OpenAPI Repair — synthetic reproducibility pack v1 Checked 6 October 2026 Purpose Nine small synthetic cases expose specific checker behavior. These are maintainer-run checks that you can replay; they are not independent certification, a full conformance suite, an AWS import test, or evidence of production security. The target is the browser-local checker, not the separately hosted ChatGPT plugin. No customer API definitions, credentials, or implementation source are included. Replay in the browser Before testing, choose No thanks in the optional usage-count prompt, or Turn off if counts are on. Downloaded synthetic fixtures use the file-input path; turning counts off keeps replay tests out of ordinary usage totals. 1. Open https://openapi-repair.pages.dev/ and choose a case's .input.json or .input.yaml file. Use the input file, not its .expected.json report. 2. Compare each finding's title, severity and Source pointer with the diagnosis in the matching .expected.json. Expand findings or download the full report. The UI may sort fixable findings first; compare findings by ruleId and path, not row order. An empty JSON Pointer means the document root. 3. For the three cases with preview.available=true, open Review change, select the inherited-security copies and choose Preview selected change. Inspect the exact patch and download the reviewed candidate only if you approve it. 4. Compare the candidate with the matching .preview.json or .preview.yaml. Compare parsed values and the exact bytes. Byte hashes refer to UTF-8 files including their newline; changing line endings or formatting changes a hash. 5. Load the downloaded candidate again: no further security-copy repair should be available. This checks idempotence, not deployment correctness. 6. In the six cases without a preview, expect the documented findings or no findings, and no eligible security-copy repair. No candidate is supplied. Integrity manifest.json lists SHA-256 hashes for every input, expected report and candidate. SHA256SUMS also covers this README and the manifest. In an extracted folder: Linux: sha256sum -c SHA256SUMS macOS: shasum -a 256 -c SHA256SUMS Hashes establish the expected bytes, not the correctness of those expectations. How these results were checked Each synthetic input was analyzed twice through the existing worker handler in a local test harness and its pinned OpenAPI 3.0 structure validator. Eligible previews were computed twice; results were compared. Independent assertions checked exact security copying, unchanged root/explicit overrides, no invented operations, rejection categories, and refusal of a second repair. A fetch test double recorded no calls during these worker executions. The harness and implementation are not in this pack. The engine fingerprint in the manifest identifies the tested source combination; it is not a public-source release or an independently verifiable source attestation. Limits of that evidence The network assertion covers these handler executions, not every browser action. Actual browser Worker execution and mobile rendering were not tested in this run. The website still loads assets; its separately disclosed optional usage-count feature is outside this fixture test. The website does not upload specification contents. The ChatGPT plugin processes supplied definitions on its server and has different limits; these results do not certify that plugin. No AWS import, deployment, IAM, authorizer, backend integration, quota, or runtime permission test was performed. A clean result does not prove AWS compatibility or correct authorization. HTTP APIs, WebSocket APIs, Swagger 2.0 and OpenAPI 3.1+ are not supported targets for repair. See the live /limitations/ and /privacy/. Reporting a mismatch Share the case ID, pack version, expected finding and observed difference. Do not send credentials or a production/customer definition. Start with the unchanged synthetic case. A reproducible mismatch is useful evidence; no third-party evaluation or testimonial is claimed here.