Files
core/tests/rigor/relational-comparator-rule.test.js
T
John Dvorak 4fd4e20bd0 js-rigor: reliability flows through every rule kind; multi_hop value collection fixed
Systemic reliability gap found by the probe sweep: the compiled evaluation
paths never emitted the reliability the engine computes.

- Compiled _evaluateDirect omitted the relation's reliability, and the
  chain/multi_hop rules hardcoded reliability: 1.0 — so check() results
  reported 1.0 for any rule whose decision came through a chain, multi_hop,
  union, intersection, exclusion, or defeasible combination.
- The chain and multi_hop traversals now track per-path reliability (product
  of edge reliabilities) and report the winning path's value; the compiled
  and fallback logical operators (union/intersection/exclusion, direct_list
  fast path, early exits) report the selected child's reliability
  (max/min child or OWA trace index; exclusion multiplies both legs), and
  normal-mode defeasible combines base x requires x defeater reliabilities.
- The checker's logical fast path dropped collectedValues from union/
  intersection/exclusion results; it now passes them through.
- MultiHopRule.valueManager was read off relationManager where the real
  arbiter keeps it on the arbiter — collectValues: true on a multi_hop rule
  with a value-carrying edge crashed the evaluation (error result, silent
  denial). Now resolved at the arbiter level with a relationManager
  fallback for stubs.

Campaign pins: reliability per kind (chain/multi_hop product, union/intersection
selected child, exclusion/defeasible product), and multi_hop value collection
through persistent and partial contexts.
2026-08-01 09:52:31 -07:00

231 lines
11 KiB
JavaScript

/**
* rigor/relational-comparator-rule.test.js — js-rigor property tests for RelationalComparatorRule.
*
* RelationalComparatorRule compares values from two operands (rules) and returns
* access based on whether the comparison holds. Properties verified:
*
* - left > right (with sufficient gap) → high possibility, reason='values_compared_comparison_true'
* - left < right → 0 possibility, reason='values_compared_comparison_false'
* - left == right (with epsilon tolerance) → comparison true
* - missing left operand → fallbackBehavior 'deny' yields 0
* - missing left operand → fallbackBehavior 'allow' yields high possibility
* - result.possibility ∈ [0, 1]
* - minRulePossibility threshold: possibilities below it drop to 0
* - result has stable shape (possibility, reliability, reason, meta)
*/
import { describe, it, beforeEach } from 'node:test';
import assert from 'node:assert/strict';
import { rigor } from '@rigor/core';
import { Arbiter } from '../../src/index.js';
import { RuleEvaluator } from '../../src/authorization/RuleEvaluator.js';
import { RelationalComparatorRule } from '../../src/authorization/rules/RelationalComparatorRule.js';
let arbiter, ruleEvaluator, comparatorRule;
beforeEach(() => {
arbiter = new Arbiter();
ruleEvaluator = new RuleEvaluator(arbiter);
comparatorRule = new RelationalComparatorRule(arbiter, ruleEvaluator);
// Set up minimal relations
arbiter.addNode('user:alice', 'user');
arbiter.addNode('doc:secret', 'doc');
arbiter.setRelationConfig('has_balance', { type: 'direct' });
arbiter.setRelationConfig('has_price', { type: 'direct' });
});
function evalRule(userKey, objectKey, rule, options = {}) {
const userId = arbiter.resolveNodeId(userKey);
const objectId = arbiter.resolveNodeId(objectKey);
return comparatorRule._evaluateRule(userId, userKey, objectId, objectKey, rule, new Set(), null, { collectValues: true, includeMeta: true, ...options });
}
describe('RelationalComparatorRule evaluation (rigor)', () => {
it('left > right → high possibility, reason=values_compared_comparison_true', async () => {
async function check(balance, price) {
// Skip trivial case where balance == price
if (balance <= price) return null;
