Files
sanderling/internal/ltl/finalize_test.go
T
pj 94d9511312 test: full test-suite refactor sweep (#61)
* chore(test): start test-suite refactor sweep

* test(ltl): pin exact multi-obligation residual AST

* test(ltl): table-test finalize Kleene connective combinations

* test(ltl): pin reduce over pending inner for bound, Or, Not

* test(ltl): marshal bounded Always steps/duration/deadline

* test(verifier): cover LTL combinator verdict transitions and within unit panic

* test(verifier): table-test DecodeAction kinds and lastAction field exposure

* test(verifier): assert WithPlatform(ios) reaches the picker host and key pool

* test(verifier): widen weighted-selection assertion to a 5x skew margin

* test(verifier): un-skip ax-find round trip with a committed tree fixture

* test(runner): pin isWDADrop to sidecar reconnect-failed message origin

* test(runner): assert PressKey/Wait trace encoding records kind-specific fields

* test(runner): cover RenderSummary unsupported-verbs surfacing branch

* test(trace): set Hierarchy in round-trip and lock lossy Tree contract

Also add a -race concurrent WriteStep test that asserts N well-formed JSONL lines, catching torn lines if the writer mutex is dropped.

* test(trace): round-trip witnesses/changes/metrics/exceptions, pin step-0 witness

* test(trace): document ViolationsAreGreppable grep contract and lock-free WriteScreenshot

* test(hierarchy): cover invalid-JSON and malformed-bounds parser paths

* test(trace): guard writer mutex via WriteStep/Close race on w.file

* test(replay): drop unfailable assets and devproxy assertions

* test(replay): cache reuses on equal mtime, reparses after append

* test(replay): violation marker falls back to detection step when attributed missing

* test(replay): corrupt meta/trace dirs return 500 with error body

* test(replay): SSE client receives runs.changed after a broadcast

* test(replay): Run coalesces creates, ignores write/chmod, closes subs on cancel

* fix(sidecar): synchronize health fixture writes and exercise healthError

* test(sidecar): cover swipe/longpress/doubletap/erase/presskey/metrics/logs translations

* test(sidecar): cover DoubleTapSelector composition and mid-gesture cancel

* test(sidecar): assert gRPC error status surfaces from action RPC

* fix(chrome): route action methods through runCtx so caller cancellation aborts CDP

* fix(chrome): route hierarchy/screenshot/waitidle/metrics through runCtx

* refactor(ios): extract pure simctl JSON parsers

* refactor(ios): add command-runner seams for EnsureSimulator

* test(ios): table-test simctl parsers and EnsureSimulator seams

* test(sidecarassets): cover placeholder build path

* test(sidecarassets): assert reuse via sentinel bytes not mtime

* test(bundler): cover properties-only spec registration

* refactor(testrun): extract prepareBundleInputs from Execute

* test(testrun): cover prepareBundleInputs aliases and missing-runtime error

* test(testrun): table-test resolveRuntimeSibling search edges

* test(testrun): exact-output tests for progressHandler line format

* fix(cmd): point bundle-check aliases at pkg/spec/src

* test(cmd): smoke-test bundle-check resolves spec aliases

* test(cmd): table-test hier-check parse and FindAll on fixture

* test(cmd): unit-test buildBrowseURL deep-link vs root

* test(cmd): drop flaky TestRun_Doctor that launched real Chromium

* test(cmd): pin pipeline error to bundle resolution on web platform

* test(replay-ui): add bun test script

* ci(replay-ui): run bun test via make web-test target

* ci(replay-ui): point bun cache key at replay-ui/bun.lock

* test(replay-ui): exercise real URL encoding and non-ok throw in getJson

* refactor(replay-ui): extract snapshot flatten/getAtPath into lib module

* test(replay-ui): pin snapshot flatten/getAtPath path round-trip

* refactor(replay-ui): extract action selector/format into lib module

* test(replay-ui): pin action selector parse and row formatting

* refactor(replay-ui): share one statusFor between panels

* refactor(replay-ui): extract run-history derivation into lib module

* test(replay-ui): pin shared statusFor precedence and ordering

* test(replay-ui): pin run-history derivation alignment

* refactor(replay-ui): export clampIndex for testing

* refactor(replay-ui): extract keyboard-nav dispatch into pure module

* refactor(replay-ui): extract metrics formatters into lib module

* test(replay-ui): pin clampIndex step boundaries

* test(replay-ui): pin keyboard-nav ownership and key routing

* test(replay-ui): pin metrics formatters and path gap handling

* refactor(sidecar): expose device-output parsers as internal for testing

* test(sidecar): table-test device-output parsers against malformed input

* test(sidecar): cover logcat parsing year inference and line skipping

* test(sidecar): pin pressKey keycode mapping and unknown-key rejection

* test(sidecar): metrics bundleId falls back to launched app and honors override

* test(sidecar): loosen deadline upper bound to tolerate slow CI scheduling

* test(web-runtime): export selector builders for unit tests

* test(web-runtime): guard sanitize cycle, function, and depth limits

* test(web-runtime): table-test selector builder quoting and escaping

* test(sidecar): collapse scalar-forwarding RPC tests into a table

* test(replay-ui): dedup step/summary fixtures into shared module

* test(ios): collapse pickSimulator point-tests into a table
2026-06-06 13:59:08 +05:30

