test(adversarial): P3Adversarial.t.sol — task_240926_17 Part 2 - #218
robertocarlous wants to merge 1 commit into
Conversation
13 tests covering all rows of the adversarial threat model (issue InfiniteZeroFoundation#154). Maps each row to a test named test_{costBounded|defended|knownGap}_{desc}. Rows covered: 1 cost-bounded: Sybil no-participation (unassigned agg, S2 non-participant) 2 cost-bounded: Sybil seat capture cost = k * MIN_STAKE 3 defended: S5 recidivism escalation fires on threshold-th miss 4 knownGap: auditor bloc inflated scores in S3 shadow mode (no slash) 5 knownGap: T1 wrong CID persists post-dispute; honest dissenter slashed 6 knownGap: dual-role cross-registration (agg + auditor, same GI) 7a knownGap: owner rejects dispute (resolveDispute=false) — bond forfeited 7b knownGap: owner suppresses via settleRecomputation(false) — bond forfeited 7c knownGap: bond locked forever when owner never resolves 8 defended: dispute-seed subgroup is deterministic; re-lock reverts 9a cost-bounded: inflated score with odd reveal count — outlier can't shift median 9b cost-bounded: even reveal count — colluder moves median halfway 11 knownGap: per-slasher S5 ring evasion across two task contracts
|
Cc: @umeradl |
|
Reviewed against Claimed: 13 tests, one per row of Verified — exact match: Claimed: the tests encode each row's expected outcome. Verified by breaking the code under test:
All sources restored afterwards; the worktree is clean. Against the threat model's "Expected test outcome" column (which task_240926_17 says the tests are written against):
Against task_240926_17 Part 2's rules:
Interplay with open plans: task-plan-051026-1 (PR No. 219) closes Row 6 (No. 180) and Row 11 (No. 193). Whichever merges second flips The suite builds, passes, and Rows 5, 6, 7a–c, 9b and 11 encode their expected outcomes. But three "defended"/"costBounded" checks can't fail on the regression they're named for (Rows 4/9a event data, Row 8 determinism, Row 2 seat capture), and Rows 1 and 3 miss part of their expected outcome. Recommendation: changes requested before merge:
|
Files changed (1) — as of
|
| Field | Value |
|---|---|
| Change | New |
| Lines | +845/-0 |
| Diff (what exactly is in this PR) | 13 tests named test_{costBounded,defended,knownGap}_…, one per threat-model row (7 and 9 split, 10 deferred), with platform/task-pair fixtures, seed-lock helpers, sender-bound T1/T2 commit-reveal helpers, and a second task pair for Row 11. |
| Functionality — how & why | How: each test drives a real platform + task pair. Rows 1, 2, 4, 5, 6, 7, 8 and 9 go through registration, seed locks, batch creation and commit-reveal (_setupToT1Open, _runToT1Finalized, _runToAuditorsSlashed). Rows 3 and 11 call slashPartial directly as the task contract. Why: issue No. 154 Part 2. Each threat-model row gets a test whose class says whether the protocol defends, bounds the cost of, or knowingly allows the attack, so a later fix fails a knownGap test and a regression fails a defended one. The build passes and 13/13 pass (504/504 overall). Breaking S5 escalation fails Rows 3 and 11 as it should. |
Diff vs current develop HEAD |
None — new file |
| Recommended merge proposal | Changes requested before merge (detail in the verification comment): (1) Rows 4/9a expectEmit(…, false) doesn't compare exceedsThreshold/scores, verified by changing every data field and still passing; (2) Row 8 asserts only non-zero assignees, so a timestamp/caller-seeded shuffle still passes; (3) Row 2 sums stakes and never measures seat capture; (4) Row 1 (c) S5 and Row 3's "4th registration reverts" are missing, and Rows 3/11 bypass the real GI lifecycle Part 2 requires; (5) NatSpec attack narratives and flip notes on knownGap tests. |
| Actual merge proposal | Soon |
| Pending proposal | Author fixes 1–5. Row 6 / Row 11 flips coordinated with PR No. 219 (whichever merges second). |
| Local merge conflict | No |
| GitHub merge conflict | No |
Verification
Full detail is in the verification comment above. In short: via_ir forge build passes. P3AdversarialTest 13/13, full suite 504/504 in 40 suites. Break-then-fix: S5 is caught (2 tests fail), but the Row 8 seed and the Row 4 event data are not caught. GitHub CI is green.
Local vs. GitHub agree: both report a clean merge.
Summary
Closes Part 2 of task_240926_17 (issue #154).
Adds
foundry/test/P3Adversarial.t.solwith 13 tests covering every row ofDeveloper/design/adversarial-threat-model.md.Each test is named
test_{class}_{description}where class iscostBounded,defended, orknownGap, matching the row classification in the threat model doc.test_costBounded_sybilNoParticipationtest_costBounded_sybilSeatCapture_stakeIsKTimesMinStaketest_defended_recidivistS5Escalationtest_knownGap_auditorBlocPoisonedModeltest_knownGap_t1WrongCID_finalCIDUnchangedDissenterSlashedtest_knownGap_dualRoleRegistrationtest_knownGap_ownerSuppressesDispute_rejectedtest_knownGap_ownerSuppressesDispute_forfeitedViaSettlementtest_knownGap_ownerSuppressesDispute_bondLockedIfNeverResolvedtest_defended_disputeSeedSubgroupDeterministictest_costBounded_inflatedScores_oddCounttest_costBounded_inflatedScores_evenCount_colluderMovesMedianHalfwaytest_knownGap_perSlasherS5EvasionAll 13 tests pass (
forge test --match-contract P3AdversarialTest).Accounts for all three develop changes Umer flagged in discussion #164:
lockAggSeed/lockAuditSeed(H-2 fix)Test plan
forge test --match-contract P3AdversarialTest -vvshows 13/13 passing