Phase G.6 Adversarial Fuzz Session

sc-compose known-template reverse-extraction campaign

Generated: 2026-08-01

Source: adversarial-fuzzing skill v1.1.0 / G.6 campaign g6-20260802-0001

DRIFT

Summary

Four bounded workers exercised the complete Phase-G extraction surface. One deterministic dotted-expression candidate remains inconclusive pending product-contract clarification.

Fuzz run descriptionIterationsPassResult
Malformed XML, missing occurrences, ambiguity, empty values, and include/exclude selection. 50 50/50 PASS
Compare Rust, Python, and CLI results for the same known-template extraction cases. 8 8/8 PASS
Repeated siblings, attributes, text nodes, whitespace, entities, declarations, and comments. 24 24/24 PASS
Supported scalar expressions versus unsupported filters, control flow, concatenation, and type-looking values. 30 29/30 FAIL

Adversarial fuzz worker

boundary-probe

Session g6-20260802-0001 · Worker boundary-probe

PASS

Fuzz run descriptionIterationsPassResult
Malformed XML, missing occurrences, ambiguity, empty values, and include/exclude selection. 50 50/50 PASS

Inputs exercised

CaseTemplate / inputOutcome
boundary-001Malformed rendered XML Template: <root><name>{{ name }}</name></root> Rendered input: <root><name>Ada</root>PASS: stable malformed-input diagnostic
boundary-002Missing rendered occurrence Template: <root><name>{{ name }}</name></root> Rendered input: <root><other>Ada</other></root>PASS: missing occurrence warning without fabricated value
boundary-003Adjacent expressions without delimiter Template: <root>{{ first }}{{ second }}</root> Rendered input: <root>AB</root>PASS: stable ambiguity diagnostic

Adversarial fuzz worker

differential-probe

Session g6-20260802-0001 · Worker differential-probe

PASS

Fuzz run descriptionIterationsPassResult
Compare Rust, Python, and CLI results for the same known-template extraction cases. 8 8/8 PASS

Inputs exercised

CaseTemplate / inputOutcome
differential-001Attribute extraction across Rust, Python, and CLI Template: <root id="{{ id }}">{{ name }}</root> Rendered input: <root id="42">Ada</root>PASS: values and occurrence provenance agree
differential-002Missing occurrence diagnostics across surfaces Template: <root><name>{{ name }}</name></root> Rendered input: <root><other>Ada</other></root>PASS: diagnostic category agrees
differential-003Three-run deterministic replay Template: <root><name>{{ name }}</name></root> Rendered input: <root><name>Ada</name></root>PASS: all surfaces deterministic

Adversarial fuzz worker

shape-probe

Session g6-20260802-0001 · Worker shape-probe

PASS

Fuzz run descriptionIterationsPassResult
Repeated siblings, attributes, text nodes, whitespace, entities, declarations, and comments. 24 24/24 PASS

Inputs exercised

CaseTemplate / inputOutcome
shape-001Attribute and text scalar with repeated sibling path Template: <items><item id="{{ id }}">{{ label }}</item></items> Rendered input: <items><item id="42">Ada</item></items>PASS: scalar values and structural occurrence recorded
shape-002XML declaration, comment, entity, and static prefix/suffix Template: <?xml version="1.0"?><root><!-- note --><name>Hi {{ name }} &amp; team</name></root> Rendered input: <?xml version="1.0"?><root><!-- note --><name>Hi Ada &amp; team</name></root>PASS: declaration/comment/entity structure preserved
shape-003Empty scalar and whitespace-padded text node Template: <root><value> {{ value }} </value></root> Rendered input: <root><value> </value></root>PASS: empty rendered scalar reported without fabrication

Adversarial fuzz worker

template-probe

Session g6-20260802-0001 · Worker template-probe

FAIL

Fuzz run descriptionIterationsPassResult
Supported scalar expressions versus unsupported filters, control flow, concatenation, and type-looking values. 30 29/30 FAIL

Inputs exercised

CaseTemplate / inputOutcome
template-001Supported scalar with static prefix and suffix Template: <root><name>Hello {{ name }}!</name></root> Rendered input: <root><name>Hello Ada!</name></root>PASS: scalar expression extracted
template-002Unsupported filter is rejected fail-closed Template: <root>{{ name | upper }}</root> Rendered input: <root>ADA</root>PASS: ERR_EXTRACT_UNSUPPORTED
template-003Dotted expression contract candidate Template: <root><name>{{ user.name }}</name></root> Rendered input: <root><name>Ada</name></root>INCONCLUSIVE: accepted as literal user.name; replayed 3/3

Findings

FUZZ-template-probe-dotted-expression

Minimal template / frontmatter
<root><name>{{ user.name }}</name></root>
Input
<root><name>Ada</name></root>
Expected
The worker oracle expected dotted attribute syntax to be rejected with ERR_EXTRACT_UNSUPPORTED.
Observed
{"deterministic": true, "diagnostic": "WARN_EXTRACT_LOW_CONFIDENCE", "exit_code": 0, "values": {"user.name": "Ada"}}
Requirement / ADR
FR-16 and ADR-0011 define a documented scalar XML subset but do not define dotted-expression semantics. VariableName::new explicitly permits dots, while extraction does not promise reconstruction of object attributes.
Requirement / ADR follow-up
Team lead/product owner should decide whether dotted expressions are literal variable names or object-path expressions, then amend FR-16/ADR-0011 and add a contract test if needed.
Root cause
Extraction reuses the permissive VariableName validator; product intent for dotted names is unresolved.
Recommended fix
Clarify the contract before changing implementation. Do not reject or reinterpret dotted names solely from this fuzz result.

Recommendations

Resolve the dotted-variable versus object-path contract in FR-16/ADR-0011 before changing extraction behavior.

Metadata

Campaigng6-20260802-0001
Targetcomplete Phase-G Rust, Python, and CLI extraction surface
Baseline125076545d623921d14bdb62dbdb7214d7e024fd
Seed7001
Worker limits4 workers; 50 cases/worker; 120 seconds/worker
Cases111/112 passed
Confirmed defects0
Inconclusive findings1
Evidence sourcedocs/phase-G/evidence/g-6-reverse-extract-campaign.json