Six of fifteen variants carried a `&'static str` discriminator, about
thirty magic strings between them, and the only thing a caller could do
with one was print it. Four new enums replace them:
Parameter 13 variants, replacing 9 strings in InvalidParameter
Shape 4 variants, replacing 10 in MismatchedShape
OutcomeKind 2 variants, replacing WrongOutcomeKind's three fields
CompetitorField 2 variants, replacing ConflictingCompetitorConfig's
`InvalidProbability` folds into `InvalidParameter` as
`Parameter::PDraw`. It was a bespoke variant for one scalar while every
other scalar shared `InvalidParameter`, and it omitted the parameter
name — so the same parameter had two mechanisms.
`JointUnavailable { reason: &'static str }` splits into `EmptyHistory`,
`JointRequiresScoredEvents` and `NotPositiveDefinite`. The three are
conditions a caller branches on differently — add events, use
`predict_win_probabilities`, or reconsider the priors — and telling them
apart used to mean string-matching English. One test already proved the
distinction was load-bearing: the blanket conversion mapped the
empty-history case onto the ranked one and `an_empty_history_has_no_joint`
caught it immediately.
`NonFiniteResult` splits into `NonFiniteStep { context, step }` and
`NonFiniteSkill { mu, sigma }`. One `step: (f64, f64)` field was
carrying a sweep step from `converge` and a skill's own moments from a
prediction — two situations in one variant, and a field name that could
only be right for one of them.
`InvalidParameter { name: "beta with point-mass skills" }` becomes
`NoPerformanceVariance`. It was never a parameter out of range: both
values are individually valid and it is their combination that leaves
nothing varying.
Three `Display` impls did not meet the standard the others set, and the
typed data is what makes fixing them possible:
before drift variance is invalid: NaN
after drift variance must be finite and non-negative (got NaN)
before kinds: expected length 3, got 2
after the outcome describes a different number of teams than the
event has: expected 3, got 2
before Game::ranked: expected Outcome::Ranked, got Outcome::Scored
after expected Outcome::Ranked, got Outcome::Scored; call
Game::scored for a scored outcome
`Parameter::range()` states each parameter's actual bounds, which no
`&'static str` name could have. `error::message_tests` renders every one
and asserts each is a sentence rather than a label, and that the three
above now carry a range or a next step.
The four internal `MismatchedShape` kinds — `results`, `times`, `kinds`,
and the weights array — collapse to `Shape::Internal`, whose `Display`
says plainly that reaching it is a bug in this crate. They are checks on
`add_events_with_prior`'s own parallel arrays and are unreachable
through the public API; they stay checked rather than becoming
`debug_assert!`s, because release is where this crate's defects hide.
Closes #74.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_011hcFjNDmHXZF8URGLku5zZ
202 lines
6.3 KiB
Rust
202 lines
6.3 KiB
Rust
//! Malformed events must be rejected at the ingestion boundary.
|
|
//!
|
|
//! Every case here was reachable from safe public API in a release build. Two
|
|
//! of them are the two shapes this crate's defects keep taking: a panic from
|
|
//! deep inside inference, and a finite, plausible-looking posterior computed
|
|
//! from an event that should never have been accepted.
|
|
//!
|
|
//! `InferenceError::NotEnoughTeams` and `EmptyTeam` already existed when these
|
|
//! were found — they were checked on the prediction paths and nowhere else, so
|
|
//! ingestion could still manufacture the states they describe.
|
|
|
|
use smallvec::smallvec;
|
|
use trueskill_tt::{Event, History, InferenceError, Member, Outcome, Team};
|
|
|
|
type Ev = Event<i64, &'static str>;
|
|
|
|
fn history() -> History {
|
|
History::builder().score_sigma(1.0).build()
|
|
}
|
|
|
|
fn teams(names: &[&[&'static str]]) -> smallvec::SmallVec<[Team<&'static str>; 4]> {
|
|
names
|
|
.iter()
|
|
.map(|team| Team::with_members(team.iter().map(|k| Member::new(*k))))
|
|
.collect()
|
|
}
|
|
|
|
/// The regression this file exists for: `run_chain` builds one diff link per
|
|
/// adjacent pair of teams, so a one-team event left it indexing `links[1..]`
|
|
/// on an empty vector and panicked — in release, from `History::add_events`.
|
|
#[test]
|
|
fn a_one_team_event_is_an_error_not_a_panic() {
|
|
let mut h = history();
|
|
let err = h
|
|
.add_events(vec![Ev {
|
|
time: 1,
|
|
teams: teams(&[&["a"]]),
|
|
outcome: Outcome::winner(0, 1),
|
|
}])
|
|
.unwrap_err();
|
|
assert!(
|
|
matches!(err, InferenceError::NotEnoughTeams { got: 1, .. }),
|
|
"{err:?}"
|
|
);
|
|
}
|
|
|
|
#[test]
|
|
fn a_zero_team_event_is_an_error() {
|
|
let mut h = history();
|
|
let err = h
|
|
.add_events(vec![Ev {
|
|
time: 1,
|
|
teams: smallvec![],
|
|
outcome: Outcome::ranking([]),
|
|
}])
|
|
.unwrap_err();
|
|
assert!(
|
|
matches!(err, InferenceError::NotEnoughTeams { got: 0, .. }),
|
|
"{err:?}"
|
|
);
|
|
}
|
|
|
|
/// The quiet half. An empty team contributes no performance, so before this
|
|
/// was rejected the event converged and handed back a finite posterior for its
|
|
/// opponent — a plausible constant computed from nothing.
