes
satisfied_requirement
unsatisfied_requirement
open
diffy

Tigran Bantikyan (Gerrit)

unread,
May 27, 2026, 5:12:39 PM (24 hours ago) May 27
to Jocelyn Tran, Giovanni Ortuno Urquidi, chromium...@chromium.org, ortuno...@chromium.org, titoua...@chromium.org
Attention needed from Jocelyn Tran

Tigran Bantikyan added 1 comment

Patchset-level comments
Tigran Bantikyan . resolved

Hi Jocelyn, PTAL at this CL.

Open in Gerrit

Related details

Attention is currently required from:
  • Jocelyn Tran
Submit Requirements:
  • requirement satisfiedCode-Coverage
  • requirement satisfiedCode-Owners
  • requirement is not satisfiedCode-Review
  • requirement satisfiedReview-Enforcement
Inspect html for hidden footers to help with email filtering. To unsubscribe visit settings. DiffyGerrit
Gerrit-MessageType: comment
Gerrit-Project: chromium/src
Gerrit-Branch: main
Gerrit-Change-Id: Ie1212b1bd5a559dc3e5361818ec0eb86d53cf515
Gerrit-Change-Number: 7878172
Gerrit-PatchSet: 1
Gerrit-Owner: Tigran Bantikyan <bant...@google.com>
Gerrit-Reviewer: Giovanni Ortuno Urquidi <ort...@chromium.org>
Gerrit-Reviewer: Jocelyn Tran <jocel...@google.com>
Gerrit-Attention: Jocelyn Tran <jocel...@google.com>
Gerrit-Comment-Date: Wed, 27 May 2026 21:12:30 +0000
Gerrit-HasComments: Yes
Gerrit-Has-Labels: No
satisfied_requirement
unsatisfied_requirement
open
diffy

Jocelyn Tran (Gerrit)

unread,
10:25 AM (7 hours ago) 10:25 AM
to Tigran Bantikyan, Chromium LUCI CQ, Giovanni Ortuno Urquidi, chromium...@chromium.org, ortuno...@chromium.org, titoua...@chromium.org
Attention needed from Tigran Bantikyan

Jocelyn Tran voted and added 1 comment

Votes added by Jocelyn Tran

Code-Review+1

1 comment

File chrome/test/fuzzing/js_in_process_fuzzer.cc
Line 163, Patchset 1 (Latest): raise(SIGTERM);
Jocelyn Tran . unresolved

nit: Why not `CHECK(false)` or `base::ImmediateCrash()` here?

Open in Gerrit

Related details

Attention is currently required from:
  • Tigran Bantikyan
Submit Requirements:
    • requirement satisfiedCode-Coverage
    • requirement satisfiedCode-Owners
    • requirement satisfiedCode-Review
    • requirement is not satisfiedNo-Unresolved-Comments
    • requirement satisfiedReview-Enforcement
    Inspect html for hidden footers to help with email filtering. To unsubscribe visit settings. DiffyGerrit
    Gerrit-MessageType: comment
    Gerrit-Project: chromium/src
    Gerrit-Branch: main
    Gerrit-Change-Id: Ie1212b1bd5a559dc3e5361818ec0eb86d53cf515
    Gerrit-Change-Number: 7878172
    Gerrit-PatchSet: 1
    Gerrit-Owner: Tigran Bantikyan <bant...@google.com>
    Gerrit-Reviewer: Giovanni Ortuno Urquidi <ort...@chromium.org>
    Gerrit-Reviewer: Jocelyn Tran <jocel...@google.com>
    Gerrit-Attention: Tigran Bantikyan <bant...@google.com>
    Gerrit-Comment-Date: Thu, 28 May 2026 14:24:59 +0000
    Gerrit-HasComments: Yes
    Gerrit-Has-Labels: Yes
    satisfied_requirement
    unsatisfied_requirement
    open
    diffy

    Tigran Bantikyan (Gerrit)

    unread,
    10:41 AM (6 hours ago) 10:41 AM
    to Jocelyn Tran, Chromium LUCI CQ, Giovanni Ortuno Urquidi, chromium...@chromium.org, ortuno...@chromium.org, titoua...@chromium.org

    Tigran Bantikyan added 1 comment

    File chrome/test/fuzzing/js_in_process_fuzzer.cc
    Jocelyn Tran . resolved

    nit: Why not `CHECK(false)` or `base::ImmediateCrash()` here?

    Tigran Bantikyan

    Fuzzilli is specifically [looking for SIGTERM or SIGSEGV](https://crsrc.org/c/chrome/test/fuzzing/js_in_process_fuzzer.cc;l=107-113?ss=chromium&q=chrome%2Ftest%2Ffuzzing%2Fjs_in_process_fuzzer.cc). I believe those raise SIGABRT on Linux, but the implementation is platform dependent, so I found it simpler to raise SIGTERM explicitly.

