v0.8.0 — the board replays what everyone else did, instead of arriving rearranged

TODO #13, #15 and #18 — Gitea#20 steps 2-4 pointed at a seated player's own screen.
Every accepted intent, and every automatic phase that does anything, becomes an
ordered presentation step. A bot's whole switching turn used to land in one push;
now it arrives as a run of steps, the district panel follows whoever is acting,
and a [N behind] … [Skip] row says how far the board is from the game.

Solitaire runs the same path — one collector inside submit(), which both session
kinds already funnel through — which is where its automatic phases finally get a
visible beat.

Dwell is assigned by kind: switching holds the screen, turn bookkeeping costs
nothing, and the clock turning over earns the beat. Tunable per viewer without a
rebuild, and off entirely at pace 0.

Also: switching was the one class of action logging unattributed, and now names
its train. Reasoning, measurements and the three things that turned out wrong are
in CHANGELOG.md.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01X6cF1iYvJ1kNmzYBzu4QX6
This commit is contained in:
Jesse.Markowitz
2026-09-09 15:31:46 -04:00
co-authored by Claude Opus 5
parent 312e0301e0
commit 02289e94b8
25 changed files with 2669 additions and 145 deletions
+101 -13
View File
@@ -244,11 +244,67 @@ describe('redaction — the shared narration log never carries a seat\'s secrets
describe('#91 — nothing private survives serialisation, in any state', () => {
const names = ['Ann', 'Bob', 'Cy'];
/** Everything one seat can see, as one string: their Frame, the public board, and their lines. */
const everythingSeatSees = (g: ReturnType<typeof newMultiplayerGame>, seat: PlayerIndex): string =>
JSON.stringify(snapshot(g.state, g.log, null, null, null, false, seat)) +
'\n' + JSON.stringify(publicSnapshot(g.state)) +
'\n' + g.log.map((l) => l.text).join('\n');
/**
* Everything one seat can see, split into the two halves the checks below treat differently.
*
* `structural` is the machine-readable state: their Frame, the public board, and the frame of every
* presentation step they are sent (v0.8.0, TODO #13). `narration` is what the table was TOLD.
*
* Steps are folded in here rather than given a test of their own so every case below covers them:
* the blind draw, the pending decision, Employee Rotation before and after the seating moves, and
* the played-out game. Their `lines` are a slice of `g.log` by construction, so the log covers the
* narration half of a step and does not need to be searched twice.
*/
const everythingSeatSees = (g: ReturnType<typeof newMultiplayerGame>, seat: PlayerIndex): {
structural: string;
history: string;
narration: string[];
} => ({
/**
* `[]` for the Frame's own lines, MATCHING PRODUCTION. `frameFor()` (`server/session.ts`) has
* passed no log since #97 — narration goes out incrementally through `Push.lines` instead — so
* embedding it here audits a path that no longer exists, and worse, it puts the whole log inside
* `structural` where the face-up-pile rule below cannot reach it. The log is audited in full as
* `narration`; this is a de-duplication, not a relaxation.
*/
structural:
JSON.stringify(snapshot(g.state, [], null, null, null, false, seat)) +
'\n' + JSON.stringify(publicSnapshot(g.state)),
/**
* THE STEP FRAMES ARE A RECORD OF WHAT WAS PUBLIC OVER TIME, not a view of the position now —
* so they get the PRECISE check and not the fuzzy one, for the same reason the face-up-pile
* lines do.
*
* Every one is built by `deltaPublicFrame` over `publicSnapshot`, which the allow-list test at
* the bottom of this file pins property by property; that is what guarantees a step frame is
* clean. Searching their accumulation for a card NAME asks "was this ever public?" and answers
* a question nobody was posing: Train 6 sat face-up in a Department at step 40 and is in Ann's
* hand at step 120, and both facts are correct. A card ID is different — narration never renders
* one and no public field carries an opponent's, so finding one anywhere is still proof.
*/
history: JSON.stringify(g.display.steps.map((step) => step.frame)),
narration: g.log.map((l) => l.text),
});
/**
* A FACE-UP PILE IS ALLOWED TO NAME THE CARD ON IT, and the log is history rather than a view.
*
* §2.6: the three Department piles and the Salvage Yard are face up, "so players can audit
* discards" — a discard goes onto one precisely so a rival can take it. So "Player Ann discarded
* Train 6 face-up on top of Department 3" is the record working, and it stays in the log after Ann
* takes the card back into her hand. The name-based check below would otherwise read that historical
* line as proof of what Ann is holding NOW, which is how it reported a leak against correct code on
* seed 1917398.
*
* These lines are excluded from the NAME check only. The card-id check and the seed check still run
* over them, because those are precise: an id is unique, so finding one is proof, and narration
* never renders a raw id.
*
* **This does not weaken the blind-draw detection**, which is the leak this whole net was built
* for (v0.7.9.2, "Red Flags"): a blind draw names the HOME OFFICE DECK, which is face down and
* matches nothing here.
*/
const namesAFaceUpPile = (line: string): boolean => /Department|Salvage/i.test(line);
/**
* Every secret belonging to somebody OTHER than `seat`: their card ids, and the names those ids
@@ -265,8 +321,14 @@ describe('#91 — nothing private survives serialisation, in any state', () => {
* This is what caught the blind-draw leak in v0.7.9.2: "Red Flags" was in exactly one hand, and it
* was in the log.
*/
const secretsOfOthers = (g: ReturnType<typeof newMultiplayerGame>, seat: PlayerIndex): { what: string; value: string }[] => {
const out: { what: string; value: string }[] = [];
const secretsOfOthers = (
g: ReturnType<typeof newMultiplayerGame>,
seat: PlayerIndex,
): { what: string; value: string; precise: boolean }[] => {
// `precise` marks evidence that is proof on its own — a card id is unique, so finding one
// anywhere is a leak. A NAME is circumstantial and is searched over a narrower string; see
// `namesAFaceUpPile`.
const out: { what: string; value: string; precise: boolean }[] = [];
// How many cards in the whole game carry each name, and how many of those are in a given hand.
const totalByName = new Map<string, number>();
for (const id of g.state.cards.keys()) {
@@ -282,10 +344,10 @@ describe('#91 — nothing private survives serialisation, in any state', () => {
heldByName.set(n, (heldByName.get(n) ?? 0) + 1);
}
for (const id of hand) {
out.push({ what: `${p.name}'s card id`, value: id });
out.push({ what: `${p.name}'s card id`, value: id, precise: true });
const name = cardName(g.state, id);
if (totalByName.get(name) === heldByName.get(name)) {
out.push({ what: `${p.name}'s card name, unique to their hand`, value: name });
out.push({ what: `${p.name}'s card name, unique to their hand`, value: name, precise: false });
}
}
}
@@ -295,15 +357,19 @@ describe('#91 — nothing private survives serialisation, in any state', () => {
/** Runs the whole net over one state, and says which state failed if it does. */
const audit = (g: ReturnType<typeof newMultiplayerGame>, where: string): void => {
for (const seat of g.state.players.map((p) => p.index)) {
const seen = everythingSeatSees(g, seat);
for (const { what, value } of secretsOfOthers(g, seat)) {
const { structural, history, narration } = everythingSeatSees(g, seat);
const everything = structural + '\n' + history + '\n' + narration.join('\n');
// Names are fuzzy evidence, so they are searched everywhere EXCEPT the lines a face-up pile
// is entitled to name a card on. Ids are precise and are searched everywhere.
const forNames = structural + '\n' + narration.filter((l) => !namesAFaceUpPile(l)).join('\n');
for (const { what, value, precise } of secretsOfOthers(g, seat)) {
assert.ok(
!seen.includes(value),
!(precise ? everything : forNames).includes(value),
`${where}: seat ${seat} can see ${what} ("${value}")`,
);
}
// The seed is the whole future of the deal and must not reach a seat by any route.
assert.ok(!seen.includes(String(g.seed)), `${where}: seat ${seat} can see the seed ${g.seed}`);
assert.ok(!everything.includes(String(g.seed)), `${where}: seat ${seat} can see the seed ${g.seed}`);
}
// And the spectator board, which has no seat and is therefore entitled to nothing private.
const pub = JSON.stringify(publicSnapshot(g.state));
@@ -346,6 +412,28 @@ describe('#91 — nothing private survives serialisation, in any state', () => {
audit(g, 'after a blind draw');
});
it('the net actually sees the presentation steps it claims to cover (v0.8.0)', () => {
/**
* Guards the COVERAGE, not the code. `everythingSeatSees` folds `display.steps` into the string
* every case above is audited against — which is worth nothing if that array is empty in
* practice. So: play a real game, and assert both that steps accumulated and that the audited
* string contains them.
*/
const g = newMultiplayerGame(1917398, config, names);
play(g, 120);
assert.ok(g.display.steps.length > 20, `only ${g.display.steps.length} steps — the net covers little`);
const { history, narration } = everythingSeatSees(g, 0 as PlayerIndex);
assert.ok(
history.includes(JSON.stringify(g.display.steps.map((step) => step.frame))),
'the audited string does not actually contain the step frames',
);
// And a step's own narration is a slice of the log, so the log half covers it.
const fromSteps = g.display.steps.flatMap((step) => step.lines.map((l) => l.text));
assert.ok(fromSteps.length > 0, 'the steps carried no narration to cover');
assert.ok(fromSteps.every((t) => narration.includes(t)), 'a step said something the log did not');
audit(g, 'a played game with presentation steps');
});
it('mid-game, with real hands and a built board', () => {
// A DISTINCTIVE seed, deliberately. Seed 7 makes the seed check meaningless — "7" is in "Train
// 7", in every coordinate and in half the numbers on the board — so it reported a leak that was