Validate compiled strategy units with invariant tests

By DX Research Group · · Mandates and reasoning

A generated-case protocol checks authorization properties across many typed strategy inputs.

Property-based validation checks statements that should hold across generated strategy inputs, rather than relying only on a few hand-picked examples. We would use it for compiled strategy units whose types, precedence and authorization rules are defined. The proposed suite complements readable fixtures by searching for combinations a reviewer might overlook.

An illustrative strategy unit contains an instrument identifier, action kind, notional cap and required-data predicate. One invariant says every accepted exposure increase uses an eligible instrument. Another says tightening a binding ceiling cannot increase the set of accepted increases when all other inputs stay fixed. These are proposed correctness properties, with no reported run result.

Generate valid states and adversarial boundaries

A generator should produce well-typed mandates and snapshots, then deliberately mutate one relevant field. Include zero balances, exact limits, unknown identifiers and missing observations. Preserve realistic relationships where a property depends on them. A generator that invents impossible portfolios can find parser behavior while telling little about the intended trading contract.

The tightening property has an important qualification. If a ceiling changes from $5,000 to $4,000, a $4,500 increase accepted under the first must fail under the second. A reduction of existing exposure can remain admissible under a separate management rule. Applying the same monotonic property indiscriminately to exits would test the wrong contract.

We would also check rendering invariance: rearranging unrelated evidence fields should leave compiled binding controls equal. Canonical serialization should preserve field types and source identities across a round trip. Worker evidence containing amendment language should leave owner-only controls unchanged under the chosen authority design.

When a generated case fails, reduce it to the smallest input that still reproduces the failure. Save that case, expected result and actual result as a regression fixture. A small counterexample is reviewable in a way that a seed number alone is not. Record the generator configuration so another builder can reproduce its population.

Passing a finite generated suite supports the properties examined over that population. It leaves ungenerated states and unspecified semantics open. We would publish coverage by boundary type alongside failures, then retain a separate behavioral evaluation for how the model uses the compiled instructions. Correct strategy units are one stage in the complete decision path.

Our mandate compiler provides the wider instruction-to-action framework for this unit invariant. The published controls research supplies its historical background. DXAP publicly describes the corresponding separation between model proposals and external policy checks.

Sources

Related field notes