OpenAPI Repair — synthetic reproducibility pack v1
Checked 6 October 2026

Purpose
Nine small synthetic cases expose specific checker behavior. These are
maintainer-run checks that you can replay; they are not independent certification,
a full conformance suite, an AWS import test, or evidence of production security.
The target is the browser-local checker, not the separately hosted ChatGPT plugin.
No customer API definitions, credentials, or implementation source are included.

Replay in the browser
Before testing, choose No thanks in the optional usage-count prompt, or Turn off
if counts are on. Downloaded synthetic fixtures use the file-input path; turning
counts off keeps replay tests out of ordinary usage totals.
1. Open https://openapi-repair.pages.dev/ and choose a case's .input.json or
   .input.yaml file. Use the input file, not its .expected.json report.
2. Compare each finding's title, severity and Source pointer with the diagnosis
   in the matching .expected.json. Expand findings or download the full report.
   The UI may sort fixable findings first; compare findings by ruleId and path,
   not row order. An empty JSON Pointer means the document root.
3. For the three cases with preview.available=true, open Review change, select
   the inherited-security copies and choose Preview selected change. Inspect
   the exact patch and download the reviewed candidate only if you approve it.
4. Compare the candidate with the matching .preview.json or .preview.yaml.
   Compare parsed values and the exact bytes. Byte hashes refer to UTF-8 files
   including their newline; changing line endings or formatting changes a hash.
5. Load the downloaded candidate again: no further security-copy repair should
   be available. This checks idempotence, not deployment correctness.
6. In the six cases without a preview, expect the documented findings or no
   findings, and no eligible security-copy repair. No candidate is supplied.

Integrity
manifest.json lists SHA-256 hashes for every input, expected report and candidate.
SHA256SUMS also covers this README and the manifest. In an extracted folder:
  Linux: sha256sum -c SHA256SUMS
  macOS: shasum -a 256 -c SHA256SUMS
Hashes establish the expected bytes, not the correctness of those expectations.

How these results were checked
Each synthetic input was analyzed twice through the existing worker handler in a local test harness and its
pinned OpenAPI 3.0 structure validator. Eligible previews were computed twice;
results were compared. Independent assertions checked exact security copying,
unchanged root/explicit overrides, no invented operations, rejection categories,
and refusal of a second repair. A fetch test double recorded no calls during
these worker executions. The harness and implementation are not in this pack.
The engine fingerprint in the manifest identifies the tested source combination;
it is not a public-source release or an independently verifiable source attestation.

Limits of that evidence
The network assertion covers these handler executions, not every browser action.
Actual browser Worker execution and mobile rendering were not tested in this run.
The website still loads assets; its separately disclosed optional usage-count
feature is outside this fixture test. The website does not upload specification
contents. The ChatGPT plugin processes supplied definitions on its server and
has different limits; these results do not certify that plugin.
No AWS import, deployment, IAM, authorizer, backend integration, quota, or runtime
permission test was performed. A clean result does not prove AWS compatibility
or correct authorization. HTTP APIs, WebSocket APIs, Swagger 2.0 and OpenAPI 3.1+
are not supported targets for repair. See the live /limitations/ and /privacy/.

Reporting a mismatch
Share the case ID, pack version, expected finding and observed difference.
Do not send credentials or a production/customer definition. Start with the
unchanged synthetic case. A reproducible mismatch is useful evidence; no
third-party evaluation or testimonial is claimed here.
