google / google/oss-fuzz

Label or comment string to request OSS-Fuzz team look at an issue

Open
#6,974 9 comments 0 reactions 0 assignees View on GitHub
backlog
Dominant language
Shell
Stars
12.6k
Forks
2.9k
Avg merge
2d 2h
Merged PRs (30d)
62

Description

OSS-Fuzz bug reports say:

> This bug tracker is not being monitored by OSS-Fuzz team. If you have any questions, please create an issue at https://github.com/google/oss-fuzz/issues/new.

However, sometimes reports are caused by OSS-Fuzz infrastructure, not the fuzzers. Recently there have been a slew of build issues. Other times, LLVM regressions have triggered false positives in sanitizers. It is tedious to go to a separate system to report an issue, paste links back and forth, and then manually synchronize the two threads. Additionally, since the GitHub tracker is public, posting becomes extra difficult if it's unclear whether something is sanitizer false positive, or true regression.

I noticed myself even ignoring likely infra issues. The process for summoning the OSS-Fuzz team is difficult, infra issues will likely get reported elsewhere, and I may be too busy at the time for a time-consuming report. But that means rare infra issues go unnoticed. Worse, if it was a true positive, it gets lost in the noise.

There should be an easy, _inline_ way for project maintainers to tag an issue as needing OSS-Fuzz team feedback as part of triage.

Contributor guide

Open the contributing guide

Research direction

No file, test, or entry point is named. Start by examining the current OSS-Fuzz report and triage workflow described in the issue, then define the inline maintainer trigger, team notification path, and synchronization behavior that would make the request complete.

Written by the indexing model from the issue text.

Assessment

Tech stack
github
Domain
tooling
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.