54. Fuzzing the source input

Level: advanced · Reading time: 20 min · Prerequisite: book/chapters/53-property-based-testing-parser.html · Track: supplemental · Maturity: draft · Last review: 2026-05-09

TL;DR (5 lines)

  • Tests are evidence of a specific claim.
  • Different layers prove different things.
  • A compact flow is enough to teach testing structure.
  • Invalid paths deserve explicit fixtures.
  • The chapter should teach proof design, not ritual.

Frequent mistakes

  • Treating every test as the same kind of evidence.
  • Adding giant scenarios where a small invariant test would be stronger.
  • Explaining tooling before explaining the proof obligation.

Prerequisites: book/chapters/53-property-based-testing-parser.html. See also: book/chapters/53-property-based-testing-parser.html, book/chapters/27-grammar.html, book/chapters/31-build-errors.html.

Concrete Problem

Testing chapters often become lists of test names instead of explanations of what evidence each layer should provide.

Red Thread (Single Project)

One feature is checked by a unit-level invariant, a scenario-level flow, and an invalid-path assertion.

For what

This chapter helps the reader design tests as evidence, not ceremony.

Work in this chapter

You will inspect one tested flow, then classify which part belongs to unit, scenario, regression, or generation-oriented validation.

Coherent example

space demo/tests

proc classify_score(x: int) -> int {
  if x < 0 { give 11 }
  if x > 100 { give 12 }
  give 0
}

export *

Complete examples

Each block below is a complete reading unit with its own boundary, data shape, and observable result.

Primary coherent example

This is the compact chapter anchor used by the surrounding explanation.

space demo/tests

proc classify_score(x: int) -> int {
  if x < 0 { give 11 }
  if x > 100 { give 12 }
  give 0
}

export *

Invariant target

This example exposes one behavior that a unit test can protect.

space examples/testing/invariant

proc bounded(value: int) -> int {
  if value < 0 { give 0 }
  if value > 10 { give 10 }
  give value
}

proc main(args: list[string]) -> int {
  give bounded(8)
}

export *

Scenario target

This complete flow gives scenario tests a stable entry path.

space examples/testing/scenario

proc prepare(name: string) -> int {
  if name == "" { give 11 }
  give 0
}

proc run(name: string) -> int {
  let status: int = prepare(name)
  if status != 0 { give status }
  give 0
}

proc main(args: list[string]) -> int {
  give run("demo")
}

export *

Immediate work for this chapter

  • Name the evidence each test layer provides.
  • Keep one unit-level invariant and one scenario-level path visible.
  • Use invalid fixtures to protect known failure contracts.
  • Keep the first code block complete and aligned with current Vitte docs syntax.
  • Keep the invalid block focused on one broken contract only.
  • Replace generic prose with one concrete rule visible in the code.
  • Keep every example small enough to review from top to bottom.

Chapter override: 54-source-fuzzing.html

Dedicated problem

54. Fuzzing the source input needs a concrete production-grade anchor around invariant, scenario, and regression fixture. The page should keep the examples, diagnostics, and review rules tied to that exact boundary instead of drifting back to generic tutorial prose.

Specific complete examples

54. Fuzzing the source input chapter anchor

The primary example is promoted here as the first chapter-specific production reading unit.

space demo/tests

proc classify_score(x: int) -> int {
  if x < 0 { give 11 }
  if x > 100 { give 12 }
  give 0
}

export *

Invariant target

This example exposes one behavior that a unit test can protect.

space examples/testing/invariant

proc bounded(value: int) -> int {
  if value < 0 { give 0 }
  if value > 10 { give 10 }
  give value
}

proc main(args: list[string]) -> int {
  give bounded(8)
}

export *

Scenario target

This complete flow gives scenario tests a stable entry path.

space examples/testing/scenario

proc prepare(name: string) -> int {
  if name == "" { give 11 }
  give 0
}

proc run(name: string) -> int {
  let status: int = prepare(name)
  if status != 0 { give status }
  give 0
}

proc main(args: list[string]) -> int {
  give run("demo")
}

export *

Risks and diagnostics

RiskDiagnostic signalAction
Boundary driftThe chapter loses sight of invariant, scenario, and regression fixture.Restate the boundary beside the first code block and every invalid case.
Generic proseA paragraph would still be true in another chapter.Replace it with a code-specific rule from this page.
Weak diagnosticThe failure does not point back to the chapter contract.Reduce the invalid case until one failure explains the rule.

