Skip to content

Wave-32 C07: sustained fuzz cadence soft job - #266

Merged
KooshaPari merged 2 commits into
mainfrom
feat/sl-w32-c07-fuzz-cadence
Jul 14, 2026
Merged

Wave-32 C07: sustained fuzz cadence soft job#266
KooshaPari merged 2 commits into
mainfrom
feat/sl-w32-c07-fuzz-cadence

Conversation

@KooshaPari

Copy link
Copy Markdown
Owner

Summary

  • Sustained fuzz cadence soft/scheduled job + SelfCheck

Test plan

  • SelfCheck passes; PR fuzz smoke unchanged

Made with Cursor

Add fuzz-cadence SSOT, soft nightly 120s campaigns with crash artifact triage, and SelfCheck without slowing PR fuzz-smoke.

Co-authored-by: Cursor <cursoragent@cursor.com>
@gemini-code-assist

Copy link
Copy Markdown

Warning

You have reached your daily quota limit. Please wait up to 24 hours and I will start processing your requests again!

@coderabbitai

coderabbitai Bot commented Jul 14, 2026

Copy link
Copy Markdown

Review Change Stack

Warning

Review limit reached

@KooshaPari, you've reached your PR review limit, so we couldn't start this review.

Next review available in: 49 minutes

Enable usage-based reviews in Billing to review now. Otherwise, wait until the next included review is available.
You're only billed for reviews past your plan's rate limits ($0.25/file).

How can I continue?

After more reviews become available, a review can be triggered using the @coderabbitai review command as a PR comment. Alternatively, push new commits to this PR.

To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based reviews.

How do review limits work?

CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan review availability.

For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, additional reviews become available more gradually as earlier reviews age out of the rolling window.

Please refer docs for additional details.

Review details
⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Pro

Run ID: 4baca010-960b-4583-8432-27ed4682148b

📥 Commits

Reviewing files that changed from the base of the PR and between ea42059 and 1f96578.

📒 Files selected for processing (1)
  • tests/fuzz_cadence.rs
📝 Walkthrough

Walkthrough

Adds a scheduled and manually dispatched soft fuzzing workflow, documents fuzz cadence and crash triage, introduces a PowerShell SelfCheck for configuration anchors, and runs that SelfCheck from a Rust test.

Changes

Fuzz cadence

Layer / File(s) Summary
Cadence workflow and documentation
.github/workflows/fuzz-cadence.yml, docs/ops/fuzz-cadence.md, docs/ops/test-pyramid.md, CONTRIBUTING.md
Adds PR SelfCheck and non-PR sustained fuzz jobs, documents targets and triage, and clarifies 10-second PR smoke versus 120-second sustained runs.
Cadence SelfCheck implementation
scripts/fuzz-cadence-check.ps1
Validates required files, documentation anchors, workflow settings, fuzz targets, artifacts, and the 10-second PR smoke constraint.
Automated SelfCheck validation
tests/fuzz_cadence.rs
Runs the PowerShell SelfCheck through pwsh and asserts successful completion and output.

Estimated code review effort: 3 (Moderate) | ~20 minutes

Sequence Diagram(s)

sequenceDiagram
  participant GitHubActions
  participant SelfCheck
  participant FuzzTargets
  GitHubActions->>SelfCheck: Run -SelfCheck for pull_request
  SelfCheck->>SelfCheck: Validate docs and workflow anchors
  GitHubActions->>FuzzTargets: Run both targets for 120 seconds on scheduled or manual runs
  FuzzTargets-->>GitHubActions: Upload crash artifacts on failure
Loading

Possibly related PRs

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Title check ✅ Passed The title clearly summarizes the main change: adding a sustained fuzz cadence soft job.
Description check ✅ Passed The description is directly related to the fuzz cadence and SelfCheck changes in the pull request.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch feat/sl-w32-c07-fuzz-cadence
✨ Simplify code
  • Create PR with simplified code
  • Commit simplified code in branch feat/sl-w32-c07-fuzz-cadence

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In @.github/workflows/fuzz-cadence.yml:
- Line 30: Disable credential persistence for both checkout steps in jobs
fuzz-selfcheck and fuzz-sustained by adding with.persist-credentials: false to
the checkout actions at .github/workflows/fuzz-cadence.yml lines 30-30 and
48-48.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Pro

Run ID: 9e3fb455-e97d-44f8-9c83-45768a4476cd

📥 Commits

Reviewing files that changed from the base of the PR and between f8a4642 and ea42059.

📒 Files selected for processing (6)
  • .github/workflows/fuzz-cadence.yml
  • CONTRIBUTING.md
  • docs/ops/fuzz-cadence.md
  • docs/ops/test-pyramid.md
  • scripts/fuzz-cadence-check.ps1
  • tests/fuzz_cadence.rs
📜 Review details
⏰ Context from checks skipped due to timeout. (7)
  • GitHub Check: semgrep-cloud-platform/scan
  • GitHub Check: sl-daemon · pinned builder image offline build
  • GitHub Check: clean-host smoke · Windows unsigned portable install
  • GitHub Check: sl-daemon build · windows-latest
  • GitHub Check: cargo audit
  • GitHub Check: visual contract · WCAG AA
  • GitHub Check: soft loom · loom_model
🧰 Additional context used
📓 Path-based instructions (2)
**/*

📄 CodeRabbit inference engine (AGENTS.md)

**/*: Perform feature work in a git worktree under .claude/worktrees/, never directly on main; use branches named <type>/<topic> where <type> is feat, fix, chore, ci, or docs.
Do not directly commit to main; submit changes through a PR.
Do not use git reset --hard, git stash, or git clean in worktrees.
Do not use --no-verify or bypass hooks without operator approval.
Do not add AI attribution to commit or PR metadata.
Validate changes with the repository's required build, test, lint, and formatting commands: cargo build --all-targets --locked, cargo test --all-features --locked, cargo clippy --all-targets --all-features, and cargo fmt --all --check.

Files:

  • tests/fuzz_cadence.rs
  • docs/ops/test-pyramid.md
  • CONTRIBUTING.md
  • docs/ops/fuzz-cadence.md
  • scripts/fuzz-cadence-check.ps1
**/*.rs

📄 CodeRabbit inference engine (AGENTS.md)

Fix Clippy warnings; do not use #[allow] unless accompanied by a tracking-issue comment.

Files:

  • tests/fuzz_cadence.rs
🪛 LanguageTool
docs/ops/fuzz-cadence.md

[uncategorized] ~9-~9: The official name of this software platform is spelled with a capital “H”.
Context: ...yramid layer),
fuzz/, [.github/workflows/ci.yml](../../.github/workfl...

(GITHUB)


[uncategorized] ~10-~10: The official name of this software platform is spelled with a capital “H”.
Context: ...thub/workflows/ci.yml)
(fuzz-smoke), [.github/workflows/fuzz-cadence.yml](../../.git...

(GITHUB)


[uncategorized] ~67-~67: The official name of this software platform is spelled with a capital “H”.
Context: ...
| Soft sustained fuzz CI | done | .github/workflows/fuzz-cadence.yml (`continue-...

(GITHUB)


[uncategorized] ~68-~68: The official name of this software platform is spelled with a capital “H”.
Context: ...
| PR fuzz-smoke (10 s) | done | .github/workflows/ci.yml (unchanged; stays blo...

(GITHUB)

🪛 PSScriptAnalyzer (1.25.0)
scripts/fuzz-cadence-check.ps1

[warning] 53-53: The cmdlet 'Test-DocContains' uses a plural noun. A singular noun should be used instead.

