Separate obfuscated names in nugetfuzz - #4184
Merged
1 commit merged intoSep 28, 2026
Merged
1 commit merged into
1 commit merged into
Conversation
siegfriedpammer
force-pushed
the
testtools/nugetfuzz-obfuscated-names
branch
from
September 27, 2026 10:33
bc92c53 to
12a3a6b
Compare
Non-printable identifiers and invalid names that do not match compiler-generated-name shapes come from obfuscators, not compiler-generated patterns. Report them separately so sweep triage does not mix obfuscation noise into generated-name leak buckets, reclassify existing ledger rows when rendering, and stream large HTML reports so the current crawl report can be rebuilt without retaining the whole file in memory. Assisted-by: OpenCode:openai/gpt-5.5:OpenCode
siegfriedpammer
force-pushed
the
testtools/nugetfuzz-obfuscated-names
branch
from
September 27, 2026 15:51
12a3a6b to
3b8775d
Compare
pull Bot
pushed a commit
to H1d3r/ILSpy
that referenced
this pull request
Sep 27, 2026
…uzz-obfuscated-names Separate obfuscated names in nugetfuzz
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
nugetfuzz treated every invalid identifier as a leaked compiler-generated name. Invalid names that do not match compiler-generated-name shapes, and all names containing non-printable characters, come from obfuscators and should not be mixed into generated-name leak buckets.
This reports those names as
OBFUSCATED, keeps generated-name-shaped invalid identifiers as compiler-generatedLEAKs, reclassifies existing ledger rows when rendering, and adds anOBFUSCATEDsection to the HTML report. Large HTML reports are streamed to disk so the current crawl report can be rebuilt without holding the whole output in memory.Verification:
OPENSSL_ENABLE_SHA1_SIGNATURES=1 dotnet run "TestTools/nugetfuzz.cs" --OPENSSL_ENABLE_SHA1_SIGNATURES=1 dotnet run "TestTools/nugetfuzz.cs" -- --report "TestTools/crawl/findings.jsonl" "TestTools/crawl/nugetfuzz-report-current.html"/home/siegfried/Projects/ILSpy/TestTools/crawl/nugetfuzz-report-current.html:LEAK (23967 distinct, 73972 hits),OBFUSCATED (96852 distinct, 1137282 hits).This PR description was written by an AI agent (OpenCode gpt-5.5) working under @siegfriedpammer's direction.