227 lines
8.3 KiB
Go

package ltl
import (
"testing"
"testing/quick"
"time"
)
func TestFinalize_UnboundedEventuallyUnmetIsViolated(t *testing.T) {
evaluator := NewEvaluator(Eventually(ThunkNamed("p", func() (bool, error) { return false, nil })))
for index := range 3 {
if got := evaluator.ObserveAt(time.Unix(int64(index), 0)); got != VerdictPending {
t.Fatalf("step %d: got %v, want pending", index, got)
}
}
if got := evaluator.Finalize(); got != VerdictViolated {
t.Errorf("Finalize = %v, want violated", got)
}
}
func TestFinalize_FinalStepNextIsVacuouslyHolds(t *testing.T) {
// A next obligation pending at run end has no successor state to check;
// the run ending before the check is not a failure (weak next at the
// trace boundary).
evaluator := NewEvaluator(Next(ThunkNamed("p", func() (bool, error) { return true, nil })))
if got := evaluator.Observe(); got != VerdictPending {
t.Fatalf("step 1: got %v, want pending", got)
}
if got := evaluator.Finalize(); got != VerdictHolds {
t.Errorf("Finalize = %v, want holds", got)
}
if witness := evaluator.Violation(); witness != nil {
t.Errorf("Violation = %+v, want nil for a vacuous next", witness)
}
}
func TestFinalize_AlwaysNextNeverReportsAtRunEnd(t *testing.T) {
// always(next(p)): every step spawns a deferred check and the last one is
// always pending when the run ends. That residue must not surface as an
// end-of-run violation.
evaluator := NewEvaluator(Always(Next(ThunkNamed("p", func() (bool, error) { return true, nil }))))
for index := range 3 {
evaluator.ObserveAt(time.Unix(int64(index), 0))
}
if got := evaluator.Finalize(); got != VerdictHolds {
t.Errorf("Finalize = %v, want holds", got)
}
}
func TestFinalize_HoldingRunStaysHolds(t *testing.T) {
evaluator := NewEvaluator(Always(Pure(true)))
evaluator.Observe()
if got := evaluator.Finalize(); got != VerdictHolds {
t.Errorf("Finalize = %v, want holds", got)
}
}
func TestFinalize_AlreadyViolatedStaysViolated(t *testing.T) {
evaluator := NewEvaluator(Always(Pure(false)))
if got := evaluator.Observe(); got != VerdictViolated {
t.Fatalf("expected violated, got %v", got)
}
if got := evaluator.Finalize(); got != VerdictViolated {
t.Errorf("Finalize = %v, want violated", got)
}
}
func TestFinalize_BoundedAlwaysVacuouslyHolds(t *testing.T) {
// A bounded Always whose window never closed (still pending) is safe.
evaluator := NewEvaluator(EventuallyWithinSteps(Pure(false), 5))
evaluator.Observe()
// The negated form of this is a bounded Always; build it directly.
bounded := NewEvaluator(Always(Not(EventuallyWithinSteps(ThunkNamed("p", func() (bool, error) { return false, nil }), 5))))
bounded.Observe()
if got := bounded.Finalize(); got == VerdictViolated {
t.Errorf("bounded always should not finalize to violated, got %v", got)
}
}
// TestEventuallyWithin_ViolatesIffNConsecutiveFalse locks the bounded
// eventually contract: with a step bound of n and an inner that is false for
// the first n observations, the verdict violates exactly at step n, and with at
// least one true observation inside the window it holds.
func TestEventuallyWithin_ViolatesIffNConsecutiveFalse(t *testing.T) {
law := func(boundSeed uint8, trueAtSeed uint8) bool {
bound := int(boundSeed%5) + 1
// trueAt < 0 means inner is never true.
trueAt := int(trueAtSeed)%(bound+2) - 1
step := 0
inner := ThunkNamed("p", func() (bool, error) {
current := trueAt >= 0 && step == trueAt
return current, nil
})
evaluator := NewEvaluator(EventuallyWithinSteps(inner, bound))
satisfiedInWindow := trueAt >= 0 && trueAt < bound
var final Verdict = VerdictPending
for index := range bound {
step = index
final = evaluator.ObserveAt(time.Unix(int64(index), 0))
if final == VerdictHolds || final == VerdictViolated {
break
}
}
if satisfiedInWindow {
return final == VerdictHolds
}
return final == VerdictViolated
}
if err := quick.Check(law, nil); err != nil {
t.Error(err)
}
}
// TestViolationLatchIsMonotonic locks: once an evaluator reports Violated, every
// subsequent observation (and Finalize) stays Violated regardless of inputs.
func TestViolationLatchIsMonotonic(t *testing.T) {
law := func(seed uint64) bool {
values := make([]bool, 8)
for index := range values {
values[index] = (seed>>uint(index))&1 == 1
}
step := 0
evaluator := NewEvaluator(Always(ThunkNamed("p", func() (bool, error) {
current := values[step%len(values)]
step++
return current, nil
})))
seenViolated := false
for index := range 16 {
got := evaluator.ObserveAt(time.Unix(int64(index), 0))
if got == VerdictViolated {
seenViolated = true
} else if seenViolated {
return false
}
}
if seenViolated && evaluator.Finalize() != VerdictViolated {
return false
}
return true
}
if err := quick.Check(law, nil); err != nil {
t.Error(err)
}
}
// TestFinalize_KleeneConnectives locks the soundness guarantee in finalize's
// doc comment: an indefinite (pending) operand must never let a connective
// manufacture a definite verdict. Bug class: a pending side collapsing to
// holds/violated at run end, making sanderling lie about pass/fail.
func TestFinalize_KleeneConnectives(t *testing.T) {
pure := func(v bool) Formula { return PureFormula{Value: v} }
pendingThunk := ThunkFormula{Name: "t", Func: func() (bool, error) { return true, nil }}
eventuallyViolated := EventuallyFormula{Inner: PureFormula{Value: false}}
nextPending := NextFormula{Inner: PureFormula{Value: true}}
alwaysHolds := AlwaysFormula{Inner: PureFormula{Value: true}}
cases := []struct {
name string
formula Formula
want residualStatus
}{
{"and-pending-violated", AndFormula{Left: pendingThunk, Right: eventuallyViolated}, statusViolated},
{"and-violated-pending", AndFormula{Left: nextPending, Right: eventuallyViolated}, statusViolated},
{"and-pending-holds", AndFormula{Left: pendingThunk, Right: alwaysHolds}, statusPending},
{"and-holds-holds", AndFormula{Left: pure(true), Right: alwaysHolds}, statusHolds},
{"or-pending-violated", OrFormula{Left: pendingThunk, Right: eventuallyViolated}, statusPending},
{"or-pending-holds", OrFormula{Left: pendingThunk, Right: alwaysHolds}, statusHolds},
{"or-violated-violated", OrFormula{Left: pure(false), Right: eventuallyViolated}, statusViolated},
{"not-pending", NotFormula{Inner: pendingThunk}, statusPending},
{"not-violated", NotFormula{Inner: eventuallyViolated}, statusHolds},
{"not-holds", NotFormula{Inner: alwaysHolds}, statusViolated},
{"implies-pending-violated", ImpliesFormula{Antecedent: pendingThunk, Consequent: eventuallyViolated}, statusPending},
{"implies-holds-violated", ImpliesFormula{Antecedent: alwaysHolds, Consequent: eventuallyViolated}, statusViolated},
{"implies-violated-pending", ImpliesFormula{Antecedent: eventuallyViolated, Consequent: nextPending}, statusHolds},
{"now-violated", NowFormula{Inner: eventuallyViolated}, statusViolated},
{"now-pending", NowFormula{Inner: nextPending}, statusPending},
}
for _, tc := range cases {
if got := finalize(tc.formula); got != tc.want {
t.Errorf("%s: finalize = %v, want %v", tc.name, got, tc.want)
}
}
}
func TestCollapse_IdenticalObligationsMerge(t *testing.T) {
merged := collapse([]obligation{
{formula: Next(Pure(true)), origin: 1},
{formula: Next(Pure(true)), origin: 2},
{formula: Next(Pure(true)), origin: 3},
})
if len(merged) != 1 {
t.Errorf("expected 1 obligation after collapse, got %d", len(merged))
}
if merged[0].origin != 1 {
t.Errorf("collapse must keep the earliest origin, got %d", merged[0].origin)
}
}
func TestCollapse_DistinctPredicatesDoNotMerge(t *testing.T) {
merged := collapse([]obligation{
{formula: Eventually(ThunkNamed("p3", func() (bool, error) { return false, nil }))},
{formula: Eventually(ThunkNamed("p4", func() (bool, error) { return false, nil }))},
})
if len(merged) != 2 {
t.Errorf("distinct predicates must not merge, got %d", len(merged))
}
}
func TestCollapse_NamedThunkLeakBoundsPendingSet(t *testing.T) {
// Always(Eventually(sameThunk)): each step spawns an identical obligation.
// Without collapse the pending set grows unboundedly.
evaluator := NewEvaluator(Always(Eventually(ThunkNamed("p", func() (bool, error) { return false, nil }))))
for index := range 20 {
evaluator.ObserveAt(time.Unix(int64(index), 0))
}
if len(evaluator.pending) > 2 {
t.Errorf("pending set leaked to %d obligations", len(evaluator.pending))
}
}