Suggested fix: Singularized correction of 'Test-DocContains'

(PSUseSingularNouns)

🪛 YAMLlint (1.37.1)
.github/workflows/fuzz-cadence.yml

[error] 1-1: wrong new line character: expected \n

(new-lines)


[warning] 7-7: truthy value should be one of [false, true]

(truthy)

🪛 zizmor (1.26.1)
.github/workflows/fuzz-cadence.yml

[warning] 30-30: credential persistence through GitHub Actions artifacts (artipacked): does not set persist-credentials: false

(artipacked)


[warning] 48-48: credential persistence through GitHub Actions artifacts (artipacked): does not set persist-credentials: false

(artipacked)


[info] 49-49: action functionality is already included by the runner (superfluous-actions): use rustup and/or cargo in a script step

(superfluous-actions)

🔇 Additional comments (5)
docs/ops/fuzz-cadence.md (1)

1-91: LGTM!

docs/ops/test-pyramid.md (1)

137-140: LGTM!

CONTRIBUTING.md (1)

33-36: LGTM!

scripts/fuzz-cadence-check.ps1 (1)

1-147: LGTM!

tests/fuzz_cadence.rs (1)

1-43: LGTM!

timeout-minutes: 5
continue-on-error: true
steps:
- uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🔒 Security & Privacy | 🟡 Minor | ⚡ Quick win

Disable credential persistence in checkout steps.

Both checkout steps rely on the default behavior that leaves the GITHUB_TOKEN in the local .git/config. Since this workflow does not push changes, it is a security best practice to explicitly disable this to prevent potential credential leakage.

  • .github/workflows/fuzz-cadence.yml#L30-L30: Add with: and persist-credentials: false to the checkout step in the fuzz-selfcheck job.
  • .github/workflows/fuzz-cadence.yml#L48-L48: Add with: and persist-credentials: false to the checkout step in the fuzz-sustained job.
🧰 Tools
🪛 zizmor (1.26.1)

[warning] 30-30: credential persistence through GitHub Actions artifacts (artipacked): does not set persist-credentials: false

(artipacked)

📍 Affects 1 file
  • .github/workflows/fuzz-cadence.yml#L30-L30 (this comment)
  • .github/workflows/fuzz-cadence.yml#L48-L48
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In @.github/workflows/fuzz-cadence.yml at line 30, Disable credential
persistence for both checkout steps in jobs fuzz-selfcheck and fuzz-sustained by
adding with.persist-credentials: false to the checkout actions at
.github/workflows/fuzz-cadence.yml lines 30-30 and 48-48.

Source: Linters/SAST tools

@KooshaPari
KooshaPari merged commit 57ac852 into main Jul 14, 2026
54 of 56 checks passed
KooshaPari added a commit that referenced this pull request Jul 14, 2026
audit: Wave-32 reaudit after #266-#271 (375/402, 93% A)
cancel-in-progress: true

permissions:
contents: read

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

WARNING: permissions: contents: read likely breaks the crash-artifact upload

Setting permissions: at workflow scope overrides the default GITHUB_TOKEN grants and leaves the token with only contents: read. actions/upload-artifact@v7 (v4) needs actions: read to query the run/API, and sibling uploads in ci.yml work precisely because they set no permissions: block (so they inherit defaults). Because the upload step is if: failure() inside a continue-on-error: true job, a permission failure here is silent — crashing fuzz runs won't produce the triage artifacts this PR exists to capture. Add actions: read (and id-token: write if OIDC upload is used) to the permissions block.


Reply with @kilocode-bot fix it to have Kilo Code address this issue.

Comment thread tests/fuzz_cadence.rs
let script = repo_root().join("scripts/fuzz-cadence-check.ps1");
assert!(script.is_file(), "expected fuzz cadence check script at {}", script.display());

let output = Command::new("pwsh")

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

SUGGESTION: Test hard-depends on pwsh, breaking cargo test without PowerShell

This integration test spawns pwsh unconditionally. It passes on GitHub-hosted runners (pwsh is preinstalled, so cargo test --all-features in ci.yml is fine), but panics with "failed to spawn pwsh" on contributor machines/CI images lacking PowerShell — breaking the local test loop the custom rules require (cargo test --workspace must pass). Consider checking for pwsh and skipping gracefully, or gating the test behind an availability guard, and document the requirement.


Reply with @kilocode-bot fix it to have Kilo Code address this issue.

#>
[CmdletBinding()]
param(
[switch]$SelfCheck

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

SUGGESTION: -SelfCheck switch is declared but never used for branching

The [switch]$SelfCheck parameter and its .PARAMETER/.EXAMPLE docs imply it changes behavior, but the script runs identical checks regardless of the flag (the only effect is an extra "Mode: SelfCheck" log line). Either honor the switch or drop the param and simplify the docs to avoid a misleading API.


Reply with @kilocode-bot fix it to have Kilo Code address this issue.

$selfPath = Join-Path $repoRoot "scripts/fuzz-cadence-check.ps1"
$okfTarget = Join-Path $repoRoot "fuzz/fuzz_targets/okf_roundtrip.rs"
$jsonlTarget = Join-Path $repoRoot "fuzz/fuzz_targets/jsonl_ingest.rs"
$okfCorpus = Join-Path $repoRoot "fuzz/corpus/okf_roundtrip/minimal.json"

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

SUGGESTION: SelfCheck pins specific corpus seed filenames

$okfCorpus/$jsonlCorpus assert exact files (minimal.json, two_sessions.jsonl). These exist today, but renaming or adding seeds will break the SelfCheck (and the Rust test + CI) with a cryptic "Missing ... corpus seed" error. Prefer asserting the corpus directory exists and contains at least one seed, which survives seed renames.


Reply with @kilocode-bot fix it to have Kilo Code address this issue.

@kilo-code-bot

kilo-code-bot Bot commented Jul 14, 2026

Copy link
Copy Markdown

Code Review Summary

Status: 4 Issues Found | Recommendation: Address before merge (soft CI only; non-blocking)

Overview

Severity Count
CRITICAL 0
WARNING 1
SUGGESTION 3
Issue Details (click to expand)

WARNING

File Line Issue
.github/workflows/fuzz-cadence.yml 18 permissions: contents: read overrides default token grants and drops actions: read that actions/upload-artifact@v7 (v4) needs; the if: failure() upload in a continue-on-error job will fail silently, defeating crash-triage. Add actions: read.

SUGGESTION

File Line Issue
tests/fuzz_cadence.rs 18 Integration test unconditionally spawns pwsh; panics on machines/CI without PowerShell, breaking the local cargo test loop. Guard/skip when pwsh is absent.
scripts/fuzz-cadence-check.ps1 20 -SelfCheck switch is declared and documented but never used for branching; behavior is identical regardless. Honor it or remove it.
scripts/fuzz-cadence-check.ps1 33 SelfCheck asserts exact corpus seed filenames (minimal.json, two_sessions.jsonl); renaming seeds breaks the check + Rust test + CI with a cryptic error. Assert the corpus dir has at least one seed instead.
Files Reviewed (6 files)
  • .github/workflows/fuzz-cadence.yml - 1 issue (WARNING)
  • CONTRIBUTING.md - 0 issues
  • docs/ops/fuzz-cadence.md - 0 issues
  • docs/ops/test-pyramid.md - 0 issues
  • scripts/fuzz-cadence-check.ps1 - 2 issues (SUGGESTION)
  • tests/fuzz_cadence.rs - 1 issue (SUGGESTION)

Note: A separate persist-credentials: false finding on the checkout steps (line 30/48) was already raised by another reviewer and is not duplicated here.

Fix these issues in Kilo Cloud


Reviewed by hy3:free · Input: 97K · Output: 18.7K · Cached: 348K

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant