Skip to content

Complete the existing mutation gate with a real sandboxed Stryker.NET runner - #698

Merged
AdamFrisby merged 3 commits into
mainfrom
codeybox/b2b898c9
Oct 5, 2026
Merged

AdamFrisby merged 3 commits into
mainfrom
codeybox/b2b898c9

Conversation

@AdamFrisby

Copy link
Copy Markdown
Owner

Automated via CodeyBox — work item b2b898c967054c10ad0b9a12e09e21cb

Initiated by CodeyBox operator


Co-Authored-By: CodeyBox noreply@codeybox.invalid
🤖 Generated with CodeyBox

AdamFrisby and others added 3 commits October 5, 2026 05:42
Implements the real .NET mutation seam: StrykerMutationRunner invokes the
pinned dotnet-stryker (4.16.0) inside the credential-free audit sandbox,
selects owning production projects plus referencing test projects,
scopes mutation to validated changed paths, and parses only the
machine-readable JSON report. Scoped runs carry no overall score and
never move the ratchet; baselines are digest-isolated per engine
configuration. Default composition stays inert (NullMutationRunner,
gate disabled).

Validation: 132 unit tests plus real-tool integration proving the
weak-fixture survivor and its death on strengthened tests; solution
builds warnings-clean; gitleaks and semgrep (changed files) clean.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

CodeyBox-Prompt-Revision: 1
Co-Authored-By: CodeyBox <noreply@codeybox.invalid>
Route every Stryker console/report-derived string through
StrykerPaths.SanitizeForLog before it reaches exceptions, findings,
or RawOutput; reject control characters in TryParseMutant and harden
tool-version parsing to a strict token charset. Covers probe,
discovery, no-report classification, console-tail provenance,
survivor details, and auditor failure/enumeration paths. Adds
regression tests for hostile mutators, console output, and
survivor findings.

CodeyBox-Prompt-Revision: 1
Co-Authored-By: CodeyBox <noreply@codeybox.invalid>
Reject any path segment starting with '-' in NormalizeRepoPath and
validate every repo-derived Stryker option value at the argv sink, so
attacker-influenceable file names can never desynchronize stryker flag
parsing. Fail closed with a Tool-kind diagnostic.

CodeyBox-Prompt-Revision: 1
Co-Authored-By: CodeyBox <noreply@codeybox.invalid>
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
@AdamFrisby
AdamFrisby merged commit 8c72dbb into main Oct 5, 2026
@AdamFrisby
AdamFrisby deleted the codeybox/b2b898c9 branch October 5, 2026 07:19
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant