fix(fuzz): count decoded JSON argument leaves in leak oracle - #104
Conversation
|
Verification at 95c6ebf: node --import tsx _test_fuzz.js passes all 18 properties (75 runs each) plus the new deterministic regression block. Original scheduled-run artifact also replays without error. Negative-control mutation restores a claimed raw argument after redaction and is rejected in both chat/Responses and reversible/strip modes. Base reduced seed reproduced 5 remaining vs 4 allowed before the change. CI compilation and review are pending; no local build or production deployment performed. |
sprayberry-redline
left a comment
There was a problem hiding this comment.
Verdict: approve. The oracle now counts decoded object and array argument leaves while keeping ordinary text and primitive JSON literal. The regressions cover escaped values, duplicate occurrences, both OpenAI dialects and redaction modes, and confirm that a deliberately missed replacement still fails the leak check.
Fixes 00MULBN1DVE2E254C5D22BB232. Aligns occurrence counting with object/array argument decoding for Responses and chat; ordinary message strings, malformed JSON and primitive JSON retain raw-text semantics. No production code or budget changes. Adds newline/backslash/quote, duplicate and real missed-replacement controls to the existing fuzz test battery. Reduced CI seed failed before this patch; reduced seed and original 396-byte artifact pass after. Local source tests run using tsx; CI remains authoritative for compilation.