{
 "_doc": "The lab's current claim and limits for one result, copied word for word from the portfolio's current-claims file at the line named here. A value this site does not print in full is replaced by its sha256 and byte count, with the reason; the excerpts beside it are copied word for word from the same value. Nothing here is written by hand.",
 "result": "code-admission:patch-differential",
 "title": "Weakened-patch fuzzing differential",
 "claim": "Six off-by-a-slack weakenings, built so that very few inputs break them, each pass a 20,000-draw uniform fuzz battery with 0 hits (pooled 120,000 draws, 0 hits). For three classes (openssl, libxml2, libpng) the over-acceptance is counted exactly: a uniform draw hits with probability 2.3e-10 (openssl, libpng) or 4.66e-10 (libxml2), giving an expected 4.7e-06 detections at the median; for zlib, sudo and curl the over-acceptance is an estimate with a wide interval and no hit probability is claimed. The published median is over the three exact classes. A coverage-guided fuzzer at default settings finds every one: libFuzzer hit all six weakened guards in 30 of 30 runs (5 seeds per class) within at most 27,898 executions, and AFL++ in 30 of 30 runs within at most 2,443, where a uniform fuzzer needs 2,147,483,648 to 4,294,967,296 draws on average for the exact classes. Every hit input replays in exact arithmetic as an in-domain counterexample that refutes its weakening, so the fuzz-evasion holds against uniform random sampling only.",
 "limits": "The uniform battery and its hit probability model the fuzzer as uniform i.i.d. sampling (the artifact's fuzz_miss_probability field holds that per-draw hit probability). The real-fuzzer runs used libFuzzer from Homebrew clang 22.1.8 and AFL++ 5.01c at default settings (AFL_MAP_SIZE=65536 on this host), on harnesses generated from the modelled guards over the uniform model's own box, not on the libraries' code; executions are host-independent, wall-clock seconds are not (artifacts/certbench/patch_differential_realfuzz.json). over_acceptance_exact is false for zlib_inflate_extra, sudo_set_cmnd and curl_ntlm_type3 and fuzz_miss_probability is null for them (artifacts/certbench/patch_differential.json :: per_class[]); median_fuzz_miss_probability is a median over the 3 classes that have one, corrected 2026-09-02. The scorer's recorded sudo counterexample (su_idx 0, su_size 0) lies outside the declared domain (su_size >= 1), and its libxml2 refutation is an exact count, not a counterexample; the fuzzers' hits are in-domain counterexamples for all six.",
 "claim_excerpts": [],
 "limits_excerpts": [],
 "lab_commit": "b36a228c1b7ad32cc67717ac41d4419be13994a3",
 "source": {
  "file": "portfolio-control registry/CLAIMS_CURRENT.jsonl",
  "line": 10,
  "sha256": "81776df15a1498abec7228ea179c952d01c54e031ffd4144498a30660963074b"
 },
 "evidence": "/receipts/code-admission/results/patch-differential.json",
 "copied_utc": "2026-10-03T16:11:27Z"
}
