mirror of
https://github.com/priyanshujain/sanderling.git
synced 2026-10-02 19:17:10 +00:00
feat(ltl): attribute violations to the obligation origin step
This commit is contained in:
1 parent
ce65cc32a4
commit
dc7d23eaa2
3 files changed
+131
-38
No files matched your search
+47
-31
@@ -33,17 +33,27 @@ func (v Verdict) String() string {
|
|||||||
// violates, the overall verdict latches to Violated.
|
// violates, the overall verdict latches to Violated.
|
||||||
type Evaluator struct {
|
type Evaluator struct {
|
||||||
root Formula
|
root Formula
|
||||||
pending []Formula
|
pending []obligation
|
||||||
violated bool
|
violated bool
|
||||||
steps int
|
steps int
|
||||||
violation *Violation
|
violation *Violation
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// obligation pairs a residual formula with the step that spawned it, so a
|
||||||
|
// deferred check (a next, a pending eventually) that fails on a later step can
|
||||||
|
// be attributed to the step that created the obligation.
|
||||||
|
type obligation struct {
|
||||||
|
formula Formula
|
||||||
|
origin int
|
||||||
|
}
|
||||||
|
|
||||||
// Violation is the witness for a latched verdict: the failing sub-formula, a
|
// Violation is the witness for a latched verdict: the failing sub-formula, a
|
||||||
// human-readable reason, and the observation step it fired at. A thrown
|
// human-readable reason, and the step the failed obligation originated at. For
|
||||||
// predicate carries the goja error text as its reason and sets IsError; a plain
|
// an immediate predicate failure that is the observation step itself; for a
|
||||||
// false carries "predicate false"; Finalize fills it for liveness obligations
|
// deferred obligation (next, eventually) it is the earlier step that spawned
|
||||||
// that never discharged.
|
// it, the one that caused the violation. A thrown predicate carries the goja
|
||||||
|
// error text as its reason and sets IsError; a plain false carries "predicate
|
||||||
|
// false"; Finalize fills it for liveness obligations that never discharged.
|
||||||
type Violation struct {
|
type Violation struct {
|
||||||
Formula Formula
|
Formula Formula
|
||||||
Reason string
|
Reason string
|
||||||
@@ -62,19 +72,29 @@ func (e *Evaluator) Observe() Verdict {
|
|||||||
return e.ObserveAt(time.Now())
|
return e.ObserveAt(time.Now())
|
||||||
}
|
}
|
||||||
|
|
||||||
// ObserveAt is like Observe but takes the current step time explicitly.
|
// ObserveAt is like Observe but takes the current step time explicitly. Steps
|
||||||
|
// are numbered by an internal counter starting at 1; callers whose step
|
||||||
|
// numbering can skip observations should use ObserveAtStep instead.
|
||||||
func (e *Evaluator) ObserveAt(now time.Time) Verdict {
|
func (e *Evaluator) ObserveAt(now time.Time) Verdict {
|
||||||
|
return e.ObserveAtStep(now, e.steps+1)
|
||||||
|
}
|
||||||
|
|
||||||
|
// ObserveAtStep is like ObserveAt but labels the observation with the caller's
|
||||||
|
// step index, so violation witnesses carry the caller's numbering even when
|
||||||
|
// some steps were never observed (for example transitional steps the verifier
|
||||||
|
// skips).
|
||||||
|
func (e *Evaluator) ObserveAtStep(now time.Time, step int) Verdict {
|
||||||
if e.violated {
|
if e.violated {
|
||||||
return VerdictViolated
|
return VerdictViolated
|
||||||
}
|
}
|
||||||
e.steps++
|
e.steps = step
|
||||||
|
|
||||||
fresh := rootObligation(e.root)
|
fresh := obligation{formula: rootObligation(e.root), origin: step}
|
||||||
obligations := append(e.pending, fresh)
|
obligations := append(e.pending, fresh)
|
||||||
e.pending = e.pending[:0]
|
e.pending = e.pending[:0]
|
||||||
|
|
||||||
for _, obligation := range obligations {
|
for _, entry := range obligations {
|
||||||
result := reduce(obligation, now)
|
result := reduce(entry.formula, now)
|
||||||
switch result.status {
|
switch result.status {
|
||||||
case statusHolds:
|
case statusHolds:
|
||||||
// drop
|
// drop
|
||||||
@@ -83,11 +103,11 @@ func (e *Evaluator) ObserveAt(now time.Time) Verdict {
|
|||||||
e.pending = nil
|
e.pending = nil
|
||||||
e.violation = result.witness
|
e.violation = result.witness
|
||||||
if e.violation != nil {
|
if e.violation != nil {
|
||||||
e.violation.Step = e.steps
|
e.violation.Step = entry.origin
|
||||||
}
|
}
|
||||||
return VerdictViolated
|
return VerdictViolated
|
||||||
case statusPending:
|
case statusPending:
|
||||||
e.pending = append(e.pending, result.formula)
|
e.pending = append(e.pending, obligation{formula: result.formula, origin: entry.origin})
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -100,21 +120,22 @@ func (e *Evaluator) ObserveAt(now time.Time) Verdict {
|
|||||||
}
|
}
|
||||||
|
|
||||||
// collapse removes structurally-identical obligations, keeping the first
|
// collapse removes structurally-identical obligations, keeping the first
|
||||||
// occurrence in order. Distinct predicates never merge because ThunkFormula's
|
// occurrence in order so the surviving entry carries the earliest origin step.
|
||||||
// name participates in its describe() key, so deduping cannot hide a violation.
|
// Distinct predicates never merge because ThunkFormula's name participates in
|
||||||
func collapse(obligations []Formula) []Formula {
|
// its describe() key, so deduping cannot hide a violation.
|
||||||
|
func collapse(obligations []obligation) []obligation {
|
||||||
if len(obligations) < 2 {
|
if len(obligations) < 2 {
|
||||||
return obligations
|
return obligations
|
||||||
}
|
}
|
||||||
seen := make(map[string]struct{}, len(obligations))
|
seen := make(map[string]struct{}, len(obligations))
|
||||||
result := obligations[:0]
|
result := obligations[:0]
|
||||||
for _, obligation := range obligations {
|
for _, entry := range obligations {
|
||||||
key := obligation.describe()
|
key := entry.formula.describe()
|
||||||
if _, ok := seen[key]; ok {
|
if _, ok := seen[key]; ok {
|
||||||
continue
|
continue
|
||||||
}
|
}
|
||||||
seen[key] = struct{}{}
|
seen[key] = struct{}{}
|
||||||
result = append(result, obligation)
|
result = append(result, entry)
|
||||||
}
|
}
|
||||||
return result
|
return result
|
||||||
}
|
}
|
||||||
@@ -127,14 +148,14 @@ func (e *Evaluator) Finalize() Verdict {
|
|||||||
if e.violated {
|
if e.violated {
|
||||||
return VerdictViolated
|
return VerdictViolated
|
||||||
}
|
}
|
||||||
for _, obligation := range e.pending {
|
for _, entry := range e.pending {
|
||||||
if finalize(obligation) == statusViolated {
|
if finalize(entry.formula) == statusViolated {
|
||||||
e.violated = true
|
e.violated = true
|
||||||
e.pending = nil
|
e.pending = nil
|
||||||
e.violation = &Violation{
|
e.violation = &Violation{
|
||||||
Formula: obligation,
|
Formula: entry.formula,
|
||||||
Reason: finalizeReason(obligation),
|
Reason: finalizeReason(entry.formula),
|
||||||
Step: e.steps,
|
Step: entry.origin,
|
||||||
}
|
}
|
||||||
return VerdictViolated
|
return VerdictViolated
|
||||||
}
|
}
|
||||||
@@ -224,9 +245,9 @@ func (e *Evaluator) Residual() Formula {
|
|||||||
if len(e.pending) == 0 {
|
if len(e.pending) == 0 {
|
||||||
return PureFormula{Value: true}
|
return PureFormula{Value: true}
|
||||||
}
|
}
|
||||||
combined := e.pending[0]
|
combined := e.pending[0].formula
|
||||||
for _, formula := range e.pending[1:] {
|
for _, entry := range e.pending[1:] {
|
||||||
combined = AndFormula{Left: combined, Right: formula}
|
combined = AndFormula{Left: combined, Right: entry.formula}
|
||||||
}
|
}
|
||||||
return combined
|
return combined
|
||||||
}
|
}
|
||||||
@@ -258,11 +279,6 @@ type reduceResult struct {
|
|||||||
|
|
||||||
func holds() reduceResult { return reduceResult{status: statusHolds} }
|
func holds() reduceResult { return reduceResult{status: statusHolds} }
|
||||||
|
|
||||||
// violated reports a violation without an attached witness. Used where the
|
|
||||||
// failing sub-formula is recovered from a child result whose own witness is
|
|
||||||
// carried up by violatedFrom.
|
|
||||||
func violated() reduceResult { return reduceResult{status: statusViolated} }
|
|
||||||
|
|
||||||
// violatedWith reports a violation that originates at the given sub-formula
|
// violatedWith reports a violation that originates at the given sub-formula
|
||||||
// with the given reason. The reason distinguishes a thrown predicate from a
|
// with the given reason. The reason distinguishes a thrown predicate from a
|
||||||
// plain false so callers (and the replay UI) can render the cause.
|
// plain false so callers (and the replay UI) can render the cause.
|
||||||
|
|||||||
@@ -128,20 +128,23 @@ func TestViolationLatchIsMonotonic(t *testing.T) {
|
|||||||
}
|
}
|
||||||
|
|
||||||
func TestCollapse_IdenticalObligationsMerge(t *testing.T) {
|
func TestCollapse_IdenticalObligationsMerge(t *testing.T) {
|
||||||
merged := collapse([]Formula{
|
merged := collapse([]obligation{
|
||||||
Next(Pure(true)),
|
{formula: Next(Pure(true)), origin: 1},
|
||||||
Next(Pure(true)),
|
{formula: Next(Pure(true)), origin: 2},
|
||||||
Next(Pure(true)),
|
{formula: Next(Pure(true)), origin: 3},
|
||||||
})
|
})
|
||||||
if len(merged) != 1 {
|
if len(merged) != 1 {
|
||||||
t.Errorf("expected 1 obligation after collapse, got %d", len(merged))
|
t.Errorf("expected 1 obligation after collapse, got %d", len(merged))
|
||||||
}
|
}
|
||||||
|
if merged[0].origin != 1 {
|
||||||
|
t.Errorf("collapse must keep the earliest origin, got %d", merged[0].origin)
|
||||||
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
func TestCollapse_DistinctPredicatesDoNotMerge(t *testing.T) {
|
func TestCollapse_DistinctPredicatesDoNotMerge(t *testing.T) {
|
||||||
merged := collapse([]Formula{
|
merged := collapse([]obligation{
|
||||||
Eventually(ThunkNamed("p3", func() (bool, error) { return false, nil })),
|
{formula: Eventually(ThunkNamed("p3", func() (bool, error) { return false, nil }))},
|
||||||
Eventually(ThunkNamed("p4", func() (bool, error) { return false, nil })),
|
{formula: Eventually(ThunkNamed("p4", func() (bool, error) { return false, nil }))},
|
||||||
})
|
})
|
||||||
if len(merged) != 2 {
|
if len(merged) != 2 {
|
||||||
t.Errorf("distinct predicates must not merge, got %d", len(merged))
|
t.Errorf("distinct predicates must not merge, got %d", len(merged))
|
||||||
|
|||||||
@@ -71,6 +71,80 @@ func TestViolation_FinalizeFillsWitness(t *testing.T) {
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
func TestViolation_NextAttributesOriginStep(t *testing.T) {
|
||||||
|
// always(next(p)): the obligation spawned at step 2 is checked against
|
||||||
|
// step 3's state; the violation belongs to step 2, the step that caused it.
|
||||||
|
values := []bool{true, false}
|
||||||
|
step := 0
|
||||||
|
evaluator := NewEvaluator(Always(Next(ThunkNamed("p", func() (bool, error) {
|
||||||
|
current := values[step]
|
||||||
|
step++
|
||||||
|
return current, nil
|
||||||
|
}))))
|
||||||
|
if got := evaluator.ObserveAt(time.Unix(0, 0)); got != VerdictPending {
|
||||||
|
t.Fatalf("step 1: got %v, want pending", got)
|
||||||
|
}
|
||||||
|
if got := evaluator.ObserveAt(time.Unix(1, 0)); got != VerdictPending {
|
||||||
|
t.Fatalf("step 2: got %v, want pending", got)
|
||||||
|
}
|
||||||
|
if got := evaluator.ObserveAt(time.Unix(2, 0)); got != VerdictViolated {
|
||||||
|
t.Fatalf("step 3: got %v, want violated", got)
|
||||||
|
}
|
||||||
|
witness := evaluator.Violation()
|
||||||
|
if witness == nil {
|
||||||
|
t.Fatal("Violation = nil, want non-nil")
|
||||||
|
}
|
||||||
|
if witness.Step != 2 {
|
||||||
|
t.Errorf("Step = %d, want 2 (the step that spawned the next obligation)", witness.Step)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestViolation_FinalizeAttributesOriginStep(t *testing.T) {
|
||||||
|
evaluator := NewEvaluator(Always(Next(ThunkNamed("p", func() (bool, error) {
|
||||||
|
return true, nil
|
||||||
|
}))))
|
||||||
|
evaluator.ObserveAt(time.Unix(0, 0))
|
||||||
|
evaluator.ObserveAt(time.Unix(1, 0))
|
||||||
|
if got := evaluator.Finalize(); got != VerdictViolated {
|
||||||
|
t.Fatalf("Finalize = %v, want violated", got)
|
||||||
|
}
|
||||||
|
witness := evaluator.Violation()
|
||||||
|
if witness == nil {
|
||||||
|
t.Fatal("Violation = nil after Finalize, want non-nil")
|
||||||
|
}
|
||||||
|
if witness.Step != 2 {
|
||||||
|
t.Errorf("Step = %d, want 2 (the step whose next obligation has no successor)", witness.Step)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestViolation_ObserveAtStepUsesCallerNumbering(t *testing.T) {
|
||||||
|
// The caller skips step 5 (a transitional step the verifier never saw); the
|
||||||
|
// origin must carry the caller's labels, not a contiguous internal count.
|
||||||
|
values := []bool{true, false}
|
||||||
|
step := 0
|
||||||
|
evaluator := NewEvaluator(Always(Next(ThunkNamed("p", func() (bool, error) {
|
||||||
|
current := values[step]
|
||||||
|
step++
|
||||||
|
return current, nil
|
||||||
|
}))))
|
||||||
|
if got := evaluator.ObserveAtStep(time.Unix(0, 0), 3); got != VerdictPending {
|
||||||
|
t.Fatalf("step 3: got %v, want pending", got)
|
||||||
|
}
|
||||||
|
if got := evaluator.ObserveAtStep(time.Unix(1, 0), 4); got != VerdictPending {
|
||||||
|
t.Fatalf("step 4: got %v, want pending", got)
|
||||||
|
}
|
||||||
|
if got := evaluator.ObserveAtStep(time.Unix(2, 0), 6); got != VerdictViolated {
|
||||||
|
t.Fatalf("step 6: got %v, want violated", got)
|
||||||
|
}
|
||||||
|
witness := evaluator.Violation()
|
||||||
|
if witness == nil {
|
||||||
|
t.Fatal("Violation = nil, want non-nil")
|
||||||
|
}
|
||||||
|
if witness.Step != 4 {
|
||||||
|
t.Errorf("Step = %d, want 4 (caller-labeled origin, not detection step 6)", witness.Step)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
func TestViolation_NilBeforeViolation(t *testing.T) {
|
func TestViolation_NilBeforeViolation(t *testing.T) {
|
||||||
evaluator := NewEvaluator(Always(Pure(true)))
|
evaluator := NewEvaluator(Always(Pure(true)))
|
||||||
evaluator.Observe()
|
evaluator.Observe()
|
||||||
|
|||||||
Reference in new issue
Block a user