Adversarial fuzz worker

boundary-probe

Session qa-fuzz-20260729-0001 · Worker boundary-probe

inconclusive

21/22 boundary cases behaved correctly. --var-file path traversal escaped --root while --file remained confined; commands containing <root> and && must remain valid XML text.

Fuzz run descriptionIterationsPassResult
CLI path confinement, malformed inputs, and <root> boundary cases 22 21/22 FAIL

Inputs exercised

CaseTemplate / inputOutcome
bound-16arender --mode profile --kind agent --agent '../../etc/passwd' --root <root> --jsonPASS; invalid agent rejected
bound-16bcd <root> && render --root . --file tpl.md.j2 --var-file ../outside/secret_vars.yaml --jsonFAIL; var-file escaped root
bound-16c--file <abs-outside>/secret.md.j2 (absolute escape)PASS; file escape rejected

Findings

FUZZ-BOUND-001

Minimal template / frontmatter
Hello {{ name }}
Input
--root <root> --var-file ../outside/secret_vars.yaml && render
Expected
Both --file and --var-file paths remain confined beneath --root.
Observed
--var-file accepted relative traversal and absolute paths outside <root> with exit 0.
Requirement / ADR
The path-confinement requirement covers template files; var-file confinement is not explicitly stated.
Requirement / ADR follow-up
Assess whether var-file confinement is a supported security contract before creating or updating an ADR.
Root cause
The CLI applies root confinement to --file resolution but reads --var-file paths through a separate unconstrained path.
Recommended fix
Resolve --var-file through the same confined-root helper and add traversal regression tests.