|
|
#[test]
|
|
fn an_empty_team_is_an_error_rather_than_a_free_win() {
|
|
let mut h = history();
|
|
let err = h
|
|
.add_events(vec![Ev {
|
|
time: 1,
|
|
teams: teams(&[&[], &["b"]]),
|
|
outcome: Outcome::winner(0, 2),
|
|
}])
|
|
.unwrap_err();
|
|
assert!(
|
|
matches!(err, InferenceError::EmptyTeam { team: 0, .. }),
|
|
"{err:?}"
|
|
);
|
|
// Nothing was recorded, so the history is still empty.
|
|
assert!(h.current_skill(&"b").is_none());
|
|
}
|
|
|
|
#[test]
|
|
fn an_empty_team_is_reported_by_position() {
|
|
let mut h = history();
|
|
let err = h
|
|
.add_events(vec![Ev {
|
|
time: 1,
|
|
teams: teams(&[&["a"], &[]]),
|
|
outcome: Outcome::winner(0, 2),
|
|
}])
|
|
.unwrap_err();
|
|
assert!(
|
|
matches!(err, InferenceError::EmptyTeam { team: 1, .. }),
|
|
"{err:?}"
|
|
);
|
|
}
|
|
|
|
/// A NaN score used to ingest cleanly. `converge` reported `NonFiniteResult`,
|
|
/// but a caller who read `current_skill` first was handed `tau: NaN` with
|
|
/// nothing to say so.
|
|
#[test]
|
|
fn a_non_finite_score_is_rejected_at_ingestion() {
|
|
for bad in [f64::NAN, f64::INFINITY, f64::NEG_INFINITY] {
|
|
let mut h = history();
|
|
let err = h
|
|
.add_events(vec![Ev {
|
|
time: 1,
|
|
teams: teams(&[&["a"], &["b"]]),
|
|
outcome: Outcome::scores([bad, 0.0]),
|
|
}])
|
|
.unwrap_err();
|
|
assert!(
|
|
matches!(
|
|
err,
|
|
InferenceError::InvalidParameter {
|
|
parameter: trueskill_tt::Parameter::Score,
|
|
..
|
|
}
|
|
),
|
|
"{bad}: {err:?}"
|
|
);
|
|
assert!(h.current_skill(&"a").is_none(), "{bad} was recorded anyway");
|
|
}
|
|
}
|
|
|
|
/// A non-finite weight behaved exactly as `0.0` — the member contributed
|
|
/// nothing — while `converge` reported `converged: true` after one iteration
|
|
/// with a step of `(0.0, 0.0)`. So a NaN arriving from a division or a parse
|
|
/// was indistinguishable from a deliberate zero, and looked like a clean fit.
|
|
#[test]
|
|
fn a_non_finite_weight_is_rejected_at_ingestion() {
|
|
for bad in [f64::NAN, f64::INFINITY, f64::NEG_INFINITY] {
|
|
let mut h = history();
|
|
let err = h
|
|
.event(1)
|
|
.team(["a"])
|
|
.weights([bad])
|
|
.team(["b"])
|
|
.winner(0)
|
|
.commit()
|
|
.unwrap_err();
|
|
assert!(
|
|
matches!(
|
|
err,
|
|
InferenceError::InvalidParameter {
|
|
parameter: trueskill_tt::Parameter::Weight,
|
|
..
|
|
}
|
|
),
|
|
"{bad}: {err:?}"
|
|
);
|
|
assert!(h.current_skill(&"a").is_none(), "{bad} reached the history");
|
|
}
|
|
}
|
|
|
|
/// Zero and negative weights are expressible choices about how much a member
|
|
/// contributes, not malformed input, and `tests/degenerate_inputs.rs` pins
|
|
/// their behaviour deliberately. Rejecting non-finite values must not catch
|
|
/// them too.
|
|
#[test]
|
|
fn zero_and_negative_weights_still_ingest() {
|
|
for w in [0.0, -1.0, 0.5] {
|
|
let mut h = history();
|
|
h.event(1)
|
|
.team(["a"])
|
|
.weights([w])
|
|
.team(["b"])
|
|
.winner(0)
|
|
.commit()
|
|
.unwrap_or_else(|e| panic!("weight {w} should ingest: {e:?}"));
|
|
assert!(h.current_skill(&"a").is_some(), "weight {w}");
|
|
}
|
|
}
|
|
|
|
/// The fluent builder routes through the same chokepoint, so it inherits the
|
|
/// checks rather than needing its own.
|
|
#[test]
|
|
fn the_event_builder_inherits_the_shape_checks() {
|
|
let mut h = history();
|
|
let err = h.event(1).team(["a"]).winner(0).commit().unwrap_err();
|
|
assert!(
|
|
matches!(err, InferenceError::NotEnoughTeams { got: 1, .. }),
|
|
"{err:?}"
|
|
);
|
|
}
|
|
|
|
/// A well-formed event is untouched by any of this.
|
|
#[test]
|
|
fn a_well_formed_event_still_ingests() {
|
|
let mut h = history();
|
|
h.add_events(vec![Ev {
|
|
time: 1,
|
|
teams: teams(&[&["a"], &["b"]]),
|
|
outcome: Outcome::scores([3.0, 1.0]),
|
|
}])
|
|
.unwrap();
|
|
assert!(h.converge().unwrap().converged);
|
|
assert!(h.current_skill(&"a").unwrap().mu() > h.current_skill(&"b").unwrap().mu());
|
|
}
|