20260817-1 Beads Fuzz Campaign

Post-hoc durable evidence reconstruction

Generated: 2026-08-28

Source: Promoted regression tests at commit 12cfef8

FAIL

Summary

The original campaign report was not committed. This durable reconstruction preserves the three promoted findings and their minimized reproducers without claiming to reproduce missing worker transcripts.

Fuzz run descriptionIterationsPassResult
Legacy JSON null representation at different nesting depths 1 0/1 FAIL
TOML formula interpolation containing quotes and backslashes 1 0/1 FAIL
Distinct formula render failures retain distinguishable diagnostics 2 0/2 FAIL

Adversarial fuzz worker

shape-probe

Session sc-compose-fuzz-20260817-1 · Worker shape-probe

FAIL

Fuzz run descriptionIterationsPassResult
Legacy JSON null representation at different nesting depths 1 0/1 FAIL

Inputs exercised

CaseTemplate / inputOutcome
FUZZ-SHAPE-001Render `{ "n": "{{ n }}" }` under Legacy mode with top-level, array-nested, and object-nested JSON null values.FAIL: output diverges as empty string, `[none]`, and `{\"x\": none}` rather than one JSON-safe null representation.

Findings

FUZZ-SHAPE-001

Minimal template / frontmatter
{ "n": "{{ n }}" }
Input
n=null; n=[null]; n={"x":null}
Expected
A JSON null leaf has one consistent JSON-safe representation regardless of structured nesting.
Observed
Legacy mode emits an empty string for a top-level null but minijinja-style `none` for nested null values.
Requirement / ADR
No requirement or ADR currently covers this Legacy-mode null rendering invariant.
Requirement / ADR follow-up
Treat as a renderer compatibility decision; preserve the minimized regression until the intended Legacy representation is selected.
Root cause
Nested values reach minijinja's Python-style null formatting while a top-level null takes a separate coercion path.
Recommended fix
Serialize JSON null consistently at every nesting depth, then update this test to the selected contract.

Adversarial fuzz worker

template-probe

Session sc-compose-fuzz-20260817-1 · Worker template-probe

FAIL

Fuzz run descriptionIterationsPassResult
TOML formula interpolation containing quotes and backslashes 1 0/1 FAIL

Inputs exercised

CaseTemplate / inputOutcome
FUZZ-TEMPLATE-001Render TOML template `a = "{{{ x }}}"` with literal quotes and a backslash in `x`.FAIL: interpolated quotes and backslashes are unescaped, producing invalid quoted TOML.

Findings

FUZZ-TEMPLATE-001

Minimal template / frontmatter
a = "{{{ x }}}"
Input
x=has "quotes" and \backslash
Expected
A quoted TOML formula value either renders as valid TOML or fails with an explicit diagnostic.
Observed
The value is embedded without TOML string escaping.
Requirement / ADR
ADR-0021 makes formula rendering a sc-composer-beads responsibility but does not define TOML escaping semantics.
Requirement / ADR follow-up
Define the intended TOML formula rendering contract before implementing format-aware escaping or a fail-closed validation error.
Root cause
`.formula.toml.j2` receives the generic auto-escape mode, which has no TOML string-safety branch.
Recommended fix
Add a TOML-aware render path or reject unsafe interpolated TOML strings before emitting a formula.

Adversarial fuzz worker

boundary-probe

Session sc-compose-fuzz-20260817-1 · Worker boundary-probe

FAIL

Fuzz run descriptionIterationsPassResult
Distinct formula render failures retain distinguishable diagnostics 2 0/2 FAIL

Inputs exercised

CaseTemplate / inputOutcome
FUZZ-4177-BOUNDARY-01Compare malformed-template and missing-variable formula render failures.FAIL: both conditions report the same fixed `template rendering failed` message.

Findings

FUZZ-4177-BOUNDARY-01

Minimal template / frontmatter
hello {{{ unterminated; and a separate template referencing a missing value
Input
structured compose variables lacking the referenced value
Expected
Distinct render failures retain cause-specific details for diagnostics.
Observed
`RenderError::Display` collapses both causes to the same opaque text.
Requirement / ADR
ADR-0021 requires retained rendering failure details for Beads diagnostics.
Requirement / ADR follow-up
No new ADR is needed; implementation must satisfy the existing retained-detail contract.
Root cause
The adapter uses `RenderError::to_string()` instead of its cause-specific `message()` accessor.
Recommended fix
Use the cause-specific render error message when constructing `BeadComposeError::RenderFailed`.

Metadata

Sessionsc-compose-fuzz-20260817-1
Provenancepost_hoc_reconstruction
Promoted testscrates/sc-composer/src/renderer.rs::renderer_json_legacy_mode_null_representation_diverges_by_nesting_depth; crates/sc-composer-beads/src/render.rs::toml_formula_templates_embed_unescaped_quotes_and_backslashes; crates/sc-composer-beads/src/render.rs::render_failed_message_is_identical_for_distinct_failure_causes