Enforce Zhuyuan persona-source epistemic gate
This commit is contained in:
parent
927ab7825d
commit
b0deae2718
30 changed files with 1741 additions and 34 deletions
|
|
@ -0,0 +1,204 @@
|
|||
import assert from "node:assert/strict";
|
||||
import test from "node:test";
|
||||
import {
|
||||
assertControllerDevelopmentBoundary,
|
||||
createTaskEvent,
|
||||
rotateTaskEvent,
|
||||
validatePersonaBindingReceipt,
|
||||
} from "./persona-source-binding-policy.mjs";
|
||||
|
||||
const sha = (letter) => letter.repeat(64);
|
||||
|
||||
function lane() {
|
||||
return {
|
||||
thread_id: "019ff951-f127-72f1-a65d-a3bf0333d95b",
|
||||
development_id: "DEV-20260813-006",
|
||||
persona: "ICE-P-ZY001",
|
||||
controller_persona_id: "ICE-P-ZY001",
|
||||
development_object_ids: ["ICE-GL-ZL-001"],
|
||||
human_anchor: "ICE-GL∞",
|
||||
summary: "repair persona source priority inversion",
|
||||
task_lock: { fingerprint: sha("a") },
|
||||
};
|
||||
}
|
||||
|
||||
function boundFixture() {
|
||||
const current = lane();
|
||||
current.task_event = createTaskEvent({
|
||||
lane: current,
|
||||
intent: "correction",
|
||||
requestSummary: current.summary,
|
||||
openedAt: "2026-08-13T12:58:53.438Z",
|
||||
});
|
||||
const receipt = {
|
||||
schema: "guanghu.codex-preconscious-persona-binding/v1",
|
||||
decision: "BOUND_CURRENT_CARRIER",
|
||||
binding_id: "CODEX-BIND-DEV-006-001",
|
||||
thread_id: current.thread_id,
|
||||
development_id: current.development_id,
|
||||
controller_persona_id: current.controller_persona_id,
|
||||
development_objects: current.development_object_ids,
|
||||
human_anchor: current.human_anchor,
|
||||
task_fingerprint: current.task_lock.fingerprint,
|
||||
task_event_id: current.task_event.task_event_id,
|
||||
checkpoint_sha256: sha("b"),
|
||||
persona_handoff: { state: "NONE", authorized: false },
|
||||
carrier: {
|
||||
host: "codex",
|
||||
thread_id: current.thread_id,
|
||||
development_id: current.development_id,
|
||||
nonce: "carrier-nonce-DEV-006-001",
|
||||
},
|
||||
adapter: {
|
||||
id: "CODEX-PRECONSCIOUS-ENTRY-001",
|
||||
source_sha256: sha("c"),
|
||||
},
|
||||
brain_cycle: {
|
||||
cycle_id: "ZY-CYCLE-000008-test",
|
||||
event_sha256: sha("d"),
|
||||
controller_witness_sha256: sha("e"),
|
||||
completed_cycles_before: 7,
|
||||
completed_cycles_after: 8,
|
||||
witness_decision: "ALLOW_COMMIT",
|
||||
},
|
||||
carrier_consumption: {
|
||||
state: "CURRENT_CODEX_READ_AND_ACCEPTED_BRAIN_CYCLE",
|
||||
required_cycle_id: "ZY-CYCLE-000008-test",
|
||||
required_witness_sha256: sha("e"),
|
||||
},
|
||||
source_hashes: {
|
||||
checkpoint: sha("b"),
|
||||
brain_runtime_contract: sha("f"),
|
||||
living_controller_map: sha("1"),
|
||||
language_world_boundary: sha("2"),
|
||||
},
|
||||
};
|
||||
const binding = {
|
||||
binding_id: receipt.binding_id,
|
||||
receipt_sha256: sha("3"),
|
||||
};
|
||||
const pointer = {
|
||||
thread_id: current.thread_id,
|
||||
development_id: current.development_id,
|
||||
checkpoint_sha256: sha("b"),
|
||||
};
|
||||
return { current, receipt, binding, pointer };
|
||||
}
|
||||
|
||||
test("development object cannot replace the controller persona", () => {
|
||||
assert.throws(
|
||||
() =>
|
||||
assertControllerDevelopmentBoundary({
|
||||
persona: "ICE-GL-ZL-001",
|
||||
controllerPersonaId: "ICE-GL-ZL-001",
|
||||
previousControllerPersonaId: "ICE-P-ZY001",
|
||||
developmentObjectIds: ["ICE-GL-ZL-001"],
|
||||
humanAnchor: "ICE-GL∞",
|
||||
}),
|
||||
/CONTROLLER_PERSONA_IMMUTABLE/,
|
||||
);
|
||||
});
|
||||
|
||||
test("a new task event invalidates but preserves the old binding", () => {
|
||||
const current = lane();
|
||||
current.task_event = createTaskEvent({
|
||||
