@@ -33,23 +33,38 @@ Execute the patching and verification stage as follows:
3333
34342 . ** Generate and Apply Minimal Patches:** For each reproduced security flaw:
3535
36+ - ** Target Agnosticism (Binaries vs Source):** If the target is source
37+ code, proceed with generating and applying a code patch as described
38+ below. If the target is a compiled binary or firmware blob without
39+ source code available, ** do not attempt to modify the binary or write
40+ binary patching scripts** . Instead, skip the file
41+ backup/modification/diff steps and generate a general, high-level
42+ recommendation for how this issue could be mitigated in a production
43+ environment without requiring deep technical depth. Output this
44+ mitigation string in place of the ` patch_diff ` field.
45+
3646 - * Optional Parallel Trajectory Search:* If your framework supports
3747 subagents, you may spawn multiple concurrent subagents to design diverse
3848 patch implementations. Test all generated patches that successfully
3949 secure the code without breaking standard functionality, and select the
4050 * best* patch (e.g., the most minimal, readable, and idiomatic fix)
4151 rather than just the first one that works.
52+
4253 - Read the original flawed file to grasp function dependencies and
4354 structures.
55+
4456 - Design a minimal, correct patch to mitigate the security flaw (e.g.
4557 adding bound checks, validating sizes, inserting NUL-terminators)
4658 without breaking other features.
59+
4760 - ** Backup First:** Create a copy of the target file appending ` .bak ` to
4861 its filename to allow robust recovery in case the patch breaks
4962 compilation or functionality.
63+
5064 - Replace the file content with your generated patched code.
5165
52- 3 . ** Post-Patch Verification Run:** To confirm the patch works, re-run the
66+ 3 . ** Post-Patch Verification Run:** * (Skip this step for binary-only targets
67+ where no code patch was applied)* . To confirm the patch works, re-run the
5368 reproducer script inside your isolated execution environment. Use the exact
5469 ` "repro_file_path" ` and ` "run_command" ` from the reproduction entry to
5570 verify the patch.
@@ -69,9 +84,10 @@ Execute the patching and verification stage as follows:
6984 bug, or if your re-attack successfully bypasses your patch, the patch is
7085 insufficient. Re-evaluate and adapt your fix.
7186
72- 4 . ** Extract Patch and Restore Codebase:** Do not leave the codebase in an
73- altered state. Once you have a final outcome (either ` VERIFIED_SECURE ` or
74- you have exhausted your retries), you must:
87+ 4 . ** Extract Patch and Restore Codebase:** * (Skip this step for binary-only
88+ targets)* . Do not leave the codebase in an altered state. Once you have a
89+ final outcome (either ` VERIFIED_SECURE ` or you have exhausted your retries),
90+ you must:
7591
7692 - If successful, generate a unified diff (e.g., ` diff -u file.bak file ` )
7793 representing your exact changes.
0 commit comments