Description:
The existing proptests cover individual properties such as bond conservation and fill conservation. Build a stateful harness that generates random sequences over every public entrypoint with multiple actors and ledger-time jumps, runs them against a simple Rust reference model, and checks global invariants after every step.
Problem Statement & Context:
Most historical bugs here (counter drift, dead writes, stale state) only show up under interleavings, which unit tests don't explore.
Scope & Acceptance Criteria:
- Invariants checked after each step:
OpenIntents equals the count of Open or PartiallyFilled intents.
TotalSolvers equals len(SolverList).
active_intents equals len(SolverIntents).
- Solvency holds.
- No intent is in an impossible state.
- Every event matches its state transition.
- Shrinking produces minimal failing sequences.
- A configurable case count, 256 by default in PRs, with nightly runs at a higher count via the existing workflow.
- Out of scope: cross-contract fuzzing (a separate follow-up).
Implementation Guidelines:
- Key Files/Modules: a new
intent_settlement/src/proptest_state_machine.rs.
- Design/Architecture: Use the
proptest-state-machine crate, or a hand-rolled Strategy of Vec<Op>.
- Edge Cases/Constraints: Keep the runtime reasonable (at most 5 minutes for 256 cases), and use
try_ clients so expected errors are handled.
- Testing: Seed the harness with at least 3 historical bugs (reverted locally) and show it finds them.
Definition of "Done":
- Harness merged, with evidence it catches the seeded bugs.
- Reviewed and approved.
Resources:
Complexity: High (200 points)
Description:
The existing proptests cover individual properties such as bond conservation and fill conservation. Build a stateful harness that generates random sequences over every public entrypoint with multiple actors and ledger-time jumps, runs them against a simple Rust reference model, and checks global invariants after every step.
Problem Statement & Context:
Most historical bugs here (counter drift, dead writes, stale state) only show up under interleavings, which unit tests don't explore.
Scope & Acceptance Criteria:
OpenIntentsequals the count of Open or PartiallyFilled intents.TotalSolversequalslen(SolverList).active_intentsequalslen(SolverIntents).Implementation Guidelines:
intent_settlement/src/proptest_state_machine.rs.proptest-state-machinecrate, or a hand-rolledStrategyofVec<Op>.try_clients so expected errors are handled.Definition of "Done":
Resources:
fill_intentvolume/fee conservation #209, [High] Add a scheduled nightly CI job running the fuzzing harness from issue #22 #284Complexity: High (200 points)