fix(currency): cap repeated currency move tags at one per reply

TagExtractor collects every [MOVE:] tag occurrence with no dedupe, and
MoveValidator is a pure membership test against available_moves, so N
copies of one legal move all pass validation. MoveApplier then looped
and applied every copy. A model could therefore pick an arbitrary
amount of money in unary by repeating one tag: [MOVE: accept_item(copper)]
x47 against a 47c purse drains it to 0; [MOVE: give_item(gold)] x10
mints +100,000c. The eight-move vocabulary (§6) takes no quantity
argument precisely so the AI cannot choose a number — this closed that
gap by another door and was a §2 breach (AI owns text, never state).

MoveApplier.apply() now tracks currency moves (give_item/accept_item on
a denomination) already applied within one call, keyed on name+denom,
and skips repeats. Non-currency moves are untouched — repeated
give_item(amulet) still yields multiple copies, which stays bounded by
the pre-existing cross-reply gifts_given gate and is a separate,
already-reported issue. move_validator.gd and tag_extractor.gd are
untouched.

Also adds the Finding-2 test the currency spec (§7) named but never
delivered: after GameState.grant("gold", 1), inventory stays empty, so
accept_item(gold) in available_moves comes only from the affordability
loop, never double-offered via the inventory.keys() loop.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01QYa9u7Kdxv5gX4AnwWexy8
This commit is contained in:
2026-07-12 18:47:19 -05:00
parent 6c496d3ed8
commit 8e1238c316
3 changed files with 83 additions and 0 deletions

View File

@@ -11,9 +11,20 @@ const HOSTILE_FLOOR := -100
static func apply(moves: Array, game_state, canon_log, content_db, npc_id: String) -> void:
# A currency move (give_item/accept_item on a denomination) applies AT MOST
# ONCE per reply. Without this, a model repeating one tag N times would pick
# an arbitrary amount in unary — the AI choosing a number is a §2 breach.
# Real-item duplicates are unaffected; that stays bounded by gifts_given.
var currency_applied_this_reply := {} # "name(denom)" -> true
for move in moves:
var name: String = move.get("name", "")
var args: Array = move.get("args", [])
if name in ["give_item", "accept_item"] and not args.is_empty() \
and Currency.is_currency(str(args[0])):
var currency_key := "%s(%s)" % [name, str(args[0])]
if currency_applied_this_reply.has(currency_key):
continue
currency_applied_this_reply[currency_key] = true
match name:
"offer_quest":
var q: String = str(args[0])