Review checklist

  • The first example is complete and aligned with Vitte docs syntax.
  • The production section names where this construct belongs in real code.
  • The risk table connects each failure to a diagnostic or review action.
  • The avoid list rejects broad misuse without adding quiz-like prompts.

Production use

  • Use this chapter when a code review needs to preserve invariant, scenario, and regression fixture.
  • Keep examples small enough to copy into fixtures or docs smoke tests.
  • Treat the invalid case as regression material for future docs checks.

What to avoid

  • Do not add a second topic that hides the chapter's main contract.
  • Do not expand examples by adding unrelated subsystems.
  • Do not rely on prose when a small Vitte block can show the rule.

Global explanation

Testing pages should explain what each test proves. A useful chapter distinguishes local invariants, end-to-end scenarios, regression proof, and failure-focused fixtures without collapsing them into one vague category.

Invalid case

proc bad_test_surface(x: int) -> int {
  if x { give 11 }
  give 0
}

This invalid case is intentionally small. It exists to isolate the contract failure that the chapter is trying to teach.

Common pitfalls

  • Treating every test as the same kind of evidence.
  • Adding giant scenarios where a small invariant test would be stronger.
  • Explaining tooling before explaining the proof obligation.

Short exercise

Take the example and write one invariant it needs, one scenario it needs, and one invalid-path check it needs.

Summary in 5 points

  1. Tests are evidence of a specific claim.
  2. Different layers prove different things.
  3. A compact flow is enough to teach testing structure.
  4. Invalid paths deserve explicit fixtures.
  5. The chapter should teach proof design, not ritual.

See also

Next best action

Extend the coherent example by one small, justified step and keep the same contract visible from input to output.

Chapter deep dive

54. Fuzzing the source input shows what evidence each test is supposed to provide. The chapter is written for a reader writing tests that prove a claim.

The practical boundary is: invariant, scenario, and regression fixture. Keep that boundary in view while reading the example, the invalid case, and the exercise.

Role in the learning path

Testing chapters often become lists of test names instead of explanations of what evidence each layer should provide.

One feature is checked by a unit-level invariant, a scenario-level flow, and an invalid-path assertion.

This chapter helps the reader design tests as evidence, not ceremony.

Profile-specific deep dive

Evidence layers

  • Unit tests protect small invariants.
  • Scenario tests protect user-visible flows.
  • Regression tests protect previously broken contracts.

Fixture design

  • Keep valid and invalid fixtures close to the code shape they prove.
  • Name the claim before naming the test file.
  • Avoid giant fixtures when a smaller one proves the same claim.

Reading the valid example

  1. space demo/tests: names the ownership boundary before any behavior appears.
  2. proc classify_score(x: int) -> int {: states the callable contract: inputs first, result shape last.
  3. if x < 0 { give 11 }: guards a failure or edge case before the nominal result.
  4. if x > 100 { give 12 }: guards a failure or edge case before the nominal result.
  5. give 0: ends the local path with an explicit result.
  6. }: is a behavior that should map to a test claim.
  7. export *: is a behavior that should map to a test claim.

Lesson from the invalid example

  1. proc bad_test_surface(x: int) -> int {: this line helps isolate the failure because it states the callable contract: inputs first, result shape last.
  2. if x { give 11 }: this line helps isolate the failure because it guards a failure or edge case before the nominal result.
  3. give 0: this line helps isolate the failure because it ends the local path with an explicit result.
  4. }: this line helps isolate the failure because it is a behavior that should map to a test claim.

Engineering decisions to preserve

  • Name the boundary before changing code: Tests are evidence of a specific claim.
  • Keep the smallest example executable: Different layers prove different things.
  • Make the invalid path explain one failure only: A compact flow is enough to teach testing structure.
  • Prefer a visible contract over an implied convention: Invalid paths deserve explicit fixtures.
  • Leave a review anchor that another maintainer can verify: The chapter should teach proof design, not ritual.

Context-specific review criteria

  • The page makes the invariant, scenario, and regression fixture boundary visible before the first code block.
  • The intended reader, a reader writing tests that prove a claim, can follow the valid example through named contracts instead of memorized tokens.
  • The invalid example fails for the same reason the prose discusses.
  • The exercise extends the same contract instead of introducing an unrelated concept.
  • The next chapter can reuse the vocabulary introduced here without redefining it.
  • The chapter stays specific enough that its title materially changes the meaning of the page.
  • Every warning connects to a concrete code shape.
  • The summary leaves one durable engineering rule behind.