    Open in Gerrit

    Related details

    Attention set is empty
    Submit Requirements:
      • requirement satisfiedCode-Coverage
      • requirement satisfiedCode-Owners
      • requirement satisfiedCode-Review
      • requirement satisfiedReview-Enforcement
      Inspect html for hidden footers to help with email filtering. To unsubscribe visit settings. DiffyGerrit
      Gerrit-MessageType: comment
      Gerrit-Project: chromium/src
      Gerrit-Branch: main
      Gerrit-Change-Id: Ie1212b1bd5a559dc3e5361818ec0eb86d53cf515
      Gerrit-Change-Number: 7878172
      Gerrit-PatchSet: 1
      Gerrit-Owner: Tigran Bantikyan <bant...@google.com>
      Gerrit-Reviewer: Giovanni Ortuno Urquidi <ort...@chromium.org>
      Gerrit-Reviewer: Jocelyn Tran <jocel...@google.com>
      Gerrit-Comment-Date: Thu, 28 May 2026 14:41:28 +0000
      Gerrit-HasComments: Yes
      Gerrit-Has-Labels: No
      Comment-In-Reply-To: Jocelyn Tran <jocel...@google.com>
      satisfied_requirement
      open
      diffy

      Tigran Bantikyan (Gerrit)

      unread,
      3:35 PM (1 hour ago) 3:35 PM
      to Jocelyn Tran, Chromium LUCI CQ, Giovanni Ortuno Urquidi, chromium...@chromium.org, ortuno...@chromium.org, titoua...@chromium.org

      Tigran Bantikyan voted Commit-Queue+2

      Commit-Queue+2
      Open in Gerrit

      Related details

      Attention set is empty
      Submit Requirements:
      • requirement satisfiedCode-Coverage
      • requirement satisfiedCode-Owners
      • requirement satisfiedCode-Review
      • requirement satisfiedReview-Enforcement
      Inspect html for hidden footers to help with email filtering. To unsubscribe visit settings. DiffyGerrit
      Gerrit-MessageType: comment
      Gerrit-Project: chromium/src
      Gerrit-Branch: main
      Gerrit-Change-Id: Ie1212b1bd5a559dc3e5361818ec0eb86d53cf515
      Gerrit-Change-Number: 7878172
      Gerrit-PatchSet: 1
      Gerrit-Owner: Tigran Bantikyan <bant...@google.com>
      Gerrit-Reviewer: Giovanni Ortuno Urquidi <ort...@chromium.org>
      Gerrit-Reviewer: Jocelyn Tran <jocel...@google.com>
      Gerrit-Reviewer: Tigran Bantikyan <bant...@google.com>
      Gerrit-Comment-Date: Thu, 28 May 2026 19:35:25 +0000
      Gerrit-HasComments: No
      Gerrit-Has-Labels: Yes
      satisfied_requirement
      open
      diffy

      Chromium LUCI CQ (Gerrit)

      unread,
      3:39 PM (1 hour ago) 3:39 PM
      to Tigran Bantikyan, Jocelyn Tran, Giovanni Ortuno Urquidi, chromium...@chromium.org, ortuno...@chromium.org, titoua...@chromium.org

      Chromium LUCI CQ submitted the change

      Change information

      Commit message:
      [experimental] Add crash to Fuzzilli fuzzing to investigate ClusterFuzz

      This CL introduces a crash for every JavaScript program that outputs a
      "EXPERIMENTAL_lock_manager_crash" and updates the
      MojoLockManagerProfile.swift profile to emit that string. This change is
      experimental in nature, as we seek to understand how ClusterFuzz will
      handle `js_in_process_fuzzer` fuzz target crashes.
      Bug: 517206974
      Change-Id: Ie1212b1bd5a559dc3e5361818ec0eb86d53cf515
      Commit-Queue: Tigran Bantikyan <bant...@google.com>
      Reviewed-by: Giovanni Ortuno Urquidi <ort...@chromium.org>
      Reviewed-by: Jocelyn Tran <jocel...@google.com>
      Cr-Commit-Position: refs/heads/main@{#1637881}
      Files:
      • M chrome/test/fuzzing/js_in_process_fuzzer.cc
      • M testing/libfuzzer/research/fuzzilli_mojom_fuzzing/MojoLockManagerProfile.swift
      Change size: XS
      Delta: 2 files changed, 8 insertions(+), 0 deletions(-)
      Branch: refs/heads/main
      Submit Requirements:
      • requirement satisfiedCode-Review: +1 by Giovanni Ortuno Urquidi, +1 by Jocelyn Tran
      Open in Gerrit
      Inspect html for hidden footers to help with email filtering. To unsubscribe visit settings. DiffyGerrit
      Gerrit-MessageType: merged
      Gerrit-Project: chromium/src
      Gerrit-Branch: main
      Gerrit-Change-Id: Ie1212b1bd5a559dc3e5361818ec0eb86d53cf515
      Gerrit-Change-Number: 7878172
      Gerrit-PatchSet: 2
      Gerrit-Owner: Tigran Bantikyan <bant...@google.com>
      Gerrit-Reviewer: Chromium LUCI CQ <chromiu...@luci-project-accounts.iam.gserviceaccount.com>
      Gerrit-Reviewer: Giovanni Ortuno Urquidi <ort...@chromium.org>
      Gerrit-Reviewer: Jocelyn Tran <jocel...@google.com>
      Gerrit-Reviewer: Tigran Bantikyan <bant...@google.com>
      open
      diffy
      satisfied_requirement
      Reply all
      Reply to author
      Forward
      0 new messages