Fix FuzzRedact leak of called digits in compact To headers - #2
Open
dimondevceo wants to merge 1 commit into
Open
dimondevceo wants to merge 1 commit into
dimondevceo wants to merge 1 commit into
Conversation
cursor
Bot
force-pushed
the
cursor/fix-fuzzredact-to-header-df12
branch
from
September 30, 2026 02:19
f8fcc6b to
d849861
Compare
dimondevceo
marked this pull request as ready for review
September 30, 2026 02:23
The digit scrub on called-party headers is already on main. This keeps the CI input T:4155550123tel: as a unit test and a fuzzer seed. Co-authored-by: DimonDev <dimondevceo@users.noreply.github.com>
cursor
Bot
force-pushed
the
cursor/fix-fuzzredact-to-header-df12
branch
from
September 30, 2026 02:25
d849861 to
980fa09
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Root cause
FuzzRedacton mainc614a3d(v0.9.16) failed in thecitest job:The fuzzer kept called digits
4155550in the shared SIP:redactNameAddrtreats atel:orsip:substring as a URI and replaces only the user after the scheme. Digits glued in front of the scheme stay. CompactTis a called-party header, so that path skipped the digit pass already used on Call-ID and From.Fix
Called-party header values run the existing digit scrub (
s.text) after URI redaction. That is the same pass used on Call-ID and From.Main
83e6457already contains that scrub. This PR keeps the deterministic test for the CI input (T:4155550123tel:with called4155550) and the matching fuzzer seed.Verification
Local, matching the
ci.ymltest job. All passed:gofmt -l .go vet ./...go test -race ./...go test -run '^$' -fuzz=FuzzParse -fuzztime=20s ./internal/sipmsg/go test -run '^$' -fuzz=FuzzRedact -fuzztime=20s ./internal/share/go test -run '^$' -fuzz=FuzzCompute -fuzztime=20s ./internal/fingerprint/GitHub Actions
cion this branch is green, includingtest.