diff --git a/next/kernel/envelope.erl b/next/kernel/envelope.erl new file mode 100644 index 00000000..669a4735 --- /dev/null +++ b/next/kernel/envelope.erl @@ -0,0 +1,53 @@ +-module(envelope). +-export([validate_shape/1, get_field/2]). + +%% Activity envelope per design §3.1. +%% +%% Erlang maps (#{...}) are not supported by this port, so envelopes +%% are represented as property lists of {atom_key, value} pairs. This +%% port's binary syntax also can't carry string literals; values that +%% would naturally be binaries in real Erlang are kept as atoms or +%% integer-segment binaries in the test corpus. +%% +%% Required fields: id, type, actor, published, signature. +%% The signature value is itself a property list with key_id, +%% algorithm, value. +%% +%% validate_shape/1 returns ok | {error, Reason}. Reasons: +%% not_a_proplist +%% {missing_field, FieldName} +%% {bad_signature, BadSigReason} +%% +%% get_field/2 returns {ok, Value} | not_found. + +validate_shape(Env) when is_list(Env) -> + case check_required([id, type, actor, published, signature], Env) of + ok -> validate_signature_shape(Env); + Err -> Err + end; +validate_shape(_) -> + {error, not_a_proplist}. + +get_field(_, []) -> not_found; +get_field(K, [{K, V} | _]) -> {ok, V}; +get_field(K, [_ | Rest]) -> get_field(K, Rest). + +check_required([], _) -> ok; +check_required([F | Rest], Env) -> + case get_field(F, Env) of + {ok, _} -> check_required(Rest, Env); + not_found -> {error, {missing_field, F}} + end. + +validate_signature_shape(Env) -> + {ok, Sig} = get_field(signature, Env), + case is_list(Sig) of + true -> + case check_required([key_id, algorithm, value], Sig) of + ok -> ok; + {error, {missing_field, F}} -> + {error, {bad_signature, {missing_field, F}}} + end; + false -> + {error, {bad_signature, not_a_proplist}} + end. diff --git a/next/tests/envelope_shape.sh b/next/tests/envelope_shape.sh new file mode 100755 index 00000000..bc7d1fea --- /dev/null +++ b/next/tests/envelope_shape.sh @@ -0,0 +1,126 @@ +#!/usr/bin/env bash +# next/tests/envelope_shape.sh — Step 2a acceptance test. +# +# Loads next/kernel/envelope.erl into the Erlang-on-SX runtime and +# checks validate_shape/1 / get_field/2 against the design §3.1 shape +# contract. 13 cases. + +set -uo pipefail +cd "$(git rev-parse --show-toplevel)" + +SX_SERVER="${SX_SERVER:-hosts/ocaml/_build/default/bin/sx_server.exe}" +if [ ! -x "$SX_SERVER" ]; then + SX_SERVER="/root/rose-ash/hosts/ocaml/_build/default/bin/sx_server.exe" +fi +if [ ! -x "$SX_SERVER" ]; then + echo "ERROR: sx_server.exe not found." >&2 + exit 1 +fi + +VERBOSE="${1:-}" +PASS=0; FAIL=0; ERRORS="" +TMPFILE=$(mktemp); trap "rm -f $TMPFILE" EXIT + +cat > "$TMPFILE" <<'EPOCHS' +(epoch 1) +(load "lib/erlang/tokenizer.sx") +(load "lib/erlang/parser.sx") +(load "lib/erlang/parser-core.sx") +(load "lib/erlang/parser-expr.sx") +(load "lib/erlang/parser-module.sx") +(load "lib/erlang/transpile.sx") +(load "lib/erlang/runtime.sx") +(load "lib/erlang/vm/dispatcher.sx") + +(epoch 2) +(eval "(get (erlang-load-module (file-read \"next/kernel/envelope.erl\")) :name)") + +;; Reusable valid envelope as Erlang text. The signature itself is a +;; property list with key_id, algorithm, value. +;; E0 = [{id,1},{type,create},{actor,alice},{published,1000}, +;; {signature,[{key_id,k1},{algorithm,ed25519},{value,v}]}] + +;; Complete valid envelope +(epoch 10) +(eval "(get (erlang-eval-ast \"envelope:validate_shape([{id,1},{type,create},{actor,alice},{published,1000},{signature,[{key_id,k1},{algorithm,ed25519},{value,v}]}]) =:= ok\") :name)") + +;; Missing each top-level required field +(epoch 11) +(eval "(get (erlang-eval-ast \"envelope:validate_shape([{type,create},{actor,alice},{published,1000},{signature,[{key_id,k1},{algorithm,ed25519},{value,v}]}]) =:= {error,{missing_field,id}}\") :name)") +(epoch 12) +(eval "(get (erlang-eval-ast \"envelope:validate_shape([{id,1},{actor,alice},{published,1000},{signature,[{key_id,k1},{algorithm,ed25519},{value,v}]}]) =:= {error,{missing_field,type}}\") :name)") +(epoch 13) +(eval "(get (erlang-eval-ast \"envelope:validate_shape([{id,1},{type,create},{published,1000},{signature,[{key_id,k1},{algorithm,ed25519},{value,v}]}]) =:= {error,{missing_field,actor}}\") :name)") +(epoch 14) +(eval "(get (erlang-eval-ast \"envelope:validate_shape([{id,1},{type,create},{actor,alice},{signature,[{key_id,k1},{algorithm,ed25519},{value,v}]}]) =:= {error,{missing_field,published}}\") :name)") +(epoch 15) +(eval "(get (erlang-eval-ast \"envelope:validate_shape([{id,1},{type,create},{actor,alice},{published,1000}]) =:= {error,{missing_field,signature}}\") :name)") + +;; Non-list