Adversarial fuzz worker

shape-probe

Session qa-fuzz-20260729-0001 · Worker shape-probe

confirmed_bug

19/20 cases passed. A YAML merge-key <<: *anchor inside an array-of-objects var-file silently produced empty fields instead of merged values or an explicit diagnostic.

Fuzz run descriptionIterationsPassResult
Var-file shapes, YAML anchors, and mixed arrays from the live campaign 20 19/20 FAIL

Inputs exercised

CaseTemplate / inputOutcome
shape-09case08-yaml-anchors.yaml: YAML anchor + merge key (<<: *defaults) inside items[]FAIL; empty id/value fields
shape-10base: &base followed by - <<: *baseFAIL; literal merge key dropped

Findings

FUZZ-SHAPE-001

Minimal template / frontmatter
{% for item in items %}{{ item.id }}: {{ item.value }}{% endfor %}
Input
items: - <<: *base base: &base id: 1 value: anchored
Expected
YAML merge-key semantics resolve <<: *base, or sc-compose emits an explicit unsupported-construct diagnostic.
Observed
Exit 0 with empty id/value fields and zero diagnostics; literal << and &anchor content was silently dropped.
Requirement / ADR
No existing requirement/ADR explicitly defines YAML 1.1 merge-key support.
Requirement / ADR follow-up
Create or update docs/requirements.md only if merge-key support is a genuine supported-contract gap.
Root cause
serde_yaml 0.9 leaves the literal << mapping key intact and the var-file path performs no post-parse merge-key validation.
Recommended fix
Implement merge-key expansion or emit ERR_VAL_UNSUPPORTED_YAML_MERGE_KEY before rendering.