lib

Core libraries for Radroots
git clone https://radroots.dev/git/lib.git
Log | Files | Refs | README

commit 97f1ce38f6e9a513e9942a912b19102477a2e452
parent 19b98b2fef4e37f95b3d052793366607e1c52c0d
Author: triesap <tyson@radroots.org>
Date:   Tue, 28 Jul 2026 07:21:35 +0000

event_store: cover visibility oracle failures

- reject ephemeral rows in immutable raw authority
- reject malformed events presented as admitted deletions
- bound deletion cutoffs to the SQLite integer range
- preserve production AST hashes while improving governed coverage

Diffstat:
Mcrates/event_store/src/nip09/reconciliation_v1/visibility_oracle_v1.rs | 85+++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
1 file changed, 85 insertions(+), 0 deletions(-)

diff --git a/crates/event_store/src/nip09/reconciliation_v1/visibility_oracle_v1.rs b/crates/event_store/src/nip09/reconciliation_v1/visibility_oracle_v1.rs @@ -521,6 +521,91 @@ mod tests { .expect("admitted deletion request") } + fn reconciled_event( + ingest: RadrootsEventIngest, + status: RadrootsEventAdmissionStatus, + ) -> ReconciledEvent { + ReconciledEvent { + seq: 1, + inserted_at_ms: ingest.observed_at_ms(), + verified_event: ingest.verified_event().clone(), + admission: super::super::EventAdmission { + status, + code: None, + contract: None, + }, + } + } + + #[test] + fn raw_snapshot_visibility_oracle_rejects_impossible_raw_authority_v1() { + let ephemeral = reconciled_event( + signed_ingest(20_001, 1_700_000_000, "ephemeral fixture"), + RadrootsEventAdmissionStatus::Unsupported, + ); + assert!(matches!( + expected_visibility(&[ephemeral]), + Err(RadrootsEventStoreError::RawSourceRebuildStateDrift { + kind: RadrootsEventStoreRawSourceRebuildDriftV1::ImmutableRawAuthority, + .. + }) + )); + + let malformed_deletion = reconciled_event( + signed_ingest(5, 1_700_000_001, "missing deletion targets"), + RadrootsEventAdmissionStatus::Admitted, + ); + assert!(matches!( + oracle_deletion_requests(&[malformed_deletion]), + Err(RadrootsEventStoreError::RawSourceRebuildStateDrift { + kind: RadrootsEventStoreRawSourceRebuildDriftV1::DerivedProductStateAuthority, + .. + }) + )); + } + + #[test] + fn raw_snapshot_visibility_oracle_rejects_unrepresentable_cutoff_v1() { + let target = signed_ingest_with_tags( + 30_402, + 1, + "{}", + vec![vec!["d".to_owned(), "unrepresentable-cutoff".to_owned()]], + ); + let coordinate = format!( + "30402:{}:unrepresentable-cutoff", + target.event().author_str() + ); + let created_at = u64::try_from(i64::MAX).expect("i64 maximum fits u64") + 1; + let keys = + Keys::new(SecretKey::from_hex(FIXTURE_SECRET_KEY_HEX).expect("fixture secret key")); + let request = EventBuilder::new(Kind::Custom(5), "unrepresentable cutoff") + .tags(vec![Tag::custom( + TagKind::Custom("a".into()), + vec![coordinate], + )]) + .custom_created_at(Timestamp::from_secs(created_at)) + .sign_with_keys(&keys) + .expect("signed cutoff request"); + let request = RadrootsEventIngest::from_raw_json( + serde_json::to_string(&request).expect("cutoff request JSON"), + 0, + ) + .expect("verified cutoff request"); + let events = [ + reconciled_event(target, RadrootsEventAdmissionStatus::Admitted), + reconciled_event(request, RadrootsEventAdmissionStatus::Admitted), + ]; + + assert!(matches!( + expected_visibility(&events), + Err(RadrootsEventStoreError::RawSourceRebuildStateDrift { + kind: RadrootsEventStoreRawSourceRebuildDriftV1::DerivedProductStateAuthority, + .. + }) + )); + } + #[test] fn raw_snapshot_visibility_oracle_bounds_high_fan_in_evidence_v1() { const REQUEST_COUNT: usize = 512;