This directory contains the OSS-Fuzz fuzz
targets for FormatJS. OSS-Fuzz invokes build.sh inside its
base-builder-javascript image; everything here is intended to run in that
container, not as part of the FormatJS Bazel/pnpm workspace.
fuzz_icu_messageformat_parser.js— exercises@formatjs/icu-messageformat-parser'sparse()across the parser flag matrix.fuzz_intl_messageformat.js— drives the publicintl-messageformatIntlMessageFormatconstructor,format(), andformatToParts()over ten locales.fuzz_icu_skeleton_parser.js— covers@formatjs/icu-skeleton-parser's number and date-time skeleton entry points.
- The fuzz workspace installs the published
@formatjs/*andintl-messageformatpackages from npm rather than building from the local Bazel sources. This keeps the OSS-Fuzz build path independent of the monorepo toolchain. - The published packages are ESM-only.
build.shruns a targeted Babel ESM→CommonJS transform onnode_modules/@formatjs/*andnode_modules/intl-messageformatso Jazzer.js (which loads targets via CommonJSrequire) can pick them up. Other packages innode_modulesare CommonJS already and are left alone. @jazzer.js/coreis pinned to^2. Jazzer.js 4.0.0's prebuilt native addon requiresGLIBC_2.32, which the current OSS-Fuzz base images (Ubuntu 20.04, glibc 2.31) don't provide. The pin can be dropped once the base images move past glibc 2.32.
The targets are designed to run under the OSS-Fuzz toolchain rather than
standalone. To reproduce a build locally, run the standard OSS-Fuzz helper
against the formatjs project at
google/oss-fuzz:
python3 infra/helper.py build_fuzzers formatjs
python3 infra/helper.py check_build formatjs
python3 infra/helper.py run_fuzzer formatjs fuzz_icu_messageformat_parser