Adversarial suite for AUTO mode (#104) - #106
Merged
Merged
Conversation
…p visibility (#104) AUTO is the default mode (#67); these pin its boundary semantics: - Exact-match authority, parametrized: target/scope/task mismatch or an expired/revoked standing grant derives nothing and creates no capability rows; an unavailable action fails louder — WriteForbidden from the mode gate before any grant is consulted. - The standing marker is not a wildcard: it lives only on the GRANT (empty hash); consuming a standing grant id directly misses, the derived child binds the payload's real digest, and a mutated payload cannot ride it. - A capability derived before a scope edit never executes after it (grants die with the scope change; the flow refuses). - Quota day boundary: check before midnight + consume after lands in the new day; exhaustion blocks today and recovers tomorrow without a restart (FakeClock across midnights). - Grant-less skips are recorded exactly once — a broken authorize path is diagnosable from the log, never silent. One expectation correction vs the issue text: action mismatch raises WriteForbidden (mode gate) rather than returning None — stricter, kept. 718 tests pass; demo 8/8.
Closed
8 tasks done
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Implements #104. AUTO has been the default since #67; these 10 tests pin the boundary semantics the gated suite doesn't: parametrized exact-match authority (target/scope/task/expired/revoked derive nothing, zero capability rows), the standing marker's non-wildcardness (it lives only on grants; derived children bind real payload digests; mutated payloads cannot ride them), scope-change killing derived-but-unexecuted capabilities, quota day-boundary accounting with next-day recovery, and once-only visibility of grant-less skips.
One honest expectation correction vs the issue text: an action mismatch raises
WriteForbiddenfrom the mode gate rather than returning None — stricter than proposed, so it was kept and documented in the test.718 tests pass (+10), demo 8/8.