Summary
Adversarial fuzz campaign sc-compose-fuzz-20260811-3 ran 4 background workers (shape-probe, template-probe, boundary-probe, differential-probe) against a 105-file real-world corpus (atm-core:47, data-sourcegenerators:31, p3-documentation:5, HitlCore:22), partitioned deterministically via SHA-256(seed 157 + filepath) mod 4, for a total of 260 bounded iterations. 3 confirmed bugs (FUZZ-001, FUZZ-002, FUZZ-003) were found and promoted as RED (intentionally failing) regression tests, following this repo's test-first/fix-later pattern; no production code was modified or committed, and no PR was opened. Two additional candidates (template-probe-001, differential-probe-001) were traced to documented, intentional behavior and are not filed as bugs.
| Fuzz run description | Iterations | Pass | Result |
| Recursive JSON/YAML values, mixed arrays, and ingress parity against the corpus partition |
46 |
45/46 |
FAIL |
| Nested loops, control flow, includes, delimiters, and output against the corpus partition |
100 |
98/100 |
FAIL |
| Malformed inputs, stable diagnostics, and path boundaries against the corpus partition |
85 |
84/85 |
FAIL |
| Baseline comparison, metamorphic relations, and determinism against the corpus partition |
29 |
29/29 |
PASS |
All 3 confirmed bugs remain unresolved pending a production fix: FUZZ-001 (template-init/render JSON round-trip in crates/sc-compose/src/commands/template_init.rs and crates/sc-composer/src/renderer.rs), and FUZZ-002/FUZZ-003 (clap error paths bypassing the --json DiagnosticEnvelope contract per FR-8a, shared fix target in crates/sc-compose/src/main.rs / crates/sc-compose/src/cli/mod.rs). A duplicate check against GitHub issues (#166-170, #240-254, #268-273, #293, #370-375) found no existing coverage; all three are new findings.