node: drop Quasar/Annulus/Lux from profile identifiers

Mirror of consensus/config rename:
  ProfileLuxStrictPQ   -> ProfileStrictPQ
  ProfileLuxPermissive -> ProfilePermissive
  ProfileLuxFIPS       -> ProfileFIPS
  LuxStrictPQ()        -> StrictPQ() constructor
  LuxPermissive()      -> Permissive()

Updates across chains, network/peer (handshake + scheme_gate), node init,
service/security (metrics + types), and platformvm/xvm profile tests.
Wire-string assertions updated to drop LUX_ prefix (e.g. "STRICT_PQ").
This commit is contained in:
Hanzo AI
2026-05-11 16:51:03 -07:00
parent 58d7efe2cc
commit e75cd24807
12 changed files with 101 additions and 101 deletions
+2 -2
View File
@@ -17,7 +17,7 @@ import (
// underlying registry shape.
func TestMetrics_NilReceiver_Noop(t *testing.T) {
var m *Metrics
m.SetActiveProfile(consensusconfig.LuxStrictPQ())
m.SetActiveProfile(consensusconfig.StrictPQ())
m.SetActiveProfile(nil)
m.ObserveMempoolClassicalCredential("P")
m.SetZchainProofLagEpochs(1)
@@ -32,7 +32,7 @@ func TestMetrics_ConstructionUnderNoopRegistry_DoesNotPanic(t *testing.T) {
reg := metric.NewRegistry()
metricsInstance := metric.NewWithRegistry("lux_security", reg)
m := NewMetrics(metricsInstance)
m.SetActiveProfile(consensusconfig.LuxStrictPQ())
m.SetActiveProfile(consensusconfig.StrictPQ())
m.ObserveMempoolClassicalCredential("P")
m.SetZchainProofLagEpochs(3)
// Gather is expected to be empty under the noop registry; we
+6 -6
View File
@@ -25,7 +25,7 @@ func TestMetrics_SecurityProfileGauge_Reflects_ActiveProfile(t *testing.T) {
metricsInstance := metric.NewWithRegistry("lux_security", reg)
m := NewMetrics(metricsInstance)
strictPQ := consensusconfig.LuxStrictPQ()
strictPQ := consensusconfig.StrictPQ()
m.SetActiveProfile(strictPQ)
// Gather and assert the gauge family for each expected metric
@@ -38,14 +38,14 @@ func TestMetrics_SecurityProfileGauge_Reflects_ActiveProfile(t *testing.T) {
expect := map[string]float64{
"lux_security_profile_post_quantum_end_to_end:profile_id=" +
strconv.Itoa(int(consensusconfig.ProfileLuxStrictPQ)) +
",profile_name=LUX_STRICT_PQ": 1,
strconv.Itoa(int(consensusconfig.ProfileStrictPQ)) +
",profile_name=STRICT_PQ": 1,
"lux_security_profile_nist_friendly:profile_id=" +
strconv.Itoa(int(consensusconfig.ProfileLuxStrictPQ)): 1,
strconv.Itoa(int(consensusconfig.ProfileStrictPQ)): 1,
"lux_security_profile_lux_canonical:profile_id=" +
strconv.Itoa(int(consensusconfig.ProfileLuxStrictPQ)): 1,
strconv.Itoa(int(consensusconfig.ProfileStrictPQ)): 1,
"lux_security_profile_unsafe_mode_enabled:profile_id=" +
strconv.Itoa(int(consensusconfig.ProfileLuxStrictPQ)): 0,
strconv.Itoa(int(consensusconfig.ProfileStrictPQ)): 0,
}
for key, want := range expect {
got, ok := values[key]
+23 -23
View File
@@ -26,7 +26,7 @@ import (
// Closes the spec contract for the public RPC surface that auditors
// and dApps consult.
