Repository navigation
fuzz: a null HIR link target is a finding only when serde accepts the input - #1081
Merged
Merged
Conversation
… input With the empty-target crash fixed (#1080), yaml_footguns now stops on `target: null`: the HIR reads it as the text `null`. That is not a silent accept. The serde path cannot parse a null target, and the parse error fails `rivet validate` on both paths (the default path also reports the HIR link to `null` as broken); confirmed with a fixture for `null` and `~`. The HIR null oracle now fires only when serde accepted the document, which is when the coercion would go unreported. This narrows the oracle; it changes no product behaviour. Refs: REQ-028 Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_015HMQUV3u86jN2hmCtXNTc9
Codecov Report✅ All modified and coverable lines are covered by tests. 📢 Thoughts on this report? Let us know! |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Once #1080 fixed the empty-target crash,
yaml_footgunsreached the next input,target: null, and crashed on it (job 114142156725):This is not a silent accept. I checked with a fixture for
nulland~on both paths:rivet validate(default)did not match any variant of untagged enum LinkTargetWire) and ERROR: link targets'null', which does not existrivet validate --directChange: the oracle only, with no product behaviour change. The HIR null-target assertion now fires only when
parse_generic_yamlaccepted the document, which is the case where the coercion would go unreported. This narrows the old assertion, which fired on any null-ish HIR target. It follows the same reasoning as your empty-target decision: a malformed link is acceptable when validation rejects it loudly. Please review this, since it is a judgement about the oracle rather than a behaviour fix.The harness type-checks on the pinned nightly. The post-merge fuzz runs are the evidence.
🤖 Generated with Claude Code
https://claude.ai/code/session_015HMQUV3u86jN2hmCtXNTc9