Contract matrix

ConcernChapter ruleEvidence to keep
OwnershipCode belongs behind the boundary named by the chapter.The chapter keeps ownership visible through invariant, scenario, and regression fixture.
Input contractThe procedure receives a shape that is named before branching.The valid example names the accepted shape before branching.
Nominal pathThe clean path remains readable without hidden state.The successful result can be found without reading hidden state.
Failure pathThe invalid case isolates one failure reason.The broken example has one main reason to fail.
NamingNames explain the domain rather than only the mechanism.Names remain tied to the chapter goal.
TypesTypes remove ambiguity from values and results.Fields and return values carry domain meaning.
Control flowBranches stay traceable from guard to result.Guards appear before the result they protect.
Module boundaryThe public surface stays smaller than implementation detail.The public surface remains smaller than the implementation detail.
Diagnostic valueThe failure path points back to the exact contract.The invalid example points back to the exact contract.
Test valueRegression evidence covers one passing path and one failing path.One passing case and one failing case cover the lesson.
Refactor valueImplementation cleanup preserves the result shape.The result shape stays stable during local cleanup.
Publication valueThe chapter leaves one concrete engineering rule.The chapter leaves one concrete engineering rule.

Rewrite path for this chapter

  1. Rewrite the opening paragraph so it names invariant, scenario, and regression fixture before naming syntax.
  2. Keep the valid example small enough that the full contract fits on screen.
  3. Move any broad claim back to a specific line in the example.
  4. Preserve one invalid case that fails for the chapter's main reason.
  5. Add one sentence explaining why the invalid case is not a random error.
  6. Make every pitfall actionable by naming the code shape it damages.
  7. Keep the exercise inside the same domain as the example.
  8. Avoid introducing a second unrelated project just to show variety.
  9. Use the summary to restate the chapter rule, not the table of contents.
  10. Check that the next chapter can build on this vocabulary.
  11. Remove any sentence that would still be true in every other chapter.
  12. Keep the last action small, local, and testable.

Diagnostic anchors

  • The first inspected line is the one that declares the chapter's main contract.
  • The central type, field, procedure, or branch carries the chapter's main idea.
  • The invalid example includes a sentence-level explanation of its failure.
  • Refactors preserve the detail that would otherwise mislead a future reader.
  • The behavior that must stay stable is named before implementation changes begin.
  • Vague names are replaced before they become review friction.
  • Regression coverage protects the chapter's main contract.
  • Implementation details stay out of public API unless the chapter explicitly teaches that surface.
  • Beginner-facing diagnostics point to the contract, not to a random syntax detail.
  • The next chapter can assume one clearly named concept from this page.

When extending this chapter

  • Extend toward a reader writing tests that prove a claim, not toward a broader catalog of features.
  • Add a second example only if it sharpens the same contract.
  • Prefer a small variant over a new subsystem.
  • Keep prose close to code; every abstract claim should point to a visible shape.
  • Do not hide a new concept in the exercise.
  • If a paragraph explains policy, add the concrete code boundary it protects.
  • If a paragraph explains syntax, add the semantic reason the syntax matters.
  • If a paragraph explains architecture, identify the owner of each boundary.
  • If a paragraph explains failure, keep the failing line close to the explanation.
  • Stop expanding when the chapter has one complete, testable lesson.

Failure modes to avoid

  • Treating every test as the same kind of evidence.
  • Adding giant scenarios where a small invariant test would be stronger.
  • Explaining tooling before explaining the proof obligation.

Practice scenario

Start from the coherent example in 54. Fuzzing the source input. Change one identifier, one guard, and one returned value. After each change, write down whether the public contract is still the same contract or a new one.

If the contract changed, update the type or result shape first. If only the implementation changed, keep the external name stable and add one regression note explaining what should not change again.

Before moving on

  • You can state the chapter role: shows what evidence each test is supposed to provide.
  • You can point to the main boundary: invariant, scenario, and regression fixture.
  • You can connect the invalid case to the problem statement: Testing chapters often become lists of test names instead of explanations of what evidence each layer should provide.
  • You can perform the exercise: Take the example and write one invariant it needs, one scenario it needs, and one invalid-path check it needs.