Skip to content

test(storage): the object store's refusals are exercised - #1069

Merged
cryptskii merged 2 commits into
mainfrom
test/storage-node-unexercised-refusals
Sep 30, 2026
Merged

cryptskii merged 2 commits into
mainfrom
test/storage-node-unexercised-refusals

Conversation

@cryptskii

Copy link
Copy Markdown
Collaborator

What

Four storage-node requirement rows were Partial only because no test reached the branch that enforces them. This adds those tests. No production code changes.

Row Rule (storage spec) Test (dsm_storage_node::immutable_store_round_trip::…)
MR-STOR-0023 §5.2: a caller-supplied address is a check, never the key a_put_stating_another_address_is_refused_and_nothing_is_held
MR-STOR-0025 §5.4: different bytes at an address are reported as corruption different_bytes_at_an_address_are_reported_as_corruption
MR-STOR-0026 §5.5: the node recomputes the address before serving a_held_object_that_no_longer_hashes_to_its_address_is_not_served
MR-STOR-0016 §3.4: a misresponse is detectable by hash and affects availability only the same, with dsm::sofi::storage::tests::wrong_bytes_never_count on the reader's side

The damaged-row tests change a held row directly in Postgres, the way a failing disk would. That puts the store outside the fault model (§3), which is exactly the case these refusals exist for.

Mutation controls

Each mutant compiled, and its named test failed at the intended assertion. The source was restored to main's after each.

Mutation Failed at
The stated-address comparison in put_immutable never refuses a_put_stating…: 201 where 422 is expected
get_immutable serves without recomputing the address a_held_object…: 200 where 500 is expected
put_immutable answers a conflict as an ack different_bytes…: 200 where 500 is expected

Evidence pins

The existing tests' helpers (member, put, get) are untouched, so no pinned evidence closure moves. The new tests have their own helpers, member_and_store and put_stating.

Records

  • CONFORMANCE §6.41 (new), and §8 rows 0016, 0023, 0025 and 0026, now Met.
  • Three verification-matrix rows with their mutation controls.
  • Totals regenerated (ci/conformance_evidence.py --write).

Runs

  • cargo test --locked -p dsm_storage_node --release -- --nocapture --test-threads=1: 64 passed, 0 failed, 0 ignored, on the rebased tree.
  • cargo fmt --all -- --check and cargo clippy --all-targets -- -D warnings (pinned 1.98.0): exit 0.
  • The frontend half of make lint was not run locally: this worktree has no node_modules, and this change touches no frontend file.

Four storage rows were Partial only because no test reached the branch that
enforces them. Each now has a test on the assembly the node serves, on
Postgres, and each test was observed red with its branch removed:

- MR-STOR-0023 (spec §5.2): a put stating the address of other bytes is
  refused, and nothing is held at either address.
- MR-STOR-0025 (§5.4): different bytes at an address are reported as
  corruption, and the held row is left as it was.
- MR-STOR-0026 (§5.5): a held row damaged in place, in its payload or its
  namespace, is never served; an intact object beside it still is.
- MR-STOR-0016 (§3.4): the same refusal on the node, with Core's re-hash
  (`wrong_bytes_never_count`) on the reader's side.

The existing tests' helpers are untouched, so no pinned evidence moves; the
new tests have their own (`member_and_store`, `put_stating`).

CONFORMANCE §6.41 and §8, and the verification matrix, record the rows and
their mutation controls; the totals are regenerated.
cryptskii added a commit that referenced this pull request Sep 30, 2026
A change that touches the storage node and not the SDK runs the
`sdk-node-protocol` group, which named four SDK suites that no longer exist:

- `b0x_integration` (deleted in #977) and `storage_full_lifecycle` (deleted in
  #932), integration targets. cargo refuses an unknown target, so the group
  failed on the first storage-only PR since then (#1069).
- `sdk::storage_sync_sdk` and `sdk::storage_node_health`, lib filters. A
  filter that matches nothing runs nothing and passes, so these narrowed the
  group's coverage silently.

The four names are removed. No SDK integration binary exercises the
storage-node contract now, so the group runs one command: the four lib
suites that do (`handlers::storage_routes`, `sdk::storage_node_sdk`,
`sdk::b0x_sdk`, `sdk::storage_set`).

The selector's self-test now refuses a lib filter that does not resolve to a
module of dsm_sdk (`test_every_named_sdk_suite_is_a_module_that_exists`).
Mutation control: `sdk::storage_sync_sdk` put back, the test is red.
Signed-off-by: Cryptskii <47649969+cryptskii@users.noreply.github.com>
@cryptskii
cryptskii merged commit 375506f into main Sep 30, 2026
12 of 13 checks passed
cryptskii added a commit that referenced this pull request Sep 30, 2026
…numbered once (#1071)

#1065, #1066 and #1069 merged together and left main (375506f) with
three defects in its records.

Evidence pins. #1066 moved code that 266 pins cover, and it merged before
they were refreshed, so Code map is red on main and on every PR based on
it. They are refreshed at 375506f:
- against CI's code map of that commit, whose tree fingerprint equals this
  tree's;
- the stale rows' evidence, 156 tests in 13 cargo runs, run here in
  release: 156 passed, 0 failed, 0 ignored;
- 264 rows moved only in code, repinned as a code refresh;
- MR-DSM-0114 and MR-DSM-0119 on
  `dsm::merkle::sparse_merkle_tree::DEFAULT_SMT_HEIGHT` (android) also moved
  in reading, REACHED_VIA_DISPATCH to REACHED: #1066 defines `const
  LEAF_LEVEL: usize = DEFAULT_SMT_HEIGHT as usize;` (sparse_merkle_tree.rs:154),
  and the map reaches the height through it. Accepted with --accept reading.
Exactly those 266 rows changed. The comparator reads 0 failing rows and
581 of 581 pins PINNED.

Totals. #1069's branch update kept both sides of the `All` row, and
neither was the count. Regenerated by ci/conformance_evidence.py --write:
340 Met, 233 Partial, 117 Missing, 10 Violated, 64 Not code, 154 Deferred.

§6 numbering. Three sections were numbered 6.41. They now run in merge
order:
- 6.41 is #1065; its six citations are unchanged;
- 6.42 is #1066; nothing cites it;
- 6.43 is #1069, moved after the other two, and its four row citations
  (MR-STOR-0016, 0023, 0025, 0026) now read §6.43.
Two headings get back the blank line the merge dropped. Nothing else in the
file changed.

No code changes.
cryptskii added a commit that referenced this pull request Sep 30, 2026
…erified

CONFORMANCE_GAPS.md conflicted in §6 and §7. Resolved:
- §6 keeps main's order, 6.41 #1065, 6.42 #1066, 6.43 #1069, and this
  branch's section follows as 6.44. Its nine §8 references (MR-DSM-0017,
  0019 twice, 0046, 0056, 0126, 0138, 0141, 0170) now read §6.44. The four
  MR-STOR rows keep §6.43, as on main.
- §7 is regenerated by ci/conformance_evidence.py --write: 343 Met,
  229 Partial, 118 Missing, 10 Violated, 64 Not code, 154 Deferred, the sum
  of the subtotal rows.
Every section body is byte-identical on both sides; only numbers moved.

From main this brings the refreshed pins (#1071). This branch still owes
pins for its eight new manifest rows.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant