Skip to content

Fix review findings from PRs #11, #45, #46 - #47

Merged
daedalus merged 1 commit into
masterfrom
ccr-503d6e26-3ijog5
Oct 1, 2026
Merged

daedalus merged 1 commit into
masterfrom
ccr-503d6e26-3ijog5

Conversation

@daedalus

@daedalus daedalus commented Oct 1, 2026 •

Copy link
Copy Markdown
Owner

Addresses the open Copilot threads on merged PRs #11, #45, #46.

#11

  • --mod-solving trace reassigned the directed targets param → Katz skipped, _distance_targets = fuzz target. Local renamed div_targets.

#45 (Doppler)

  • 64 seeds picked in turn: LRU evicted every partial frame, nothing scored. Now new seeds wait for a slot; a frame untouched for STALE_FRAMES frames is scored early (≥3 samples) and freed.

  • Flow-edge ids: frozenset → sorted int64 array, global cap 2²⁰ ids (8 MiB), LRU-evicted.
  • Multi-target: frame key namespaced by target (observe + energy lookup).
  • No SHM: falls back to base with a warning.
  • Wiring test fails on compile error instead of skipping.
  • PNG staleness: already fixed in 2807e04 (png regenerated); no change.

#46

  • OS seed-arm ledgers gated on live corpus (seed picker's cached key map, memoized per parent), not seed_meta (standalone QEA).
  • EEVDF docs: heap work O(log n) amortized; pick O(n + log n).

Validation

  • New tests (falsification + adversarial each), observed failing before fixes.
  • 527 passed / 54 skipped across affected files; ruff + lizard clean.
  • PowerDoppler.observe: 113 → 109 µs at 2k edges (no regression).

🤖 Generated with Claude Code

https://claude.ai/code/session_01Rvj2gdMAa4HA8MGHULfDJE


Generated by Claude Code

Summary by Sourcery

Fix scheduling, directed-mode, and seed-accounting regressions while strengthening Doppler behavior and regression coverage.

Bug Fixes:

  • Preserve directed targets and Katz scoring when trace-based SMT solving is enabled.
  • Make Doppler scheduling reliable for large and multi-target corpora by retaining partial frames, scoring stale frames, bounding flow-edge memory, and isolating target-specific data.
  • Fall back to the base schedule when Doppler lacks shared-memory coverage.
  • Record seed-arm outcomes only for seeds currently present in the live corpus.

Enhancements:

  • Clarify EEVDF complexity as O(n + log n) overall with amortized heap work of O(log n).

Documentation:

  • Update the changelog, deep-dive documentation, and scheduling TODOs to describe the corrected Doppler behavior and resolved regressions.

Tests:

  • Add regression and adversarial coverage for trace-mode target handling, Doppler capacity and memory bounds, SHM fallback, multi-target isolation, and live-corpus seed-arm accounting.
  • Require Doppler wiring builds to fail on compilation errors instead of skipping them.

- #11: --mod-solving trace clobbered `targets`, dropping Katz.
- #45: Doppler frames close for any corpus size (admission, not LRU
  eviction); flow ids compact and capped; keys per target; falls back
  to base without SHM; compile failure fails the wiring test.
- #46: seed-arm ledgers gate on live-corpus membership, not seed_meta;
  EEVDF docs state O(n + log n) pick cost.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Rvj2gdMAa4HA8MGHULfDJE
@sourcery-ai

sourcery-ai Bot commented Oct 1, 2026

Copy link
Copy Markdown

Reviewer's Guide

This PR closes review findings across directed trace setup, Doppler scheduling, seed-arm accounting, and EEVDF documentation. The implementation preserves existing target state through local renaming, redesigns Doppler admission/eviction and compact flow-id retention with target-aware keys and an SHM capability gate, derives seed membership from the live corpus cache, and adds falsification/adversarial tests that expose the prior failures.

Sequence diagram for target-aware Doppler observation and scoring

sequenceDiagram
    participant Fuzzer
    participant SHM as SHM_Coverage
    participant Doppler as PowerDoppler
    participant Scorer as SeedScorer

    Fuzzer->>SHM: get_edge_counts()
    Fuzzer->>Doppler: observe(_doppler_key(seed_key), hits)
    alt Open frame available
        Doppler->>Doppler: observe(seed_key, hits)
    else Slots full and frame stale
        Doppler->>Doppler: _close(seed_key, ensemble)
        Doppler->>Doppler: observe(seed_key, hits)
    else Slots full and frames active
        Doppler-->>Fuzzer: refuse sample
    end
    Fuzzer->>Doppler: energy(_doppler_key(seed_key))
    Doppler-->>Scorer: doppler energy
Loading

Flow diagram for Doppler capability fallback

flowchart TD
    A["schedule = doppler"] --> B{SHM coverage available?}
    B -->|yes| C["Initialize PowerDoppler"]
    B -->|no| D["Print warning"]
    D --> E["Use base schedule"]
    C --> F["SeedScorer uses doppler"]
    E --> G["SeedScorer uses base"]
Loading

File-Level Changes

Change Details Files
Preserve directed-target and Katz behavior when trace-mode SMT setup is enabled.
  • Rename the trace-local target list so the constructor’s directed-target parameter remains intact.
  • Add regression coverage for both Katz preservation and directed-target preservation.
src/fuzzer_tool/services/fuzzer.py
tests/test_regression_katz_resume_contract.py
CHANGELOG.md
docs/TODO.md
Make Doppler frame collection robust and memory-bounded for large and multi-target campaigns.
  • Refuse new seeds while all frame slots are active, then score and reclaim sufficiently stale partial frames.
  • Store flow-edge ids as sorted int64 arrays with a global memory cap and correct replacement/eviction accounting.
  • Namespace frame and energy keys by target in multi-target mode.
  • Fall back to the base schedule with a warning when SHM coverage is unavailable.
  • Add adversarial/regression tests for stale frames, caps, rescores, SHM gating, and target isolation.
src/fuzzer_tool/core/power_doppler.py
src/fuzzer_tool/services/fuzzer.py
tests/test_power_doppler.py
CHANGELOG.md
docs/DEEP_DIVE.md
docs/TODO.md
Restrict OS/network seed-arm feedback to live corpus members.
  • Replace seed_meta membership checks with the seed picker’s cached corpus key map.
  • Memoize membership per parent and corpus size so admissions are observed without repeated lookups.
  • Test standalone-QEA exclusion and later corpus admission.
src/fuzzer_tool/services/fuzzer.py
tests/test_os_net_scheduler_wiring.py
CHANGELOG.md
Clarify EEVDF complexity guarantees and strengthen wiring-test failure behavior.
  • Document heap work as amortized O(log n) while retaining the overall O(n + log n) pick cost.
  • Make Doppler’s compile/wiring test fail on build errors instead of skipping them.
src/fuzzer_tool/core/fair_queue.py
tests/test_power_doppler.py

Tips and commands

Interacting with Sourcery

  • Trigger a new review: Comment @sourcery-ai review on the pull request.
  • Continue discussions: Reply directly to Sourcery's review comments.
  • Generate a GitHub issue from a review comment: Ask Sourcery to create an
    issue from a review comment by replying to it. You can also reply to a
    review comment with @sourcery-ai issue to create an issue from it.
  • Generate a pull request title: Write @sourcery-ai anywhere in the pull
    request title to generate a title at any time. You can also comment
    @sourcery-ai title on the pull request to (re-)generate the title at any time.
  • Generate a pull request summary: Write @sourcery-ai summary anywhere in
    the pull request body to generate a PR summary at any time exactly where you
    want it. You can also comment @sourcery-ai summary on the pull request to
    (re-)generate the summary at any time.
  • Generate reviewer's guide: Comment @sourcery-ai guide on the pull
    request to (re-)generate the reviewer's guide at any time.
  • Resolve all Sourcery comments: Comment @sourcery-ai resolve on the
    pull request to resolve all Sourcery comments. Useful if you've already
    addressed all the comments and don't want to see them anymore.
  • Dismiss all Sourcery reviews: Comment @sourcery-ai dismiss on the pull
    request to dismiss all existing Sourcery reviews. Especially useful if you
    want to start fresh with a new review - don't forget to comment
    @sourcery-ai review to trigger a new review!

Customizing Your Experience

Access your dashboard to:

  • Enable or disable review features such as the Sourcery-generated pull request
    summary, the reviewer's guide, and others.
  • Change the review language.
  • Add, remove or edit custom review instructions.
  • Adjust other review settings.

Getting Help

@daedalus
daedalus marked this pull request as ready for review October 1, 2026 00:49
Copilot AI balanced review requested due to automatic review settings October 1, 2026 00:49
@daedalus
daedalus merged commit 082d2a7 into master Oct 1, 2026

@sourcery-ai sourcery-ai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Sorry @daedalus, you've used your own review budget of 250,000 diff characters for the last 7 days.

You can request another review in 2 days and 14 hours by commenting @sourcery-ai review. Upgrade to get a review now.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Doppler can still starve large cyclic corpora, and corpus membership memoization can become stale after same-length replacements.

Review effort: Balanced
Findings: 1 High severity · 1 Medium severity

Open (2)
What changed in this PR

Fixes regressions in directed fuzzing, Doppler scheduling, and seed-arm accounting.

Changes:

  • Preserves directed targets during trace solving.
  • Bounds and namespaces Doppler state; adds SHM fallback.
  • Uses live-corpus membership for seed-arm records and expands tests/docs.
File Description
src/​fuzzer_tool/​services/​fuzzer.py Fixes target handling, Doppler wiring, and corpus gating.
src/​fuzzer_tool/​core/​power_doppler.py Adds bounded frames, scores, and flow IDs.
src/​fuzzer_tool/​core/​fair_queue.py Clarifies EEVDF complexity.
tests/​test_regression_katz_resume_contract.py Tests trace-mode target preservation.
tests/​test_power_doppler.py Tests Doppler limits, fallback, and isolation.
tests/​test_os_net_scheduler_wiring.py Tests live-corpus seed accounting.
docs/​DEEP_DIVE.md Documents corrected Doppler behavior.
docs/​TODO.md Updates resolved and pending work.
CHANGELOG.md Records fixes.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

self._scores: LRUCache = LRUCache(max_scores, on_evict=self._evicted)
self._max_scores = max_scores
self._max_flow_ids = max_flow_ids
self._stale_after = max_seeds * ensemble * STALE_FRAMES
Comment on lines +4554 to +4557
n = len(self.corpus)
memo = self._parent_memo
if memo is not None and memo[0] is parent and memo[1] == n:
return memo[2]
daedalus pushed a commit that referenced this pull request Oct 1, 2026
- Doppler: abandon horizon doubles when a dropped seed returns; a
  fixed horizon thrashed once the corpus cycle outlasted it.
- Seed-arm corpus memo: hits re-validated by slot identity, misses not
  memoized; length-keyed memo went stale on in-place trims.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Rvj2gdMAa4HA8MGHULfDJE
daedalus added a commit that referenced this pull request Oct 1, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants