proof-aware-crypto-tooling-.../tests
mrwulf 7c717d03fc Log accountability: STH pinning, consistency enforcement, freshness, monitor
A transparency log without split-view defense is just a signature with
extra steps: the provider could serve one tree to the agent and another
to the world, or roll the log back, and standalone receipt verification
would never notice. The primitives (RFC 9162 consistency proofs) were
already implemented and correct; this closes the loop on the AGENT side.

- src/pacta/sthstore.py: a local STH pin store. Unknown log -> pin
  (trust-on-first-use, recorded as such). Same tree size -> the root
  must match the pin byte-for-byte; a mismatch is named EQUIVOCATION
  and is a hard rejection. Larger tree -> a consistency proof FROM THE
  PINNED SIZE is required and verified before the pin advances
  (receipts already embed a from-previous anchor; the anchor's root is
  itself checked against the pin so a lying anchor cannot bridge a
  split view). Smaller tree -> LOG ROLLBACK, hard rejection.
- Freshness policy: --max-sth-age-seconds rejects stale (or
  future-dated) tree heads - an old-but-valid STH can hide later
  entries.
- Wired into receipt-verify, claims, and agent (--sth-store,
  --consistency-proof, --max-sth-age-seconds); evidence records the
  pin action; any accountability failure fails the receipt closed.
- Provider: log-consistency --from-size N (serve proofs for pinning
  agents whose pin is older than the receipt's embedded anchor) and
  log-audit (monitor self-check: recompute the tree, verify the stored
  STH and per-entry leaf hashes).

Live drill in this commit's validation: pin-on-first-use -> matched ->
grown-with-proof advance -> a real forged same-size split view REJECTED
with the equivocation diagnostic -> freshness rejection -> clean
self-audit. tests/test_sthstore.py covers pin/match/equivocation,
growth-without-proof, lying consistency anchors, rollback, freshness.
45/45 tests green.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-06 10:08:34 +02:00
..
fixtures/mini-ed25519-verified/verification initial proof-aware tooling prototype 2026-07-03 10:51:03 +02:00
test_agent.py add policy-gated agent consequences 2026-07-03 11:05:06 +02:00
test_artifact.py add policy-gated agent consequences 2026-07-03 11:05:06 +02:00
test_attestation.py Estate sync: boundary-axiom vocabulary + the four-tier apex reality (R4) 2026-07-06 10:04:43 +02:00
test_boundaries.py Estate sync: boundary-axiom vocabulary + the four-tier apex reality (R4) 2026-07-06 10:04:43 +02:00
test_claim_cards.py initial proof-aware tooling prototype 2026-07-03 10:51:03 +02:00
test_claim_failures.py add policy-gated agent consequences 2026-07-03 11:05:06 +02:00
test_curriculum_notebooks.py add proof-aware crypto curriculum notebooks 2026-07-03 14:42:59 +02:00
test_doctor.py add verifier bootstrap and attestation lane 2026-07-03 11:24:13 +02:00
test_hygiene.py initial proof-aware tooling prototype 2026-07-03 10:51:03 +02:00
test_lean.py add nested proof check provider 2026-07-03 13:03:58 +02:00
test_manifest_parsing.py initial proof-aware tooling prototype 2026-07-03 10:51:03 +02:00
test_profiles.py Estate sync: boundary-axiom vocabulary + the four-tier apex reality (R4) 2026-07-06 10:04:43 +02:00
test_provider.py Estate sync: boundary-axiom vocabulary + the four-tier apex reality (R4) 2026-07-06 10:04:43 +02:00
test_risk.py add verifier bootstrap and attestation lane 2026-07-03 11:24:13 +02:00
test_signing.py add nested proof check provider 2026-07-03 13:03:58 +02:00
test_sthstore.py Log accountability: STH pinning, consistency enforcement, freshness, monitor 2026-07-06 10:08:34 +02:00
test_transparency.py add transparency log trust provider 2026-07-03 14:09:34 +02:00