mirror of
https://github.com/SHOGGOTH-SECTOR/sica-fondt.git
synced 2026-09-30 01:15:10 +00:00
ada: cut to a border-only gate; delete the wrong organ/cognition modeling
Ada is the D1 border, not the body. Removed everything that pretended otherwise
and completed the real gate so it builds, links, and passes its tests.
Deleted (wrong/defunct/superseded):
- ada_medium.adb (defunct medium, header commented 'WRONG'; replaced by Ichor)
- sockets.{ads,adb} (empty package with an illegal body)
- bbb-bludbrenburier.ads ('this is filler'); invariants-architecture.cobol ('idk cobol')
- tests/soul_tests.adb, tests/cycle_tests.adb (exercise a Soul.Tarot/State/Ada_Medium
subsystem that does not exist -- the old 56-card/Big-3 design, superseded)
mafiabot_types -> border-only: organs aren't Ada (organs are R/Octave/Pony/Guile),
so drop Organ_Id; drop Cycle_Step (cognition) and the fixed-point Drive/Ratio/
Cost/Axis numerics (drive/affect math lives in the organs, in floats). Keep the
source/trust tag (Provenance_Tag), Operation_Status, and a bounded payload --
content is pre-digested into RAG context upstream, so the gate scans a bounded
buffer for prompt-injection rather than streaming raw input.
trust_boundary: Organ_Message -> Border_Message {Provenance, Payload} (Ada does
not route by organ -- that's Ichor); add the D1 body (blocklist scan, provenance,
rate limit, Trust_Guard) -- the unit Ichor's barrier FFI targets.
Add mafiabot_types.adb. Fix mafiabot_core.gpr (drop phantom dirs + nonexistent
mafiabot.adb main). alire.toml: drop unused gnat_sockets/spark_lemmas.
Builds clean on GNAT 13.3/Alire; trust + config tests pass.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_015hmgREHNsxYCuim33yUF2c
This commit is contained in:
@@ -1 +0,0 @@
|
||||
idk cobol
|
||||
@@ -0,0 +1,131 @@
|
||||
-- SPARK trust boundary body — defense model §8.2.
|
||||
-- No heap, no regex, no exceptions: naive substring search, tick-based rate
|
||||
-- limiting, provenance equality. Matches the contracts in the spec.
|
||||
package body Trust_Boundary
|
||||
with SPARK_Mode => On
|
||||
is
|
||||
|
||||
-- --------------------------------------------------------------------
|
||||
-- Naive substring search — O(n*m), no heap, no regex.
|
||||
|
||||
function Matches_Blocklist
|
||||
(Text : Bounded_Text;
|
||||
List : Blocklist) return Boolean
|
||||
is
|
||||
begin
|
||||
for I in Blocklist_Index loop
|
||||
if List (I).Active and then List (I).Pattern_Len > 0
|
||||
and then List (I).Pattern_Len <= Text.Length
|
||||
then
|
||||
declare
|
||||
P_Len : constant Pattern_Length := List (I).Pattern_Len;
|
||||
Pat : constant String := List (I).Pattern (1 .. P_Len);
|
||||
begin
|
||||
for Start in 1 .. (Text.Length - P_Len + 1) loop
|
||||
if Text.Data (Start .. Start + P_Len - 1) = Pat then
|
||||
return True;
|
||||
end if;
|
||||
end loop;
|
||||
end;
|
||||
end if;
|
||||
end loop;
|
||||
return False;
|
||||
end Matches_Blocklist;
|
||||
|
||||
-- --------------------------------------------------------------------
|
||||
-- Provenance enforcement: a message may not reclassify its authority.
|
||||
|
||||
procedure Validate_Provenance
|
||||
(Source : in Provenance_Tag;
|
||||
Claimed : in Provenance_Tag;
|
||||
Result : out Operation_Status)
|
||||
is
|
||||
begin
|
||||
if Source = Claimed then
|
||||
Result := OK;
|
||||
else
|
||||
Result := Error_Trust_Violation;
|
||||
end if;
|
||||
end Validate_Provenance;
|
||||
|
||||
-- --------------------------------------------------------------------
|
||||
-- Tick-based rate limiting (no wall-clock).
|
||||
|
||||
procedure Check_Rate
|
||||
(Limit : in out Rate_Limit;
|
||||
Tick : in Natural;
|
||||
Result : out Operation_Status)
|
||||
is
|
||||
begin
|
||||
-- Open a fresh window if the clock reset or the window has elapsed.
|
||||
if Tick < Limit.Window_Start
|
||||
or else (Tick - Limit.Window_Start) >= Limit.Window_Size
|
||||
then
|
||||
Limit.Window_Start := Tick;
|
||||
Limit.Current_Count := 0;
|
||||
end if;
|
||||
|
||||
if Limit.Current_Count < Limit.Max_Per_Window then
|
||||
Limit.Current_Count := Limit.Current_Count + 1;
|
||||
Result := OK;
|
||||
else
|
||||
Result := Error_Blocked;
|
||||
end if;
|
||||
end Check_Rate;
|
||||
|
||||
-- --------------------------------------------------------------------
|
||||
-- Combined message check: system-internal always passes (proven
|
||||
-- invariant); everything else is screened against the blocklist.
|
||||
|
||||
procedure Check_Message
|
||||
(Msg : in Border_Message;
|
||||
Result : out Operation_Status)
|
||||
is
|
||||
begin
|
||||
if Msg.Provenance = System_Internal then
|
||||
Result := OK;
|
||||
elsif Matches_Blocklist (Msg.Payload, Default_Blocklist) then
|
||||
Result := Error_Blocked;
|
||||
else
|
||||
Result := OK;
|
||||
end if;
|
||||
end Check_Message;
|
||||
|
||||
-- --------------------------------------------------------------------
|
||||
-- The guard: rate-limit then screen, on a shared tick.
|
||||
|
||||
protected body Trust_Guard is
|
||||
|
||||
procedure Screen_Inbound
|
||||
(Msg : in Border_Message;
|
||||
Status : out Operation_Status)
|
||||
is
|
||||
Rate_Status : Operation_Status;
|
||||
begin
|
||||
Tick := Tick + 1;
|
||||
Check_Rate (Inbound_Rate, Tick, Rate_Status);
|
||||
if Rate_Status /= OK then
|
||||
Status := Rate_Status;
|
||||
else
|
||||
Check_Message (Msg, Status);
|
||||
end if;
|
||||
end Screen_Inbound;
|
||||
|
||||
procedure Screen_Outbound
|
||||
(Msg : in Border_Message;
|
||||
Status : out Operation_Status)
|
||||
is
|
||||
Rate_Status : Operation_Status;
|
||||
begin
|
||||
Tick := Tick + 1;
|
||||
Check_Rate (Outbound_Rate, Tick, Rate_Status);
|
||||
if Rate_Status /= OK then
|
||||
Status := Rate_Status;
|
||||
else
|
||||
Check_Message (Msg, Status);
|
||||
end if;
|
||||
end Screen_Outbound;
|
||||
|
||||
end Trust_Guard;
|
||||
|
||||
end Trust_Boundary;
|
||||
@@ -7,12 +7,12 @@ package Trust_Boundary
|
||||
with SPARK_Mode => On
|
||||
is
|
||||
|
||||
-- Inter-organ message (same type used by Ada_Medium routing)
|
||||
type Organ_Message is record
|
||||
Source : Organ_Id := Ada_Medium;
|
||||
Destination : Organ_Id := Ada_Medium;
|
||||
Provenance : Provenance_Tag := System_Internal;
|
||||
Payload : Bounded_Text;
|
||||
-- A message crossing the border (D1). Ada does not route by organ -- that
|
||||
-- is Ichor's job -- so this carries only the source/trust tag the gate
|
||||
-- screens by, plus the (pre-digested) payload to scan.
|
||||
type Border_Message is record
|
||||
Provenance : Provenance_Tag := System_Internal;
|
||||
Payload : Bounded_Text;
|
||||
end record;
|
||||
|
||||
-- -----------------------------------------------------------------------
|
||||
@@ -68,7 +68,7 @@ is
|
||||
-- Message check (combines provenance + blocklist)
|
||||
|
||||
procedure Check_Message
|
||||
(Msg : in Organ_Message;
|
||||
(Msg : in Border_Message;
|
||||
Result : out Operation_Status)
|
||||
with Post => (if Msg.Provenance = System_Internal then Result = OK);
|
||||
|
||||
@@ -79,11 +79,11 @@ is
|
||||
pragma Priority (System.Priority'Last);
|
||||
|
||||
procedure Screen_Inbound
|
||||
(Msg : in Organ_Message;
|
||||
(Msg : in Border_Message;
|
||||
Status : out Operation_Status);
|
||||
|
||||
procedure Screen_Outbound
|
||||
(Msg : in Organ_Message;
|
||||
(Msg : in Border_Message;
|
||||
Status : out Operation_Status);
|
||||
|
||||
private
|
||||
|
||||
Reference in New Issue
Block a user