services_hardening_reconciliation_replay_contract.rs (4110B)
1 #![forbid(unsafe_code)] 2 3 use rhi::RHI_RECONCILIATION_REPLAY_CONTRACT_VERSION; 4 use serde_json::json; 5 6 const CONTRACT: &str = 7 include_str!("../contracts/services_hardening/reconciliation_replay.v1.json"); 8 const ROOT: &str = include_str!("../src/lib.rs"); 9 const SOURCE: &str = include_str!("../src/reconciliation_replay.rs"); 10 const README: &str = include_str!("../README"); 11 12 #[test] 13 fn machine_contract_freezes_the_complete_step_189_boundary() { 14 let contract: serde_json::Value = serde_json::from_str(CONTRACT).expect("contract"); 15 assert_eq!(contract["schema"], "radroots.rhi.reconciliation-replay"); 16 assert_eq!(contract["schema_version"], 1); 17 assert_eq!( 18 contract["contract_version"], 19 RHI_RECONCILIATION_REPLAY_CONTRACT_VERSION 20 ); 21 assert_eq!(contract["state_schema_version"], 5); 22 assert_eq!( 23 contract["replay_identity"]["domain"], 24 "radroots.rhi.reconciliation_source_replay.v1\\0" 25 ); 26 assert_eq!( 27 contract["replay_identity"]["exact_vector"]["replay_id_hex"], 28 "2490a2e9a6e85051e92f6c2fc2ff7e98a1367afd6c26f8625eb421cd2ab30c68" 29 ); 30 assert_eq!( 31 contract["cursor"]["tuple"], 32 json!(["event_authored_unix_seconds", "verified_event_id"]) 33 ); 34 assert_eq!(contract["cursor"]["equal_timestamp_safe"], true); 35 assert_eq!( 36 contract["cursor"]["input"], 37 "sealed_step_190_committed_cursor_evidence" 38 ); 39 assert_eq!( 40 contract["cursor"]["scope"], 41 json!([ 42 "source_id", 43 "trade_id", 44 "evidence_policy_digest", 45 "selector_digest" 46 ]) 47 ); 48 assert_eq!( 49 contract["cursor"]["eligible_only_for"], 50 "complete_and_strictly_after_prior_cursor" 51 ); 52 assert_eq!( 53 contract["inventory"]["signed_event_identity"], 54 json!(["verified_event_id", "verified_signature"]) 55 ); 56 assert_eq!( 57 contract["inventory"]["first_provenance"], 58 "earliest_injected_observation_time_retained" 59 ); 60 assert_eq!(contract["effects"]["sqlite"], false); 61 assert_eq!(contract["effects"]["source_or_relay"], false); 62 assert_eq!(contract["effects"]["ambient_clock"], false); 63 assert_eq!(contract["effects"]["ambient_entropy"], false); 64 assert_eq!( 65 contract["deferred"], 66 json!([ 67 "source_execution", 68 "durable_source_result_commit", 69 "durable_scope_revalidation", 70 "checkpoint_advance", 71 "manifest", 72 "reducer", 73 "attestation", 74 "publication" 75 ]) 76 ); 77 } 78 79 #[test] 80 fn replay_model_is_private_bounded_pure_and_documented() { 81 assert!(ROOT.contains("mod reconciliation_replay;")); 82 assert!(!ROOT.contains("pub mod reconciliation_replay;")); 83 for required in [ 84 "RhiReconciliationSourceReplayPlan", 85 "RhiReconciliationSourceReplay", 86 "RhiReconciliationSourceCursorEvidence", 87 "RhiReconciliationReplayError", 88 ] { 89 assert!(ROOT.contains(required), "root API is missing {required}"); 90 } 91 for required in [ 92 ".take(maximum_events.saturating_add(1))", 93 "saturating_sub(overlap_seconds)", 94 "cursor_scope_matches(", 95 "fn eligible_cursor(", 96 "RhiTradeSourceCompletion::Complete", 97 "RhiReconciliationReplayErrorKind::MutationConflict", 98 "RhiReconciliationReplayErrorKind::SignedEventConflict", 99 ] { 100 assert!( 101 SOURCE.contains(required), 102 "replay boundary is missing {required}" 103 ); 104 } 105 for forbidden in [ 106 "sqlx::", 107 "std::fs", 108 "std::net", 109 "tokio::", 110 "SystemTime", 111 "thread_rng", 112 "OsRng", 113 "pub fn cursor_evidence", 114 ] { 115 assert!( 116 !SOURCE.contains(forbidden), 117 "replay model gained deferred authority {forbidden}" 118 ); 119 } 120 assert!(README.contains("## Overlap-safe reconciliation replay")); 121 assert!(README.contains( 122 "[`reconciliation_replay.v1.json`](contracts/services_hardening/reconciliation_replay.v1.json)" 123 )); 124 }