fix(trace): an action names the generator that produced it

The setup exclusion landed for the model arm only, because only a model
pick stamped a source. A seeded run returned setup's action through the
same entry with no marker, so its denominator still counted the login
while the model arm's did not, and the two are compared.

serializeAction names setup and seeded on the wire, so both arms are
counted by one rule. An already-recorded trace names nothing and keeps
exactly the count it was reported with; unattributed_actions counts those
steps so the old denominator cannot pass as the new one. TraceVersion is
deliberately unbumped: oracle-reduction refuses a differing version, and
a bump would make all 169 recorded runs unreplayable.
This commit is contained in:
pj committed 2026-08-18 17:58:38 +05:30
1 parent 66fd5bce5d
commit 454988fbc8
19 files changed
+377 -82

No files matched your search

+40 -20
View File
@@ -3,125 +3,145 @@
"kind": "Tap",
"x": 250,
"y": 260,
"selector": "id:gamma"
"selector": "id:gamma",
"source": "seeded"
},
{
"kind": "Tap",
"x": 150,
"y": 160,
"selector": "id:beta"
"selector": "id:beta",
"source": "seeded"
},
{
"kind": "Tap",
"x": 50,
"y": 60,
"selector": "id:alpha"
"selector": "id:alpha",
"source": "seeded"
},
{
"kind": "InputText",
"x": 150,
"y": 160,
"text": "a",
"selector": "id:beta"
"selector": "id:beta",
"source": "seeded"
},
{
"kind": "InputText",
"x": 50,
"y": 60,
"text": "\t\n",
"selector": "id:alpha"
"selector": "id:alpha",
"source": "seeded"
},
{
"kind": "Tap",
"x": 250,
"y": 260,
"selector": "id:gamma"
"selector": "id:gamma",
"source": "seeded"
},
{
"kind": "Tap",
"x": 150,
"y": 160,
"selector": "id:beta"
"selector": "id:beta",
"source": "seeded"
},
{
"kind": "Tap",
"x": 250,
"y": 260,
"selector": "id:gamma"
"selector": "id:gamma",
"source": "seeded"
},
{
"kind": "Tap",
"x": 150,
"y": 160,
"selector": "id:beta"
"selector": "id:beta",
"source": "seeded"
},
{
"kind": "Tap",
"x": 250,
"y": 260,
"selector": "id:gamma"
"selector": "id:gamma",
"source": "seeded"
},
{
"kind": "Tap",
"x": 250,
"y": 260,
"selector": "id:gamma"
"selector": "id:gamma",
"source": "seeded"
},
{
"kind": "Tap",
"x": 150,
"y": 160,
"selector": "id:beta"
"selector": "id:beta",
"source": "seeded"
},
{
"kind": "Tap",
"x": 250,
"y": 260,
"selector": "id:gamma"
"selector": "id:gamma",
"source": "seeded"
},
{
"kind": "Tap",
"x": 50,
"y": 60,
"selector": "id:alpha"
"selector": "id:alpha",
"source": "seeded"
},
{
"kind": "InputText",
"x": 150,
"y": 160,
"text": "999999999999999999999",
"selector": "id:beta"
"selector": "id:beta",
"source": "seeded"
},
{
"kind": "InputText",
"x": 150,
"y": 160,
"text": "-1",
"selector": "id:beta"
"selector": "id:beta",
"source": "seeded"
},
{
"kind": "InputText",
"x": 250,
"y": 260,
"text": "-1",
"selector": "id:gamma"
"selector": "id:gamma",
"source": "seeded"
},
{
"kind": "Tap",
"x": 50,
"y": 60,
"selector": "id:alpha"
"selector": "id:alpha",
"source": "seeded"
},
{
"kind": "Tap",
"x": 250,
"y": 260,
"selector": "id:gamma"
"selector": "id:gamma",
"source": "seeded"
},
{
"kind": "Tap",
"x": 50,
"y": 60,
"selector": "id:alpha"
"selector": "id:alpha",
"source": "seeded"
}
]
+4 -2
View File
@@ -45,12 +45,14 @@ const HOST: Host = {
// runParity emits the parity scenario's action stream from a fresh Pcg. It
// drives pick.ts directly (not installRuntime, whose globals are locked once)
// so the caller can run it repeatedly to assert determinism.
// so the caller can run it repeatedly to assert determinism. The scenario has
// no setup, so it stands in for the entry's action-root branch and tags what it
// emits the way that branch does.
export function runParity(): (SerializedAction | null)[] {
const rng = new Pcg(PARITY_SEED_HI, 0n);
const stream: (SerializedAction | null)[] = [];
for (let i = 0; i < PARITY_STEPS; i++) {
stream.push(serializeAction(nextAction(PARITY_ROOT, rng, HOST)));
stream.push(serializeAction(nextAction(PARITY_ROOT, rng, HOST), "seeded"));
}
return stream;
}
+28
View File
@@ -1129,3 +1129,31 @@ test("a nested undefined leaves the page as a dropped key, a nested null does no
});
assert.equal(wire, `{"0":{"value":{"empty":null,"present":1}}}`);
});
// The web half of the cross-host marker contract: for the same spec shape, the
// entry must name setup's action and the action root's differently, and by the
// same two names the goja engine uses (TestNextActionNamesTheGeneratorThatProducedIt
// in internal/verifier/setup_action_test.go asserts them there). A per-action
// rate divides by the root's steps only, so an action that names no producer
// puts a login's taps in the denominator of the policy's exploration.
const { Tap, actions, taps } = await import("../src/actions.ts");
test("the next-action entry names the generator each action came from", () => {
const button = fakeElement({
tag: "button", x: 0, y: 0, width: 40, height: 20, id: "SignIn", clickable: true,
});
const g = globalThis as { actions?: unknown; setup?: unknown; __sanderlingNextAction__?: unknown };
const nextAction = g.__sanderlingNextAction__ as () => { source?: string } | null;
withFakeDocument([button], () => {
try {
g.actions = taps;
g.setup = actions(() => [Tap({ on: "id:SignIn" })]);
assert.equal(nextAction()?.source, "setup");
g.setup = undefined;
assert.equal(nextAction()?.source, "seeded");
} finally {
g.actions = undefined;
g.setup = undefined;
}
});
});