|
| 1 | +/** |
| 2 | + * One implementation of the failure fingerprint, shared by everything that |
| 3 | + * groups the same failure: the version/create report, the fuzzer's dedup of |
| 4 | + * its findings, and (later) the replay of the stored corpus. Two |
| 5 | + * implementations would mean the counts behind "how often does this happen" |
| 6 | + * are fiction, so callers import from here rather than writing their own |
| 7 | + * regexes. |
| 8 | + * |
| 9 | + * Redaction is the other half. A detail line carries whatever hermesc printed, |
| 10 | + * which is the user's own code: the first rejection seen in production named |
| 11 | + * the property `promotionRequestItemId`. Details travel to the server, into |
| 12 | + * issue lists and -- once the fix loop runs -- into public pull requests and CI |
| 13 | + * fixtures, so the identifiers are replaced by tokens *before* the report |
| 14 | + * leaves the machine. The local console keeps the unredacted text: that is |
| 15 | + * where the name is actually useful. |
| 16 | + */ |
| 17 | +import { createHash } from 'node:crypto'; |
| 18 | + |
| 19 | +const sha = (value: string) => createHash('sha256').update(value).digest('hex'); |
| 20 | + |
| 21 | +/** stable stand-in for one redacted value; the same input always yields it */ |
| 22 | +const token = (kind: string, value: string) => |
| 23 | + `${kind}#${sha(value).slice(0, 8)}`; |
| 24 | + |
| 25 | +/** |
| 26 | + * Replace the parts of a detail line that can only come from the user's code: |
| 27 | + * quoted string operands (property names, string literals), function names, |
| 28 | + * and filesystem paths that reach the line through a compiler's stderr. What |
| 29 | + * stays is the shape a fix is reasoned about -- opcodes, registers, counts, |
| 30 | + * literal kinds -- plus each redacted value's length and character class. |
| 31 | + * |
| 32 | + * This is redaction by class, not a proof: it covers the shapes the comparison |
| 33 | + * and the compilers are known to emit. Anything that arrives in an unknown |
| 34 | + * shape still has its paths and quoted runs stripped, so a new detail format |
| 35 | + * cannot silently start leaking identifiers. |
| 36 | + */ |
| 37 | +export function redactFailureDetail(detail: string): string { |
| 38 | + return ( |
| 39 | + detail |
| 40 | + // Paths first: a compiler's stderr reaches the line with them, and |
| 41 | + // running this pass after the others would eat the `/<length>` suffix |
| 42 | + // the string pass writes. |
| 43 | + .replace(/(?:\.{0,2}\/)[^\s:,)"']*/g, (path: string) => { |
| 44 | + const ext = /\.([A-Za-z0-9]+)$/.exec(path); |
| 45 | + return `${token('path', path)}${ext ? `.${ext[1]}` : ''}`; |
| 46 | + }) |
| 47 | + // Function<name>(…) headers, including the raw-audit variants |
| 48 | + .replace( |
| 49 | + /\b(Function|NCFunction|Constructor)<([^>]*)>/g, |
| 50 | + (_all, kind: string, name: string) => |
| 51 | + `${kind}<${name ? token('fn', name) : ''}>`, |
| 52 | + ) |
| 53 | + // Quoted operands. hermesc does not escape quotes inside strings, so the |
| 54 | + // run is taken as-is up to the next quote; a stray tail keeps whatever |
| 55 | + // the earlier passes left rather than being reconstructed. |
| 56 | + .replace(/"([^"\n]*)"/g, (_all, value: string) => { |
| 57 | + const units = Array.from(value); |
| 58 | + const ascii = units.every((char) => char.charCodeAt(0) < 0x80); |
| 59 | + return `"${token('str', value)}/${units.length}${ascii ? '' : '/u16'}"`; |
| 60 | + }) |
| 61 | + ); |
| 62 | +} |
| 63 | + |
| 64 | +/** |
| 65 | + * The grouping key: a redacted detail with everything that varies between two |
| 66 | + * occurrences of the same defect removed -- registers, ids, offsets, labels, |
| 67 | + * counts and the redaction tokens themselves. Sixteen bytes; the server stores |
| 68 | + * it as 32 hex characters. |
| 69 | + */ |
| 70 | +export function failureFingerprint(detail: string): string { |
| 71 | + const shape = redactFailureDetail(detail) |
| 72 | + .replace(/#[0-9a-f]{8}/g, '#') |
| 73 | + .replace(/\br\d+\b/g, 'r') |
| 74 | + .replace(/\bL\d+\b/g, 'L') |
| 75 | + .replace(/\d+/g, 'N') |
| 76 | + .replace(/\s+/g, ' ') |
| 77 | + .trim(); |
| 78 | + return sha(shape).slice(0, 32); |
| 79 | +} |
0 commit comments