inputs +(epoch 16) +(eval "(get (erlang-eval-ast \"envelope:validate_shape(42) =:= {error,not_a_proplist}\") :name)") +(epoch 17) +(eval "(get (erlang-eval-ast \"envelope:validate_shape(some_atom) =:= {error,not_a_proplist}\") :name)") + +;; Signature sub-shape +(epoch 20) +(eval "(get (erlang-eval-ast \"envelope:validate_shape([{id,1},{type,create},{actor,alice},{published,1000},{signature,[{algorithm,ed25519},{value,v}]}]) =:= {error,{bad_signature,{missing_field,key_id}}}\") :name)") +(epoch 21) +(eval "(get (erlang-eval-ast \"envelope:validate_shape([{id,1},{type,create},{actor,alice},{published,1000},{signature,[{key_id,k1},{value,v}]}]) =:= {error,{bad_signature,{missing_field,algorithm}}}\") :name)") +(epoch 22) +(eval "(get (erlang-eval-ast \"envelope:validate_shape([{id,1},{type,create},{actor,alice},{published,1000},{signature,[{key_id,k1},{algorithm,ed25519}]}]) =:= {error,{bad_signature,{missing_field,value}}}\") :name)") +(epoch 23) +(eval "(get (erlang-eval-ast \"envelope:validate_shape([{id,1},{type,create},{actor,alice},{published,1000},{signature,not_a_proplist}]) =:= {error,{bad_signature,not_a_proplist}}\") :name)") + +;; get_field +(epoch 30) +(eval "(get (erlang-eval-ast \"envelope:get_field(actor,[{id,1},{actor,alice}]) =:= {ok,alice}\") :name)") +(epoch 31) +(eval "(get (erlang-eval-ast \"envelope:get_field(missing,[{id,1},{actor,alice}]) =:= not_found\") :name)") +EPOCHS + +OUTPUT=$(timeout 120 "$SX_SERVER" < "$TMPFILE" 2>/dev/null) + +check() { + local epoch="$1" desc="$2" expected="$3" + local actual + actual=$(echo "$OUTPUT" | awk -v e="$epoch" ' + $0 ~ "^\\(ok-len " e " " { getline; print; exit } + $0 ~ "^\\(ok " e " " { print; exit } + $0 ~ "^\\(error " e " " { print; exit } + ') + [ -z "$actual" ] && actual="" + if echo "$actual" | grep -qF -- "$expected"; then + PASS=$((PASS+1)) + [ "$VERBOSE" = "-v" ] && echo " ok $desc" + else + FAIL=$((FAIL+1)) + ERRORS+=" FAIL [$desc] (epoch $epoch) expected: $expected | actual: $actual +" + fi +} + +check 2 "module load name" "envelope" +check 10 "complete envelope -> ok" "true" +check 11 "missing id" "true" +check 12 "missing type" "true" +check 13 "missing actor" "true" +check 14 "missing published" "true" +check 15 "missing signature" "true" +check 16 "non-list (integer)" "true" +check 17 "non-list (atom)" "true" +check 20 "signature missing key_id" "true" +check 21 "signature missing algorithm" "true" +check 22 "signature missing value" "true" +check 23 "signature not a proplist" "true" +check 30 "get_field hit" "true" +check 31 "get_field miss" "true" + +TOTAL=$((PASS+FAIL)) +if [ $FAIL -eq 0 ]; then + echo "ok $PASS/$TOTAL next/tests/envelope_shape.sh passed" +else + echo "FAIL $PASS/$TOTAL passed, $FAIL failed:" + echo "$ERRORS" +fi +[ $FAIL -eq 0 ] diff --git a/plans/fed-sx-milestone-1.md b/plans/fed-sx-milestone-1.md index 2fcd31fb..312b3bf8 100644 --- a/plans/fed-sx-milestone-1.md +++ b/plans/fed-sx-milestone-1.md @@ -150,6 +150,11 @@ canonicalize_sx(V) -> ... % sorts dict keys, normalizes strings ## Step 2 — Activity envelope + signature verify +**Sub-deliverables:** +- [x] **2a** — `next/kernel/envelope.erl` `validate_shape/1` + `get_field/2` (property-list envelope; Erlang maps `#{}` not supported in this port) + `next/tests/envelope_shape.sh` (15 cases) +- [ ] **2b** — `canonical_bytes/1` over sig-stripped envelope (deterministic textual form via `cid:to_string` substrate) + tests +- [ ] **2c** — `verify_signature/2` against actor key set, time-aware key validity per design §9.6 + tests + **Deliverables:** ```erlang @@ -932,6 +937,7 @@ A few things still under-specified; resolve as work begins. Newest first. One line per sub-deliverable commit. Erlang conformance gate (`bash lib/erlang/conformance.sh`) must remain 729/729 on every entry. +- **2026-05-26** — Step 2a: `next/kernel/envelope.erl` `validate_shape/1` + `get_field/2` over property-list envelopes (Erlang `#{}` maps not supported in this port). `next/tests/envelope_shape.sh` 15/15 pass. Erlang conformance 729/729 preserved. - **2026-05-26** — Step 1b: `next/kernel/nx_cid.erl` (from_sx/to_string/from_string/equals) — thin Erlang wrapper around the `cid:to_string/1` BIF. `next/tests/cid.sh` 13/13 pass. Module named `nx_cid` to avoid shadowing the `cid` BIF (user-module dispatch takes precedence over BIFs by module name). Erlang conformance 729/729 preserved. - **2026-05-26** — Step 1a: `next/` skeleton created (kernel/, genesis/, tests/, data/), README, `.gitignore data/`. Erlang conformance 729/729 preserved.