Skip to content

fix(spec): the evidence levels hold under post-load realm mutation (#345's final file) - #577

Merged
LamaSu merged 5 commits into
masterfrom
fix/evidence-level-realm
Oct 6, 2026
Merged

LamaSu merged 5 commits into
masterfrom
fix/evidence-level-realm

Conversation

@LamaSu

@LamaSu LamaSu commented Oct 4, 2026 •

Copy link
Copy Markdown
Owner

Rows: steward #5186 (the realm-mutation class) and evidence #6440. This makes #345's FINAL evidence-level.ts, now on master, hold under post-load realm mutation. It is the evidence-level half of #519's 550b212, ported onto the final file; #519 itself waits on its merge-up.

Why

Master's evidence-level.ts (37adc7b) looks up built-ins when it is called. Evidence demonstrated the effect (#6440):

  • with Array.prototype.indexOf patched after load, meetsEvidenceLevel("submitted", "inspected_output") answered true;
  • with Set.prototype.has patched, a failed inspection's verdict became none.

The new harness, run against master's file, changes answers in 31 of its 68 checks. The escalations include:

  • that meetsEvidenceLevel;
  • with Object.prototype.deviceId written, an event with no device id proving device_reported;
  • with Array.prototype[0] written, a hole in executorTrustDomains turning a refusal into inspected_output.

The change (packages/spec/src/evidence/evidence-level.ts)

  • Call-time built-ins. It calls only intrinsics captured at load (util/primordials.ts), index loops and operators: no method looked up at call time, no iterator protocol, spread, in or RegExp, at load or at call time.
    • The sets and the pinned-verdict table are frozen null-prototype records built at load.
    • The exported lists are frozen.
    • The operator-principal pattern is a code-unit predicate. A test holds it equal to the old RegExp and its safe-integer check, on the edge cases and on 30,000 seeded strings.
  • Own reads (rule 7 stays one read each). An event's type, source and payload, source.deviceId and source.simulated, a bundle's events and trustDomain, the context's executorTrustDomains and every list element are read only when they are OWN properties. An own accessor still runs exactly once, as E5's tests require.
  • payload.mock keeps isFabricated's plain read, which E5's payload trap test pins. Written on Object.prototype, it can only make evidence fabricated, which refuses.
  • The pinned verdict field must hold an own value. "value" in descriptor let a value written on Object.prototype make an accessor read as data.
  • util/primordials.ts is fix(spec): profile admission and the evidence levels hold under post-load realm mutation (#363 follow-up, steward #5186) #519's reviewed version, verbatim: 195 lines added, none removed. fix(spec): profile admission and the evidence levels hold under post-load realm mutation (#363 follow-up, steward #5186) #519's merge-up therefore sees identical content there.

Tests

  • evidence-level.test.ts (E5): unchanged, 128 of 128.

  • evidence-level-intrinsics.test.ts (new):

  • Mutations: 26 of 26 killed, each a single call site put back on the live built-in or a plain inherited read:

    • 12 caught by the scan and the realm runs together;
    • 3 by the scan alone (in, Array.isArray in isPlainObject, Object.freeze, all equivalent in behaviour);
    • 10 by the realm runs alone (the own-only reads);
    • 1 by the frozen-exports check.

    The realm runs added a forged Array.prototype[0] after two read mutants (bundles[i] and events[j]) first survived.

  • Suites: spec 2476 of 2476; tsc --noEmit clean.

🤖 Generated with Claude Code

LamaSu added 2 commits October 3, 2026 20:15
's final file)

Evidence #6440 asked sensors to own this port: #519's 550b212 pattern, applied to
#345's final evidence-level.ts. On master, code that runs after @pcc/spec loads
could change its answers. With Array.prototype.indexOf replaced,
meetsEvidenceLevel("submitted", "inspected_output") was true. The new harness,
run against master's file, changes answers in 31 of its 68 checks, escalations
included.

- It calls only intrinsics captured at load (util/primordials.ts, which is #519's
  reviewed version, verbatim), index loops and operators. No method looked up at
  call time, no iterator protocol, spread, in or RegExp, at load or at call time.
- The sets and the pinned-verdict table are frozen null-prototype records, and
  the exported lists are frozen.
- The principal-id RegExp is a code-unit predicate, held equal to the pattern.
- The pinned verdict field must hold an own value.
- Rule 7 still reads each field once, but only OWN properties count. An own
  accessor still runs once. payload.mock keeps isFabricated's read, which E5's
  trap test pins; written on Object.prototype it can only refuse.

Tests: E5's evidence-level.test.ts is unchanged, 128 of 128. The new
evidence-level-intrinsics.test.ts runs 61 child-realm scenarios over 141
answers, plus source scans, frozen exports, RegExp reachability and the
predicate's equivalence. Mutations: 26 of 26 killed. Spec: 2476 of 2476.
…own fields of objects only (pack 267)

Pack 267 (DO-NOT-SHIP) found 2 HIGH in #577. Both were reproduced at e13a395
by new realm scenarios; 6 scenarios changed answers.

- An inherited payload.mock was still read, through isFabricated, BEFORE
  source.deviceId. An Object.prototype.mock getter could write the event's
  deviceId and answer false, and an unattributed completion then proved
  device_reported (an up-tier). A throwing getter turned a classification into
  a refusal.
- A primitive source or payload was passed to isFabricated as it was. Its read
  boxed the primitive and consulted Number.prototype, String.prototype and
  Object.prototype: a written `simulated` made a bundle fabricated and erased its
  completion-and-failure contradiction.

isFabricated now receives null-prototype snapshots of source.simulated and
payload.mock. Each is read once as an OWN property, and is undefined for a
non-object. E5's trap test now expects the own-only read of mock
(getOwnPropertyDescriptor:mock, no get:mock). Its inherited-mock case is now an
explicit assertion: canonicalize hashes own fields only, so verified evidence
never carries an inherited marker.

The harness gains primitive-source and primitive-payload items and four
scenarios: a mock getter that writes deviceId, a throwing mock getter,
Number.prototype.simulated and String.prototype.mock. The test's mock exception
is gone, so every scenario must be identical. Mutations: 28 of 28 killed.
E5 128 of 128; realm tests 73.
The fullwidth and Arabic-Indic digits in the principal-id cases were literal
characters in the source. As escapes, a reviewer sees them for what they are.
No behaviour changes.
LamaSu added a commit that referenced this pull request Oct 4, 2026
…to the realm-hardened admission

#363 moved profile admission to #345's one rule (steward #6478). The deal's
executorTrustDomains are an input. The signature leg answers { trustDomain }.
Levels and contradictions run over authenticated bundles, each event counts at
its LOWEST level, and inspections pass by the pinned verdict field
(inspectionVerdict). #519 had made admission hold under post-load realm
mutation. This merge carries the migration into #519's hardened file, so both
hold.

Conflicts and how each was resolved:
- evidence-level.ts: #577's file (426be44), the realm port of #345's final
  file. It already freezes EVIDENCE_LEVELS, #363's only change to that file,
  and master has not touched the file since #577 forked. E5's
  evidence-level.test.ts is #577's too, for the two expectations #577 changed.
- profile-admission.ts: #519's hardened file with the migration applied in
  its style:
  - executorTrustDomains is read as data with the other fields (INPUT_FIELDS,
    DATA_FIELDS, plainDataCopy) and checked by isOperatorPrincipalId. That is
    a code-unit predicate equal to principal-id.ts parseOperatorPrincipalId,
    with no RegExp; it is exported, and a test holds the two equal on edge
    cases and 20,000 near-misses.
  - The signature leg's answer is read once from its own data (signerOf) into
    a frozen null-prototype record. A proxy, an own then, an accessor or a
    malformed domain fails it.
  - A native promise is followed by the then captured at load
    (followedPromise, new in util/primordials.ts), and its value is read
    inside the handler.
  - A promised answer must have no prototype (signedBy, exported). Resolving
    an ordinary object looks then up on Object.prototype, where code running
    after load could substitute the answer. A synchronous plain answer is
    still accepted, since nothing resolves it.
  - Levels and contradictions run over null-prototype AuthenticatedBundles.
    The lowest level per event hash is kept in a null-prototype record.
    reached is the highest of those.
- Tests:
  - #363's two-operator world, with the auto-merged helper's duplicated
    executorTrustDomains removed.
  - #519's pack-187 inputs now carry executorTrustDomains, and the
    binding-lookup test uses the two-bundle pilot.
  - New cases cover the signature leg under a then getter planted on
    Object.prototype, signedBy, a promised ordinary record, a thenable or
    proxy answer, and the executors refused at the input boundary (no leg
    runs).
- The realm harness:
  - It moves to the two-operator world (the printer in A's bundle, every
    other device in B's) and the new leg contract.
  - It gains cases for the new leg (a signedBy async leg, a promised ordinary
    record, a bare true, a null domain, the executor's own camera, no or
    malformed executors, a thenable).
  - Its evidence-level items are dropped: #577's harness
    (evidence-level-realm.ts) holds the levels under realm mutation.

Spec 2676 of 2676, admission 249 of 249, tsc clean.
Mutations: 19 of 20 killed. The survivor, "null copy not lowest", is
equivalent, as in pack 271: copies of one event differ in level only when a
bundle is fabricated, and admission refuses fabricated events first.
LamaSu added a commit that referenced this pull request Oct 4, 2026
…519

#519 follows #577 for evidence-level.ts: the previous merge already took
#577's file and E5's two changed expectations. This merge brings #577's
history and its realm tests: evidence-level-intrinsics.test.ts and
harness/evidence-level-realm.ts.

One conflict, util/primordials.ts. #577's copy is #519's file verbatim
(3b27e8a's blob), so #519's side is the resolution: that file plus
followedPromise.

Spec 2749 of 2749 (81 files); tsc clean.
LamaSu added a commit that referenced this pull request Oct 4, 2026
…master (269 SHIP; steward #6523's standing rule; a plain merge)
@LamaSu
LamaSu marked this pull request as ready for review October 6, 2026 22:48
@LamaSu
LamaSu merged commit 54a6e0c into master Oct 6, 2026
13 of 16 checks passed

This branch had an error being deployed

1 failed deployment
trusted-checks — 86a6ed63 Deployed Oct 6, 2026 by LamaSu via post-verdicts #173
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant