test(buzz-media): assert header-page granule in the Ogg contract oracle

The oracle blessed output that leaked the RFC 3533 6.2 "no packet completes
on this page" sentinel (0xFF..FF) onto the Vorbis comment page. Decoders
ignore granule on header pages, so such a file decodes, reports exact
duration, and compares PCM-identical while being wire-invalid — and the
relay validator correctly rejects it.

Assert granule 0 on any of the first three pages that completes a packet.
Pages that complete nothing (a spanning setup continuation) legitimately
carry the sentinel and are exempt.

Verified both directions: fails on the leaking output, passes on the
corrected output and on the reference strippers.

Co-authored-by: Dawn <c6237ef84fa537c78dcee78efd2d4e59f728859c7f194da42ac51ededfa0be05@buzz.block.builderlab.xyz>
Signed-off-by: Dawn <c6237ef84fa537c78dcee78efd2d4e59f728859c7f194da42ac51ededfa0be05@buzz.block.builderlab.xyz>
This commit is contained in:
Dawn
2026-08-14 12:21:26 -04:00
parent 1f87c19d84
commit 977674c2d0
2 changed files with 24 additions and 3 deletions
+12 -3
View File
@@ -72,6 +72,15 @@ python3 verify_contract.py <file.ogg>...
Asserts the canonical layout the client emits: one logical stream, page
sequence contiguous from 0, every page CRC recomputed and re-verified, the
identification packet alone on the BOS page, the canonical empty comment
packet alone on page 1 with a single lacing value, and the setup packet
isolated on its own page(s). Written from RFC 3533 rather than from any
particular stripper implementation, so it is an independent oracle.
packet alone on page 1 with a single lacing value, the setup packet
isolated on its own page(s), and granule 0 (never the `-1` sentinel) on
every header page that completes a packet. Written from RFC 3533 rather than
from any particular stripper implementation, so it is an independent oracle.
The granule assertion was added after all four instruments above — plus this
oracle's earlier revision — passed an implementation that leaked the RFC 3533
§6.2 "no packet completes here" sentinel (`0xFF..FF`) onto the comment page.
Every decoder ignores that field on header pages, so the file decoded, timed,
and PCM-compared perfectly while being wire-invalid. An oracle is only as
strong as its strictest clause; when the relay validator rejects something
this script blesses, the script is what's wrong.
@@ -13,10 +13,22 @@ def check(path):
page=d[off:off+body];pay=d[off+hdr:off+body]
seq=struct.unpack('<I',page[18:22])[0]
stored=struct.unpack('<I',page[22:26])[0]
granule=struct.unpack('<Q',page[6:14])[0]
calc=crc32_ogg(page[:22]+b'\x00'*4+page[26:])
serials.add(page[14:18])
if stored!=calc: errs.append(f"page{i}: CRC mismatch")
if seq!=i: errs.append(f"page{i}: seq={seq} not contiguous")
# RFC 3533 6.2: granule -1 (0xFF..FF) means "no packet completes on this
# page". The three Vorbis header packets carry no sample position, so a
# header page that DOES complete a packet has granule 0 — never the -1
# sentinel. (A header page that completes nothing, i.e. a spanning setup
# continuation, legitimately carries -1.) Leaking -1 onto a completing
# header page decodes fine everywhere, so only a structural check sees
# it; the relay validator rejects it.
completes = len(seg)>0 and seg[-1]!=255
if i<3 and completes and granule!=0:
shown="-1 (0xFF..FF sentinel)" if granule==0xFFFFFFFFFFFFFFFF else granule
errs.append(f"page{i}: header-page granule={shown}, want 0")
if i==0:
if not (page[5]&0x02): errs.append("page0: BOS flag not set")
if pay[:7]!=b'\x01vorbis': errs.append("page0: not identification")