Skip to content

fuzz: a null HIR link target is a finding only when serde accepts the input - #1081

Merged
avrabe merged 1 commit into
mainfrom
fuzz/null-target-oracle
Oct 10, 2026
Merged

avrabe merged 1 commit into
mainfrom
fuzz/null-target-oracle

Conversation

@avrabe

@avrabe avrabe commented Oct 10, 2026

Copy link
Copy Markdown
Contributor

Once #1080 fixed the empty-target crash, yaml_footguns reached the next input, target: null, and crashed on it (job 114142156725):

silent-accept: hir link target coerced from YAML null: "null"

This is not a silent accept. I checked with a fixture for null and ~ on both paths:

path result
rivet validate (default) ERROR: the file fails to parse (serde: did not match any variant of untagged enum LinkTargetWire) and ERROR: link targets 'null', which does not exist
rivet validate --direct ERROR: the file fails to parse

Change: the oracle only, with no product behaviour change. The HIR null-target assertion now fires only when parse_generic_yaml accepted the document, which is the case where the coercion would go unreported. This narrows the old assertion, which fired on any null-ish HIR target. It follows the same reasoning as your empty-target decision: a malformed link is acceptable when validation rejects it loudly. Please review this, since it is a judgement about the oracle rather than a behaviour fix.

The harness type-checks on the pinned nightly. The post-merge fuzz runs are the evidence.

🤖 Generated with Claude Code

https://claude.ai/code/session_015HMQUV3u86jN2hmCtXNTc9

… input

With the empty-target crash fixed (#1080), yaml_footguns now stops on
`target: null`: the HIR reads it as the text `null`. That is not a silent
accept. The serde path cannot parse a null target, and the parse error fails
`rivet validate` on both paths (the default path also reports the HIR link
to `null` as broken); confirmed with a fixture for `null` and `~`. The HIR
null oracle now fires only when serde accepted the document, which is when
the coercion would go unreported. This narrows the oracle; it changes no
product behaviour.

Refs: REQ-028

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_015HMQUV3u86jN2hmCtXNTc9
@codecov

codecov Bot commented Oct 10, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.

📢 Thoughts on this report? Let us know!

@avrabe
avrabe merged commit 2c83276 into main Oct 10, 2026
33 checks passed
@avrabe
avrabe deleted the fuzz/null-target-oracle branch October 10, 2026 09:04
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant