Adversarial fuzz worker

template-probe

Session qa-fuzz-20260729-0001 · Worker template-probe

confirmed_bug

Two cases falsely flagged the standard Jinja loop context as an undeclared token under --strict; include syntax @<path> and delimiter text were also exercised.

Fuzz run descriptionIterationsPassResult
Jinja loops, recursive @<path> includes, and custom << delimiters 18 16/18 FAIL

Inputs exercised

CaseTemplate / inputOutcome
tmpl-08escape.md.j2 @<../outside-escape.md>: include path escaping confinement rootPASS; correctly rejected
tmpl-10--variable-delimiters '<<' '>>' --var name=RandPASS; custom delimiters accepted

Findings

FUZZ-TP-01

Minimal template / frontmatter
{% for item in items %}{{ loop.index }}: {{ item }}{% endfor %}
Input
items: [<one>, <two>] & optional marker
Expected
The loop.* Jinja builtin validates and renders under default and --strict modes.
Observed
Default mode warns and --strict mode fails with an undeclared referenced token diagnostic for loop.index.
Requirement / ADR
Existing renderer validation requirements cover declared variables but do not document loop.* builtin handling.
Requirement / ADR follow-up
Update the existing requirement or add an ADR only if loop.* support is a genuine supported contract.
Root cause
The token validator treats the Jinja loop context object as an undeclared variable inside for-loops.
Recommended fix
Exclude documented loop.* builtins from undeclared-token validation and add strict-mode regression coverage.