fix(currency): cap repeated currency move tags at one per reply

TagExtractor collects every [MOVE:] tag occurrence with no dedupe, and
MoveValidator is a pure membership test against available_moves, so N
copies of one legal move all pass validation. MoveApplier then looped
and applied every copy. A model could therefore pick an arbitrary
amount of money in unary by repeating one tag: [MOVE: accept_item(copper)]
x47 against a 47c purse drains it to 0; [MOVE: give_item(gold)] x10
mints +100,000c. The eight-move vocabulary (§6) takes no quantity
argument precisely so the AI cannot choose a number — this closed that
gap by another door and was a §2 breach (AI owns text, never state).

MoveApplier.apply() now tracks currency moves (give_item/accept_item on
a denomination) already applied within one call, keyed on name+denom,
and skips repeats. Non-currency moves are untouched — repeated
give_item(amulet) still yields multiple copies, which stays bounded by
the pre-existing cross-reply gifts_given gate and is a separate,
already-reported issue. move_validator.gd and tag_extractor.gd are
untouched.

Also adds the Finding-2 test the currency spec (§7) named but never
delivered: after GameState.grant("gold", 1), inventory stays empty, so
accept_item(gold) in available_moves comes only from the affordability
loop, never double-offered via the inventory.keys() loop.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01QYa9u7Kdxv5gX4AnwWexy8
This commit is contained in:
2026-07-12 18:47:19 -05:00
parent 6c496d3ed8
commit 8e1238c316
3 changed files with 83 additions and 0 deletions

View File

@@ -84,3 +84,60 @@ func test_refuse_and_end_are_noops():
var gs = GameState.new()
MoveApplier.apply([_m("refuse"), _m("end_conversation")], gs, CanonLog.new(), _content(), "fenn")
assert_eq(gs.npc_dispositions.size(), 0)
# --- Finding 1: a repeated currency move tag in ONE reply must not let the AI
# pick an arbitrary amount by unary repetition (§2 breach). A currency move
# (give_item/accept_item on a denomination) applies AT MOST ONCE per apply()
# call, keyed on move name + denomination.
func test_repeated_accept_item_silver_applies_once():
var gs = GameState.new()
gs.purse_copper = 10000
MoveApplier.apply([_m("accept_item", ["silver"]), _m("accept_item", ["silver"])],
gs, CanonLog.new(), _content(), "fenn")
assert_eq(gs.purse_copper, 9900, "second accept_item(silver) tag must be a no-op")
func test_repeated_give_item_gold_applies_once():
var gs = GameState.new()
var moves: Array = []
for i in range(10):
moves.append(_m("give_item", ["gold"]))
MoveApplier.apply(moves, gs, CanonLog.new(), _content(), "fenn")
assert_eq(gs.purse_copper, 10000, "nine of the ten give_item(gold) tags must be no-ops")
func test_repeated_accept_item_copper_applies_once():
var gs = GameState.new()
gs.purse_copper = 47
var moves: Array = []
for i in range(47):
moves.append(_m("accept_item", ["copper"]))
MoveApplier.apply(moves, gs, CanonLog.new(), _content(), "fenn")
assert_eq(gs.purse_copper, 46, "46 of the 47 accept_item(copper) tags must be no-ops")
func test_different_currency_moves_both_still_apply():
# Proves dedup is keyed per (move name + denomination), not per reply as a whole.
var gs = GameState.new()
MoveApplier.apply([_m("give_item", ["gold"]), _m("accept_item", ["silver"])],
gs, CanonLog.new(), _content(), "fenn")
assert_eq(gs.purse_copper, 9900)
func test_repeated_non_currency_give_item_still_applies_each_time():
# Pins the scope line: real-item duplicate handling is UNCHANGED by this fix
# (it stays bounded only by the cross-reply gifts_given gate, reported separately).
var gs = GameState.new()
MoveApplier.apply([_m("give_item", ["amulet"]), _m("give_item", ["amulet"]), _m("give_item", ["amulet"])],
gs, CanonLog.new(), _content(), "fenn")
assert_eq(gs.inventory.get("amulet", 0), 3, "non-currency give_item is out of scope for this fix")
func test_repeated_non_currency_accept_item_still_applies_each_time():
var gs = GameState.new()
gs.add_item("worn_shortsword", 5)
MoveApplier.apply([_m("accept_item", ["worn_shortsword"]), _m("accept_item", ["worn_shortsword"])],
gs, CanonLog.new(), _content(), "fenn")
assert_eq(gs.inventory.get("worn_shortsword", 0), 3, "non-currency accept_item is out of scope for this fix")