Skip to content

libvips: exclude dependencies from static introspection - #16171

Draft
kleisauke wants to merge 1 commit into
google:masterfrom
kleisauke:libvips-fix-fuzz-introspector-2
Draft

kleisauke wants to merge 1 commit into
google:masterfrom
kleisauke:libvips-fix-fuzz-introspector-2

Conversation

@kleisauke

Copy link
Copy Markdown
Contributor

Follow up to: #16158.

@kleisauke

Copy link
Copy Markdown
Contributor Author

PR #16158 didn't work, see e.g.:
https://oss-fuzz-build-logs.storage.googleapis.com/log-74347519-9a4d-46fa-b0b8-78cf5daad3eb.txt

So, let's exclude dependencies from the light introspector analysis by cloning them into /deps and symlinking them into $SRC/. Hopefully, this will also work on ClusterFuzz.

Tested with:

$ time python3 infra/helper.py introspector libvips --private-corpora
[...]
2026-09-23 08:12:05.043 INFO oss_fuzz - analyse_folder: Found 593 files to include in analysis
2026-09-23 08:12:05.043 INFO oss_fuzz - analyse_folder: Going C/C++ route
2026-09-23 08:12:05.043 INFO oss_fuzz - analyse_folder: Loading tree-sitter trees
2026-09-23 08:12:12.515 INFO frontend_c_cpp - load_treesitter_trees: harness: /src/libvips/fuzz/generic_buffer_fuzzer.cc
2026-09-23 08:12:12.547 INFO frontend_c_cpp - load_treesitter_trees: harness: /src/libvips/fuzz/generic_buffer_with_args_fuzzer.cc
2026-09-23 08:12:12.578 INFO frontend_c_cpp - load_treesitter_trees: harness: /src/libvips/fuzz/jpegsave_file_fuzzer.cc
2026-09-23 08:12:12.599 INFO frontend_c_cpp - load_treesitter_trees: harness: /src/libvips/fuzz/mosaic_fuzzer.cc
2026-09-23 08:12:12.620 INFO frontend_c_cpp - load_treesitter_trees: harness: /src/libvips/fuzz/sharpen_fuzzer.cc
2026-09-23 08:12:12.640 INFO frontend_c_cpp - load_treesitter_trees: harness: /src/libvips/fuzz/smartcrop_fuzzer.cc
2026-09-23 08:12:12.661 INFO frontend_c_cpp - load_treesitter_trees: harness: /src/libvips/fuzz/thumbnail_fuzzer.cc
2026-09-23 08:12:12.736 INFO frontend_c_cpp - load_treesitter_trees: harness: /src/libvips/fuzz/vips_fuzzer.cc
2026-09-23 08:13:15.877 INFO oss_fuzz - analyse_folder: Dump methods for generic_buffer_fuzzer
2026-09-23 08:13:15.878 INFO datatypes - dump_module_logic: Generating report
2026-09-23 08:13:55.459 INFO datatypes - dump_module_logic: Report generated
2026-09-23 08:13:55.601 INFO datatypes - dump_module_logic: Dumping project-wide logic.
2026-09-23 08:13:55.601 INFO datatypes - dump_module_logic: Using safe yaml safe C dumper.
2026-09-23 08:13:57.408 INFO datatypes - dump_module_logic: Dumped
2026-09-23 08:13:57.417 INFO oss_fuzz - analyse_folder: Extracting calltree for generic_buffer_fuzzer
2026-09-23 08:13:59.269 INFO oss_fuzz - analyse_folder: Calltree extracted
2026-09-23 08:13:59.270 INFO datatypes - dump_type_definition: Dumping custom type definitions.
2026-09-23 08:13:59.275 INFO datatypes - dump_type_definition: Custom type definitions dumping completed.
2026-09-23 08:13:59.275 INFO datatypes - dump_macro_block_info: Dumping macro blocks information.
2026-09-23 08:13:59.279 INFO datatypes - dump_macro_block_info: Macro blocks information dumping completed.
[...]
INFO:__main__:Introspector run complete. Report in /home/kleisauke/oss-fuzz/build/out/libvips/introspector-report/inspector
INFO:__main__:To browse the report, run: `python3 -m http.server 8008 --directory /home/kleisauke/oss-fuzz/build/out/libvips/introspector-report/inspector`and navigate to localhost:8008/fuzz_report.html in your browser

real	181m55.454s
user	1m8.708s
sys	0m47.571s
$ echo $?
0

If this doesn't work on ClusterFuzz, I'm out of ideas and would prefer to opt-out (perhaps via an env variable?) of the light FI introduced in commit fb88de8 (since the version based on regular LTO works fine).

