From 898ff72b37ccf53c8c3f4882dfde0f6b2616dc90 Mon Sep 17 00:00:00 2001 From: PJ Date: Mon, 1 Jun 2026 13:49:44 +0530 Subject: [PATCH] test(ltl): Finalize, bounded eventually, latch, collapse Property tests for monotonic violation latch and eventually-within violating iff n consecutive false, plus Finalize and collapse cases. --- internal/ltl/finalize_test.go | 161 ++++++++++++++++++++++++++++++++++ 1 file changed, 161 insertions(+) create mode 100644 internal/ltl/finalize_test.go diff --git a/internal/ltl/finalize_test.go b/internal/ltl/finalize_test.go new file mode 100644 index 0000000..6cd8263 --- /dev/null +++ b/internal/ltl/finalize_test.go @@ -0,0 +1,161 @@ +package ltl + +import ( + "testing" + "testing/quick" + "time" +) + +func TestFinalize_UnboundedEventuallyUnmetIsViolated(t *testing.T) { + evaluator := NewEvaluator(Eventually(ThunkNamed("p", func() bool { return false }))) + for index := range 3 { + if got := evaluator.ObserveAt(time.Unix(int64(index), 0)); got != VerdictPending { + t.Fatalf("step %d: got %v, want pending", index, got) + } + } + if got := evaluator.Finalize(); got != VerdictViolated { + t.Errorf("Finalize = %v, want violated", got) + } +} + +func TestFinalize_FinalStepNextIsViolated(t *testing.T) { + evaluator := NewEvaluator(Next(ThunkNamed("p", func() bool { return true }))) + if got := evaluator.Observe(); got != VerdictPending { + t.Fatalf("step 1: got %v, want pending", got) + } + if got := evaluator.Finalize(); got != VerdictViolated { + t.Errorf("Finalize = %v, want violated", got) + } +} + +func TestFinalize_HoldingRunStaysHolds(t *testing.T) { + evaluator := NewEvaluator(Always(Pure(true))) + evaluator.Observe() + if got := evaluator.Finalize(); got != VerdictHolds { + t.Errorf("Finalize = %v, want holds", got) + } +} + +func TestFinalize_AlreadyViolatedStaysViolated(t *testing.T) { + evaluator := NewEvaluator(Always(Pure(false))) + if got := evaluator.Observe(); got != VerdictViolated { + t.Fatalf("expected violated, got %v", got) + } + if got := evaluator.Finalize(); got != VerdictViolated { + t.Errorf("Finalize = %v, want violated", got) + } +} + +func TestFinalize_BoundedAlwaysVacuouslyHolds(t *testing.T) { + // A bounded Always whose window never closed (still pending) is safe. + evaluator := NewEvaluator(EventuallyWithinSteps(Pure(false), 5)) + evaluator.Observe() + // The negated form of this is a bounded Always; build it directly. + bounded := NewEvaluator(Always(Not(EventuallyWithinSteps(ThunkNamed("p", func() bool { return false }), 5)))) + bounded.Observe() + if got := bounded.Finalize(); got == VerdictViolated { + t.Errorf("bounded always should not finalize to violated, got %v", got) + } +} + +// TestEventuallyWithin_ViolatesIffNConsecutiveFalse locks the bounded +// eventually contract: with a step bound of n and an inner that is false for +// the first n observations, the verdict violates exactly at step n, and with at +// least one true observation inside the window it holds. +func TestEventuallyWithin_ViolatesIffNConsecutiveFalse(t *testing.T) { + law := func(boundSeed uint8, trueAtSeed uint8) bool { + bound := int(boundSeed%5) + 1 + // trueAt < 0 means inner is never true. + trueAt := int(trueAtSeed)%(bound+2) - 1 + step := 0 + inner := ThunkNamed("p", func() bool { + current := trueAt >= 0 && step == trueAt + return current + }) + evaluator := NewEvaluator(EventuallyWithinSteps(inner, bound)) + + satisfiedInWindow := trueAt >= 0 && trueAt < bound + var final Verdict = VerdictPending + for index := range bound { + step = index + final = evaluator.ObserveAt(time.Unix(int64(index), 0)) + if final == VerdictHolds || final == VerdictViolated { + break + } + } + + if satisfiedInWindow { + return final == VerdictHolds + } + return final == VerdictViolated + } + if err := quick.Check(law, nil); err != nil { + t.Error(err) + } +} + +// TestViolationLatchIsMonotonic locks: once an evaluator reports Violated, every +// subsequent observation (and Finalize) stays Violated regardless of inputs. +func TestViolationLatchIsMonotonic(t *testing.T) { + law := func(seed uint64) bool { + values := make([]bool, 8) + for index := range values { + values[index] = (seed>>uint(index))&1 == 1 + } + step := 0 + evaluator := NewEvaluator(Always(ThunkNamed("p", func() bool { + current := values[step%len(values)] + step++ + return current + }))) + seenViolated := false + for index := range 16 { + got := evaluator.ObserveAt(time.Unix(int64(index), 0)) + if got == VerdictViolated { + seenViolated = true + } else if seenViolated { + return false + } + } + if seenViolated && evaluator.Finalize() != VerdictViolated { + return false + } + return true + } + if err := quick.Check(law, nil); err != nil { + t.Error(err) + } +} + +func TestCollapse_IdenticalObligationsMerge(t *testing.T) { + merged := collapse([]Formula{ + Next(Pure(true)), + Next(Pure(true)), + Next(Pure(true)), + }) + if len(merged) != 1 { + t.Errorf("expected 1 obligation after collapse, got %d", len(merged)) + } +} + +func TestCollapse_DistinctPredicatesDoNotMerge(t *testing.T) { + merged := collapse([]Formula{ + Eventually(ThunkNamed("p3", func() bool { return false })), + Eventually(ThunkNamed("p4", func() bool { return false })), + }) + if len(merged) != 2 { + t.Errorf("distinct predicates must not merge, got %d", len(merged)) + } +} + +func TestCollapse_NamedThunkLeakBoundsPendingSet(t *testing.T) { + // Always(Eventually(sameThunk)): each step spawns an identical obligation. + // Without collapse the pending set grows unboundedly. + evaluator := NewEvaluator(Always(Eventually(ThunkNamed("p", func() bool { return false })))) + for index := range 20 { + evaluator.ObserveAt(time.Unix(int64(index), 0)) + } + if len(evaluator.pending) > 2 { + t.Errorf("pending set leaked to %d obligations", len(evaluator.pending)) + } +}