Commit Graph

2 Commits

Author SHA1 Message Date
John Dvorak 440230b2c5 fix: caller clock everywhere — value TTL, decay, qualitative decay, cache TTL
CI / test (push) Successful in 5m52s
CI / benchmark (push) Successful in 22s
CI / publish (push) Has been skipped
The principle: time is caller-provided (options.now / partialGraph.now);
the wall clock is only the fallback for unpinned callers, never a hidden
decision input. Remaining clock leaks:

- getBlurredValue gained an optional now param threaded to _isValueExpired;
  ChainRule (2 sites), MultiHopRule (2 sites), RelationManager (3 sites)
  now pass the caller clock. Previously a pinned-clock caller's chain/
  multi-hop value TTL used the WALL clock (wall in 2026, pinned T0 in
  2001 -> values wrongly expired).
- MultiHopRule's TTL gate used valueFilters.ttl || 24h instead of the
  valueManager's per-relation TTL (inconsistent with chain/comparator);
  now valueManager.getTTL is the authority, valueFilters.ttl the override.
- QualitativeRelationalComparatorRule decay (_calculatePeriodsElapsed)
  and value timestamps used the wall clock, so qualitative possibility
  decay ignored the pinned clock; now threaded through _evaluateOperand.
- ValueManager decay internals (getDecayedRelation, _calculateSeparated
  Decay, _calculateBlurredValue) accept a now param (background worker
  still passes none -> wall clock is correct there).
- PartialGraphContext._addChallengeProof/_addRelation used Date.now()
  instead of the context's own this.now (the partial graph's time).
- Arbiter gained an injectable clock (options.clock) driving unpinned
  cache-entry freshness in DecisionCache, RuleEvaluator, ChainRule, and
  RelationalComparatorRule; DecisionCache explicit clock still wins.
- Collected-value timestamps in DirectRule and RelationalComparatorRule
  honor the caller clock.

Pinned-clock chain probe: values fresh at T0, expired at T0+61s, with the
wall clock in 2026. Rigor 251/251, full suite 853/791/0.
2026-08-02 17:50:24 -07:00
John Dvorak 717ae1031e initial commit: @arbiter/core authorization engine with js-rigor hardening
Zanzibar-style authorization graph engine (direct/chain/TTU/defeasible/
binary modes, condensed snapshots, value relations) with 39 rigor test
campaigns. Includes fixes for snapshot binary writer/reader format
mismatch (snapshot-of-snapshot corruption), possibility write-boundary
validation, empty-graph snapshot serialization, relation lookup cache
direction collision, config-redefinition cache invalidation, binary
threshold semantics, defeasible compiled routing, and comparator
reason whitelisting.
2026-07-31 13:44:06 -07:00