fix(cli): validate and preserve model attribution (#1459) - #1597
enricopiovesan merged 6 commits into
Conversation
|
All contributors have signed the CLA ✍️ ✅ |
|
I have read the CLA Document and I hereby sign the CLA |
|
recheck |
|
Thanks @DevChiniwala — appreciate the first PR and for closing the door on #1459 (validate and preserve model attribution). CLA is green ✅. Eng will take the code/CI review from here (not merging from this note). If you haven't already, a star on traverse-framework/traverse is always welcome — optional, no pressure. |
…ssion parity (traverse-framework#1459) Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…raverse-framework#1459) Port every contract-decidable registry CI rule for the ai object (registry Spec 001 FR-017 + Spec 026) into crates/traverse-cli/src/ai_admission.rs: immutable commit pins, SPDX syntax (license-expression semantics over the spdx crate's id tables), the full rights record, evidence-file shape, derivation, data obligations, rights_change. ai: null is treated as absent. Errors carry registry CI codes. Parity is proven against the registry-owned fixture corpus vendored and pinned at registry f5221c43 (Spec 056 v1.1.0 FR-014..FR-019, Decision 109). Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…ol table (traverse-framework#1459) A differential fuzz against registry CI found the spdx crate disagrees with license-expression on exception classification, its license list, multi-word aliases and a trailing-operator quirk. Vendor the registry's exported symbol table (registry#630) under the same pin as the corpus, resolve ids only through it, merge multi-word aliases, and drop the spdx dependency. Also fix a trailing-newline edge in the release-URL check. Fuzz rerun: 0 disagreements over 27,263 cases. Decision 109 amended. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…traverse-framework#1459) Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
|
Landed — thanks again @DevChiniwala. Capability publish now rejects contract-decidable bad Honesty Q&A on the site: https://traverse-framework.com/questions/does-capability-publish-validate-model-attribution.html If you want another ticket in this area, happy to point you at one. |
|
Thanks for carrying the initial fix through full registry-admission parity and for preserving my original commit. I reviewed the landed scope: the pinned corpus/symbol-table parity and contract-decidable boundary are especially useful guidance for future contributions. I?d be glad to take another bounded, currently prioritized ticket in this area. #1598 looks like the closest follow-up, but I?m happy to follow your preferred ordering if another unclaimed item would be more useful. |
Summary
Fixes #1459.
capability publishnow rejects, offline and before any registry Git write, everyaiobject that registry CI would reject on rules decidable from the contract alone. It also keeps theaiobject verbatim in the generated registry contract; until now it was silently dropped.This PR started as @DevChiniwala's FR-017 shape check (the first commit, kept as-is). A maintainer review found the CLI checked less than registry CI does. Decision 109 extended the scope, and the remaining commits implement it.
Governing Spec
Spec 056 is amended to v1.1.0 in this PR (FR-014–FR-019, Decision 109). It mirrors registry Spec 001 FR-017 (Decision 124) and registry Spec 026 (Decision 127).
Project Item
What Changed
Rules (
crates/traverse-cli/src/ai_admission.rs): a faithful port of registrycapability_validation.py, contract-decidable parts only. It covers:string[]is accepted only whenmodel_backedis false;license-expressionsymbol table (registry#630), covering licences vs. exceptions, aliases and multi-word aliases;derivation,data_obligationsandrights_change.Each failure carries the registry CI error code.
What stays with registry CI: downloading evidence files to verify their digests, the
model-weights.jsoncross-check, and rights drift (FR-015). Nothing is fetched.ai: nullcounts as absent, as it does in registry CI (FR-017).Parity: the registry fixture corpus (1.1.0) and SPDX symbol table (feat(ci): ai admission fixture corpus for publish-time parity (#627) registry#629, feat(ci): export SPDX symbol table and reject dangling operators (#627 follow-up) registry#630) are vendored in
crates/traverse-cli/registry-admission/with aPIN.jsonholding the registry commit and each file's sha256. A test must agree with everycontract_decidable+newly_addedfixture and lists the rest as skipped (FR-019).Differential fuzz (not committed) of the CLI port against registry CI: 0 disagreements across 27,263 cases (5,000 mutated
aiobjects, 22,263 SPDX expressions).Docs:
approved-specs.jsonentry;capability publishhelp text;No new dependencies.
Depends on
e9b8b104).Validation
cargo test -p traverse-cli-rs: 512 passed, including the corpus parity testcargo clippy -p traverse-cli-rs --all-targets -- -D warningsandcargo fmt --checklocal_preflight.sh🤖 Generated with Claude Code