O.5 Release Corpus and Parser-Backed Fuzz Gate

1.4.1 release-candidate evidence on pinned consumer roots

Generated: 2026-08-13

Source: sc-compose O.5 campaign o5-20260813-0001

DRIFT

Summary

Three local parser-backed workers passed 24 bounded cases. The seven-root inventory counted 40 templates; 28 external production templates require owner migration or an explicit legacy pin, and the full just lint wrapper is blocked by the missing sc-lint-boundary package, so release readiness is conditional.

Fuzz run descriptionIterationsPassResult
O.4 six-template parser oracle 6 6/6 PASS
Mode compatibility and 1.4.0 regression 6 6/6 PASS
Nested/conditional hostile boundary corpus 12 12/12 PASS
Pinned seven-root external corpus inventory 40 40/40 FAIL

Adversarial fuzz worker

six-template-parser-oracle

Session o5-20260813-0001 · Worker six-template-parser-oracle

PASS

Fuzz run descriptionIterationsPassResult
O.4 six-template hostile-value renders and complete JSON parser oracle 6 6/6 PASS

Inputs exercised

CaseTemplate / inputOutcome
o4-best-practicesrust-best-practices assignment with scalar and array valuesPASS: parsed object; no injected key
o4-rust-qarust-qa assignment with booleans and pathsPASS: parsed object; types preserved
o4-serviceservice-hardening assignment with topicsPASS: parsed object; no injection
o4-archarch-qa conditional null and referencesPASS: parsed object; null branch preserved
o4-flakyflaky-test-qa optional scope valuesPASS: parsed object; optional fields stable
o4-reqreq-qa document and branch arraysPASS: parsed object; array boundaries preserved

Adversarial fuzz worker

mode-compatibility-regression

Session o5-20260813-0001 · Worker mode-compatibility-regression

PASS

Fuzz run descriptionIterationsPassResult
Auto/legacy mode contract, 1.4.0 regression, and fail-closed output probes 6 6/6 PASS

Inputs exercised

CaseTemplate / inputOutcome
regression-auto-quotedOriginal 1.4.0 shape {"value": "{{ value }}"}PASS: ERR_JSON_MODE_CONTRACT before stdout/body emission
compat-legacy-quotedExplicit legacy quoted scalarPASS: valid JSON string and one WARN_JSON_LEGACY_ESCAPE_MODE
auto-bare-stringBare string complete JSON slotPASS: serde_json parsed string
auto-array-objectBare array/object valuesPASS: serde_json preserved array/object
checked-rendervalidate --check-render parser gatePASS: render_checked state and no emitted body
malformed-outputMalformed rendered JSONPASS: ERR_RENDER_JSON_MALFORMED and no output file

Adversarial fuzz worker

boundary-and-structure

Session o5-20260813-0001 · Worker boundary-and-structure

PASS

Fuzz run descriptionIterationsPassResult
Nested/conditional templates, hostile strings, lint diagnostics, and parser boundaries 12 12/12 PASS

Inputs exercised

CaseTemplate / inputOutcome
nested-arrayNested array/object contextPASS: complete JSON parse
conditional-nullConditional optional fieldPASS: null values preserved
unicodeUnicode and control-safe textPASS: parser and injection checks
lint-warningLegacy static lint warningPASS: stable warning code
lint-errorAuto quoted contract violationPASS: stable error code
no-bodyParser failure output confinementPASS: no stdout/file body

Adversarial fuzz worker

cross-repository-inventory

Session o5-20260813-0001 · Worker cross-repository-inventory

FAIL

Fuzz run descriptionIterationsPassResult
Pinned seven-root inventory and external legacy-template ownership scan 40 40/40 FAIL

Inputs exercised

CaseTemplate / inputOutcome
root-sc-composePinned sc-compose O.4 rootPASS: 11 paths counted; expected fixtures classified
root-atm-corePinned atm-core rootPASS: 7 paths counted; 6 owned findings
root-cpoPinned cpo rootPASS: 7 paths counted; 7 owned findings
root-raptorPinned raptor rootPASS: 3 paths counted; 3 owned findings
root-sc-lintPinned sc-lint rootPASS: 6 paths counted; 6 owned findings
root-synapticPinned synaptic-canvas rootPASS: 3 paths counted; 3 owned findings
root-roslyn-lintPinned roslyn-lint rootPASS: 3 paths counted; 3 owned findings