@github-actions

Copy link
Copy Markdown

kleisauke has previously contributed to projects/libvips. The previous PR was #16158

@kleisauke

kleisauke commented Sep 23, 2026 •

Copy link
Copy Markdown
Contributor Author

I also added commit eb3d426 to this PR to ensure srcmap correctly handles symlinked source directories.

Before
$ docker run -it -e FUZZING_LANGUAGE=c++ gcr.io/oss-fuzz/libvips /bin/bash -c srcmap
{
  "/src/seed-corpora": {
    "type": "git",
    "url": "https://github.com/libvips/seed-corpora.git",
    "rev": "4d14170c78172da46babe9b5bb4158484ef538c9"
  },
  "/src/libvips": {
    "type": "git",
    "url": "https://github.com/libvips/libvips.git",
    "rev": "bb5b1b63c96a699414157dd20ec933af16d7e6a5"
  }
}
After
$ docker run -it -e FUZZING_LANGUAGE=c++ -v ./infra/base-images/base-builder/srcmap:/usr/local/bin/srcmap gcr.io/oss-fuzz/libvips /bin/bash -c srcmap
{
  "/src/aom": {
    "type": "git",
    "url": "https://aomedia.googlesource.com/aom",
    "rev": "b4ce2cd097b00921b0327bfb5f07b5f8361ade99"
  },
  "/src/cgif": {
    "type": "git",
    "url": "https://github.com/dloebl/cgif.git",
    "rev": "b68f18ac125085923cae83b458e019e89feebe25"
  },
  "/src/highway": {
    "type": "git",
    "url": "https://github.com/google/highway.git",
    "rev": "9d1374260ad6f234aa7bafcfccf48abe96c41999"
  },
  "/src/lcms": {
    "type": "git",
    "url": "https://github.com/mm2/Little-CMS.git",
    "rev": "a0b0d7a69b13b461bdbd9cff9f7f1d59ccd1858c"
  },
  "/src/libexif": {
    "type": "git",
    "url": "https://github.com/libexif/libexif.git",
    "rev": "282d7c6f161718fa5cf417120b05116c1ecc3f43"
  },
  "/src/libheif": {
    "type": "git",
    "url": "https://github.com/strukturag/libheif.git",
    "rev": "5c7b41f3cc097447dd3c700cc9ec7d94fbb59eec"
  },
  "/src/libimagequant": {
    "type": "git",
    "url": "https://github.com/lovell/libimagequant.git",
    "rev": "ce5fdeb1ccd9db288950faa21fd09c42c0a59bbb"
  },
  "/src/libjpeg-turbo": {
    "type": "git",
    "url": "https://github.com/libjpeg-turbo/libjpeg-turbo.git",
    "rev": "2a8bd381b42664e72cfc0f652db6caf4c9e98117"
  },
  "/src/libjxl": {
    "type": "git",
    "url": "https://github.com/libjxl/libjxl.git",
    "rev": "b87738951c1254cd8cccaa6d47712ba735da56d8"
  },
  "/src/libpng": {
    "type": "git",
    "url": "https://github.com/pnggroup/libpng.git",
    "rev": "964b4135949703b705fc760fc3fb546b86e5ab47"
  },
  "/src/libtiff": {
    "type": "git",
    "url": "https://gitlab.com/libtiff/libtiff.git",
    "rev": "0962d91b19f172eba97caf2ee31995a39d99768b"
  },
  "/src/libultrahdr": {
    "type": "git",
    "url": "https://github.com/google/libultrahdr.git",
    "rev": "f3e36226914289cfefcf0d81a6471cf6266c79fb"
  },
  "/src/libwebp": {
    "type": "git",
    "url": "https://chromium.googlesource.com/webm/libwebp",
    "rev": "e7a9045111cfb6349affc37e64d6664f5f77dc93"
  },
  "/src/zlib": {
    "type": "git",
    "url": "https://github.com/madler/zlib.git",
    "rev": "767c4c947852e143f582c85f14cf573411df1b35"
  },
  "/src/seed-corpora": {
    "type": "git",
    "url": "https://github.com/libvips/seed-corpora.git",
    "rev": "4d14170c78172da46babe9b5bb4158484ef538c9"
  },
  "/src/libvips": {
    "type": "git",
    "url": "https://github.com/libvips/libvips.git",
    "rev": "bb5b1b63c96a699414157dd20ec933af16d7e6a5"
  }
}

(Happy to split this change out into a separate PR if needed)

Edit: split out into PR #16210.

@kleisauke
kleisauke force-pushed the libvips-fix-fuzz-introspector-2 branch from eb3d426 to decf42c Compare September 30, 2026 09:51
@kleisauke
kleisauke marked this pull request as draft September 30, 2026 09:52
@kleisauke

Copy link
Copy Markdown
Contributor Author

Marked as a draft since this depends on PR #16210.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant