Introduce a property testing harness for asserting a set of properties expected of the repository identity. The harness uses the `Network` fixture for providing four nodes that can interact with the repository identity. The state of the harness is advanced by providing an actor and operation on the identity document. Invariants are then asserted about the identity. The current invariants are: - The `current` revision is the one and only `Accepted` revision. - The chain of revisions is valid. That is, `Active` revisions only have a parent that is `Accepted`, and not `Rejected` or `Redacted`. - `Active` revisions do not contain a majority approval. - `Accepted` revisions contain a majority approval. - `Rejected` revisions do not contain a majority approval. - For each revision, at most one child is `Accepted`. - For each revision, if any of its children is `Accepted`, all other children are `Rejected`. - A revision which is `Rejected(RejectedBy::Parent)` has a parent that is `Rejected`. - A revision which is `Redacted(RedactedBy::Parent)` has a parent that is `Redacted`. - For each revision that is `Rejected` or `Redacted`, none of its children is `Active`. - A sibling or ancestor revision's rejected state applies to its sibling or descendant. - The repository identity documents converge when all nodes have applied all operations. |
||
|---|---|---|
| .. | ||
| src | ||
| CHANGELOG.md | ||
| Cargo.toml | ||
| build.rs | ||