Findings

O5-ATM-001

Minimal template / frontmatter
atm-core: six .claude assignment JSON templates listed in docs/phase-O/evidence/o5-release-corpus.md
Input
hostile string value in a manually quoted placeholder
Expected
Migrate to explicit auto/bare values or explicitly pin legacy
Observed
No explicit mode; 1.4.1 auto contract will reject quoted placeholders or risk double quoting
Requirement / ADR
docs/requirements.md FR-1b-json; ADR-0019
Requirement / ADR follow-up
atm-core owner creates migration PR and reruns O5
Root cause
Consumer templates predate the 1.4.1 mode contract
Recommended fix
Migrate six paths in atm-core; add parser-backed tests

O5-CPO-001

Minimal template / frontmatter
cpo: seven JSON assignment paths listed in docs/phase-O/evidence/o5-release-corpus.md
Input
hostile string value in a manually quoted placeholder
Expected
Migrate to explicit auto/bare values or explicitly pin legacy
Observed
No explicit mode and quoted placeholders across all seven paths
Requirement / ADR
docs/requirements.md FR-1b-json; ADR-0019
Requirement / ADR follow-up
cpo owner creates migration PR and reruns O5
Root cause
Consumer templates predate the 1.4.1 mode contract
Recommended fix
Migrate seven paths and add parser-backed tests

O5-RAPTOR-001

Minimal template / frontmatter
raptor: three .claude/assets/sc-rust assignment paths listed in docs/phase-O/evidence/o5-release-corpus.md
Input
hostile string value in a manually quoted placeholder
Expected
Migrate to explicit auto/bare values or explicitly pin legacy
Observed
No explicit mode and quoted placeholders across all three paths
Requirement / ADR
docs/requirements.md FR-1b-json; ADR-0019
Requirement / ADR follow-up
raptor owner creates migration PR and reruns O5
Root cause
Consumer templates predate the 1.4.1 mode contract
Recommended fix
Migrate three paths and add parser-backed tests

O5-SCLINT-001

Minimal template / frontmatter
sc-lint: six assignment paths listed in docs/phase-O/evidence/o5-release-corpus.md
Input
hostile string value in a manually quoted placeholder
Expected
Migrate to explicit auto/bare values or explicitly pin legacy
Observed
No explicit mode and quoted placeholders across all six paths
Requirement / ADR
docs/requirements.md FR-1b-json; ADR-0019
Requirement / ADR follow-up
sc-lint owner creates migration PR or coordinates canonical package update
Root cause
Shared templates predate the 1.4.1 mode contract
Recommended fix
Migrate six paths and add parser-backed tests

O5-SYNAPTIC-001

Minimal template / frontmatter
synaptic-canvas: three packages/sc-rust assignment paths listed in docs/phase-O/evidence/o5-release-corpus.md
Input
hostile string value in a manually quoted placeholder
Expected
Migrate to explicit auto/bare values or explicitly pin legacy
Observed
No explicit mode and quoted placeholders across all three paths
Requirement / ADR
docs/requirements.md FR-1b-json; ADR-0019
Requirement / ADR follow-up
synaptic-canvas owner creates migration PR or consumes canonical package
Root cause
Consumer templates predate the 1.4.1 mode contract
Recommended fix
Migrate three paths and add parser-backed tests

O5-ROSLYN-001

Minimal template / frontmatter
roslyn-lint: three .claude/skills/codex-orchestration assignment paths listed in docs/phase-O/evidence/o5-release-corpus.md
Input
hostile string value in a manually quoted placeholder
Expected
Migrate to explicit auto/bare values or explicitly pin legacy
Observed
No explicit mode and quoted placeholders across all three paths
Requirement / ADR
docs/requirements.md FR-1b-json; ADR-0019
Requirement / ADR follow-up
roslyn-lint owner creates migration PR and reruns O5
Root cause
Consumer templates predate the 1.4.1 mode contract
Recommended fix
Migrate three paths and add parser-backed tests

Recommendations

Metadata

Pinned roots7 (sc-compose, atm-core, cpo, raptor, sc-lint, synaptic-canvas, roslyn-lint)
Templates scanned40 total; 28 external owned findings
Workspace gatesjust test/cargo/fmt/clippy/fast/direct boundary PASS; full just lint BLOCKED
Release recommendationCONDITIONAL