Skip to content

fix(fuzz): count decoded JSON argument leaves in leak oracle - #104

Merged
askalf merged 2 commits into
mainfrom
agent/developer/redact-leak-decoded-arguments
Sep 28, 2026
Merged

askalf merged 2 commits into
mainfrom
agent/developer/redact-leak-decoded-arguments

Conversation

@askalf

@askalf askalf commented Sep 28, 2026

Copy link
Copy Markdown
Owner

Fixes 00MULBN1DVE2E254C5D22BB232. Aligns occurrence counting with object/array argument decoding for Responses and chat; ordinary message strings, malformed JSON and primitive JSON retain raw-text semantics. No production code or budget changes. Adds newline/backslash/quote, duplicate and real missed-replacement controls to the existing fuzz test battery. Reduced CI seed failed before this patch; reduced seed and original 396-byte artifact pass after. Local source tests run using tsx; CI remains authoritative for compilation.

@github-actions github-actions Bot added tests Test suite and CI fuzz Fuzzing and ClusterFuzzLite size/M 50-199 hand-written lines labels Sep 28, 2026
@askalf

askalf commented Sep 28, 2026

Copy link
Copy Markdown
Owner Author

Verification at 95c6ebf: node --import tsx _test_fuzz.js passes all 18 properties (75 runs each) plus the new deterministic regression block. Original scheduled-run artifact also replays without error. Negative-control mutation restores a claimed raw argument after redaction and is rejected in both chat/Responses and reversible/strip modes. Base reduced seed reproduced 5 remaining vs 4 allowed before the change. CI compilation and review are pending; no local build or production deployment performed.

@sprayberry-redline sprayberry-redline left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Verdict: approve. The oracle now counts decoded object and array argument leaves while keeping ordinary text and primitive JSON literal. The regressions cover escaped values, duplicate occurrences, both OpenAI dialects and redaction modes, and confirm that a deliberately missed replacement still fails the leak check.

@askalf
askalf merged commit de27afa into main Sep 28, 2026
12 checks passed
@askalf
askalf deleted the agent/developer/redact-leak-decoded-arguments branch September 28, 2026 14:25
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

fuzz Fuzzing and ClusterFuzzLite size/M 50-199 hand-written lines tests Test suite and CI

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants