Skip to content
CAI
Software that uses CAICheck a score

googleprojectzero/fuzzilli

50.2

Adequate · 1 October 2026

67.5k

lines of production code

Swift

primary language

2

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

Fuzzilli is an open-source, coverage-guided fuzzer designed to discover vulnerabilities in JavaScript engines and WebAssembly runtimes. It operates by generating and mutating JavaScript programs via an intermediate representation (FuzzIL), executing them within instrumented engine instances using REPRL for process isolation, and analyzing crashes through differential fuzzing and coverage tracking. The system supports a wide range of targets—including V8, SpiderMonkey, and JavaScriptCore—via Dockerized build environments and distributed cloud clusters, while providing tools for corpus management, program minimization, and automated crash triage.

How it got here

2019 — Open-source release and major refactoring

24 changes.

Fuzzilli was released as open source, accompanied by a comprehensive overhaul of its core architecture to support modern JavaScript and WebAssembly features. The project replaced legacy components with a new type system, lifter, and execution engine, while adding support for differential fuzzing and distributed testing across multiple platforms.

2020 — Docker-based infrastructure and serialization

14 changes.

This period focused on establishing a reproducible, containerized fuzzing environment by introducing Docker builders for multiple JavaScript engines and GCE deployment scripts. Concurrently, the project modernized its internal data handling by switching FuzzIL program serialization to Protocol Buffers and expanded target support with new integrations for JerryScript, QuickJS, and Duktape.

2021–2026 — JavaScript engine expansion and compiler infrastructure

17 changes.

This period focused on expanding Fuzzilli's support for diverse JavaScript engines by adding new targets like QtJS, NJS, and profiles for Duktape and JerryScript. Significant infrastructure work included implementing a JavaScript-to-FuzzIL compiler and parser to ingest real-world code, alongside a Markov-based corpus manager to improve coverage-guided fuzzing efficiency. The work also introduced tools for differential fuzzing against V8 and validation of WebAssembly generation via Binaryen.

Features

Add GCE deployment scripts and configuration for distributed fuzzing

Added a new set of shell scripts (start.sh, stop.sh, push.sh) and a configuration template (config-template.sh) to Cloud/GCE, enabling users to deploy and manage a distributed Fuzzilli fuzzing cluster on Google Compute Engine. The scripts automate the creation of a hierarchical instance structure (root, intermediate, and leaf nodes) to synchronize corpora and collect crashes, with configuration options for project IDs, machine types, disk sizes, and instance counts.

Cloud/GCE · high confidence

Add NJS as a fuzzing target

Introduces a new fuzzing target for the NJS JavaScript engine. This change adds build scripts (setup.sh, fuzzbuild.sh) and custom C modules that integrate the Fuzzilli fuzzer, enabling users to build a fuzzable version of NJS with coverage instrumentation and REPRL support.

Targets/njs · high confidence

Add experimental directory with documentation and ownership rules

An experimental/ subdirectory has been added to the repository, accompanied by an OWNERS file granting broad access and a README explaining that this location is intended for experiments and tools that do not meet the standard code review or quality requirements of the main codebase.

experimental · high confidence

Add presubmit, binaryen bootstrap, and test runner tools

The Tools directory now includes a presubmit script that validates code formatting and ensures generated protobuf files are up-to-date, a bootstrap script to build and cache Binaryen from a specific commit SHA for supported platforms, and a test runner that parses Swift test event streams to compare actual failures against an expected failures list.

Tools · high confidence

Add tool for detecting missing builtins

A new executable, DetectMissingBuiltins, has been added to the Sources/FuzzilliDetectMissingBuiltins directory. This tool analyzes a JavaScript shell's global object to identify builtins that are present in the runtime but missing from Fuzzilli's internal type environment. It supports configurable profiles to exclude specific engine-specific or test-only functions (such as V8's \d8\ or \arguments\) and filters out less relevant properties like \valueOf\ and \toString\ to focus on meaningful fuzzing targets.

Sources/FuzzilliDetectMissingBuiltins · high confidence

Added Docker-based build infrastructure for SpiderMonkey and V8 engines

Introduced new Dockerfiles and build scripts for the SpiderMonkey and V8 JavaScript engines, enabling reproducible builds within isolated containers. The SpiderMonkey builder now requires the python3-pip package and uses git pull to ensure source updates, while the V8 builder includes support for fetching and syncing the V8 source tree. These changes provide the necessary tooling to compile these engines for fuzzing targets.

Cloud/Docker/SpidermonkeyBuilder · high confidence

Added Duktape JS engine integration for Fuzzilli

Users can now build the Duktape JavaScript engine with Fuzzilli integration. This change introduces a new Docker-based build environment (Cloud/Docker/DuktapeBuilder) that compiles Duktape from source and produces the \duk-fuzzilli\ binary, enabling Fuzzilli to leverage the Duktape engine for fuzzing.

Cloud/Docker/DuktapeBuilder · high confidence

Added JSC Builder Docker environment for fuzzing

Introduced a new Docker-based build environment for the JavaScriptCore engine, enabling local and cloud-based fuzzing workflows. The change adds a Dockerfile that clones the WebKit source, applies specific patches, and executes a fuzzing build script, alongside a helper build.sh script to orchestrate the Docker container and extract the resulting binary.

Cloud/Docker/JSCBuilder · high confidence

Added crash triage script for fuzzing results

A new shell script (check.sh) and documentation have been added to the Cloud/Triage directory to assist with crash triaging. The script automates the process of running JavaScript shells (such as JavaScriptCore, SpiderMonkey, or V8) against crash files generated by Fuzzilli, capturing output and ASAN reports to a log file for easier analysis of keywords like segfaults or sanitizer errors.

Cloud/Triage · high confidence

Added fuzzing support for QuickJS

Added a new fuzzing target for QuickJS by introducing a patch that instruments the JavaScript engine with coverage tracing (via -fsanitize-coverage=trace-pc-guard) and shared-memory edge reporting, enabling integration with fuzzing frameworks like Fuzzilli. The change includes the necessary build configuration updates, source code modifications to handle coverage initialization and REPRl mode communication, and documentation outlining the steps to build the instrumented binary.

Targets/QJS · high confidence

Added fuzzing target for Qt QJSEngine

Added a new fuzzing target for the Qt QJSEngine, including build scripts, configuration, and a patched example application. The target enables fuzzing by integrating coverage instrumentation (trace-pc-guard), adding a REPRl harness for process restarts, and exposing specific JavaScript functions to trigger controlled crashes for testing purposes.

Targets/QTJS · high confidence

Initial JavaScript-to-FuzzIL parser implementation

Added a new JavaScript parser component that translates JavaScript source code into the protobuf-based AST format used by the FuzzIL compiler. The parser leverages Babel.js to handle modern JavaScript syntax, including explicit resource management, and outputs a structured AST that the FuzzIL compiler consumes for fuzzing. This enables the toolchain to ingest and analyze arbitrary JavaScript programs by converting them into the internal FuzzIL representation.

Sources/Fuzzilli/Compiler/Parser · high confidence

Introduce DiffOracle for comparing optimized and unoptimized Dumpling dumps

Added a new \DiffOracle\ tool that compares two Dumpling frame dumps (optimized vs. unoptimized) for equality. The oracle parses frame headers (Interpreter, Sparkplug, Maglev, Turbofan, deopt Turbofan) and handles incremental dump formats by maintaining running state for arguments and registers. It allows optimized frames to differ from unoptimized ones if values are marked as \\<optimized\_out\>\ or \\<non-materialized\>\, ensuring accurate diffing of JIT execution traces.

Sources/Fuzzilli/DumplingDiffOracle · high confidence

Introduce FuzzILTool for program conversion and generation

Adds a new command-line utility, FuzzILTool, that allows users to convert FuzzIL programs (serialized as .fzil protobuf files) into JavaScript or FuzzIL text format, compile JavaScript source code into FuzzIL programs, and generate random FuzzIL programs. The tool supports batch processing of corpus directories and includes options for debugging program representations and checking corpus validity.

Sources/FuzzILTool · high confidence

Introduce JavaScript-to-FuzzIL compiler and parser

Added a new JavaScriptCompiler that translates JavaScript ASTs into FuzzIL programs, supporting features such as classes, destructuring, loops, and various expressions. This is paired with a JavaScriptParser that invokes a Node.js-based Babel parser to generate the AST, with a fix to ignore stdout to prevent pipe deadlocks.

Sources/Fuzzilli/Compiler · high confidence

Introduce JavaScriptEnvironment for fuzzing

A new JavaScriptEnvironment component has been added to define the JavaScript runtime context for the fuzzer. This includes registering global builtins, TypedArray constructors, interesting integer and float values for edge-case triggering, well-known symbols, and a comprehensive set of regex patterns designed to expose engine vulnerabilities.

Sources/Fuzzilli/Environment · high confidence

Introduce RelateTool for V8 differential fuzzing

Added a new command-line utility, RelateTool, that executes a JavaScript proof-of-concept (PoC) against the V8 engine using two different configurations: a differential mode (with JIT and Maglev enabled) and a reference mode (with Turbofan and Maglev disabled). The tool compares the output dumps from both runs using a DiffOracle to detect discrepancies, exiting with an error code if the results do not match, thereby aiding in the identification of optimization-related bugs.

Sources/RelateTool · high confidence

New Binaryen-based WebAssembly code generation and program templates

The code generator now includes a new BinaryenWasmGenerator that invokes the Binaryen toolchain to produce WebAssembly modules, parsing the resulting boundary exports to create WasmModuleMetadata and enabling direct interaction with Wasm functions from JavaScript. This is complemented by new program templates (e.g., BinaryenWasmTemplate, JSPI, ThrowInWasmCatchInJS) that orchestrate the generation of these modules and their integration with JavaScript fuzzing, including support for WebAssembly JavaScript Promises Interface (JSPI) and exception handling across the JS/Wasm boundary.

Sources/Fuzzilli/CodeGen · high confidence

New Docker-based build process for Fuzzilli binaries

Added a new Docker build environment (FuzzilliBuilder) that compiles Fuzzilli and its REPRLRun binary inside a Swift container. Users can now use the provided build.sh script to generate release binaries (FuzzilliCli and REPRLRun) locally without needing a full Swift development environment installed on the host machine.

Cloud/Docker/FuzzilliBuilder · high confidence

New Docker-based fuzzing environment with JerryScript support

Users can now build and run Fuzzilli fuzzing tasks inside a Docker container, which bundles the Fuzzilli binary along with compiled JavaScript engines including JavaScriptCore, SpiderMonkey, V8, Duktape, and the newly added JerryScript. The provided build script allows selective compilation of specific engines or a full rebuild, packaging only the necessary binaries into a lightweight image for consistent fuzzing across different environments.

Cloud/Docker · high confidence

New Markov-based corpus manager for coverage-guided fuzzing

Fuzzilli now includes a MarkovCorpus implementation that prioritizes seeds triggering less frequently hit code paths, based on the Coverage-based Greybox Fuzzing as Markov Chain paper. This corpus tracks edge coverage to schedule programs that explore under-explored areas, while the existing BasicCorpus remains available for standard mutation-based fuzzing. The new manager also detects and warns when edge coverage data appears to leak, helping maintain the integrity of the fuzzing process.

Sources/Fuzzilli/Corpus · high confidence

New documentation and coverage instrumentation for adding JavaScript engine targets

Added a README in the Targets directory that guides users on how to integrate new JavaScript engines as Fuzzilli targets, detailing compilation requirements, REPRL loop implementation, and profile configuration fields. Included a new coverage.c file providing SanitizerCoverage-based instrumentation code that must be copied into the target JS shell binary to enable edge-counting and shared-memory coverage collection.

Targets · high confidence

New fuzzing profiles for Duktape, Jerryscript, Njs, Serenity, and QtJS

Added dedicated fuzzing profiles for Duktape, Jerryscript, Njs, Serenity, and QtJS, expanding the range of JavaScript engines that Fuzzilli can target. These profiles define engine-specific startup tests, code generators (such as JIT forcing for QtJS), and built-in functions to ensure effective fuzzing coverage for each environment.

Sources/Fuzzilli/Profiles · high confidence

New test transpilation tooling for Fuzzilli

The \Tools/transpile\_tests\ directory now contains a new Python-based toolchain to transpile JavaScript test suites (specifically Test262 and mjsunit) into FuzzIL and back, enabling their use with the Fuzzilli fuzzer. This includes a main transpilation script (\transpile\_tests.py\) that supports parallel execution and sharding, a setup script (\setup\_test262.py\) to prepare the test corpus by injecting harness files and neutering assertions, and a results merger (\merge\_json\_results.py\) to aggregate outcomes. The tooling also introduces a \Test262MetaDataParser\ to handle test metadata and exclusions, along with comprehensive unit tests for all components.

_Tools/transpile\tests · high confidence

Port libreprl to Windows

libreprl now supports Windows in addition to POSIX systems. The previous single-platform implementation has been split into platform-specific modules (libreprl-posix.c and libreprl-windows.c), introducing Windows-native process creation, handle-based communication channels, and memory mapping to enable REPRL functionality on Windows.

Sources/libreprl · high confidence

Project initialization and open-source release

Fuzzilli is now open source, with the repository initialized to include the core Swift source code, a \.swift-format\ configuration for consistent code styling, and a \PRESUBMIT.py\ script to enforce quality checks on uploads. The project documentation has been updated to reflect the new structure, including a comprehensive Bug Showcase of vulnerabilities found using the tool, links to relevant research papers and blog posts, and an adherence to the Chromium AI Coding Policy in the contributing guidelines.

