commit 97f1ce38f6e9a513e9942a912b19102477a2e452
parent 19b98b2fef4e37f95b3d052793366607e1c52c0d
Author: triesap <tyson@radroots.org>
Date: Tue, 28 Jul 2026 07:21:35 +0000
event_store: cover visibility oracle failures
- reject ephemeral rows in immutable raw authority
- reject malformed events presented as admitted deletions
- bound deletion cutoffs to the SQLite integer range
- preserve production AST hashes while improving governed coverage
Diffstat:
1 file changed, 85 insertions(+), 0 deletions(-)
diff --git a/crates/event_store/src/nip09/reconciliation_v1/visibility_oracle_v1.rs b/crates/event_store/src/nip09/reconciliation_v1/visibility_oracle_v1.rs
@@ -521,6 +521,91 @@ mod tests {
.expect("admitted deletion request")
}
+ fn reconciled_event(
+ ingest: RadrootsEventIngest,
+ status: RadrootsEventAdmissionStatus,
+ ) -> ReconciledEvent {
+ ReconciledEvent {
+ seq: 1,
+ inserted_at_ms: ingest.observed_at_ms(),
+ verified_event: ingest.verified_event().clone(),
+ admission: super::super::EventAdmission {
+ status,
+ code: None,
+ contract: None,
+ },
+ }
+ }
+
+ #[test]
+ fn raw_snapshot_visibility_oracle_rejects_impossible_raw_authority_v1() {
+ let ephemeral = reconciled_event(
+ signed_ingest(20_001, 1_700_000_000, "ephemeral fixture"),
+ RadrootsEventAdmissionStatus::Unsupported,
+ );
+ assert!(matches!(
+ expected_visibility(&[ephemeral]),
+ Err(RadrootsEventStoreError::RawSourceRebuildStateDrift {
+ kind: RadrootsEventStoreRawSourceRebuildDriftV1::ImmutableRawAuthority,
+ ..
+ })
+ ));
+
+ let malformed_deletion = reconciled_event(
+ signed_ingest(5, 1_700_000_001, "missing deletion targets"),
+ RadrootsEventAdmissionStatus::Admitted,
+ );
+ assert!(matches!(
+ oracle_deletion_requests(&[malformed_deletion]),
+ Err(RadrootsEventStoreError::RawSourceRebuildStateDrift {
+ kind: RadrootsEventStoreRawSourceRebuildDriftV1::DerivedProductStateAuthority,
+ ..
+ })
+ ));
+ }
+
+ #[test]
+ fn raw_snapshot_visibility_oracle_rejects_unrepresentable_cutoff_v1() {
+ let target = signed_ingest_with_tags(
+ 30_402,
+ 1,
+ "{}",
+ vec![vec!["d".to_owned(), "unrepresentable-cutoff".to_owned()]],
+ );
+ let coordinate = format!(
+ "30402:{}:unrepresentable-cutoff",
+ target.event().author_str()
+ );
+ let created_at = u64::try_from(i64::MAX).expect("i64 maximum fits u64") + 1;
+ let keys =
+ Keys::new(SecretKey::from_hex(FIXTURE_SECRET_KEY_HEX).expect("fixture secret key"));
+ let request = EventBuilder::new(Kind::Custom(5), "unrepresentable cutoff")
+ .tags(vec![Tag::custom(
+ TagKind::Custom("a".into()),
+ vec![coordinate],
+ )])
+ .custom_created_at(Timestamp::from_secs(created_at))
+ .sign_with_keys(&keys)
+ .expect("signed cutoff request");
+ let request = RadrootsEventIngest::from_raw_json(
+ serde_json::to_string(&request).expect("cutoff request JSON"),
+ 0,
+ )
+ .expect("verified cutoff request");
+ let events = [
+ reconciled_event(target, RadrootsEventAdmissionStatus::Admitted),
+ reconciled_event(request, RadrootsEventAdmissionStatus::Admitted),
+ ];
+
+ assert!(matches!(
+ expected_visibility(&events),
+ Err(RadrootsEventStoreError::RawSourceRebuildStateDrift {
+ kind: RadrootsEventStoreRawSourceRebuildDriftV1::DerivedProductStateAuthority,
+ ..
+ })
+ ));
+ }
+
#[test]
fn raw_snapshot_visibility_oracle_bounds_high_fan_in_evidence_v1() {
const REQUEST_COUNT: usize = 512;