v0.8.0 — the board replays what everyone else did, instead of arriving rearranged
TODO #13, #15 and #18 — Gitea#20 steps 2-4 pointed at a seated player's own screen. Every accepted intent, and every automatic phase that does anything, becomes an ordered presentation step. A bot's whole switching turn used to land in one push; now it arrives as a run of steps, the district panel follows whoever is acting, and a [N behind] … [Skip] row says how far the board is from the game. Solitaire runs the same path — one collector inside submit(), which both session kinds already funnel through — which is where its automatic phases finally get a visible beat. Dwell is assigned by kind: switching holds the screen, turn bookkeeping costs nothing, and the clock turning over earns the beat. Tunable per viewer without a rebuild, and off entirely at pace 0. Also: switching was the one class of action logging unattributed, and now names its train. Reasoning, measurements and the three things that turned out wrong are in CHANGELOG.md. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01X6cF1iYvJ1kNmzYBzu4QX6
This commit is contained in:
co-authored by
Claude Opus 5
parent
312e0301e0
commit
02289e94b8
+101
-13
@@ -244,11 +244,67 @@ describe('redaction — the shared narration log never carries a seat\'s secrets
|
||||
describe('#91 — nothing private survives serialisation, in any state', () => {
|
||||
const names = ['Ann', 'Bob', 'Cy'];
|
||||
|
||||
/** Everything one seat can see, as one string: their Frame, the public board, and their lines. */
|
||||
const everythingSeatSees = (g: ReturnType<typeof newMultiplayerGame>, seat: PlayerIndex): string =>
|
||||
JSON.stringify(snapshot(g.state, g.log, null, null, null, false, seat)) +
|
||||
'\n' + JSON.stringify(publicSnapshot(g.state)) +
|
||||
'\n' + g.log.map((l) => l.text).join('\n');
|
||||
/**
|
||||
* Everything one seat can see, split into the two halves the checks below treat differently.
|
||||
*
|
||||
* `structural` is the machine-readable state: their Frame, the public board, and the frame of every
|
||||
* presentation step they are sent (v0.8.0, TODO #13). `narration` is what the table was TOLD.
|
||||
*
|
||||
* Steps are folded in here rather than given a test of their own so every case below covers them:
|
||||
* the blind draw, the pending decision, Employee Rotation before and after the seating moves, and
|
||||
* the played-out game. Their `lines` are a slice of `g.log` by construction, so the log covers the
|
||||
* narration half of a step and does not need to be searched twice.
|
||||
*/
|
||||
const everythingSeatSees = (g: ReturnType<typeof newMultiplayerGame>, seat: PlayerIndex): {
|
||||
structural: string;
|
||||
history: string;
|
||||
narration: string[];
|
||||
} => ({
|
||||
/**
|
||||
* `[]` for the Frame's own lines, MATCHING PRODUCTION. `frameFor()` (`server/session.ts`) has
|
||||
* passed no log since #97 — narration goes out incrementally through `Push.lines` instead — so
|
||||
* embedding it here audits a path that no longer exists, and worse, it puts the whole log inside
|
||||
* `structural` where the face-up-pile rule below cannot reach it. The log is audited in full as
|
||||
* `narration`; this is a de-duplication, not a relaxation.
|
||||
*/
|
||||
structural:
|
||||
JSON.stringify(snapshot(g.state, [], null, null, null, false, seat)) +
|
||||
'\n' + JSON.stringify(publicSnapshot(g.state)),
|
||||
/**
|
||||
* THE STEP FRAMES ARE A RECORD OF WHAT WAS PUBLIC OVER TIME, not a view of the position now —
|
||||
* so they get the PRECISE check and not the fuzzy one, for the same reason the face-up-pile
|
||||
* lines do.
|
||||
*
|
||||
* Every one is built by `deltaPublicFrame` over `publicSnapshot`, which the allow-list test at
|
||||
* the bottom of this file pins property by property; that is what guarantees a step frame is
|
||||
* clean. Searching their accumulation for a card NAME asks "was this ever public?" and answers
|
||||
* a question nobody was posing: Train 6 sat face-up in a Department at step 40 and is in Ann's
|
||||
* hand at step 120, and both facts are correct. A card ID is different — narration never renders
|
||||
* one and no public field carries an opponent's, so finding one anywhere is still proof.
|
||||
*/
|
||||
history: JSON.stringify(g.display.steps.map((step) => step.frame)),
|
||||
narration: g.log.map((l) => l.text),
|
||||
});
|
||||
|
||||
/**
|
||||
* A FACE-UP PILE IS ALLOWED TO NAME THE CARD ON IT, and the log is history rather than a view.
|
||||
*
|
||||
* §2.6: the three Department piles and the Salvage Yard are face up, "so players can audit
|
||||
* discards" — a discard goes onto one precisely so a rival can take it. So "Player Ann discarded
|
||||
* Train 6 face-up on top of Department 3" is the record working, and it stays in the log after Ann
|
||||
* takes the card back into her hand. The name-based check below would otherwise read that historical
|
||||
* line as proof of what Ann is holding NOW, which is how it reported a leak against correct code on
|
||||
* seed 1917398.
|
||||
*
|
||||
* These lines are excluded from the NAME check only. The card-id check and the seed check still run
|
||||
* over them, because those are precise: an id is unique, so finding one is proof, and narration
|
||||
* never renders a raw id.
|
||||
*
|
||||
* **This does not weaken the blind-draw detection**, which is the leak this whole net was built
|
||||
* for (v0.7.9.2, "Red Flags"): a blind draw names the HOME OFFICE DECK, which is face down and
|
||||
* matches nothing here.
|
||||
*/
|
||||
const namesAFaceUpPile = (line: string): boolean => /Department|Salvage/i.test(line);
|
||||
|
||||
/**
|
||||
* Every secret belonging to somebody OTHER than `seat`: their card ids, and the names those ids
|
||||
@@ -265,8 +321,14 @@ describe('#91 — nothing private survives serialisation, in any state', () => {
|
||||
* This is what caught the blind-draw leak in v0.7.9.2: "Red Flags" was in exactly one hand, and it
|
||||
* was in the log.
|
||||
*/
|
||||
const secretsOfOthers = (g: ReturnType<typeof newMultiplayerGame>, seat: PlayerIndex): { what: string; value: string }[] => {
|
||||
const out: { what: string; value: string }[] = [];
|
||||
const secretsOfOthers = (
|
||||
g: ReturnType<typeof newMultiplayerGame>,
|
||||
seat: PlayerIndex,
|
||||
): { what: string; value: string; precise: boolean }[] => {
|
||||
// `precise` marks evidence that is proof on its own — a card id is unique, so finding one
|
||||
// anywhere is a leak. A NAME is circumstantial and is searched over a narrower string; see
|
||||
// `namesAFaceUpPile`.
|
||||
const out: { what: string; value: string; precise: boolean }[] = [];
|
||||
// How many cards in the whole game carry each name, and how many of those are in a given hand.
|
||||
const totalByName = new Map<string, number>();
|
||||
for (const id of g.state.cards.keys()) {
|
||||
@@ -282,10 +344,10 @@ describe('#91 — nothing private survives serialisation, in any state', () => {
|
||||
heldByName.set(n, (heldByName.get(n) ?? 0) + 1);
|
||||
}
|
||||
for (const id of hand) {
|
||||
out.push({ what: `${p.name}'s card id`, value: id });
|
||||
out.push({ what: `${p.name}'s card id`, value: id, precise: true });
|
||||
const name = cardName(g.state, id);
|
||||
if (totalByName.get(name) === heldByName.get(name)) {
|
||||
out.push({ what: `${p.name}'s card name, unique to their hand`, value: name });
|
||||
out.push({ what: `${p.name}'s card name, unique to their hand`, value: name, precise: false });
|
||||
}
|
||||
}
|
||||
}
|
||||
@@ -295,15 +357,19 @@ describe('#91 — nothing private survives serialisation, in any state', () => {
|
||||
/** Runs the whole net over one state, and says which state failed if it does. */
|
||||
const audit = (g: ReturnType<typeof newMultiplayerGame>, where: string): void => {
|
||||
for (const seat of g.state.players.map((p) => p.index)) {
|
||||
const seen = everythingSeatSees(g, seat);
|
||||
for (const { what, value } of secretsOfOthers(g, seat)) {
|
||||
const { structural, history, narration } = everythingSeatSees(g, seat);
|
||||
const everything = structural + '\n' + history + '\n' + narration.join('\n');
|
||||
// Names are fuzzy evidence, so they are searched everywhere EXCEPT the lines a face-up pile
|
||||
// is entitled to name a card on. Ids are precise and are searched everywhere.
|
||||
const forNames = structural + '\n' + narration.filter((l) => !namesAFaceUpPile(l)).join('\n');
|
||||
for (const { what, value, precise } of secretsOfOthers(g, seat)) {
|
||||
assert.ok(
|
||||
!seen.includes(value),
|
||||
!(precise ? everything : forNames).includes(value),
|
||||
`${where}: seat ${seat} can see ${what} ("${value}")`,
|
||||
);
|
||||
}
|
||||
// The seed is the whole future of the deal and must not reach a seat by any route.
|
||||
assert.ok(!seen.includes(String(g.seed)), `${where}: seat ${seat} can see the seed ${g.seed}`);
|
||||
assert.ok(!everything.includes(String(g.seed)), `${where}: seat ${seat} can see the seed ${g.seed}`);
|
||||
}
|
||||
// And the spectator board, which has no seat and is therefore entitled to nothing private.
|
||||
const pub = JSON.stringify(publicSnapshot(g.state));
|
||||
@@ -346,6 +412,28 @@ describe('#91 — nothing private survives serialisation, in any state', () => {
|
||||
audit(g, 'after a blind draw');
|
||||
});
|
||||
|
||||
it('the net actually sees the presentation steps it claims to cover (v0.8.0)', () => {
|
||||
/**
|
||||
* Guards the COVERAGE, not the code. `everythingSeatSees` folds `display.steps` into the string
|
||||
* every case above is audited against — which is worth nothing if that array is empty in
|
||||
* practice. So: play a real game, and assert both that steps accumulated and that the audited
|
||||
* string contains them.
|
||||
*/
|
||||
const g = newMultiplayerGame(1917398, config, names);
|
||||
play(g, 120);
|
||||
assert.ok(g.display.steps.length > 20, `only ${g.display.steps.length} steps — the net covers little`);
|
||||
const { history, narration } = everythingSeatSees(g, 0 as PlayerIndex);
|
||||
assert.ok(
|
||||
history.includes(JSON.stringify(g.display.steps.map((step) => step.frame))),
|
||||
'the audited string does not actually contain the step frames',
|
||||
);
|
||||
// And a step's own narration is a slice of the log, so the log half covers it.
|
||||
const fromSteps = g.display.steps.flatMap((step) => step.lines.map((l) => l.text));
|
||||
assert.ok(fromSteps.length > 0, 'the steps carried no narration to cover');
|
||||
assert.ok(fromSteps.every((t) => narration.includes(t)), 'a step said something the log did not');
|
||||
audit(g, 'a played game with presentation steps');
|
||||
});
|
||||
|
||||
it('mid-game, with real hands and a built board', () => {
|
||||
// A DISTINCTIVE seed, deliberately. Seed 7 makes the seed check meaningless — "7" is in "Train
|
||||
// 7", in every coordinate and in half the numbers on the board — so it reported a leak that was
|
||||
|
||||
Reference in New Issue
Block a user