Compare commits

...

9 Commits

Author SHA1 Message Date
cloudinit-bot fff74b2de1 test(guild): P3 verify — GREEN (vet+race+coverage+lexicon+G-003+G-028)
docs-build / go test ./... (lexicon firewall + all x/* tests) (push) Has been cancelled
docs-build / mkdocs build (docs site artifact) (push) Has been cancelled
---ci---
project: oy
phase: 3
milestone: v0.7
status: verify
---/ci---
2026-08-19 02:16:46 +00:00
cloudinit-bot b6d7b1a9ec feat(guild): P3 Guild Charter + Chapter Federation + Household/Confederation
Extends x/guild with P3 (v0.7) Guild Charter + Chapter Federation runtime
+ Household one-tap exit + Confederation Voice delegation + D-087
PierCarriesVoice locked const + REQ-064 cooling consts.

- x/guild/types: extend Guild (CommonBondHash, PublicProfile,
  ParentGuildID, IsChapter, SecessionTermsHash, GoodStandingLiens); add
  GuildPublicProfile, Lien, SecessionTerms, ConfederationVoice structs;
  add PierCarriesVoice=false (D-087), CoolingSecessionCoverActiveDays=21,
  CoolingSecessionNonCoverDays=14 consts; extend Params + GenesisState
  (Chapters slice + Chapter->ParentGuildID ref check).
- x/guild/types/msg_guild.go: 5 Msg* (CreateGuild, CreateChapter,
  OneTapExitStand, DelegateConfederationVoice, AddLien) + MsgServer
  interface + Response types (Disclaimer surfaced per REQ-061).
- x/guild/types/expected_keepers.go: StandKeeper + StashKeeper G-003 shims.
- x/guild/keeper: NEW store-backed Keeper (guild/lien/delegation stores)
  + MsgServer handlers + simtest (8 cases).
- x/guild/module.go: AppModule (D-054 simtest-grade).
- x/stand/types: IsHousehold + IsConfederation helpers + ConfederationVoice
  type-level scaffold (REQ-057/REQ-058).

Coverage: x/guild 85.7%, keeper 94.3%, types 97.1%.
G-006/G-028 intact. go.mod/go.sum diff EMPTY. go vet clean.

REQs: REQ-051, REQ-053, REQ-057, REQ-058, REQ-061

---ci---
project: oy
phase: 3
milestone: v0.7
status: execute
---/ci---
2026-08-19 02:16:42 +00:00
cloudinit-bot 4eec2ff502 Merge phase/02 into milestone/v0.7 (P2 complete → v0.6.2)
docs-build / go test ./... (lexicon firewall + all x/* tests) (push) Has been cancelled
docs-build / mkdocs build (docs site artifact) (push) Has been cancelled
2026-08-19 02:08:43 +00:00
cloudinit-bot 72cc922b3b test(cover): P2 verify — GREEN (vet+race+coverage+lexicon+G-003+G-028)
docs-build / go test ./... (lexicon firewall + all x/* tests) (push) Has been cancelled
docs-build / mkdocs build (docs site artifact) (push) Has been cancelled
---ci---
project: oy
phase: 2
milestone: v0.7
status: verify
---/ci---
2026-08-19 02:08:43 +00:00
cloudinit-bot 907dc66d12 feat(cover): P2 Cover-Charter + Pool Council + staging + Bill of Rights (D-090(1))
P2 of v0.7 extends x/cover with Cover-Charter + Pool governance hybrid +
category staging + the Anti-Capture Bill of Rights types (D-090(1)
temporal-gap fix — Bill of Rights types land HERE, not P5, so the dual
firewall is in place before any Charter can be signed).

New (x/cover/types/rights.go): RightID type + 13 Right* consts +
AntiCaptureBillOfRightsCount=13 locked const + 13 Waivable* bool consts
(all false) + RightIsWaivable() always false + AllRights()/AllWaivableFlags().

New structs: CoverCharter (REQ-052) + CharterAmendment (7-day cooling) +
PoolCouncil (REQ-062 — 3 Masons + Watcher observer; NO Anchor/MAB seat) +
CoverCallVote (majority requires Watcher observer present). CoverPool
extended with CharterRef + CouncilRef. D-086 DefaultParams [Phase2] ->
[Phase2, Phase3, Phase4].

New Msg*: MsgSignCoverCharter (D-090(1) WaivedRights gate at
ValidateBasic — mirrors MissionLockAmendmentRejected D-064),
MsgAmendCoverCharter, MsgElectPoolMason, MsgVoteCoverCall,
MsgAmendPoolStandingGate (D-090(3) dual check: floor at ValidateBasic +
handler), MsgEscalateReserveCeiling (12-month age check).

New handlers: SignCoverCharter, AmendCoverCharter (Proposed + ProposedAt),
ElectPoolMason (max 3), VoteCoverCall (Yes requires observer),
AmendPoolStandingGate (D-090(3) re-check), EscalateReserveCeiling,
CoolCharterAmendment + RatifyCharterAmendment lifecycle helpers.

New stores: charter/ council/ vote/ amendment/ + SetParamsOverride/Params().

Simtest cases (a)-(h): Charter signing + D-090(1) WaivedRights reject +
7-day cooling + election + vote observer + D-086 out-of-phase + ceiling
escalation + D-090(3) below-floor reject.

Lexicon: rights.go + msg_charter.go lexicon-clean (initial 'policy' hit
fixed -> 'invariant'). .lexicon_fixture SkipDir guard added to 3 lexicon
walks (fixes pre-existing cross-package test-isolation race).

G-003/G-006/G-028/G-024 intact. go.mod/go.sum diff EMPTY.
Coverage: types 98.9%, keeper 95.1%, firewall 100.0%.

REQs: REQ-048, REQ-052, REQ-062, REQ-065 (D-090(1) Bill of Rights types
for REQ-056 land here; P5 adds the ceremony)

---ci---
project: oy
phase: 2
milestone: v0.7
status: execute
---/ci---
2026-08-19 02:08:33 +00:00
cloudinit-bot a23856a9ee Merge phase/01 into milestone/v0.7-fraternal-groups (P1 complete → v0.6.1)
docs-build / go test ./... (lexicon firewall + all x/* tests) (push) Has been cancelled
docs-build / mkdocs build (docs site artifact) (push) Has been cancelled
2026-08-19 01:53:57 +00:00
cloudinit-bot 7a00131cf0 test(cover): P1 verify — structural+behavioral+security+quality GREEN
docs-build / go test ./... (lexicon firewall + all x/* tests) (push) Has been cancelled
docs-build / mkdocs build (docs site artifact) (push) Has been cancelled
VERIFY stage for P1 v0.7. Four verification layers:

1. STRUCTURAL: go vet ./x/cover/... ./lexicon_meta_cover/... — CLEAN
2. BEHAVIORAL: go test -race ./x/cover/... — GREEN (no race conditions)
3. SECURITY: 4 lexicon meta-tests green (x/, docs/, web/, cover/); G-003
   production firewall intact (no cross-module struct imports in
   x/cover/types — only expected_keepers.go interface references); G-028
   go.mod/go.sum diff EMPTY
4. QUALITY: coverage x/cover/types 97.8%, x/cover/keeper 94.1%,
   x/cover/firewall 100.0% — all ≥80% target

All existing v0.1-v0.6 tests still pass (no regressions).

---ci---
project: oy
phase: 1
milestone: v0.7
status: verify
---/ci---
2026-08-19 01:53:52 +00:00
cloudinit-bot 6d63482c48 feat(cover): P1 v0.7 Cover Pool foundation + Anti-Crowding-Out firewall
Add the new x/cover module (Cover Pool runtime) implementing P1 of the
v0.7 milestone: CoverPool/CoverFeeTag/CoverCall types with the 4 GRILL-
ratified locked consts (CoverReserveFloorAnnualContribX=1.5,
CoverReserveCeilingAnnualContribX=2.5, CoverStandingGateTrusted=4.0,
CoverStandingGatePreferred=4.5), the 8-category/3-phase CoverCategory
enum with D-086 FactoryAllowedPhases=[Phase2]-only default, three Msg*
types (LaunchCoverPool/RouteCoverFee/FileCoverCall) with full sdk.Msg
impls, store-backed Keeper with 4 G-003 expected-keeper shims
(StandingKeeper/WatcherKeeper/BondKeeper/StillKeeper), and three
handlers enforcing the D-077 Standing gate, D-086 category phase check,
REQ-047 reserve floor + below-floor auto-pause (D-089(1) Still
invocation), and REQ-050 category-tag match.

Add the x/cover/firewall subpackage (Anti-Crowding-Out firewall, D-079/
D-088): a stdlib-only leaf checker enforcing RightNoTaxOnPersonalStash
by rejecting Cover-Fee routing to the Root-Pool operating-expenses
destination (defense in depth with the lexicon meta-test).

Add the lexicon_meta_cover meta-test (4th lexicon firewall, D-088):
scans x/cover/**/*.go for both lexicon.FindBannedTerm (10 project-wide
terms) AND lexicon.FindCoverBannedTerm (4 Cover-specific terms), with
G-013 walk-coverage + G-009 self-test tables.

Add lexicon.CoverBannedTerms()/FindCoverBannedTerm()/
SyntheticCoverBannedStrings() helpers (additive to the existing
project-wide BannedTerms — no changes to existing helpers).

Apply D-088(3) optional doc-fix: replace 'insurance-like' with
'Cover-like' in x/pact/types docstrings.

Coverage: x/cover/types 97.8%, x/cover/keeper 94.1%, x/cover/firewall
100.0%. go.mod/go.sum unchanged (G-006/G-028). All existing tests pass.

REQs: REQ-046, REQ-047, REQ-049, REQ-050

---ci---
project: oy
phase: 1
milestone: v0.7
status: execute
---/ci---
2026-08-19 01:52:58 +00:00
cloudinit-bot 463e11e8d2 Merge phase/00 into milestone/v0.7-fraternal-groups (P0 complete → v0.6.0)
docs-build / go test ./... (lexicon firewall + all x/* tests) (push) Has been cancelled
docs-build / mkdocs build (docs site artifact) (push) Has been cancelled
2026-08-19 01:42:30 +00:00
31 changed files with 9707 additions and 22 deletions
+83
View File
@@ -123,3 +123,86 @@ func SyntheticBannedStrings() []string {
"the " + terms[9] + " lost money", // depositor
}
}
// coverFragments holds the 4 Cover-specific banned terms (D-088, REQ-055
// lexicon scope) as (a, b) halves. Neither half alone is a banned term, and
// concatenation produces the banned term at runtime — the same fragment-
// assembly bootstrapping pattern as the project-wide fragments above so this
// package's source does not contain any banned term as a literal substring.
// These are the four terms the Cover module's vocabulary MUST NOT use: the
// safe vision names are "Cover", "Cover-Fee", "Cover Call", "Cover-Charter",
// "Cover Pool", "Cover Claims Voucher" (D-088); the four terms below are the
// banned synonyms enforced by lexicon_meta_cover.
var coverFragments = []term{
{"insur", "ance"}, // insurance
{"prem", "ium"}, // premium
{"cla", "im"}, // claim
{"pol", "icy"}, // policy
}
// CoverBannedTerms returns the 4 Cover-specific banned terms (D-088): the
// four terms the Cover module's vocabulary MUST NOT use. The terms are
// assembled at runtime from coverFragments so this package's source does not
// contain any banned term as a literal substring (the standard lexicon-test
// bootstrapping pattern). These are ADDITIVE to the project-wide
// BannedTerms() — the project-wide 10 terms also apply to x/cover; this list
// is the Cover-specific superset layer enforced by lexicon_meta_cover.
func CoverBannedTerms() []string {
out := make([]string, len(coverFragments))
for i, t := range coverFragments {
out[i] = t.a + t.b
}
return out
}
// coverBannedTermRegexes are the compiled word-boundary regexes for the 4
// Cover-specific banned terms. Word boundaries prevent false positives (a
// Cover-Call's "claimant" must NOT trip the banned "claim" — the regex bans
// the word as a concept, not as an arbitrary substring). The regexes are
// case-insensitive. Mirrors bannedTermRegexes for the Cover-specific list.
var coverBannedTermRegexes = func() []*regexp.Regexp {
terms := CoverBannedTerms()
out := make([]*regexp.Regexp, len(terms))
for i, t := range terms {
out[i] = regexp.MustCompile(`\b` + regexp.QuoteMeta(t) + `\b`)
}
return out
}()
// FindCoverBannedTerm returns the first Cover-specific banned term found in
// s (case-insensitive, word-boundary match) and true, or "" and false if
// none. Mirrors FindBannedTerm but uses the Cover-specific 4-term list
// (D-088). Used by the lexicon_meta_cover meta-test (the 4th lexicon meta-
// test) and the per-package lexicon assertion in x/cover/types/types_test.go.
// A Cover source file that contains a Cover-specific banned term triggers
// this helper; the project-wide FindBannedTerm is NOT consulted here (the
// two firewalls are layered: project-wide + Cover-specific).
func FindCoverBannedTerm(s string) (string, bool) {
lower := strings.ToLower(s)
terms := CoverBannedTerms()
for i, re := range coverBannedTermRegexes {
if re.MatchString(lower) {
return terms[i], true
}
}
return "", false
}
// SyntheticCoverBannedStrings returns one synthetic string per Cover-specific
// banned term, each embedding exactly one banned term in a plausible Cover-
// module sentence context. This is the single source of truth (G-014) for
// the synthetic self-test table consumed by lexicon_meta_cover ::
// TestLexiconMetaCoverSelfTestTable. Mirrors SyntheticBannedStrings for the
// 4-term Cover-specific list. The strings are built from CoverBannedTerms()
// (already fragment-assembled), so this package's own source stays lexicon-
// clean. The returned slice is indexed positionally against CoverBannedTerms():
// the i-th synthetic string embeds the i-th Cover-specific banned term.
func SyntheticCoverBannedStrings() []string {
terms := CoverBannedTerms()
return []string{
"buy " + terms[0] + " now", // insurance
"pay the " + terms[1] + " fee", // premium
"file a " + terms[2] + " today", // claim
"the " + terms[3] + " expires", // policy
}
}
@@ -0,0 +1,372 @@
// Package lexicon_meta_cover holds the Cover lexicon firewall (REQ-055,
// D-088) — the 4th lexicon meta-test.
//
// It is a NEW sibling meta-test created in v0.7 P1 that MIRRORS the v0.6
// web firewall (lexicon_meta_web/lexicon_meta_web_test.go, package
// lexicon_meta_web) but scans the Cover module surface (x/cover/**/*.go)
// for BOTH the 10 project-wide banned terms (lexicon.FindBannedTerm) AND
// the 4 Cover-specific banned terms (lexicon.FindCoverBannedTerm — D-088).
// It uses the SAME lexicon.FindBannedTerm + lexicon.FindCoverBannedTerm
// (word-boundary, case-insensitive) — NO detection reimplementation — so
// the four firewalls (x/*.go project-wide, docs, web, cover) share a
// single source of truth for the banned terms. The Cover-specific 4 terms
// (insurance, premium, claim, policy — assembled from fragments by
// lexicon.CoverBannedTerms) are the Cover-module superset layer: the
// project-wide 10 terms ALSO apply to x/cover; this firewall adds the 4
// Cover-specific terms on top.
//
// Placement: this file lives in lexicon_meta_cover/ (a subdirectory of the
// repo root) because Go does not permit two distinct packages in the same
// directory; the v0.2 firewall is package lexicon_meta at the repo root,
// the v0.3 firewall is package lexicon_meta_docs in lexicon_meta_docs/,
// and the v0.6 firewall is package lexicon_meta_web in lexicon_meta_web/.
// The invocation `go test ./lexicon_meta_cover/...` (PLANS v0.7 P1)
// resolves to this package. Run via `go test ./...` from the repo root.
//
// G-013 walk-coverage: TestLexiconMetaCoverWalkCoverage injects synthetic
// banned-term .go files into a temp x/cover/ subtree and asserts the walk
// FINDS them — one for a project-wide term, one for a Cover-specific term.
// This closes the "silently scans nothing and reports green" failure mode
// that the G-009 self-test table (detection) alone does not cover.
//
// G-014 self-test drift: the self-test tables reuse
// lexicon.SyntheticBannedStrings() (project-wide) +
// lexicon.SyntheticCoverBannedStrings() (Cover-specific) — the single
// sources of truth shared with the other three meta-tests.
//
// G-024: this test file stays stdlib + lexicon-only (no cosmos-sdk import).
package lexicon_meta_cover
import (
"os"
"path/filepath"
"runtime"
"strings"
"testing"
"github.com/oy/openyield/lexicon"
)
// repoRoot returns the absolute path to the repo root by walking up from
// this test file (the test lives at <repoRoot>/lexicon_meta_cover/).
func repoRoot(t *testing.T) string {
t.Helper()
_, file, _, ok := runtime.Caller(0)
if !ok {
t.Fatal("runtime.Caller failed")
}
// file = .../oy/lexicon_meta_cover/lexicon_meta_cover_test.go
// repo root = filepath.Dir(filepath.Dir(file))
return filepath.Dir(filepath.Dir(file))
}
// coverRoot returns the absolute path to the repo's x/cover directory.
func coverRoot(t *testing.T) string {
t.Helper()
return filepath.Join(repoRoot(t), "x", "cover")
}
// thisFile returns the absolute path of this meta-test file (to exclude it
// from its own scan — it references banned terms via the lexicon package,
// whose source assembles terms from fragments, so no banned-term literal
// appears in the firewall's own code).
func thisFile(t *testing.T) string {
t.Helper()
_, file, _, ok := runtime.Caller(0)
if !ok {
t.Fatal("runtime.Caller failed")
}
return file
}
// isCoverTarget reports whether path (relative to repo root) is a .go file
// under x/cover/ (production + test). Non-.go files under x/cover/ are
// skipped.
func isCoverTarget(rel string) bool {
prefix := strings.Join([]string{"x", "cover", ""}, string(filepath.Separator))
if !strings.HasPrefix(rel, prefix) {
return false
}
return strings.HasSuffix(rel, ".go")
}
// TestLexiconMetaCoverNoBannedTerms is the Cover firewall (D-088). It walks
// x/cover/**/*.go (production + test), reads each file's source, and
// asserts no banned term (project-wide OR Cover-specific) is present
// (word-boundary, case-insensitive). Excludes this test file itself
// (self-exclusion via runtime.Caller(0) — though this file lives outside
// x/cover/, the exclusion is belt-and-suspenders in case the walk root is
// ever broadened).
//
// Passes at P1 with the x/cover module lexicon-clean by construction. The
// x/cover/types/types_test.go per-package lexicon assertion
// (TestLexiconNoBannedTermsInCover) is the in-module firewall; this
// meta-test is the repo-wide Cover firewall (run via `go test ./...`).
func TestLexiconMetaCoverNoBannedTerms(t *testing.T) {
root := coverRoot(t)
this := thisFile(t)
hits := []string{}
err := filepath.Walk(root, func(path string, info os.FileInfo, err error) error {
if err != nil {
return err
}
if info.IsDir() {
// Skip the walk-coverage fixture dir (G-013):
// TestLexiconMetaCoverWalkCoverage creates
// x/cover/.lexicon_fixture/ with synthetic banned-term .go
// files. Those fixtures are test artifacts, NOT production
// code; skip the dir to avoid a self-trip if cleanup is
// delayed.
if info.Name() == ".lexicon_fixture" {
return filepath.SkipDir
}
return nil
}
if !strings.HasSuffix(path, ".go") {
return nil
}
// Self-exclusion: skip this meta-test file (belt-and-suspenders;
// this file lives outside x/cover/ so the walk would not reach it
// anyway, but the exclusion is robust to a future walk-root change).
if path == this {
return nil
}
bz, rerr := os.ReadFile(path)
if rerr != nil {
return rerr
}
src := string(bz)
// Project-wide 10 terms.
if found, ok := lexicon.FindBannedTerm(src); ok {
rel, _ := filepath.Rel(root, path)
hits = append(hits, rel+" contains project-wide banned term "+found)
}
// Cover-specific 4 terms.
if found, ok := lexicon.FindCoverBannedTerm(src); ok {
rel, _ := filepath.Rel(root, path)
hits = append(hits, rel+" contains Cover-specific banned term "+found)
}
return nil
})
if err != nil {
t.Fatalf("walk: %v", err)
}
if len(hits) > 0 {
t.Errorf("REQ-055/D-088 Cover lexicon firewall violations:\n %s",
strings.Join(hits, "\n "))
}
}
// TestLexiconMetaCoverSelfTestTable (G-009 for cover) is the firewall's own
// detection-coverage guard. Each synthetic string embeds exactly one
// banned term in a plausible sentence context and is asserted to trigger
// detection, so the firewall's detection logic is durably verified — if
// detection ever breaks, this test fails before the firewall silently
// passes a real violation in a Cover source file.
//
// This test exercises BOTH the project-wide terms (lexicon.SyntheticBannedStrings
// + lexicon.FindBannedTerm) AND the Cover-specific terms
// (lexicon.SyntheticCoverBannedStrings + lexicon.FindCoverBannedTerm),
// so both layers of the Cover firewall are durably verified.
func TestLexiconMetaCoverSelfTestTable(t *testing.T) {
// Project-wide layer.
terms := lexicon.BannedTerms()
if len(terms) != 10 {
t.Fatalf("BannedTerms() len = %d, want 10", len(terms))
}
synthetic := lexicon.SyntheticBannedStrings()
if len(synthetic) != len(terms) {
t.Fatalf("SyntheticBannedStrings() len = %d, want %d", len(synthetic), len(terms))
}
for i, s := range synthetic {
found, ok := lexicon.FindBannedTerm(s)
if !ok {
t.Errorf("G-009 cover self-test (project-wide) [%d]: synthetic string did not trigger detection: %q", i, s)
continue
}
if found != terms[i] {
t.Errorf("G-009 cover self-test (project-wide) [%d]: detected %q, want %q (in %q)", i, found, terms[i], s)
}
}
// Cover-specific layer.
coverTerms := lexicon.CoverBannedTerms()
if len(coverTerms) != 4 {
t.Fatalf("CoverBannedTerms() len = %d, want 4 (D-088)", len(coverTerms))
}
coverSynthetic := lexicon.SyntheticCoverBannedStrings()
if len(coverSynthetic) != len(coverTerms) {
t.Fatalf("SyntheticCoverBannedStrings() len = %d, want %d (must match CoverBannedTerms())", len(coverSynthetic), len(coverTerms))
}
for i, s := range coverSynthetic {
found, ok := lexicon.FindCoverBannedTerm(s)
if !ok {
t.Errorf("G-009 cover self-test (Cover-specific) [%d]: synthetic string did not trigger detection: %q", i, s)
continue
}
if found != coverTerms[i] {
t.Errorf("G-009 cover self-test (Cover-specific) [%d]: detected %q, want %q (in %q)", i, found, coverTerms[i], s)
}
}
}
// TestLexiconMetaCoverBannedTermsCount asserts exactly 10 project-wide
// banned terms + 4 Cover-specific banned terms are configured (locked-const
// for the firewall's scope). Derived from lexicon.BannedTerms() +
// lexicon.CoverBannedTerms() — the single sources — so a count change
// breaks the firewalls (G-014 drift prevention).
func TestLexiconMetaCoverBannedTermsCount(t *testing.T) {
terms := lexicon.BannedTerms()
if len(terms) != 10 {
t.Errorf("BannedTerms() len = %d, want 10 (REQ-012)", len(terms))
}
coverTerms := lexicon.CoverBannedTerms()
if len(coverTerms) != 4 {
t.Errorf("CoverBannedTerms() len = %d, want 4 (D-088)", len(coverTerms))
}
seen := map[string]bool{}
for _, tr := range terms {
if seen[tr] {
t.Errorf("duplicate project-wide banned term %q", tr)
}
seen[tr] = true
}
for _, tr := range coverTerms {
if seen[tr] {
t.Errorf("Cover-specific banned term %q duplicates a project-wide term", tr)
}
seen[tr] = true
}
}
// TestLexiconMetaCoverNoFalsePositiveOnClaimant asserts the field name
// "ClaimantReachID" (used by types.CoverCall) does NOT trigger the
// Cover-specific banned term that looks like a substring of "Claimant"
// (word-boundary matching must not match substrings of identifiers). This
// is the regression firewall for the word-boundary detection design on the
// Cover-specific layer — mirrors the project-wide
// TestLexiconMetaNoFalsePositiveOnOpenYield.
func TestLexiconMetaCoverNoFalsePositiveOnClaimant(t *testing.T) {
cases := []string{
"ClaimantReachID",
"ClaimantReachID string",
"the ClaimantReachID field",
"c.ClaimantReachID",
}
for _, s := range cases {
if _, ok := lexicon.FindCoverBannedTerm(s); ok {
t.Errorf("false positive: %q triggered a Cover-specific banned term (word-boundary must avoid this)", s)
}
}
}
// TestLexiconMetaCoverWalkCoverage (G-013) is the walk-coverage firewall
// for the Cover meta-test. The G-009 self-test table (above) verifies
// DETECTION (FindBannedTerm / FindCoverBannedTerm on synthetic strings)
// but NOT the WALK (which files are scanned). A walk bug — e.g. wrong path
// prefix, missing x/cover/ recursion — would silently scan nothing and
// report green on zero files. This test closes that gap by injecting
// synthetic banned-term .go files into a fixture dir under the real
// x/cover/ path the walk scans and asserting the walk FINDS them — one
// fixture for a project-wide term, one for a Cover-specific term.
//
// The fixtures are created under x/cover/.lexicon_fixture/ (a real x/cover/
// subtree the walk reaches) and removed via defer so they never leak into
// the repo. If the walk logic misses either fixture, this test fails loudly
// instead of letting a broken walk pass the firewall green on zero files
// scanned.
func TestLexiconMetaCoverWalkCoverage(t *testing.T) {
root := coverRoot(t)
// Build synthetic banned terms from fragments so THIS file does not
// contain banned-term literals.
terms := lexicon.BannedTerms()
if len(terms) == 0 {
t.Fatal("BannedTerms() returned no terms — cannot run walk-coverage")
}
coverTerms := lexicon.CoverBannedTerms()
if len(coverTerms) == 0 {
t.Fatal("CoverBannedTerms() returned no terms — cannot run walk-coverage")
}
// Project-wide fixture: use the first banned term ("bank") reassembled.
pwTerm := terms[0][:2] + terms[0][2:]
// Cover-specific fixture: use the first Cover term reassembled.
coverTerm := coverTerms[0][:len(coverTerms[0])/2] + coverTerms[0][len(coverTerms[0])/2:]
fixtureDir := filepath.Join(root, ".lexicon_fixture")
if err := os.MkdirAll(fixtureDir, 0o755); err != nil {
t.Fatalf("mkdir fixture: %v", err)
}
defer os.RemoveAll(fixtureDir)
// Project-wide fixture .go file.
pwFixture := filepath.Join(fixtureDir, "bad_pw_fixture.go")
pwContent := []byte("// fixture\n// this file contains a project-wide banned term: " + pwTerm + "\npackage lexicon_fixture\n")
if err := os.WriteFile(pwFixture, pwContent, 0o644); err != nil {
t.Fatalf("write pw fixture: %v", err)
}
// Cover-specific fixture .go file.
coverFixture := filepath.Join(fixtureDir, "bad_cover_fixture.go")
coverContent := []byte("// fixture\n// this file contains a Cover-specific banned term: " + coverTerm + "\npackage lexicon_fixture\n")
if err := os.WriteFile(coverFixture, coverContent, 0o644); err != nil {
t.Fatalf("write cover fixture: %v", err)
}
// Run the SAME walk logic as TestLexiconMetaCoverNoBannedTerms and
// assert it FINDS both fixtures' banned terms. A walk that returns zero
// hits here proves the walk logic is broken.
pwHits := []string{}
coverHits := []string{}
err := filepath.Walk(root, func(path string, info os.FileInfo, err error) error {
if err != nil {
return err
}
if info.IsDir() {
return nil
}
if !strings.HasSuffix(path, ".go") {
return nil
}
bz, rerr := os.ReadFile(path)
if rerr != nil {
return rerr
}
src := string(bz)
if found, ok := lexicon.FindBannedTerm(src); ok {
rel, _ := filepath.Rel(root, path)
pwHits = append(pwHits, rel+":"+found)
}
if found, ok := lexicon.FindCoverBannedTerm(src); ok {
rel, _ := filepath.Rel(root, path)
coverHits = append(coverHits, rel+":"+found)
}
return nil
})
if err != nil {
t.Fatalf("walk: %v", err)
}
// Assert the project-wide fixture was found.
foundPW := false
for _, h := range pwHits {
if strings.Contains(h, "bad_pw_fixture.go") && strings.Contains(h, pwTerm) {
foundPW = true
break
}
}
if !foundPW {
t.Errorf("G-013 walk-coverage (project-wide): the walk did NOT find the synthetic project-wide banned-term fixture at %s — the Cover firewall walk logic is broken (it would silently scan nothing and report green). pwHits=%v", pwFixture, pwHits)
}
// Assert the Cover-specific fixture was found.
foundCover := false
for _, h := range coverHits {
if strings.Contains(h, "bad_cover_fixture.go") && strings.Contains(h, coverTerm) {
foundCover = true
break
}
}
if !foundCover {
t.Errorf("G-013 walk-coverage (Cover-specific): the walk did NOT find the synthetic Cover-specific banned-term fixture at %s — the Cover firewall walk logic is broken. coverHits=%v", coverFixture, coverHits)
}
}
+10
View File
@@ -43,6 +43,16 @@ func TestLexiconMetaNoBannedTermsInX(t *testing.T) {
return err
}
if info.IsDir() {
// Skip the lexicon_meta_cover walk-coverage fixture dir
// (G-013): TestLexiconMetaCoverWalkCoverage creates
// x/cover/.lexicon_fixture/ with synthetic banned-term .go
// files to verify the Cover firewall's walk logic. Those
// fixtures are test artifacts, NOT production code, and would
// trip this project-wide firewall if scanned concurrently.
// Skip the fixture dir to avoid the test-isolation race.
if info.Name() == ".lexicon_fixture" {
return filepath.SkipDir
}
return nil
}
if !strings.HasSuffix(path, ".go") {
+89
View File
@@ -0,0 +1,89 @@
// Package firewall holds the Anti-Crowding-Out firewall (D-079, D-088).
//
// The firewall is the enforcement mechanism for RightNoTaxOnPersonalStash —
// the Bill of Rights right that prohibits routing Cover-Fees OUT of
// contributor-pool semantics. A Cover-Fee is the annual contrib that funds
// a Cover Pool's reserve; it MUST route into the Pool's ReserveAccount (a
// contributor-pool reserve holder), never into a Root-Pool operating-
// expenses holder (the Anti-Crowding-Out case: routing Cover-Fees to Root-
// Pool operating expenses would let the protocol crowding-out the
// contributor pool's reserve).
//
// The firewall is an ALLOW-LIST of permitted routing destinations (D-088(2)
// — the concrete simtest-enforceable shape). The RouteCoverFee handler
// passes the destination holder string to CheckCoverFeeRouting; the
// firewall checks the destination is non-empty AND not a known bad
// destination. For P1 simtest-grade, the firewall rejects the specific
// string "root-pool-operating-expenses" (the Anti-Crowding-Out case) and
// accepts any other non-empty string. The full destination-match check
// (the destination must EXACTLY match the Pool's ReserveAccount) is
// enforced at the call site (the handler compares the destination to
// pool.ReserveAccount BEFORE calling the firewall; the firewall is the
// second-layer defense).
//
// Defense in depth (D-079): the runtime firewall (this package) rejects
// code paths; the lexicon_meta_cover meta-test rejects doc drift. The two
// layers together close the Anti-Crowding-Out failure mode: a code path
// that routes a Cover-Fee to a Root-Pool holder is rejected by the
// firewall; a doc that drifts to describing Cover-Fees as routing to
// Root-Pool is rejected by the meta-test.
//
// This package is a LEAF checker: it does NOT import x/cover/types (the
// handler passes strings in). It is stdlib-only (G-024 — the firewall has
// no cosmos-sdk dependency; it is a pure string check). This keeps the
// firewall testable in isolation + import-cycle-free.
package firewall
import (
"errors"
"strings"
)
// ErrAntiCrowdingOut is returned by CheckCoverFeeRouting when the
// destination is a known bad destination (the Anti-Crowding-Out case). The
// RouteCoverFee handler wraps this in a cover-specific error message.
var ErrAntiCrowdingOut = errors.New("cover-fee routing outside contributor-pool semantics (Anti-Crowding-Out firewall)")
// badDestination is the known bad destination the firewall rejects (the
// Anti-Crowding-Out case). Built from fragments so this source file does
// not contain the literal bad destination as a searchable string (mirrors
// the lexicon fragment-assembly pattern; the firewall's own code is
// allowed to name the destination it bans, but the fragment assembly keeps
// the source grep-clean for "root-pool" drift auditing). P1 simtest-grade:
// the firewall rejects exactly this one destination; the full destination-
// match check (destination must EXACTLY match the Pool's ReserveAccount)
// is enforced at the call site.
var badDestination = string([]byte{
'r', 'o', 'o', 't', '-', 'p', 'o', 'o', 'l',
'-', 'o', 'p', 'e', 'r', 'a', 't', 'i', 'n', 'g',
'-', 'e', 'x', 'p', 'e', 'n', 's', 'e', 's',
})
// CheckCoverFeeRouting is the Anti-Crowding-Out firewall (D-079, D-088).
// It returns nil if the destination is a permitted routing destination (a
// non-empty holder string that is NOT the known bad destination), or
// ErrAntiCrowdingOut if the destination is the known bad destination (the
// Root-Pool operating-expenses holder — the Anti-Crowding-Out case).
//
// The RouteCoverFee handler calls this AFTER loading the pool + BEFORE
// persisting the Cover-Fee routing. The handler passes the pool's
// ReserveAccount (the destination the fee routes into); the firewall is
// the second-layer defense (the first layer is the handler's own
// destination-match check — the destination must be the pool's
// ReserveAccount; the firewall catches the case where the destination IS
// the pool's ReserveAccount but that holder is itself the bad destination,
// i.e. a pool misconfigured to route to Root-Pool operating expenses).
//
// P1 simtest-grade: the firewall rejects exactly the one known bad
// destination + the empty-string case. The full destination-match check
// is enforced at the call site (the handler compares the destination to
// pool.ReserveAccount).
func CheckCoverFeeRouting(destinationAccount string) error {
if destinationAccount == "" {
return errors.New("cover-fee routing: empty destination (Anti-Crowding-Out firewall)")
}
if strings.EqualFold(destinationAccount, badDestination) {
return ErrAntiCrowdingOut
}
return nil
}
+100
View File
@@ -0,0 +1,100 @@
package firewall
// firewall_test.go holds the unit tests for the Anti-Crowding-Out firewall
// (D-079, D-088). The firewall is a leaf checker (stdlib-only); these tests
// exercise CheckCoverFeeRouting in isolation. The keeper simtest also
// exercises the firewall via the RouteCoverFee handler (integration
// coverage), but this in-package test gives the firewall package its own
// coverage number >=80%.
//
// Lexicon self-exclusion (D-088): this test file must NOT contain the
// banned project-wide or Cover-specific terms as literals. The bad
// destination string is assembled from bytes (not a literal) so the
// firewall's own bad-destination constant is not re-inlined here as a
// searchable literal.
import (
"strings"
"testing"
)
// badDest reassembles the firewall's bad destination from bytes so this
// test file does not contain the literal bad string as a searchable
// substring (mirrors the firewall's own byte assembly). Matches the
// firewall's badDestination byte-for-byte.
func badDest() string {
return string([]byte{
'r', 'o', 'o', 't', '-', 'p', 'o', 'o', 'l',
'-', 'o', 'p', 'e', 'r', 'a', 't', 'i', 'n', 'g',
'-', 'e', 'x', 'p', 'e', 'n', 's', 'e', 's',
})
}
// TestCheckCoverFeeRoutingAcceptsPermitted asserts the firewall accepts a
// non-empty permitted destination (returns nil).
func TestCheckCoverFeeRoutingAcceptsPermitted(t *testing.T) {
cases := []string{
"acc-1",
"oy:reserve:pool-1",
"contributor-pool-reserve",
"some-other-destination",
}
for _, c := range cases {
if err := CheckCoverFeeRouting(c); err != nil {
t.Errorf("CheckCoverFeeRouting(%q) = %v, want nil", c, err)
}
}
}
// TestCheckCoverFeeRoutingRejectsEmpty asserts the firewall rejects an
// empty destination.
func TestCheckCoverFeeRoutingRejectsEmpty(t *testing.T) {
err := CheckCoverFeeRouting("")
if err == nil {
t.Fatal("CheckCoverFeeRouting(empty) should error")
}
if !strings.Contains(err.Error(), "empty") {
t.Errorf("empty-destination error = %q, want 'empty'", err.Error())
}
}
// TestCheckCoverFeeRoutingRejectsBadDestination asserts the firewall
// rejects the known bad destination (the Anti-Crowding-Out case) with
// ErrAntiCrowdingOut.
func TestCheckCoverFeeRoutingRejectsBadDestination(t *testing.T) {
err := CheckCoverFeeRouting(badDest())
if err == nil {
t.Fatal("CheckCoverFeeRouting(bad destination) should error")
}
if err != ErrAntiCrowdingOut {
t.Errorf("error = %v, want ErrAntiCrowdingOut", err)
}
if !strings.Contains(err.Error(), "Anti-Crowding-Out") {
t.Errorf("error = %q, want 'Anti-Crowding-Out'", err.Error())
}
}
// TestCheckCoverFeeRoutingCaseInsensitive asserts the firewall rejects the
// bad destination case-insensitively (the Root-Pool operating-expenses
// holder in any case is the Anti-Crowding-Out case).
func TestCheckCoverFeeRoutingCaseInsensitive(t *testing.T) {
upper := strings.ToUpper(badDest())
if err := CheckCoverFeeRouting(upper); err == nil {
t.Error("CheckCoverFeeRouting(upper-case bad destination) should error (case-insensitive)")
}
if err := CheckCoverFeeRouting(strings.ToLower(badDest())); err == nil {
t.Error("CheckCoverFeeRouting(lower-case bad destination) should error")
}
}
// TestErrAntiCrowdingOutIsSentinel asserts ErrAntiCrowdingOut is a non-nil
// sentinel error (the handler wraps it; the simtest asserts on the
// message substring).
func TestErrAntiCrowdingOutIsSentinel(t *testing.T) {
if ErrAntiCrowdingOut == nil {
t.Fatal("ErrAntiCrowdingOut should be non-nil")
}
if !strings.Contains(ErrAntiCrowdingOut.Error(), "Anti-Crowding-Out") {
t.Errorf("ErrAntiCrowdingOut Error = %q, want 'Anti-Crowding-Out'", ErrAntiCrowdingOut.Error())
}
}
+465
View File
@@ -0,0 +1,465 @@
package keeper
// keeper.go holds the store-backed Keeper for the cover module's Cover Pool
// runtime (REQ-046, REQ-047, REQ-049, REQ-050, REQ-055, D-077, D-086,
// D-088, D-089).
//
// The Keeper wraps an sdk.KVStore via a storeKey. It holds:
// - the CoverPool records (pool-id -> CoverPool);
// - the CoverCall records (call-id -> CoverCall; the FileCoverCall
// handler persists here; P4 adds the Voucher adjudication).
//
// The Cover-Fee routing (RouteCoverFee) does NOT persist a separate record
// in P1 — the routing is the event (the reserve balance update is a
// simtest-grade stub). P2 may add a CoverFeeRouting record; P1 ships the
// event-only path.
//
// The Keeper also holds the FOUR expected-keeper shims (StandingKeeper for
// the D-077 gate; WatcherKeeper for the launch attestation; BondKeeper for
// the P4 MAB check; StillKeeper for the below-floor auto-pause). The shims
// are interfaces (G-003 — no struct import of x/standing/types,
// x/watcher/types, x/bond/types, x/still/types); the concrete keepers (or
// simtest stubs) satisfy them structurally.
//
// State-machine ordering (vision §7, enforced in every handler):
// ValidateBasic -> handler authz/gate -> state mutation -> ctx.EventManager().EmitEvent
import (
"encoding/json"
"fmt"
storetypes "cosmossdk.io/store/types"
"github.com/cosmos/cosmos-sdk/codec"
sdk "github.com/cosmos/cosmos-sdk/types"
"github.com/oy/openyield/x/cover/types"
)
// Keeper is the store-backed cover Cover-Pool keeper.
type Keeper struct {
cdc codec.Codec
storeKey storetypes.StoreKey
standingKeeper types.StandingKeeper
watcherKeeper types.WatcherKeeper
bondKeeper types.BondKeeper
stillKeeper types.StillKeeper
// paramsOverride is a simtest-grade Params override (nil = use
// DefaultParams). A future P2+ will load the Params from the params
// store; for now the handler uses DefaultParams unless an override is
// set via SetParamsOverride (the D-086 simtest case (f) uses this to
// restrict FactoryAllowedPhases to [Phase2, Phase3] only and reject a
// Phase4 launch).
paramsOverride *types.Params
}
// NewKeeper constructs a new store-backed cover Keeper. The four expected-
// keeper shims are injected (all nil-able for partial tests; the handlers
// guard nil shims and skip the corresponding check, still mutating state —
// the simtest wiring documents this). The StandingKeeper gates the launch
// (D-077); the WatcherKeeper attests the launch (REQ-046); the BondKeeper
// is held for P4 (the P1 handlers do not call it); the StillKeeper records
// the below-floor auto-pause (D-089(1)).
func NewKeeper(cdc codec.Codec, storeKey storetypes.StoreKey, sk types.StandingKeeper, wk types.WatcherKeeper, bk types.BondKeeper, stK types.StillKeeper) Keeper {
return Keeper{
cdc: cdc,
storeKey: storeKey,
standingKeeper: sk,
watcherKeeper: wk,
bondKeeper: bk,
stillKeeper: stK,
}
}
// SetStandingKeeper sets the StandingKeeper expected-keeper shim (for
// post-construction wiring, e.g., app wiring or test setup).
func (k *Keeper) SetStandingKeeper(sk types.StandingKeeper) { k.standingKeeper = sk }
// SetWatcherKeeper sets the WatcherKeeper expected-keeper shim.
func (k *Keeper) SetWatcherKeeper(wk types.WatcherKeeper) { k.watcherKeeper = wk }
// SetBondKeeper sets the BondKeeper expected-keeper shim.
func (k *Keeper) SetBondKeeper(bk types.BondKeeper) { k.bondKeeper = bk }
// SetStillKeeper sets the StillKeeper expected-keeper shim.
func (k *Keeper) SetStillKeeper(stK types.StillKeeper) { k.stillKeeper = stK }
// SetParamsOverride sets a simtest-grade Params override (nil = use
// DefaultParams). The D-086 simtest case (f) uses this to restrict
// FactoryAllowedPhases to [Phase2, Phase3] only and reject a Phase4
// launch. A future P2+ will replace this with a params-store load.
func (k *Keeper) SetParamsOverride(p types.Params) { k.paramsOverride = &p }
// Params returns the effective Params (the override if set, else
// DefaultParams). The handler calls this to get FactoryAllowedPhases +
// PoolStandingGate.
func (k Keeper) Params() types.Params {
if k.paramsOverride != nil {
return *k.paramsOverride
}
return types.DefaultParams()
}
// StoreKey returns the keeper's store key (exported for simtest access to
// the underlying KVStore, e.g. to inject corrupt bytes for marshal-error
// coverage). Mirrors the x/hub simtest pattern (the simtest reaches the
// store via ctx.KVStore(k.StoreKey())).
func (k Keeper) StoreKey() storetypes.StoreKey { return k.storeKey }
// --- CoverPool store ----------------------------------------------------------
var poolKeyPrefix = []byte("pool/")
func poolKey(poolID string) []byte {
return append(poolKeyPrefix, []byte(poolID)...)
}
// GetCoverPool loads a CoverPool by pool-id. Returns the pool and true if
// found, or zero value + false if not.
func (k Keeper) GetCoverPool(ctx sdk.Context, poolID string) (types.CoverPool, bool) {
store := ctx.KVStore(k.storeKey)
bz := store.Get(poolKey(poolID))
if bz == nil {
return types.CoverPool{}, false
}
var p types.CoverPool
if err := json.Unmarshal(bz, &p); err != nil {
return types.CoverPool{}, false
}
return p, true
}
// SetCoverPool persists a CoverPool by pool-id.
func (k Keeper) SetCoverPool(ctx sdk.Context, p types.CoverPool) {
store := ctx.KVStore(k.storeKey)
bz, err := json.Marshal(p)
if err != nil {
panic(fmt.Sprintf("cover: marshal pool %q: %v", p.PoolID, err))
}
store.Set(poolKey(p.PoolID), bz)
}
// AllCoverPools returns all persisted CoverPool records (iteration helper,
// unordered).
func (k Keeper) AllCoverPools(ctx sdk.Context) []types.CoverPool {
store := ctx.KVStore(k.storeKey)
iterator := store.Iterator(poolKeyPrefix, prefixEnd(poolKeyPrefix))
defer iterator.Close()
out := []types.CoverPool{}
for ; iterator.Valid(); iterator.Next() {
var p types.CoverPool
if err := json.Unmarshal(iterator.Value(), &p); err == nil {
out = append(out, p)
}
}
return out
}
// --- CoverCall store ----------------------------------------------------------
var callKeyPrefix = []byte("call/")
func callKey(callID string) []byte {
return append(callKeyPrefix, []byte(callID)...)
}
// GetCoverCall loads a CoverCall by call-id. Returns the call and true if
// found, or zero value + false if not.
func (k Keeper) GetCoverCall(ctx sdk.Context, callID string) (types.CoverCall, bool) {
store := ctx.KVStore(k.storeKey)
bz := store.Get(callKey(callID))
if bz == nil {
return types.CoverCall{}, false
}
var c types.CoverCall
if err := json.Unmarshal(bz, &c); err != nil {
return types.CoverCall{}, false
}
return c, true
}
// SetCoverCall persists a CoverCall by call-id.
func (k Keeper) SetCoverCall(ctx sdk.Context, c types.CoverCall) {
store := ctx.KVStore(k.storeKey)
bz, err := json.Marshal(c)
if err != nil {
panic(fmt.Sprintf("cover: marshal call %q: %v", c.CallID, err))
}
store.Set(callKey(c.CallID), bz)
}
// AllCoverCalls returns all persisted CoverCall records (iteration helper,
// unordered).
func (k Keeper) AllCoverCalls(ctx sdk.Context) []types.CoverCall {
store := ctx.KVStore(k.storeKey)
iterator := store.Iterator(callKeyPrefix, prefixEnd(callKeyPrefix))
defer iterator.Close()
out := []types.CoverCall{}
for ; iterator.Valid(); iterator.Next() {
var c types.CoverCall
if err := json.Unmarshal(iterator.Value(), &c); err == nil {
out = append(out, c)
}
}
return out
}
// --- prefixEnd helper ---------------------------------------------------------
// prefixEnd returns the key that sorts immediately after all keys sharing
// the given prefix (the standard prefix-iteration end key: increment the
// last byte, drop overflow). Used for store.Iterator(start, prefixEnd(start))
// prefix scans. Mirrors x/hub/keeper/keeper.go.
func prefixEnd(prefix []byte) []byte {
if len(prefix) == 0 {
return nil
}
end := make([]byte, len(prefix))
copy(end, prefix)
for i := len(end) - 1; i >= 0; i-- {
end[i]++
if end[i] != 0 {
return end
}
}
// All bytes were 0xFF; return nil (iterate to end of store).
return nil
}
// --- P2: CoverCharter / PoolCouncil / CoverCallVote / CharterAmendment stores --
//
// (REQ-052, REQ-062). Four new stores keyed by ID-string. The
// CoverCharter store is keyed by CharterID; the PoolCouncil store is keyed
// by PoolID (one council per pool); the CoverCallVote store is keyed by
// VoteID; the CharterAmendment store is keyed by AmendmentID. All four
// use the same JSON-marshal pattern as the P1 CoverPool / CoverCall
// stores. The Get/Set/All helpers mirror the P1 helpers.
var charterKeyPrefix = []byte("charter/")
func charterKey(charterID string) []byte {
return append(charterKeyPrefix, []byte(charterID)...)
}
// GetCoverCharter loads a CoverCharter by charter-id. Returns the charter
// and true if found, or zero value + false if not.
func (k Keeper) GetCoverCharter(ctx sdk.Context, charterID string) (types.CoverCharter, bool) {
store := ctx.KVStore(k.storeKey)
bz := store.Get(charterKey(charterID))
if bz == nil {
return types.CoverCharter{}, false
}
var c types.CoverCharter
if err := json.Unmarshal(bz, &c); err != nil {
return types.CoverCharter{}, false
}
return c, true
}
// SetCoverCharter persists a CoverCharter by charter-id.
func (k Keeper) SetCoverCharter(ctx sdk.Context, c types.CoverCharter) {
store := ctx.KVStore(k.storeKey)
bz, err := json.Marshal(c)
if err != nil {
panic(fmt.Sprintf("cover: marshal charter %q: %v", c.CharterID, err))
}
store.Set(charterKey(c.CharterID), bz)
}
// AllCoverCharters returns all persisted CoverCharter records (iteration
// helper, unordered).
func (k Keeper) AllCoverCharters(ctx sdk.Context) []types.CoverCharter {
store := ctx.KVStore(k.storeKey)
iterator := store.Iterator(charterKeyPrefix, prefixEnd(charterKeyPrefix))
defer iterator.Close()
out := []types.CoverCharter{}
for ; iterator.Valid(); iterator.Next() {
var c types.CoverCharter
if err := json.Unmarshal(iterator.Value(), &c); err == nil {
out = append(out, c)
}
}
return out
}
var councilKeyPrefix = []byte("council/")
func councilKey(poolID string) []byte {
return append(councilKeyPrefix, []byte(poolID)...)
}
// GetPoolCouncil loads a PoolCouncil by pool-id. Returns the council and
// true if found, or zero value + false if not.
func (k Keeper) GetPoolCouncil(ctx sdk.Context, poolID string) (types.PoolCouncil, bool) {
store := ctx.KVStore(k.storeKey)
bz := store.Get(councilKey(poolID))
if bz == nil {
return types.PoolCouncil{}, false
}
var c types.PoolCouncil
if err := json.Unmarshal(bz, &c); err != nil {
return types.PoolCouncil{}, false
}
return c, true
}
// SetPoolCouncil persists a PoolCouncil by pool-id.
func (k Keeper) SetPoolCouncil(ctx sdk.Context, c types.PoolCouncil) {
store := ctx.KVStore(k.storeKey)
bz, err := json.Marshal(c)
if err != nil {
panic(fmt.Sprintf("cover: marshal council for pool %q: %v", c.PoolID, err))
}
store.Set(councilKey(c.PoolID), bz)
}
// AllPoolCouncils returns all persisted PoolCouncil records (iteration
// helper, unordered).
func (k Keeper) AllPoolCouncils(ctx sdk.Context) []types.PoolCouncil {
store := ctx.KVStore(k.storeKey)
iterator := store.Iterator(councilKeyPrefix, prefixEnd(councilKeyPrefix))
defer iterator.Close()
out := []types.PoolCouncil{}
for ; iterator.Valid(); iterator.Next() {
var c types.PoolCouncil
if err := json.Unmarshal(iterator.Value(), &c); err == nil {
out = append(out, c)
}
}
return out
}
var voteKeyPrefix = []byte("vote/")
func voteKey(voteID string) []byte {
return append(voteKeyPrefix, []byte(voteID)...)
}
// GetCoverCallVote loads a CoverCallVote by vote-id. Returns the vote and
// true if found, or zero value + false if not.
func (k Keeper) GetCoverCallVote(ctx sdk.Context, voteID string) (types.CoverCallVote, bool) {
store := ctx.KVStore(k.storeKey)
bz := store.Get(voteKey(voteID))
if bz == nil {
return types.CoverCallVote{}, false
}
var v types.CoverCallVote
if err := json.Unmarshal(bz, &v); err != nil {
return types.CoverCallVote{}, false
}
return v, true
}
// SetCoverCallVote persists a CoverCallVote by vote-id.
func (k Keeper) SetCoverCallVote(ctx sdk.Context, v types.CoverCallVote) {
store := ctx.KVStore(k.storeKey)
bz, err := json.Marshal(v)
if err != nil {
panic(fmt.Sprintf("cover: marshal vote %q: %v", v.VoteID, err))
}
store.Set(voteKey(v.VoteID), bz)
}
// AllCoverCallVotes returns all persisted CoverCallVote records (iteration
// helper, unordered).
func (k Keeper) AllCoverCallVotes(ctx sdk.Context) []types.CoverCallVote {
store := ctx.KVStore(k.storeKey)
iterator := store.Iterator(voteKeyPrefix, prefixEnd(voteKeyPrefix))
defer iterator.Close()
out := []types.CoverCallVote{}
for ; iterator.Valid(); iterator.Next() {
var v types.CoverCallVote
if err := json.Unmarshal(iterator.Value(), &v); err == nil {
out = append(out, v)
}
}
return out
}
var amendmentKeyPrefix = []byte("amendment/")
func amendmentKey(amendmentID string) []byte {
return append(amendmentKeyPrefix, []byte(amendmentID)...)
}
// GetCharterAmendment loads a CharterAmendment by amendment-id. Returns
// the amendment and true if found, or zero value + false if not.
func (k Keeper) GetCharterAmendment(ctx sdk.Context, amendmentID string) (types.CharterAmendment, bool) {
store := ctx.KVStore(k.storeKey)
bz := store.Get(amendmentKey(amendmentID))
if bz == nil {
return types.CharterAmendment{}, false
}
var a types.CharterAmendment
if err := json.Unmarshal(bz, &a); err != nil {
return types.CharterAmendment{}, false
}
return a, true
}
// SetCharterAmendment persists a CharterAmendment by amendment-id.
func (k Keeper) SetCharterAmendment(ctx sdk.Context, a types.CharterAmendment) {
store := ctx.KVStore(k.storeKey)
bz, err := json.Marshal(a)
if err != nil {
panic(fmt.Sprintf("cover: marshal amendment %q: %v", a.AmendmentID, err))
}
store.Set(amendmentKey(a.AmendmentID), bz)
}
// AllCharterAmendments returns all persisted CharterAmendment records
// (iteration helper, unordered).
func (k Keeper) AllCharterAmendments(ctx sdk.Context) []types.CharterAmendment {
store := ctx.KVStore(k.storeKey)
iterator := store.Iterator(amendmentKeyPrefix, prefixEnd(amendmentKeyPrefix))
defer iterator.Close()
out := []types.CharterAmendment{}
for ; iterator.Valid(); iterator.Next() {
var a types.CharterAmendment
if err := json.Unmarshal(iterator.Value(), &a); err == nil {
out = append(out, a)
}
}
return out
}
// CoolCharterAmendment transitions a Proposed CharterAmendment to Cooled
// if the 7-day cooling has elapsed (REQ-052). Returns an error if the
// amendment is not found, not in the Proposed status, or the cooling has
// not elapsed. The handler (or simtest) calls this after the cooling
// period; a separate RatifyCharterAmendment transitions to Ratified.
func (k Keeper) CoolCharterAmendment(ctx sdk.Context, amendmentID string, now int64) (types.CharterAmendment, error) {
a, ok := k.GetCharterAmendment(ctx, amendmentID)
if !ok {
return types.CharterAmendment{}, fmt.Errorf("cover: amendment %q not found", amendmentID)
}
if a.Status != types.AmendmentProposed {
return types.CharterAmendment{}, fmt.Errorf("cover: amendment %q status %q (only Proposed can be Cooled)", amendmentID, a.Status)
}
if now-a.ProposedAt < types.CharterAmendmentCoolingSeconds {
return types.CharterAmendment{}, fmt.Errorf("cover: amendment %q cooling not elapsed (now=%d ProposedAt=%d, need %d seconds)", amendmentID, now, a.ProposedAt, types.CharterAmendmentCoolingSeconds)
}
a.Status = types.AmendmentCooled
a.CooledAt = now
k.SetCharterAmendment(ctx, a)
return a, nil
}
// RatifyCharterAmendment transitions a Cooled CharterAmendment to
// Ratified (REQ-052). Returns an error if the amendment is not found or
// not in the Cooled status. The Pool supermajority + Watcher + Counsel
// are checked upstream (the handler); this helper does the state
// transition + appends the amendment to the parent charter's Amendments
// slice.
func (k Keeper) RatifyCharterAmendment(ctx sdk.Context, amendmentID string, now int64) (types.CharterAmendment, error) {
a, ok := k.GetCharterAmendment(ctx, amendmentID)
if !ok {
return types.CharterAmendment{}, fmt.Errorf("cover: amendment %q not found", amendmentID)
}
if a.Status != types.AmendmentCooled {
return types.CharterAmendment{}, fmt.Errorf("cover: amendment %q status %q (only Cooled can be Ratified)", amendmentID, a.Status)
}
a.Status = types.AmendmentRatified
a.RatifiedAt = now
k.SetCharterAmendment(ctx, a)
return a, nil
}
+706
View File
@@ -0,0 +1,706 @@
package keeper
// msg_server.go implements the cover module's MsgServer (REQ-046, REQ-047,
// REQ-049, REQ-050, REQ-052, REQ-055, REQ-056, REQ-062, REQ-048, D-077,
// D-079, D-086, D-088, D-089, D-090). The MsgServer wraps the Keeper + the
// four expected-keeper shims (already on the Keeper: StandingKeeper,
// WatcherKeeper, BondKeeper, StillKeeper).
//
// Each method returns a (*Response, error). Handler state-machine ordering
// is enforced: ValidateBasic -> handler authz/gate -> state mutation ->
// ctx.EventManager().EmitEvent.
//
// P1 handler set:
// - LaunchCoverPool: D-086 category phase check + D-077 Standing gate +
// reserve floor + Watcher attestation; persists the CoverPool.
// - RouteCoverFee: D-079 Anti-Crowding-Out firewall + category-tag match +
// below-floor auto-pause + StillKeeper invocation; emits the routing
// event.
// - FileCoverCall: P1 scaffold — persists the CoverCall + emits an event;
// P4 adds the Voucher adjudication + no-self-adjudication + slashing.
//
// P2 handler set:
// - SignCoverCharter: D-090(1) Bill of Rights gate (ValidateBasic) +
// idempotency + Watcher attestation; persists the CoverCharter.
// - AmendCoverCharter: creates a CharterAmendment with Status=Proposed;
// the 7-day cooling is enforced by CoolCharterAmendment /
// RatifyCharterAmendment (keeper helpers).
// - ElectPoolMason: loads/creates the PoolCouncil + adds the Mason (max
// 3 — a 4th is REJECTED).
// - VoteCoverCall: loads the CoverCall + Watcher-observer-present check
// for a CallVoteYes; persists the CoverCallVote.
// - AmendPoolStandingGate: D-090(3) dual check (ValidateBasic + handler
// re-check) + updates the pool's PoolStandingGate.
// - EscalateReserveCeiling: 12-month age check + Watcher attestation +
// sets the pool's reserve target to CoverReserveCeilingAnnualContribX.
//
// Nil-shim behavior (simtest wiring): a nil StandingKeeper skips the D-077
// gate (the handler still mutates state — the simtest documents the wiring
// contract); a nil WatcherKeeper skips the launch/charter/escalation
// attestation; a nil StillKeeper skips the auto-Still recording (the pool's
// PoolPaused flag is still set, just the Still event is not recorded in a
// still store); a nil BondKeeper is the P1 default (the P4 handler will
// reject a nil shim as a wiring error when the P4 MAB check is wired).
import (
"fmt"
sdk "github.com/cosmos/cosmos-sdk/types"
"github.com/oy/openyield/x/cover/firewall"
"github.com/oy/openyield/x/cover/types"
)
// msgServer is the concrete MsgServer implementation wrapping the Keeper.
type msgServer struct {
Keeper
}
// NewMsgServerImpl returns the cover MsgServer for the provided Keeper.
func NewMsgServerImpl(k Keeper) types.MsgServer {
return &msgServer{Keeper: k}
}
var _ types.MsgServer = msgServer{}
// unwrapCtx extracts the sdk.Context from the interface-typed ctx.
func unwrapCtx(ctx interface{}) sdk.Context {
if c, ok := ctx.(sdk.Context); ok {
return c
}
panic(fmt.Sprintf("cover: expected sdk.Context, got %T", ctx))
}
// gateForCategory returns the locked Standing gate floor for a Cover
// category (D-077). HealthMCS demands the Preferred gate (4.5); Travel +
// IncomePause use the Trusted gate (4.0) as the default. Other Phase2
// categories (none in P1) would also use the Trusted gate; the handler
// rejects out-of-phase categories BEFORE reaching this helper (the D-086
// phase check runs first), so this helper is only called for in-phase
// categories.
func gateForCategory(cat types.CoverCategory) float64 {
if cat == types.CatHealthMCS {
return types.CoverStandingGatePreferred
}
return types.CoverStandingGateTrusted
}
// bucketMeetsGate reports whether a Standing bucket string + score meet the
// locked gate floor (D-077). The bucket string is one of "New", "Trusted",
// "Preferred", "Top", "Slashed" (cross-doc to x/standing.StandingBucket).
// "Trusted" or higher ("Preferred", "Top") meets a Trusted gate; "Preferred"
// or higher ("Top") meets a Preferred gate. The score is a secondary check
// (defense in depth: the bucket is the primary gate, the score confirms).
// "New" or "Slashed" never meets either gate.
func bucketMeetsGate(bucket string, score float64, gate float64) bool {
switch bucket {
case "Top":
return true
case "Preferred":
return gate <= types.CoverStandingGatePreferred && score >= gate
case "Trusted":
return gate <= types.CoverStandingGateTrusted && score >= gate
}
return false
}
// --- LaunchCoverPool ----------------------------------------------------------
// LaunchCoverPool launches a Cover Pool (REQ-046, REQ-047, REQ-049, D-077,
// D-086). The handler enforces:
// 1. ValidateBasic (stateless — floor check on ReserveAnnualContribRatio).
// 2. Idempotency: pool-id must not already exist.
// 3. D-086 category phase check: each category's phase must be in the
// pool's FactoryAllowedPhases (P1 default = [Phase2] only — so only
// Travel/HealthMCS/IncomePause allowed in P1; Phase3/Phase4 categories
// REJECTED).
// 4. D-090(3) dual gate check: the Params.PoolStandingGate >= the protocol
// minimum (CoverStandingGateTrusted) — a pool may tighten the gate but
// never lower it.
// 5. D-077 Standing gate: for each category, query
// StandingKeeper.GetStandingBucket(hostReachID, category). Compare the
// returned bucket + score against the locked gate (Trusted for Travel/
// IncomePause; Preferred for HealthMCS). A nil StandingKeeper skips
// the gate check (simtest wiring).
// 6. Reserve floor re-check (REQ-047 defense in depth):
// ReserveAnnualContribRatio >= CoverReserveFloorAnnualContribX.
// 7. Watcher attestation (REQ-046): WatcherKeeper.Attest(poolID, payload).
// A nil WatcherKeeper skips (simtest).
// 8. Persist the CoverPool (PoolPaused = false, FactoryAllowedPhases +
// PoolStandingGate from Params).
//
// On success an event is emitted.
func (s msgServer) LaunchCoverPool(ctx interface{}, msg *types.MsgLaunchCoverPool) (*types.MsgLaunchCoverPoolResponse, error) {
if err := msg.ValidateBasic(); err != nil {
return nil, err
}
sdkCtx := unwrapCtx(ctx)
// Idempotency: pool-id must not already exist.
if _, ok := s.Keeper.GetCoverPool(sdkCtx, msg.PoolID); ok {
return nil, fmt.Errorf("cover: pool %q already exists", msg.PoolID)
}
// Load the Params (the effective Params: the override if set, else
// DefaultParams). The D-086 simtest case (f) uses the override to
// restrict FactoryAllowedPhases to [Phase2, Phase3] only and reject a
// Phase4 launch. A future P2+ will load the Params from the params
// store; for now the keeper holds the override.
params := s.Keeper.Params()
if err := params.Validate(); err != nil {
return nil, fmt.Errorf("cover: params invalid: %w", err)
}
// D-086 category phase check: each category's phase must be in the
// FactoryAllowedPhases (P1 default = [Phase2] only).
allowed := make(map[types.CoverCategoryPhase]bool, len(params.FactoryAllowedPhases))
for _, ph := range params.FactoryAllowedPhases {
allowed[ph] = true
}
for _, cat := range msg.Categories {
ph := types.CoverCategoryPhaseFor(cat)
if ph == "" {
return nil, fmt.Errorf("cover: unknown category %q (D-086 phase check)", cat)
}
if !allowed[ph] {
return nil, fmt.Errorf("cover: category %q is phase %q, not in FactoryAllowedPhases %v (D-086: P1 allows %v only)", cat, ph, params.FactoryAllowedPhases, params.FactoryAllowedPhases)
}
}
// D-077 Standing gate: for each category, query the host's Standing
// bucket + score and compare against the locked gate. A nil
// StandingKeeper skips the gate check (simtest wiring — documented).
if s.Keeper.standingKeeper != nil {
for _, cat := range msg.Categories {
gate := gateForCategory(cat)
bucket, score, err := s.Keeper.standingKeeper.GetStandingBucket(msg.HostReachID, string(cat))
if err != nil {
return nil, fmt.Errorf("cover: Standing lookup for host %q category %q: %w (D-077 gate)", msg.HostReachID, cat, err)
}
if !bucketMeetsGate(bucket, score, gate) {
return nil, fmt.Errorf("cover: host %q Standing bucket %q score %.2f for category %q does not meet the locked gate %.2f (D-077)", msg.HostReachID, bucket, score, cat, gate)
}
}
}
// Reserve floor re-check (defense in depth — ValidateBasic already
// checked this statelessly).
if msg.ReserveAnnualContribRatio < types.CoverReserveFloorAnnualContribX {
return nil, fmt.Errorf("cover: ReserveAnnualContribRatio %.2f < floor %.2f (REQ-047 handler re-check)", msg.ReserveAnnualContribRatio, types.CoverReserveFloorAnnualContribX)
}
// Watcher attestation (REQ-046). A nil WatcherKeeper skips (simtest).
if s.Keeper.watcherKeeper != nil {
payload := []byte(fmt.Sprintf("cover.launch:%s:%s:%v:%.2f", msg.PoolID, msg.HostReachID, msg.Categories, msg.ReserveAnnualContribRatio))
if _, err := s.Keeper.watcherKeeper.Attest(msg.PoolID, payload); err != nil {
return nil, fmt.Errorf("cover: Watcher attestation for pool %q: %w (REQ-046)", msg.PoolID, err)
}
}
pool := types.CoverPool{
PoolID: msg.PoolID,
HostReachID: msg.HostReachID,
Categories: msg.Categories,
ReserveAnnualContribRatio: msg.ReserveAnnualContribRatio,
ReserveAccount: msg.ReserveAccount,
PoolPaused: false,
CharterHash: msg.CharterHash,
FactoryAllowedPhases: params.FactoryAllowedPhases,
PoolStandingGate: params.PoolStandingGate,
CreatedAt: sdkCtx.BlockTime().Unix(),
}
s.Keeper.SetCoverPool(sdkCtx, pool)
sdkCtx.EventManager().EmitEvent(sdk.NewEvent(
"cover.pool_launched",
sdk.NewAttribute("pool_id", msg.PoolID),
sdk.NewAttribute("host_reach_id", msg.HostReachID),
sdk.NewAttribute("reserve_annual_contrib_ratio", fmt.Sprintf("%.2f", msg.ReserveAnnualContribRatio)),
))
return &types.MsgLaunchCoverPoolResponse{}, nil
}
// --- RouteCoverFee ------------------------------------------------------------
// RouteCoverFee routes a Cover-Fee into a pool's reserve (REQ-050, D-079
// firewall, REQ-047 below-floor auto-pause). The handler enforces:
// 1. ValidateBasic (stateless).
// 2. Load the CoverPool. If not found, REJECT.
// 3. Below-floor pause check (REQ-047): if pool.PoolPaused == true, REJECT
// with "pool paused (below reserve floor)".
// 4. D-079 Anti-Crowding-Out firewall: call
// firewall.CheckCoverFeeRouting(pool.ReserveAccount). If the firewall
// rejects (the destination is NOT permitted — e.g. the pool's
// ReserveAccount is the Root-Pool operating-expenses holder), REJECT.
// 5. Category-tag validation (REQ-050, FR-COVER-11): the CategoryTag must
// match one of the Pool's Categories. Mismatch -> REJECT.
// 6. Reserve floor check (REQ-047): if pool.ReserveAnnualContribRatio <
// floor, REJECT the routing AND set pool.PoolPaused = true (auto-pause)
// AND invoke StillKeeper.Still(poolID, "below reserve floor") (D-089(1)
// — nil StillKeeper skips). Persist the paused pool. Emit
// cover.pool_below_floor.
// 7. Otherwise: emit cover.cover_fee_routed (the routing is the event; the
// reserve balance update is a simtest-grade stub).
func (s msgServer) RouteCoverFee(ctx interface{}, msg *types.MsgRouteCoverFee) (*types.MsgRouteCoverFeeResponse, error) {
if err := msg.ValidateBasic(); err != nil {
return nil, err
}
sdkCtx := unwrapCtx(ctx)
pool, ok := s.Keeper.GetCoverPool(sdkCtx, msg.PoolID)
if !ok {
return nil, fmt.Errorf("cover: pool %q not found (RouteCoverFee rejected)", msg.PoolID)
}
// Below-floor pause check: a paused pool rejects all routing.
if pool.PoolPaused {
return nil, fmt.Errorf("cover: pool %q paused (below reserve floor) — routing rejected", msg.PoolID)
}
// D-079 Anti-Crowding-Out firewall: the destination (the pool's
// ReserveAccount) must be a permitted routing destination. The firewall
// is the second-layer defense (the first layer is the handler's own
// destination-match check — the destination IS pool.ReserveAccount by
// construction; the firewall catches a pool misconfigured to route to
// the Root-Pool operating-expenses holder).
if err := firewall.CheckCoverFeeRouting(pool.ReserveAccount); err != nil {
return nil, fmt.Errorf("cover: %w (pool %q ReserveAccount %q)", err, msg.PoolID, pool.ReserveAccount)
}
// Category-tag validation (REQ-050, FR-COVER-11): the CategoryTag must
// match one of the Pool's Categories.
tagMatched := false
for _, cat := range pool.Categories {
if string(cat) == msg.CategoryTag {
tagMatched = true
break
}
}
if !tagMatched {
return nil, fmt.Errorf("cover: CategoryTag %q does not match any of pool %q categories %v (REQ-050)", msg.CategoryTag, msg.PoolID, pool.Categories)
}
// Reserve floor check (REQ-047): if the pool's ReserveAnnualContribRatio
// is below the floor, REJECT the routing AND auto-pause the pool AND
// invoke StillKeeper.Still (D-089(1)). A nil StillKeeper skips the
// Still recording (the pool's PoolPaused flag is still set).
if pool.ReserveAnnualContribRatio < types.CoverReserveFloorAnnualContribX {
pool.PoolPaused = true
s.Keeper.SetCoverPool(sdkCtx, pool)
if s.Keeper.stillKeeper != nil {
if err := s.Keeper.stillKeeper.Still(msg.PoolID, "below reserve floor"); err != nil {
return nil, fmt.Errorf("cover: Still invocation for pool %q (below reserve floor): %w (D-089(1))", msg.PoolID, err)
}
}
sdkCtx.EventManager().EmitEvent(sdk.NewEvent(
"cover.pool_below_floor",
sdk.NewAttribute("pool_id", msg.PoolID),
sdk.NewAttribute("reserve_annual_contrib_ratio", fmt.Sprintf("%.2f", pool.ReserveAnnualContribRatio)),
sdk.NewAttribute("floor", fmt.Sprintf("%.2f", types.CoverReserveFloorAnnualContribX)),
))
return nil, fmt.Errorf("cover: pool %q below reserve floor (%.2f < %.2f) — routing rejected, pool auto-paused (REQ-047)", msg.PoolID, pool.ReserveAnnualContribRatio, types.CoverReserveFloorAnnualContribX)
}
// Success: the routing is the event (the reserve balance update is a
// simtest-grade stub — P2 may add a CoverFeeRouting record).
sdkCtx.EventManager().EmitEvent(sdk.NewEvent(
"cover.cover_fee_routed",
sdk.NewAttribute("pool_id", msg.PoolID),
sdk.NewAttribute("category_tag", msg.CategoryTag),
sdk.NewAttribute("grain_amount", fmt.Sprintf("%d", msg.GrainAmount)),
sdk.NewAttribute("reserve_account", pool.ReserveAccount),
))
return &types.MsgRouteCoverFeeResponse{}, nil
}
// --- FileCoverCall ------------------------------------------------------------
// FileCoverCall files a Cover Call against a pool's category (REQ-055 P1
// scaffold — the Voucher adjudication lands in P4). The handler enforces:
// 1. ValidateBasic (stateless).
// 2. Load the CoverPool. If not found, REJECT.
// 3. The category must match one of the Pool's Categories.
// 4. Persist the CoverCall. Emit cover.cover_call_filed.
//
// P4 adds: the Voucher assignment + no-self-adjudication (the
// ClaimantReachID must not be the adjudicating Voucher) + the MAB misuse
// auto-Still (D-089(1) — a Voucher whose MAB is slashed triggers the
// StillKeeper).
func (s msgServer) FileCoverCall(ctx interface{}, msg *types.MsgFileCoverCall) (*types.MsgFileCoverCallResponse, error) {
if err := msg.ValidateBasic(); err != nil {
return nil, err
}
sdkCtx := unwrapCtx(ctx)
pool, ok := s.Keeper.GetCoverPool(sdkCtx, msg.PoolID)
if !ok {
return nil, fmt.Errorf("cover: pool %q not found (FileCoverCall rejected)", msg.PoolID)
}
// The category must match one of the Pool's Categories.
catMatched := false
for _, cat := range pool.Categories {
if cat == msg.Category {
catMatched = true
break
}
}
if !catMatched {
return nil, fmt.Errorf("cover: category %q does not match any of pool %q categories %v", msg.Category, msg.PoolID, pool.Categories)
}
call := types.CoverCall{
CallID: msg.CallID,
PoolID: msg.PoolID,
ClaimantReachID: msg.ClaimantReachID,
Category: msg.Category,
AmountGrain: msg.AmountGrain,
FiledAt: sdkCtx.BlockHeight(),
}
s.Keeper.SetCoverCall(sdkCtx, call)
sdkCtx.EventManager().EmitEvent(sdk.NewEvent(
"cover.cover_call_filed",
sdk.NewAttribute("call_id", msg.CallID),
sdk.NewAttribute("pool_id", msg.PoolID),
sdk.NewAttribute("claimant_reach_id", msg.ClaimantReachID),
sdk.NewAttribute("category", string(msg.Category)),
sdk.NewAttribute("amount_grain", fmt.Sprintf("%d", msg.AmountGrain)),
))
return &types.MsgFileCoverCallResponse{}, nil
}
// --- P2: SignCoverCharter -----------------------------------------------------
// SignCoverCharter signs a Cover-Charter for a Pool (REQ-052, REQ-056,
// D-090(1)). The handler enforces:
// 1. ValidateBasic (stateless — includes the D-090(1) Bill of Rights
// gate: any WaivedRights element REJECTS the signing).
// 2. Idempotency: CharterID must not already exist.
// 3. The referenced Pool must exist (the charter binds to a pool).
// 4. WatcherKeeper.Attest on the charter witness hash (a nil WatcherKeeper
// skips; an empty WatcherWitnessHash skips).
// 5. Persist the CoverCharter + link the pool's CharterRef.
// 6. Emit cover.charter_signed.
func (s msgServer) SignCoverCharter(ctx interface{}, msg *types.MsgSignCoverCharter) (*types.MsgSignCoverCharterResponse, error) {
if err := msg.ValidateBasic(); err != nil {
return nil, err
}
sdkCtx := unwrapCtx(ctx)
// Idempotency: charter-id must not already exist.
if _, ok := s.Keeper.GetCoverCharter(sdkCtx, msg.CharterID); ok {
return nil, fmt.Errorf("cover: charter %q already exists", msg.CharterID)
}
// The referenced pool must exist (the charter binds to a pool).
pool, ok := s.Keeper.GetCoverPool(sdkCtx, msg.PoolID)
if !ok {
return nil, fmt.Errorf("cover: pool %q not found (SignCoverCharter rejected)", msg.PoolID)
}
// Watcher attestation over the witness hash (REQ-052). A nil
// WatcherKeeper skips; an empty WatcherWitnessHash skips (the charter
// may be signed without a witness in simtest).
if s.Keeper.watcherKeeper != nil && len(msg.WatcherWitnessHash) > 0 {
if _, err := s.Keeper.watcherKeeper.Attest(msg.PoolID, msg.WatcherWitnessHash); err != nil {
return nil, fmt.Errorf("cover: Watcher attestation for charter %q: %w (REQ-052)", msg.CharterID, err)
}
}
charter := types.CoverCharter{
CharterID: msg.CharterID,
PoolID: msg.PoolID,
StatementOfBeliefsHash: msg.StatementOfBeliefsHash,
DisputePath: msg.DisputePath,
Gate: msg.Gate,
HoldingPeriodDays: msg.HoldingPeriodDays,
HostReachID: msg.HostReachID,
WatcherWitnessHash: msg.WatcherWitnessHash,
Amendments: []types.CharterAmendment{},
WaivedRights: msg.WaivedRights,
}
s.Keeper.SetCoverCharter(sdkCtx, charter)
// Link the pool's CharterRef.
pool.CharterRef = msg.CharterID
s.Keeper.SetCoverPool(sdkCtx, pool)
sdkCtx.EventManager().EmitEvent(sdk.NewEvent(
"cover.charter_signed",
sdk.NewAttribute("charter_id", msg.CharterID),
sdk.NewAttribute("pool_id", msg.PoolID),
sdk.NewAttribute("host_reach_id", msg.HostReachID),
))
return &types.MsgSignCoverCharterResponse{}, nil
}
// --- P2: AmendCoverCharter ----------------------------------------------------
// AmendCoverCharter files a Charter amendment (REQ-052). The handler
// enforces:
// 1. ValidateBasic (stateless).
// 2. The referenced charter must exist.
// 3. Create a CharterAmendment with Status=AmendmentProposed,
// ProposedAt=now. Persist the amendment + append to the charter's
// Amendments slice.
// 4. Emit cover.charter_amend_proposed.
//
// The 7-day cooling is enforced by CoolCharterAmendment /
// RatifyCharterAmendment (keeper helpers) — a simtest time-advance or a
// separate handler transitions the amendment to Cooled then Ratified.
func (s msgServer) AmendCoverCharter(ctx interface{}, msg *types.MsgAmendCoverCharter) (*types.MsgAmendCoverCharterResponse, error) {
if err := msg.ValidateBasic(); err != nil {
return nil, err
}
sdkCtx := unwrapCtx(ctx)
charter, ok := s.Keeper.GetCoverCharter(sdkCtx, msg.CharterID)
if !ok {
return nil, fmt.Errorf("cover: charter %q not found (AmendCoverCharter rejected)", msg.CharterID)
}
// Idempotency: amendment-id must not already exist.
if _, ok := s.Keeper.GetCharterAmendment(sdkCtx, msg.AmendmentID); ok {
return nil, fmt.Errorf("cover: amendment %q already exists", msg.AmendmentID)
}
amendment := types.CharterAmendment{
AmendmentID: msg.AmendmentID,
Description: msg.Description,
Status: types.AmendmentProposed,
ProposedAt: sdkCtx.BlockTime().Unix(),
}
s.Keeper.SetCharterAmendment(sdkCtx, amendment)
// Append the amendment to the charter's Amendments slice + persist.
charter.Amendments = append(charter.Amendments, amendment)
s.Keeper.SetCoverCharter(sdkCtx, charter)
sdkCtx.EventManager().EmitEvent(sdk.NewEvent(
"cover.charter_amend_proposed",
sdk.NewAttribute("charter_id", msg.CharterID),
sdk.NewAttribute("amendment_id", msg.AmendmentID),
))
return &types.MsgAmendCoverCharterResponse{}, nil
}
// --- P2: ElectPoolMason -------------------------------------------------------
// ElectPoolMason elects a Mason to the Pool Council (REQ-062). The
// handler enforces:
// 1. ValidateBasic (stateless).
// 2. The referenced pool must exist.
// 3. Load or create the PoolCouncil. Add the MasonReachID to
// ElectedMasonReachIDs (max PoolCouncilMaxMasons = 3 — a 4th is
// REJECTED). Reject a duplicate MasonReachID (already elected).
// 4. Persist the PoolCouncil + link the pool's CouncilRef.
// 5. Emit cover.pool_mason_elected.
func (s msgServer) ElectPoolMason(ctx interface{}, msg *types.MsgElectPoolMason) (*types.MsgElectPoolMasonResponse, error) {
if err := msg.ValidateBasic(); err != nil {
return nil, err
}
sdkCtx := unwrapCtx(ctx)
pool, ok := s.Keeper.GetCoverPool(sdkCtx, msg.PoolID)
if !ok {
return nil, fmt.Errorf("cover: pool %q not found (ElectPoolMason rejected)", msg.PoolID)
}
council, exists := s.Keeper.GetPoolCouncil(sdkCtx, msg.PoolID)
if !exists {
council = types.PoolCouncil{
PoolID: msg.PoolID,
HostReachID: pool.HostReachID,
ElectedMasonReachIDs: [3]string{},
}
}
// Reject a duplicate MasonReachID (already elected).
for _, m := range council.ElectedMasonReachIDs {
if m == msg.MasonReachID {
return nil, fmt.Errorf("cover: mason %q already elected to pool %q council (REQ-062)", msg.MasonReachID, msg.PoolID)
}
}
// Find the first empty slot; if all 3 are filled, REJECT (max
// PoolCouncilMaxMasons).
slotIdx := -1
for i, m := range council.ElectedMasonReachIDs {
if m == "" {
slotIdx = i
break
}
}
if slotIdx == -1 {
return nil, fmt.Errorf("cover: pool %q council already has %d masons (REQ-062 max %d)", msg.PoolID, types.PoolCouncilMaxMasons, types.PoolCouncilMaxMasons)
}
council.ElectedMasonReachIDs[slotIdx] = msg.MasonReachID
s.Keeper.SetPoolCouncil(sdkCtx, council)
// Link the pool's CouncilRef (the council is keyed by pool-id, so the
// ref is the pool-id itself).
pool.CouncilRef = msg.PoolID
s.Keeper.SetCoverPool(sdkCtx, pool)
sdkCtx.EventManager().EmitEvent(sdk.NewEvent(
"cover.pool_mason_elected",
sdk.NewAttribute("pool_id", msg.PoolID),
sdk.NewAttribute("mason_reach_id", msg.MasonReachID),
sdk.NewAttribute("slot", fmt.Sprintf("%d", slotIdx)),
))
return &types.MsgElectPoolMasonResponse{}, nil
}
// --- P2: VoteCoverCall --------------------------------------------------------
// VoteCoverCall votes on a Cover Call (REQ-062). The handler enforces:
// 1. ValidateBasic (stateless — includes the valid VoteOption check).
// 2. The referenced CoverCall must exist.
// 3. The Watcher-observer-present check: if VoteOption == CallVoteYes and
// WatcherObserverPresent == false, REJECT (majority requires observer
// present — REQ-062).
// 4. Idempotency: VoteID must not already exist.
// 5. Persist the CoverCallVote. Emit cover.cover_call_voted.
func (s msgServer) VoteCoverCall(ctx interface{}, msg *types.MsgVoteCoverCall) (*types.MsgVoteCoverCallResponse, error) {
if err := msg.ValidateBasic(); err != nil {
return nil, err
}
sdkCtx := unwrapCtx(ctx)
// The referenced CoverCall must exist.
if _, ok := s.Keeper.GetCoverCall(sdkCtx, msg.CallID); !ok {
return nil, fmt.Errorf("cover: call %q not found (VoteCoverCall rejected)", msg.CallID)
}
// The Watcher-observer-present check (REQ-062): a CallVoteYes requires
// the Watcher observer to be present. A CallVoteNo / CallVoteAbstain
// does NOT require the observer (only an affirmative vote demands the
// witness).
if msg.VoteOption == types.CallVoteYes && !msg.WatcherObserverPresent {
return nil, fmt.Errorf("cover: CallVoteYes on call %q requires Watcher observer present (REQ-062)", msg.CallID)
}
// Idempotency: vote-id must not already exist.
if _, ok := s.Keeper.GetCoverCallVote(sdkCtx, msg.VoteID); ok {
return nil, fmt.Errorf("cover: vote %q already exists", msg.VoteID)
}
vote := types.CoverCallVote{
VoteID: msg.VoteID,
CallID: msg.CallID,
PoolID: msg.PoolID,
VoterReachID: msg.VoterReachID,
VoteOption: msg.VoteOption,
WatcherObserverPresent: msg.WatcherObserverPresent,
VotedAt: sdkCtx.BlockTime().Unix(),
}
s.Keeper.SetCoverCallVote(sdkCtx, vote)
sdkCtx.EventManager().EmitEvent(sdk.NewEvent(
"cover.cover_call_voted",
sdk.NewAttribute("vote_id", msg.VoteID),
sdk.NewAttribute("call_id", msg.CallID),
sdk.NewAttribute("pool_id", msg.PoolID),
sdk.NewAttribute("voter_reach_id", msg.VoterReachID),
sdk.NewAttribute("vote_option", string(msg.VoteOption)),
))
return &types.MsgVoteCoverCallResponse{}, nil
}
// --- P2: AmendPoolStandingGate ------------------------------------------------
// AmendPoolStandingGate amends a Pool's Standing gate (D-090(3)). The
// handler enforces:
// 1. ValidateBasic (stateless — includes the D-090(3) dual check:
// NewGate >= CoverStandingGateTrusted).
// 2. The referenced pool must exist.
// 3. D-090(3) handler re-check (defense in depth): NewGate >=
// CoverStandingGateTrusted. ValidateBasic already checked, but the
// handler re-checks in case of a future Params-bypass.
// 4. Update the pool's PoolStandingGate. Persist.
// 5. Emit cover.pool_standing_gate_amended.
func (s msgServer) AmendPoolStandingGate(ctx interface{}, msg *types.MsgAmendPoolStandingGate) (*types.MsgAmendPoolStandingGateResponse, error) {
if err := msg.ValidateBasic(); err != nil {
return nil, err
}
sdkCtx := unwrapCtx(ctx)
pool, ok := s.Keeper.GetCoverPool(sdkCtx, msg.PoolID)
if !ok {
return nil, fmt.Errorf("cover: pool %q not found (AmendPoolStandingGate rejected)", msg.PoolID)
}
// D-090(3) handler re-check (defense in depth — ValidateBasic already
// checked, but the handler re-checks in case of a future Params-bypass).
if msg.NewGate < types.CoverStandingGateTrusted {
return nil, fmt.Errorf("cover: NewGate %.2f < CoverStandingGateTrusted %.2f (D-090(3) handler re-check: a pool may tighten the gate but never lower it)", msg.NewGate, types.CoverStandingGateTrusted)
}
pool.PoolStandingGate = msg.NewGate
s.Keeper.SetCoverPool(sdkCtx, pool)
sdkCtx.EventManager().EmitEvent(sdk.NewEvent(
"cover.pool_standing_gate_amended",
sdk.NewAttribute("pool_id", msg.PoolID),
sdk.NewAttribute("new_gate", fmt.Sprintf("%.2f", msg.NewGate)),
))
return &types.MsgAmendPoolStandingGateResponse{}, nil
}
// --- P2: EscalateReserveCeiling -----------------------------------------------
// EscalateReserveCeiling escalates a Pool's reserve target to the
// CoverReserveCeilingAnnualContribX (REQ-048). The handler enforces:
// 1. ValidateBasic (stateless).
// 2. The referenced pool must exist.
// 3. 12-month age check: now - pool.CreatedAt >= ReserveCeilingAgeSeconds
// (365 days). A fresh pool is REJECTED. NOTE: pool.CreatedAt is set to
// sdkCtx.BlockHeight() at launch in P1; for the age check we use
// BlockTime().Unix() - pool.CreatedAt where pool.CreatedAt is
// interpreted as a unix timestamp (the simtest sets CreatedAt to a
// unix timestamp to satisfy this check).
// 4. Set the pool's ReserveAnnualContribRatio to
// CoverReserveCeilingAnnualContribX (2.5).
// 5. WatcherKeeper.Attest (a nil WatcherKeeper skips).
// 6. Persist the updated pool. Emit cover.reserve_ceiling_escalated.
func (s msgServer) EscalateReserveCeiling(ctx interface{}, msg *types.MsgEscalateReserveCeiling) (*types.MsgEscalateReserveCeilingResponse, error) {
if err := msg.ValidateBasic(); err != nil {
return nil, err
}
sdkCtx := unwrapCtx(ctx)
pool, ok := s.Keeper.GetCoverPool(sdkCtx, msg.PoolID)
if !ok {
return nil, fmt.Errorf("cover: pool %q not found (EscalateReserveCeiling rejected)", msg.PoolID)
}
// 12-month age check (REQ-048): the pool must have >= 365 days of
// operating history before the reserve target can be escalated to the
// ceiling. pool.CreatedAt is interpreted as a unix timestamp (the
// simtest sets it accordingly).
now := sdkCtx.BlockTime().Unix()
if now-pool.CreatedAt < types.ReserveCeilingAgeSeconds {
return nil, fmt.Errorf("cover: pool %q age %d seconds < %d seconds (REQ-048: 12-month operating history required for reserve ceiling escalation)", msg.PoolID, now-pool.CreatedAt, types.ReserveCeilingAgeSeconds)
}
// Set the pool's reserve target to the ceiling.
pool.ReserveAnnualContribRatio = types.CoverReserveCeilingAnnualContribX
// Watcher attestation (REQ-048). A nil WatcherKeeper skips.
if s.Keeper.watcherKeeper != nil {
payload := []byte(fmt.Sprintf("cover.escalate:%s:%.2f", msg.PoolID, types.CoverReserveCeilingAnnualContribX))
if _, err := s.Keeper.watcherKeeper.Attest(msg.PoolID, payload); err != nil {
return nil, fmt.Errorf("cover: Watcher attestation for reserve ceiling escalation on pool %q: %w (REQ-048)", msg.PoolID, err)
}
}
s.Keeper.SetCoverPool(sdkCtx, pool)
sdkCtx.EventManager().EmitEvent(sdk.NewEvent(
"cover.reserve_ceiling_escalated",
sdk.NewAttribute("pool_id", msg.PoolID),
sdk.NewAttribute("reserve_annual_contrib_ratio", fmt.Sprintf("%.2f", types.CoverReserveCeilingAnnualContribX)),
))
return &types.MsgEscalateReserveCeilingResponse{}, nil
}
File diff suppressed because it is too large Load Diff
+82
View File
@@ -0,0 +1,82 @@
package cover
// module.go holds the cover module's AppModule + RegisterServices (REQ-046,
// D-054 simtest-grade).
//
// The AppModule wraps the cover Keeper and registers the MsgServer via
// RegisterServices. This is the simtest-grade AppModule (D-054): the
// RegisterServices wires the hand-rolled MsgServer (no protobuf codegen
// per the skeleton's zero-codegen style). The MsgServer is constructed
// directly and exposed via the module for test wiring.
//
// The four expected-keeper shims (StandingKeeper, WatcherKeeper,
// BondKeeper, StillKeeper) are injected at construction (all nil-able for
// partial tests — a nil StandingKeeper skips the D-077 gate; a nil
// WatcherKeeper skips the launch attestation; a nil StillKeeper skips the
// auto-Still recording; a nil BondKeeper is the P1 default).
import (
"encoding/json"
storetypes "cosmossdk.io/store/types"
"github.com/cosmos/cosmos-sdk/codec"
sdk "github.com/cosmos/cosmos-sdk/types"
"github.com/cosmos/cosmos-sdk/types/module"
"github.com/oy/openyield/x/cover/keeper"
"github.com/oy/openyield/x/cover/types"
)
// ConsensusVersion is the cover module's consensus version (AppModule).
const ConsensusVersion = 1
// AppModule is the cover application module (simtest-grade — D-054).
type AppModule struct {
keeper keeper.Keeper
}
// NewAppModule constructs a new cover AppModule. The four expected-keeper
// shims are injected (all nil-able for partial tests).
func NewAppModule(cdc codec.Codec, storeKey storetypes.StoreKey, sk types.StandingKeeper, wk types.WatcherKeeper, bk types.BondKeeper, stK types.StillKeeper) AppModule {
k := keeper.NewKeeper(cdc, storeKey, sk, wk, bk, stK)
return AppModule{keeper: k}
}
// RegisterServices registers the cover MsgServer. Simtest-grade wiring:
// the MsgServer is constructed from the keeper and exposed via the
// module's MsgServer method (tests use NewMsgServerImpl directly).
func (am AppModule) RegisterServices(cfg module.Configurator) {
_ = cfg
}
// MsgServer returns the cover MsgServer for this module's keeper.
func (am AppModule) MsgServer() types.MsgServer {
return keeper.NewMsgServerImpl(am.keeper)
}
// Name returns the module name.
func (AppModule) Name() string { return types.ModuleName }
// ConsensusVersion implements AppModule.ConsensusVersion.
func (AppModule) ConsensusVersion() uint64 { return ConsensusVersion }
// InitGenesis performs genesis initialization for the cover module
// (simtest-grade no-op — the runtime stores are created at handler time;
// genesis init of runtime-promoted stores is deferred to the live chain
// v0.8+).
func (am AppModule) InitGenesis(ctx sdk.Context, cdc codec.JSONCodec, data json.RawMessage) {
var gs types.GenesisState
cdc.MustUnmarshalJSON(data, &gs)
_ = gs
}
// ExportGenesis returns the exported genesis state as raw bytes (simtest-
// grade: returns an empty genesis; live chain export deferred to v0.8+).
func (am AppModule) ExportGenesis(ctx sdk.Context, cdc codec.JSONCodec) json.RawMessage {
gs := types.DefaultGenesisState()
return cdc.MustMarshalJSON(gs)
}
// Compile-time assertions: AppModule implements the module interface stubs.
var _ module.HasName = AppModule{}
var _ module.HasConsensusVersion = AppModule{}
+141
View File
@@ -0,0 +1,141 @@
package types
// expected_keepers.go holds the Go INTERFACES for the cross-module keepers
// x/cover depends on (G-003 firewall — ibc-go expected-keepers convention).
//
// The cover runtime (REQ-046, REQ-047, REQ-049, REQ-050) depends on FOUR
// cross-module keepers:
//
// 1. x/standing (StandingKeeper) — the LaunchCoverPool handler asserts the
// host's Standing per category meets the locked gate (D-077: Travel
// requires >= Trusted; HealthMCS requires >= Preferred; IncomePause
// uses the Trusted gate). The handler queries GetStandingBucket for the
// bucket string + score and compares against the CoverStandingGateTrusted
// / CoverStandingGatePreferred consts. This is the v0.7 P1 cover-launch
// edge: the Cover module references a holder's Standing by reach-id +
// category (G-003 — no struct import of x/standing/types).
//
// 2. x/watcher (WatcherKeeper) — the LaunchCoverPool handler emits a
// Watcher attestation over the launch payload (REQ-046). The attestation
// is the Watcher's signed observation that the pool was launched per
// the validated terms. P1 stubs the attestation in simtest; the live
// x/watcher pipeline lands in P3.
//
// 3. x/bond (BondKeeper) — the FileCoverCall handler (P4) consults the
// Mutual Aid Bond (MAB) posted by the adjudicating Voucher. P1 DEFINES
// the interface but does NOT use it (the MAB misuse auto-Still + the
// Voucher adjudication land in P4). The interface is here so the P1
// wiring is stable.
//
// 4. x/still (StillKeeper) — the RouteCoverFee handler invokes
// Still(poolID, "below reserve floor") on the below-floor auto-pause
// (D-089(1)) and the P4 MAB-misuse auto-Still. P1 satisfies this by a
// simtest-local stub (x/still/keeper is empty; NOT a real keeper). A
// nil StillKeeper skips the auto-Still (simtest wiring — documented).
//
// All four dependencies are expressed as INTERFACES defined HERE (in
// x/cover/types), NOT as struct imports of any x/<module>/types. The
// concrete keepers (or simtest stubs) satisfy these interfaces structurally
// (the P1 simtest wires stubs per G-003 test exemption); the handler
// depends on the interface, preserving G-003's intent (no cross-module
// struct coupling, no import cycles).
//
// Test-only cross-package imports (the G-003 test exemption) remain exempt:
// the simtest imports x/cover/keeper + the stub keepers (defined in the
// test file) to wire the shims in test setup — NOT a production struct
// import.
//
// Lexicon note (REQ-012, D-088): "Cover", "Cover Pool", "Cover-Fee",
// "Cover Call", "Standing", "Watcher", "Bond", "Mutual Aid Bond", "Still"
// are all lexicon-clean. The Cover-specific banned terms (enumerated by
// lexicon.CoverBannedTerms — not inlined here so this source stays
// lexicon-clean) NEVER appear in this file (enforced by lexicon_meta_cover).
// StandingKeeper is the expected-keeper interface for x/standing (G-003).
// The LaunchCoverPool handler calls it for the D-077 Standing gate: for
// each category the pool covers, the handler queries the host's Standing
// bucket + score and compares against the locked gate consts
// (CoverStandingGateTrusted for Travel/IncomePause;
// CoverStandingGatePreferred for HealthMCS). A bucket below the locked
// minimum REJECTS the launch.
//
// No struct import of x/standing/types — the interface is the by-ID-string
// boundary (G-003). The reachID + category are opaque strings (the holder's
// reach-id + the Cover category name). A nil StandingKeeper skips the gate
// check (simtest wiring — documented in the handler: a nil shim is the
// simtest's way of saying "no Standing keeper wired; skip the gate" so the
// handler still mutates state for the simtest path that does not exercise
// the gate).
type StandingKeeper interface {
// GetStandingBucket returns the holder's Standing bucket string +
// score for the given category (D-077). The bucket string is one of
// "New", "Trusted", "Preferred", "Top", "Slashed" (cross-doc to
// x/standing.StandingBucket); the handler compares the bucket +
// score against the locked gate consts. A non-existent holder
// returns ("", 0, err) — the handler treats this as a gate failure
// (REJECT).
GetStandingBucket(reachID, category string) (bucket string, score float64, err error)
}
// WatcherKeeper is the expected-keeper interface for x/watcher (G-003). The
// LaunchCoverPool handler calls it to emit a Watcher attestation over the
// launch payload (REQ-046): the Watcher signs an observation that the pool
// was launched per the validated terms. The attestation-ref is recorded
// against the pool (for audit). P1 stubs the attestation in simtest; the
// live x/watcher pipeline lands in P3.
//
// No struct import of x/watcher/types — the interface is the by-ID-string
// boundary (G-003). The poolID is an opaque string (the Cover Pool's ID).
// A nil WatcherKeeper skips the attestation (simtest wiring — documented in
// the handler: a nil shim is the simtest's way of saying "no Watcher keeper
// wired; skip the attestation" so the handler still mutates state).
type WatcherKeeper interface {
// Attest emits a Watcher attestation over the payload (the launch
// terms serialized as bytes). Returns the attestation-ref (an opaque
// string the handler records against the pool for audit). A non-nil
// error REJECTS the launch (the Watcher could not attest — the pool
// is not created).
Attest(poolID string, payload []byte) (attestationRef string, err error)
}
// BondKeeper is the expected-keeper interface for x/bond (G-003). P1 DEFINES
// the interface but does NOT use it (the FileCoverCall handler in P4
// consults the Mutual Aid Bond posted by the adjudicating Voucher; the MAB
// misuse auto-Still is also P4). The interface is here so the P1 wiring is
// stable (the keeper holds the shim; the P4 handler calls it).
//
// No struct import of x/bond/types — the interface is the by-ID-string
// boundary (G-003). The bondID is an opaque string (the MAB's ID). A nil
// BondKeeper is the P1 default (the keeper holds nil; the P4 handler will
// reject a nil shim as a wiring error when the P4 MAB check is wired).
type BondKeeper interface {
// GetBond reports whether the named bond (by-ID-string) exists. The
// P4 FileCoverCall handler consults this to verify the adjudicating
// Voucher's MAB is posted before adjudication. P1 does not call this.
GetBond(bondID string) (exists bool)
}
// StillKeeper is the expected-keeper interface for x/still (G-003). The
// RouteCoverFee handler invokes Still(poolID, "below reserve floor") on
// the below-floor auto-pause (D-089(1): a pool whose
// ReserveAnnualContribRatio drops below CoverReserveFloorAnnualContribX is
// auto-paused + the Still keeper is invoked to record the pause). The P4
// MAB-misuse auto-Still also calls this. P1 satisfies this by a simtest-
// local stub (x/still/keeper is empty; NOT a real keeper — the simtest
// stub records Still() calls for assertion).
//
// No struct import of x/still/types — the interface is the by-ID-string
// boundary (G-003). The poolID is an opaque string (the Cover Pool's ID);
// the reason is an opaque string (the pause reason, e.g. "below reserve
// floor"). A nil StillKeeper skips the auto-Still (simtest wiring —
// documented in the handler: a nil shim is the simtest's way of saying "no
// Still keeper wired; skip the pause-recording" so the handler still
// mutates the pool's PoolPaused flag, just does not record the Still event
// in a still store).
type StillKeeper interface {
// Still pauses the named entity (by-ID-string) for the given reason.
// The RouteCoverFee handler calls this on the below-floor auto-pause
// (D-089(1)). A non-nil error REJECTS the routing (the pause could
// not be recorded — the routing is not committed).
Still(poolID string, reason string) error
}
+462
View File
@@ -0,0 +1,462 @@
package types
// msg_charter.go holds the P2 Cover-Charter + Pool-Council + Cover-Call-Vote
// Msg* types (REQ-052, REQ-062, REQ-056, REQ-048, D-090(1), D-090(3)). The
// P1 Msg* types live in msg_cover.go; this file is the P2 extension
// (separated for file-hygiene — the P1 file is already at ~280 lines).
//
// G-006 controlled exception: this file gains the cosmos-sdk import for
// sdk.Msg (mirrors msg_cover.go — D-055; the invariant/lexicon tests in
// *_test.go stay stdlib-only per G-024, isolated from this msg_*.go file).
//
// The six P2 Msg types drive the Cover-Charter + Pool Council + Cover Call
// Vote runtime:
// - MsgSignCoverCharter: sign a Cover-Charter (the handler enforces the
// D-090(1) Bill of Rights gate at ValidateBasic: any WaivedRights
// element REJECTS the signing; persists the CoverCharter + Watcher
// attests the witness hash).
// - MsgAmendCoverCharter: file a Charter amendment (the handler creates a
// CharterAmendment with Status=AmendmentProposed; a separate ratify
// handler / simtest time-advance transitions it to Cooled then
// Ratified after the 7-day cooling).
// - MsgElectPoolMason: elect a Mason to the Pool Council (the handler
// adds the MasonReachID to ElectedMasonReachIDs, max 3 — a 4th is
// REJECTED).
// - MsgVoteCoverCall: vote on a Cover Call (the handler enforces the
// Watcher-observer-present check for a CallVoteYes — REQ-062).
// - MsgAmendPoolStandingGate: amend a Pool's Standing gate (D-090(3) dual
// check: ValidateBasic rejects NewGate < CoverStandingGateTrusted; the
// handler re-checks in defense in depth).
// - MsgEscalateReserveCeiling: escalate a Pool's reserve target to the
// CoverReserveCeilingAnnualContribX (REQ-048 — the handler enforces
// the 12-month age check: now - pool.CreatedAt >= 365 days).
//
// All cross-module refs are by-ID-string (G-003). The WaivedRights field
// on MsgSignCoverCharter is []RightID (the RightID type from rights.go) so
// the D-090(1) gate can type-check it.
//
// Lexicon note (REQ-012, D-088): the message names + field names use the
// safe Cover vocabulary EXCLUSIVELY. "Cover-Charter", "Pool Council",
// "Cover Call Vote", "Charter Amendment" are the clean names; the four
// Cover-specific banned terms NEVER appear (enforced by lexicon_meta_cover).
import (
"fmt"
sdk "github.com/cosmos/cosmos-sdk/types"
)
// --- MsgSignCoverCharter ------------------------------------------------------
// MsgSignCoverCharter signs a Cover-Charter for a Pool (REQ-052, REQ-056,
// D-090(1)). The handler enforces:
// - D-090(1) Bill of Rights gate at ValidateBasic: len(WaivedRights) > 0
// -> REJECT with "REQ-056: rights non-amendable, non-waivable by any
// Charter". This is the dual-firewall runtime gate (mirrors
// MissionLockAmendmentRejected at ValidateBasic in x/council).
// - Idempotency: CharterID must not already exist.
// - WatcherKeeper.Attest on the charter witness hash (a nil WatcherKeeper
// skips).
// - Persist the CoverCharter + emit cover.charter_signed.
//
// ValidateBasic is stateless: non-empty fields + the D-090(1) WaivedRights
// gate. The WaivedRights field is []RightID (the RightID type from
// rights.go) so the gate can type-check it; the gate rejects any non-empty
// slice (the 13 rights are non-waivable by any Charter).
type MsgSignCoverCharter struct {
CharterID string `json:"charter_id" yaml:"charter_id"`
PoolID string `json:"pool_id" yaml:"pool_id"`
StatementOfBeliefsHash []byte `json:"statement_of_beliefs_hash" yaml:"statement_of_beliefs_hash"`
DisputePath string `json:"dispute_path" yaml:"dispute_path"`
Gate string `json:"gate" yaml:"gate"`
HoldingPeriodDays uint32 `json:"holding_period_days" yaml:"holding_period_days"`
HostReachID string `json:"host_reach_id" yaml:"host_reach_id"`
WatcherWitnessHash []byte `json:"watcher_witness_hash" yaml:"watcher_witness_hash"`
WaivedRights []RightID `json:"waived_rights" yaml:"waived_rights"`
Signer string `json:"signer" yaml:"signer"`
}
// Reset implements proto.Message.
func (m *MsgSignCoverCharter) Reset() { *m = MsgSignCoverCharter{} }
// String implements proto.Message.
func (m *MsgSignCoverCharter) String() string {
return fmt.Sprintf("MsgSignCoverCharter{CharterID:%s PoolID:%s HostReachID:%s Gate:%s HoldingPeriodDays:%d WaivedRights:%v Signer:%s}",
m.CharterID, m.PoolID, m.HostReachID, m.Gate, m.HoldingPeriodDays, m.WaivedRights, m.Signer)
}
// ProtoMessage implements proto.Message.
func (*MsgSignCoverCharter) ProtoMessage() {}
// ValidateBasic is the stateless validation: non-empty fields + the
// D-090(1) Bill of Rights gate. The gate rejects any non-empty WaivedRights
// slice (the 13 rights are non-amendable, non-waivable by any Charter —
// REQ-056, vision §8.2). This is the dual-firewall runtime gate (mirrors
// MissionLockAmendmentRejected at ValidateBasic in x/council — D-064).
func (m *MsgSignCoverCharter) ValidateBasic() error {
if m.CharterID == "" {
return fmt.Errorf("cover: empty charter-id")
}
if m.PoolID == "" {
return fmt.Errorf("cover: empty pool-id")
}
if m.HostReachID == "" {
return fmt.Errorf("cover: empty host-reach-id")
}
if m.DisputePath == "" {
return fmt.Errorf("cover: empty dispute-path")
}
if m.Gate == "" {
return fmt.Errorf("cover: empty gate")
}
if m.HoldingPeriodDays == 0 {
return fmt.Errorf("cover: empty holding-period-days")
}
if m.Signer == "" {
return fmt.Errorf("cover: empty signer")
}
// D-090(1) Bill of Rights gate: the 13 rights are non-amendable,
// non-waivable by any Charter (REQ-056, vision §8.2). Any WaivedRights
// element REJECTS the signing. This is the dual-firewall runtime gate
// (the const firewall is the 13 Waivable* consts all false +
// RightIsWaivable() always false; this gate is the runtime rejection).
// Mirrors MissionLockAmendmentRejected at ValidateBasic in x/council
// (D-064).
if len(m.WaivedRights) > 0 {
return fmt.Errorf("cover: REQ-056: rights non-amendable, non-waivable by any Charter (WaivedRights=%v)", m.WaivedRights)
}
return nil
}
// GetSigners returns the signer's reach-id as sdk.AccAddress bytes.
func (m *MsgSignCoverCharter) GetSigners() []sdk.AccAddress {
return []sdk.AccAddress{[]byte(m.Signer)}
}
// --- MsgAmendCoverCharter -----------------------------------------------------
// MsgAmendCoverCharter files a Charter amendment (REQ-052). The handler
// creates a CharterAmendment with Status=AmendmentProposed, ProposedAt=now.
// After the 7-day cooling (CharterAmendmentCoolingSeconds), a separate
// ratify handler (or simtest time-advance) transitions it to Cooled then
// Ratified. The cooling is the Anti-Capture Bill of Rights RightCooling
// enforcement.
//
// ValidateBasic is stateless: non-empty fields.
type MsgAmendCoverCharter struct {
CharterID string `json:"charter_id" yaml:"charter_id"`
AmendmentID string `json:"amendment_id" yaml:"amendment_id"`
Description string `json:"description" yaml:"description"`
Signer string `json:"signer" yaml:"signer"`
}
// Reset implements proto.Message.
func (m *MsgAmendCoverCharter) Reset() { *m = MsgAmendCoverCharter{} }
// String implements proto.Message.
func (m *MsgAmendCoverCharter) String() string {
return fmt.Sprintf("MsgAmendCoverCharter{CharterID:%s AmendmentID:%s Signer:%s}",
m.CharterID, m.AmendmentID, m.Signer)
}
// ProtoMessage implements proto.Message.
func (*MsgAmendCoverCharter) ProtoMessage() {}
// ValidateBasic is the stateless validation: non-empty fields.
func (m *MsgAmendCoverCharter) ValidateBasic() error {
if m.CharterID == "" {
return fmt.Errorf("cover: empty charter-id")
}
if m.AmendmentID == "" {
return fmt.Errorf("cover: empty amendment-id")
}
if m.Description == "" {
return fmt.Errorf("cover: empty description")
}
if m.Signer == "" {
return fmt.Errorf("cover: empty signer")
}
return nil
}
// GetSigners returns the signer's reach-id as sdk.AccAddress bytes.
func (m *MsgAmendCoverCharter) GetSigners() []sdk.AccAddress {
return []sdk.AccAddress{[]byte(m.Signer)}
}
// --- MsgElectPoolMason --------------------------------------------------------
// MsgElectPoolMason elects a Mason to the Pool Council (REQ-062). The
// handler loads or creates the PoolCouncil, adds the MasonReachID to
// ElectedMasonReachIDs (max 3 — a 4th is REJECTED), and persists.
//
// ValidateBasic is stateless: non-empty fields.
type MsgElectPoolMason struct {
PoolID string `json:"pool_id" yaml:"pool_id"`
MasonReachID string `json:"mason_reach_id" yaml:"mason_reach_id"`
Signer string `json:"signer" yaml:"signer"`
}
// Reset implements proto.Message.
func (m *MsgElectPoolMason) Reset() { *m = MsgElectPoolMason{} }
// String implements proto.Message.
func (m *MsgElectPoolMason) String() string {
return fmt.Sprintf("MsgElectPoolMason{PoolID:%s MasonReachID:%s Signer:%s}",
m.PoolID, m.MasonReachID, m.Signer)
}
// ProtoMessage implements proto.Message.
func (*MsgElectPoolMason) ProtoMessage() {}
// ValidateBasic is the stateless validation: non-empty fields.
func (m *MsgElectPoolMason) ValidateBasic() error {
if m.PoolID == "" {
return fmt.Errorf("cover: empty pool-id")
}
if m.MasonReachID == "" {
return fmt.Errorf("cover: empty mason-reach-id")
}
if m.Signer == "" {
return fmt.Errorf("cover: empty signer")
}
return nil
}
// GetSigners returns the signer's reach-id as sdk.AccAddress bytes.
func (m *MsgElectPoolMason) GetSigners() []sdk.AccAddress {
return []sdk.AccAddress{[]byte(m.Signer)}
}
// --- MsgVoteCoverCall ---------------------------------------------------------
// MsgVoteCoverCall votes on a Cover Call (REQ-062). The handler enforces:
// - the CoverCall exists.
// - the Watcher-observer-present check: if VoteOption == CallVoteYes and
// WatcherObserverPresent == false, REJECT (majority requires observer
// present — REQ-062).
// - persist the CoverCallVote + emit cover.cover_call_voted.
//
// ValidateBasic is stateless: non-empty fields + valid VoteOption.
type MsgVoteCoverCall struct {
VoteID string `json:"vote_id" yaml:"vote_id"`
CallID string `json:"call_id" yaml:"call_id"`
PoolID string `json:"pool_id" yaml:"pool_id"`
VoterReachID string `json:"voter_reach_id" yaml:"voter_reach_id"`
VoteOption CallVoteOption `json:"vote_option" yaml:"vote_option"`
WatcherObserverPresent bool `json:"watcher_observer_present" yaml:"watcher_observer_present"`
Signer string `json:"signer" yaml:"signer"`
}
// Reset implements proto.Message.
func (m *MsgVoteCoverCall) Reset() { *m = MsgVoteCoverCall{} }
// String implements proto.Message.
func (m *MsgVoteCoverCall) String() string {
return fmt.Sprintf("MsgVoteCoverCall{VoteID:%s CallID:%s PoolID:%s VoterReachID:%s VoteOption:%s WatcherObserverPresent:%v Signer:%s}",
m.VoteID, m.CallID, m.PoolID, m.VoterReachID, m.VoteOption, m.WatcherObserverPresent, m.Signer)
}
// ProtoMessage implements proto.Message.
func (*MsgVoteCoverCall) ProtoMessage() {}
// ValidateBasic is the stateless validation: non-empty fields + valid
// VoteOption.
func (m *MsgVoteCoverCall) ValidateBasic() error {
if m.VoteID == "" {
return fmt.Errorf("cover: empty vote-id")
}
if m.CallID == "" {
return fmt.Errorf("cover: empty call-id")
}
if m.PoolID == "" {
return fmt.Errorf("cover: empty pool-id")
}
if m.VoterReachID == "" {
return fmt.Errorf("cover: empty voter-reach-id")
}
if m.Signer == "" {
return fmt.Errorf("cover: empty signer")
}
if !knownCallVoteOption(m.VoteOption) {
return fmt.Errorf("cover: unknown vote-option %q", m.VoteOption)
}
return nil
}
// GetSigners returns the signer's reach-id as sdk.AccAddress bytes.
func (m *MsgVoteCoverCall) GetSigners() []sdk.AccAddress {
return []sdk.AccAddress{[]byte(m.Signer)}
}
// --- MsgAmendPoolStandingGate -------------------------------------------------
// MsgAmendPoolStandingGate amends a Pool's Standing gate (D-090(3)). The
// handler re-checks NewGate >= CoverStandingGateTrusted in defense in
// depth (ValidateBasic already checked — but the handler re-checks in
// case of a future Params-bypass). The gate may be TIGHTENED above the
// protocol minimum but NEVER lowered below it.
//
// ValidateBasic is the D-090(3) dual check: NewGate >=
// CoverStandingGateTrusted (a below-floor amendment is REJECTED at
// ValidateBasic, NOT just at the handler).
type MsgAmendPoolStandingGate struct {
PoolID string `json:"pool_id" yaml:"pool_id"`
NewGate float64 `json:"new_gate" yaml:"new_gate"`
Signer string `json:"signer" yaml:"signer"`
}
// Reset implements proto.Message.
func (m *MsgAmendPoolStandingGate) Reset() { *m = MsgAmendPoolStandingGate{} }
// String implements proto.Message.
func (m *MsgAmendPoolStandingGate) String() string {
return fmt.Sprintf("MsgAmendPoolStandingGate{PoolID:%s NewGate:%.2f Signer:%s}",
m.PoolID, m.NewGate, m.Signer)
}
// ProtoMessage implements proto.Message.
func (*MsgAmendPoolStandingGate) ProtoMessage() {}
// ValidateBasic is the D-090(3) dual check: non-empty fields + NewGate >=
// CoverStandingGateTrusted (a below-floor amendment is REJECTED at
// ValidateBasic, NOT just at the handler — the dual firewall).
func (m *MsgAmendPoolStandingGate) ValidateBasic() error {
if m.PoolID == "" {
return fmt.Errorf("cover: empty pool-id")
}
if m.Signer == "" {
return fmt.Errorf("cover: empty signer")
}
if m.NewGate < CoverStandingGateTrusted {
return fmt.Errorf("cover: NewGate %.2f < CoverStandingGateTrusted %.2f (D-090(3): a pool may tighten the gate but never lower it)", m.NewGate, CoverStandingGateTrusted)
}
return nil
}
// GetSigners returns the signer's reach-id as sdk.AccAddress bytes.
func (m *MsgAmendPoolStandingGate) GetSigners() []sdk.AccAddress {
return []sdk.AccAddress{[]byte(m.Signer)}
}
// --- MsgEscalateReserveCeiling ------------------------------------------------
// MsgEscalateReserveCeiling escalates a Pool's reserve target to the
// CoverReserveCeilingAnnualContribX (REQ-048). The handler enforces the
// 12-month age check: now - pool.CreatedAt >= ReserveCeilingAgeSeconds
// (365 days). A fresh pool is REJECTED. The handler calls
// WatcherKeeper.Attest (a nil WatcherKeeper skips).
//
// ValidateBasic is stateless: non-empty fields.
type MsgEscalateReserveCeiling struct {
PoolID string `json:"pool_id" yaml:"pool_id"`
Signer string `json:"signer" yaml:"signer"`
}
// Reset implements proto.Message.
func (m *MsgEscalateReserveCeiling) Reset() { *m = MsgEscalateReserveCeiling{} }
// String implements proto.Message.
func (m *MsgEscalateReserveCeiling) String() string {
return fmt.Sprintf("MsgEscalateReserveCeiling{PoolID:%s Signer:%s}", m.PoolID, m.Signer)
}
// ProtoMessage implements proto.Message.
func (*MsgEscalateReserveCeiling) ProtoMessage() {}
// ValidateBasic is the stateless validation: non-empty fields.
func (m *MsgEscalateReserveCeiling) ValidateBasic() error {
if m.PoolID == "" {
return fmt.Errorf("cover: empty pool-id")
}
if m.Signer == "" {
return fmt.Errorf("cover: empty signer")
}
return nil
}
// GetSigners returns the signer's reach-id as sdk.AccAddress bytes.
func (m *MsgEscalateReserveCeiling) GetSigners() []sdk.AccAddress {
return []sdk.AccAddress{[]byte(m.Signer)}
}
// --- P2 Response types --------------------------------------------------------
//
// Hand-rolled (no protobuf codegen); empty bodies — the response is the
// state mutation + event. Mirrors the P1 Response types in msg_cover.go.
// MsgSignCoverCharterResponse is the response to MsgSignCoverCharter.
type MsgSignCoverCharterResponse struct{}
// Reset implements proto.Message.
func (m *MsgSignCoverCharterResponse) Reset() { *m = MsgSignCoverCharterResponse{} }
// String implements proto.Message.
func (m *MsgSignCoverCharterResponse) String() string { return "MsgSignCoverCharterResponse{}" }
// ProtoMessage implements proto.Message.
func (*MsgSignCoverCharterResponse) ProtoMessage() {}
// MsgAmendCoverCharterResponse is the response to MsgAmendCoverCharter.
type MsgAmendCoverCharterResponse struct{}
// Reset implements proto.Message.
func (m *MsgAmendCoverCharterResponse) Reset() { *m = MsgAmendCoverCharterResponse{} }
// String implements proto.Message.
func (m *MsgAmendCoverCharterResponse) String() string { return "MsgAmendCoverCharterResponse{}" }
// ProtoMessage implements proto.Message.
func (*MsgAmendCoverCharterResponse) ProtoMessage() {}
// MsgElectPoolMasonResponse is the response to MsgElectPoolMason.
type MsgElectPoolMasonResponse struct{}
// Reset implements proto.Message.
func (m *MsgElectPoolMasonResponse) Reset() { *m = MsgElectPoolMasonResponse{} }
// String implements proto.Message.
func (m *MsgElectPoolMasonResponse) String() string { return "MsgElectPoolMasonResponse{}" }
// ProtoMessage implements proto.Message.
func (*MsgElectPoolMasonResponse) ProtoMessage() {}
// MsgVoteCoverCallResponse is the response to MsgVoteCoverCall.
type MsgVoteCoverCallResponse struct{}
// Reset implements proto.Message.
func (m *MsgVoteCoverCallResponse) Reset() { *m = MsgVoteCoverCallResponse{} }
// String implements proto.Message.
func (m *MsgVoteCoverCallResponse) String() string { return "MsgVoteCoverCallResponse{}" }
// ProtoMessage implements proto.Message.
func (*MsgVoteCoverCallResponse) ProtoMessage() {}
// MsgAmendPoolStandingGateResponse is the response to MsgAmendPoolStandingGate.
type MsgAmendPoolStandingGateResponse struct{}
// Reset implements proto.Message.
func (m *MsgAmendPoolStandingGateResponse) Reset() { *m = MsgAmendPoolStandingGateResponse{} }
// String implements proto.Message.
func (m *MsgAmendPoolStandingGateResponse) String() string {
return "MsgAmendPoolStandingGateResponse{}"
}
// ProtoMessage implements proto.Message.
func (*MsgAmendPoolStandingGateResponse) ProtoMessage() {}
// MsgEscalateReserveCeilingResponse is the response to MsgEscalateReserveCeiling.
type MsgEscalateReserveCeilingResponse struct{}
// Reset implements proto.Message.
func (m *MsgEscalateReserveCeilingResponse) Reset() { *m = MsgEscalateReserveCeilingResponse{} }
// String implements proto.Message.
func (m *MsgEscalateReserveCeilingResponse) String() string {
return "MsgEscalateReserveCeilingResponse{}"
}
// ProtoMessage implements proto.Message.
func (*MsgEscalateReserveCeilingResponse) ProtoMessage() {}
+325
View File
@@ -0,0 +1,325 @@
package types
// msg_charter_test.go holds the P2 Msg* method coverage tests for
// x/cover/types (REQ-052, REQ-062, REQ-056, REQ-048, D-090(1), D-090(3)).
// The P2 Msg* Reset/String/ProtoMessage/ValidateBasic/GetSigners methods
// are exercised here so the types package coverage is >=80%.
//
// G-024 controlled exception (mirrors msg_cover_test.go): this file imports
// cosmos-sdk for GetSigners (sdk.AccAddress) — this is a Msg-method test,
// NOT an invariant/lexicon test, so the G-024 stdlib-only constraint does
// not apply.
import (
"strings"
"testing"
sdk "github.com/cosmos/cosmos-sdk/types"
)
// --- MsgSignCoverCharter methods ---------------------------------------------
func TestMsgSignCoverCharterMethods(t *testing.T) {
m := &MsgSignCoverCharter{
CharterID: "c1", PoolID: "p1", HostReachID: "h1", DisputePath: "dp",
Gate: "Trusted", HoldingPeriodDays: 30, Signer: "h1",
StatementOfBeliefsHash: []byte{1, 2},
WatcherWitnessHash: []byte{3, 4},
WaivedRights: []RightID{},
}
if err := m.ValidateBasic(); err != nil {
t.Errorf("valid MsgSignCoverCharter ValidateBasic: %v", err)
}
if !strings.Contains(m.String(), "c1") {
t.Errorf("MsgSignCoverCharter String = %q, want c1", m.String())
}
m.Reset()
if m.CharterID != "" {
t.Errorf("MsgSignCoverCharter Reset did not zero: %+v", m)
}
m.ProtoMessage()
m2 := &MsgSignCoverCharter{Signer: "host-1"}
if got := m2.GetSigners(); len(got) != 1 || string(got[0]) != "host-1" {
t.Errorf("MsgSignCoverCharter GetSigners = %v, want [host-1]", got)
}
var _ []sdk.AccAddress = m2.GetSigners()
}
// TestMsgSignCoverCharterValidateBasicErrors asserts each error path,
// including the D-090(1) Bill of Rights gate (any WaivedRights element
// REJECTS the signing).
func TestMsgSignCoverCharterValidateBasicErrors(t *testing.T) {
cases := []struct {
name string
msg MsgSignCoverCharter
}{
{"empty charter-id", MsgSignCoverCharter{PoolID: "p", HostReachID: "h", DisputePath: "dp", Gate: "g", HoldingPeriodDays: 30, Signer: "s"}},
{"empty pool-id", MsgSignCoverCharter{CharterID: "c", HostReachID: "h", DisputePath: "dp", Gate: "g", HoldingPeriodDays: 30, Signer: "s"}},
{"empty host-reach-id", MsgSignCoverCharter{CharterID: "c", PoolID: "p", DisputePath: "dp", Gate: "g", HoldingPeriodDays: 30, Signer: "s"}},
{"empty dispute-path", MsgSignCoverCharter{CharterID: "c", PoolID: "p", HostReachID: "h", Gate: "g", HoldingPeriodDays: 30, Signer: "s"}},
{"empty gate", MsgSignCoverCharter{CharterID: "c", PoolID: "p", HostReachID: "h", DisputePath: "dp", HoldingPeriodDays: 30, Signer: "s"}},
{"zero holding-period-days", MsgSignCoverCharter{CharterID: "c", PoolID: "p", HostReachID: "h", DisputePath: "dp", Gate: "g", Signer: "s"}},
{"empty signer", MsgSignCoverCharter{CharterID: "c", PoolID: "p", HostReachID: "h", DisputePath: "dp", Gate: "g", HoldingPeriodDays: 30}},
{"waived-rights non-empty (D-090(1))", MsgSignCoverCharter{CharterID: "c", PoolID: "p", HostReachID: "h", DisputePath: "dp", Gate: "g", HoldingPeriodDays: 30, Signer: "s", WaivedRights: []RightID{RightOneTapExit}}},
}
for _, c := range cases {
err := c.msg.ValidateBasic()
if err == nil {
t.Errorf("case %q: ValidateBasic should fail", c.name)
continue
}
// The D-090(1) case must mention REQ-056.
if c.name == "waived-rights non-empty (D-090(1))" && !strings.Contains(err.Error(), "REQ-056") {
t.Errorf("case %q: error = %q, want 'REQ-056'", c.name, err.Error())
}
}
}
// --- MsgAmendCoverCharter methods --------------------------------------------
func TestMsgAmendCoverCharterMethods(t *testing.T) {
m := &MsgAmendCoverCharter{CharterID: "c1", AmendmentID: "a1", Description: "d", Signer: "h1"}
if err := m.ValidateBasic(); err != nil {
t.Errorf("valid MsgAmendCoverCharter ValidateBasic: %v", err)
}
if !strings.Contains(m.String(), "a1") {
t.Errorf("MsgAmendCoverCharter String = %q, want a1", m.String())
}
m.Reset()
if m.CharterID != "" {
t.Errorf("MsgAmendCoverCharter Reset did not zero: %+v", m)
}
m.ProtoMessage()
m2 := &MsgAmendCoverCharter{Signer: "host-1"}
if got := m2.GetSigners(); len(got) != 1 || string(got[0]) != "host-1" {
t.Errorf("MsgAmendCoverCharter GetSigners = %v", got)
}
}
func TestMsgAmendCoverCharterValidateBasicErrors(t *testing.T) {
cases := []struct {
name string
msg MsgAmendCoverCharter
}{
{"empty charter-id", MsgAmendCoverCharter{AmendmentID: "a", Description: "d", Signer: "s"}},
{"empty amendment-id", MsgAmendCoverCharter{CharterID: "c", Description: "d", Signer: "s"}},
{"empty description", MsgAmendCoverCharter{CharterID: "c", AmendmentID: "a", Signer: "s"}},
{"empty signer", MsgAmendCoverCharter{CharterID: "c", AmendmentID: "a", Description: "d"}},
}
for _, c := range cases {
if err := c.msg.ValidateBasic(); err == nil {
t.Errorf("case %q: ValidateBasic should fail", c.name)
}
}
}
// --- MsgElectPoolMason methods -----------------------------------------------
func TestMsgElectPoolMasonMethods(t *testing.T) {
m := &MsgElectPoolMason{PoolID: "p1", MasonReachID: "m1", Signer: "h1"}
if err := m.ValidateBasic(); err != nil {
t.Errorf("valid MsgElectPoolMason ValidateBasic: %v", err)
}
if !strings.Contains(m.String(), "m1") {
t.Errorf("MsgElectPoolMason String = %q, want m1", m.String())
}
m.Reset()
if m.PoolID != "" {
t.Errorf("MsgElectPoolMason Reset did not zero: %+v", m)
}
m.ProtoMessage()
m2 := &MsgElectPoolMason{Signer: "host-1"}
if got := m2.GetSigners(); len(got) != 1 || string(got[0]) != "host-1" {
t.Errorf("MsgElectPoolMason GetSigners = %v", got)
}
}
func TestMsgElectPoolMasonValidateBasicErrors(t *testing.T) {
cases := []struct {
name string
msg MsgElectPoolMason
}{
{"empty pool-id", MsgElectPoolMason{MasonReachID: "m", Signer: "s"}},
{"empty mason-reach-id", MsgElectPoolMason{PoolID: "p", Signer: "s"}},
{"empty signer", MsgElectPoolMason{PoolID: "p", MasonReachID: "m"}},
}
for _, c := range cases {
if err := c.msg.ValidateBasic(); err == nil {
t.Errorf("case %q: ValidateBasic should fail", c.name)
}
}
}
// --- MsgVoteCoverCall methods ------------------------------------------------
func TestMsgVoteCoverCallMethods(t *testing.T) {
m := &MsgVoteCoverCall{VoteID: "v1", CallID: "c1", PoolID: "p1", VoterReachID: "v1", VoteOption: CallVoteYes, WatcherObserverPresent: true, Signer: "h1"}
if err := m.ValidateBasic(); err != nil {
t.Errorf("valid MsgVoteCoverCall ValidateBasic: %v", err)
}
if !strings.Contains(m.String(), "v1") {
t.Errorf("MsgVoteCoverCall String = %q, want v1", m.String())
}
m.Reset()
if m.VoteID != "" {
t.Errorf("MsgVoteCoverCall Reset did not zero: %+v", m)
}
m.ProtoMessage()
m2 := &MsgVoteCoverCall{Signer: "host-1"}
if got := m2.GetSigners(); len(got) != 1 || string(got[0]) != "host-1" {
t.Errorf("MsgVoteCoverCall GetSigners = %v", got)
}
}
func TestMsgVoteCoverCallValidateBasicErrors(t *testing.T) {
cases := []struct {
name string
msg MsgVoteCoverCall
}{
{"empty vote-id", MsgVoteCoverCall{CallID: "c", PoolID: "p", VoterReachID: "v", VoteOption: CallVoteYes, Signer: "s"}},
{"empty call-id", MsgVoteCoverCall{VoteID: "v", PoolID: "p", VoterReachID: "v", VoteOption: CallVoteYes, Signer: "s"}},
{"empty pool-id", MsgVoteCoverCall{VoteID: "v", CallID: "c", VoterReachID: "v", VoteOption: CallVoteYes, Signer: "s"}},
{"empty voter-reach-id", MsgVoteCoverCall{VoteID: "v", CallID: "c", PoolID: "p", VoteOption: CallVoteYes, Signer: "s"}},
{"empty signer", MsgVoteCoverCall{VoteID: "v", CallID: "c", PoolID: "p", VoterReachID: "v", VoteOption: CallVoteYes}},
{"unknown vote-option", MsgVoteCoverCall{VoteID: "v", CallID: "c", PoolID: "p", VoterReachID: "v", VoteOption: CallVoteOption("Maybe"), Signer: "s"}},
}
for _, c := range cases {
if err := c.msg.ValidateBasic(); err == nil {
t.Errorf("case %q: ValidateBasic should fail", c.name)
}
}
}
// --- MsgAmendPoolStandingGate methods ----------------------------------------
func TestMsgAmendPoolStandingGateMethods(t *testing.T) {
m := &MsgAmendPoolStandingGate{PoolID: "p1", NewGate: 4.5, Signer: "h1"}
if err := m.ValidateBasic(); err != nil {
t.Errorf("valid MsgAmendPoolStandingGate ValidateBasic: %v", err)
}
if !strings.Contains(m.String(), "p1") {
t.Errorf("MsgAmendPoolStandingGate String = %q, want p1", m.String())
}
m.Reset()
if m.PoolID != "" {
t.Errorf("MsgAmendPoolStandingGate Reset did not zero: %+v", m)
}
m.ProtoMessage()
m2 := &MsgAmendPoolStandingGate{Signer: "host-1"}
if got := m2.GetSigners(); len(got) != 1 || string(got[0]) != "host-1" {
t.Errorf("MsgAmendPoolStandingGate GetSigners = %v", got)
}
}
// TestMsgAmendPoolStandingGateD0903BelowFloor asserts the D-090(3) dual
// check: a NewGate below CoverStandingGateTrusted (4.0) is REJECTED at
// ValidateBasic (NOT just at the handler). NewGate = 3.0 < 4.0 -> REJECT.
func TestMsgAmendPoolStandingGateD0903BelowFloor(t *testing.T) {
m := &MsgAmendPoolStandingGate{PoolID: "p", NewGate: 3.0, Signer: "s"}
err := m.ValidateBasic()
if err == nil {
t.Fatal("MsgAmendPoolStandingGate with NewGate 3.0 < 4.0 should fail ValidateBasic (D-090(3))")
}
if !strings.Contains(err.Error(), "D-090(3)") {
t.Errorf("error = %q, want 'D-090(3)'", err.Error())
}
}
func TestMsgAmendPoolStandingGateValidateBasicErrors(t *testing.T) {
cases := []struct {
name string
msg MsgAmendPoolStandingGate
}{
{"empty pool-id", MsgAmendPoolStandingGate{NewGate: 4.5, Signer: "s"}},
{"empty signer", MsgAmendPoolStandingGate{PoolID: "p", NewGate: 4.5}},
{"below floor", MsgAmendPoolStandingGate{PoolID: "p", NewGate: 3.0, Signer: "s"}},
{"below floor zero", MsgAmendPoolStandingGate{PoolID: "p", NewGate: 0, Signer: "s"}},
}
for _, c := range cases {
if err := c.msg.ValidateBasic(); err == nil {
t.Errorf("case %q: ValidateBasic should fail", c.name)
}
}
}
// --- MsgEscalateReserveCeiling methods ---------------------------------------
func TestMsgEscalateReserveCeilingMethods(t *testing.T) {
m := &MsgEscalateReserveCeiling{PoolID: "p1", Signer: "h1"}
if err := m.ValidateBasic(); err != nil {
t.Errorf("valid MsgEscalateReserveCeiling ValidateBasic: %v", err)
}
if !strings.Contains(m.String(), "p1") {
t.Errorf("MsgEscalateReserveCeiling String = %q, want p1", m.String())
}
m.Reset()
if m.PoolID != "" {
t.Errorf("MsgEscalateReserveCeiling Reset did not zero: %+v", m)
}
m.ProtoMessage()
m2 := &MsgEscalateReserveCeiling{Signer: "host-1"}
if got := m2.GetSigners(); len(got) != 1 || string(got[0]) != "host-1" {
t.Errorf("MsgEscalateReserveCeiling GetSigners = %v", got)
}
}
func TestMsgEscalateReserveCeilingValidateBasicErrors(t *testing.T) {
cases := []struct {
name string
msg MsgEscalateReserveCeiling
}{
{"empty pool-id", MsgEscalateReserveCeiling{Signer: "s"}},
{"empty signer", MsgEscalateReserveCeiling{PoolID: "p"}},
}
for _, c := range cases {
if err := c.msg.ValidateBasic(); err == nil {
t.Errorf("case %q: ValidateBasic should fail", c.name)
}
}
}
// --- P2 Response types methods -----------------------------------------------
func TestP2ResponseTypesMethods(t *testing.T) {
r1 := &MsgSignCoverCharterResponse{}
r1.Reset()
if !strings.Contains(r1.String(), "MsgSignCoverCharterResponse") {
t.Errorf("MsgSignCoverCharterResponse String = %q", r1.String())
}
r1.ProtoMessage()
r2 := &MsgAmendCoverCharterResponse{}
r2.Reset()
if !strings.Contains(r2.String(), "MsgAmendCoverCharterResponse") {
t.Errorf("MsgAmendCoverCharterResponse String = %q", r2.String())
}
r2.ProtoMessage()
r3 := &MsgElectPoolMasonResponse{}
r3.Reset()
if !strings.Contains(r3.String(), "MsgElectPoolMasonResponse") {
t.Errorf("MsgElectPoolMasonResponse String = %q", r3.String())
}
r3.ProtoMessage()
r4 := &MsgVoteCoverCallResponse{}
r4.Reset()
if !strings.Contains(r4.String(), "MsgVoteCoverCallResponse") {
t.Errorf("MsgVoteCoverCallResponse String = %q", r4.String())
}
r4.ProtoMessage()
r5 := &MsgAmendPoolStandingGateResponse{}
r5.Reset()
if !strings.Contains(r5.String(), "MsgAmendPoolStandingGateResponse") {
t.Errorf("MsgAmendPoolStandingGateResponse String = %q", r5.String())
}
r5.ProtoMessage()
r6 := &MsgEscalateReserveCeilingResponse{}
r6.Reset()
if !strings.Contains(r6.String(), "MsgEscalateReserveCeilingResponse") {
t.Errorf("MsgEscalateReserveCeilingResponse String = %q", r6.String())
}
r6.ProtoMessage()
}
+292
View File
@@ -0,0 +1,292 @@
package types
// msg_cover.go holds the x/cover Msg* types implementing sdk.Msg (REQ-046,
// REQ-050, REQ-055; G-006 controlled exception: types/ gains the cosmos-sdk
// import for sdk.Msg — D-055; the invariant/lexicon tests in *_test.go stay
// stdlib-only per G-024, isolated from this msg_*.go file).
//
// The three Cover Msg types drive the Cover Pool runtime:
// - MsgLaunchCoverPool: launch a Cover Pool (the handler enforces the
// D-077 Standing gate + the D-086 category phase check + the reserve
// floor + the Watcher attestation; persists the CoverPool).
// - MsgRouteCoverFee: route a Cover-Fee into a pool's reserve (the
// handler enforces the D-079 Anti-Crowding-Out firewall + the category-
// tag match + the below-floor auto-pause + Still invocation).
// - MsgFileCoverCall: file a Cover Call against a pool's category (P1
// scaffold — persists the CoverCall; P4 adds the Voucher adjudication +
// no-self-adjudication + slashing).
//
// All cross-module refs are by-ID-string (G-003): host-reach-id refs an
// x/standing holder; pool-id refs a Cover Pool; claimant-reach-id refs a
// holder. No struct imports of x/standing/types or x/still/types (the
// shims are interfaces defined in expected_keepers.go — G-003 preserved).
//
// Lexicon note (REQ-012, D-088): the message names + field names use the
// safe Cover vocabulary EXCLUSIVELY. "Cover", "Cover-Fee", "Cover Call",
// "Cover-Charter", "Cover Pool" are the clean names; the banned Cover-
// specific terms (enumerated by lexicon.CoverBannedTerms — not inlined
// here so this source stays lexicon-clean) NEVER appear (enforced by
// lexicon_meta_cover). Note: "FileCoverCall" uses "Call" not the banned
// noun — correct. "ClaimantReachID" uses "Claimant" (a person, not the
// banned noun — the word-boundary regex does not match "Claimant").
import (
"fmt"
sdk "github.com/cosmos/cosmos-sdk/types"
)
// --- MsgLaunchCoverPool -------------------------------------------------------
// MsgLaunchCoverPool launches a Cover Pool (REQ-046, REQ-047, REQ-049,
// D-077, D-086). The handler enforces:
// - D-086 category phase check: each category's phase must be in the
// FactoryAllowedPhases (P1 default = [Phase2] only).
// - D-077 Standing gate: for each category, the host's Standing bucket +
// score must meet the locked gate (Trusted for Travel/IncomePause;
// Preferred for HealthMCS).
// - reserve floor: ReserveAnnualContribRatio >=
// CoverReserveFloorAnnualContribX (1.5).
// - Watcher attestation over the launch payload.
//
// ValidateBasic is stateless: non-empty fields, ReserveAnnualContribRatio
// >= CoverReserveFloorAnnualContribX (the stateless floor check; the
// handler does the full Standing gate + category phase check), non-empty
// categories.
type MsgLaunchCoverPool struct {
PoolID string `json:"pool_id" yaml:"pool_id"`
HostReachID string `json:"host_reach_id" yaml:"host_reach_id"`
Categories []CoverCategory `json:"categories" yaml:"categories"`
ReserveAnnualContribRatio float64 `json:"reserve_annual_contrib_ratio" yaml:"reserve_annual_contrib_ratio"`
ReserveAccount string `json:"reserve_account" yaml:"reserve_account"`
CharterHash []byte `json:"charter_hash" yaml:"charter_hash"`
Signer string `json:"signer" yaml:"signer"`
}
// Reset implements proto.Message (sdk.Msg = proto.Message).
func (m *MsgLaunchCoverPool) Reset() { *m = MsgLaunchCoverPool{} }
// String implements proto.Message.
func (m *MsgLaunchCoverPool) String() string {
return fmt.Sprintf("MsgLaunchCoverPool{PoolID:%s HostReachID:%s Categories:%v ReserveAnnualContribRatio:%.2f ReserveAccount:%s Signer:%s}",
m.PoolID, m.HostReachID, m.Categories, m.ReserveAnnualContribRatio, m.ReserveAccount, m.Signer)
}
// ProtoMessage implements proto.Message.
func (*MsgLaunchCoverPool) ProtoMessage() {}
// ValidateBasic is the stateless validation: non-empty pool-id, non-empty
// host-reach-id, non-empty categories, ReserveAnnualContribRatio >=
// CoverReserveFloorAnnualContribX (the stateless floor check; the handler
// re-checks + does the full Standing gate + category phase check), non-
// empty ReserveAccount, non-empty signer.
func (m *MsgLaunchCoverPool) ValidateBasic() error {
if m.PoolID == "" {
return fmt.Errorf("cover: empty pool-id")
}
if m.HostReachID == "" {
return fmt.Errorf("cover: empty host-reach-id")
}
if len(m.Categories) == 0 {
return fmt.Errorf("cover: empty categories")
}
if m.ReserveAccount == "" {
return fmt.Errorf("cover: empty ReserveAccount")
}
if m.Signer == "" {
return fmt.Errorf("cover: empty signer")
}
if m.ReserveAnnualContribRatio < CoverReserveFloorAnnualContribX {
return fmt.Errorf("cover: ReserveAnnualContribRatio %.2f < floor %.2f (REQ-047 stateless floor check)", m.ReserveAnnualContribRatio, CoverReserveFloorAnnualContribX)
}
return nil
}
// GetSigners returns the signer's reach-id as sdk.AccAddress bytes.
func (m *MsgLaunchCoverPool) GetSigners() []sdk.AccAddress {
return []sdk.AccAddress{[]byte(m.Signer)}
}
// --- MsgRouteCoverFee ---------------------------------------------------------
// MsgRouteCoverFee routes a Cover-Fee into a pool's reserve (REQ-050,
// D-079 firewall, REQ-047 below-floor auto-pause). The handler enforces:
// - the pool exists + is not paused.
// - the D-079 Anti-Crowding-Out firewall: the destination is the pool's
// ReserveAccount (not a Root-Pool operating-expenses holder).
// - the category-tag matches one of the pool's Categories.
// - the reserve floor: if the pool's ReserveAnnualContribRatio < floor,
// the routing is REJECTED + the pool is auto-paused + StillKeeper.Still
// is invoked.
//
// ValidateBasic is stateless: non-empty pool-id, non-empty category-tag,
// GrainAmount > 0.
type MsgRouteCoverFee struct {
PoolID string `json:"pool_id" yaml:"pool_id"`
GrainAmount int64 `json:"grain_amount" yaml:"grain_amount"`
CategoryTag string `json:"category_tag" yaml:"category_tag"`
Signer string `json:"signer" yaml:"signer"`
}
// Reset implements proto.Message.
func (m *MsgRouteCoverFee) Reset() { *m = MsgRouteCoverFee{} }
// String implements proto.Message.
func (m *MsgRouteCoverFee) String() string {
return fmt.Sprintf("MsgRouteCoverFee{PoolID:%s GrainAmount:%d CategoryTag:%s Signer:%s}",
m.PoolID, m.GrainAmount, m.CategoryTag, m.Signer)
}
// ProtoMessage implements proto.Message.
func (*MsgRouteCoverFee) ProtoMessage() {}
// ValidateBasic is the stateless validation: non-empty pool-id, non-empty
// category-tag, GrainAmount > 0, non-empty signer.
func (m *MsgRouteCoverFee) ValidateBasic() error {
if m.PoolID == "" {
return fmt.Errorf("cover: empty pool-id")
}
if m.CategoryTag == "" {
return fmt.Errorf("cover: empty category-tag")
}
if m.GrainAmount <= 0 {
return fmt.Errorf("cover: GrainAmount %d <= 0", m.GrainAmount)
}
if m.Signer == "" {
return fmt.Errorf("cover: empty signer")
}
return nil
}
// GetSigners returns the signer's reach-id as sdk.AccAddress bytes.
func (m *MsgRouteCoverFee) GetSigners() []sdk.AccAddress {
return []sdk.AccAddress{[]byte(m.Signer)}
}
// --- MsgFileCoverCall ---------------------------------------------------------
// MsgFileCoverCall files a Cover Call against a pool's category (REQ-055
// P1 scaffold — the Voucher adjudication lands in P4). The handler enforces:
// - the pool exists.
// - the category matches one of the pool's Categories.
// - persists the CoverCall + emits an event.
//
// ValidateBasic is stateless: non-empty fields, AmountGrain > 0.
type MsgFileCoverCall struct {
CallID string `json:"call_id" yaml:"call_id"`
PoolID string `json:"pool_id" yaml:"pool_id"`
ClaimantReachID string `json:"claimant_reach_id" yaml:"claimant_reach_id"`
Category CoverCategory `json:"category" yaml:"category"`
AmountGrain int64 `json:"amount_grain" yaml:"amount_grain"`
Signer string `json:"signer" yaml:"signer"`
}
// Reset implements proto.Message.
func (m *MsgFileCoverCall) Reset() { *m = MsgFileCoverCall{} }
// String implements proto.Message.
func (m *MsgFileCoverCall) String() string {
return fmt.Sprintf("MsgFileCoverCall{CallID:%s PoolID:%s ClaimantReachID:%s Category:%s AmountGrain:%d Signer:%s}",
m.CallID, m.PoolID, m.ClaimantReachID, m.Category, m.AmountGrain, m.Signer)
}
// ProtoMessage implements proto.Message.
func (*MsgFileCoverCall) ProtoMessage() {}
// ValidateBasic is the stateless validation: non-empty call-id, non-empty
// pool-id, non-empty claimant-reach-id, non-empty category, AmountGrain > 0,
// non-empty signer.
func (m *MsgFileCoverCall) ValidateBasic() error {
if m.CallID == "" {
return fmt.Errorf("cover: empty call-id")
}
if m.PoolID == "" {
return fmt.Errorf("cover: empty pool-id")
}
if m.ClaimantReachID == "" {
return fmt.Errorf("cover: empty claimant-reach-id")
}
if m.Category == "" {
return fmt.Errorf("cover: empty category")
}
if m.AmountGrain <= 0 {
return fmt.Errorf("cover: AmountGrain %d <= 0", m.AmountGrain)
}
if m.Signer == "" {
return fmt.Errorf("cover: empty signer")
}
return nil
}
// GetSigners returns the signer's reach-id as sdk.AccAddress bytes.
func (m *MsgFileCoverCall) GetSigners() []sdk.AccAddress {
return []sdk.AccAddress{[]byte(m.Signer)}
}
// --- MsgServer interface + Response types -------------------------------------
// MsgServer is the cover module's message server interface (one method per
// Msg*). The keeper's msg_server.go implements this; module.go's
// RegisterServices wires the implementation. Hand-rolled (no protobuf
// codegen per the skeleton's zero-codegen style).
//
// P2 extension (REQ-052, REQ-062, REQ-056, REQ-048): the six new methods
// (SignCoverCharter, AmendCoverCharter, ElectPoolMason, VoteCoverCall,
// AmendPoolStandingGate, EscalateReserveCeiling) are defined in
// msg_charter.go; their Response types are defined below the interface.
type MsgServer interface {
LaunchCoverPool(ctx interface{}, msg *MsgLaunchCoverPool) (*MsgLaunchCoverPoolResponse, error)
RouteCoverFee(ctx interface{}, msg *MsgRouteCoverFee) (*MsgRouteCoverFeeResponse, error)
FileCoverCall(ctx interface{}, msg *MsgFileCoverCall) (*MsgFileCoverCallResponse, error)
SignCoverCharter(ctx interface{}, msg *MsgSignCoverCharter) (*MsgSignCoverCharterResponse, error)
AmendCoverCharter(ctx interface{}, msg *MsgAmendCoverCharter) (*MsgAmendCoverCharterResponse, error)
ElectPoolMason(ctx interface{}, msg *MsgElectPoolMason) (*MsgElectPoolMasonResponse, error)
VoteCoverCall(ctx interface{}, msg *MsgVoteCoverCall) (*MsgVoteCoverCallResponse, error)
AmendPoolStandingGate(ctx interface{}, msg *MsgAmendPoolStandingGate) (*MsgAmendPoolStandingGateResponse, error)
EscalateReserveCeiling(ctx interface{}, msg *MsgEscalateReserveCeiling) (*MsgEscalateReserveCeilingResponse, error)
}
// Response types (hand-rolled; empty bodies — the response is the state
// mutation + event).
// MsgLaunchCoverPoolResponse is the response to MsgLaunchCoverPool.
type MsgLaunchCoverPoolResponse struct{}
// Reset implements proto.Message.
func (m *MsgLaunchCoverPoolResponse) Reset() { *m = MsgLaunchCoverPoolResponse{} }
// String implements proto.Message.
func (m *MsgLaunchCoverPoolResponse) String() string {
return "MsgLaunchCoverPoolResponse{}"
}
// ProtoMessage implements proto.Message.
func (*MsgLaunchCoverPoolResponse) ProtoMessage() {}
// MsgRouteCoverFeeResponse is the response to MsgRouteCoverFee.
type MsgRouteCoverFeeResponse struct{}
// Reset implements proto.Message.
func (m *MsgRouteCoverFeeResponse) Reset() { *m = MsgRouteCoverFeeResponse{} }
// String implements proto.Message.
func (m *MsgRouteCoverFeeResponse) String() string {
return "MsgRouteCoverFeeResponse{}"
}
// ProtoMessage implements proto.Message.
func (*MsgRouteCoverFeeResponse) ProtoMessage() {}
// MsgFileCoverCallResponse is the response to MsgFileCoverCall.
type MsgFileCoverCallResponse struct{}
// Reset implements proto.Message.
func (m *MsgFileCoverCallResponse) Reset() { *m = MsgFileCoverCallResponse{} }
// String implements proto.Message.
func (m *MsgFileCoverCallResponse) String() string {
return "MsgFileCoverCallResponse{}"
}
// ProtoMessage implements proto.Message.
func (*MsgFileCoverCallResponse) ProtoMessage() {}
+196
View File
@@ -0,0 +1,196 @@
package types
// msg_cover_test.go holds the Msg* method coverage tests for x/cover/types
// (REQ-046, REQ-050, REQ-055). The Msg* Reset/String/ProtoMessage/
// ValidateBasic/GetSigners methods are exercised here so the types package
// coverage is >=80% (the keeper simtest exercises the handlers but its
// coverage counts toward the keeper package, not types).
//
// G-024: this file imports cosmos-sdk for GetSigners (sdk.AccAddress) —
// this is a Msg-method test, NOT an invariant/lexicon test, so the G-024
// stdlib-only constraint does not apply (the invariant + lexicon
// assertions live in types_test.go, which stays stdlib + lexicon-only).
import (
"strings"
"testing"
sdk "github.com/cosmos/cosmos-sdk/types"
)
// --- MsgLaunchCoverPool methods ---------------------------------------------
func TestMsgLaunchCoverPoolMethods(t *testing.T) {
m := &MsgLaunchCoverPool{
PoolID: "p1", HostReachID: "h1", Categories: []CoverCategory{CatTravel},
ReserveAnnualContribRatio: 1.5, ReserveAccount: "acc1", Signer: "h1",
}
// ValidateBasic — valid.
if err := m.ValidateBasic(); err != nil {
t.Errorf("valid MsgLaunchCoverPool ValidateBasic: %v", err)
}
// String contains the pool-id.
if !strings.Contains(m.String(), "p1") {
t.Errorf("MsgLaunchCoverPool String = %q, want to contain p1", m.String())
}
// Reset zeroes.
m.Reset()
if m.PoolID != "" || len(m.Categories) != 0 {
t.Errorf("MsgLaunchCoverPool Reset did not zero: %+v", m)
}
m.ProtoMessage() // no-op coverage
// GetSigners.
m2 := &MsgLaunchCoverPool{Signer: "host-1"}
if got := m2.GetSigners(); len(got) != 1 || string(got[0]) != "host-1" {
t.Errorf("MsgLaunchCoverPool GetSigners = %v, want [host-1]", got)
}
// Compile-time: GetSigners returns sdk.AccAddress.
var _ []sdk.AccAddress = m2.GetSigners()
}
// TestMsgLaunchCoverPoolValidateBasicErrors asserts each error path.
func TestMsgLaunchCoverPoolValidateBasicErrors(t *testing.T) {
cases := []struct {
name string
msg MsgLaunchCoverPool
}{
{"empty pool-id", MsgLaunchCoverPool{HostReachID: "h", Categories: []CoverCategory{CatTravel}, ReserveAnnualContribRatio: 1.5, ReserveAccount: "a", Signer: "s"}},
{"empty host-reach-id", MsgLaunchCoverPool{PoolID: "p", Categories: []CoverCategory{CatTravel}, ReserveAnnualContribRatio: 1.5, ReserveAccount: "a", Signer: "s"}},
{"empty categories", MsgLaunchCoverPool{PoolID: "p", HostReachID: "h", ReserveAnnualContribRatio: 1.5, ReserveAccount: "a", Signer: "s"}},
{"empty ReserveAccount", MsgLaunchCoverPool{PoolID: "p", HostReachID: "h", Categories: []CoverCategory{CatTravel}, ReserveAnnualContribRatio: 1.5, Signer: "s"}},
{"empty signer", MsgLaunchCoverPool{PoolID: "p", HostReachID: "h", Categories: []CoverCategory{CatTravel}, ReserveAnnualContribRatio: 1.5, ReserveAccount: "a"}},
{"below floor", MsgLaunchCoverPool{PoolID: "p", HostReachID: "h", Categories: []CoverCategory{CatTravel}, ReserveAnnualContribRatio: 1.0, ReserveAccount: "a", Signer: "s"}},
}
for _, c := range cases {
if err := c.msg.ValidateBasic(); err == nil {
t.Errorf("case %q: ValidateBasic should fail", c.name)
}
}
}
// --- MsgRouteCoverFee methods -----------------------------------------------
func TestMsgRouteCoverFeeMethods(t *testing.T) {
m := &MsgRouteCoverFee{PoolID: "p1", GrainAmount: 100, CategoryTag: "Travel", Signer: "h1"}
if err := m.ValidateBasic(); err != nil {
t.Errorf("valid MsgRouteCoverFee ValidateBasic: %v", err)
}
if !strings.Contains(m.String(), "p1") {
t.Errorf("MsgRouteCoverFee String = %q, want p1", m.String())
}
m.Reset()
if m.PoolID != "" {
t.Errorf("MsgRouteCoverFee Reset did not zero: %+v", m)
}
m.ProtoMessage()
m2 := &MsgRouteCoverFee{Signer: "h1"}
if got := m2.GetSigners(); len(got) != 1 || string(got[0]) != "h1" {
t.Errorf("MsgRouteCoverFee GetSigners = %v, want [h1]", got)
}
}
func TestMsgRouteCoverFeeValidateBasicErrors(t *testing.T) {
cases := []struct {
name string
msg MsgRouteCoverFee
}{
{"empty pool-id", MsgRouteCoverFee{CategoryTag: "c", GrainAmount: 1, Signer: "s"}},
{"empty category-tag", MsgRouteCoverFee{PoolID: "p", GrainAmount: 1, Signer: "s"}},
{"zero grain", MsgRouteCoverFee{PoolID: "p", CategoryTag: "c", Signer: "s"}},
{"neg grain", MsgRouteCoverFee{PoolID: "p", CategoryTag: "c", GrainAmount: -1, Signer: "s"}},
{"empty signer", MsgRouteCoverFee{PoolID: "p", CategoryTag: "c", GrainAmount: 1}},
}
for _, c := range cases {
if err := c.msg.ValidateBasic(); err == nil {
t.Errorf("case %q: ValidateBasic should fail", c.name)
}
}
}
// --- MsgFileCoverCall methods -----------------------------------------------
func TestMsgFileCoverCallMethods(t *testing.T) {
m := &MsgFileCoverCall{CallID: "c1", PoolID: "p1", ClaimantReachID: "u1", Category: CatTravel, AmountGrain: 100, Signer: "u1"}
if err := m.ValidateBasic(); err != nil {
t.Errorf("valid MsgFileCoverCall ValidateBasic: %v", err)
}
if !strings.Contains(m.String(), "c1") {
t.Errorf("MsgFileCoverCall String = %q, want c1", m.String())
}
m.Reset()
if m.CallID != "" {
t.Errorf("MsgFileCoverCall Reset did not zero: %+v", m)
}
m.ProtoMessage()
m2 := &MsgFileCoverCall{Signer: "u1"}
if got := m2.GetSigners(); len(got) != 1 || string(got[0]) != "u1" {
t.Errorf("MsgFileCoverCall GetSigners = %v, want [u1]", got)
}
}
func TestMsgFileCoverCallValidateBasicErrors(t *testing.T) {
cases := []struct {
name string
msg MsgFileCoverCall
}{
{"empty call-id", MsgFileCoverCall{PoolID: "p", ClaimantReachID: "u", Category: CatTravel, AmountGrain: 1, Signer: "s"}},
{"empty pool-id", MsgFileCoverCall{CallID: "c", ClaimantReachID: "u", Category: CatTravel, AmountGrain: 1, Signer: "s"}},
{"empty claimant", MsgFileCoverCall{CallID: "c", PoolID: "p", Category: CatTravel, AmountGrain: 1, Signer: "s"}},
{"empty category", MsgFileCoverCall{CallID: "c", PoolID: "p", ClaimantReachID: "u", AmountGrain: 1, Signer: "s"}},
{"zero amount", MsgFileCoverCall{CallID: "c", PoolID: "p", ClaimantReachID: "u", Category: CatTravel, Signer: "s"}},
{"neg amount", MsgFileCoverCall{CallID: "c", PoolID: "p", ClaimantReachID: "u", Category: CatTravel, AmountGrain: -1, Signer: "s"}},
{"empty signer", MsgFileCoverCall{CallID: "c", PoolID: "p", ClaimantReachID: "u", Category: CatTravel, AmountGrain: 1}},
}
for _, c := range cases {
if err := c.msg.ValidateBasic(); err == nil {
t.Errorf("case %q: ValidateBasic should fail", c.name)
}
}
}
// --- Response types methods -------------------------------------------------
func TestResponseTypesMethods(t *testing.T) {
r1 := &MsgLaunchCoverPoolResponse{}
r1.Reset()
if !strings.Contains(r1.String(), "MsgLaunchCoverPoolResponse") {
t.Errorf("MsgLaunchCoverPoolResponse String = %q", r1.String())
}
r1.ProtoMessage()
r2 := &MsgRouteCoverFeeResponse{}
r2.Reset()
if !strings.Contains(r2.String(), "MsgRouteCoverFeeResponse") {
t.Errorf("MsgRouteCoverFeeResponse String = %q", r2.String())
}
r2.ProtoMessage()
r3 := &MsgFileCoverCallResponse{}
r3.Reset()
if !strings.Contains(r3.String(), "MsgFileCoverCallResponse") {
t.Errorf("MsgFileCoverCallResponse String = %q", r3.String())
}
r3.ProtoMessage()
}
// --- CoverFeeTag / CoverCall / CoverPool coverage --------------------------
// TestCoverPoolAndFeeTagAndCallStructs exercises the struct construction +
// the GenesisState ProtoMessage for coverage on the zero-method paths.
func TestCoverPoolAndFeeTagAndCallStructs(t *testing.T) {
p := CoverPool{PoolID: "p", HostReachID: "h", Categories: []CoverCategory{CatTravel}, ReserveAnnualContribRatio: 1.5, ReserveAccount: "a"}
if p.PoolID != "p" {
t.Errorf("CoverPool PoolID = %q", p.PoolID)
}
tag := CoverFeeTag{GrainAmount: 100, CategoryTag: "Travel", PoolID: "p"}
if tag.GrainAmount != 100 {
t.Errorf("CoverFeeTag GrainAmount = %d", tag.GrainAmount)
}
c := CoverCall{CallID: "c", PoolID: "p", ClaimantReachID: "u", Category: CatTravel, AmountGrain: 1}
if c.CallID != "c" {
t.Errorf("CoverCall CallID = %q", c.CallID)
}
// DefaultGenesisState ProtoMessage.
gs := DefaultGenesisState()
gs.ProtoMessage()
}
+220
View File
@@ -0,0 +1,220 @@
package types
// rights.go holds the Anti-Capture Bill of Rights types (REQ-056, vision §8.2,
// D-090(1) temporal-gap fix). This file lands in P2 (NOT P5) so the dual
// firewall is in place BEFORE any Cover-Charter can be signed: the P2
// MsgSignCoverCharter handler rejects any WaivedRights element at
// ValidateBasic, and P5 then layers the Counsel review ceremony on top of
// these already-locked types.
//
// The 13 rights are non-amendable, non-waivable by any Charter (REQ-056,
// vision §8.2). The dual firewall mirrors the Mission-Lock firewall in
// x/council (D-064): there the firewall is MissionLockAmendable=false (the
// const) + MissionLockAmendmentRejected rejected at ValidateBasic (the gate);
// here the firewall is the 13 Waivable* consts (all false) +
// RightIsWaivable() always returns false + MsgSignCoverCharter.ValidateBasic
// rejects any WaivedRights element. A future agent flipping any const OR
// removing the ValidateBasic gate breaks the regression tests in
// rights_test.go.
//
// The Bill of Rights is the INVARIANT declaration; the Anti-Crowding-Out
// firewall (x/cover/firewall, P1) is the ENFORCEMENT mechanism for
// RightNoTaxOnPersonalStash (the firewall rejects a Cover-Fee routing
// destination that is a Root-Pool operating-expenses holder, which would
// crowd out the contributor-pool reserve — exactly what
// RightNoTaxOnPersonalStash forbids). The two layers together close the
// Anti-Capture failure mode: the right declares the invariant; the firewall
// rejects the code path that would violate it; the ValidateBasic gate
// rejects a Charter that would waive it.
//
// D-085 13th-right candidate (RightNonParticipationNoDenial, confidence
// 0.55): logged as an assumption per the P2 plan — the lead-developer
// surfaces D-085 to the PO before P2; the fallback (log the 13th right and
// proceed) is exercised here. The const AntiCaptureBillOfRightsCount = 13
// is the locked regression firewall for the count; removing or adding a
// right breaks the test.
//
// Lexicon note (REQ-012, D-088): "Right", "Charter", "Waived", "Counsel",
// "Watcher", "Freeholder", "Wayfarer", "Secession" are all lexicon-clean.
// The right identifiers use the safe Cover vocabulary EXCLUSIVELY; the four
// Cover-specific banned terms (enumerated by lexicon.CoverBannedTerms — not
// inlined here so this source stays lexicon-clean) NEVER appear in this
// file (enforced by lexicon_meta_cover).
// RightID is the identifier type for an Anti-Capture Bill of Rights right
// (REQ-056, vision §8.2). A RightID is a string enum: one of the 13 locked
// Right* consts below. The type is a string (not a uint8) so the value is
// self-documenting at the call site + in serialized state (a WaivedRights
// slice in a CoverCharter serializes the right names, not opaque integers).
type RightID string
const (
// RightOneTapExit is the right to one-tap exit a Stand (vision §8.2).
// A Stand holder may dissolve their Stand + return assets to their
// Stash with no Council vote required (the Household one-tap-exit
// handler in P3 is the enforcement). Non-waivable.
RightOneTapExit RightID = "OneTapExit"
// RightNoTaxOnPersonalStash is the right that the personal Stash is
// not taxed to fund Cover-Fee routing (vision §8.2 — the Anti-
// Crowding-Out firewall enforces this: a Cover-Fee may NEVER route
// into a Root-Pool operating-expenses holder, only into a Cover
// Pool's ReserveAccount). Non-waivable.
RightNoTaxOnPersonalStash RightID = "NoTaxOnPersonalStash"
// RightAuditableVoice is the right that Voice is auditable (vision
// §8.2 — the Voice tally is recorded + replayable; the council
// module's TallyResult is the audit record). Non-waivable.
RightAuditableVoice RightID = "AuditableVoice"
// RightCooling is the right to a cooling period before a Charter
// amendment is ratified (vision §8.2 — the 7-day Charter amendment
// cooling in P2 is the enforcement). Non-waivable.
RightCooling RightID = "Cooling"
// RightWatcherInspection is the right that a Watcher may inspect any
// Cover Pool (vision §8.2 — the Watcher attestation pipeline is the
// inspection surface). Non-waivable.
RightWatcherInspection RightID = "WatcherInspection"
// RightFreeholderVoucher is the right that a Freeholder's Vouch is
// counted (vision §8.2 — the Standing module's Vouch weight is the
// counting). Non-waivable.
RightFreeholderVoucher RightID = "FreeholderVoucher"
// RightCounselEscalation is the right to escalate to Counsel
// (vision §8.2 — the Counsel review ceremony in P5 is the escalation
// surface). Non-waivable.
RightCounselEscalation RightID = "CounselEscalation"
// RightAnchoredBreadConversion is the right that Bread conversion is
// anchored to the mission (vision §8.2 — the Bread/Grain conversion
// is mission-locked, not freely tunable). Non-waivable.
RightAnchoredBreadConversion RightID = "AnchoredBreadConversion"
// RightWayfarersRecord is the right that the Wayfarer's record is
// preserved (vision §8.2 — the Wayfarer's journey is recorded
// immutably). Non-waivable.
RightWayfarersRecord RightID = "WayfarersRecord"
// RightSecessionFoundingTerms is the right that secession terms are
// coded at founding (vision §8.2 — the SecessionTerms hash-pinned at
// Guild/Chapter creation in P3 is the enforcement; the terms are
// immutable after founding). Non-waivable.
RightSecessionFoundingTerms RightID = "SecessionFoundingTerms"
// RightNonCoverAccess is the right that non-Cover access is preserved
// (vision §8.2 — a holder's access to the mesh is not gated on Cover
// Pool participation). Non-waivable.
RightNonCoverAccess RightID = "NonCoverAccess"
// RightCategoryMismatchRefusal is the right to refuse a category
// mismatch (vision §8.2 — a Cover Call filed against a category the
// Pool does not cover is REJECTED at the handler; the holder is not
// forced to accept a mismatched Call). Non-waivable.
RightCategoryMismatchRefusal RightID = "CategoryMismatchRefusal"
// RightNonParticipationNoDenial is the D-085 13th-right candidate
// (confidence 0.55, logged as an assumption per the P2 plan): the
// right that non-participation in a Cover Pool does NOT deny mesh
// access (vision §8.2 — a holder who does not join a Cover Pool is
// not denied the mesh-level rights). Non-waivable.
RightNonParticipationNoDenial RightID = "NonParticipationNoDenial"
)
// AntiCaptureBillOfRightsCount is the LOCKED count of Anti-Capture Bill of
// Rights rights (REQ-056, vision §8.2). The 13 rights are non-amendable,
// non-waivable by any Charter. A regression here is a mission-lock breach:
// adding or removing a right breaks the locked-const test in rights_test.go.
// The count is the dual-firewall anchor: the 13 Waivable* consts below +
// RightIsWaivable() + the ValidateBasic gate all key off this count.
const AntiCaptureBillOfRightsCount = 13
// The 13 Waivable* bool consts (all false) are the first layer of the dual
// firewall: each right has a matching Waivable* const that is LOCKED false
// (a right can NEVER be waivable). The RightIsWaivable() function below is
// the second layer (it consults these consts + always returns false); the
// MsgSignCoverCharter.ValidateBasic gate is the third layer (it rejects any
// WaivedRights element). A future agent flipping any const to true breaks
// the regression test. Mirrors MissionLockAmendable=false (D-064).
const (
WaivableOneTapExit = false
WaivableNoTaxOnPersonalStash = false
WaivableAuditableVoice = false
WaivableCooling = false
WaivableWatcherInspection = false
WaivableFreeholderVoucher = false
WaivableCounselEscalation = false
WaivableAnchoredBreadConversion = false
WaivableWayfarersRecord = false
WaivableSecessionFoundingTerms = false
WaivableNonCoverAccess = false
WaivableCategoryMismatchRefusal = false
WaivableNonParticipationNoDenial = false
)
// AllRights returns all 13 Anti-Capture Bill of Rights RightID values in
// canonical order (REQ-056, vision §8.2). The canonical order is the
// declaration order above (OneTapExit first, NonParticipationNoDenial last).
// The locked-const test in rights_test.go asserts exactly 13 entries with
// these names. A future agent reordering, adding, or removing a right
// breaks the test.
func AllRights() []RightID {
return []RightID{
RightOneTapExit,
RightNoTaxOnPersonalStash,
RightAuditableVoice,
RightCooling,
RightWatcherInspection,
RightFreeholderVoucher,
RightCounselEscalation,
RightAnchoredBreadConversion,
RightWayfarersRecord,
RightSecessionFoundingTerms,
RightNonCoverAccess,
RightCategoryMismatchRefusal,
RightNonParticipationNoDenial,
}
}
// AllWaivableFlags returns the 13 Waivable* bool flags keyed by RightID
// (all false — the dual-firewall regression surface). Used by the
// rights_test.go regression test to assert every flag is false. A future
// agent flipping any flag breaks the test. Mirrors the
// MissionLockAmendable=false const firewall in x/council (D-064) but
// applied per-right (13 flags instead of one).
func AllWaivableFlags() map[RightID]bool {
return map[RightID]bool{
RightOneTapExit: WaivableOneTapExit,
RightNoTaxOnPersonalStash: WaivableNoTaxOnPersonalStash,
RightAuditableVoice: WaivableAuditableVoice,
RightCooling: WaivableCooling,
RightWatcherInspection: WaivableWatcherInspection,
RightFreeholderVoucher: WaivableFreeholderVoucher,
RightCounselEscalation: WaivableCounselEscalation,
RightAnchoredBreadConversion: WaivableAnchoredBreadConversion,
RightWayfarersRecord: WaivableWayfarersRecord,
RightSecessionFoundingTerms: WaivableSecessionFoundingTerms,
RightNonCoverAccess: WaivableNonCoverAccess,
RightCategoryMismatchRefusal: WaivableCategoryMismatchRefusal,
RightNonParticipationNoDenial: WaivableNonParticipationNoDenial,
}
}
// RightIsWaivable reports whether the named right is waivable by a Charter
// (REQ-056, vision §8.2). ALWAYS returns false — the 13 rights are non-
// waivable by any Charter. This is the firewall function: the
// MsgSignCoverCharter.ValidateBasic gate calls this (defense in depth —
// the gate also checks len(WaivedRights) > 0 directly, but this function
// is the canonical query for any future call site that asks "is this right
// waivable?"). A future agent changing the return to true breaks the
// regression test. Mirrors the MissionLockAmendable=false const firewall
// in x/council (D-064): there the const is the firewall; here the function
// is the firewall (consulting the 13 Waivable* consts, all false).
func RightIsWaivable(id RightID) bool {
flags := AllWaivableFlags()
if waivable, ok := flags[id]; ok {
return waivable
}
return false
}
+167
View File
@@ -0,0 +1,167 @@
package types
// rights_test.go holds the Anti-Capture Bill of Rights regression tests
// (REQ-056, vision §8.2, D-090(1) temporal-gap fix).
//
// G-024: this test file stays STDLIB-ONLY (no cosmos-sdk import) — it does
// invariant + lexicon assertions, not handler logic. The handler simtest
// (x/cover/keeper/msg_server_simtest_test.go) MAY import cosmos-sdk.
//
// The regression surface:
// - AntiCaptureBillOfRightsCount == 13 (the locked count firewall).
// - All 13 Waivable* consts are false (the dual-firewall const layer).
// - RightIsWaivable returns false for all 13 rights (the firewall
// function layer).
// - AllRights returns 13 RightID values in canonical order.
// - AllWaivableFlags returns a 13-entry map, all values false.
// - RightIsWaivable returns false for an unknown RightID (defense in
// depth — an unknown right is NOT waivable by default).
import (
"testing"
)
// TestAntiCaptureBillOfRightsCount asserts the locked count of rights is
// 13 (REQ-056, vision §8.2). A regression here is a mission-lock breach:
// adding or removing a right breaks the dual-firewall anchor.
func TestAntiCaptureBillOfRightsCount(t *testing.T) {
if AntiCaptureBillOfRightsCount != 13 {
t.Errorf("AntiCaptureBillOfRightsCount = %d, want 13 (REQ-056 locked count, vision §8.2)", AntiCaptureBillOfRightsCount)
}
if len(AllRights()) != 13 {
t.Errorf("len(AllRights()) = %d, want 13 (REQ-056)", len(AllRights()))
}
if len(AllWaivableFlags()) != 13 {
t.Errorf("len(AllWaivableFlags()) = %d, want 13 (REQ-056)", len(AllWaivableFlags()))
}
}
// TestWaivableConstsAllFalse asserts all 13 Waivable* consts are false
// (the dual-firewall const layer — mirrors MissionLockAmendable=false in
// x/council, D-064). A future agent flipping any const to true breaks
// this test.
func TestWaivableConstsAllFalse(t *testing.T) {
cases := []struct {
name string
waivable bool
}{
{"WaivableOneTapExit", WaivableOneTapExit},
{"WaivableNoTaxOnPersonalStash", WaivableNoTaxOnPersonalStash},
{"WaivableAuditableVoice", WaivableAuditableVoice},
{"WaivableCooling", WaivableCooling},
{"WaivableWatcherInspection", WaivableWatcherInspection},
{"WaivableFreeholderVoucher", WaivableFreeholderVoucher},
{"WaivableCounselEscalation", WaivableCounselEscalation},
{"WaivableAnchoredBreadConversion", WaivableAnchoredBreadConversion},
{"WaivableWayfarersRecord", WaivableWayfarersRecord},
{"WaivableSecessionFoundingTerms", WaivableSecessionFoundingTerms},
{"WaivableNonCoverAccess", WaivableNonCoverAccess},
{"WaivableCategoryMismatchRefusal", WaivableCategoryMismatchRefusal},
{"WaivableNonParticipationNoDenial", WaivableNonParticipationNoDenial},
}
if len(cases) != AntiCaptureBillOfRightsCount {
t.Fatalf("test cases len = %d, want AntiCaptureBillOfRightsCount %d (a Waivable* const is missing from the test)", len(cases), AntiCaptureBillOfRightsCount)
}
for _, c := range cases {
if c.waivable {
t.Errorf("%s = true, want false (REQ-056: rights non-amendable, non-waivable by any Charter)", c.name)
}
}
}
// TestRightIsWaivableAlwaysFalse asserts RightIsWaivable returns false for
// all 13 rights + for an unknown RightID (the firewall function layer).
// A future agent changing the return to true breaks this test.
func TestRightIsWaivableAlwaysFalse(t *testing.T) {
for _, id := range AllRights() {
if RightIsWaivable(id) {
t.Errorf("RightIsWaivable(%q) = true, want false (REQ-056: rights non-waivable by any Charter)", id)
}
}
// An unknown RightID returns false (defense in depth — an unknown
// right is NOT waivable by default).
if RightIsWaivable(RightID("UnknownRight")) {
t.Error("RightIsWaivable(UnknownRight) = true, want false (unknown rights are NOT waivable)")
}
}
// TestAllRightsCanonicalOrder asserts AllRights returns the 13 rights in
// the canonical declaration order (OneTapExit first,
// NonParticipationNoDenial last). A reordering breaks the test.
func TestAllRightsCanonicalOrder(t *testing.T) {
want := []RightID{
RightOneTapExit,
RightNoTaxOnPersonalStash,
RightAuditableVoice,
RightCooling,
RightWatcherInspection,
RightFreeholderVoucher,
RightCounselEscalation,
RightAnchoredBreadConversion,
RightWayfarersRecord,
RightSecessionFoundingTerms,
RightNonCoverAccess,
RightCategoryMismatchRefusal,
RightNonParticipationNoDenial,
}
got := AllRights()
if len(got) != len(want) {
t.Fatalf("len(AllRights()) = %d, want %d", len(got), len(want))
}
for i, id := range got {
if id != want[i] {
t.Errorf("AllRights()[%d] = %q, want %q (canonical order)", i, id, want[i])
}
}
}
// TestAllWaivableFlagsAllFalse asserts AllWaivableFlags returns a 13-entry
// map with all values false. A future agent flipping a flag breaks this
// test.
func TestAllWaivableFlagsAllFalse(t *testing.T) {
flags := AllWaivableFlags()
if len(flags) != AntiCaptureBillOfRightsCount {
t.Fatalf("len(AllWaivableFlags()) = %d, want %d", len(flags), AntiCaptureBillOfRightsCount)
}
for id, waivable := range flags {
if waivable {
t.Errorf("AllWaivableFlags()[%q] = true, want false (REQ-056)", id)
}
}
// Cross-check: every right in AllRights() has an entry in
// AllWaivableFlags().
for _, id := range AllRights() {
if _, ok := flags[id]; !ok {
t.Errorf("AllWaivableFlags() missing entry for right %q", id)
}
}
}
// TestRightIDValues asserts the 13 RightID string values are the expected
// canonical strings (a regression on the string value would break
// serialized state compatibility).
func TestRightIDValues(t *testing.T) {
cases := []struct {
id RightID
want string
}{
{RightOneTapExit, "OneTapExit"},
{RightNoTaxOnPersonalStash, "NoTaxOnPersonalStash"},
{RightAuditableVoice, "AuditableVoice"},
{RightCooling, "Cooling"},
{RightWatcherInspection, "WatcherInspection"},
{RightFreeholderVoucher, "FreeholderVoucher"},
{RightCounselEscalation, "CounselEscalation"},
{RightAnchoredBreadConversion, "AnchoredBreadConversion"},
{RightWayfarersRecord, "WayfarersRecord"},
{RightSecessionFoundingTerms, "SecessionFoundingTerms"},
{RightNonCoverAccess, "NonCoverAccess"},
{RightCategoryMismatchRefusal, "CategoryMismatchRefusal"},
{RightNonParticipationNoDenial, "NonParticipationNoDenial"},
}
for _, c := range cases {
if string(c.id) != c.want {
t.Errorf("RightID(%q) value = %q, want %q", c.id, c.id, c.want)
}
}
}
+497
View File
@@ -0,0 +1,497 @@
// Package types defines the Cover module API types (vision §15, REQ-046,
// REQ-047, REQ-049, REQ-050, REQ-055, D-077, D-086, D-088).
//
// The Cover module ships the Cover Pool: a mission-locked contributor-pool
// reserve that a Host maintains against a set of Cover categories (Travel,
// HealthMCS, IncomePause, EquipmentLoss, LifeBurial, RoadSide,
// CyberSkimming, GuildInternalMutualAid). The reserve is funded by a
// Cover-Fee (an annual contrib ratio, floor-locked at
// CoverReserveFloorAnnualContribX=1.5); Cover Calls are filed against a
// pool's category and adjudicated by a Cover Claims Voucher in P4.
//
// Lexicon note (REQ-012, D-088): the Cover vocabulary is HIGH lexicon-risk
// because the primitive is a natural fit for the banned Cover-specific
// terms. The safe vision names are used EXCLUSIVELY here — "Cover", "Cover-
// Fee", "Cover Call", "Cover-Charter", "Cover Pool", "Cover Claims
// Voucher", "Mutual Aid Bond" are the clean names; the four Cover-specific
// banned terms (enumerated by lexicon.CoverBannedTerms — not inlined here
// so this source stays lexicon-clean) NEVER appear in this package
// (enforced by lexicon_meta_cover, the 4th lexicon meta-test, which scans
// x/cover/**/*.go for both lexicon.FindBannedTerm (the 10 project-wide
// terms) AND lexicon.FindCoverBannedTerm (the 4 Cover-specific terms)).
// Note: "Cover Call" uses "Call" not the banned noun — correct. The
// FileCoverCall handler name is clean. The "ClaimantReachID" field on
// CoverCall uses "Claimant" (a person, not the banned noun) — the
// word-boundary regex does NOT match "Claimant" (it is not the banned
// word), so this field name is lexicon-clean.
//
// Cross-module references are by-ID-string per G-003 (no struct imports):
// - HostReachID references an x/standing holder by reach-id (D-077
// Standing gate: the handler queries StandingKeeper.GetStandingBucket
// for the host's bucket + score per category; the gate consts
// CoverStandingGateTrusted / CoverStandingGatePreferred are
// cross-documented to x/standing.BucketTrusted / BucketPreferred).
// - PoolID references a Cover Pool by ID-string (the store key).
// - the WatcherKeeper shim's Attest(poolID, payload) is the x/watcher
// attestation pipeline (G-003 by-ID-string; the shim is an interface).
// - the StillKeeper shim's Still(poolID, reason) is the x/still pause
// pipeline (D-089(1) — the below-floor auto-pause + the MAB misuse
// auto-Still call this; nil shim skips in simtest).
package types
import (
"encoding/json"
"fmt"
)
const (
ModuleName = "cover"
StoreKey = ModuleName
RouterKey = ModuleName
QuerierRoute = ModuleName
// CoverReserveFloorAnnualContribX is the LOCKED mission-floor on a Cover
// Pool's annual reserve contrib ratio (REQ-047, GRILL-ratified). A pool
// whose ReserveAnnualContribRatio drops below this floor is auto-paused
// (the RouteCoverFee handler pauses + invokes StillKeeper.Still on a
// below-floor routing). This is the mission-locked floor — it can NEVER
// be lowered (the reserve must stay mission-adequate). Cross-doc: the
// floor is the lower bound on CoverPool.ReserveAnnualContribRatio; the
// handler re-checks it at routing time (defense in depth).
CoverReserveFloorAnnualContribX = 1.5
// CoverReserveCeilingAnnualContribX is the bounded UPPER limit on a
// Cover Pool's annual reserve contrib ratio (REQ-048 — NOT locked, can
// be tuned by governance). A pool's ReserveAnnualContribRatio must stay
// <= this ceiling. P1 ships the const; the enforcement is at
// LaunchCoverPool (the handler rejects a launch above the ceiling).
CoverReserveCeilingAnnualContribX = 2.5
// CoverStandingGateTrusted is the LOCKED Standing gate floor for the
// Trusted bucket (REQ-049, GRILL-ratified). A Cover Pool's host must
// have Standing >= Trusted (bucket == "Trusted" or "Preferred" or "Top";
// score >= 4.0) for the Travel + IncomePause categories. Cross-
// documented to x/standing.BucketTrusted (the gate const mirrors the
// bucket boundary). The const is LOCAL to x/cover to avoid importing
// x/standing (G-003 — no struct import); the two consts MUST stay in
// sync (a change to x/standing.BucketTrusted's boundary requires a
// matching change here).
CoverStandingGateTrusted = 4.0
// CoverStandingGatePreferred is the LOCKED Standing gate floor for the
// Preferred bucket (REQ-049, GRILL-ratified). A Cover Pool's host must
// have Standing >= Preferred (bucket == "Preferred" or "Top"; score >=
// 4.5) for the HealthMCS category (the higher-stakes category demands
// the higher gate). Cross-documented to x/standing.BucketPreferred
// (the gate const mirrors the bucket boundary). LOCAL to x/cover for
// the same G-003 reason as CoverStandingGateTrusted.
CoverStandingGatePreferred = 4.5
)
// CoverCategoryPhase enumerates the three rollout phases of the Cover
// category factory (REQ-065, D-086). The full enum lands here in P1; the P1
// Factory only ALLOWS Phase2 (D-086 — FactoryAllowedPhases = [Phase2] only
// in DefaultParams). Phase3 + Phase4 categories are REJECTED at launch in
// P1 (the D-086 category phase check).
type CoverCategoryPhase string
const (
Phase2 CoverCategoryPhase = "Phase2" // P1: Travel, HealthMCS, IncomePause
Phase3 CoverCategoryPhase = "Phase3" // P2: EquipmentLoss, LifeBurial, RoadSide
Phase4 CoverCategoryPhase = "Phase4" // P3: CyberSkimming, GuildInternalMutualAid
)
// CoverCategory enumerates the eight Cover categories across the three
// phases (vision §15, REQ-065). The category is the unit of Cover-Fee
// routing (a Cover-Fee's CategoryTag must match one of the pool's
// Categories) and the unit of the Standing gate (the handler queries the
// host's Standing per category).
type CoverCategory string
const (
CatTravel CoverCategory = "Travel" // Phase2
CatHealthMCS CoverCategory = "HealthMCS" // Phase2 (Preferred gate)
CatIncomePause CoverCategory = "IncomePause" // Phase2
CatEquipmentLoss CoverCategory = "EquipmentLoss" // Phase3
CatLifeBurial CoverCategory = "LifeBurial" // Phase3
CatRoadSide CoverCategory = "RoadSide" // Phase3
CatCyberSkimming CoverCategory = "CyberSkimming" // Phase4
CatGuildInternalMutualAid CoverCategory = "GuildInternalMutualAid" // Phase4
)
// CoverCategoryPhaseFor returns the CoverCategoryPhase for a CoverCategory
// (REQ-065, D-086). The handler uses this to check that a launch's
// categories are all in the Pool's FactoryAllowedPhases (P1 default =
// [Phase2] only). Returns the zero CoverCategoryPhase ("") for an unknown
// category (the handler rejects an unknown category as a separate check).
func CoverCategoryPhaseFor(cat CoverCategory) CoverCategoryPhase {
switch cat {
case CatTravel, CatHealthMCS, CatIncomePause:
return Phase2
case CatEquipmentLoss, CatLifeBurial, CatRoadSide:
return Phase3
case CatCyberSkimming, CatGuildInternalMutualAid:
return Phase4
}
return ""
}
// CoverPool is a Cover Pool: a mission-locked contributor-pool reserve a
// Host maintains against a set of Cover categories (REQ-046, REQ-047). The
// pool is launched via MsgLaunchCoverPool (the handler enforces the D-077
// Standing gate + the D-086 category phase check + the reserve floor). The
// reserve is funded by a Cover-Fee (the annual contrib ratio); Cover Calls
// are filed against the pool's categories. CharterHash is a placeholder
// for P2 (the Cover-Charter content hash; P1 ships the field, the charter
// adjudication is deferred). PoolStandingGate is the pool's TIGHTENED gate
// (>= CoverStandingGateTrusted; the pool can demand a higher gate than the
// protocol minimum but never lower). FactoryAllowedPhases is the pool's
// allowed phases (P1 default = [Phase2] only per D-086).
//
// P2 extensions (REQ-052, REQ-062): CharterRef is the by-ID-string ref to
// the CoverCharter signed for this pool (empty until a Charter is signed);
// CouncilRef is the by-ID-string ref to the PoolCouncil elected for this
// pool (empty until a Council is seated). Both are by-ID-string per G-003
// (no struct import of the charter/council records — the keeper loads them
// by ID from their own stores).
type CoverPool struct {
PoolID string `json:"pool_id" yaml:"pool_id"`
HostReachID string `json:"host_reach_id" yaml:"host_reach_id"`
Categories []CoverCategory `json:"categories" yaml:"categories"`
ReserveAnnualContribRatio float64 `json:"reserve_annual_contrib_ratio" yaml:"reserve_annual_contrib_ratio"`
ReserveAccount string `json:"reserve_account" yaml:"reserve_account"`
PoolPaused bool `json:"pool_paused" yaml:"pool_paused"`
CharterHash []byte `json:"charter_hash" yaml:"charter_hash"`
FactoryAllowedPhases []CoverCategoryPhase `json:"factory_allowed_phases" yaml:"factory_allowed_phases"`
PoolStandingGate float64 `json:"pool_standing_gate" yaml:"pool_standing_gate"`
CreatedAt int64 `json:"created_at" yaml:"created_at"`
CharterRef string `json:"charter_ref" yaml:"charter_ref"`
CouncilRef string `json:"council_ref" yaml:"council_ref"`
}
// CoverFeeTag is the category tag on a Cover-Fee routing event (REQ-050,
// FR-COVER-11). GrainAmount is the Grain amount being routed (the OY
// internal unit, cross-ref x/bread by name only — no struct import).
// CategoryTag is the category the fee is routed against (must match one of
// the Pool's Categories). PoolID is the pool the fee is routed into. This
// is NOT on x/bread.Grain (the Cover-Fee is a routing event, not a Grain
// field); the Cover-Fee's category tag is the Cover-module's own bookkeeping.
type CoverFeeTag struct {
GrainAmount int64 `json:"grain_amount" yaml:"grain_amount"`
CategoryTag string `json:"category_tag" yaml:"category_tag"`
PoolID string `json:"pool_id" yaml:"pool_id"`
}
// CoverCall is a Cover Call: a request for Cover against a pool's category
// (REQ-055 P1 scaffold — the Voucher adjudication lands in P4). ClaimantReachID
// is the filer's reach-id (the person filing the Cover Call; "Claimant" is a
// person, NOT the banned noun — the word-boundary regex does not match
// "Claimant"). AmountGrain is the Grain amount requested. FiledAt is the
// filing block height. P4 adds the Voucher assignment + no-self-adjudication
// + slashing (the FileCoverCall handler in P1 only persists the call +
// emits an event).
type CoverCall struct {
CallID string `json:"call_id" yaml:"call_id"`
PoolID string `json:"pool_id" yaml:"pool_id"`
ClaimantReachID string `json:"claimant_reach_id" yaml:"claimant_reach_id"`
Category CoverCategory `json:"category" yaml:"category"`
AmountGrain int64 `json:"amount_grain" yaml:"amount_grain"`
FiledAt int64 `json:"filed_at" yaml:"filed_at"`
}
// Params for the cover module (REQ-049, D-086). FactoryAllowedPhases is the
// factory's allowed phases (P1 default = [Phase2] only per D-086 — only
// Travel/HealthMCS/IncomePause can be launched in P1). PoolStandingGate is
// the protocol-minimum Standing gate a pool must meet (default =
// CoverStandingGateTrusted; a pool's own PoolStandingGate field may be
// TIGHTENED above this but never lowered below it — the D-090(3) dual
// check: the handler checks BOTH the pool's gate AND the Params floor).
type Params struct {
FactoryAllowedPhases []CoverCategoryPhase `json:"factory_allowed_phases" yaml:"factory_allowed_phases"`
PoolStandingGate float64 `json:"pool_standing_gate" yaml:"pool_standing_gate"`
}
// DefaultParams returns the P2 default Params (D-086 P2 completion):
// FactoryAllowedPhases = [Phase2, Phase3, Phase4] (the P1 default was
// [Phase2] only; P2 extends the factory to all three phases so Phase3
// categories (EquipmentLoss/LifeBurial/RoadSide) and Phase4 categories
// (CyberSkimming/GuildInternalMutualAid) can be launched), PoolStandingGate
// = CoverStandingGateTrusted (the locked protocol minimum). A test that
// needs the P1 behavior (Phase2 only) overrides FactoryAllowedPhases
// explicitly (the D-086 simtest case f does this).
func DefaultParams() Params {
return Params{
FactoryAllowedPhases: []CoverCategoryPhase{Phase2, Phase3, Phase4},
PoolStandingGate: CoverStandingGateTrusted,
}
}
// Validate asserts the Params are well-formed: PoolStandingGate >=
// CoverStandingGateTrusted (a pool may tighten the gate but never lower it
// below the protocol minimum — D-090(3)), and FactoryAllowedPhases is
// non-empty (the factory must allow at least one phase).
func (p Params) Validate() error {
if p.PoolStandingGate < CoverStandingGateTrusted {
return fmt.Errorf("cover: PoolStandingGate %.2f < protocol minimum %.2f (D-090(3): a pool may tighten the gate but never lower it)", p.PoolStandingGate, CoverStandingGateTrusted)
}
if len(p.FactoryAllowedPhases) == 0 {
return fmt.Errorf("cover: FactoryAllowedPhases empty (the factory must allow at least one phase)")
}
return nil
}
// GenesisState defines the cover module genesis state (REQ-046). The Pools
// slice holds the CoverPool records; the Calls slice holds the CoverCall
// records. ValidateGenesis enforces per-set ID uniqueness (A-212) and the
// Params.Validate invariants.
type GenesisState struct {
Params Params `json:"params" yaml:"params"`
Pools []CoverPool `json:"pools" yaml:"pools"`
Calls []CoverCall `json:"calls" yaml:"calls"`
}
// DefaultGenesisState returns an empty genesis state with non-nil slices
// and the P1 default Params.
func DefaultGenesisState() *GenesisState {
return &GenesisState{
Params: DefaultParams(),
Pools: []CoverPool{},
Calls: []CoverCall{},
}
}
// Reset implements proto.Message (codec.JSONCodec.MustMarshalJSON /
// MustUnmarshalJSON require proto.Message; the GenesisState is the JSON
// genesis container for the cover module).
func (m *GenesisState) Reset() { *m = GenesisState{} }
// String implements proto.Message.
func (m *GenesisState) String() string {
return fmt.Sprintf("GenesisState{Pools:%d Calls:%d}", len(m.Pools), len(m.Calls))
}
// ProtoMessage implements proto.Message.
func (*GenesisState) ProtoMessage() {}
// ValidateGenesis performs ID-uniqueness checks (A-212) and the Params
// invariants on genesis load: rejects duplicate pool-ids, duplicate call-
// ids, and a Params violation (PoolStandingGate below the protocol minimum
// or empty FactoryAllowedPhases).
func ValidateGenesis(bz json.RawMessage) error {
var gs GenesisState
if err := json.Unmarshal(bz, &gs); err != nil {
return fmt.Errorf("cover: invalid genesis: %w", err)
}
if err := gs.Params.Validate(); err != nil {
return fmt.Errorf("cover: %w", err)
}
if err := validatePools(gs.Pools); err != nil {
return fmt.Errorf("cover: %w", err)
}
if err := validateCalls(gs.Calls); err != nil {
return fmt.Errorf("cover: %w", err)
}
return nil
}
// validatePools enforces pool-id presence and uniqueness.
func validatePools(pools []CoverPool) error {
seen := make(map[string]bool, len(pools))
for i, p := range pools {
if p.PoolID == "" {
return fmt.Errorf("pool [%d]: empty pool-id", i)
}
if seen[p.PoolID] {
return fmt.Errorf("pool: duplicate pool-id %q", p.PoolID)
}
seen[p.PoolID] = true
}
return nil
}
// validateCalls enforces call-id presence and uniqueness.
func validateCalls(calls []CoverCall) error {
seen := make(map[string]bool, len(calls))
for i, c := range calls {
if c.CallID == "" {
return fmt.Errorf("call [%d]: empty call-id", i)
}
if seen[c.CallID] {
return fmt.Errorf("call: duplicate call-id %q", c.CallID)
}
seen[c.CallID] = true
}
return nil
}
// --- P2: Cover-Charter + CharterAmendment + PoolCouncil + CoverCallVote -------
//
// (REQ-052, REQ-062, REQ-056; vision §15, §8.2.) The four structs below are
// the P2 governance surface. CoverCharter is the mission-locked charter a
// Pool Host signs (with the Anti-Capture Bill of Rights gate at
// MsgSignCoverCharter.ValidateBasic — D-090(1)). CharterAmendment is the
// amendment record with a 7-day cooling (the amendment stays Proposed for
// 7 days, then Cooled, then Ratified). PoolCouncil is the Pool's elected
// governance council (3 Masons + 1 Watcher observer; NO Anchor seat; NO
// MAB-holder seat — REQ-062, REQ-063). CoverCallVote is a single vote on
// a Cover Call (the majority requires a Watcher observer present for a
// CallVoteYes — REQ-062).
//
// Lexicon note (REQ-012, D-088): "Cover-Charter", "Pool Council", "Cover
// Call Vote", "Charter Amendment" are lexicon-clean. The four Cover-
// specific banned terms NEVER appear (enforced by lexicon_meta_cover).
// CharterAmendmentStatus is the lifecycle status of a CharterAmendment
// (REQ-052). The amendment transitions Proposed -> Cooled (after the 7-day
// cooling) -> Ratified (after the Pool supermajority + Watcher + Counsel).
// The cooling is enforced at the handler: a ratify attempt before 7 days
// is REJECTED.
type CharterAmendmentStatus string
const (
// AmendmentProposed is the initial status (the amendment is filed; the
// 7-day cooling clock starts at ProposedAt).
AmendmentProposed CharterAmendmentStatus = "Proposed"
// AmendmentCooled is the post-cooling status (>= 7 days after
// ProposedAt; the amendment is eligible for ratification).
AmendmentCooled CharterAmendmentStatus = "Cooled"
// AmendmentRatified is the terminal status (the Pool supermajority +
// Watcher + Counsel have ratified the amendment).
AmendmentRatified CharterAmendmentStatus = "Ratified"
)
// CharterAmendmentCoolingSeconds is the LOCKED 7-day cooling period for a
// Charter amendment (REQ-052). The amendment stays Proposed for this many
// seconds before it can be Cooled + Ratified. A regression here is a
// mission-lock breach (the cooling is the Anti-Capture Bill of Rights
// RightCooling enforcement). The handler checks `now - ProposedAt >=
// CharterAmendmentCoolingSeconds` before transitioning to Cooled.
const CharterAmendmentCoolingSeconds int64 = 7 * 24 * 60 * 60
// ReserveCeilingAgeSeconds is the LOCKED 12-month operating-history age
// required before a Watcher can escalate a pool's reserve target to the
// CoverReserveCeilingAnnualContribX (REQ-048). The handler checks
// `now - pool.CreatedAt >= ReserveCeilingAgeSeconds` before the escalation
// is permitted. A regression here is a mission-lock breach (the 12-month
// age check prevents a fresh pool from jumping to the ceiling).
const ReserveCeilingAgeSeconds int64 = 365 * 24 * 60 * 60
// CharterAmendment is a single amendment to a Cover-Charter (REQ-052).
// The amendment is filed via MsgAmendCoverCharter (Status = AmendmentProposed,
// ProposedAt = now). After the 7-day cooling (CharterAmendmentCoolingSeconds),
// a separate handler (or simtest time-advance) transitions it to
// AmendmentCooled. After the Pool supermajority + Watcher + Counsel, it
// transitions to AmendmentRatified. The cooling is the Anti-Capture Bill
// of Rights RightCooling enforcement.
type CharterAmendment struct {
AmendmentID string `json:"amendment_id" yaml:"amendment_id"`
Description string `json:"description" yaml:"description"`
Status CharterAmendmentStatus `json:"status" yaml:"status"`
ProposedAt int64 `json:"proposed_at" yaml:"proposed_at"`
CooledAt int64 `json:"cooled_at" yaml:"cooled_at"`
RatifiedAt int64 `json:"ratified_at" yaml:"ratified_at"`
}
// CoverCharter is the mission-locked charter a Pool Host signs (REQ-052,
// REQ-056). The charter is signed via MsgSignCoverCharter (the handler
// enforces the D-090(1) Bill of Rights gate at ValidateBasic: any
// WaivedRights element REJECTS the signing). The charter's
// StatementOfBeliefsHash is the hash of the charter's statement of beliefs
// (the protocol does NOT enforce the content — FR-CHTR-5). DisputePath is
// the dispute-resolution path. Gate is the pool's tightened Standing gate
// (>= CoverStandingGateTrusted). HoldingPeriodDays is the minimum holding
// period. HostReachID is the host's reach-id. WatcherWitnessHash is the
// Watcher's witness hash (the handler calls WatcherKeeper.Attest; a nil
// WatcherKeeper skips). Amendments is the amendment history. WaivedRights
// is the (ALWAYS EMPTY in a valid charter) slice of waived rights — the
// ValidateBasic gate rejects any non-empty slice.
type CoverCharter struct {
CharterID string `json:"charter_id" yaml:"charter_id"`
PoolID string `json:"pool_id" yaml:"pool_id"`
StatementOfBeliefsHash []byte `json:"statement_of_beliefs_hash" yaml:"statement_of_beliefs_hash"`
DisputePath string `json:"dispute_path" yaml:"dispute_path"`
Gate string `json:"gate" yaml:"gate"`
HoldingPeriodDays uint32 `json:"holding_period_days" yaml:"holding_period_days"`
HostReachID string `json:"host_reach_id" yaml:"host_reach_id"`
WatcherWitnessHash []byte `json:"watcher_witness_hash" yaml:"watcher_witness_hash"`
Amendments []CharterAmendment `json:"amendments" yaml:"amendments"`
WaivedRights []RightID `json:"waived_rights" yaml:"waived_rights"`
}
// PoolCouncil is the Pool's elected governance council (REQ-062). The
// council is seated via MsgElectPoolMason (the handler adds MasonReachIDs
// to the ElectedMasonReachIDs array, max 3 — a 4th is REJECTED). The
// ElectedMasonReachIDs is a fixed-size [3]string array (the three elected
// Masons; empty strings until elected). WatcherObserverReachID is the
// Watcher observer (the majority-required-with-observer check in
// VoteCoverCall: a CallVoteYes requires WatcherObserverPresent == true).
// NO Anchor seat (vision §5 — the Anchor does not sit on the Pool
// Council). NO MAB-holder seat (REQ-063 — the MAB holder is excluded from
// the Pool Council voice set; the MAB governance lands in P4 but the
// struct excludes them now).
type PoolCouncil struct {
PoolID string `json:"pool_id" yaml:"pool_id"`
HostReachID string `json:"host_reach_id" yaml:"host_reach_id"`
ElectedMasonReachIDs [3]string `json:"elected_mason_reach_ids" yaml:"elected_mason_reach_ids"`
WatcherObserverReachID string `json:"watcher_observer_reach_id" yaml:"watcher_observer_reach_id"`
}
// PoolCouncilMaxMasons is the LOCKED max number of elected Masons on a
// Pool Council (REQ-062). A 4th election is REJECTED at the handler. A
// regression here is a mission-lock breach.
const PoolCouncilMaxMasons = 3
// CallVoteOption is the vote option on a Cover Call (REQ-062). The three
// options: CallVoteYes, CallVoteNo, CallVoteAbstain. A CallVoteYes
// requires the Watcher observer to be present (WatcherObserverPresent ==
// true) at the handler — a CallVoteYes without the observer is REJECTED.
type CallVoteOption string
const (
CallVoteYes CallVoteOption = "Yes"
CallVoteNo CallVoteOption = "No"
CallVoteAbstain CallVoteOption = "Abstain"
)
// CallVoteOptionCount is the LOCKED count of CallVoteOption enum values
// (REQ-062). A regression firewall: adding/removing/renaming a
// CallVoteOption breaks this const's test.
const CallVoteOptionCount = 3
// AllCallVoteOptions returns all three CallVoteOption values in REQ-062
// order. The locked-const test asserts exactly 3 entries.
func AllCallVoteOptions() []CallVoteOption {
return []CallVoteOption{
CallVoteYes,
CallVoteNo,
CallVoteAbstain,
}
}
// knownCallVoteOption reports whether o is one of the three CallVoteOption
// values (used by MsgVoteCoverCall.ValidateBasic).
func knownCallVoteOption(o CallVoteOption) bool {
for _, oo := range AllCallVoteOptions() {
if o == oo {
return true
}
}
return false
}
// CoverCallVote is a single vote on a Cover Call (REQ-062). The vote is
// cast via MsgVoteCoverCall (the handler enforces the CoverCall exists +
// the Watcher-observer-present check for a CallVoteYes). VoterReachID is
// the voter's reach-id. VoteOption is the CallVoteOption. WatcherObserverPresent
// records whether the Watcher observer was present at the time of the vote
// (the handler rejects a CallVoteYes with WatcherObserverPresent == false).
// VotedAt is the vote timestamp (unix seconds).
type CoverCallVote struct {
VoteID string `json:"vote_id" yaml:"vote_id"`
CallID string `json:"call_id" yaml:"call_id"`
PoolID string `json:"pool_id" yaml:"pool_id"`
VoterReachID string `json:"voter_reach_id" yaml:"voter_reach_id"`
VoteOption CallVoteOption `json:"vote_option" yaml:"vote_option"`
WatcherObserverPresent bool `json:"watcher_observer_present" yaml:"watcher_observer_present"`
VotedAt int64 `json:"voted_at" yaml:"voted_at"`
}
+379
View File
@@ -0,0 +1,379 @@
package types
// types_test.go holds the locked-const + lexicon regression tests for
// x/cover/types (REQ-047, REQ-048, REQ-049, REQ-065, D-086, D-088).
//
// G-024: this test file stays STDLIB-ONLY (no cosmos-sdk import) — it does
// invariant + lexicon assertions, not handler logic. The handler simtest
// (x/cover/keeper/msg_server_simtest_test.go) MAY import cosmos-sdk (it is
// a simtest, not an invariant test).
//
// Lexicon self-exclusion (D-088): this test file lives in x/cover/types/
// so it must NOT contain the banned Cover-specific terms (enumerated by
// lexicon.CoverBannedTerms — not inlined here so this source stays
// lexicon-clean) or the 10 project-wide banned terms as literals. The
// lexicon assertion below scans x/cover/**/*.go using the lexicon package
// helpers (which assemble the banned terms from fragments), so this file's
// own source stays lexicon-clean (it references the helpers, not the
// literals).
import (
"encoding/json"
"os"
"path/filepath"
"runtime"
"strings"
"testing"
"github.com/oy/openyield/lexicon"
)
// --- Locked consts (REQ-047, REQ-048, REQ-049) ------------------------------
// TestLockedConsts asserts the four GRILL-ratified locked consts (REQ-047,
// REQ-048, REQ-049) hold their locked values. A regression here is a
// mission-lock breach.
func TestLockedConsts(t *testing.T) {
if CoverReserveFloorAnnualContribX != 1.5 {
t.Errorf("CoverReserveFloorAnnualContribX = %.2f, want 1.5 (REQ-047 locked mission floor)", CoverReserveFloorAnnualContribX)
}
if CoverReserveCeilingAnnualContribX != 2.5 {
t.Errorf("CoverReserveCeilingAnnualContribX = %.2f, want 2.5 (REQ-048 bounded upper limit)", CoverReserveCeilingAnnualContribX)
}
if CoverStandingGateTrusted != 4.0 {
t.Errorf("CoverStandingGateTrusted = %.2f, want 4.0 (REQ-049 locked Trusted gate, cross-doc x/standing.BucketTrusted)", CoverStandingGateTrusted)
}
if CoverStandingGatePreferred != 4.5 {
t.Errorf("CoverStandingGatePreferred = %.2f, want 4.5 (REQ-049 locked Preferred gate, cross-doc x/standing.BucketPreferred)", CoverStandingGatePreferred)
}
}
// --- CoverCategoryPhaseFor (REQ-065, D-086) ---------------------------------
// TestCoverCategoryPhaseFor asserts the phase mapping for each of the 8
// Cover categories (REQ-065, D-086).
func TestCoverCategoryPhaseFor(t *testing.T) {
cases := []struct {
cat CoverCategory
want CoverCategoryPhase
}{
{CatTravel, Phase2},
{CatHealthMCS, Phase2},
{CatIncomePause, Phase2},
{CatEquipmentLoss, Phase3},
{CatLifeBurial, Phase3},
{CatRoadSide, Phase3},
{CatCyberSkimming, Phase4},
{CatGuildInternalMutualAid, Phase4},
}
for _, c := range cases {
got := CoverCategoryPhaseFor(c.cat)
if got != c.want {
t.Errorf("CoverCategoryPhaseFor(%q) = %q, want %q", c.cat, got, c.want)
}
}
// Unknown category returns the zero phase.
if got := CoverCategoryPhaseFor(CoverCategory("Unknown")); got != "" {
t.Errorf("CoverCategoryPhaseFor(Unknown) = %q, want empty", got)
}
}
// --- DefaultParams (D-086) --------------------------------------------------
// TestDefaultParamsFactoryAllowedPhases asserts DefaultParams ships
// FactoryAllowedPhases = [Phase2, Phase3, Phase4] (D-086 P2 completion —
// P1 allowed Phase2 only; P2 extends the factory to all three phases so
// Phase3 categories (EquipmentLoss/LifeBurial/RoadSide) and Phase4
// categories (CyberSkimming/GuildInternalMutualAid) can be launched) and
// PoolStandingGate = CoverStandingGateTrusted (the locked protocol minimum).
// A test that needs the P1 behavior (Phase2 only) overrides
// FactoryAllowedPhases explicitly.
func TestDefaultParamsFactoryAllowedPhases(t *testing.T) {
p := DefaultParams()
if len(p.FactoryAllowedPhases) != 3 {
t.Fatalf("DefaultParams FactoryAllowedPhases len = %d, want 3 (D-086 P2: [Phase2, Phase3, Phase4])", len(p.FactoryAllowedPhases))
}
want := []CoverCategoryPhase{Phase2, Phase3, Phase4}
for i, ph := range p.FactoryAllowedPhases {
if ph != want[i] {
t.Errorf("DefaultParams FactoryAllowedPhases[%d] = %q, want %q (D-086 P2)", i, ph, want[i])
}
}
if p.PoolStandingGate != CoverStandingGateTrusted {
t.Errorf("DefaultParams PoolStandingGate = %.2f, want %.2f (CoverStandingGateTrusted)", p.PoolStandingGate, CoverStandingGateTrusted)
}
}
// TestParamsValidate asserts Params.Validate rejects a gate below the
// protocol minimum (D-090(3)) and empty FactoryAllowedPhases.
func TestParamsValidate(t *testing.T) {
// Default is valid.
if err := DefaultParams().Validate(); err != nil {
t.Errorf("DefaultParams Validate: %v", err)
}
// Gate below minimum.
bad := Params{FactoryAllowedPhases: []CoverCategoryPhase{Phase2}, PoolStandingGate: 3.0}
if err := bad.Validate(); err == nil {
t.Error("Params with PoolStandingGate 3.0 < 4.0 should fail Validate (D-090(3))")
}
// Empty FactoryAllowedPhases.
bad2 := Params{FactoryAllowedPhases: nil, PoolStandingGate: CoverStandingGateTrusted}
if err := bad2.Validate(); err == nil {
t.Error("Params with empty FactoryAllowedPhases should fail Validate")
}
}
// --- ValidateGenesis (A-212 ID-uniqueness) ----------------------------------
// TestValidateGenesisIDUniqueness asserts ValidateGenesis rejects duplicate
// pool-ids + duplicate call-ids, and accepts a valid genesis.
func TestValidateGenesisIDUniqueness(t *testing.T) {
// Valid genesis.
valid := DefaultGenesisState()
valid.Pools = []CoverPool{{PoolID: "p1", HostReachID: "h1", Categories: []CoverCategory{CatTravel}, ReserveAnnualContribRatio: 1.5, ReserveAccount: "acc-1"}}
valid.Calls = []CoverCall{{CallID: "c1", PoolID: "p1", ClaimantReachID: "u1", Category: CatTravel, AmountGrain: 100}}
bz, err := json.Marshal(valid)
if err != nil {
t.Fatalf("marshal: %v", err)
}
if err := ValidateGenesis(bz); err != nil {
t.Errorf("valid genesis: %v", err)
}
// Duplicate pool-id.
dupPool := DefaultGenesisState()
dupPool.Pools = []CoverPool{
{PoolID: "dup", HostReachID: "h1", Categories: []CoverCategory{CatTravel}, ReserveAnnualContribRatio: 1.5, ReserveAccount: "a"},
{PoolID: "dup", HostReachID: "h2", Categories: []CoverCategory{CatTravel}, ReserveAnnualContribRatio: 1.5, ReserveAccount: "b"},
}
bz, _ = json.Marshal(dupPool)
if err := ValidateGenesis(bz); err == nil {
t.Error("genesis with duplicate pool-id should fail")
}
// Duplicate call-id.
dupCall := DefaultGenesisState()
dupCall.Calls = []CoverCall{
{CallID: "dup", PoolID: "p1", ClaimantReachID: "u1", Category: CatTravel, AmountGrain: 1},
{CallID: "dup", PoolID: "p1", ClaimantReachID: "u2", Category: CatTravel, AmountGrain: 2},
}
bz, _ = json.Marshal(dupCall)
if err := ValidateGenesis(bz); err == nil {
t.Error("genesis with duplicate call-id should fail")
}
// Invalid params (gate below minimum).
badParams := DefaultGenesisState()
badParams.Params = Params{FactoryAllowedPhases: []CoverCategoryPhase{Phase2}, PoolStandingGate: 3.0}
bz, _ = json.Marshal(badParams)
if err := ValidateGenesis(bz); err == nil {
t.Error("genesis with PoolStandingGate below minimum should fail")
}
// Invalid JSON.
if err := ValidateGenesis(json.RawMessage([]byte("not-json"))); err == nil {
t.Error("invalid JSON genesis should fail")
}
}
// --- Lexicon assertion (REQ-012, D-088) -------------------------------------
//
// TestLexiconNoBannedTermsInCover scans every .go file under x/cover/ for
// BOTH the 10 project-wide banned terms (lexicon.FindBannedTerm) AND the 4
// Cover-specific banned terms (lexicon.FindCoverBannedTerm). Production +
// test files are scanned. This file is excluded from its own scan (it
// references the banned terms via the lexicon package helpers, whose source
// assembles terms from fragments, so no banned-term literal appears in the
// firewall's own code).
//
// G-024: this test stays stdlib + lexicon-only (no cosmos-sdk import).
func coverRoot(t *testing.T) string {
t.Helper()
_, file, _, ok := runtime.Caller(0)
if !ok {
t.Fatal("runtime.Caller failed")
}
// file = .../oy/x/cover/types/types_test.go -> x/cover/ = filepath.Dir(filepath.Dir(file))
return filepath.Dir(filepath.Dir(file))
}
func thisFile(t *testing.T) string {
t.Helper()
_, file, _, ok := runtime.Caller(0)
if !ok {
t.Fatal("runtime.Caller failed")
}
return file
}
// TestLexiconNoBannedTermsInCover is the per-package lexicon firewall for
// x/cover (REQ-012 project-wide + D-088 Cover-specific). It walks every
// .go file under x/cover/ and asserts no banned term (project-wide OR
// Cover-specific) is present (word-boundary, case-insensitive). This file
// is excluded (self-exclusion via runtime.Caller(0)).
func TestLexiconNoBannedTermsInCover(t *testing.T) {
root := coverRoot(t)
this := thisFile(t)
hits := []string{}
err := filepath.Walk(root, func(path string, info os.FileInfo, err error) error {
if err != nil {
return err
}
if info.IsDir() {
// Skip the lexicon_meta_cover walk-coverage fixture dir
// (G-013): TestLexiconMetaCoverWalkCoverage creates
// x/cover/.lexicon_fixture/ with synthetic banned-term .go
// files. Those fixtures are test artifacts, NOT production
// code; skip the dir to avoid a cross-package test-isolation
// race (the fixture is created + cleaned up by the
// lexicon_meta_cover package, which runs concurrently with
// this package).
if info.Name() == ".lexicon_fixture" {
return filepath.SkipDir
}
return nil
}
if !strings.HasSuffix(path, ".go") {
return nil
}
// Self-exclusion: skip this test file (it references banned terms
// via the lexicon helpers).
if path == this {
return nil
}
bz, rerr := os.ReadFile(path)
if rerr != nil {
return rerr
}
src := string(bz)
// Project-wide 10 terms.
if found, ok := lexicon.FindBannedTerm(src); ok {
rel, _ := filepath.Rel(root, path)
hits = append(hits, rel+" contains project-wide banned term "+found)
}
// Cover-specific 4 terms.
if found, ok := lexicon.FindCoverBannedTerm(src); ok {
rel, _ := filepath.Rel(root, path)
hits = append(hits, rel+" contains Cover-specific banned term "+found)
}
return nil
})
if err != nil {
t.Fatalf("walk: %v", err)
}
if len(hits) > 0 {
t.Errorf("REQ-012/D-088 lexicon firewall violations in x/cover:\n %s",
strings.Join(hits, "\n "))
}
}
// --- GenesisState proto.Message methods --------------------------------------
// TestGenesisStateProtoMessage asserts the GenesisState Reset/String/ProtoMessage
// methods behave (codec.JSONCodec requires proto.Message).
func TestGenesisStateProtoMessage(t *testing.T) {
m := &GenesisState{Pools: []CoverPool{{PoolID: "p"}}, Calls: []CoverCall{{CallID: "c"}}}
s := m.String()
if !strings.Contains(s, "Pools:1") || !strings.Contains(s, "Calls:1") {
t.Errorf("GenesisState String = %q, want Pools:1 + Calls:1", s)
}
m.Reset()
if len(m.Pools) != 0 || len(m.Calls) != 0 {
t.Errorf("GenesisState Reset did not zero: Pools=%d Calls=%d", len(m.Pools), len(m.Calls))
}
m.ProtoMessage() // no-op, just cover
}
// --- P2 consts (REQ-052, REQ-062, REQ-048, D-086) ----------------------------
// TestP2LockedConsts asserts the P2 locked consts hold their locked values
// (REQ-052 cooling, REQ-062 council max + vote options, REQ-048 reserve
// ceiling age). A regression here is a mission-lock breach.
func TestP2LockedConsts(t *testing.T) {
// REQ-052: 7-day Charter amendment cooling.
if CharterAmendmentCoolingSeconds != 7*24*60*60 {
t.Errorf("CharterAmendmentCoolingSeconds = %d, want %d (REQ-052 7-day cooling)", CharterAmendmentCoolingSeconds, 7*24*60*60)
}
// REQ-048: 12-month operating history for reserve ceiling escalation.
if ReserveCeilingAgeSeconds != 365*24*60*60 {
t.Errorf("ReserveCeilingAgeSeconds = %d, want %d (REQ-048 12-month age check)", ReserveCeilingAgeSeconds, 365*24*60*60)
}
// REQ-062: Pool Council max 3 Masons.
if PoolCouncilMaxMasons != 3 {
t.Errorf("PoolCouncilMaxMasons = %d, want 3 (REQ-062)", PoolCouncilMaxMasons)
}
// REQ-062: CallVoteOption enum count = 3.
if CallVoteOptionCount != 3 {
t.Errorf("CallVoteOptionCount = %d, want 3 (REQ-062)", CallVoteOptionCount)
}
if len(AllCallVoteOptions()) != 3 {
t.Errorf("len(AllCallVoteOptions()) = %d, want 3 (REQ-062)", len(AllCallVoteOptions()))
}
}
// TestCallVoteOptionValues asserts the three CallVoteOption string values
// (a regression on the string value would break serialized state).
func TestCallVoteOptionValues(t *testing.T) {
cases := []struct {
opt CallVoteOption
want string
}{
{CallVoteYes, "Yes"},
{CallVoteNo, "No"},
{CallVoteAbstain, "Abstain"},
}
for _, c := range cases {
if string(c.opt) != c.want {
t.Errorf("CallVoteOption(%q) value = %q, want %q", c.opt, c.opt, c.want)
}
}
}
// TestCharterAmendmentStatusValues asserts the three CharterAmendmentStatus
// string values (Proposed/Cooled/Ratified).
func TestCharterAmendmentStatusValues(t *testing.T) {
if string(AmendmentProposed) != "Proposed" {
t.Errorf("AmendmentProposed = %q, want Proposed", AmendmentProposed)
}
if string(AmendmentCooled) != "Cooled" {
t.Errorf("AmendmentCooled = %q, want Cooled", AmendmentCooled)
}
if string(AmendmentRatified) != "Ratified" {
t.Errorf("AmendmentRatified = %q, want Ratified", AmendmentRatified)
}
}
// TestP2StructConstruction exercises the P2 struct construction (CoverCharter,
// CharterAmendment, PoolCouncil, CoverCallVote) for coverage on the
// zero-method paths.
func TestP2StructConstruction(t *testing.T) {
c := CoverCharter{
CharterID: "c1", PoolID: "p1", HostReachID: "h1", DisputePath: "dp",
Gate: "Trusted", HoldingPeriodDays: 30,
StatementOfBeliefsHash: []byte{1, 2, 3},
WatcherWitnessHash: []byte{4, 5, 6},
Amendments: []CharterAmendment{{AmendmentID: "a1", Status: AmendmentProposed}},
WaivedRights: []RightID{},
}
if c.CharterID != "c1" {
t.Errorf("CoverCharter CharterID = %q", c.CharterID)
}
a := CharterAmendment{AmendmentID: "a1", Description: "d", Status: AmendmentProposed, ProposedAt: 1000}
if a.AmendmentID != "a1" {
t.Errorf("CharterAmendment AmendmentID = %q", a.AmendmentID)
}
pc := PoolCouncil{PoolID: "p1", HostReachID: "h1", ElectedMasonReachIDs: [3]string{"m1", "m2", "m3"}, WatcherObserverReachID: "w1"}
if pc.ElectedMasonReachIDs[0] != "m1" {
t.Errorf("PoolCouncil ElectedMasonReachIDs[0] = %q", pc.ElectedMasonReachIDs[0])
}
v := CoverCallVote{VoteID: "v1", CallID: "c1", PoolID: "p1", VoterReachID: "v1", VoteOption: CallVoteYes, WatcherObserverPresent: true, VotedAt: 1000}
if v.VoteID != "v1" {
t.Errorf("CoverCallVote VoteID = %q", v.VoteID)
}
// CoverPool P2 fields.
p := CoverPool{PoolID: "p1", CharterRef: "c1", CouncilRef: "p1"}
if p.CharterRef != "c1" || p.CouncilRef != "p1" {
t.Errorf("CoverPool P2 refs = %q/%q", p.CharterRef, p.CouncilRef)
}
}
+275
View File
@@ -0,0 +1,275 @@
package keeper
// keeper.go holds the store-backed Keeper for the guild module's Guild
// Charter + Chapter Federation + Household + Confederation runtime (P3,
// REQ-051, REQ-053, REQ-057, REQ-058).
//
// The Keeper wraps an sdk.KVStore via a storeKey. It holds:
// - the Guild records (guild-id -> Guild; both Parent Guilds and Chapters
// are stored here — a Chapter is a Guild with IsChapter=true);
// - the Lien records (guild-id + lien-idx -> Lien; the AddLien handler
// appends here with SecuredAtFounding=false; founding-locked liens
// (SecuredAtFounding=true) are stored on the Guild itself at creation);
// - the Confederation Voice delegation records
// (confederation-stand-id + member-stand-id -> ConfederationVoice).
//
// The Keeper also holds the two expected-keeper shims (StandKeeper for the
// Household/Confederation type check; StashKeeper for the asset return on
// Household one-tap exit). The shims are interfaces (G-003 — no struct
// import of x/stand/types or x/stash/types); the concrete keepers (or
// simtest stubs) satisfy them structurally.
//
// State-machine ordering (vision §7, enforced in every handler):
// ValidateBasic -> handler authz/gate -> state mutation -> ctx.EventManager().EmitEvent
import (
"encoding/json"
"fmt"
storetypes "cosmossdk.io/store/types"
"github.com/cosmos/cosmos-sdk/codec"
sdk "github.com/cosmos/cosmos-sdk/types"
"github.com/oy/openyield/x/guild/types"
)
// Keeper is the store-backed guild Keeper.
type Keeper struct {
cdc codec.Codec
storeKey storetypes.StoreKey
standKeeper types.StandKeeper
stashKeeper types.StashKeeper
paramsHolder types.Params
}
// NewKeeper constructs a new store-backed guild Keeper. The StandKeeper +
// StashKeeper expected-keeper shims are injected (StandKeeper is nil-able
// for partial wiring — the OneTapExitStand + DelegateConfederationVoice
// handlers REJECT on a nil StandKeeper (the type check is load-bearing);
// StashKeeper is nil-able — a nil StashKeeper skips the asset return on
// one-tap exit (simtest wiring)).
func NewKeeper(cdc codec.Codec, storeKey storetypes.StoreKey, sk types.StandKeeper, stashK types.StashKeeper) Keeper {
return Keeper{
cdc: cdc,
storeKey: storeKey,
standKeeper: sk,
stashKeeper: stashK,
paramsHolder: types.DefaultParams(),
}
}
// SetStandKeeper sets the StandKeeper expected-keeper shim (for
// post-construction wiring, e.g., app wiring or test setup).
func (k *Keeper) SetStandKeeper(sk types.StandKeeper) { k.standKeeper = sk }
// SetStashKeeper sets the StashKeeper expected-keeper shim.
func (k *Keeper) SetStashKeeper(stashK types.StashKeeper) { k.stashKeeper = stashK }
// SetParams sets the Params (simtest-grade override; a future version will
// load from the params store).
func (k *Keeper) SetParams(p types.Params) { k.paramsHolder = p }
// Params returns the effective Params.
func (k Keeper) Params() types.Params { return k.paramsHolder }
// StoreKey returns the keeper's store key (exported for simtest access to
// the underlying KVStore, e.g., to inject corrupt bytes for marshal-error
// coverage). Mirrors the x/cover simtest pattern.
func (k Keeper) StoreKey() storetypes.StoreKey { return k.storeKey }
// --- Guild store --------------------------------------------------------------
var guildKeyPrefix = []byte("guild/")
func guildKey(guildID string) []byte {
return append(guildKeyPrefix, []byte(guildID)...)
}
// GetGuild loads a Guild by guild-id. Returns the Guild and true if found,
// or zero value + false if not. Both Parent Guilds and Chapters are stored
// here (a Chapter is a Guild with IsChapter=true).
func (k Keeper) GetGuild(ctx sdk.Context, guildID string) (types.Guild, bool) {
store := ctx.KVStore(k.storeKey)
bz := store.Get(guildKey(guildID))
if bz == nil {
return types.Guild{}, false
}
var g types.Guild
if err := json.Unmarshal(bz, &g); err != nil {
return types.Guild{}, false
}
return g, true
}
// SetGuild persists a Guild by guild-id.
func (k Keeper) SetGuild(ctx sdk.Context, g types.Guild) {
store := ctx.KVStore(k.storeKey)
bz, err := json.Marshal(g)
if err != nil {
panic(fmt.Sprintf("guild: marshal guild %q: %v", g.GuildID, err))
}
store.Set(guildKey(g.GuildID), bz)
}
// AllGuilds returns all persisted Guild records (iteration helper,
// unordered). Both Parent Guilds and Chapters are returned.
func (k Keeper) AllGuilds(ctx sdk.Context) []types.Guild {
store := ctx.KVStore(k.storeKey)
iterator := store.Iterator(guildKeyPrefix, prefixEnd(guildKeyPrefix))
defer iterator.Close()
out := []types.Guild{}
for ; iterator.Valid(); iterator.Next() {
var g types.Guild
if err := json.Unmarshal(iterator.Value(), &g); err == nil {
out = append(out, g)
}
}
return out
}
// --- Lien store ---------------------------------------------------------------
//
// The Lien store is keyed by guild-id + lien-idx. The AddLien handler
// appends here with SecuredAtFounding=false. Founding-locked liens
// (SecuredAtFounding=true) are stored on the Guild itself at creation
// (GoodStandingLiens slice); the AddLien handler rejects any new
// SecuredAtFounding=true lien (founding is a one-time event — REQ-053).
var lienKeyPrefix = []byte("lien/")
func lienKey(guildID string, idx uint32) []byte {
return append(lienKeyPrefix, []byte(fmt.Sprintf("%s/%d", guildID, idx))...)
}
// GetLien loads a Lien by guild-id + lien-idx. Returns the Lien and true if
// found, or zero value + false if not.
func (k Keeper) GetLien(ctx sdk.Context, guildID string, idx uint32) (types.Lien, bool) {
store := ctx.KVStore(k.storeKey)
bz := store.Get(lienKey(guildID, idx))
if bz == nil {
return types.Lien{}, false
}
var l types.Lien
if err := json.Unmarshal(bz, &l); err != nil {
return types.Lien{}, false
}
return l, true
}
// SetLien persists a Lien by guild-id + lien-idx.
func (k Keeper) SetLien(ctx sdk.Context, guildID string, idx uint32, l types.Lien) {
store := ctx.KVStore(k.storeKey)
bz, err := json.Marshal(l)
if err != nil {
panic(fmt.Sprintf("guild: marshal lien %s/%d: %v", guildID, idx, err))
}
store.Set(lienKey(guildID, idx), bz)
}
// AllLiens returns all persisted Lien records for a guild (iteration helper,
// unordered — the idx ordering is NOT preserved across iterations; the
// simtest asserts count + content, not order).
func (k Keeper) AllLiens(ctx sdk.Context, guildID string) []types.Lien {
prefix := append(lienKeyPrefix, []byte(guildID+"/")...)
store := ctx.KVStore(k.storeKey)
iterator := store.Iterator(prefix, prefixEnd(prefix))
defer iterator.Close()
out := []types.Lien{}
for ; iterator.Valid(); iterator.Next() {
var l types.Lien
if err := json.Unmarshal(iterator.Value(), &l); err == nil {
out = append(out, l)
}
}
return out
}
// NextLienIdx returns the next lien-idx for a guild (the count of existing
// liens — the AddLien handler uses this to assign the new lien's idx). The
// founding-locked liens on the Guild's GoodStandingLiens slice do NOT
// consume an idx in this store (they are stored on the Guild itself); only
// post-founding liens (SecuredAtFounding=false) added via AddLien consume an
// idx here.
func (k Keeper) NextLienIdx(ctx sdk.Context, guildID string) uint32 {
return uint32(len(k.AllLiens(ctx, guildID)))
}
// --- Confederation Voice delegation store --------------------------------------
//
// The delegation store is keyed by confederation-stand-id + member-stand-id.
// The DelegateConfederationVoice handler records one delegation per member
// Stand (a duplicate delegation from the same MemberStandID is REJECTED).
// One-Stand-one-Vote: each member Stand gets exactly 1 Voice in the
// Confederation's aggregate, regardless of size.
var delegationKeyPrefix = []byte("delegation/")
func delegationKey(confederationStandID, memberStandID string) []byte {
return append(delegationKeyPrefix, []byte(fmt.Sprintf("%s/%s", confederationStandID, memberStandID))...)
}
// GetDelegation loads a ConfederationVoice delegation by confederation-stand-id
// + member-stand-id. Returns the ConfederationVoice (from x/guild/types) and
// true if found, or zero value + false if not.
func (k Keeper) GetDelegation(ctx sdk.Context, confederationStandID, memberStandID string) (types.ConfederationVoice, bool) {
store := ctx.KVStore(k.storeKey)
bz := store.Get(delegationKey(confederationStandID, memberStandID))
if bz == nil {
return types.ConfederationVoice{}, false
}
var v types.ConfederationVoice
if err := json.Unmarshal(bz, &v); err != nil {
return types.ConfederationVoice{}, false
}
return v, true
}
// SetDelegation persists a ConfederationVoice delegation by confederation-
// stand-id + member-stand-id.
func (k Keeper) SetDelegation(ctx sdk.Context, v types.ConfederationVoice) {
store := ctx.KVStore(k.storeKey)
bz, err := json.Marshal(v)
if err != nil {
panic(fmt.Sprintf("guild: marshal delegation %s/%s: %v", v.ConfederationStandID, v.MemberStandID, err))
}
store.Set(delegationKey(v.ConfederationStandID, v.MemberStandID), bz)
}
// AllDelegations returns all persisted ConfederationVoice delegations for a
// Confederation Stand (iteration helper, unordered).
func (k Keeper) AllDelegations(ctx sdk.Context, confederationStandID string) []types.ConfederationVoice {
prefix := append(delegationKeyPrefix, []byte(confederationStandID+"/")...)
store := ctx.KVStore(k.storeKey)
iterator := store.Iterator(prefix, prefixEnd(prefix))
defer iterator.Close()
out := []types.ConfederationVoice{}
for ; iterator.Valid(); iterator.Next() {
var v types.ConfederationVoice
if err := json.Unmarshal(iterator.Value(), &v); err == nil {
out = append(out, v)
}
}
return out
}
// --- prefixEnd helper ---------------------------------------------------------
// prefixEnd returns the key that sorts immediately after all keys sharing
// the given prefix (the standard prefix-iteration end key: increment the
// last byte, drop overflow). Used for store.Iterator(start, prefixEnd(start))
// prefix scans. Mirrors x/hub/keeper/keeper.go + x/cover/keeper/keeper.go.
func prefixEnd(prefix []byte) []byte {
if len(prefix) == 0 {
return nil
}
end := make([]byte, len(prefix))
copy(end, prefix)
for i := len(end) - 1; i >= 0; i-- {
end[i]++
if end[i] != 0 {
return end
}
}
// All bytes were 0xFF; return nil (iterate to end of store).
return nil
}
+333
View File
@@ -0,0 +1,333 @@
package keeper
// msg_server.go implements the guild module's MsgServer (P3, REQ-051,
// REQ-053, REQ-057, REQ-058, REQ-061). The MsgServer wraps the Keeper + the
// StandKeeper + StashKeeper expected-keeper shims (already on the Keeper).
//
// Each method returns a (*Response, error). Handler state-machine ordering
// is enforced: ValidateBasic -> handler authz/gate -> state mutation ->
// ctx.EventManager().EmitEvent.
//
// Handler set:
// - CreateGuild (REQ-051): validate, idempotency, persist Guild with
// CommonBondHash + PublicProfile, surface a jurisdictional disclaimer
// (REQ-061).
// - CreateChapter (REQ-053): validate, idempotency, load Parent Guild,
// pin SecessionTermsHash, set IsChapter=true + ParentGuildID, record
// GoodStandingLiens (SecuredAtFounding=true), reject cooling below the
// protocol minimum, persist, surface a disclaimer (REQ-061).
// - OneTapExitStand (REQ-057): validate, assert Stand type is Household
// via StandKeeper shim (nil REJECTS), dissolve the Stand + return assets
// to the Holder's Stash via StashKeeper shim (nil skips the return,
// still emits the dissolution event), emit event.
// - DelegateConfederationVoice (REQ-058): validate, assert Confederation
// Stand type via StandKeeper shim, record one delegation per member
// Stand (duplicate REJECTED), emit event.
// - AddLien (REQ-053): validate, load Guild, REJECT any new
// SecuredAtFounding=true lien (founding is one-time — REQ-053/REQ-081),
// persist the lien, emit event.
//
// Nil-shim behavior (simtest wiring): a nil StandKeeper REJECTS the
// OneTapExitStand + DelegateConfederationVoice handlers (the Household /
// Confederation type check is load-bearing — it cannot be skipped). A nil
// StashKeeper skips the asset return on one-tap exit (the handler still
// emits the dissolution event — the asset return is a side-effect the
// simtest stub records).
import (
"fmt"
sdk "github.com/cosmos/cosmos-sdk/types"
"github.com/oy/openyield/x/guild/types"
)
// DisclaimerJurisdictional is the jurisdictional disclaimer surfaced at
// every charter signing (REQ-061). NOT session-bounded — surfaced at every
// CreateGuild + CreateChapter. The disclaimer is a fixed string (the live
// jurisdictional overlay lands in a later phase; the simtest asserts the
// Disclaimer field is non-empty).
const DisclaimerJurisdictional = "OpenYield Guilds are self-governed mesh collectives; the protocol does not provide legal, tax, or fiduciary advice. Signers affirm they have reviewed the Common Bond + jurisdictional obligations before signing."
// msgServer is the concrete MsgServer implementation wrapping the Keeper.
type msgServer struct {
Keeper
}
// NewMsgServerImpl returns the guild MsgServer for the provided Keeper.
func NewMsgServerImpl(k Keeper) types.MsgServer {
return &msgServer{Keeper: k}
}
var _ types.MsgServer = msgServer{}
// unwrapCtx extracts the sdk.Context from the interface-typed ctx.
func unwrapCtx(ctx interface{}) sdk.Context {
if c, ok := ctx.(sdk.Context); ok {
return c
}
panic(fmt.Sprintf("guild: expected sdk.Context, got %T", ctx))
}
// --- CreateGuild (REQ-051, REQ-061) -------------------------------------------
// CreateGuild creates a Guild with a Common Bond hash + Public Profile
// (REQ-051). The handler enforces:
// 1. ValidateBasic (stateless — non-empty fields + non-empty
// CommonBondHash).
// 2. Idempotency: guild-id must not already exist.
// 3. Persist the Guild with CommonBondHash + PublicProfile (the Common
// Bond is hash-pinned at creation — immutable; the handler does NOT
// store the bond text, only the hash).
// 4. Surface a jurisdictional disclaimer (REQ-061) in the response.
//
// On success the Guild is persisted and an event is emitted.
func (s msgServer) CreateGuild(ctx interface{}, msg *types.MsgCreateGuild) (*types.MsgCreateGuildResponse, error) {
if err := msg.ValidateBasic(); err != nil {
return nil, err
}
sdkCtx := unwrapCtx(ctx)
// Idempotency: guild-id must not already exist.
if _, ok := s.Keeper.GetGuild(sdkCtx, msg.GuildID); ok {
return nil, fmt.Errorf("guild: guild %q already exists", msg.GuildID)
}
g := types.Guild{
GuildID: msg.GuildID,
Name: msg.Name,
FounderReach: msg.FounderReach,
CreatedAt: sdkCtx.BlockTime().Unix(),
StandAffiliationID: msg.StandAffiliationID,
CommonBondHash: msg.CommonBondHash,
PublicProfile: msg.PublicProfile,
IsChapter: false,
ParentGuildID: "",
}
s.Keeper.SetGuild(sdkCtx, g)
sdkCtx.EventManager().EmitEvent(sdk.NewEvent(
"guild.guild_created",
sdk.NewAttribute("guild_id", msg.GuildID),
sdk.NewAttribute("founder_reach", msg.FounderReach),
))
return &types.MsgCreateGuildResponse{Disclaimer: DisclaimerJurisdictional}, nil
}
// --- CreateChapter (REQ-053, REQ-061) -----------------------------------------
// CreateChapter creates a Chapter under a Parent Guild (REQ-053). The
// handler enforces:
// 1. ValidateBasic (stateless — non-empty fields, SecessionTerms valid +
// protocol-minimum-bounded, each GoodStandingLien is SecuredAtFounding).
// 2. Idempotency: chapter guild-id must not already exist.
// 3. Load the Parent Guild (must exist; must NOT itself be a Chapter — a
// Chapter cannot have a Chapter parent).
// 4. Pin the SecessionTerms hash (HashSecessionTerms — immutable; no
// handler to amend it).
// 5. Set IsChapter=true + ParentGuildID + GoodStandingLiens (each with
// SecuredAtFounding=true — ValidateBasic already enforced this).
// 6. Persist the Chapter.
// 7. Surface a jurisdictional disclaimer (REQ-061) in the response.
//
// On success the Chapter is persisted and an event is emitted.
func (s msgServer) CreateChapter(ctx interface{}, msg *types.MsgCreateChapter) (*types.MsgCreateChapterResponse, error) {
if err := msg.ValidateBasic(); err != nil {
return nil, err
}
sdkCtx := unwrapCtx(ctx)
// Idempotency: chapter guild-id must not already exist.
if _, ok := s.Keeper.GetGuild(sdkCtx, msg.GuildID); ok {
return nil, fmt.Errorf("guild: chapter %q already exists", msg.GuildID)
}
// Load the Parent Guild (must exist; must NOT itself be a Chapter).
parent, ok := s.Keeper.GetGuild(sdkCtx, msg.ParentGuildID)
if !ok {
return nil, fmt.Errorf("guild: parent guild %q not found (REQ-053)", msg.ParentGuildID)
}
if parent.IsChapter {
return nil, fmt.Errorf("guild: parent %q is itself a Chapter (a Chapter cannot have a Chapter parent — REQ-053)", msg.ParentGuildID)
}
// Pin the SecessionTerms hash (immutable — no handler to amend it).
termsHash := types.HashSecessionTerms(msg.SecessionTerms)
// GoodStandingLiens are recorded with SecuredAtFounding=true
// (ValidateBasic already enforced this — founding-locked liens).
liens := make([]types.Lien, len(msg.GoodStandingLiens))
copy(liens, msg.GoodStandingLiens)
chapter := types.Guild{
GuildID: msg.GuildID,
Name: msg.Name,
FounderReach: msg.FounderReach,
CreatedAt: sdkCtx.BlockTime().Unix(),
CommonBondHash: parent.CommonBondHash, // a Chapter inherits the Parent's Common Bond hash
PublicProfile: parent.PublicProfile, // a Chapter inherits the Parent's Public Profile
IsChapter: true,
ParentGuildID: msg.ParentGuildID,
SecessionTermsHash: termsHash,
GoodStandingLiens: liens,
}
s.Keeper.SetGuild(sdkCtx, chapter)
sdkCtx.EventManager().EmitEvent(sdk.NewEvent(
"guild.chapter_created",
sdk.NewAttribute("guild_id", msg.GuildID),
sdk.NewAttribute("parent_guild_id", msg.ParentGuildID),
))
return &types.MsgCreateChapterResponse{Disclaimer: DisclaimerJurisdictional}, nil
}
// --- OneTapExitStand (REQ-057) ------------------------------------------------
// OneTapExitStand one-tap exits a Household Stand (REQ-057). The handler
// enforces:
// 1. ValidateBasic (stateless).
// 2. StandKeeper shim must be non-nil (the Household type check is
// load-bearing — a nil shim is a wiring error, REJECTED).
// 3. The Stand must exist + its type must be "Household" (one-tap exit is
// Household-only — a Crew / Entity / etc. Stand is REJECTED).
// 4. StashKeeper shim: if non-nil, call ReturnAssetsToHolder to return the
// dissolved Stand's assets to the Holder's Stash (a nil shim skips the
// return — simtest wiring; the dissolution event is still emitted). A
// non-nil error from ReturnAssetsToHolder REJECTS the dissolution (the
// asset return is load-bearing — a failed return leaves the Stand
// intact).
// 5. Emit the dissolution event.
//
// The signer is treated as the Holder (the Reach the assets are returned
// to). The live authz (signer must be the Stand's admin-reach) is deferred
// (simtest grade).
func (s msgServer) OneTapExitStand(ctx interface{}, msg *types.MsgOneTapExitStand) (*types.MsgOneTapExitStandResponse, error) {
if err := msg.ValidateBasic(); err != nil {
return nil, err
}
sdkCtx := unwrapCtx(ctx)
// StandKeeper shim must be non-nil (the type check is load-bearing).
if s.Keeper.standKeeper == nil {
return nil, fmt.Errorf("guild: StandKeeper not wired (OneTapExitStand rejected — Household type check is load-bearing)")
}
// The Stand must exist + be a Household (one-tap exit is Household-only).
standType, exists := s.Keeper.standKeeper.GetStand(msg.StandID)
if !exists {
return nil, fmt.Errorf("guild: stand %q not found (OneTapExitStand rejected)", msg.StandID)
}
if standType != "Household" {
return nil, fmt.Errorf("guild: stand %q type %q is not a Household (one-tap exit is Household-only — REQ-057)", msg.StandID, standType)
}
// StashKeeper: return the dissolved Stand's assets to the Holder's Stash.
// A nil shim skips the return (simtest wiring); a non-nil error REJECTS
// (the asset return is load-bearing).
if s.Keeper.stashKeeper != nil {
if err := s.Keeper.stashKeeper.ReturnAssetsToHolder(msg.Signer, msg.StandID); err != nil {
return nil, fmt.Errorf("guild: return assets to holder %q for stand %q: %w", msg.Signer, msg.StandID, err)
}
}
sdkCtx.EventManager().EmitEvent(sdk.NewEvent(
"guild.one_tap_exit",
sdk.NewAttribute("stand_id", msg.StandID),
sdk.NewAttribute("holder_reach", msg.Signer),
))
return &types.MsgOneTapExitStandResponse{}, nil
}
// --- DelegateConfederationVoice (REQ-058) -------------------------------------
// DelegateConfederationVoice delegates a member Stand's Voice in a
// Confederation (REQ-058). The handler enforces:
// 1. ValidateBasic (stateless).
// 2. StandKeeper shim must be non-nil (the Confederation type check is
// load-bearing — a nil shim is a wiring error, REJECTED).
// 3. The Confederation Stand must exist + its type must be "Confederation".
// 4. One delegation per member Stand: a duplicate delegation from the same
// MemberStandID is REJECTED (one-Stand-one-Vote — each member Stand gets
// exactly 1 Voice in the Confederation's aggregate, regardless of size).
// 5. Persist the delegation + emit the event.
func (s msgServer) DelegateConfederationVoice(ctx interface{}, msg *types.MsgDelegateConfederationVoice) (*types.MsgDelegateConfederationVoiceResponse, error) {
if err := msg.ValidateBasic(); err != nil {
return nil, err
}
sdkCtx := unwrapCtx(ctx)
// StandKeeper shim must be non-nil (the type check is load-bearing).
if s.Keeper.standKeeper == nil {
return nil, fmt.Errorf("guild: StandKeeper not wired (DelegateConfederationVoice rejected — Confederation type check is load-bearing)")
}
// The Confederation Stand must exist + be a Confederation.
standType, exists := s.Keeper.standKeeper.GetStand(msg.ConfederationStandID)
if !exists {
return nil, fmt.Errorf("guild: confederation stand %q not found", msg.ConfederationStandID)
}
if standType != "Confederation" {
return nil, fmt.Errorf("guild: stand %q type %q is not a Confederation (REQ-058)", msg.ConfederationStandID, standType)
}
// One delegation per member Stand: a duplicate is REJECTED.
if _, ok := s.Keeper.GetDelegation(sdkCtx, msg.ConfederationStandID, msg.MemberStandID); ok {
return nil, fmt.Errorf("guild: member stand %q already delegates in confederation %q (one-Stand-one-Vote — duplicate REJECTED — REQ-058)", msg.MemberStandID, msg.ConfederationStandID)
}
v := types.ConfederationVoice{
ConfederationStandID: msg.ConfederationStandID,
MemberStandID: msg.MemberStandID,
DelegateReachID: msg.DelegateReachID,
DelegatedAt: sdkCtx.BlockTime().Unix(),
}
s.Keeper.SetDelegation(sdkCtx, v)
sdkCtx.EventManager().EmitEvent(sdk.NewEvent(
"guild.confederation_voice_delegated",
sdk.NewAttribute("confederation_stand_id", msg.ConfederationStandID),
sdk.NewAttribute("member_stand_id", msg.MemberStandID),
sdk.NewAttribute("delegate_reach_id", msg.DelegateReachID),
))
return &types.MsgDelegateConfederationVoiceResponse{}, nil
}
// --- AddLien (REQ-053) --------------------------------------------------------
// AddLien adds a Good-Standing Lien to a Guild (REQ-053). The handler
// enforces:
// 1. ValidateBasic (stateless — non-empty fields, Lien Amount > 0).
// 2. The Guild must exist.
// 3. REJECT any new SecuredAtFounding=true lien (founding is a one-time
// event — REQ-053/REQ-081; post-founding liens added via AddLien MUST
// be SecuredAtFounding=false).
// 4. Persist the lien (assigned the next lien-idx) + emit the event.
func (s msgServer) AddLien(ctx interface{}, msg *types.MsgAddLien) (*types.MsgAddLienResponse, error) {
if err := msg.ValidateBasic(); err != nil {
return nil, err
}
sdkCtx := unwrapCtx(ctx)
// The Guild must exist.
if _, ok := s.Keeper.GetGuild(sdkCtx, msg.GuildID); !ok {
return nil, fmt.Errorf("guild: guild %q not found (AddLien rejected)", msg.GuildID)
}
// REJECT any new SecuredAtFounding=true lien (founding is one-time —
// REQ-053/REQ-081).
if msg.Lien.SecuredAtFounding {
return nil, fmt.Errorf("guild: AddLien rejects SecuredAtFounding=true liens (founding is a one-time event — REQ-053/REQ-081; post-founding liens must be SecuredAtFounding=false)")
}
idx := s.Keeper.NextLienIdx(sdkCtx, msg.GuildID)
s.Keeper.SetLien(sdkCtx, msg.GuildID, idx, msg.Lien)
sdkCtx.EventManager().EmitEvent(sdk.NewEvent(
"guild.lien_added",
sdk.NewAttribute("guild_id", msg.GuildID),
sdk.NewAttribute("lien_idx", fmt.Sprintf("%d", idx)),
sdk.NewAttribute("creditor_reach_id", msg.Lien.CreditorReachID),
sdk.NewAttribute("amount", fmt.Sprintf("%d", msg.Lien.Amount)),
))
return &types.MsgAddLienResponse{}, nil
}
+978
View File
@@ -0,0 +1,978 @@
package keeper_test
// msg_server_simtest_test.go is the x/guild keeper simtest (P3, REQ-051,
// REQ-053, REQ-057, REQ-058, REQ-061).
//
// D-054: simtest-grade — in-memory sdk.Context + dbm in-memory store, no
// real Stand keeper (the StandKeeper shim is a stub; G-003 test exemption),
// no real Stash keeper (the StashKeeper shim is a simtest-local stub that
// records ReturnAssetsToHolder calls for assertion). The simtest exercises:
//
// CreateGuild (REQ-051 + REQ-061 disclaimer):
// - (a) successful Guild creation with Common Bond hash + Public Profile
// (MasonCount disclosed).
// - (b) successful Guild creation with MasonCountPrivate=true (count not
// disclosed — MasonCount is 0).
// - idempotency: a second CreateGuild on the same guild-id is REJECTED.
// - (g) Disclaimer surfaced at every signing (the response Disclaimer is
// non-empty).
//
// CreateChapter (REQ-053 + REQ-061 disclaimer):
// - (c) successful Chapter creation with secession terms hash-pinned +
// good-standing liens (SecuredAtFounding=true).
// - (d) Chapter inherits Parent policy + tightens (longer cooling allowed)
// + loosens (shorter cooling REJECTED at ValidateBasic).
// - rejected on non-existent Parent Guild.
// - rejected when Parent is itself a Chapter.
// - (g) Disclaimer surfaced at every signing.
//
// OneTapExitStand (REQ-057):
// - (e) Household one-tap exit succeeds (Stand type Household + StandKeeper
// stub returns "Household" + StashKeeper stub records the call).
// - (e) Crew one-tap exit REJECTED (one-tap is Household-only).
// - rejected on non-existent Stand.
// - rejected on nil StandKeeper (the type check is load-bearing).
//
// DelegateConfederationVoice (REQ-058):
// - (f) Confederation Voice delegation succeeds (one-per-Stand).
// - (f) duplicate delegation REJECTED (one-Stand-one-Vote).
// - rejected on non-Confederation Stand type.
// - rejected on nil StandKeeper.
//
// AddLien (REQ-053):
// - (h) post-founding lien with SecuredAtFounding=false succeeds.
// - (h) post-founding lien with SecuredAtFounding=true REJECTED (founding
// is one-time — REQ-053/REQ-081).
// - rejected on non-existent Guild.
//
// Coverage target: >=80% on x/guild/keeper.
import (
"strings"
"testing"
"time"
"cosmossdk.io/log"
"cosmossdk.io/store"
storetypes "cosmossdk.io/store/types"
cmtproto "github.com/cometbft/cometbft/proto/tendermint/types"
dbm "github.com/cosmos/cosmos-db"
"github.com/cosmos/cosmos-sdk/codec"
codectypes "github.com/cosmos/cosmos-sdk/codec/types"
sdk "github.com/cosmos/cosmos-sdk/types"
"github.com/oy/openyield/x/guild/keeper"
"github.com/oy/openyield/x/guild/types"
)
// --- Stub expected-keepers (G-003 test exemption) ---------------------------
// stubStandKeeper satisfies types.StandKeeper for the simtest. It returns a
// configurable stand-type per stand-id (a missing key returns ("", false) —
// the non-existent Stand case).
type stubStandKeeper struct {
stands map[string]string // stand-id -> stand-type
}
func (s *stubStandKeeper) GetStand(standID string) (string, bool) {
if s.stands == nil {
return "", false
}
t, ok := s.stands[standID]
return t, ok
}
// stubStashKeeper satisfies types.StashKeeper for the simtest. It records
// every ReturnAssetsToHolder call for assertion (the one-tap exit simtest
// asserts the call was made with the right holder + stand-id).
type stubStashKeeper struct {
calls []struct {
holderReachID string
standID string
}
err error
}
func (s *stubStashKeeper) ReturnAssetsToHolder(holderReachID string, standID string) error {
if s.err != nil {
return s.err
}
s.calls = append(s.calls, struct {
holderReachID string
standID string
}{holderReachID, standID})
return nil
}
// --- Simtest context helper --------------------------------------------------
// newSimtestContext constructs an in-memory sdk.Context with a KVStore
// mounted at the guild store key. Returns the ctx, the two stub keepers,
// the store key, and the Keeper.
func newSimtestContext(t *testing.T) (sdk.Context, *stubStandKeeper, *stubStashKeeper, storetypes.StoreKey, keeper.Keeper) {
t.Helper()
db := dbm.NewMemDB()
cdc := newTestCodec()
storeKey := storetypes.NewKVStoreKey(types.StoreKey)
cms := store.NewCommitMultiStore(db, log.NewNopLogger(), nil)
cms.MountStoreWithDB(storeKey, storetypes.StoreTypeDB, nil)
if err := cms.LoadLatestVersion(); err != nil {
t.Fatalf("load latest version: %v", err)
}
ctx := sdk.NewContext(cms, cmtproto.Header{Time: time.Unix(1000, 0)}, false, log.NewNopLogger())
sk := &stubStandKeeper{}
stashK := &stubStashKeeper{}
k := keeper.NewKeeper(cdc, storeKey, sk, stashK)
return ctx, sk, stashK, storeKey, k
}
// newSimtestContextNilStand constructs an in-memory ctx with a nil
// StandKeeper (for the nil-shim reject-path coverage).
func newSimtestContextNilStand(t *testing.T) (sdk.Context, storetypes.StoreKey, keeper.Keeper) {
t.Helper()
db := dbm.NewMemDB()
cdc := newTestCodec()
storeKey := storetypes.NewKVStoreKey(types.StoreKey)
cms := store.NewCommitMultiStore(db, log.NewNopLogger(), nil)
cms.MountStoreWithDB(storeKey, storetypes.StoreTypeDB, nil)
if err := cms.LoadLatestVersion(); err != nil {
t.Fatalf("load latest version: %v", err)
}
ctx := sdk.NewContext(cms, cmtproto.Header{Time: time.Unix(1000, 0)}, false, log.NewNopLogger())
k := keeper.NewKeeper(cdc, storeKey, nil, nil)
return ctx, storeKey, k
}
// newTestCodec constructs a minimal codec for the simtest.
func newTestCodec() codec.Codec {
registry := codectypes.NewInterfaceRegistry()
return codec.NewProtoCodec(registry)
}
// hasEvent reports whether ctx emitted an event of the given type.
func hasEvent(ctx sdk.Context, eventType string) bool {
for _, ev := range ctx.EventManager().Events() {
if ev.Type == eventType {
return true
}
}
return false
}
// validTerms returns SecessionTerms at the protocol minimums.
func validTerms() types.SecessionTerms {
return types.SecessionTerms{
CoolingCoverActiveDays: types.CoolingSecessionCoverActiveDays,
CoolingNonCoverDays: types.CoolingSecessionNonCoverDays,
LienAuditRequired: true,
CovenantClearanceRequired: true,
}
}
// createParentGuild is a helper that creates a Parent Guild for the Chapter
// simtest cases.
func createParentGuild(t *testing.T, srv types.MsgServer, ctx sdk.Context, guildID string) {
t.Helper()
_, err := srv.CreateGuild(ctx, &types.MsgCreateGuild{
GuildID: guildID,
Name: "Parent",
FounderReach: "reach:founder",
CommonBondHash: []byte{0xAA, 0xBB, 0xCC},
PublicProfile: types.GuildPublicProfile{
BondSummary: "bond-summary",
MasonCount: 10,
},
Signer: "reach:founder",
})
if err != nil {
t.Fatalf("createParentGuild %q: %v", guildID, err)
}
}
// --- CreateGuild (REQ-051, REQ-061) ------------------------------------------
// TestCreateGuildSuccess (case a) asserts a successful Guild creation with
// Common Bond hash + Public Profile (MasonCount disclosed).
func TestCreateGuildSuccess(t *testing.T) {
ctx, _, _, _, k := newSimtestContext(t)
srv := keeper.NewMsgServerImpl(k)
resp, err := srv.CreateGuild(ctx, &types.MsgCreateGuild{
GuildID: "g-1",
Name: "Task Guild",
FounderReach: "reach:founder",
CommonBondHash: []byte{1, 2, 3},
PublicProfile: types.GuildPublicProfile{
BondSummary: "a bond summary",
Disclaimers: []string{"d1"},
MasonCount: 42,
},
Signer: "reach:founder",
})
if err != nil {
t.Fatalf("CreateGuild: %v", err)
}
g, ok := k.GetGuild(ctx, "g-1")
if !ok {
t.Fatal("Guild not persisted")
}
if g.IsChapter {
t.Error("IsChapter should be false for a Parent Guild")
}
if g.ParentGuildID != "" {
t.Errorf("ParentGuildID = %q, want empty for a Parent Guild", g.ParentGuildID)
}
if len(g.CommonBondHash) != 3 {
t.Errorf("CommonBondHash = %v, want 3 bytes", g.CommonBondHash)
}
if g.PublicProfile.MasonCount != 42 {
t.Errorf("MasonCount = %d, want 42", g.PublicProfile.MasonCount)
}
if g.PublicProfile.MasonCountPrivate {
t.Error("MasonCountPrivate should be false when count is disclosed")
}
if !hasEvent(ctx, "guild.guild_created") {
t.Error("guild.guild_created event not emitted")
}
// (g) Disclaimer surfaced.
if resp.Disclaimer == "" {
t.Error("CreateGuild response Disclaimer is empty (REQ-061)")
}
}
// TestCreateGuildMasonCountPrivate (case b) asserts a Guild creation with
// MasonCountPrivate=true (count not disclosed — MasonCount is 0).
func TestCreateGuildMasonCountPrivate(t *testing.T) {
ctx, _, _, _, k := newSimtestContext(t)
srv := keeper.NewMsgServerImpl(k)
_, err := srv.CreateGuild(ctx, &types.MsgCreateGuild{
GuildID: "g-priv",
Name: "Private Count Guild",
FounderReach: "reach:f",
CommonBondHash: []byte{1},
PublicProfile: types.GuildPublicProfile{
BondSummary: "private count",
MasonCount: 0,
MasonCountPrivate: true,
},
Signer: "reach:f",
})
if err != nil {
t.Fatalf("CreateGuild: %v", err)
}
g, _ := k.GetGuild(ctx, "g-priv")
if !g.PublicProfile.MasonCountPrivate {
t.Error("MasonCountPrivate should be true")
}
if g.PublicProfile.MasonCount != 0 {
t.Errorf("MasonCount = %d, want 0 (not disclosed)", g.PublicProfile.MasonCount)
}
}
// TestCreateGuildIdempotentReject asserts a second CreateGuild on the same
// guild-id is REJECTED.
func TestCreateGuildIdempotentReject(t *testing.T) {
ctx, _, _, _, k := newSimtestContext(t)
srv := keeper.NewMsgServerImpl(k)
first := &types.MsgCreateGuild{
GuildID: "g-dup", Name: "n", FounderReach: "reach:f",
CommonBondHash: []byte{1}, Signer: "reach:f",
}
if _, err := srv.CreateGuild(ctx, first); err != nil {
t.Fatalf("first CreateGuild: %v", err)
}
_, err := srv.CreateGuild(ctx, first)
if err == nil {
t.Error("second CreateGuild on same guild-id should be rejected (idempotent)")
}
}
// TestCreateGuildValidateBasicReject asserts a CreateGuild with empty
// CommonBondHash is REJECTED at ValidateBasic.
func TestCreateGuildValidateBasicReject(t *testing.T) {
ctx, _, _, _, k := newSimtestContext(t)
srv := keeper.NewMsgServerImpl(k)
_, err := srv.CreateGuild(ctx, &types.MsgCreateGuild{
GuildID: "g-bad", Name: "n", FounderReach: "reach:f",
CommonBondHash: nil, Signer: "reach:f",
})
if err == nil {
t.Error("CreateGuild with empty CommonBondHash should be rejected at ValidateBasic")
}
}
// --- CreateChapter (REQ-053, REQ-061) ----------------------------------------
// TestCreateChapterSuccess (case c) asserts a successful Chapter creation
// with secession terms hash-pinned + good-standing liens
// (SecuredAtFounding=true).
func TestCreateChapterSuccess(t *testing.T) {
ctx, _, _, _, k := newSimtestContext(t)
srv := keeper.NewMsgServerImpl(k)
createParentGuild(t, srv, ctx, "g-parent")
resp, err := srv.CreateChapter(ctx, &types.MsgCreateChapter{
GuildID: "g-chapter",
Name: "Chapter",
ParentGuildID: "g-parent",
FounderReach: "reach:founder",
SecessionTerms: types.SecessionTerms{
CoolingCoverActiveDays: types.CoolingSecessionCoverActiveDays,
CoolingNonCoverDays: types.CoolingSecessionNonCoverDays,
LienAuditRequired: true,
CovenantClearanceRequired: true,
},
GoodStandingLiens: []types.Lien{
{Amount: 1000, CreditorReachID: "reach:cred", SecuredAtFounding: true, CoverPoolCovenantRef: "covenant-1"},
},
Signer: "reach:founder",
})
if err != nil {
t.Fatalf("CreateChapter: %v", err)
}
c, ok := k.GetGuild(ctx, "g-chapter")
if !ok {
t.Fatal("Chapter not persisted")
}
if !c.IsChapter {
t.Error("IsChapter should be true for a Chapter")
}
if c.ParentGuildID != "g-parent" {
t.Errorf("ParentGuildID = %q, want g-parent", c.ParentGuildID)
}
// SecessionTermsHash is pinned (non-empty).
if len(c.SecessionTermsHash) == 0 {
t.Error("SecessionTermsHash should be pinned (non-empty)")
}
// The pinned hash matches HashSecessionTerms.
expected := types.HashSecessionTerms(types.SecessionTerms{
CoolingCoverActiveDays: types.CoolingSecessionCoverActiveDays,
CoolingNonCoverDays: types.CoolingSecessionNonCoverDays,
LienAuditRequired: true,
CovenantClearanceRequired: true,
})
if string(c.SecessionTermsHash) != string(expected) {
t.Errorf("SecessionTermsHash mismatch: got %x, want %x", c.SecessionTermsHash, expected)
}
// Good-standing liens recorded with SecuredAtFounding=true.
if len(c.GoodStandingLiens) != 1 || !c.GoodStandingLiens[0].SecuredAtFounding {
t.Errorf("GoodStandingLiens = %v", c.GoodStandingLiens)
}
if c.GoodStandingLiens[0].CoverPoolCovenantRef != "covenant-1" {
t.Errorf("CoverPoolCovenantRef = %q", c.GoodStandingLiens[0].CoverPoolCovenantRef)
}
// Chapter inherits Parent's Common Bond hash + Public Profile.
parent, _ := k.GetGuild(ctx, "g-parent")
if string(c.CommonBondHash) != string(parent.CommonBondHash) {
t.Errorf("Chapter CommonBondHash = %x, want parent's %x", c.CommonBondHash, parent.CommonBondHash)
}
if !hasEvent(ctx, "guild.chapter_created") {
t.Error("guild.chapter_created event not emitted")
}
// (g) Disclaimer surfaced.
if resp.Disclaimer == "" {
t.Error("CreateChapter response Disclaimer is empty (REQ-061)")
}
}
// TestCreateChapterTightenCoolingAllowed (case d) asserts a Chapter MAY
// tighten the cooling (longer than the protocol minimum is allowed).
func TestCreateChapterTightenCoolingAllowed(t *testing.T) {
ctx, _, _, _, k := newSimtestContext(t)
srv := keeper.NewMsgServerImpl(k)
createParentGuild(t, srv, ctx, "g-p-tight")
_, err := srv.CreateChapter(ctx, &types.MsgCreateChapter{
GuildID: "g-c-tight",
Name: "Tight Chapter",
ParentGuildID: "g-p-tight",
FounderReach: "reach:f",
SecessionTerms: types.SecessionTerms{
CoolingCoverActiveDays: types.CoolingSecessionCoverActiveDays + 10, // tighter (longer)
CoolingNonCoverDays: types.CoolingSecessionNonCoverDays + 5, // tighter (longer)
},
GoodStandingLiens: []types.Lien{
{Amount: 100, CreditorReachID: "reach:c", SecuredAtFounding: true},
},
Signer: "reach:f",
})
if err != nil {
t.Fatalf("CreateChapter with tighter cooling should succeed: %v", err)
}
if _, ok := k.GetGuild(ctx, "g-c-tight"); !ok {
t.Error("tighter Chapter not persisted")
}
}
// TestCreateChapterLoosenCoolingRejected (case d) asserts a Chapter MAY NOT
// loosen the cooling (shorter than the protocol minimum is REJECTED at
// ValidateBasic).
func TestCreateChapterLoosenCoolingRejected(t *testing.T) {
ctx, _, _, _, k := newSimtestContext(t)
srv := keeper.NewMsgServerImpl(k)
createParentGuild(t, srv, ctx, "g-p-loose")
_, err := srv.CreateChapter(ctx, &types.MsgCreateChapter{
GuildID: "g-c-loose",
Name: "Loose Chapter",
ParentGuildID: "g-p-loose",
FounderReach: "reach:f",
SecessionTerms: types.SecessionTerms{
CoolingCoverActiveDays: types.CoolingSecessionCoverActiveDays - 1, // looser (shorter) — REJECT
CoolingNonCoverDays: types.CoolingSecessionNonCoverDays,
},
GoodStandingLiens: []types.Lien{
{Amount: 100, CreditorReachID: "reach:c", SecuredAtFounding: true},
},
Signer: "reach:f",
})
if err == nil {
t.Fatal("CreateChapter with looser cooling (shorter) should be rejected (Chapter may tighten but not loosen — REQ-053/REQ-064)")
}
if !strings.Contains(err.Error(), "minimum") {
t.Errorf("error = %q, want 'minimum'", err.Error())
}
// The Chapter was NOT persisted.
if _, ok := k.GetGuild(ctx, "g-c-loose"); ok {
t.Error("loose Chapter should NOT be persisted on reject")
}
}
// TestCreateChapterNonExistentParent asserts a CreateChapter with a non-
// existent Parent Guild is REJECTED.
func TestCreateChapterNonExistentParent(t *testing.T) {
ctx, _, _, _, k := newSimtestContext(t)
srv := keeper.NewMsgServerImpl(k)
_, err := srv.CreateChapter(ctx, &types.MsgCreateChapter{
GuildID: "g-c-noparent",
Name: "n",
ParentGuildID: "no-such-parent",
FounderReach: "reach:f",
SecessionTerms: validTerms(),
GoodStandingLiens: []types.Lien{
{Amount: 100, CreditorReachID: "reach:c", SecuredAtFounding: true},
},
Signer: "reach:f",
})
if err == nil {
t.Fatal("CreateChapter with non-existent parent should be rejected")
}
if !strings.Contains(err.Error(), "not found") {
t.Errorf("error = %q, want 'not found'", err.Error())
}
}
// TestCreateChapterParentIsChapter asserts a CreateChapter whose Parent is
// itself a Chapter is REJECTED (a Chapter cannot have a Chapter parent).
func TestCreateChapterParentIsChapter(t *testing.T) {
ctx, _, _, _, k := newSimtestContext(t)
srv := keeper.NewMsgServerImpl(k)
createParentGuild(t, srv, ctx, "g-real-parent")
// Create a first Chapter.
_, err := srv.CreateChapter(ctx, &types.MsgCreateChapter{
GuildID: "g-chapter-1",
Name: "Chapter1",
ParentGuildID: "g-real-parent",
FounderReach: "reach:f",
SecessionTerms: validTerms(),
GoodStandingLiens: []types.Lien{
{Amount: 100, CreditorReachID: "reach:c", SecuredAtFounding: true},
},
Signer: "reach:f",
})
if err != nil {
t.Fatalf("first CreateChapter: %v", err)
}
// Attempt to create a second Chapter under the first Chapter (a Chapter
// parent) — REJECTED.
_, err = srv.CreateChapter(ctx, &types.MsgCreateChapter{
GuildID: "g-chapter-2",
Name: "Chapter2",
ParentGuildID: "g-chapter-1",
FounderReach: "reach:f",
SecessionTerms: validTerms(),
GoodStandingLiens: []types.Lien{
{Amount: 100, CreditorReachID: "reach:c", SecuredAtFounding: true},
},
Signer: "reach:f",
})
if err == nil {
t.Fatal("CreateChapter with a Chapter parent should be rejected")
}
if !strings.Contains(err.Error(), "Chapter") {
t.Errorf("error = %q, want 'Chapter'", err.Error())
}
}
// TestCreateChapterIdempotentReject asserts a second CreateChapter on the
// same chapter guild-id is REJECTED.
func TestCreateChapterIdempotentReject(t *testing.T) {
ctx, _, _, _, k := newSimtestContext(t)
srv := keeper.NewMsgServerImpl(k)
createParentGuild(t, srv, ctx, "g-p-dup")
first := &types.MsgCreateChapter{
GuildID: "g-c-dup",
Name: "n",
ParentGuildID: "g-p-dup",
FounderReach: "reach:f",
SecessionTerms: validTerms(),
GoodStandingLiens: []types.Lien{
{Amount: 100, CreditorReachID: "reach:c", SecuredAtFounding: true},
},
Signer: "reach:f",
}
if _, err := srv.CreateChapter(ctx, first); err != nil {
t.Fatalf("first CreateChapter: %v", err)
}
_, err := srv.CreateChapter(ctx, first)
if err == nil {
t.Error("second CreateChapter on same guild-id should be rejected (idempotent)")
}
}
// --- OneTapExitStand (REQ-057) -----------------------------------------------
// TestOneTapExitStandHouseholdSuccess (case e) asserts a Household one-tap
// exit succeeds (Stand type Household + StashKeeper stub records the call).
func TestOneTapExitStandHouseholdSuccess(t *testing.T) {
ctx, sk, stashK, _, k := newSimtestContext(t)
sk.stands = map[string]string{"stand-hh": "Household"}
srv := keeper.NewMsgServerImpl(k)
_, err := srv.OneTapExitStand(ctx, &types.MsgOneTapExitStand{
StandID: "stand-hh",
Signer: "reach:holder",
})
if err != nil {
t.Fatalf("OneTapExitStand: %v", err)
}
if !hasEvent(ctx, "guild.one_tap_exit") {
t.Error("guild.one_tap_exit event not emitted")
}
// StashKeeper recorded the asset return.
if len(stashK.calls) != 1 {
t.Fatalf("StashKeeper calls = %d, want 1", len(stashK.calls))
}
if stashK.calls[0].holderReachID != "reach:holder" || stashK.calls[0].standID != "stand-hh" {
t.Errorf("StashKeeper call = %+v", stashK.calls[0])
}
}
// TestOneTapExitStandCrewRejected (case e) asserts a Crew Stand one-tap exit
// is REJECTED (one-tap is Household-only).
func TestOneTapExitStandCrewRejected(t *testing.T) {
ctx, sk, _, _, k := newSimtestContext(t)
sk.stands = map[string]string{"stand-crew": "Crew"}
srv := keeper.NewMsgServerImpl(k)
_, err := srv.OneTapExitStand(ctx, &types.MsgOneTapExitStand{
StandID: "stand-crew",
Signer: "reach:holder",
})
if err == nil {
t.Fatal("OneTapExitStand on a Crew Stand should be rejected (one-tap is Household-only — REQ-057)")
}
if !strings.Contains(err.Error(), "Household") {
t.Errorf("error = %q, want 'Household'", err.Error())
}
}
// TestOneTapExitStandNonExistent asserts a one-tap exit on a non-existent
// Stand is REJECTED.
func TestOneTapExitStandNonExistent(t *testing.T) {
ctx, sk, _, _, k := newSimtestContext(t)
sk.stands = map[string]string{}
srv := keeper.NewMsgServerImpl(k)
_, err := srv.OneTapExitStand(ctx, &types.MsgOneTapExitStand{
StandID: "no-such-stand",
Signer: "reach:holder",
})
if err == nil {
t.Fatal("OneTapExitStand on non-existent Stand should be rejected")
}
if !strings.Contains(err.Error(), "not found") {
t.Errorf("error = %q, want 'not found'", err.Error())
}
}
// TestOneTapExitStandNilStandKeeperReject asserts a nil StandKeeper REJECTS
// the one-tap exit (the type check is load-bearing).
func TestOneTapExitStandNilStandKeeperReject(t *testing.T) {
ctx, _, k := newSimtestContextNilStand(t)
srv := keeper.NewMsgServerImpl(k)
_, err := srv.OneTapExitStand(ctx, &types.MsgOneTapExitStand{
StandID: "any-stand",
Signer: "reach:holder",
})
if err == nil {
t.Fatal("OneTapExitStand with nil StandKeeper should be rejected (type check is load-bearing)")
}
if !strings.Contains(err.Error(), "StandKeeper") {
t.Errorf("error = %q, want 'StandKeeper'", err.Error())
}
}
// TestOneTapExitStandNilStashKeeperSkip asserts a nil StashKeeper skips the
// asset return (the dissolution event is still emitted).
func TestOneTapExitStandNilStashKeeperSkip(t *testing.T) {
ctx, sk, _, _, k := newSimtestContext(t)
sk.stands = map[string]string{"stand-hh2": "Household"}
// Wire a nil StashKeeper via the setter (the keeper was constructed with
// a non-nil stub; override to nil for this case).
k.SetStashKeeper(nil)
srv := keeper.NewMsgServerImpl(k)
_, err := srv.OneTapExitStand(ctx, &types.MsgOneTapExitStand{
StandID: "stand-hh2",
Signer: "reach:holder",
})
if err != nil {
t.Fatalf("OneTapExitStand with nil StashKeeper should skip asset return: %v", err)
}
if !hasEvent(ctx, "guild.one_tap_exit") {
t.Error("guild.one_tap_exit event should still be emitted with nil StashKeeper")
}
}
// TestOneTapExitStandStashErrorReject asserts a StashKeeper error REJECTS
// the one-tap exit (the asset return is load-bearing).
func TestOneTapExitStandStashErrorReject(t *testing.T) {
ctx, sk, stashK, _, k := newSimtestContext(t)
sk.stands = map[string]string{"stand-hh-err": "Household"}
stashK.err = sentinelErr("stash return failed (simtest)")
srv := keeper.NewMsgServerImpl(k)
_, err := srv.OneTapExitStand(ctx, &types.MsgOneTapExitStand{
StandID: "stand-hh-err",
Signer: "reach:holder",
})
if err == nil {
t.Fatal("OneTapExitStand with StashKeeper error should be rejected")
}
if !strings.Contains(err.Error(), "return assets") {
t.Errorf("error = %q, want 'return assets'", err.Error())
}
}
// --- DelegateConfederationVoice (REQ-058) ------------------------------------
// TestDelegateConfederationVoiceSuccess (case f) asserts a Confederation
// Voice delegation succeeds (one-per-Stand).
func TestDelegateConfederationVoiceSuccess(t *testing.T) {
ctx, sk, _, _, k := newSimtestContext(t)
sk.stands = map[string]string{"conf-1": "Confederation"}
srv := keeper.NewMsgServerImpl(k)
_, err := srv.DelegateConfederationVoice(ctx, &types.MsgDelegateConfederationVoice{
ConfederationStandID: "conf-1",
MemberStandID: "mem-1",
DelegateReachID: "reach:delegate",
Signer: "reach:s",
})
if err != nil {
t.Fatalf("DelegateConfederationVoice: %v", err)
}
v, ok := k.GetDelegation(ctx, "conf-1", "mem-1")
if !ok {
t.Fatal("delegation not persisted")
}
if v.DelegateReachID != "reach:delegate" {
t.Errorf("DelegateReachID = %q, want reach:delegate", v.DelegateReachID)
}
if !hasEvent(ctx, "guild.confederation_voice_delegated") {
t.Error("guild.confederation_voice_delegated event not emitted")
}
}
// TestDelegateConfederationVoiceDuplicateRejected (case f) asserts a
// duplicate delegation from the same MemberStandID is REJECTED (one-Stand-
// one-Vote).
func TestDelegateConfederationVoiceDuplicateRejected(t *testing.T) {
ctx, sk, _, _, k := newSimtestContext(t)
sk.stands = map[string]string{"conf-dup": "Confederation"}
srv := keeper.NewMsgServerImpl(k)
first := &types.MsgDelegateConfederationVoice{
ConfederationStandID: "conf-dup",
MemberStandID: "mem-dup",
DelegateReachID: "reach:d1",
Signer: "reach:s",
}
if _, err := srv.DelegateConfederationVoice(ctx, first); err != nil {
t.Fatalf("first delegation: %v", err)
}
// A second delegation from the same MemberStandID (even to a different
// delegate) is REJECTED.
_, err := srv.DelegateConfederationVoice(ctx, &types.MsgDelegateConfederationVoice{
ConfederationStandID: "conf-dup",
MemberStandID: "mem-dup",
DelegateReachID: "reach:d2",
Signer: "reach:s",
})
if err == nil {
t.Fatal("duplicate delegation from the same MemberStandID should be rejected (one-Stand-one-Vote — REQ-058)")
}
if !strings.Contains(err.Error(), "duplicate") {
t.Errorf("error = %q, want 'duplicate'", err.Error())
}
}
// TestDelegateConfederationVoiceNonConfederationRejected asserts a
// delegation where the named Confederation Stand is NOT a Confederation type
// is REJECTED.
func TestDelegateConfederationVoiceNonConfederationRejected(t *testing.T) {
ctx, sk, _, _, k := newSimtestContext(t)
sk.stands = map[string]string{"not-conf": "Crew"}
srv := keeper.NewMsgServerImpl(k)
_, err := srv.DelegateConfederationVoice(ctx, &types.MsgDelegateConfederationVoice{
ConfederationStandID: "not-conf",
MemberStandID: "mem-1",
DelegateReachID: "reach:d",
Signer: "reach:s",
})
if err == nil {
t.Fatal("DelegateConfederationVoice on a non-Confederation Stand should be rejected")
}
if !strings.Contains(err.Error(), "Confederation") {
t.Errorf("error = %q, want 'Confederation'", err.Error())
}
}
// TestDelegateConfederationVoiceNonExistent asserts a delegation on a non-
// existent Stand is REJECTED.
func TestDelegateConfederationVoiceNonExistent(t *testing.T) {
ctx, sk, _, _, k := newSimtestContext(t)
sk.stands = map[string]string{}
srv := keeper.NewMsgServerImpl(k)
_, err := srv.DelegateConfederationVoice(ctx, &types.MsgDelegateConfederationVoice{
ConfederationStandID: "no-such-conf",
MemberStandID: "mem-1",
DelegateReachID: "reach:d",
Signer: "reach:s",
})
if err == nil {
t.Fatal("DelegateConfederationVoice on non-existent Stand should be rejected")
}
if !strings.Contains(err.Error(), "not found") {
t.Errorf("error = %q, want 'not found'", err.Error())
}
}
// TestDelegateConfederationVoiceNilStandKeeperReject asserts a nil
// StandKeeper REJECTS the delegation (the type check is load-bearing).
func TestDelegateConfederationVoiceNilStandKeeperReject(t *testing.T) {
ctx, _, k := newSimtestContextNilStand(t)
srv := keeper.NewMsgServerImpl(k)
_, err := srv.DelegateConfederationVoice(ctx, &types.MsgDelegateConfederationVoice{
ConfederationStandID: "any",
MemberStandID: "mem",
DelegateReachID: "reach:d",
Signer: "reach:s",
})
if err == nil {
t.Fatal("DelegateConfederationVoice with nil StandKeeper should be rejected (type check is load-bearing)")
}
if !strings.Contains(err.Error(), "StandKeeper") {
t.Errorf("error = %q, want 'StandKeeper'", err.Error())
}
}
// --- AddLien (REQ-053) -------------------------------------------------------
// TestAddLienPostFoundingSuccess (case h) asserts a post-founding lien with
// SecuredAtFounding=false succeeds.
func TestAddLienPostFoundingSuccess(t *testing.T) {
ctx, _, _, _, k := newSimtestContext(t)
srv := keeper.NewMsgServerImpl(k)
createParentGuild(t, srv, ctx, "g-lien")
_, err := srv.AddLien(ctx, &types.MsgAddLien{
GuildID: "g-lien",
Lien: types.Lien{
Amount: 500,
CreditorReachID: "reach:cred",
SecuredAtFounding: false,
CoverPoolCovenantRef: "covenant-2",
},
Signer: "reach:s",
})
if err != nil {
t.Fatalf("AddLien: %v", err)
}
// The lien is persisted at idx 0.
l, ok := k.GetLien(ctx, "g-lien", 0)
if !ok {
t.Fatal("lien not persisted")
}
if l.Amount != 500 || l.SecuredAtFounding {
t.Errorf("lien = %+v", l)
}
if !hasEvent(ctx, "guild.lien_added") {
t.Error("guild.lien_added event not emitted")
}
if got := k.AllLiens(ctx, "g-lien"); len(got) != 1 {
t.Errorf("AllLiens = %d, want 1", len(got))
}
}
// TestAddLienSecuredAtFoundingRejected (case h) asserts a post-founding lien
// with SecuredAtFounding=true is REJECTED (founding is a one-time event —
// REQ-053/REQ-081).
func TestAddLienSecuredAtFoundingRejected(t *testing.T) {
ctx, _, _, _, k := newSimtestContext(t)
srv := keeper.NewMsgServerImpl(k)
createParentGuild(t, srv, ctx, "g-lien-reject")
_, err := srv.AddLien(ctx, &types.MsgAddLien{
GuildID: "g-lien-reject",
Lien: types.Lien{
Amount: 500,
CreditorReachID: "reach:cred",
SecuredAtFounding: true, // REJECTED — founding is one-time
},
Signer: "reach:s",
})
if err == nil {
t.Fatal("AddLien with SecuredAtFounding=true post-founding should be rejected (founding is one-time — REQ-053/REQ-081)")
}
if !strings.Contains(err.Error(), "SecuredAtFounding") {
t.Errorf("error = %q, want 'SecuredAtFounding'", err.Error())
}
// The lien was NOT persisted.
if got := k.AllLiens(ctx, "g-lien-reject"); len(got) != 0 {
t.Errorf("AllLiens = %d, want 0 (rejected lien not persisted)", len(got))
}
}
// TestAddLienNonExistentGuild asserts an AddLien on a non-existent Guild is
// REJECTED.
func TestAddLienNonExistentGuild(t *testing.T) {
ctx, _, _, _, k := newSimtestContext(t)
srv := keeper.NewMsgServerImpl(k)
_, err := srv.AddLien(ctx, &types.MsgAddLien{
GuildID: "no-such-guild",
Lien: types.Lien{
Amount: 100, CreditorReachID: "reach:c", SecuredAtFounding: false,
},
Signer: "reach:s",
})
if err == nil {
t.Fatal("AddLien on non-existent Guild should be rejected")
}
if !strings.Contains(err.Error(), "not found") {
t.Errorf("error = %q, want 'not found'", err.Error())
}
}
// --- unwrapCtx panic --------------------------------------------------------
// TestUnwrapCtxPanic asserts unwrapCtx panics on a non-sdk.Context value.
func TestUnwrapCtxPanic(t *testing.T) {
defer func() {
if r := recover(); r == nil {
t.Error("unwrapCtx on non-sdk.Context should panic")
}
}()
_, _ = keeper.NewMsgServerImpl(keeper.Keeper{}).AddLien("not-a-ctx",
&types.MsgAddLien{GuildID: "g", Lien: types.Lien{Amount: 1, CreditorReachID: "c"}, Signer: "s"})
}
// --- Keeper accessors (coverage) --------------------------------------------
// TestKeeperAccessors exercises the exported Keeper accessors that the
// simtest above does not directly hit (AllGuilds, GetLien on empty,
// AllDelegations, the marshal-error paths, the setters) to push coverage
// >=80%.
func TestKeeperAccessors(t *testing.T) {
ctx, sk, _, storeKey, k := newSimtestContext(t)
_ = sk
// Empty-store accessors return empty (not nil) slices.
if got := k.AllGuilds(ctx); len(got) != 0 {
t.Errorf("AllGuilds empty = %d, want 0", len(got))
}
if got := k.AllLiens(ctx, "nobody"); len(got) != 0 {
t.Errorf("AllLiens empty = %d, want 0", len(got))
}
if got := k.AllDelegations(ctx, "nobody"); len(got) != 0 {
t.Errorf("AllDelegations empty = %d, want 0", len(got))
}
if _, ok := k.GetLien(ctx, "nobody", 0); ok {
t.Error("GetLien on empty store should return false")
}
if _, ok := k.GetDelegation(ctx, "nobody", "nobody"); ok {
t.Error("GetDelegation on empty store should return false")
}
// Populate + read back.
k.SetGuild(ctx, types.Guild{GuildID: "g-a", Name: "n", FounderReach: "reach:f"})
if g, ok := k.GetGuild(ctx, "g-a"); !ok || g.Name != "n" {
t.Errorf("GetGuild = %+v ok=%v", g, ok)
}
if got := k.AllGuilds(ctx); len(got) != 1 {
t.Errorf("AllGuilds = %d, want 1", len(got))
}
k.SetLien(ctx, "g-a", 0, types.Lien{Amount: 1, CreditorReachID: "reach:c"})
if l, ok := k.GetLien(ctx, "g-a", 0); !ok || l.Amount != 1 {
t.Errorf("GetLien = %+v ok=%v", l, ok)
}
if got := k.AllLiens(ctx, "g-a"); len(got) != 1 {
t.Errorf("AllLiens = %d, want 1", len(got))
}
if idx := k.NextLienIdx(ctx, "g-a"); idx != 1 {
t.Errorf("NextLienIdx = %d, want 1", idx)
}
k.SetDelegation(ctx, types.ConfederationVoice{
ConfederationStandID: "conf-a", MemberStandID: "mem-a",
DelegateReachID: "reach:d", DelegatedAt: 1,
})
if v, ok := k.GetDelegation(ctx, "conf-a", "mem-a"); !ok || v.DelegateReachID != "reach:d" {
t.Errorf("GetDelegation = %+v ok=%v", v, ok)
}
if got := k.AllDelegations(ctx, "conf-a"); len(got) != 1 {
t.Errorf("AllDelegations = %d, want 1", len(got))
}
// Marshal-error paths (corrupt bytes in store).
store := ctx.KVStore(storeKey)
store.Set([]byte("guild/corrupt"), []byte("not-json"))
if _, ok := k.GetGuild(ctx, "corrupt"); ok {
t.Error("GetGuild on corrupt bytes should return false")
}
store.Set([]byte("lien/corrupt/0"), []byte("not-json"))
if _, ok := k.GetLien(ctx, "corrupt", 0); ok {
t.Error("GetLien on corrupt bytes should return false")
}
store.Set([]byte("delegation/corrupt/m"), []byte("not-json"))
if _, ok := k.GetDelegation(ctx, "corrupt", "m"); ok {
t.Error("GetDelegation on corrupt bytes should return false")
}
// Post-construction setters (coverage).
k.SetStandKeeper(&stubStandKeeper{stands: map[string]string{"s": "Household"}})
k.SetStashKeeper(&stubStashKeeper{})
k.SetParams(types.DefaultParams())
if k.Params().DefaultCoolingCoverActiveDays != types.CoolingSecessionCoverActiveDays {
t.Errorf("Params DefaultCoolingCoverActiveDays = %d", k.Params().DefaultCoolingCoverActiveDays)
}
}
// --- sentinel error helper ---------------------------------------------------
type sentinelErr string
func (e sentinelErr) Error() string { return string(e) }
+89
View File
@@ -0,0 +1,89 @@
package guild
// module.go holds the guild module's AppModule + RegisterServices (P3,
// REQ-051, REQ-053, REQ-057, REQ-058).
//
// The AppModule wraps the guild Keeper and registers the MsgServer via
// RegisterServices. This is the simtest-grade AppModule (D-054): the
// RegisterServices wires the hand-rolled MsgServer (no protobuf codegen
// per the skeleton's zero-codegen style). The MsgServer is constructed
// directly and exposed via the module for test wiring.
//
// The StandKeeper + StashKeeper expected-keeper shims are injected at
// construction (StandKeeper nil-able — the OneTapExitStand +
// DelegateConfederationVoice handlers REJECT on a nil StandKeeper; the type
// check is load-bearing. StashKeeper nil-able — a nil StashKeeper skips the
// asset return on one-tap exit; the dissolution event is still emitted).
import (
"encoding/json"
storetypes "cosmossdk.io/store/types"
"github.com/cosmos/cosmos-sdk/codec"
sdk "github.com/cosmos/cosmos-sdk/types"
"github.com/cosmos/cosmos-sdk/types/module"
"github.com/oy/openyield/x/guild/keeper"
"github.com/oy/openyield/x/guild/types"
)
// ConsensusVersion is the guild module's consensus version (AppModule).
const ConsensusVersion = 1
// AppModule is the guild application module (simtest-grade — D-054).
type AppModule struct {
keeper keeper.Keeper
}
// NewAppModule constructs a new guild AppModule. The StandKeeper + StashKeeper
// expected-keeper shims are injected (StandKeeper nil-able — the
// OneTapExitStand + DelegateConfederationVoice handlers REJECT on a nil
// StandKeeper; StashKeeper nil-able — a nil StashKeeper skips the asset
// return on one-tap exit).
func NewAppModule(cdc codec.Codec, storeKey storetypes.StoreKey, sk types.StandKeeper, stashK types.StashKeeper) AppModule {
k := keeper.NewKeeper(cdc, storeKey, sk, stashK)
return AppModule{keeper: k}
}
// RegisterServices registers the guild MsgServer. Simtest-grade wiring: the
// MsgServer is constructed from the keeper and exposed via the module's
// MsgServer method (tests use NewMsgServerImpl directly).
func (am AppModule) RegisterServices(cfg module.Configurator) {
_ = cfg
}
// MsgServer returns the guild MsgServer for this module's keeper.
func (am AppModule) MsgServer() types.MsgServer {
return keeper.NewMsgServerImpl(am.keeper)
}
// Name returns the module name.
func (AppModule) Name() string { return types.ModuleName }
// ConsensusVersion implements AppModule.ConsensusVersion.
func (AppModule) ConsensusVersion() uint64 { return ConsensusVersion }
// InitGenesis performs genesis initialization for the guild module (simtest-
// grade no-op — the runtime stores are created at handler time; genesis
// init of runtime-promoted stores is deferred to the live chain v0.6+).
func (am AppModule) InitGenesis(ctx sdk.Context, cdc codec.JSONCodec, data json.RawMessage) {
var gs types.GenesisState
cdc.MustUnmarshalJSON(data, &gs)
for _, g := range gs.Guilds {
am.keeper.SetGuild(ctx, g)
}
for _, c := range gs.Chapters {
am.keeper.SetGuild(ctx, c)
}
}
// ExportGenesis returns the exported genesis state as raw bytes (simtest-
// grade: returns an empty genesis; live chain export deferred to v0.6+).
func (am AppModule) ExportGenesis(ctx sdk.Context, cdc codec.JSONCodec) json.RawMessage {
gs := types.DefaultGenesisState()
return cdc.MustMarshalJSON(gs)
}
// Compile-time assertions: AppModule implements the module interface stubs.
var _ module.HasName = AppModule{}
var _ module.HasConsensusVersion = AppModule{}
+104
View File
@@ -0,0 +1,104 @@
package guild_test
// module_test.go exercises the x/guild AppModule (D-054 simtest-grade).
// The AppModule wraps the Keeper + exposes the MsgServer; this test
// constructs an AppModule with nil shims + asserts Name, ConsensusVersion,
// MsgServer, InitGenesis, ExportGenesis. Coverage target: the module.go
// surface.
import (
"encoding/json"
"testing"
"cosmossdk.io/log"
"cosmossdk.io/store"
storetypes "cosmossdk.io/store/types"
cmtproto "github.com/cometbft/cometbft/proto/tendermint/types"
dbm "github.com/cosmos/cosmos-db"
"github.com/cosmos/cosmos-sdk/codec"
codectypes "github.com/cosmos/cosmos-sdk/codec/types"
sdk "github.com/cosmos/cosmos-sdk/types"
"github.com/oy/openyield/x/guild"
"github.com/oy/openyield/x/guild/types"
)
func newModuleTestContext(t *testing.T) (sdk.Context, guild.AppModule, codec.Codec) {
t.Helper()
db := dbm.NewMemDB()
cdc := newModuleTestCodec()
storeKey := storetypes.NewKVStoreKey(types.StoreKey)
cms := store.NewCommitMultiStore(db, log.NewNopLogger(), nil)
cms.MountStoreWithDB(storeKey, storetypes.StoreTypeDB, nil)
if err := cms.LoadLatestVersion(); err != nil {
t.Fatalf("load latest version: %v", err)
}
ctx := sdk.NewContext(cms, cmtproto.Header{}, false, log.NewNopLogger())
am := guild.NewAppModule(cdc, storeKey, nil, nil)
return ctx, am, cdc
}
func newModuleTestCodec() codec.Codec {
registry := codectypes.NewInterfaceRegistry()
return codec.NewProtoCodec(registry)
}
// TestAppModuleName asserts the module name.
func TestAppModuleName(t *testing.T) {
_, am, _ := newModuleTestContext(t)
if am.Name() != types.ModuleName {
t.Errorf("Name = %q, want %q", am.Name(), types.ModuleName)
}
}
// TestAppModuleConsensusVersion asserts ConsensusVersion == 1.
func TestAppModuleConsensusVersion(t *testing.T) {
_, am, _ := newModuleTestContext(t)
if am.ConsensusVersion() != guild.ConsensusVersion {
t.Errorf("ConsensusVersion = %d, want %d", am.ConsensusVersion(), guild.ConsensusVersion)
}
if guild.ConsensusVersion != 1 {
t.Errorf("ConsensusVersion const = %d, want 1", guild.ConsensusVersion)
}
}
// TestAppModuleMsgServer asserts MsgServer returns a non-nil MsgServer.
func TestAppModuleMsgServer(t *testing.T) {
_, am, _ := newModuleTestContext(t)
srv := am.MsgServer()
if srv == nil {
t.Fatal("MsgServer() returned nil")
}
}
// TestAppModuleInitExportGenesis asserts InitGenesis + ExportGenesis round-
// trip an empty genesis.
func TestAppModuleInitExportGenesis(t *testing.T) {
ctx, am, cdc := newModuleTestContext(t)
empty := types.DefaultGenesisState()
data := cdc.MustMarshalJSON(empty)
am.InitGenesis(ctx, cdc, data)
exported := am.ExportGenesis(ctx, cdc)
if len(exported) == 0 {
t.Fatal("ExportGenesis returned empty bytes")
}
var gs types.GenesisState
if err := json.Unmarshal(exported, &gs); err != nil {
t.Fatalf("ExportGenesis bytes not valid JSON: %v", err)
}
}
// TestAppModuleRegisterServicesNoPanic asserts RegisterServices does not
// panic with a nil configurator (simtest-grade — the method is a no-op stub
// for the hand-rolled MsgServer wiring).
func TestAppModuleRegisterServicesNoPanic(t *testing.T) {
_, am, _ := newModuleTestContext(t)
defer func() {
if r := recover(); r != nil {
t.Errorf("RegisterServices panicked: %v", r)
}
}()
am.RegisterServices(nil)
}
+75
View File
@@ -0,0 +1,75 @@
package types
// expected_keepers.go holds the Go INTERFACES for the cross-module keepers
// x/guild depends on (G-003 firewall — ibc-go expected-keepers convention).
//
// The guild runtime (REQ-051, REQ-053, REQ-057, REQ-058) depends on TWO
// cross-module keepers:
//
// 1. x/stand (StandKeeper) — the OneTapExitStand handler asserts the named
// Stand is a Household (REQ-057) before dissolving it; the
// DelegateConfederationVoice handler asserts the named Stand is a
// Confederation (REQ-058) before recording the delegation. The handler
// queries GetStand for the Stand type (an opaque string — "Household" or
// "Confederation") and compares. This is the v0.7 P3 household-edge: the
// Guild module references a Stand by ID-string (G-003 — no struct import
// of x/stand/types).
//
// 2. x/stash (StashKeeper) — the OneTapExitStand handler returns the
// dissolved Household Stand's assets to the Holder's Stash (REQ-057).
// The handler calls ReturnAssetsToHolder; the simtest stub records the
// call for assertion (no actual asset transfer in simtest).
//
// Both dependencies are expressed as INTERFACES defined HERE (in
// x/guild/types), NOT as struct imports of any x/<module>/types. The
// concrete keepers (or simtest stubs) satisfy these interfaces structurally
// (the P3 simtest wires stubs per G-003 test exemption); the handler depends
// on the interface, preserving G-003's intent (no cross-module struct
// coupling, no import cycles).
//
// Lexicon note (REQ-012): "Guild", "Chapter", "Stand", "Household",
// "Confederation", "Stash", "Holder", "Reach", "Voice" are all lexicon-clean.
// The project-wide 10 banned terms NEVER appear (enforced by lexicon_meta +
// the per-package lexicon assertion in types_test.go).
// StandKeeper is the expected-keeper interface for x/stand (G-003). The
// OneTapExitStand handler calls GetStand to assert the Stand type is
// "Household" (REQ-057 — one-tap exit is Household-only). The
// DelegateConfederationVoice handler calls GetStand to assert the Stand type
// is "Confederation" (REQ-058). The standType string is the opaque Stand
// type name (cross-doc to x/stand.StandType — "Household", "Confederation",
// etc.); the handler compares the string.
//
// No struct import of x/stand/types — the interface is the by-ID-string
// boundary (G-003). The standID is an opaque string. A nil StandKeeper
// REJECTS the OneTapExitStand + DelegateConfederationVoice handlers (the
// type check is load-bearing — a nil shim is a wiring error, NOT a simtest
// skip path; the household/confederation type check cannot be skipped).
type StandKeeper interface {
// GetStand returns the Stand type string + exists flag for the named
// Stand (by-ID-string). The OneTapExitStand handler compares the
// returned type against "Household"; the
// DelegateConfederationVoice handler compares against "Confederation".
// A non-existent Stand returns ("", false) — the handler REJECTS.
GetStand(standID string) (standType string, exists bool)
}
// StashKeeper is the expected-keeper interface for x/stash (G-003). The
// OneTapExitStand handler calls ReturnAssetsToHolder to return the dissolved
// Household Stand's assets to the Holder's Stash (REQ-057). The simtest stub
// records the call for assertion (no actual asset transfer in simtest — the
// simtest documents the wiring contract).
//
// No struct import of x/stash/types — the interface is the by-ID-string
// boundary (G-003). The holderReachID + standID are opaque strings. A nil
// StashKeeper skips the asset return (simtest wiring — the handler still
// emits the dissolution event; the asset return is a side-effect the simtest
// stub records).
type StashKeeper interface {
// ReturnAssetsToHolder returns the named Stand's assets to the named
// Holder's Stash. The OneTapExitStand handler calls this on a Household
// dissolution (REQ-057). A non-nil error REJECTS the dissolution (the
// asset return is load-bearing — a failed return leaves the Stand
// intact).
ReturnAssetsToHolder(holderReachID string, standID string) error
}
+421
View File
@@ -0,0 +1,421 @@
package types
// msg_guild.go holds the x/guild Msg* types implementing sdk.Msg (REQ-051,
// REQ-053, REQ-057, REQ-058). G-006 controlled exception: types/ gains the
// cosmos-sdk import for sdk.Msg (mirrors x/cover/types/msg_cover.go — D-055;
// the invariant/lexicon tests in *_test.go stay stdlib-only per G-024,
// isolated from this msg_*.go file).
//
// The five P3 Guild Msg types drive the Guild Charter + Chapter Federation +
// Household + Confederation runtime:
// - MsgCreateGuild: create a Guild with a Common Bond hash + Public Profile
// (REQ-051). The handler persists the Guild + surfaces a jurisdictional
// disclaimer (REQ-061).
// - MsgCreateChapter: create a Chapter under a Parent Guild (REQ-053). The
// handler pins the SecessionTerms hash + records the Good-Standing Liens
// (SecuredAtFounding=true) + rejects cooling below the protocol minimum
// + surfaces a jurisdictional disclaimer (REQ-061).
// - MsgOneTapExitStand: one-tap exit a Household Stand (REQ-057). The
// handler asserts the Stand type is Household via the StandKeeper shim +
// dissolves the Stand + returns assets to the Holder's Stash.
// - MsgDelegateConfederationVoice: delegate a member Stand's Voice in a
// Confederation (REQ-058). The handler asserts the Stand type is
// Confederation via the StandKeeper shim + records the delegation (one
// delegation per member Stand — duplicate REJECTED).
// - MsgAddLien: add a Good-Standing Lien to a Guild (REQ-053). The handler
// rejects any new SecuredAtFounding=true lien (founding is a one-time
// event — REQ-053/REQ-081).
//
// All cross-module refs are by-ID-string (G-003): founder-reach refs an
// x/identity Reach; stand-id refs an x/stand Stand; parent-guild-id refs a
// Guild; cover-pool-covenant-ref refs a Cover Pool covenant. No struct
// imports of x/stand/types or x/stash/types (the shims are interfaces
// defined in expected_keepers.go — G-003 preserved).
//
// Lexicon note (REQ-012): the message names + field names use the safe Guild
// vocabulary EXCLUSIVELY. "Guild", "Chapter", "Parent Guild", "Common Bond",
// "Public Profile", "Good-Standing Lien", "Secession Terms", "Household",
// "Confederation", "Hand-Pass" are the clean names; the project-wide 10
// banned terms NEVER appear (enforced by lexicon_meta + the per-package
// lexicon assertion in types_test.go).
import (
"fmt"
sdk "github.com/cosmos/cosmos-sdk/types"
)
// --- MsgCreateGuild -----------------------------------------------------------
// MsgCreateGuild creates a Guild with a Common Bond hash + Public Profile
// (REQ-051). The handler persists the Guild + surfaces a jurisdictional
// disclaimer (REQ-061 — the Disclaimer string is in the response).
//
// ValidateBasic is stateless: non-empty fields + non-empty CommonBondHash.
type MsgCreateGuild struct {
GuildID string `json:"guild_id" yaml:"guild_id"`
Name string `json:"name" yaml:"name"`
FounderReach string `json:"founder_reach" yaml:"founder_reach"`
StandAffiliationID string `json:"stand_affiliation_id,omitempty" yaml:"stand_affiliation_id,omitempty"`
CommonBondHash []byte `json:"common_bond_hash" yaml:"common_bond_hash"`
PublicProfile GuildPublicProfile `json:"public_profile" yaml:"public_profile"`
Signer string `json:"signer" yaml:"signer"`
}
// Reset implements proto.Message.
func (m *MsgCreateGuild) Reset() { *m = MsgCreateGuild{} }
// String implements proto.Message.
func (m *MsgCreateGuild) String() string {
return fmt.Sprintf("MsgCreateGuild{GuildID:%s Name:%s FounderReach:%s StandAffiliationID:%s Signer:%s}",
m.GuildID, m.Name, m.FounderReach, m.StandAffiliationID, m.Signer)
}
// ProtoMessage implements proto.Message.
func (*MsgCreateGuild) ProtoMessage() {}
// ValidateBasic is the stateless validation: non-empty guild-id, name,
// founder-reach, signer, non-empty CommonBondHash.
func (m *MsgCreateGuild) ValidateBasic() error {
if m.GuildID == "" {
return fmt.Errorf("guild: empty guild-id")
}
if m.Name == "" {
return fmt.Errorf("guild: empty name")
}
if m.FounderReach == "" {
return fmt.Errorf("guild: empty founder-reach")
}
if m.Signer == "" {
return fmt.Errorf("guild: empty signer")
}
if len(m.CommonBondHash) == 0 {
return fmt.Errorf("guild: empty common-bond-hash (REQ-051 — hash-pinned at creation)")
}
return nil
}
// GetSigners returns the signer's reach-id as sdk.AccAddress bytes.
func (m *MsgCreateGuild) GetSigners() []sdk.AccAddress {
return []sdk.AccAddress{[]byte(m.Signer)}
}
// --- MsgCreateChapter ---------------------------------------------------------
// MsgCreateChapter creates a Chapter under a Parent Guild (REQ-053). The
// handler pins the SecessionTerms hash (HashSecessionTerms) + records the
// Good-Standing Liens (SecuredAtFounding=true) + rejects cooling below the
// protocol minimum (CoolingSecessionCoverActiveDays / NonCoverDays) +
// surfaces a jurisdictional disclaimer (REQ-061).
//
// ValidateBasic is stateless: non-empty fields, non-empty ParentGuildID,
// SecessionTerms valid (non-zero + protocol-minimum-bounded via
// SecessionTerms.Validate), each GoodStandingLien has SecuredAtFounding=true
// + non-empty CreditorReachID + Amount > 0.
type MsgCreateChapter struct {
GuildID string `json:"guild_id" yaml:"guild_id"`
Name string `json:"name" yaml:"name"`
ParentGuildID string `json:"parent_guild_id" yaml:"parent_guild_id"`
FounderReach string `json:"founder_reach" yaml:"founder_reach"`
SecessionTerms SecessionTerms `json:"secession_terms" yaml:"secession_terms"`
GoodStandingLiens []Lien `json:"good_standing_liens" yaml:"good_standing_liens"`
Signer string `json:"signer" yaml:"signer"`
}
// Reset implements proto.Message.
func (m *MsgCreateChapter) Reset() { *m = MsgCreateChapter{} }
// String implements proto.Message.
func (m *MsgCreateChapter) String() string {
return fmt.Sprintf("MsgCreateChapter{GuildID:%s Name:%s ParentGuildID:%s FounderReach:%s SecessionTerms:%+v Liens:%d Signer:%s}",
m.GuildID, m.Name, m.ParentGuildID, m.FounderReach, m.SecessionTerms, len(m.GoodStandingLiens), m.Signer)
}
// ProtoMessage implements proto.Message.
func (*MsgCreateChapter) ProtoMessage() {}
// ValidateBasic is the stateless validation: non-empty fields, non-empty
// ParentGuildID, SecessionTerms valid, each GoodStandingLien is
// SecuredAtFounding=true with non-empty CreditorReachID + Amount > 0
// (founding-locked liens are recorded ONCE at founding — REQ-053).
func (m *MsgCreateChapter) ValidateBasic() error {
if m.GuildID == "" {
return fmt.Errorf("guild: empty chapter guild-id")
}
if m.Name == "" {
return fmt.Errorf("guild: empty chapter name")
}
if m.ParentGuildID == "" {
return fmt.Errorf("guild: empty parent-guild-id (REQ-053 — Chapter requires a Parent)")
}
if m.ParentGuildID == m.GuildID {
return fmt.Errorf("guild: Chapter %q cannot be its own parent", m.GuildID)
}
if m.FounderReach == "" {
return fmt.Errorf("guild: empty founder-reach")
}
if m.Signer == "" {
return fmt.Errorf("guild: empty signer")
}
if err := m.SecessionTerms.Validate(); err != nil {
return fmt.Errorf("guild: secession terms: %w", err)
}
for i, l := range m.GoodStandingLiens {
if !l.SecuredAtFounding {
return fmt.Errorf("guild: GoodStandingLien[%d] has SecuredAtFounding=false (founding liens must be secured at founding — REQ-053)", i)
}
if l.CreditorReachID == "" {
return fmt.Errorf("guild: GoodStandingLien[%d] has empty CreditorReachID", i)
}
if l.Amount <= 0 {
return fmt.Errorf("guild: GoodStandingLien[%d] Amount %d <= 0", i, l.Amount)
}
}
return nil
}
// GetSigners returns the signer's reach-id as sdk.AccAddress bytes.
func (m *MsgCreateChapter) GetSigners() []sdk.AccAddress {
return []sdk.AccAddress{[]byte(m.Signer)}
}
// --- MsgOneTapExitStand -------------------------------------------------------
// MsgOneTapExitStand one-tap exits a Household Stand (REQ-057). The handler
// asserts the Stand type is Household via the StandKeeper shim + dissolves
// the Stand + returns assets to the Holder's Stash via the StashKeeper shim.
// One-tap exit is the Household dispute path (no Council vote required —
// Household skips the formal-Council requirement).
//
// ValidateBasic is stateless: non-empty stand-id + signer.
type MsgOneTapExitStand struct {
StandID string `json:"stand_id" yaml:"stand_id"`
Signer string `json:"signer" yaml:"signer"`
}
// Reset implements proto.Message.
func (m *MsgOneTapExitStand) Reset() { *m = MsgOneTapExitStand{} }
// String implements proto.Message.
func (m *MsgOneTapExitStand) String() string {
return fmt.Sprintf("MsgOneTapExitStand{StandID:%s Signer:%s}", m.StandID, m.Signer)
}
// ProtoMessage implements proto.Message.
func (*MsgOneTapExitStand) ProtoMessage() {}
// ValidateBasic is the stateless validation: non-empty stand-id + signer.
func (m *MsgOneTapExitStand) ValidateBasic() error {
if m.StandID == "" {
return fmt.Errorf("guild: empty stand-id")
}
if m.Signer == "" {
return fmt.Errorf("guild: empty signer")
}
return nil
}
// GetSigners returns the signer's reach-id as sdk.AccAddress bytes.
func (m *MsgOneTapExitStand) GetSigners() []sdk.AccAddress {
return []sdk.AccAddress{[]byte(m.Signer)}
}
// --- MsgDelegateConfederationVoice --------------------------------------------
// MsgDelegateConfederationVoice delegates a member Stand's Voice in a
// Confederation (REQ-058). The handler asserts the ConfederationStandID
// references a Confederation Stand via the StandKeeper shim + records the
// delegation (one delegation per member Stand — a duplicate delegation from
// the same MemberStandID is REJECTED). One-Stand-one-Vote: each member Stand
// gets exactly 1 Voice in the Confederation's aggregate, regardless of size.
//
// ValidateBasic is stateless: non-empty fields.
type MsgDelegateConfederationVoice struct {
ConfederationStandID string `json:"confederation_stand_id" yaml:"confederation_stand_id"`
MemberStandID string `json:"member_stand_id" yaml:"member_stand_id"`
DelegateReachID string `json:"delegate_reach_id" yaml:"delegate_reach_id"`
Signer string `json:"signer" yaml:"signer"`
}
// Reset implements proto.Message.
func (m *MsgDelegateConfederationVoice) Reset() { *m = MsgDelegateConfederationVoice{} }
// String implements proto.Message.
func (m *MsgDelegateConfederationVoice) String() string {
return fmt.Sprintf("MsgDelegateConfederationVoice{ConfederationStandID:%s MemberStandID:%s DelegateReachID:%s Signer:%s}",
m.ConfederationStandID, m.MemberStandID, m.DelegateReachID, m.Signer)
}
// ProtoMessage implements proto.Message.
func (*MsgDelegateConfederationVoice) ProtoMessage() {}
// ValidateBasic is the stateless validation: non-empty fields.
func (m *MsgDelegateConfederationVoice) ValidateBasic() error {
if m.ConfederationStandID == "" {
return fmt.Errorf("guild: empty confederation-stand-id")
}
if m.MemberStandID == "" {
return fmt.Errorf("guild: empty member-stand-id")
}
if m.DelegateReachID == "" {
return fmt.Errorf("guild: empty delegate-reach-id")
}
if m.Signer == "" {
return fmt.Errorf("guild: empty signer")
}
if m.ConfederationStandID == m.MemberStandID {
return fmt.Errorf("guild: ConfederationStandID %q cannot delegate to itself", m.ConfederationStandID)
}
return nil
}
// GetSigners returns the signer's reach-id as sdk.AccAddress bytes.
func (m *MsgDelegateConfederationVoice) GetSigners() []sdk.AccAddress {
return []sdk.AccAddress{[]byte(m.Signer)}
}
// --- MsgAddLien ---------------------------------------------------------------
// MsgAddLien adds a Good-Standing Lien to a Guild (REQ-053). The handler
// rejects any new SecuredAtFounding=true lien (founding is a one-time event —
// REQ-053/REQ-081; post-founding liens are SecuredAtFounding=false). The
// handler loads the Guild + persists the lien.
//
// ValidateBasic is stateless: non-empty guild-id, non-empty signer, Lien
// Amount > 0, non-empty CreditorReachID.
type MsgAddLien struct {
GuildID string `json:"guild_id" yaml:"guild_id"`
Lien Lien `json:"lien" yaml:"lien"`
Signer string `json:"signer" yaml:"signer"`
}
// Reset implements proto.Message.
func (m *MsgAddLien) Reset() { *m = MsgAddLien{} }
// String implements proto.Message.
func (m *MsgAddLien) String() string {
return fmt.Sprintf("MsgAddLien{GuildID:%s Lien:{Amount:%d CreditorReachID:%s SecuredAtFounding:%v} Signer:%s}",
m.GuildID, m.Lien.Amount, m.Lien.CreditorReachID, m.Lien.SecuredAtFounding, m.Signer)
}
// ProtoMessage implements proto.Message.
func (*MsgAddLien) ProtoMessage() {}
// ValidateBasic is the stateless validation: non-empty guild-id + signer,
// Lien Amount > 0, non-empty CreditorReachID.
func (m *MsgAddLien) ValidateBasic() error {
if m.GuildID == "" {
return fmt.Errorf("guild: empty guild-id")
}
if m.Signer == "" {
return fmt.Errorf("guild: empty signer")
}
if m.Lien.Amount <= 0 {
return fmt.Errorf("guild: lien Amount %d <= 0", m.Lien.Amount)
}
if m.Lien.CreditorReachID == "" {
return fmt.Errorf("guild: empty lien CreditorReachID")
}
return nil
}
// GetSigners returns the signer's reach-id as sdk.AccAddress bytes.
func (m *MsgAddLien) GetSigners() []sdk.AccAddress {
return []sdk.AccAddress{[]byte(m.Signer)}
}
// --- MsgServer interface + Response types -------------------------------------
// MsgServer is the guild module's message server interface (one method per
// Msg*). The keeper's msg_server.go implements this; module.go's
// RegisterServices wires the implementation. Hand-rolled (no protobuf
// codegen per the skeleton's zero-codegen style).
type MsgServer interface {
CreateGuild(ctx interface{}, msg *MsgCreateGuild) (*MsgCreateGuildResponse, error)
CreateChapter(ctx interface{}, msg *MsgCreateChapter) (*MsgCreateChapterResponse, error)
OneTapExitStand(ctx interface{}, msg *MsgOneTapExitStand) (*MsgOneTapExitStandResponse, error)
DelegateConfederationVoice(ctx interface{}, msg *MsgDelegateConfederationVoice) (*MsgDelegateConfederationVoiceResponse, error)
AddLien(ctx interface{}, msg *MsgAddLien) (*MsgAddLienResponse, error)
}
// --- Response types -----------------------------------------------------------
//
// Hand-rolled (no protobuf codegen). The CreateGuild + CreateChapter
// responses carry a Disclaimer string (REQ-061 — the jurisdictional
// disclaimer surfaced at every charter signing). The other responses are
// empty bodies (the response is the state mutation + event).
// MsgCreateGuildResponse is the response to MsgCreateGuild. Disclaimer is
// the jurisdictional disclaimer surfaced at signing (REQ-061).
type MsgCreateGuildResponse struct {
Disclaimer string `json:"disclaimer" yaml:"disclaimer"`
}
// Reset implements proto.Message.
func (m *MsgCreateGuildResponse) Reset() { *m = MsgCreateGuildResponse{} }
// String implements proto.Message.
func (m *MsgCreateGuildResponse) String() string {
return fmt.Sprintf("MsgCreateGuildResponse{Disclaimer:%s}", m.Disclaimer)
}
// ProtoMessage implements proto.Message.
func (*MsgCreateGuildResponse) ProtoMessage() {}
// MsgCreateChapterResponse is the response to MsgCreateChapter. Disclaimer
// is the jurisdictional disclaimer surfaced at signing (REQ-061).
type MsgCreateChapterResponse struct {
Disclaimer string `json:"disclaimer" yaml:"disclaimer"`
}
// Reset implements proto.Message.
func (m *MsgCreateChapterResponse) Reset() { *m = MsgCreateChapterResponse{} }
// String implements proto.Message.
func (m *MsgCreateChapterResponse) String() string {
return fmt.Sprintf("MsgCreateChapterResponse{Disclaimer:%s}", m.Disclaimer)
}
// ProtoMessage implements proto.Message.
func (*MsgCreateChapterResponse) ProtoMessage() {}
// MsgOneTapExitStandResponse is the response to MsgOneTapExitStand.
type MsgOneTapExitStandResponse struct{}
// Reset implements proto.Message.
func (m *MsgOneTapExitStandResponse) Reset() { *m = MsgOneTapExitStandResponse{} }
// String implements proto.Message.
func (m *MsgOneTapExitStandResponse) String() string { return "MsgOneTapExitStandResponse{}" }
// ProtoMessage implements proto.Message.
func (*MsgOneTapExitStandResponse) ProtoMessage() {}
// MsgDelegateConfederationVoiceResponse is the response to
// MsgDelegateConfederationVoice.
type MsgDelegateConfederationVoiceResponse struct{}
// Reset implements proto.Message.
func (m *MsgDelegateConfederationVoiceResponse) Reset() {
*m = MsgDelegateConfederationVoiceResponse{}
}
// String implements proto.Message.
func (m *MsgDelegateConfederationVoiceResponse) String() string {
return "MsgDelegateConfederationVoiceResponse{}"
}
// ProtoMessage implements proto.Message.
func (*MsgDelegateConfederationVoiceResponse) ProtoMessage() {}
// MsgAddLienResponse is the response to MsgAddLien.
type MsgAddLienResponse struct{}
// Reset implements proto.Message.
func (m *MsgAddLienResponse) Reset() { *m = MsgAddLienResponse{} }
// String implements proto.Message.
func (m *MsgAddLienResponse) String() string { return "MsgAddLienResponse{}" }
// ProtoMessage implements proto.Message.
func (*MsgAddLienResponse) ProtoMessage() {}
+305
View File
@@ -0,0 +1,305 @@
package types
// msg_guild_test.go holds the Msg* method coverage tests for x/guild/types
// (REQ-051, REQ-053, REQ-057, REQ-058). The Msg* Reset/String/ProtoMessage/
// ValidateBasic/GetSigners methods are exercised here so the types package
// coverage is >=80% (the keeper simtest exercises the handlers but its
// coverage counts toward the keeper package, not types).
//
// G-024: this file imports cosmos-sdk for GetSigners (sdk.AccAddress) —
// this is a Msg-method test, NOT an invariant/lexicon test, so the G-024
// stdlib-only constraint does not apply (the invariant + lexicon assertions
// live in types_test.go, which stays stdlib + lexicon-only).
import (
"strings"
"testing"
sdk "github.com/cosmos/cosmos-sdk/types"
)
// --- MsgCreateGuild methods ---------------------------------------------------
func TestMsgCreateGuildMethods(t *testing.T) {
m := &MsgCreateGuild{
GuildID: "g1", Name: "Guild", FounderReach: "reach:f",
CommonBondHash: []byte{1, 2, 3},
PublicProfile: GuildPublicProfile{BondSummary: "s", MasonCount: 7},
Signer: "reach:f",
}
if err := m.ValidateBasic(); err != nil {
t.Errorf("valid MsgCreateGuild ValidateBasic: %v", err)
}
if !strings.Contains(m.String(), "g1") {
t.Errorf("MsgCreateGuild String = %q, want to contain g1", m.String())
}
m.Reset()
if m.GuildID != "" || len(m.CommonBondHash) != 0 {
t.Errorf("MsgCreateGuild Reset did not zero: %+v", m)
}
m.ProtoMessage() // no-op coverage
m2 := &MsgCreateGuild{Signer: "reach:s"}
if got := m2.GetSigners(); len(got) != 1 || string(got[0]) != "reach:s" {
t.Errorf("MsgCreateGuild GetSigners = %v, want [reach:s]", got)
}
var _ []sdk.AccAddress = m2.GetSigners()
}
func TestMsgCreateGuildValidateBasicErrors(t *testing.T) {
cases := []struct {
name string
mut func(*MsgCreateGuild)
}{
{"empty guild-id", func(m *MsgCreateGuild) { m.GuildID = "" }},
{"empty name", func(m *MsgCreateGuild) { m.Name = "" }},
{"empty founder-reach", func(m *MsgCreateGuild) { m.FounderReach = "" }},
{"empty signer", func(m *MsgCreateGuild) { m.Signer = "" }},
{"empty common-bond-hash", func(m *MsgCreateGuild) { m.CommonBondHash = nil }},
}
for _, c := range cases {
m := &MsgCreateGuild{GuildID: "g", Name: "n", FounderReach: "r", CommonBondHash: []byte{1}, Signer: "s"}
c.mut(m)
if err := m.ValidateBasic(); err == nil {
t.Errorf("MsgCreateGuild %s: expected error, got nil", c.name)
}
}
}
// --- MsgCreateChapter methods -------------------------------------------------
func TestMsgCreateChapterMethods(t *testing.T) {
m := &MsgCreateChapter{
GuildID: "c1", Name: "Chapter", ParentGuildID: "g1", FounderReach: "reach:f",
SecessionTerms: SecessionTerms{
CoolingCoverActiveDays: CoolingSecessionCoverActiveDays,
CoolingNonCoverDays: CoolingSecessionNonCoverDays,
},
GoodStandingLiens: []Lien{{Amount: 100, CreditorReachID: "reach:c", SecuredAtFounding: true}},
Signer: "reach:f",
}
if err := m.ValidateBasic(); err != nil {
t.Errorf("valid MsgCreateChapter ValidateBasic: %v", err)
}
if !strings.Contains(m.String(), "c1") || !strings.Contains(m.String(), "g1") {
t.Errorf("MsgCreateChapter String = %q", m.String())
}
m.Reset()
if m.GuildID != "" || m.ParentGuildID != "" {
t.Errorf("MsgCreateChapter Reset did not zero: %+v", m)
}
m.ProtoMessage()
m2 := &MsgCreateChapter{Signer: "reach:s"}
if got := m2.GetSigners(); len(got) != 1 || string(got[0]) != "reach:s" {
t.Errorf("MsgCreateChapter GetSigners = %v", got)
}
}
func TestMsgCreateChapterValidateBasicErrors(t *testing.T) {
validTerms := SecessionTerms{
CoolingCoverActiveDays: CoolingSecessionCoverActiveDays,
CoolingNonCoverDays: CoolingSecessionNonCoverDays,
}
validLiens := []Lien{{Amount: 100, CreditorReachID: "reach:c", SecuredAtFounding: true}}
cases := []struct {
name string
mut func(*MsgCreateChapter)
}{
{"empty guild-id", func(m *MsgCreateChapter) { m.GuildID = "" }},
{"empty name", func(m *MsgCreateChapter) { m.Name = "" }},
{"empty parent-guild-id", func(m *MsgCreateChapter) { m.ParentGuildID = "" }},
{"self parent", func(m *MsgCreateChapter) { m.ParentGuildID = m.GuildID }},
{"empty founder-reach", func(m *MsgCreateChapter) { m.FounderReach = "" }},
{"empty signer", func(m *MsgCreateChapter) { m.Signer = "" }},
{"loose cooling (cover)", func(m *MsgCreateChapter) {
m.SecessionTerms.CoolingCoverActiveDays = CoolingSecessionCoverActiveDays - 1
}},
{"loose cooling (non-cover)", func(m *MsgCreateChapter) {
m.SecessionTerms.CoolingNonCoverDays = CoolingSecessionNonCoverDays - 1
}},
{"zero cooling (cover)", func(m *MsgCreateChapter) { m.SecessionTerms.CoolingCoverActiveDays = 0 }},
{"lien not secured at founding", func(m *MsgCreateChapter) {
m.GoodStandingLiens = []Lien{{Amount: 100, CreditorReachID: "reach:c", SecuredAtFounding: false}}
}},
{"lien empty creditor", func(m *MsgCreateChapter) {
m.GoodStandingLiens = []Lien{{Amount: 100, CreditorReachID: "", SecuredAtFounding: true}}
}},
{"lien zero amount", func(m *MsgCreateChapter) {
m.GoodStandingLiens = []Lien{{Amount: 0, CreditorReachID: "reach:c", SecuredAtFounding: true}}
}},
}
for _, c := range cases {
m := &MsgCreateChapter{
GuildID: "c", Name: "n", ParentGuildID: "g", FounderReach: "r",
SecessionTerms: validTerms, GoodStandingLiens: validLiens, Signer: "s",
}
c.mut(m)
if err := m.ValidateBasic(); err == nil {
t.Errorf("MsgCreateChapter %s: expected error, got nil", c.name)
}
}
}
// --- MsgOneTapExitStand methods -----------------------------------------------
func TestMsgOneTapExitStandMethods(t *testing.T) {
m := &MsgOneTapExitStand{StandID: "s1", Signer: "reach:h"}
if err := m.ValidateBasic(); err != nil {
t.Errorf("valid MsgOneTapExitStand ValidateBasic: %v", err)
}
if !strings.Contains(m.String(), "s1") {
t.Errorf("MsgOneTapExitStand String = %q", m.String())
}
m.Reset()
if m.StandID != "" {
t.Errorf("MsgOneTapExitStand Reset did not zero: %+v", m)
}
m.ProtoMessage()
m2 := &MsgOneTapExitStand{Signer: "reach:s"}
if got := m2.GetSigners(); len(got) != 1 || string(got[0]) != "reach:s" {
t.Errorf("MsgOneTapExitStand GetSigners = %v", got)
}
}
func TestMsgOneTapExitStandValidateBasicErrors(t *testing.T) {
if err := (&MsgOneTapExitStand{}).ValidateBasic(); err == nil {
t.Error("empty MsgOneTapExitStand should fail ValidateBasic")
}
if err := (&MsgOneTapExitStand{StandID: "s"}).ValidateBasic(); err == nil {
t.Error("MsgOneTapExitStand with empty signer should fail ValidateBasic")
}
if err := (&MsgOneTapExitStand{Signer: "s"}).ValidateBasic(); err == nil {
t.Error("MsgOneTapExitStand with empty stand-id should fail ValidateBasic")
}
}
// --- MsgDelegateConfederationVoice methods ------------------------------------
func TestMsgDelegateConfederationVoiceMethods(t *testing.T) {
m := &MsgDelegateConfederationVoice{
ConfederationStandID: "conf-1", MemberStandID: "mem-1",
DelegateReachID: "reach:d", Signer: "reach:s",
}
if err := m.ValidateBasic(); err != nil {
t.Errorf("valid MsgDelegateConfederationVoice ValidateBasic: %v", err)
}
if !strings.Contains(m.String(), "conf-1") {
t.Errorf("MsgDelegateConfederationVoice String = %q", m.String())
}
m.Reset()
if m.ConfederationStandID != "" {
t.Errorf("MsgDelegateConfederationVoice Reset did not zero: %+v", m)
}
m.ProtoMessage()
m2 := &MsgDelegateConfederationVoice{Signer: "reach:s"}
if got := m2.GetSigners(); len(got) != 1 || string(got[0]) != "reach:s" {
t.Errorf("MsgDelegateConfederationVoice GetSigners = %v", got)
}
}
func TestMsgDelegateConfederationVoiceValidateBasicErrors(t *testing.T) {
cases := []struct {
name string
mut func(*MsgDelegateConfederationVoice)
}{
{"empty confederation", func(m *MsgDelegateConfederationVoice) { m.ConfederationStandID = "" }},
{"empty member", func(m *MsgDelegateConfederationVoice) { m.MemberStandID = "" }},
{"empty delegate", func(m *MsgDelegateConfederationVoice) { m.DelegateReachID = "" }},
{"empty signer", func(m *MsgDelegateConfederationVoice) { m.Signer = "" }},
{"self-delegate", func(m *MsgDelegateConfederationVoice) { m.MemberStandID = m.ConfederationStandID }},
}
for _, c := range cases {
m := &MsgDelegateConfederationVoice{
ConfederationStandID: "c", MemberStandID: "m",
DelegateReachID: "d", Signer: "s",
}
c.mut(m)
if err := m.ValidateBasic(); err == nil {
t.Errorf("MsgDelegateConfederationVoice %s: expected error", c.name)
}
}
}
// --- MsgAddLien methods -------------------------------------------------------
func TestMsgAddLienMethods(t *testing.T) {
m := &MsgAddLien{
GuildID: "g1",
Lien: Lien{Amount: 100, CreditorReachID: "reach:c", SecuredAtFounding: false},
Signer: "reach:s",
}
if err := m.ValidateBasic(); err != nil {
t.Errorf("valid MsgAddLien ValidateBasic: %v", err)
}
if !strings.Contains(m.String(), "g1") {
t.Errorf("MsgAddLien String = %q", m.String())
}
m.Reset()
if m.GuildID != "" {
t.Errorf("MsgAddLien Reset did not zero: %+v", m)
}
m.ProtoMessage()
m2 := &MsgAddLien{Signer: "reach:s"}
if got := m2.GetSigners(); len(got) != 1 || string(got[0]) != "reach:s" {
t.Errorf("MsgAddLien GetSigners = %v", got)
}
}
func TestMsgAddLienValidateBasicErrors(t *testing.T) {
cases := []struct {
name string
mut func(*MsgAddLien)
}{
{"empty guild-id", func(m *MsgAddLien) { m.GuildID = "" }},
{"empty signer", func(m *MsgAddLien) { m.Signer = "" }},
{"zero amount", func(m *MsgAddLien) { m.Lien.Amount = 0 }},
{"negative amount", func(m *MsgAddLien) { m.Lien.Amount = -1 }},
{"empty creditor", func(m *MsgAddLien) { m.Lien.CreditorReachID = "" }},
}
for _, c := range cases {
m := &MsgAddLien{
GuildID: "g", Lien: Lien{Amount: 100, CreditorReachID: "reach:c"}, Signer: "s",
}
c.mut(m)
if err := m.ValidateBasic(); err == nil {
t.Errorf("MsgAddLien %s: expected error", c.name)
}
}
}
// --- Response type methods ----------------------------------------------------
func TestResponseMethods(t *testing.T) {
r1 := &MsgCreateGuildResponse{Disclaimer: "d"}
if !strings.Contains(r1.String(), "d") {
t.Errorf("MsgCreateGuildResponse String = %q", r1.String())
}
r1.Reset()
if r1.Disclaimer != "" {
t.Errorf("MsgCreateGuildResponse Reset did not zero: %+v", r1)
}
r1.ProtoMessage()
r2 := &MsgCreateChapterResponse{Disclaimer: "d"}
if !strings.Contains(r2.String(), "d") {
t.Errorf("MsgCreateChapterResponse String = %q", r2.String())
}
r2.Reset()
if r2.Disclaimer != "" {
t.Errorf("MsgCreateChapterResponse Reset did not zero: %+v", r2)
}
r2.ProtoMessage()
for _, r := range []interface {
Reset()
String() string
ProtoMessage()
}{
&MsgOneTapExitStandResponse{},
&MsgDelegateConfederationVoiceResponse{},
&MsgAddLienResponse{},
} {
r.ProtoMessage()
_ = r.String()
r.Reset()
}
}
+226 -13
View File
@@ -1,6 +1,7 @@
package types
import (
"crypto/sha256"
"encoding/json"
"fmt"
)
@@ -17,18 +18,162 @@ const (
// (v0.1 already encodes HandPassGuild as a 0-fee waiver reason). v0.2's Guild
// module references that waiver, doesn't redefine the fee.
HandPassFeeBps = 0
// PierCarriesVoice is the 12th locked const (GRILL D-087, FR-VOICE-6):
// the Pier wrapper does NOT carry Voice, regardless of fiduciary role.
// This is a mission-locked invariant: a Chapter retains mesh-level Voice
// (the const enforces that the optional Pier-Routed Legal Wrapper does
// NOT carry Voice). Locked-const regression in types_test.go.
PierCarriesVoice = false
// CoolingSecessionCoverActiveDays is the LOCKED protocol minimum (REQ-064)
// for a Cover-active Chapter's secession cooling period: 21 Mesh-days. A
// Chapter's SecessionTerms MAY specify a longer cooling but NOT shorter
// (the CreateChapter handler rejects shorter). Locked-const regression in
// types_test.go.
CoolingSecessionCoverActiveDays = uint32(21)
// CoolingSecessionNonCoverDays is the LOCKED protocol minimum (REQ-064)
// for a non-Cover-active Chapter's secession cooling period: 14 Mesh-days.
// A Chapter's SecessionTerms MAY specify a longer cooling but NOT shorter
// (the CreateChapter handler rejects shorter). Locked-const regression in
// types_test.go.
CoolingSecessionNonCoverDays = uint32(14)
)
// Guild is a task-oriented collective (vision §16, REQ-017). A Guild may
// optionally affiliate with a Stand (stand-affiliation-id references x/stand
// by ID string — G-003 by-ID-string invariant). founder-reach references
// x/identity Reach by string.
//
// P3 extension (REQ-051, REQ-053): the Guild carries a Common Bond
// (hash-pinned at creation — CommonBondHash) + a Public Profile
// (GuildPublicProfile). A Parent Guild (IsChapter=false, ParentGuildID="")
// may have Chapters (IsChapter=true, ParentGuildID by-ID-string). A Chapter
// pins its SecessionTerms at creation (SecessionTermsHash — the hash of the
// JSON-encoded SecessionTerms; immutable — no handler to amend it). A
// Chapter's Good-Standing Liens (GoodStandingLiens) are recorded at founding
// with SecuredAtFounding=true; post-founding liens are SecuredAtFounding=false
// (the AddLien handler rejects any new SecuredAtFounding=true lien — founding
// is a one-time event).
type Guild struct {
GuildID string `json:"guild_id" yaml:"guild_id"`
Name string `json:"name" yaml:"name"`
FounderReach string `json:"founder_reach" yaml:"founder_reach"`
CreatedAt int64 `json:"created_at" yaml:"created_at"`
StandAffiliationID string `json:"stand_affiliation_id,omitempty" yaml:"stand_affiliation_id,omitempty"`
GuildID string `json:"guild_id" yaml:"guild_id"`
Name string `json:"name" yaml:"name"`
FounderReach string `json:"founder_reach" yaml:"founder_reach"`
CreatedAt int64 `json:"created_at" yaml:"created_at"`
StandAffiliationID string `json:"stand_affiliation_id,omitempty" yaml:"stand_affiliation_id,omitempty"`
CommonBondHash []byte `json:"common_bond_hash,omitempty" yaml:"common_bond_hash,omitempty"`
PublicProfile GuildPublicProfile `json:"public_profile,omitempty" yaml:"public_profile,omitempty"`
ParentGuildID string `json:"parent_guild_id,omitempty" yaml:"parent_guild_id,omitempty"`
IsChapter bool `json:"is_chapter,omitempty" yaml:"is_chapter,omitempty"`
SecessionTermsHash []byte `json:"secession_terms_hash,omitempty" yaml:"secession_terms_hash,omitempty"`
GoodStandingLiens []Lien `json:"good_standing_liens,omitempty" yaml:"good_standing_liens,omitempty"`
}
// GuildPublicProfile is a Guild's published profile (REQ-051). BondSummary is
// a short, human-readable summary of the Common Bond (the protocol does NOT
// parse it — FR-CHTR-5). Disclaimers is the list of jurisdictional
// disclaimers the Guild publishes. MasonCount is the member count when
// disclosed; MasonCountPrivate=true means the count is NOT disclosed
// (MasonCount is 0; consumers check the bool). PierWrapperID references a
// Pier wrapper by-ID-string (G-003); empty means no Pier wrapper (the §5
// default-no-wrapper — D-087: the Pier wrapper does NOT carry Voice).
type GuildPublicProfile struct {
BondSummary string `json:"bond_summary" yaml:"bond_summary"`
Disclaimers []string `json:"disclaimers" yaml:"disclaimers"`
MasonCount uint32 `json:"mason_count" yaml:"mason_count"`
MasonCountPrivate bool `json:"mason_count_private" yaml:"mason_count_private"`
PierWrapperID string `json:"pier_wrapper_id,omitempty" yaml:"pier_wrapper_id,omitempty"`
}
// Lien is a Good-Standing Lien on a Guild (REQ-053). Amount is the lien
// amount in Grain. CreditorReachID references the creditor's Reach by string
// (G-003). SecuredAtFounding=true marks a founding-locked lien (recorded at
// Guild/Chapter creation; NOT freely increasable post-founding — the AddLien
// handler rejects any new SecuredAtFounding=true lien). CoverPoolCovenantRef
// references a Cover Pool covenant by-ID-string (G-003); empty for a lien
// with no Cover Pool covenant backing.
type Lien struct {
Amount int64 `json:"amount" yaml:"amount"`
CreditorReachID string `json:"creditor_reach_id" yaml:"creditor_reach_id"`
SecuredAtFounding bool `json:"secured_at_founding" yaml:"secured_at_founding"`
CoverPoolCovenantRef string `json:"cover_pool_covenant_ref,omitempty" yaml:"cover_pool_covenant_ref,omitempty"`
}
// SecessionTerms is a Chapter's secession cooling terms (REQ-053, REQ-064).
// Hash-pinned at Guild creation (the SecessionTermsHash on the Guild is the
// SHA-256 of this struct's JSON; immutable — no handler to amend it). The
// cooling periods are protocol-minimum-bounded: the Chapter MAY specify
// longer but NOT shorter than CoolingSecessionCoverActiveDays /
// CoolingSecessionNonCoverDays (the CreateChapter handler rejects shorter).
// LienAuditRequired marks whether a lien audit must pass before secession
// completes. CovenantClearanceRequired marks whether Cover Call / Bond
// covenant clearance must pass before secession completes.
type SecessionTerms struct {
CoolingCoverActiveDays uint32 `json:"cooling_cover_active_days" yaml:"cooling_cover_active_days"`
CoolingNonCoverDays uint32 `json:"cooling_non_cover_days" yaml:"cooling_non_cover_days"`
LienAuditRequired bool `json:"lien_audit_required" yaml:"lien_audit_required"`
CovenantClearanceRequired bool `json:"covenant_clearance_required" yaml:"covenant_clearance_required"`
}
// HashSecessionTerms returns the SHA-256 hash of the JSON-encoded
// SecessionTerms. This is the value stored on Guild.SecessionTermsHash at
// Chapter creation (immutable). The handler pins the hash, NOT the terms
// themselves (the terms are recoverable from genesis; the hash pins them
// against amendment — REQ-053 immutability).
func HashSecessionTerms(t SecessionTerms) []byte {
bz, err := json.Marshal(t)
if err != nil {
// SecessionTerms is a plain struct with only uint32/bool fields;
// json.Marshal never errors here. Panic is the defensive path.
panic(fmt.Sprintf("guild: marshal secession terms: %v", err))
}
sum := sha256.Sum256(bz)
return sum[:]
}
// ConfederationVoice is a Confederation Voice delegation record (REQ-058).
// One-Stand-one-Vote: each member Stand gets exactly 1 Voice in the
// Confederation's aggregate, regardless of size. ConfederationStandID +
// MemberStandID reference x/stand Stands by-ID-string (G-003).
// DelegateReachID references the Reach the member Stand's Voice is delegated
// to. DelegatedAt is the delegation timestamp (block time). The guild
// keeper persists this (the DelegateConfederationVoice handler records one
// delegation per member Stand — a duplicate is REJECTED).
//
// NOTE: x/stand/types defines a type-level ConfederationVoice struct too
// (the type-level addition); this guild-side struct is the persisted record
// (the guild keeper owns the delegation store). The two structs share the
// same JSON field names so a value of one round-trips through the other
// (the simtest asserts against this struct; the x/stand/types struct is the
// type-level scaffold for the aggregation logic landing in a later phase).
type ConfederationVoice struct {
ConfederationStandID string `json:"confederation_stand_id" yaml:"confederation_stand_id"`
MemberStandID string `json:"member_stand_id" yaml:"member_stand_id"`
DelegateReachID string `json:"delegate_reach_id" yaml:"delegate_reach_id"`
DelegatedAt int64 `json:"delegated_at" yaml:"delegated_at"`
}
// Validate asserts a SecessionTerms is non-zero + protocol-minimum-bounded
// (the Chapter MAY tighten the cooling but NOT loosen it below
// CoolingSecessionCoverActiveDays / CoolingSecessionNonCoverDays). The
// CreateChapter handler calls this BEFORE pinning the hash.
func (t SecessionTerms) Validate() error {
if t.CoolingCoverActiveDays == 0 {
return fmt.Errorf("guild: CoolingCoverActiveDays must be non-zero")
}
if t.CoolingNonCoverDays == 0 {
return fmt.Errorf("guild: CoolingNonCoverDays must be non-zero")
}
if t.CoolingCoverActiveDays < CoolingSecessionCoverActiveDays {
return fmt.Errorf("guild: CoolingCoverActiveDays %d < protocol minimum %d (Chapter may tighten but not loosen — REQ-053/REQ-064)",
t.CoolingCoverActiveDays, CoolingSecessionCoverActiveDays)
}
if t.CoolingNonCoverDays < CoolingSecessionNonCoverDays {
return fmt.Errorf("guild: CoolingNonCoverDays %d < protocol minimum %d (Chapter may tighten but not loosen — REQ-053/REQ-064)",
t.CoolingNonCoverDays, CoolingSecessionNonCoverDays)
}
return nil
}
// HandPass is a free (0% protocol fee) Pass-Act issued by a Guild (REQ-017).
@@ -60,17 +205,38 @@ func IssueHandPass(passID, guildID, issuerReach, recipientReach string, amountGr
}
}
// Params for the guild module (skeleton — no tunables in v0.2).
type Params struct{}
// Params for the guild module (P3 extension — REQ-064 cooling defaults).
// DefaultCoolingCoverActiveDays + DefaultCoolingNonCoverDays are the
// protocol-default cooling periods for a Chapter with no SecessionTerms
// override (the Chapter's own SecessionTerms MAY specify longer but NOT
// shorter than the protocol minimums CoolingSecessionCoverActiveDays /
// CoolingSecessionNonCoverDays).
type Params struct {
DefaultCoolingCoverActiveDays uint32 `json:"default_cooling_cover_active_days" yaml:"default_cooling_cover_active_days"`
DefaultCoolingNonCoverDays uint32 `json:"default_cooling_non_cover_days" yaml:"default_cooling_non_cover_days"`
}
func DefaultParams() Params { return Params{} }
// DefaultParams returns the Params with the protocol-minimum cooling defaults
// (CoolingSecessionCoverActiveDays / CoolingSecessionNonCoverDays — the
// Chapter MAY tighten but NOT loosen).
func DefaultParams() Params {
return Params{
DefaultCoolingCoverActiveDays: CoolingSecessionCoverActiveDays,
DefaultCoolingNonCoverDays: CoolingSecessionNonCoverDays,
}
}
// GenesisState defines the guild module genesis state (REQ-017).
// Guilds + HandPasses are the two top-level sets; ValidateGenesis enforces
// guild-id uniqueness and pass-id uniqueness.
// GenesisState defines the guild module genesis state (REQ-017, REQ-053).
// Guilds + HandPasses + Chapters are the three top-level sets; Chapters is a
// separate slice for genesis validation clarity (a Chapter is a Guild with
// IsChapter=true — the separate slice makes the Chapter→ParentGuildID
// reference check unambiguous). ValidateGenesis enforces guild-id + pass-id
// uniqueness + the Chapter→ParentGuildID reference check (a Chapter's
// ParentGuildID must reference an existing Guild in the genesis — REQ-053).
type GenesisState struct {
Params Params `json:"params" yaml:"params"`
Guilds []Guild `json:"guilds" yaml:"guilds"`
Chapters []Guild `json:"chapters,omitempty" yaml:"chapters,omitempty"`
HandPasses []HandPass `json:"hand_passes" yaml:"hand_passes"`
}
@@ -78,19 +244,40 @@ func DefaultGenesisState() *GenesisState {
return &GenesisState{
Params: DefaultParams(),
Guilds: []Guild{},
Chapters: []Guild{},
HandPasses: []HandPass{},
}
}
// Reset implements proto.Message (required by codec.JSONCodec for
// InitGenesis/ExportGenesis).
func (m *GenesisState) Reset() { *m = GenesisState{} }
// String implements proto.Message.
func (m *GenesisState) String() string {
return fmt.Sprintf("GenesisState{Guilds:%d Chapters:%d HandPasses:%d}",
len(m.Guilds), len(m.Chapters), len(m.HandPasses))
}
// ProtoMessage implements proto.Message.
func (*GenesisState) ProtoMessage() {}
// ValidateGenesis performs ID-uniqueness checks (A-212 upgrade from v0.1
// no-op): rejects duplicate guild-ids and duplicate pass-ids. Also enforces
// the 0-fee covenant on genesis HandPasses (FeeGrain must be 0).
// the 0-fee covenant on genesis HandPasses (FeeGrain must be 0). P3
// extension (REQ-053): a Chapter (Guild with IsChapter=true, in either the
// Guilds or Chapters slice) must have a non-empty ParentGuildID referencing
// an existing Guild in the genesis (the parent must be a non-Chapter Guild).
func ValidateGenesis(bz json.RawMessage) error {
var gs GenesisState
if err := json.Unmarshal(bz, &gs); err != nil {
return fmt.Errorf("guild: invalid genesis: %w", err)
}
seenGuild := make(map[string]bool, len(gs.Guilds))
// Index all guild-ids across the Guilds + Chapters slices for the
// Chapter→ParentGuildID reference check. Reject duplicate guild-ids
// across BOTH slices (a Chapter may not share a guild-id with a Parent
// Guild).
seenGuild := make(map[string]bool, len(gs.Guilds)+len(gs.Chapters))
for _, g := range gs.Guilds {
if g.GuildID == "" {
return fmt.Errorf("guild: empty guild-id")
@@ -99,6 +286,32 @@ func ValidateGenesis(bz json.RawMessage) error {
return fmt.Errorf("guild: duplicate guild-id %q", g.GuildID)
}
seenGuild[g.GuildID] = true
// A Guild in the Guilds slice with IsChapter=true is rejected (a
// Chapter must live in the Chapters slice — the split is for genesis
// validation clarity).
if g.IsChapter {
return fmt.Errorf("guild: Guild %q has IsChapter=true but is in the Guilds slice (move to Chapters)", g.GuildID)
}
}
for _, c := range gs.Chapters {
if c.GuildID == "" {
return fmt.Errorf("guild: empty chapter guild-id")
}
if seenGuild[c.GuildID] {
return fmt.Errorf("guild: duplicate guild-id %q (Chapter)", c.GuildID)
}
seenGuild[c.GuildID] = true
// REQ-053: a Chapter must have IsChapter=true + a non-empty
// ParentGuildID referencing an existing Guild.
if !c.IsChapter {
return fmt.Errorf("guild: Chapter %q has IsChapter=false (Chapters slice requires IsChapter=true)", c.GuildID)
}
if c.ParentGuildID == "" {
return fmt.Errorf("guild: Chapter %q has empty ParentGuildID (REQ-053)", c.GuildID)
}
if !seenGuild[c.ParentGuildID] {
return fmt.Errorf("guild: Chapter %q ParentGuildID %q not found in genesis (REQ-053)", c.GuildID, c.ParentGuildID)
}
}
seenPass := make(map[string]bool, len(gs.HandPasses))
for _, p := range gs.HandPasses {
+324 -7
View File
@@ -221,14 +221,16 @@ func TestDefaultParams(t *testing.T) {
// --- Lexicon assertion (REQ-012) -------------------------------------------------
// TestLexiconNoBannedTermsInGuildPackage scans every non-test .go file in
// the guild/types package directory for the 9 banned terms (case-insensitive).
// Production files only — the test file contains the banned terms as the list
// of things to forbid (standard lexicon-test bootstrapping pattern).
// the x/guild module tree (types + keeper + module.go) for the 10 banned
// terms (case-insensitive). Production files only — the test file contains
// the banned terms as the list of things to forbid (standard lexicon-test
// bootstrapping pattern). The scan walks x/guild/**/*.go (the spec's
// `x/guild/**/*.go` lexicon assertion for P3).
func TestLexiconNoBannedTermsInGuildPackage(t *testing.T) {
pkgDir := packageDir(t, "github.com/oy/openyield/x/guild/types")
files, err := filepath.Glob(filepath.Join(pkgDir, "*.go"))
guildDir := packageDir(t, "github.com/oy/openyield/x/guild")
files, err := walkGoFiles(guildDir)
if err != nil {
t.Fatalf("glob: %v", err)
t.Fatalf("walk: %v", err)
}
prodFiles := []string{}
for _, f := range files {
@@ -238,7 +240,7 @@ func TestLexiconNoBannedTermsInGuildPackage(t *testing.T) {
prodFiles = append(prodFiles, f)
}
if len(prodFiles) == 0 {
t.Fatal("no production .go files found in guild/types")
t.Fatal("no production .go files found in x/guild")
}
for _, f := range prodFiles {
bz, err := os.ReadFile(f)
@@ -251,6 +253,321 @@ func TestLexiconNoBannedTermsInGuildPackage(t *testing.T) {
}
}
// walkGoFiles returns all .go files under dir (recursively).
func walkGoFiles(dir string) ([]string, error) {
var out []string
err := filepath.Walk(dir, func(path string, info os.FileInfo, err error) error {
if err != nil {
return err
}
if info.IsDir() {
return nil
}
if strings.HasSuffix(path, ".go") {
out = append(out, path)
}
return nil
})
return out, err
}
// --- P3 locked-const regression (REQ-064, D-087) -------------------------------
// TestPierCarriesVoiceLockedConst asserts D-087: PierCarriesVoice == false
// (FR-VOICE-6: the Pier wrapper does NOT carry Voice, regardless of
// fiduciary role — mission-locked invariant). A regression firewall:
// changing PierCarriesVoice to true breaks this test.
func TestPierCarriesVoiceLockedConst(t *testing.T) {
if types.PierCarriesVoice {
t.Errorf("PierCarriesVoice = true, expected false (D-087 FR-VOICE-6: Pier does NOT carry Voice)")
}
}
// TestCoolingSecessionLockedConsts asserts REQ-064: the protocol-minimum
// cooling periods for Chapter secession (21d Cover-active, 14d non-Cover).
// A Chapter's SecessionTerms MAY specify longer but NOT shorter (the
// CreateChapter handler rejects shorter). Regression firewall: changing
// these consts breaks this test.
func TestCoolingSecessionLockedConsts(t *testing.T) {
if types.CoolingSecessionCoverActiveDays != 21 {
t.Errorf("CoolingSecessionCoverActiveDays = %d, expected 21 (REQ-064 LOCKED)",
types.CoolingSecessionCoverActiveDays)
}
if types.CoolingSecessionNonCoverDays != 14 {
t.Errorf("CoolingSecessionNonCoverDays = %d, expected 14 (REQ-064 LOCKED)",
types.CoolingSecessionNonCoverDays)
}
}
// --- P3 Guild struct extension (REQ-051, REQ-053) ------------------------------
// TestGuildP3Fields asserts the Guild struct carries the P3 extension fields
// (CommonBondHash, PublicProfile, ParentGuildID, IsChapter,
// SecessionTermsHash, GoodStandingLiens) — a compile-time + runtime
// regression firewall (removing any field breaks this test).
func TestGuildP3Fields(t *testing.T) {
g := types.Guild{
GuildID: "g1",
Name: "Parent",
FounderReach: "reach:f",
CommonBondHash: []byte{1, 2, 3},
PublicProfile: types.GuildPublicProfile{BondSummary: "sum", MasonCount: 7},
ParentGuildID: "",
IsChapter: false,
SecessionTermsHash: nil,
GoodStandingLiens: []types.Lien{{Amount: 100, CreditorReachID: "reach:c", SecuredAtFounding: true}},
}
if g.CommonBondHash == nil || len(g.CommonBondHash) != 3 {
t.Errorf("CommonBondHash = %v, want 3 bytes", g.CommonBondHash)
}
if g.PublicProfile.BondSummary != "sum" || g.PublicProfile.MasonCount != 7 {
t.Errorf("PublicProfile = %+v", g.PublicProfile)
}
if g.IsChapter {
t.Errorf("IsChapter = true, want false for a Parent Guild")
}
if g.ParentGuildID != "" {
t.Errorf("ParentGuildID = %q, want empty for a Parent Guild", g.ParentGuildID)
}
if len(g.GoodStandingLiens) != 1 || !g.GoodStandingLiens[0].SecuredAtFounding {
t.Errorf("GoodStandingLiens = %v", g.GoodStandingLiens)
}
// Chapter variant.
c := types.Guild{
GuildID: "c1",
Name: "Chapter",
FounderReach: "reach:f",
ParentGuildID: "g1",
IsChapter: true,
SecessionTermsHash: []byte{9, 9, 9},
GoodStandingLiens: []types.Lien{{Amount: 50, CreditorReachID: "reach:c2", SecuredAtFounding: true}},
}
if !c.IsChapter || c.ParentGuildID != "g1" {
t.Errorf("Chapter fields: IsChapter=%v ParentGuildID=%q", c.IsChapter, c.ParentGuildID)
}
if len(c.SecessionTermsHash) != 3 {
t.Errorf("SecessionTermsHash = %v, want 3 bytes", c.SecessionTermsHash)
}
}
// TestGuildPublicProfileMasonCountPrivate asserts the MasonCountPrivate bool:
// when true, the MasonCount is NOT disclosed (the field is 0; consumers
// check the bool).
func TestGuildPublicProfileMasonCountPrivate(t *testing.T) {
disclosed := types.GuildPublicProfile{BondSummary: "s", MasonCount: 42, MasonCountPrivate: false}
if disclosed.MasonCountPrivate || disclosed.MasonCount != 42 {
t.Errorf("disclosed profile: %+v", disclosed)
}
private := types.GuildPublicProfile{BondSummary: "s", MasonCount: 0, MasonCountPrivate: true}
if !private.MasonCountPrivate {
t.Errorf("private profile: MasonCountPrivate = false, want true")
}
if private.MasonCount != 0 {
t.Errorf("private profile: MasonCount = %d, want 0 (not disclosed)", private.MasonCount)
}
}
// TestLienStruct asserts the Lien struct carries the four required fields
// (Amount, CreditorReachID, SecuredAtFounding, CoverPoolCovenantRef).
func TestLienStruct(t *testing.T) {
l := types.Lien{
Amount: 1000,
CreditorReachID: "reach:cred",
SecuredAtFounding: true,
CoverPoolCovenantRef: "covenant-1",
}
if l.Amount != 1000 || l.CreditorReachID != "reach:cred" ||
!l.SecuredAtFounding || l.CoverPoolCovenantRef != "covenant-1" {
t.Errorf("Lien fields: %+v", l)
}
// A lien with no Cover Pool covenant backing (empty ref) is valid.
l2 := types.Lien{Amount: 500, CreditorReachID: "reach:c", SecuredAtFounding: false}
if l2.CoverPoolCovenantRef != "" {
t.Errorf("Lien2 CoverPoolCovenantRef = %q, want empty", l2.CoverPoolCovenantRef)
}
}
// TestSecessionTermsStruct asserts the SecessionTerms struct + its Validate
// method (non-zero + protocol-minimum-bounded).
func TestSecessionTermsStruct(t *testing.T) {
// Valid: exactly the protocol minimums.
valid := types.SecessionTerms{
CoolingCoverActiveDays: types.CoolingSecessionCoverActiveDays,
CoolingNonCoverDays: types.CoolingSecessionNonCoverDays,
LienAuditRequired: true,
CovenantClearanceRequired: true,
}
if err := valid.Validate(); err != nil {
t.Errorf("valid SecessionTerms Validate: %v", err)
}
// Valid: tighter than the protocol minimum (longer cooling allowed).
tighter := types.SecessionTerms{
CoolingCoverActiveDays: types.CoolingSecessionCoverActiveDays + 10,
CoolingNonCoverDays: types.CoolingSecessionNonCoverDays + 5,
}
if err := tighter.Validate(); err != nil {
t.Errorf("tighter SecessionTerms Validate: %v", err)
}
// Invalid: zero CoolingCoverActiveDays.
if err := (types.SecessionTerms{CoolingNonCoverDays: 14}).Validate(); err == nil {
t.Error("SecessionTerms with zero CoolingCoverActiveDays should fail Validate")
}
// Invalid: zero CoolingNonCoverDays.
if err := (types.SecessionTerms{CoolingCoverActiveDays: 21}).Validate(); err == nil {
t.Error("SecessionTerms with zero CoolingNonCoverDays should fail Validate")
}
// Invalid: CoolingCoverActiveDays below protocol minimum (looser).
loose := types.SecessionTerms{
CoolingCoverActiveDays: types.CoolingSecessionCoverActiveDays - 1,
CoolingNonCoverDays: types.CoolingSecessionNonCoverDays,
}
if err := loose.Validate(); err == nil {
t.Error("SecessionTerms with CoolingCoverActiveDays below minimum should fail Validate (Chapter may tighten but not loosen)")
}
// Invalid: CoolingNonCoverDays below protocol minimum (looser).
loose2 := types.SecessionTerms{
CoolingCoverActiveDays: types.CoolingSecessionCoverActiveDays,
CoolingNonCoverDays: types.CoolingSecessionNonCoverDays - 1,
}
if err := loose2.Validate(); err == nil {
t.Error("SecessionTerms with CoolingNonCoverDays below minimum should fail Validate (Chapter may tighten but not loosen)")
}
}
// TestHashSecessionTermsDeterministic asserts HashSecessionTerms is
// deterministic (the same terms produce the same hash; different terms
// produce a different hash). This is the immutability pin: the
// SecessionTermsHash on a Chapter is the hash of its SecessionTerms JSON.
func TestHashSecessionTermsDeterministic(t *testing.T) {
t1 := types.SecessionTerms{CoolingCoverActiveDays: 21, CoolingNonCoverDays: 14}
t2 := types.SecessionTerms{CoolingCoverActiveDays: 21, CoolingNonCoverDays: 14}
if !bytesEqual(types.HashSecessionTerms(t1), types.HashSecessionTerms(t2)) {
t.Error("HashSecessionTerms not deterministic for equal terms")
}
t3 := types.SecessionTerms{CoolingCoverActiveDays: 31, CoolingNonCoverDays: 14}
if bytesEqual(types.HashSecessionTerms(t1), types.HashSecessionTerms(t3)) {
t.Error("HashSecessionTerms collided for different terms")
}
}
// bytesEqual is a stdlib-only byte-slice equality helper (the types_test.go
// stays stdlib-only per G-024 — no bytes import needed for this trivial
// comparison).
func bytesEqual(a, b []byte) bool {
if len(a) != len(b) {
return false
}
for i := range a {
if a[i] != b[i] {
return false
}
}
return true
}
// --- P3 Params + GenesisState extension ---------------------------------------
// TestDefaultParamsCooling asserts DefaultParams returns the protocol-minimum
// cooling defaults (CoolingSecessionCoverActiveDays / NonCoverDays).
func TestDefaultParamsCooling(t *testing.T) {
p := types.DefaultParams()
if p.DefaultCoolingCoverActiveDays != types.CoolingSecessionCoverActiveDays {
t.Errorf("DefaultCoolingCoverActiveDays = %d, want %d",
p.DefaultCoolingCoverActiveDays, types.CoolingSecessionCoverActiveDays)
}
if p.DefaultCoolingNonCoverDays != types.CoolingSecessionNonCoverDays {
t.Errorf("DefaultCoolingNonCoverDays = %d, want %d",
p.DefaultCoolingNonCoverDays, types.CoolingSecessionNonCoverDays)
}
}
// TestDefaultGenesisStateChapters asserts DefaultGenesisState returns a
// non-nil empty Chapters slice.
func TestDefaultGenesisStateChapters(t *testing.T) {
gs := types.DefaultGenesisState()
if gs.Chapters == nil || len(gs.Chapters) != 0 {
t.Errorf("Default Chapters should be non-nil empty slice, got %v", gs.Chapters)
}
}
// TestValidateGenesisRejectsChapterMissingParent asserts REQ-053: a Chapter
// (in the Chapters slice) with an empty ParentGuildID is REJECTED.
func TestValidateGenesisRejectsChapterMissingParent(t *testing.T) {
gs := types.GenesisState{
Guilds: []types.Guild{{GuildID: "g1"}},
Chapters: []types.Guild{{GuildID: "c1", IsChapter: true, ParentGuildID: ""}},
}
bz, _ := json.Marshal(gs)
if err := types.ValidateGenesis(bz); err == nil {
t.Error("ValidateGenesis should reject Chapter with empty ParentGuildID (REQ-053)")
}
}
// TestValidateGenesisRejectsChapterParentNotFound asserts REQ-053: a Chapter
// whose ParentGuildID does not reference an existing Guild is REJECTED.
func TestValidateGenesisRejectsChapterParentNotFound(t *testing.T) {
gs := types.GenesisState{
Chapters: []types.Guild{{GuildID: "c1", IsChapter: true, ParentGuildID: "no-such-parent"}},
}
bz, _ := json.Marshal(gs)
if err := types.ValidateGenesis(bz); err == nil {
t.Error("ValidateGenesis should reject Chapter with ParentGuildID not in genesis (REQ-053)")
}
}
// TestValidateGenesisAcceptsChapterWithParent asserts a Chapter with a
// valid ParentGuildID (referencing an existing Guild) is accepted.
func TestValidateGenesisAcceptsChapterWithParent(t *testing.T) {
gs := types.GenesisState{
Guilds: []types.Guild{{GuildID: "g1"}},
Chapters: []types.Guild{{GuildID: "c1", IsChapter: true, ParentGuildID: "g1"}},
HandPasses: []types.HandPass{{PassID: "p1", GuildID: "g1", FeeGrain: 0}},
}
bz, _ := json.Marshal(gs)
if err := types.ValidateGenesis(bz); err != nil {
t.Errorf("ValidateGenesis should accept Chapter with valid parent, got: %v", err)
}
}
// TestValidateGenesisRejectsChapterInGuildsSlice asserts a Guild in the
// Guilds slice with IsChapter=true is REJECTED (a Chapter must live in the
// Chapters slice — the split is for genesis validation clarity).
func TestValidateGenesisRejectsChapterInGuildsSlice(t *testing.T) {
gs := types.GenesisState{
Guilds: []types.Guild{{GuildID: "g1", IsChapter: true}},
}
bz, _ := json.Marshal(gs)
if err := types.ValidateGenesis(bz); err == nil {
t.Error("ValidateGenesis should reject a Chapter in the Guilds slice (move to Chapters)")
}
}
// TestValidateGenesisRejectsNonChapterInChaptersSlice asserts a Guild in
// the Chapters slice with IsChapter=false is REJECTED.
func TestValidateGenesisRejectsNonChapterInChaptersSlice(t *testing.T) {
gs := types.GenesisState{
Chapters: []types.Guild{{GuildID: "c1", IsChapter: false, ParentGuildID: "g1"}},
}
bz, _ := json.Marshal(gs)
if err := types.ValidateGenesis(bz); err == nil {
t.Error("ValidateGenesis should reject a non-Chapter in the Chapters slice")
}
}
// TestValidateGenesisRejectsDupChapterID asserts a duplicate guild-id across
// the Guilds + Chapters slices is REJECTED.
func TestValidateGenesisRejectsDupChapterID(t *testing.T) {
gs := types.GenesisState{
Guilds: []types.Guild{{GuildID: "g1"}},
Chapters: []types.Guild{{GuildID: "g1", IsChapter: true, ParentGuildID: "g1"}},
}
bz, _ := json.Marshal(gs)
if err := types.ValidateGenesis(bz); err == nil {
t.Error("ValidateGenesis should reject duplicate guild-id across Guilds + Chapters")
}
}
// packageDir resolves a Go import path to its filesystem directory.
func packageDir(t *testing.T, importPath string) string {
t.Helper()
+2 -2
View File
@@ -33,7 +33,7 @@ const (
PactPause PactType = "Pause" // circuit-breaker commitment (wraps x/still)
PactGround PactType = "Ground" // earth-anchored collateral lock commitment
PactStance PactType = "Stance" // public-position / attestation commitment
PactCover PactType = "Cover" // insurance-like commitment (Cover Pool)
PactCover PactType = "Cover" // Cover-like commitment (Cover Pool)
PactStandRegistry PactType = "StandRegistry" // registers a Stand into the canonical registry
PactHubAPI PactType = "HubAPI" // B2B backbone commitment
)
@@ -155,7 +155,7 @@ func (p *Pact) ExecuteStance() error {
return nil
}
// ExecuteCover is the execute-entry stub for a Cover Pact (insurance-like).
// ExecuteCover is the execute-entry stub for a Cover Pact (Cover-like).
// Cover Pool seniority is deferred per Q7 — the skeleton is a flat
// commitment type with no seniority fields.
func (p *Pact) ExecuteCover() error {
+34
View File
@@ -50,6 +50,40 @@ func AllStandTypes() []StandType {
}
}
// IsHousehold reports whether a StandType is a Household (REQ-057). The
// x/guild OneTapExitStand handler (via the StandKeeper shim) consults this
// to assert one-tap exit is Household-only. By-ID-string boundary (G-003):
// the handler compares the stand-type string against "Household"; this
// helper is the type-level scaffold.
func IsHousehold(t StandType) bool { return t == StandHousehold }
// IsConfederation reports whether a StandType is a Confederation (REQ-058).
// The x/guild DelegateConfederationVoice handler (via the StandKeeper shim)
// consults this to assert the named Stand is a Confederation before
// recording a delegation. By-ID-string boundary (G-003): the handler
// compares the stand-type string against "Confederation"; this helper is the
// type-level scaffold.
func IsConfederation(t StandType) bool { return t == StandConfederation }
// ConfederationVoice is a Confederation Voice delegation record (REQ-058).
// One-Stand-one-Vote: each member Stand gets exactly 1 Voice in the
// Confederation's aggregate, regardless of size. ConfederationStandID +
// MemberStandID reference Stands by-ID-string (G-003). DelegateReachID
// references the Reach the member Stand's Voice is delegated to.
// DelegatedAt is the delegation timestamp (block time).
//
// NOTE: the x/guild keeper owns the persisted delegation record (the
// x/guild/types.ConfederationVoice struct is the persisted shape — same JSON
// field names so a value of one round-trips through the other). This
// x/stand/types struct is the type-level scaffold for the Confederation
// Voice aggregation logic landing in a later phase.
type ConfederationVoice struct {
ConfederationStandID string `json:"confederation_stand_id" yaml:"confederation_stand_id"`
MemberStandID string `json:"member_stand_id" yaml:"member_stand_id"`
DelegateReachID string `json:"delegate_reach_id" yaml:"delegate_reach_id"`
DelegatedAt int64 `json:"delegated_at" yaml:"delegated_at"`
}
// Stand is a governed group holding a Vault (vision §11, REQ-016).
// Modeled on Cosmos SDK x/group (a group of members with a decision policy
// governing a Vault). admin-reach references a Reach ID (by-ID-string, G-003);
+49
View File
@@ -249,6 +249,55 @@ func TestDefaultParams(t *testing.T) {
_ = types.DefaultParams() // no panics
}
// --- P3 Household / Confederation helpers (REQ-057, REQ-058) ------------------
// TestIsHousehold asserts IsHousehold returns true only for StandHousehold.
func TestIsHousehold(t *testing.T) {
if !types.IsHousehold(types.StandHousehold) {
t.Error("IsHousehold(Household) should be true")
}
for _, s := range types.AllStandTypes() {
if s == types.StandHousehold {
continue
}
if types.IsHousehold(s) {
t.Errorf("IsHousehold(%q) should be false", s)
}
}
}
// TestIsConfederation asserts IsConfederation returns true only for
// StandConfederation.
func TestIsConfederation(t *testing.T) {
if !types.IsConfederation(types.StandConfederation) {
t.Error("IsConfederation(Confederation) should be true")
}
for _, s := range types.AllStandTypes() {
if s == types.StandConfederation {
continue
}
if types.IsConfederation(s) {
t.Errorf("IsConfederation(%q) should be false", s)
}
}
}
// TestConfederationVoiceStruct asserts the ConfederationVoice struct carries
// the four required fields (ConfederationStandID, MemberStandID,
// DelegateReachID, DelegatedAt — REQ-058).
func TestConfederationVoiceStruct(t *testing.T) {
v := types.ConfederationVoice{
ConfederationStandID: "conf-1",
MemberStandID: "mem-1",
DelegateReachID: "reach:delegate",
DelegatedAt: 12345,
}
if v.ConfederationStandID != "conf-1" || v.MemberStandID != "mem-1" ||
v.DelegateReachID != "reach:delegate" || v.DelegatedAt != 12345 {
t.Errorf("ConfederationVoice fields: %+v", v)
}
}
// --- Lexicon assertion (REQ-012) -------------------------------------------------
// TestLexiconNoBannedTermsInStandPackage scans every non-test .go file in