func TestRPC_securityProfile_StrictPQ(t *testing.T) {
profile := consensusconfig.LuxStrictPQ()
profile := consensusconfig.StrictPQ()
svc := &Service{log: log.Noop(), profile: profile}
var reply ProfileReply
@@ -34,25 +34,25 @@ func TestRPC_securityProfile_StrictPQ(t *testing.T) {
t.Fatalf("SecurityProfile: %v", err)
}
if reply.ProfileID != uint32(consensusconfig.ProfileLuxStrictPQ) {
if reply.ProfileID != uint32(consensusconfig.ProfileStrictPQ) {
t.Errorf("ProfileID = %d; want %d",
reply.ProfileID, consensusconfig.ProfileLuxStrictPQ)
reply.ProfileID, consensusconfig.ProfileStrictPQ)
}
if reply.ProfileName != "LUX_STRICT_PQ" {
t.Errorf("ProfileName = %q; want LUX_STRICT_PQ", reply.ProfileName)
if reply.ProfileName != "STRICT_PQ" {
t.Errorf("ProfileName = %q; want STRICT_PQ", reply.ProfileName)
}
wantHash := "0x" + hex.EncodeToString(profile.ProfileHash[:])
if reply.ProfileHash != wantHash {
t.Errorf("ProfileHash = %q; want %q", reply.ProfileHash, wantHash)
}
if !reply.PostQuantumEndToEnd {
t.Error("PostQuantumEndToEnd = false on LuxStrictPQ; want true")
t.Error("PostQuantumEndToEnd = false on StrictPQ; want true")
}
if !reply.NISTFriendly {
t.Error("NISTFriendly = false on LuxStrictPQ; want true")
t.Error("NISTFriendly = false on StrictPQ; want true")
}
if !reply.LuxCanonical {
t.Error("LuxCanonical = false on LuxStrictPQ; want true")
t.Error("LuxCanonical = false on StrictPQ; want true")
}
if reply.HashSuite != "SHA3_NIST" {
t.Errorf("HashSuite = %q; want SHA3_NIST", reply.HashSuite)
@@ -96,7 +96,7 @@ func TestRPC_securityProfile_StrictPQ(t *testing.T) {
}
for name, v := range allTrue {
if !v {
t.Errorf("%s = false on LuxStrictPQ; want true", name)
t.Errorf("%s = false on StrictPQ; want true", name)
}
}
}
@@ -179,20 +179,20 @@ func TestRPC_securityProfile_NoProfile_Refused(t *testing.T) {
// carries the chain-wide profile envelope and the canonical proof
// backend name.
func TestRPC_blockSecurity_StrictPQ(t *testing.T) {
svc := &Service{log: log.Noop(), profile: consensusconfig.LuxStrictPQ()}
svc := &Service{log: log.Noop(), profile: consensusconfig.StrictPQ()}
var reply BlockSecurityReply
if err := svc.BlockSecurity(nil, &BlockSecurityArgs{}, &reply); err != nil {
t.Fatalf("BlockSecurity: %v", err)
}
if reply.SecurityProfileName != "LUX_STRICT_PQ" {
t.Errorf("SecurityProfileName = %q; want LUX_STRICT_PQ",
if reply.SecurityProfileName != "STRICT_PQ" {
t.Errorf("SecurityProfileName = %q; want STRICT_PQ",
reply.SecurityProfileName)
}
if !reply.PulsarMSignatureValid {
t.Error("PulsarMSignatureValid = false; want true on LuxStrictPQ")
t.Error("PulsarMSignatureValid = false; want true on StrictPQ")
}
if !reply.PostQuantumEndToEnd {
t.Error("PostQuantumEndToEnd = false; want true on LuxStrictPQ")
t.Error("PostQuantumEndToEnd = false; want true on StrictPQ")
}
if reply.ProofBackendID == 0 {
t.Error("ProofBackendID = 0; want a populated backend byte")
@@ -207,7 +207,7 @@ func TestRPC_blockSecurity_StrictPQ(t *testing.T) {
// JSON shape as the JSON-RPC handler. One shape, two transports — no
// per-transport drift.
func TestREST_securityProfile_GET(t *testing.T) {
profile := consensusconfig.LuxStrictPQ()
profile := consensusconfig.StrictPQ()
handler, err := NewHandler(log.Noop(), profile)
if err != nil {
t.Fatalf("NewHandler: %v", err)
@@ -230,8 +230,8 @@ func TestREST_securityProfile_GET(t *testing.T) {
if err := json.NewDecoder(resp.Body).Decode(&body); err != nil {
t.Fatalf("decode: %v", err)
}
if body.ProfileName != "LUX_STRICT_PQ" {
t.Errorf("REST ProfileName = %q; want LUX_STRICT_PQ", body.ProfileName)
if body.ProfileName != "STRICT_PQ" {
t.Errorf("REST ProfileName = %q; want STRICT_PQ", body.ProfileName)
}
if body.ContractAuth != "ML_DSA_65|ZCHAIN_AUTH_PROOF" {
t.Errorf("REST ContractAuth = %q; want ML_DSA_65|ZCHAIN_AUTH_PROOF",
@@ -242,7 +242,7 @@ func TestREST_securityProfile_GET(t *testing.T) {
// TestREST_securityProfile_MethodNotAllowed proves the REST sidecar
// refuses non-GET methods (the endpoint is read-only).
func TestREST_securityProfile_MethodNotAllowed(t *testing.T) {
profile := consensusconfig.LuxStrictPQ()
profile := consensusconfig.StrictPQ()
handler, err := NewHandler(log.Noop(), profile)
if err != nil {
t.Fatalf("NewHandler: %v", err)
@@ -266,7 +266,7 @@ func TestREST_securityProfile_MethodNotAllowed(t *testing.T) {
// JSON shape as the JSON-RPC handler. One shape, two transports — no
// per-transport drift.
func TestREST_blockSecurity_GET(t *testing.T) {
profile := consensusconfig.LuxStrictPQ()
profile := consensusconfig.StrictPQ()
handler, err := NewHandler(log.Noop(), profile)
if err != nil {
t.Fatalf("NewHandler: %v", err)
@@ -286,15 +286,15 @@ func TestREST_blockSecurity_GET(t *testing.T) {
if err := json.NewDecoder(resp.Body).Decode(&body); err != nil {
t.Fatalf("decode: %v", err)
}
if body.SecurityProfileName != "LUX_STRICT_PQ" {
t.Errorf("REST SecurityProfileName = %q; want LUX_STRICT_PQ",
if body.SecurityProfileName != "STRICT_PQ" {
t.Errorf("REST SecurityProfileName = %q; want STRICT_PQ",
body.SecurityProfileName)
}
if !body.PulsarMSignatureValid {
t.Error("PulsarMSignatureValid = false; want true on LuxStrictPQ")
t.Error("PulsarMSignatureValid = false; want true on StrictPQ")
}
if !body.PostQuantumEndToEnd {
t.Error("PostQuantumEndToEnd = false; want true on LuxStrictPQ")
t.Error("PostQuantumEndToEnd = false; want true on StrictPQ")
}
}
+8 -8
View File
@@ -37,7 +37,7 @@ type ProfileReply struct {
ProfileID uint32 `json:"profile_id"`
// ProfileName is the canonical SCREAMING_SNAKE_CASE name (e.g.
// "LUX_STRICT_PQ"). Audit tooling matches on this name.
// "STRICT_PQ"). Audit tooling matches on this name.
ProfileName string `json:"profile_name"`
// ProfileHash is the 48-byte SHA3-384 commitment to the profile
@@ -207,8 +207,8 @@ func contractAuthName(profile *consensusconfig.ChainSecurityProfile) string {
return ""
}
base := renderName(profile.ContractAuthID.String())
if profile.ProfileID == uint32(consensusconfig.ProfileLuxStrictPQ) ||
profile.ProfileID == uint32(consensusconfig.ProfileLuxFIPS) {
if profile.ProfileID == uint32(consensusconfig.ProfileStrictPQ) ||
profile.ProfileID == uint32(consensusconfig.ProfileFIPS) {
// Strict-PQ + FIPS implicitly admit Z-Chain validity proofs
// as a contract-auth primitive in addition to the raw
// lattice scheme pinned on the profile.
@@ -265,9 +265,9 @@ func isLuxCanonical(profile *consensusconfig.ChainSecurityProfile) bool {
return false
}
switch profile.ProfileID {
case uint32(consensusconfig.ProfileLuxStrictPQ),
uint32(consensusconfig.ProfileLuxPermissive),
uint32(consensusconfig.ProfileLuxFIPS):
case uint32(consensusconfig.ProfileStrictPQ),
uint32(consensusconfig.ProfilePermissive),
uint32(consensusconfig.ProfileFIPS):
return true
default:
return false
@@ -292,8 +292,8 @@ func isNISTFriendly(profile *consensusconfig.ChainSecurityProfile) bool {
return false
}
switch profile.ProfileID {
case uint32(consensusconfig.ProfileLuxStrictPQ),
uint32(consensusconfig.ProfileLuxFIPS):
case uint32(consensusconfig.ProfileStrictPQ),
uint32(consensusconfig.ProfileFIPS):
return true
default:
return false