test(conformance): the g4 fixture holds what a redacted android trace holds

Android reports no secure fact for any field, so every InputText it records
writes the redaction placeholder rather than the typed value. The fixture still
carried the real value, which is the only reason the gate reported itself as
catching the doubling. Two more fixtures come with it: a repeated-character
corpus value that reads as its own doubling and must not fail, and a backend
that does record the typed value.

Red at this commit: G4 reports PASS on a doubled field it cannot see.
This commit is contained in:
pj committed 2026-08-18 20:07:39 +05:30
1 parent f7b90a9886
commit f631415cb6
15 files changed
+85 -23

No files matched your search

+5 -1
View File
@@ -493,8 +493,12 @@ self_test() {
assert "G4 pass no doubling" PASS \
"$(gate_no_doubled_text "${testdata}/pass" && echo PASS || echo FAIL)"
assert "G4 doubled text caught" FAIL \
assert "G4 doubled text caught with the typed value redacted" FAIL \
"$(gate_no_doubled_text "${testdata}/g4-doubled-text" && echo PASS || echo FAIL)"
assert "G4 repeated character is not doubling" PASS \
"$(gate_no_doubled_text "${testdata}/g4-repeated-character" && echo PASS || echo FAIL)"
assert "G4 doubled text caught from the recorded value" FAIL \
"$(gate_no_doubled_text "${testdata}/g4-recorded-text" && echo PASS || echo FAIL)"
assert "seeds default to one distinct value per run" "101 202 303 404 505" \
"$(select_seeds 5 "101 202 303 404 505" >/dev/null 2>&1 && echo "${seed_list[*]}")"