"""Lesson 1: finite, two-state teaching model. Run with Python 3.

Not RTL simulation, synthesis, a formal proof, or physical injection.
The independent reference and final gates are trusted in these examples.
An upset persists until overwrite/reset. Timing is a discrete illustration.
PASS includes expected bypasses of intentionally vulnerable logic.
"""

TRUE, FALSE = 0b0110, 0b1001


def decode_true(code):
    return code == TRUE


def vulnerable_grant(checked, stored):
    return checked and stored


def reference_gate(checked, stored, ref_complete, ref_pass):
    # Conditional comparison model: ref_* and this gate are trusted.
    return checked and stored and ref_complete and ref_pass


def accepted(valid, ready, grant):
    return valid and ready and grant


def main():
    for code in range(16):
        assert decode_true(code) == (code == 6)
    assert bin(TRUE ^ FALSE).count('1') == 4
    for bit in range(4):
        changed = FALSE ^ (1 << bit)
        assert changed not in (TRUE, FALSE)
        assert not decode_true(changed)

    # 1: fault-free authorized image is reachable in both models.
    assert accepted(True, True, vulnerable_grant(True, True))
    assert accepted(True, True, reference_gate(True, True, True, True))
    print('1 authorized/no fault: both allow')

    # 2: fault-free unauthorized image is rejected.
    assert not accepted(True, True, vulnerable_grant(True, False))
    assert not accepted(True, True, reference_gate(True, False, True, False))
    print('2 unauthorized/no fault: both reject')

    # 3: stored FALSE result is upset to TRUE after completion.
    stored = bool(0 ^ 1)
    assert accepted(True, True, vulnerable_grant(True, stored))
    assert not accepted(True, True, reference_gate(True, stored, True, False))
    print('3 result upset: vulnerable bypass; trusted reference blocks')

    # 4: upstream decision fault produces a *legal* encoded True.
    ref_pass = False
    corrupted_decision = not ref_pass
    encoded = TRUE if corrupted_decision else FALSE
    assert decode_true(encoded) and not ref_pass
    print('4 upstream upset before encoding: exact decode is bypassed')

    # 5: legal state and legal graph edge, but false authorization.
    legal_states = {'WAIT', 'CHECK', 'RELEASE', 'ERROR'}
    edges = {('WAIT', 'CHECK'), ('CHECK', 'RELEASE'), ('CHECK', 'ERROR')}
    previous = 'CHECK'
    current = 'RELEASE' if corrupted_decision else 'ERROR'
    assert current in legal_states and (previous, current) in edges
    assert not ref_pass  # Independent history/security check fails.
    print('5 legal state/edge: membership passes; authorization fails')

    # 6: a later alert does not undo an already accepted operation.
    fault_at, commit_at, alert_at, reset_at = 0, 1, 2, 5
    assert fault_at < commit_at < alert_at < reset_at
    unauthorized_commit = accepted(True, True, stored) and not ref_pass
    eventually_alerts = alert_at < reset_at
    assert unauthorized_commit and eventually_alerts
    print('6 delayed alert: unauthorized commit happened first')
    print('PASS: 16 codewords + 4 single-bit faults + 6 scenarios')


if __name__ == '__main__':
    main()
