CB-WP-0006 T05: K9's assertion, K11's format, and the AM-11 suites

K11 is implemented: crates/cb-events/src/store.rs, magic + version header,
4-byte little-endian length prefix, append-only. Reimplemented not
assimilated per ADR-0005 §2 — no new dependency, and AM-4a/AM-4b are
unchanged at 246,250 / 317,021 because nothing entered the graph.

The operative clause is "detected", so corruption is tested rather than
assumed: a tail short by one byte, a half-written length prefix, a length
prefix corrupted to claim more than the file holds, foreign magic, and a
future format version are each rejected with a distinct error. A reader
that accepts a truncated tail is worse than no format, because it silently
returns a short history that looks complete.

AM-11 is earned. LogStore has two impls — MemLogStore and FileLogStore —
driven through ONE conformance(). The trait carries raw/set_raw precisely
so the corruption controls live in the shared suite: a format contract
that only one impl enforces is not a contract. The same shape is
retro-fitted to KernelRng, which is what AM-11 actually names: ChaChaRng
and NullRng now pass one suite asserting bounds, draw(1) == 0, determinism
across fresh instances, and shuffle preserving the multiset. They were
previously exercised by two separate tests, which is why "met, narrow" was
never earned and ADR-0005 §4 downgraded it.

K9 gets the assertion it did not have: snapshot at seq N + events N+1..M
must equal the from-genesis fold, hash-compared, on GroundState,
single-seed on purpose — AM-7's probe folds a multi-seed log, which is not
a replay of anything, and that defect is not repeated. Two positive
controls: the log must exceed 50 events, and the mid-log snapshot must
differ from the end state or "apply the remainder" is vacuous.

Proof it works: the exact mutation that SURVIVED in CB-WP-0005 — making
Snapshot::take discard its EventSeq — now fails on the K9 assertion.

AM-11's mutation breaks NullRng::draw to return its bound and the shared
suite fails. That is what M-D4-SWAP claims — either impl substitutable —
and exactly what two separate per-impl tests could never demonstrate.

M-D1-MUT: 7 -> 8 of 14. CB-EV-0001's scoreboard is refreshed: AM-2, AM-5
and AM-9 added, AM-6 moved to enforced, and the headline total corrected
from 4 to 8 — it had gone stale inside the same workplan that produced it.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
tegwick 2026-08-01 10:50:52 +02:00
parent 5f7d9015d9
commit 98c6cd24c3
12 changed files with 638 additions and 19 deletions

View file

@ -53,10 +53,86 @@ impl KernelRng for NullRng {
}
}
/// The AM-11 conformance suite for [`KernelRng`] — **one** suite, driven by
/// every impl.
///
/// Before CB-WP-0006 T05 the pair was exercised by two *separate*,
/// non-shared tests (`chacha_is_deterministic_per_seed` and
/// `null_rng_never_moves_a_shuffle`). M-D4-SWAP is a bool over impls
/// "passing the same conformance suite", so a pair with no shared suite
/// never earned it; ADR-0005 §4 downgraded AM-11 to unmet on exactly that
/// reading.
///
/// The assertions are the properties true of **both** a real CSPRNG and a
/// null draw — determinism, bounds, and shuffle integrity. An impl that
/// violates any of them cannot be substituted for the other, which is what
/// the port claims.
pub fn conformance<R: KernelRng>(label: &str, mut make: impl FnMut() -> R) {
// Bounds. `draw(n)` must land in `0..n` for every impl, or callers
// indexing with it are unsound.
let mut r = make();
for bound in [1u32, 2, 3, 7, 52, 1000] {
for _ in 0..64 {
let v = r.draw(bound);
assert!(
v < bound,
"{label}: draw({bound}) returned {v}, outside 0..{bound}"
);
}
}
// draw(1) has exactly one legal answer.
let mut r = make();
assert_eq!(r.draw(1), 0, "{label}: draw(1) must be 0");
// Determinism: two fresh instances must produce identical sequences.
// This is K5 for ChaCha and trivially true for the null impl — which
// is the point of a shared suite.
let (mut a, mut b) = (make(), make());
let seq_a: Vec<u32> = (0..32).map(|_| a.draw(97)).collect();
let seq_b: Vec<u32> = (0..32).map(|_| b.draw(97)).collect();
assert_eq!(
seq_a, seq_b,
"{label}: two fresh instances must draw identically"
);
// Shuffle preserves the multiset — it may reorder, never invent or
// drop. A shuffle that loses an element would corrupt a deal.
let mut r = make();
let original: Vec<u8> = (0..52).collect();
let mut items = original.clone();
r.shuffle(&mut items);
let mut sorted = items.clone();
sorted.sort_unstable();
assert_eq!(
sorted, original,
"{label}: shuffle must preserve the multiset"
);
// Shuffling is deterministic too, or replay diverges (K8).
let (mut c, mut d) = (make(), make());
let (mut x, mut y) = (original.clone(), original.clone());
c.shuffle(&mut x);
d.shuffle(&mut y);
assert_eq!(x, y, "{label}: shuffle must be deterministic per impl");
}
#[cfg(test)]
mod tests {
use super::*;
/// AM-11: the SAME suite, both impls. Two separate tests are what the
/// pair had before, and why the metric was never earned.
#[test]
fn chacha_passes_the_conformance_suite() {
conformance("ChaChaRng", || ChaChaRng::from_seed(Seed(42)));
}
#[test]
fn null_rng_passes_the_conformance_suite() {
conformance("NullRng", NullRng::default);
}
/// AM-8 seed determinism at the unit level: same seed, same draws.
#[test]
fn chacha_is_deterministic_per_seed() {