lane: current,
|
||||
intent: "same-task",
|
||||
requestSummary: "first round",
|
||||
openedAt: "2026-08-13T12:00:00.000Z",
|
||||
});
|
||||
current.persona_source_binding = { binding_id: "BIND-OLD" };
|
||||
const rotated = rotateTaskEvent({
|
||||
lane: current,
|
||||
intent: "correction",
|
||||
requestSummary: "new user correction",
|
||||
openedAt: "2026-08-13T12:01:00.000Z",
|
||||
});
|
||||
assert.equal(rotated.persona_source_binding, null);
|
||||
assert.equal(rotated.task_event.sequence, 2);
|
||||
assert.equal(
|
||||
rotated.persona_source_binding_history[0].state,
|
||||
"STALE_SUPERSEDED_BY_NEW_TASK_EVENT",
|
||||
);
|
||||
});
|
||||
|
||||
test("current event, real adapter source, JD cycle and both pointers are required", () => {
|
||||
const { current, receipt, binding, pointer } = boundFixture();
|
||||
assert.equal(
|
||||
validatePersonaBindingReceipt({
|
||||
lane: current,
|
||||
binding,
|
||||
receipt,
|
||||
actualReceiptSha256: sha("3"),
|
||||
actualCheckpointSha256: sha("b"),
|
||||
actualAdapterSourceSha256: sha("c"),
|
||||
adapterSourcePath: "/runtime/host-adapters/codex-preconscious-entry/adapter.mjs",
|
||||
allowedAdapterRoot: "/runtime/host-adapters/codex-preconscious-entry",
|
||||
pointerEvidence: { by_thread: pointer, by_development: pointer },
|
||||
}),
|
||||
true,
|
||||
);
|
||||
});
|
||||
|
||||
test("an old round receipt cannot be replayed", () => {
|
||||
const { current, receipt, binding, pointer } = boundFixture();
|
||||
current.task_event = createTaskEvent({
|
||||
lane: current,
|
||||
intent: "same-task",
|
||||
requestSummary: "later round",
|
||||
openedAt: "2026-08-13T13:00:00.000Z",
|
||||
});
|
||||
assert.throws(
|
||||
() =>
|
||||
validatePersonaBindingReceipt({
|
||||
lane: current,
|
||||
binding,
|
||||
receipt,
|
||||
actualReceiptSha256: sha("3"),
|
||||
actualCheckpointSha256: sha("b"),
|
||||
actualAdapterSourceSha256: sha("c"),
|
||||
adapterSourcePath: "/runtime/host-adapters/codex-preconscious-entry/adapter.mjs",
|
||||
allowedAdapterRoot: "/runtime/host-adapters/codex-preconscious-entry",
|
||||
pointerEvidence: { by_thread: pointer, by_development: pointer },
|
||||
}),
|
||||
/PERSONA_SOURCE_BINDING_IDENTITY_OR_TASK_MISMATCH/,
|
||||
);
|
||||
});
|
||||
|
||||
test("a forged adapter source hash fails closed", () => {
|
||||
const { current, receipt, binding, pointer } = boundFixture();
|
||||
assert.throws(
|
||||
() =>
|
||||
validatePersonaBindingReceipt({
|
||||
lane: current,
|
||||
binding,
|
||||
receipt,
|
||||
actualReceiptSha256: sha("3"),
|
||||
actualCheckpointSha256: sha("b"),
|
||||
actualAdapterSourceSha256: sha("4"),
|
||||
adapterSourcePath: "/runtime/host-adapters/codex-preconscious-entry/adapter.mjs",
|
||||
allowedAdapterRoot: "/runtime/host-adapters/codex-preconscious-entry",
|
||||
pointerEvidence: { by_thread: pointer, by_development: pointer },
|
||||
}),
|
||||
/PERSONA_SOURCE_ADAPTER_SHA_MISMATCH/,
|
||||
);
|
||||
});
|
||||
|
||||
test("an adapter source outside the uniquely leased persistent root fails closed", () => {
|
||||
const { current, receipt, binding, pointer } = boundFixture();
|
||||
assert.throws(
|
||||
() =>
|
||||
validatePersonaBindingReceipt({
|
||||
lane: current,
|
||||
binding,
|
||||
receipt,
|
||||
actualReceiptSha256: sha("3"),
|
||||
actualCheckpointSha256: sha("b"),
|
||||
actualAdapterSourceSha256: sha("c"),
|
||||
adapterSourcePath: "/private/tmp/adapter.mjs",
|
||||
allowedAdapterRoot: "/runtime/host-adapters/codex-preconscious-entry",
|
||||
pointerEvidence: { by_thread: pointer, by_development: pointer },
|
||||
}),
|
||||
/PERSONA_SOURCE_ADAPTER_SHA_MISMATCH/,
|
||||
);
|
||||
});
|
||||
Loading…
Reference in a new issue