Skip to content

Fix FuzzRedact leak of called digits in compact To headers - #2

Open
dimondevceo wants to merge 1 commit into
mainfrom
cursor/fix-fuzzredact-to-header-df12
Open

dimondevceo wants to merge 1 commit into
mainfrom
cursor/fix-fuzzredact-to-header-df12

Conversation

@dimondevceo

@dimondevceo dimondevceo commented Sep 21, 2026 •

Copy link
Copy Markdown
Collaborator

Root cause

FuzzRedact on main c614a3d (v0.9.16) failed in the ci test job:

go test -run '^$' -fuzz=FuzzRedact -fuzztime=20s ./internal/share/

The fuzzer kept called digits 4155550 in the shared SIP:

T: 4155550123tel:REDACTED

redactNameAddr treats a tel: or sip: substring as a URI and replaces only the user after the scheme. Digits glued in front of the scheme stay. Compact T is a called-party header, so that path skipped the digit pass already used on Call-ID and From.

Fix

Called-party header values run the existing digit scrub (s.text) after URI redaction. That is the same pass used on Call-ID and From.

Main 83e6457 already contains that scrub. This PR keeps the deterministic test for the CI input (T:4155550123tel: with called 4155550) and the matching fuzzer seed.

Verification

Local, matching the ci.yml test job. All passed:

  • gofmt -l .
  • go vet ./...
  • go test -race ./...
  • go test -run '^$' -fuzz=FuzzParse -fuzztime=20s ./internal/sipmsg/
  • go test -run '^$' -fuzz=FuzzRedact -fuzztime=20s ./internal/share/
  • go test -run '^$' -fuzz=FuzzCompute -fuzztime=20s ./internal/fingerprint/

GitHub Actions ci on this branch is green, including test.

Open in Web Open in Cursor 

@cursor
cursor Bot force-pushed the cursor/fix-fuzzredact-to-header-df12 branch from f8fcc6b to d849861 Compare September 30, 2026 02:19
@dimondevceo
dimondevceo marked this pull request as ready for review September 30, 2026 02:23
The digit scrub on called-party headers is already on main. This
keeps the CI input T:4155550123tel: as a unit test and a fuzzer seed.

Co-authored-by: DimonDev <dimondevceo@users.noreply.github.com>
@cursor
cursor Bot force-pushed the cursor/fix-fuzzredact-to-header-df12 branch from d849861 to 980fa09 Compare September 30, 2026 02:25
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants