convex-tasty-streaming
Safe HaskellSafe-Inferred
LanguageHaskell2010

Convex.Tasty.Streaming.TMSummary

Synopsis

Documentation

data ThreatModelSummary Source #

Structured summary of a threat-model test case.

Constructors

ThreatModelSummary 

Fields

Instances

Instances details
FromJSON ThreatModelSummary Source # 
Instance details

Defined in Convex.Tasty.Streaming.TMSummary

ToJSON ThreatModelSummary Source # 
Instance details

Defined in Convex.Tasty.Streaming.TMSummary

Generic ThreatModelSummary Source # 
Instance details

Defined in Convex.Tasty.Streaming.TMSummary

Associated Types

type Rep ThreatModelSummary :: Type -> Type #

Show ThreatModelSummary Source # 
Instance details

Defined in Convex.Tasty.Streaming.TMSummary

Eq ThreatModelSummary Source # 
Instance details

Defined in Convex.Tasty.Streaming.TMSummary

type Rep ThreatModelSummary Source # 
Instance details

Defined in Convex.Tasty.Streaming.TMSummary

data ThreatModelCategory Source #

Which list of a suite's ThreatModelsFor instance a threat model was run from. It decides how the counts in a ThreatModelSummary are to be read: the same tmsFailed (the attack's mutated transaction still validated) is a vulnerability for a Claimed model, the required outcome for an Expected one, and a known, tolerated artifact for an Accepted one. A consumer that alerts on failed > 0 must therefore filter on the category first.

Constructors

Claimed

From threatModels: the contract is claimed secure against it; a detection fails the test.

Expected

From expectedVulnerabilities: the contract is known vulnerable; no detection fails the test.

Accepted

From acceptedFindings: the finding is a known benign artifact. Judged like Expected - a detection is the required outcome.

Surveyed

From candidateModels: run for information. Reported, but never failed for not applying.

NotApplicable

From notApplicable: reviewed as not applying here; it applying at all fails the test.

Instances

Instances details
FromJSON ThreatModelCategory Source # 
Instance details

Defined in Convex.Tasty.Streaming.TMSummary

ToJSON ThreatModelCategory Source # 
Instance details

Defined in Convex.Tasty.Streaming.TMSummary

Bounded ThreatModelCategory Source # 
Instance details

Defined in Convex.Tasty.Streaming.TMSummary

Enum ThreatModelCategory Source # 
Instance details

Defined in Convex.Tasty.Streaming.TMSummary

Generic ThreatModelCategory Source # 
Instance details

Defined in Convex.Tasty.Streaming.TMSummary

Associated Types

type Rep ThreatModelCategory :: Type -> Type #

Show ThreatModelCategory Source # 
Instance details

Defined in Convex.Tasty.Streaming.TMSummary

Eq ThreatModelCategory Source # 
Instance details

Defined in Convex.Tasty.Streaming.TMSummary

Ord ThreatModelCategory Source # 
Instance details

Defined in Convex.Tasty.Streaming.TMSummary

type Rep ThreatModelCategory Source # 
Instance details

Defined in Convex.Tasty.Streaming.TMSummary

type Rep ThreatModelCategory = D1 ('MetaData "ThreatModelCategory" "Convex.Tasty.Streaming.TMSummary" "convex-tasty-streaming-0.1.0.0-inplace" 'False) ((C1 ('MetaCons "Claimed" 'PrefixI 'False) (U1 :: Type -> Type) :+: C1 ('MetaCons "Expected" 'PrefixI 'False) (U1 :: Type -> Type)) :+: (C1 ('MetaCons "Accepted" 'PrefixI 'False) (U1 :: Type -> Type) :+: (C1 ('MetaCons "Surveyed" 'PrefixI 'False) (U1 :: Type -> Type) :+: C1 ('MetaCons "NotApplicable" 'PrefixI 'False) (U1 :: Type -> Type))))

data Fault Source #

Whose fault a failing threat-model test case is.

Only one cell of the slot-by-outcome matrix is the contract's fault; most red is a stale declaration. Saying which lets a reader — or a dashboard — tell "the contract regressed" from "somebody needs to update the instance", and stops a resolved vulnerability from reading as a broken contract.

Constructors

Contract

The script is at fault: fix the contract.

Declaration

The ThreatModelsFor instance is stale or wrong: edit the declaration.

Setup

The attack could not be carried out: fix the generator, or accept a harness limit.

Instances

Instances details
FromJSON Fault Source # 
Instance details

Defined in Convex.Tasty.Streaming.TMSummary

ToJSON Fault Source # 
Instance details

Defined in Convex.Tasty.Streaming.TMSummary

Bounded Fault Source # 
Instance details

Defined in Convex.Tasty.Streaming.TMSummary

Enum Fault Source # 
Instance details

Defined in Convex.Tasty.Streaming.TMSummary

Generic Fault Source # 
Instance details

Defined in Convex.Tasty.Streaming.TMSummary

Associated Types

type Rep Fault :: Type -> Type #

Methods

from :: Fault -> Rep Fault x #

to :: Rep Fault x -> Fault #

Show Fault Source # 
Instance details

Defined in Convex.Tasty.Streaming.TMSummary

Methods

showsPrec :: Int -> Fault -> ShowS #

show :: Fault -> String #

showList :: [Fault] -> ShowS #

Eq Fault Source # 
Instance details

Defined in Convex.Tasty.Streaming.TMSummary

Methods

(==) :: Fault -> Fault -> Bool #

(/=) :: Fault -> Fault -> Bool #

Ord Fault Source # 
Instance details

Defined in Convex.Tasty.Streaming.TMSummary

Methods

compare :: Fault -> Fault -> Ordering #

(<) :: Fault -> Fault -> Bool #

(<=) :: Fault -> Fault -> Bool #

(>) :: Fault -> Fault -> Bool #

(>=) :: Fault -> Fault -> Bool #

max :: Fault -> Fault -> Fault #

min :: Fault -> Fault -> Fault #

type Rep Fault Source # 
Instance details

Defined in Convex.Tasty.Streaming.TMSummary

type Rep Fault = D1 ('MetaData "Fault" "Convex.Tasty.Streaming.TMSummary" "convex-tasty-streaming-0.1.0.0-inplace" 'False) (C1 ('MetaCons "Contract" 'PrefixI 'False) (U1 :: Type -> Type) :+: (C1 ('MetaCons "Declaration" 'PrefixI 'False) (U1 :: Type -> Type) :+: C1 ('MetaCons "Setup" 'PrefixI 'False) (U1 :: Type -> Type)))

faultLabel :: Fault -> String Source #

The prefix a failure message leads with, so the fault is greppable.

threatModelGroupName :: ThreatModelCategory -> String Source #

The Tasty group that a category's per-model test cases live under. The single source of both the group the test tree is built with and the names the streaming reporter matches on, so that a category cannot end up in a group the reporter does not recognise (--test-id resolves a per-model test's Positive tests prerequisite from these names).

data TMStore Source #

Mutable storage for threat-model summaries, owned by the reporter.

newtype TMRecorder Source #

A recorder closure passed to test bodies via Tasty's option system. The default no-op makes summaries silently dropped when the streaming reporter is not active.

Constructors

TMRecorder 

Fields

newtype TMStoreOption Source #

Internal option carrying the live store. Set by defaultMainStreaming alongside the recorder so the reporter can read summaries back out.

Constructors

TMStoreOption (Maybe TMStore) 

data TraceRecorder Source #

Callback for recording iteration traces as pre-serialized JSON. Arguments: group name, category ("positive"/"negative"), pre-serialized trace JSON. Default is a no-op (zero overhead when streaming is not active).

When trEnabled returns True, test bodies use the expensive traced code path (building IterationTrace values with UTxO snapshots, transaction summaries, and JSON serialisation). When it returns False (the IsOption default), the cheap runActions path is used instead, avoiding all that work.

trEnabled is an IO action so that the decision can be deferred until the streaming reporter has parsed --no-trace and written the shared IORef.

Constructors

TraceRecorder 

Fields

newTMStore :: IO TMStore Source #

Allocate fresh storage. Call once per reporter run.

storeRecorder :: TMStore -> TMRecorder Source #

Build a recorder that writes into the given store.

lookupThreatModelSummary :: TMStore -> String -> IO (Maybe ThreatModelSummary) Source #

Look up a summary by key (does not delete).