The broader dataset records useful examples independently of current analyzer coverage. Metadata, acquired source, analysis, generated candidates, and build/test results are separate artifacts with explicit source identities.
The September research amendment defines inclusion and grouping. The metadata inventory records source identities, checksums, source-inferred labels, project splits, and missing tool support. An agent's source review does not constitute either required independent human review.
Keep related fixes and copied source lineages in one split. Reserve entire projects before tuning. zlib is a development example; the existing libxml2 holdout remains unopened for analysis or adapter development.
source-package accepts a local JSON request with these fields:
base: exactpath,source_url, andsha256of the acquired archive.patches: an ordered list withid,path,source_url, andsha256for each patch. An empty list represents the base without added patches.recipe: optionalsource_rootfor an archive with a containing directory.
Paths resolve relative to the request file. The command verifies supplied bytes, extracts a bounded regular-file tree, checks and applies patches in order, and retains original inputs and derived file hashes. Unsupported members, path escapes, failed patches, and limit failures cannot produce a successful package artifact.
uv run tianoshield-propagate source-package /path/package-request.json \
--output /path/new-source-packageThe product includes source-package.json, exact archive and patch bytes,
and the derived tree under materialized/. It does not assign derived files
a downstream Git commit or blob identity. Loading verifies retained evidence
without executing Git. Explicit patch replay uses replay_source_package in
the preparation module. Neither operation executes package source code.
A case request can use mode: SOURCE_PACKAGE. Its preparation parameters
name source_package, exact source_package_id, selected source_path,
and the same upstream Git fix/parent parameters used by repository cases.
The upstream proof and full package evidence travel with the saved case.
uv run tianoshield-propagate case /path/package-case.json \
--output /path/new-case
uv run tianoshield-propagate packet /path/new-case \
--output /path/new-reviewThe analyzer inspects these files and saves observations. The current sealed
classifier/generator contract still requires Git target provenance. Package
cases stop with SOURCE_PACKAGE_CLASSIFIER_UNSUPPORTED after analysis,
preserving results and the precise missing capability. They are not relabeled
as committed fixtures or assigned fabricated Git IDs.
The parser recovers function boundaries from balanced top-level source regions
when a file parse error hides a definition. Tree-sitter parses the exact original
byte ranges; macros are not removed or expanded. Original errors remain visible,
and recovered definitions always have PARTIAL coverage. K&R parameters retain
their declared types and signature order. Missing parameter types and ambiguous
unnamed types retain incomplete coverage. Callback parameter names do not enter
the outer function's parameter scope or normalization.
The three zlib development package states now complete analysis. Against the
initial fix, the base matches VULNERABLE, the initial fix matches
ALREADY_PATCHED, and the corrected series remains UNCERTAIN. All three have
partial function coverage and stop before sealed classifier evidence or
generation. The initial fix's known NULL-header regression also demonstrates
why a patch match cannot replace build and regression evidence.
Review diagnostics distinguish complete semantic NOT_APPLICABLE observations
from partial parsing, even when both have an INCOMPLETE summary. Whole-file
coverage remains separate from coverage of the selected function.
validate-build runs an explicit local recipe. It binds each variant to an
actual package product and source-tree digest, and records tool identities,
fixed command arguments, limits, expectations, and logs. Source-corpus
metadata never becomes an executable recipe automatically.
uv run tianoshield-propagate validate-build /path/recipe.json \
--source pre=/path/pre-package/materialized \
--source-package pre=/path/pre-package \
--source post=/path/post-package/materialized \
--source-package post=/path/post-package \
--output /path/new-build-resultSupport files resolve from the recipe directory unless --auxiliary-root is
supplied. Commands run in disposable copies with bounded execution and logs.
This is local process isolation, not a security sandbox. Use known development
source and a reviewed recipe.
Compile and test outcomes are independent. A failing test on the vulnerable
variant can be an expected negative control; its recorded outcome remains
FAIL. The result separately states whether expectations were met. A failed
prerequisite leaves dependent steps skipped.
Build/test evidence does not rewrite an incomplete analysis result or supply a propagation label. Passing selected tests supports only the tested behavior. Retained build verification does not rerun compilers or tests.
Retain unknown and unsupported examples, report source acquisition separately from execution, and count related states as dependent cases. Only the subset with a reviewed downstream relationship can measure propagation. Behavioral regression checks and upstream patch analysis have separate denominators.