{
  "_doc": "One result, read from the codebase’s own files at the commit named here. Every value is that file’s own, copied verbatim; nothing here is written by hand. A value replaced by {withheld: true, sha256_of_value, bytes} is committed by its sha256 instead of published, for the reason it states, and is never edited. Each whole source file is committed by sha256 below, and its bytes are published only where its visibility says so. The codebase is named by the public subject its files are published under.",
  "lane": "code-admission",
  "repository": "code-admission",
  "commit": "b36a228c1b7ad32cc67717ac41d4419be13994a3",
  "portfolio_id": "code-admission:patch-differential",
  "id": "patch-differential",
  "attestation_row": {
    "attested_at": "2026-09-24",
    "attestor": "01-videocodec",
    "repository": {
      "withheld": true,
      "why": "a working-directory name (R8)",
      "sha256_of_value": "4ae679153e57269f61a4bf89b4afd161521d2f44caf38195a42876bb222c3ee0",
      "bytes": 7
    },
    "source_doc": "CROWN_JEWELS_RESOLVED.md",
    "source_doc_sha256": "5110525f2dc1b7a9b4781fdfc31491405d8d974ef721fa679dc15d7d6b2832c4",
    "state": "attested",
    "top_n": 20,
    "note_sha256": "ecc1adb4ea43531df2a8f265f2402dfdc09ca6cd3f4e6f746f92bb63a9d0dad6",
    "ids_in_row": 20,
    "file": "dataroom/TOP_N_ATTESTATION.jsonl",
    "line": 1
  },
  "claim_source": {
    "receipt": "code-admission/dataroom/top40.json",
    "sha256": "fcfaafe5f4f159116f21a97ad79f09535cd296e2dde0f3dc1765943b7fe442c8",
    "field": "entries[15].claim",
    "file": "dataroom/top40.json"
  },
  "top40_entry": {
    "id": "patch-differential",
    "rank": 16,
    "title": "Weakened-patch fuzzing differential",
    "claim": "Six off-by-a-slack weakenings, built so that very few inputs break them, each pass a 20,000-draw uniform fuzz battery with 0 hits (pooled 120,000 draws, 0 hits). For three classes (openssl, libxml2, libpng) the over-acceptance is counted exactly: a uniform draw hits with probability 2.3e-10 (openssl, libpng) or 4.66e-10 (libxml2), giving an expected 4.7e-06 detections at the median; for zlib, sudo and curl the over-acceptance is an estimate with a wide interval and no hit probability is claimed. The published median is over the three exact classes. A coverage-guided fuzzer at default settings finds every one: libFuzzer hit all six weakened guards in 30 of 30 runs (5 seeds per class) within at most 27,898 executions, and AFL++ in 30 of 30 runs within at most 2,443, where a uniform fuzzer needs 2,147,483,648 to 4,294,967,296 draws on average for the exact classes. Every hit input replays in exact arithmetic as an in-domain counterexample that refutes its weakening, so the fuzz-evasion holds against uniform random sampling only.",
    "scope": "Six plausible off-by-a-slack weakenings, one per class. The uniform battery models the fuzzer as uniform i.i.d.; libFuzzer and AFL++ at default settings were run on the same six (artifacts/certbench/patch_differential_realfuzz.json).",
    "limits": "The uniform battery and its hit probability model the fuzzer as uniform i.i.d. sampling (the artifact's fuzz_miss_probability field holds that per-draw hit probability). The real-fuzzer runs used libFuzzer from Homebrew clang 22.1.8 and AFL++ 5.01c at default settings (AFL_MAP_SIZE=65536 on this host), on harnesses generated from the modelled guards over the uniform model's own box, not on the libraries' code; executions are host-independent, wall-clock seconds are not (artifacts/certbench/patch_differential_realfuzz.json). over_acceptance_exact is false for zlib_inflate_extra, sudo_set_cmnd and curl_ntlm_type3 and fuzz_miss_probability is null for them (artifacts/certbench/patch_differential.json :: per_class[]); median_fuzz_miss_probability is a median over the 3 classes that have one, corrected 2026-09-02. The scorer's recorded sudo counterexample (su_idx 0, su_size 0) lies outside the declared domain (su_size >= 1), and its libxml2 refutation is an exact count, not a counterexample; the fuzzers' hits are in-domain counterexamples for all six.",
    "artifact_path": "artifacts/certbench/patch_differential.json",
    "witness_command": "python3 scripts/attest/assert_claim_number.py patch-differential",
    "witness_result": "exit=0 · EXIT0_NO_TOUCH · PASS|| patch-differential: all 35 number(s) and value(s) the claim of record states equal the committed artefact's",
    "witness_class": "ASSERTING",
    "third_party_axis": "—",
    "facts": {
      "ran_with_receipt": true,
      "third_party_graded": false,
      "negative_control_stated": false,
      "ip_class_known": false,
      "reproduce_command": true,
      "regenerates_not_verifies": false
    },
    "facts_count": 2,
    "repro_command": "python3 scripts/attest/assert_claim_number.py patch-differential",
    "reproduce_command": "python3 scripts/attest/assert_claim_number.py patch-differential",
    "ip_class": null,
    "evidence_tier": "T2",
    "run_status": "RAN",
    "output_excerpt": "$ make certbench-differential\n    libpng_rfc1123         PROVEN-UNSOUND       method=grid-counterexample        fuzz_hits=0 p_hit=2.3283064365386963e-10\n    sudo_set_cmnd          PROVEN-UNSOUND       method=grid-counterexample        fuzz_hits=0 p_hit=None\nEXIT=0\n$ python3 -m certbench.realfuzz\n[certbench-realfuzz] libfuzzer: 30/30 runs hit (0 fuzzer errors, 0 no hit within 60s); classes hit in every run 6/6; max executions to hit 27898; max seconds 0.561; every hit replays True\n[certbench-realfuzz] afl++: 30/30 runs hit (0 fuzzer errors, 0 no hit within 60s); classes hit in every run 6/6; max executions to hit 2443; max seconds 0.587; every hit replays True\nEXIT=0",
    "attestation_rank": 56
  },
  "witness_quality_entry": {
    "id": "patch-differential",
    "portfolio_id": {
      "withheld": true,
      "why": "a working-directory name (R8)",
      "sha256_of_value": "aa85f9307110512515107579c53378d41505d1b5f19a1ee8fa08c4081f021c05",
      "bytes": 26
    },
    "class": "ASSERTING",
    "why": "value probe RED and control GREEN: the witness enforces the claimed number as its artifact carries it, and is not merely parsing the file.",
    "witness_command": "python3 scripts/attest/assert_claim_number.py patch-differential",
    "clone_exit": 0,
    "defect_demonstration": {
      "probe": "value",
      "number": "2.3283064365386963",
      "mutated_exit": 1,
      "restored_exit": 0
    },
    "asserts": "the witness fails when the claimed number in its artifact is changed"
  },
  "packet": null,
  "measured": {
    "measured": true,
    "basis": "defect_demonstration.mutated_exit = 1",
    "exit": 1,
    "defect_rejected": true
  },
  "register": {
    "truth_state": "attested",
    "truth_line": 120,
    "measured_per_register": false,
    "witness_class_per_register": "ASSERTING",
    "ip_class_public": "unknown",
    "ip_class_sha256": "b23a6a8439c0dde5515893e7c90c1e3233b8616e634470f20dc4928bcf3609bc",
    "ip_class_source": " @ ",
    "receipt": "register/CROWN_JEWELS_TRUTH.md",
    "receipt_sha256": "79ca50c3472bae4ebd179ed533456325be8e0e9027739787bfba9f06442fc39b",
    "ip_class_receipt": "register/ip_class.jsonl",
    "ip_class_receipt_sha256": "1cd70f508c6b79f941e894144715088f18fcd31092e56e98a4cf6be526d9e724"
  },
  "withheld_fields": [
    {
      "field": "witness_quality.portfolio_id",
      "codes": [
        "LANE_DIRECTORY_NAME"
      ]
    },
    {
      "field": "attestation_row.repository",
      "codes": [
        "LANE_DIRECTORY_NAME"
      ]
    }
  ],
  "sources": {
    "attestation": {
      "receipt": "code-admission/dataroom/TOP_N_ATTESTATION.jsonl",
      "source": "dataroom/TOP_N_ATTESTATION.jsonl",
      "commit": "b36a228c1b7ad32cc67717ac41d4419be13994a3",
      "sha256": "b74ec34446c82d9c19cb2f8d32481efab6dae665d0e521fa8df4d77981db1371",
      "bytes": 3842,
      "visibility": "sealed"
    },
    "top40": {
      "receipt": "code-admission/top40.json",
      "source": "top40.json",
      "commit": "b36a228c1b7ad32cc67717ac41d4419be13994a3",
      "sha256": "6015b44486bcc57677221edd3f60d2020cbbaeaba18295305f46d145ef489e0b",
      "bytes": 547392,
      "visibility": "sealed"
    },
    "witness_quality": {
      "receipt": "code-admission/dataroom/witness_quality.json",
      "source": "dataroom/witness_quality.json",
      "commit": "b36a228c1b7ad32cc67717ac41d4419be13994a3",
      "sha256": "7b8f6118a896052bc5b49ee22b3142833868f4f9b0eae8d0700a82e72450d84f",
      "bytes": 101422,
      "visibility": "sealed"
    }
  }
}