(repo-wide) · high confidence

REPRL helper tool adds :load command and test verification

The REPRLRun tool now supports a :load command, allowing users to execute JavaScript files by path directly from the interactive prompt. Additionally, the tool includes a built-in test suite that verifies correct REPRL behavior, ensuring that execution state and rejected promises are properly reset between runs.

Sources/REPRLRun · high confidence

Removals

Removal of Forkserver and REPRL testing utilities

The project has removed the C-based forkserver implementation and its associated testing tools. Specifically, the \Sources/libforkserver\ library (including \forkserver.c\ and \libforkserver.h\) and the \Misc/Forkserver\ and \Misc/REPRL\ test harnesses (\server.c\, \tester.c\) have been deleted. Additionally, the \Misc/enum\_properties.js\ script for enumerating JavaScript builtin properties has been removed. These components are no longer part of the codebase.

Misc, Sources/libforkserver · high confidence

Removal of JSC, Spidermonkey, and V8 engine profiles

The JSCProfile, SpidermonkeyProfile, and V8Profile files have been deleted from the Sources/FuzzilliCli/Profiles directory. This removes the specific configuration sets for these JavaScript engines, including their process arguments, environment variables, code prefixes/suffixes, crash tests, and custom code generators (such as ForceDFGCompilationGenerator for JSC and ForceV8TurbofanGenerator for V8), from the Fuzzilli CLI tool.

Sources/FuzzilliCli/Profiles · high confidence

Removal of legacy core fuzzing components

The legacy implementations for code generation, corpus management, event dispatching, the core fuzzing loop, the JavaScript environment model, and the program builder have been removed from the core module. This deletion signifies the end of the previous generation of fuzzing infrastructure, which included specific generators for literals and operations, a basic corpus with age-based cleanup, a custom event system, and the original program construction logic.

Sources/Fuzzilli/Core · high confidence

Behavioural changes

Enhanced coverage evaluation with edge tracking and state management

The coverage evaluation system now supports optional per-edge hit counting, allowing corpus schedulers to distinguish between deterministic and non-deterministic code paths by ignoring edges that reset frequently. The \ProgramAspects\ class and its \CovEdgeSet\ subclass have been updated to expose edge counts and descriptions, and the \ProgramEvaluator\ protocol now includes methods for exporting/importing state and computing aspect intersections, enabling more sophisticated corpus management and fuzzer synchronization.

Sources/Fuzzilli/Evaluation · high confidence

Execution engine refactored to support differential fuzzing and unified execution results

The execution subsystem has been significantly restructured to enable differential fuzzing and improve robustness. The legacy \Forkserver\ runner has been removed in favor of a refactored \REPRL\ runner that now captures both stdout and stderr, handles execution failures with automatic retries, and exposes environment variables and process arguments via the \ScriptRunner\ protocol. Execution outcomes now include a new \differential\ state to detect discrepancies between optimized and unoptimized builds, and the \Execution\ result type has been unified into a protocol that consistently reports stdout, stderr, and fuzz output, allowing users to run differential fuzzing tests and receive detailed diagnostic information on execution differences.

Sources/Fuzzilli/Execution · high confidence

FuzzIL programs now use Protobuf serialization with operation deduplication

Fuzzilli has switched its internal program representation from a custom format to Protocol Buffers. This change introduces a new serialization mechanism that supports operation deduplication, allowing identical instructions to be stored as indices rather than full definitions, which reduces corpus size. The update includes regenerated Swift types for AST, operations, and synchronization messages, along with new utility functions for streaming corpus encoding and decoding.

Sources/Fuzzilli/Protobuf · high confidence

Increased edge tracking capacity and added edge count APIs

The coverage library now supports tracking a larger number of code edges by increasing the shared memory size limit (SHM\_SIZE) from 0x100000 to 0x200000, effectively doubling the maximum number of edges that can be monitored. Additionally, new functionality allows users to retrieve hit counts for individual edges via the new \cov\_get\_edge\_counts\ API and the \edge\_counts\ structure, while the \cov\_evaluate\ and \cov\_compare\_equal\ functions have been updated to use \uint32\_t\ types for edge indices and counts to support this expanded scale.

Sources/libcoverage/include · high confidence

Introduce Binaryen-based Wasm mutation and refactor mutator base classes

A new BinaryenWasmMutator has been added to mutate WebAssembly modules by running them through Binaryen's wasm-opt tool, preserving imports and exports. The CodeGenMutator has been updated to bail out if insufficient JavaScript variables are visible in specific contexts (like object literals or class definitions) to prevent invalid code generation. Additionally, the mutator architecture has been refactored: BaseInstructionMutator now accepts an optional name, and RuntimeAssistedMutator now enforces that instrumented programs contain internal operations, improving the reliability of runtime-assisted mutation strategies like FixupMutator and ProbingMutator.

Sources/Fuzzilli/Mutators · high confidence

Introduce ContextGraph for generator dependency resolution

The fuzzer now uses a ContextGraph to model and resolve dependencies between code generators based on their required and provided execution contexts. This new mechanism replaces the previous ad-hoc context handling, allowing the fuzzer to automatically find valid sequences of generators (paths) to build complex programs, while also validating that all context transitions are consistent and warning about orphaned generators.

Sources/Fuzzilli/Base · high confidence

Introduce post-processing and deterministic execution checks in fuzzing engines

The fuzzing engines now support a post-processing step that can modify or reject generated programs before execution, allowing for better sample quality control. Additionally, when diagnostics are enabled, the system verifies that program execution is deterministic by re-running programs and logging warnings if outcomes differ, helping to detect and debug environment-related issues like REPRL problems.

Sources/Fuzzilli/Engines · high confidence

JavaScriptCore fuzzing target updated to use REVISION-based patches and Fuzzilli build configuration

The JavaScriptCore fuzzing target has been updated to manage patches via a new Patches directory and a REVISION file instead of a single webkit.patch, aligning the build process with the specific WebKit commit hash. The build script now targets the WebKitBuild/Fuzzilli output directory, enables the ENABLE\FUZZILLI CMake option, and exposes new JavaScript functions (\\fuzzout\\_ and crash) for fuzzing control, while also simplifying the build configuration to Linux-only with optional ASAN support.

Targets/JavaScriptCore · high confidence

JerryScript target updated to v3.0.0 with Fuzzilli integration

The JerryScript target has been updated to version 3.0.0, requiring the application of new patches to the upstream source. These patches introduce a new \--reprl-fuzzilli\ command-line option and a dedicated execution mode that defers to the Fuzzilli library for handling input, enabling the use of JerryScript as a JavaScript engine for fuzzing workflows.

Targets/Jerryscript · high confidence

Major CLI overhaul with new configuration, distributed fuzzing, and enhanced diagnostics

The Fuzzilli CLI has been significantly restructured to support advanced fuzzing workflows. The previous static configuration file (Settings.swift) containing hardcoded code generators and builtins has been removed, shifting configuration to runtime profiles and command-line flags. New command-line options allow users to select specific fuzzing engines (mutation, hybrid, multi), corpus schedulers (basic, markov), and manage distributed fuzzing via network master/worker modes with configurable synchronization strategies. The terminal UI now provides richer real-time statistics, including fuzzer state, correctness rates, and differential fuzzing findings, while new flags enable features like swarm testing, program inspection, argument randomization, and Wasm code generation.

Sources/FuzzilliCli · high confidence

Major configuration overhaul and introduction of differential fuzzing support

The Fuzzilli configuration has been significantly expanded to support new capabilities, most notably differential fuzzing via the new \DifferentialConfig\ struct and \forDifferentialFuzzing\ flag, which enables comparing outputs against a reference runner. The configuration now also supports static corpora, diagnostic and inspection modes, WASM feature toggles, and bundle generation. Additionally, the \Fuzzer\ class has been refactored to use a UUID-based identifier instead of an integer ID, and introduces a state machine (uninitialized, waiting, corpusImport, corpusGeneration, fuzzing) to manage the fuzzing lifecycle more robustly, including support for hybrid engines and program templates.

Sources/Fuzzilli · high confidence

Major overhaul of the FuzzIL intermediate language and type system

The FuzzIL language has been significantly redesigned to support modern JavaScript and WebAssembly features. This change introduces a new type system (renamed from JSTyper to JSTyper/ILType), adds support for WebAssembly GC (including custom descriptors, ref types, and SIMD), and expands JavaScript coverage with classes, modules, async/await, destructuring, and private properties. The core IR structures, including Code, Context, and Operation definitions, have been refactored to support these new capabilities, with operations now carrying explicit context requirements and attributes for mutation and block handling.

Sources/Fuzzilli/FuzzIL · high confidence

Major overhaul of the JavaScript-to-FuzzIL lifter and expression handling

The JavaScript lifter has been significantly refactored to improve code generation quality and support modern JavaScript features. Expression handling now uses a new \Characteristic\ enum (pure vs. effectful) to determine inlining safety, replacing the previous \Inlineability\ enum and changing the expression concatenation operator from \\<\>\ to \+\. The lifter now supports ECMAScript 5 and 6 profiles, enabling the generation of modern syntax including arrow functions, async/await, template literals, destructuring, and private class properties. Additionally, new runtime-assisted mutator components (Probe, Fixup) have been added to the lifting infrastructure to support advanced fuzzing strategies.

Sources/Fuzzilli/Lifting · high confidence

New minimization reducers and post-processing infrastructure

The minimization engine in Sources/Fuzzilli/Minimization has been expanded with several new reducers and a post-processing step. DataFlowSimplifier now removes unnecessary intermediate instructions in data flow chains, while DeduplicatingReducer consolidates identical variable values. InstructionSimplifier lowers complex operations (such as spread calls and guarded/optional calls) into simpler forms, and LoopSimplifier normalizes various loop structures into repeat-loops and reduces iteration counts. ReassignReducer resolves variable reassignments to enable further simplification, and VariadicInputReducer strips unused inputs from variadic operations. Additionally, MinimizationPostProcessor adds helpful features like return statements and initial values back into minimized code to aid future mutations.

Sources/Fuzzilli/Minimization · high confidence

Port libcoverage to Windows and add edge-tracking capabilities

The libcoverage library now supports Windows by replacing POSIX shared memory (shm\_open/mmap) with Windows file mapping (CreateFileMapping/MapViewOfFile) for inter-process communication. Additionally, the coverage initialization now accepts a flag to optionally track individual edge hit counts, allocating a dedicated counter array when enabled, and the internal evaluation logic has been updated to store edge indices as 64-bit values in a new \edge\_indices\ array rather than the previous \edges\ field.

Sources/libcoverage · high confidence

REPRL API refactored to use context-based execution with explicit stdout/stderr/fuzzout capture

The libreprl public API has been redesigned from a stateless, per-call spawn-and-execute model to a context-based lifecycle. Users now create a \reprl\_context\ via \reprl\_create\_context\ and initialize it with \reprl\_initialize\_context\, specifying whether to capture stdout and stderr. Execution is performed via \reprl\_execute\, which reuses the context and can optionally force a fresh instance. The old \reprl\_spawn\_child\ and \reprl\_execute\_script\ functions are removed. Output retrieval is now explicit via \reprl\_fetch\_stdout\, \reprl\_fetch\_stderr\, and \reprl\_fetch\_fuzzout\, and error handling uses \reprl\_get\_last\_error\. Status codes are now parsed via inline helpers (\RIFSIGNALED\, \RIFTIMEDOUT\, etc.) instead of the previous \reprl\_result\ struct.

Sources/libreprl/include · high confidence

Redesigned distributed fuzzing protocol with new sync module and enhanced statistics

The distributed fuzzing architecture has been refactored to support a tree hierarchy of nodes (root, intermediate, leaf) with a new \Sync.swift\ module defining the communication protocol. Network synchronization (\NetworkSync.swift\) now uses a dedicated \DispatchQueue\ per connection, explicit UUID-based handshakes, and \libsocket\ for cross-platform socket handling. The \Statistics.swift\ module has been expanded to track fuzzer overhead, minimization overhead, and per-contributor correctness/timeout rates, aggregating data across all connected nodes. Additionally, the \Storage.swift\ module now supports exporting statistics at regular intervals, saving detailed settings to \settings.json\, and organizing corpus/crash files by date-stamped names in dedicated directories.

Sources/Fuzzilli/Modules · high confidence

Refactored utility infrastructure with new execution and data structures

The Sources/Fuzzilli/Util module has been significantly expanded and refactored to support new fuzzing capabilities. A new BinaryenRunner utility was added to manage wasm-opt execution with specific feature flags (such as GC, threads, and SIMD) and timeout handling. JavaScript execution is now handled by a dedicated JavaScriptExecutor class that supports multiple engine types (user-supplied, Node.js) and configurable timeouts. Core data structures have been updated: VariableMap and VariableSet are now public, conform to standard Swift protocols (Sequence, Hashable, Codable), and VariableSet now supports set operations like intersection and subtraction. The WeightedList implementation was optimized to use binary search for random element selection instead of linear expansion. Additionally, new utility structs for Stack, RingBuffer, and LEB128 encoding were introduced, and the Arguments parser was made public with expanded type support.

Sources/Fuzzilli/Util · high confidence

SpiderMonkey fuzzing build process and patches updated

The SpiderMonkey target now uses a simplified build process via \fuzzbuild.sh\ that leverages native \--enable-js-fuzzilli\ and \--enable-fuzzing\ configuration options, removing the need for manual patch application and custom compiler flags. The build output location has changed to \obj-fuzzbuild\, and the engine has been updated to a new revision with specific patches to support import assertions and revert to a plain reprl protocol for communication.

Targets/Spidermonkey · high confidence

Updated V8 target with simplified build and new fuzzing flags

The V8 target has been updated to a new revision (99071b0) and simplified build process. The manual patch application step is removed, with the fuzzbuild.sh script now handling configuration directly. Key changes include disabling PartitionAlloc, adding the --fuzzing flag, and introducing the --interrupt-budget command line flag. The build script now explicitly targets Linux and generates the d8 executable. Sanitizer coverage instrumentation has been simplified, and the shared memory variable for coverage was renamed to \_\_shmem to avoid conflicts.

Targets/V8 · high confidence

libsocket now supports Windows and uses a unified socket type

The libsocket library has been ported to Windows, introducing a new \socket-win32.c\ implementation alongside the existing POSIX code. To support this, the public API now uses a unified \libsocket\_t\ type instead of raw integers, and adds a \socket\_shutdown\ function. The header guards have also been updated to conform to standard naming conventions.

Sources/libsocket · high confidence

Test coverage

Added end-to-end compiler tests for JavaScript-to-FuzzIL transpilation; Added new test suite for compiler, context graph, and engine behaviors.

Dependencies

Upgrade Swift tools version and add core dependencies

The project now requires Swift 5.7 and macOS 13, replacing the previous Swift 4.0 toolchain. It introduces three new dependencies: swift-protobuf (pinned to 1.35.0), swift-collections (1.2.0+), and swift-algorithms (1.2.1+). Additionally, a new Node.js parser module is added under Sources/Fuzzilli/Compiler/Parser with dependencies on @babel/parser and protobufjs, and the libcoverage target is configured with -O3 optimization and links against the rt library on Linux.

(dependencies) · high confidence

Housekeeping

Added placeholder for V8 patch directory

A .gitkeep file was added to the Targets/V8/Patches directory to ensure the folder is tracked by version control, allowing future patches to be added without the directory being ignored by Git.

Targets/V8/Patches · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

Score

  • CAI 51 → 50 (-0.3)
  • Rubric changed (rubric-2026.09.11 → rubric-2026.09.18) — scores are not directly comparable.

Lenses

  • Code Health 40 → 40 (+0.6)
  • Architecture 97 → 92 (-4.4)
  • Maturity 56 → 57 (+0.1)
  • Readiness 48 → 49 (+0.2)
  • Security 72 → 76 (+3.5)
  • Performance 78 (new)

Resolved (16)

  • Change coupling: ProgramBuilder.swift ↔ InstructionSimplifier.swift (Sources/Fuzzilli/Base/ProgramBuilder.swift)
  • Dependency hygiene PARTLY measured — npm pinning read, dependency currency not (no pnpm-resolved versions to grade)
  • Duplicated block (15–18 lines × 4) (Sources/Fuzzilli/Lifting/WasmLifter.swift)
  • Duplicated block (5 lines × 2) (Sources/Fuzzilli/Lifting/WasmLifter.swift)
  • Hotspot: Sources/Fuzzilli/FuzzIL/WasmOperations.swift (Sources/Fuzzilli/FuzzIL/WasmOperations.swift)
  • Hotspot: Sources/Fuzzilli/Minimization/BlockReducer.swift (Sources/Fuzzilli/Minimization/BlockReducer.swift)
  • Hotspot: Sources/Fuzzilli/Minimization/DataFlowSimplifier.swift (Sources/Fuzzilli/Minimization/DataFlowSimplifier.swift)
  • Hotspot: Sources/Fuzzilli/Profiles/V8SandboxProfile.swift (Sources/Fuzzilli/Profiles/V8SandboxProfile.swift)
  • Hotspot: Tests/FuzzilliTests/CompilerTests/advanced_loops.js (Tests/FuzzilliTests/CompilerTests/advanced_loops.js)
  • Members sharing a duplicated core (4 members, 50+ identical tokens) (Sources/Fuzzilli/FuzzIL/TypeSystem.swift)
  • Members sharing a duplicated core (4 members, 50+ identical tokens) (Sources/Fuzzilli/Lifting/JavaScriptLifter.swift)
  • Members sharing a duplicated core (5 members, 50+ identical tokens) (Sources/Fuzzilli/Base/ProgramBuilder.swift)
  • Members sharing a duplicated core (8 members, 50+ identical tokens) (Sources/Fuzzilli/Base/ProgramBuilder.swift)
  • Off-boarding risk: anonymized user #1
  • TodoComment (Sources/Fuzzilli/Minimization/InstructionSimplifier.swift)
  • TodoComment (Sources/Fuzzilli/Minimization/InstructionSimplifier.swift)

New (64)

  • Change coupling: Events.swift ↔ TerminalUI.swift (Sources/Fuzzilli/Base/Events.swift)
  • Change coupling: V8HoleFuzzingProfile.swift ↔ V8SandboxProfile.swift (Sources/Fuzzilli/Profiles/V8HoleFuzzingProfile.swift)
  • Constraint.fulfilled (cyclomatic 18) (Sources/Fuzzilli/CodeGen/CodeGenerator.swift)
  • Context.description (cognitive 18) (Sources/Fuzzilli/FuzzIL/Context.swift)
  • Context.description (cyclomatic 19) (Sources/Fuzzilli/FuzzIL/Context.swift)
  • Coverage not measured — Swift suite
  • Dependency hygiene PARTLY measured — npm pinning read, dependency currency not (no committed lockfile, so no resolved version to grade)
  • DestructuringPattern.numBindings (cognitive 18) (Sources/Fuzzilli/FuzzIL/JsOperations.swift)
  • DestructuringPattern.numExtraInputs (cognitive 21) (Sources/Fuzzilli/FuzzIL/JsOperations.swift)
  • Duplicated block (12 lines × 2) (Sources/Fuzzilli/Profiles/V8CommonProfile.swift)
  • Duplicated block (12–23 lines × 7) (Sources/Fuzzilli/Profiles/V8CommonProfile.swift)
  • Duplicated block (12–28 lines × 6) (Sources/Fuzzilli/Profiles/V8CommonProfile.swift)
  • Duplicated block (5 lines × 2) (Sources/Fuzzilli/Base/Contributor.swift)
  • Duplicated block (8 lines × 2) (Sources/Fuzzilli/Profiles/V8CommonProfile.swift)
  • FileTooLong: FuzzilliCli/main.swift (Sources/FuzzilliCli/main.swift)
  • FileTooLong: Profiles/V8CommonProfile.swift (Sources/Fuzzilli/Profiles/V8CommonProfile.swift)
  • FunctionTooLong: V8CommonProfile.swift.v8ProcessArgs (Sources/Fuzzilli/Profiles/V8CommonProfile.swift)
  • FunctionTooLong: main.swift.makeFuzzer (Sources/FuzzilliCli/main.swift)
  • Fuzzer.processMaybeInteresting (cognitive 21) (Sources/Fuzzilli/Fuzzer.swift)
  • Hotspot: Sources/Fuzzilli/FuzzIL/JsOperations.swift (Sources/Fuzzilli/FuzzIL/JsOperations.swift)
  • …and 44 more

Changes since last survey

  • 41 commits — 32 feature/other, 9 fixes

By area

  • Sources/Fuzzilli — 31 commits
  • Tests/FuzzilliTests — 6 commits
  • (root) — 1 commit
  • Sources/FuzzilliCli — 1 commit
  • Sources/REPRLRun — 1 commit
  • experimental/OWNERS — 1 commit

Notable commits

  • fix: Fix corpus import mode and misleading statistics messages
  • fix: Fix import fixup of uninteresting programs
  • fix: Fix testThatGeneratorsExistAndAreBuildable()
  • fix: Revert "[v8] Add SpecialObjectGenerator for new d8.test helpers"
  • fix: [Minimizer] Fix array destructuring self-reassignment in InstructionSimplifier
  • fix: [compiler] Support object literal spreads and fix computed key order
  • fix: [js] Fix d8 typing in profiles
  • fix: [wasm] Fix typing of select
  • fix: [wasm] Fix wasm flags in tests
  • change: Add option to track convergence patterns during import
  • change: Deprecate the --maxRuntimeInHours flag
  • change: FuzzILLifter: Add '#' prefix for privateProperty destructuring targets
  • change: Roll Binaryen from cb3586b8763d to fbf2e5aa2cca (17 revisions)
  • change: Throw instead of crash for instructions with > 65K inputs
  • change: Track samples with poor coverage convergence
  • change: Use missingInputs in createRequiredInputVariables
  • change: [Minimizer] Add a differential test for the multi-instruction simplifier
  • change: [Minimizer] Simplify DestructAndReassign in the InstructionSimplifier
  • change: [binaryen] Double the timeout for running wasm-opt
  • change: [binaryen] Report specific error for timeouts
  • …and 21 more

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

googleprojectzero/fuzzilli was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 1 October 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 281729bfc79f3bc9af398e4dce44933d6ea01dc4 — the exact code this score is about.
  • Scored under rubric-2026.09.18 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-e569280dd5e2.