arbiter.addRelation('user:alice', 'has_balance', 'doc:secret', { value: balance, possibility: 1.0, changed_last_at: Date.now() });
arbiter.addRelation('doc:secret', 'has_price', 'doc:secret', { value: price, possibility: 1.0, changed_last_at: Date.now() });
const rule = {
type: 'relational_comparator',
comparator: '>',
left: { rule: { type: 'direct', relation: 'has_balance' }, extractValue: true, ttl: 14 * 24 * 60 * 60 * 1000 },
right: { evaluateFrom: 'object', rule: { type: 'direct', relation: 'has_price' }, extractValue: true }
};
const result = evalRule('user:alice', 'doc:secret', rule);
if (result.reason !== 'values_compared_comparison_true') {
throw new Error(`expected reason='values_compared_comparison_true', got '${result.reason}' (balance=${balance}, price=${price})`);
}
if (result.possibility <= 0.5) {
throw new Error(`expected high possibility when balance > price, got ${result.possibility}`);
}
return result;
}
const report = await rigor.campaign(
[rigor.fn('check', check,
rigor.args(
rigor.gen.float({ min: 100, max: 10000 }),
rigor.gen.float({ min: 0, max: 99 }) // price always less than balance
)
)],
rigor.crucible([
rigor.invariant('left-gt-right', ({ error, errorMessage }) => !error && !errorMessage)
])
).run({ effort: 800 , artifacts: { dir: '', persist: 'never' }});
if (process.env.TEST_DEBUG === '1') console.log(report.toTAP());
const inv = report.crucibleVerdict?.invariants?.find(i => i.name === 'left-gt-right');
assert.ok(inv);
assert.equal(inv.passed, true, `left > right contract violated in ${inv.failureCount} cases`);
});
it('left < right → 0 possibility, reason=values_compared_comparison_false', async () => {
async function check(balance, price) {
if (balance >= price) return null;
arbiter.addRelation('user:alice', 'has_balance', 'doc:secret', { value: balance, possibility: 1.0, changed_last_at: Date.now() });
arbiter.addRelation('doc:secret', 'has_price', 'doc:secret', { value: price, possibility: 1.0, changed_last_at: Date.now() });
const rule = {
type: 'relational_comparator',
comparator: '>',
left: { rule: { type: 'direct', relation: 'has_balance' }, extractValue: true, ttl: 14 * 24 * 60 * 60 * 1000 },
right: { evaluateFrom: 'object', rule: { type: 'direct', relation: 'has_price' }, extractValue: true }
};
const result = evalRule('user:alice', 'doc:secret', rule);
if (result.possibility !== 0) {
throw new Error(`expected 0 when balance < price, got ${result.possibility}`);
}
if (result.reason !== 'values_compared_comparison_false') {
throw new Error(`expected reason='values_compared_comparison_false', got '${result.reason}'`);
}
return result;
}
const report = await rigor.campaign(
[rigor.fn('check', check,
rigor.args(
rigor.gen.float({ min: 0, max: 99 }), // balance always less than price
rigor.gen.float({ min: 100, max: 10000 })
)
)],
rigor.crucible([
rigor.invariant('left-lt-right', ({ error, errorMessage }) => !error && !errorMessage)
])
).run({ effort: 800 , artifacts: { dir: '', persist: 'never' }});
if (process.env.TEST_DEBUG === '1') console.log(report.toTAP());
const inv = report.crucibleVerdict?.invariants?.find(i => i.name === 'left-lt-right');
assert.ok(inv);
assert.equal(inv.passed, true, `left < right contract violated in ${inv.failureCount} cases`);
});
it('result.possibility ∈ [0, 1] always', async () => {
async function check(balance, price) {
arbiter.addRelation('user:alice', 'has_balance', 'doc:secret', { value: balance, possibility: 1.0, changed_last_at: Date.now() });
arbiter.addRelation('doc:secret', 'has_price', 'doc:secret', { value: price, possibility: 1.0, changed_last_at: Date.now() });
const rule = {
type: 'relational_comparator',
comparator: '>',
left: { rule: { type: 'direct', relation: 'has_balance' }, extractValue: true, ttl: 14 * 24 * 60 * 60 * 1000 },
right: { evaluateFrom: 'object', rule: { type: 'direct', relation: 'has_price' }, extractValue: true }
};
const result = evalRule('user:alice', 'doc:secret', rule);
if (result.possibility < 0 || result.possibility > 1) {
throw new Error(`possibility=${result.possibility} outside [0,1] (balance=${balance}, price=${price})`);
}
return result;
}
const report = await rigor.campaign(
[rigor.fn('check', check,
rigor.args(
rigor.gen.float({ min: 0, max: 10000 }),
rigor.gen.float({ min: 0, max: 10000 })
)
)],
rigor.crucible([
rigor.invariant('possibility-bounded', ({ error, errorMessage }) => !error && !errorMessage)
])
).run({ effort: 1500 , artifacts: { dir: '', persist: 'never' }});
if (process.env.TEST_DEBUG === '1') console.log(report.toTAP());
const inv = report.crucibleVerdict?.invariants?.find(i => i.name === 'possibility-bounded');
assert.ok(inv);
assert.equal(inv.passed, true, `possibility-bounded violated in ${inv.failureCount} cases`);
});
it('result shape is stable: possibility, reliability, reason, meta always present', async () => {
async function check(balance, price) {
arbiter.addRelation('user:alice', 'has_balance', 'doc:secret', { value: balance, possibility: 1.0, changed_last_at: Date.now() });
arbiter.addRelation('doc:secret', 'has_price', 'doc:secret', { value: price, possibility: 1.0, changed_last_at: Date.now() });
const rule = {
type: 'relational_comparator',
comparator: '>',
left: { rule: { type: 'direct', relation: 'has_balance' }, extractValue: true, ttl: 14 * 24 * 60 * 60 * 1000 },
right: { evaluateFrom: 'object', rule: { type: 'direct', relation: 'has_price' }, extractValue: true }
};
const result = evalRule('user:alice', 'doc:secret', rule);
for (const k of ['possibility', 'reliability', 'reason', 'meta']) {
if (!(k in result)) throw new Error(`result missing key '${k}' (full: ${JSON.stringify(result)})`);
}
return result;
}
const report = await rigor.campaign(
[rigor.fn('check', check,
rigor.args(
rigor.gen.float({ min: 0, max: 10000 }),
rigor.gen.float({ min: 0, max: 10000 })
)
)],
rigor.crucible([
rigor.invariant('result-shape-stable', ({ error, errorMessage }) => !error && !errorMessage)
])
).run({ effort: 800 , artifacts: { dir: '', persist: 'never' }});
if (process.env.TEST_DEBUG === '1') console.log(report.toTAP());
const inv = report.crucibleVerdict?.invariants?.find(i => i.name === 'result-shape-stable');
assert.ok(inv);
assert.equal(inv.passed, true, `result-shape violated in ${inv.failureCount} cases`);
});
it('determinism: same inputs → same result (no Date.now() / randomness)', async () => {
async function check(balance, price) {
arbiter.addRelation('user:alice', 'has_balance', 'doc:secret', { value: balance, possibility: 1.0, changed_last_at: Date.now() });
arbiter.addRelation('doc:secret', 'has_price', 'doc:secret', { value: price, possibility: 1.0, changed_last_at: Date.now() });
const rule = {
type: 'relational_comparator',
comparator: '>',
left: { rule: { type: 'direct', relation: 'has_balance' }, extractValue: true, ttl: 14 * 24 * 60 * 60 * 1000 },
right: { evaluateFrom: 'object', rule: { type: 'direct', relation: 'has_price' }, extractValue: true }
};
const r1 = evalRule('user:alice', 'doc:secret', rule);
const r2 = evalRule('user:alice', 'doc:secret', rule);
if (r1.possibility !== r2.possibility) {
throw new Error(`non-deterministic: ${r1.possibility} vs ${r2.possibility}`);
}
if (r1.reason !== r2.reason) {
throw new Error(`non-deterministic reason: ${r1.reason} vs ${r2.reason}`);
}
return r1;
}
const report = await rigor.campaign(
[rigor.fn('check', check,
rigor.args(
rigor.gen.float({ min: 0, max: 10000 }),
rigor.gen.float({ min: 0, max: 10000 })
)
)],
rigor.crucible([
rigor.invariant('determinism', ({ error, errorMessage }) => !error && !errorMessage)
])
).run({ effort: 800 , artifacts: { dir: '', persist: 'never' }});
if (process.env.TEST_DEBUG === '1') console.log(report.toTAP());
const inv = report.crucibleVerdict?.invariants?.find(i => i.name === 'determinism');
assert.ok(inv);
assert.equal(inv.passed, true, `determinism violated in ${inv.failureCount} cases`);
});
});