Adversarial fuzz worker

differential-probe

Session e3confirm-20260729-0001 · Worker differential-probe

FAIL

Fuzz run descriptionIterationsPassResult
Baseline-vs-head parity, JSON/YAML equivalence, and deterministic output (frontmatter target, corrected baseline fa675cf) 97 96/97 FAIL

Inputs exercised

CaseTemplate / inputOutcome
FUZZ-006Equivalent JSON and YAML inputs must not produce different semantics without a documented reason. Either both reject an out-of-range integer or both preserve it losslessly.confirmed product bug (5 reproductions): JSON: exit 0, renders VALUE=18446744073709552000.0 -- the integer u64::MAX+1 is silently rounded through f64 into a different value, and `validate --json` reports {"valid": true} with zero diagnostics. YAML with the same
FUZZ-007ERR_VAL_DUPLICATE is a documented stable code for duplicate frontmatter variable declarations; once `variables:` is a real declaration source, both spellings feeding one `seen` setintentional boundary (not a defect) (3 reproductions): HEAD exits 2 with ERR_VAL_DUPLICATE; pre-fix baseline ignored `variables:` so no duplicate was detected. A faithful consequence of intentional fix (c). Accounts for 12 of the 21 baseline-vs-HEAD sweep diffs.

Findings

FUZZ-006

Minimal template / frontmatter
--- required_variables: - top --- VALUE=[[top]]
Input
{"top": 18446744073709551616}
Expected
Equivalent JSON and YAML inputs must not produce different semantics without a documented reason. Either both reject an out-of-range integer or both preserve it losslessly.
Observed
JSON: exit 0, renders VALUE=18446744073709552000.0 -- the integer u64::MAX+1 is silently rounded through f64 into a different value, and `validate --json` reports {"valid": true} with zero diagnostics. YAML with the same value: exit 3, ERR_CONFIG_PARSE. Control at exactly u64::MAX renders losslessly in both formats.
Requirement / ADR
Silent data corruption with an affirmative valid:true is the worst failure mode of the two paths.
Requirement / ADR follow-up
Reject or losslessly preserve JSON integers beyond u64::MAX; never silently round to f64 while reporting valid:true.
Root cause
See observed_result; coordinator-established root cause recorded in campaign-report.json.
Recommended fix
Reject or losslessly preserve JSON integers beyond u64::MAX; never silently round to f64 while reporting valid:true.

FUZZ-007

Minimal template / frontmatter
--- required_variables: - name variables: name: required: true --- Hello {{name}}
Input
(none)
Expected
ERR_VAL_DUPLICATE is a documented stable code for duplicate frontmatter variable declarations; once `variables:` is a real declaration source, both spellings feeding one `seen` set is consistent.
Observed
HEAD exits 2 with ERR_VAL_DUPLICATE; pre-fix baseline ignored `variables:` so no duplicate was detected. A faithful consequence of intentional fix (c). Accounts for 12 of the 21 baseline-vs-HEAD sweep diffs.
Requirement / ADR
Document the cross-section duplicate rule in requirements.md; currently only implied by code.
Requirement / ADR follow-up
Coordinator classified as non-actionable (intentional_boundary/inconclusive); no new requirement/ADR needed. Document the cross-section duplicate rule in requirements.md; currently only implied by code.
Root cause
See observed_result; coordinator-established root cause recorded in campaign-report.json.
Recommended fix
No further action recommended; see coordinator_note/attribution_note.