Skip to content

Separate obfuscated names in nugetfuzz - #4184

Merged
1 commit merged into
masterfrom
testtools/nugetfuzz-obfuscated-names
Sep 28, 2026
Merged

1 commit merged into
masterfrom
testtools/nugetfuzz-obfuscated-names

Conversation

@siegfriedpammer

@siegfriedpammer siegfriedpammer commented Sep 27, 2026 •

Copy link
Copy Markdown
Member

nugetfuzz treated every invalid identifier as a leaked compiler-generated name. Invalid names that do not match compiler-generated-name shapes, and all names containing non-printable characters, come from obfuscators and should not be mixed into generated-name leak buckets.

This reports those names as OBFUSCATED, keeps generated-name-shaped invalid identifiers as compiler-generated LEAKs, reclassifies existing ledger rows when rendering, and adds an OBFUSCATED section to the HTML report. Large HTML reports are streamed to disk so the current crawl report can be rebuilt without holding the whole output in memory.

Verification:

  • OPENSSL_ENABLE_SHA1_SIGNATURES=1 dotnet run "TestTools/nugetfuzz.cs" --
  • OPENSSL_ENABLE_SHA1_SIGNATURES=1 dotnet run "TestTools/nugetfuzz.cs" -- --report "TestTools/crawl/findings.jsonl" "TestTools/crawl/nugetfuzz-report-current.html"
  • Rebuilt /home/siegfried/Projects/ILSpy/TestTools/crawl/nugetfuzz-report-current.html: LEAK (23967 distinct, 73972 hits), OBFUSCATED (96852 distinct, 1137282 hits).

This PR description was written by an AI agent (OpenCode gpt-5.5) working under @siegfriedpammer's direction.

@siegfriedpammer
siegfriedpammer force-pushed the testtools/nugetfuzz-obfuscated-names branch from bc92c53 to 12a3a6b Compare September 27, 2026 10:33
Non-printable identifiers and invalid names that do not match compiler-generated-name shapes come from obfuscators, not compiler-generated patterns. Report them separately so sweep triage does not mix obfuscation noise into generated-name leak buckets, reclassify existing ledger rows when rendering, and stream large HTML reports so the current crawl report can be rebuilt without retaining the whole file in memory.

Assisted-by: OpenCode:openai/gpt-5.5:OpenCode
@siegfriedpammer
siegfriedpammer force-pushed the testtools/nugetfuzz-obfuscated-names branch from 12a3a6b to 3b8775d Compare September 27, 2026 15:51
pull Bot pushed a commit to H1d3r/ILSpy that referenced this pull request Sep 27, 2026
…uzz-obfuscated-names

Separate obfuscated names in nugetfuzz
@christophwille christophwille closed this pull request by merging all changes into master in 7434b07 Sep 28, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants