|
| 1 | +# Substrate-signed LLM ↔ LLM messaging. |
| 2 | + |
| 3 | +fn assert_eq(actual, expected, msg) { |
| 4 | + if actual != expected { |
| 5 | + test_record_failure(msg + ": expected " + to_string(expected) + " got " + to_string(actual)); |
| 6 | + } |
| 7 | +} |
| 8 | + |
| 9 | +fn assert_true(cond, msg) { if !cond { test_record_failure(msg); } } |
| 10 | + |
| 11 | +# Basic sign + verify round-trip |
| 12 | +fn test_sign_verify_roundtrip() { |
| 13 | + h msg = omc_msg_sign("fn f(x) { return x; }", 42, 1); |
| 14 | + h check = omc_msg_verify(msg); |
| 15 | + assert_eq(dict_get(check, "valid"), 1, "signed message verifies"); |
| 16 | + assert_eq(dict_get(check, "sender_id"), 42, "sender preserved"); |
| 17 | + assert_eq(dict_get(check, "kind"), 1, "kind preserved"); |
| 18 | +} |
| 19 | + |
| 20 | +# Tampered content fails verification |
| 21 | +fn test_tampered_content_fails() { |
| 22 | + h msg = omc_msg_sign("fn original() { return 1; }", 7, 2); |
| 23 | + # Tamper with content but keep stale signature. |
| 24 | + dict_set(msg, "content", "fn tampered() { return 99; }"); |
| 25 | + h check = omc_msg_verify(msg); |
| 26 | + assert_eq(dict_get(check, "valid"), 0, "tampered → invalid"); |
| 27 | +} |
| 28 | + |
| 29 | +# Tampered hash fails verification |
| 30 | +fn test_tampered_hash_fails() { |
| 31 | + h msg = omc_msg_sign("fn f() {}", 7, 1); |
| 32 | + dict_set(msg, "content_hash", 12345); # garbage |
| 33 | + h check = omc_msg_verify(msg); |
| 34 | + assert_eq(dict_get(check, "valid"), 0, "bad hash → invalid"); |
| 35 | +} |
| 36 | + |
| 37 | +# Whitespace + alpha-rename are SIGNATURE-PRESERVING |
| 38 | +# (because content is canonicalized before hashing) |
| 39 | +fn test_whitespace_invariant_signature() { |
| 40 | + h m1 = omc_msg_sign("fn f(x) { return x; }", 1, 1); |
| 41 | + h m2 = omc_msg_sign("fn f ( x ) { return x ; }", 1, 1); |
| 42 | + assert_eq(dict_get(m1, "content_hash"), dict_get(m2, "content_hash"), |
| 43 | + "whitespace doesn't change signature"); |
| 44 | +} |
| 45 | + |
| 46 | +fn test_alpha_rename_invariant_signature() { |
| 47 | + h m1 = omc_msg_sign("fn f(x) { return x; }", 1, 1); |
| 48 | + h m2 = omc_msg_sign("fn f(y) { return y; }", 1, 1); |
| 49 | + assert_eq(dict_get(m1, "content_hash"), dict_get(m2, "content_hash"), |
| 50 | + "alpha-rename doesn't change signature"); |
| 51 | +} |
| 52 | + |
| 53 | +# Serialize → wire → deserialize → verify |
| 54 | +fn test_wire_format_roundtrip() { |
| 55 | + h msg = omc_msg_sign("fn add(x, y) { return x + y; }", 99, 3); |
| 56 | + h wire = omc_msg_serialize(msg); |
| 57 | + assert_true(str_len(wire) > 0, "wire is non-empty"); |
| 58 | + h received = omc_msg_deserialize(wire); |
| 59 | + h check = omc_msg_verify(received); |
| 60 | + assert_eq(dict_get(check, "valid"), 1, "wire-roundtrip valid"); |
| 61 | + assert_eq(dict_get(check, "sender_id"), 99, "sender preserved"); |
| 62 | +} |
| 63 | + |
| 64 | +# Different senders produce different packed IDs |
| 65 | +fn test_packed_id_distinguishes_senders() { |
| 66 | + h m1 = omc_msg_sign("fn f() {}", 1, 1); |
| 67 | + h m2 = omc_msg_sign("fn f() {}", 2, 1); |
| 68 | + assert_true(dict_get(m1, "packed") != dict_get(m2, "packed"), |
| 69 | + "different senders → different packed"); |
| 70 | +} |
| 71 | + |
| 72 | +# Different content produces different hashes |
| 73 | +fn test_different_content_different_hash() { |
| 74 | + h m1 = omc_msg_sign("fn f() { return 1; }", 1, 1); |
| 75 | + h m2 = omc_msg_sign("fn f() { return 2; }", 1, 1); |
| 76 | + assert_true(dict_get(m1, "content_hash") != dict_get(m2, "content_hash"), |
| 77 | + "different content → different hash"); |
| 78 | +} |
| 79 | + |
| 80 | +# Substrate metadata is recomputable (the verification check) |
| 81 | +fn test_substrate_metadata_recomputable() { |
| 82 | + h msg = omc_msg_sign("hello", 1, 1); |
| 83 | + h check = omc_msg_verify(msg); |
| 84 | + # drift_resonance should be near 0 since we just signed it. |
| 85 | + assert_true(dict_get(check, "drift_resonance") < 0.0001, |
| 86 | + "no resonance drift on fresh sign"); |
| 87 | +} |
| 88 | + |
| 89 | +# Empty content still produces a valid signed message |
| 90 | +fn test_empty_content_signs() { |
| 91 | + h msg = omc_msg_sign("", 0, 0); |
| 92 | + h check = omc_msg_verify(msg); |
| 93 | + assert_eq(dict_get(check, "valid"), 1, "empty signs valid"); |
| 94 | +} |
0 commit comments