Skip to content

fix(cli): validate and preserve model attribution (#1459) - #1597

Merged
enricopiovesan merged 6 commits into
traverse-framework:mainfrom
DevChiniwala:codex/issue-1459-model-attribution
Oct 2, 2026
Merged

enricopiovesan merged 6 commits into
traverse-framework:mainfrom
DevChiniwala:codex/issue-1459-model-attribution

Conversation

@DevChiniwala

@DevChiniwala DevChiniwala commented Oct 1, 2026 •

Copy link
Copy Markdown
Contributor

Summary

Fixes #1459. capability publish now rejects, offline and before any registry Git write, every ai object that registry CI would reject on rules decidable from the contract alone. It also keeps the ai object verbatim in the generated registry contract; until now it was silently dropped.

This PR started as @DevChiniwala's FR-017 shape check (the first commit, kept as-is). A maintainer review found the CLI checked less than registry CI does. Decision 109 extended the scope, and the remaining commits implement it.

Governing Spec

  • 056-capability-publish
  • 102-contract-surface-coverage

Spec 056 is amended to v1.1.0 in this PR (FR-014–FR-019, Decision 109). It mirrors registry Spec 001 FR-017 (Decision 124) and registry Spec 026 (Decision 127).

Project Item

What Changed

  • Rules (crates/traverse-cli/src/ai_admission.rs): a faithful port of registry capability_validation.py, contract-decidable parts only. It covers:

    • the FR-017 shapes, where legacy string[] is accepted only when model_backed is false;
    • immutable 40/64-hex commit pins;
    • SPDX syntax: the CLI parses the grammar itself and resolves ids only through the registry's exported license-expression symbol table (registry#630), covering licences vs. exceptions, aliases and multi-word aliases;
    • the Spec 026 rights record, including the contradictions;
    • evidence-file shape;
    • derivation, data_obligations and rights_change.

    Each failure carries the registry CI error code.

  • What stays with registry CI: downloading evidence files to verify their digests, the model-weights.json cross-check, and rights drift (FR-015). Nothing is fetched.

  • ai: null counts as absent, as it does in registry CI (FR-017).

  • Parity: the registry fixture corpus (1.1.0) and SPDX symbol table (feat(ci): ai admission fixture corpus for publish-time parity (#627) registry#629, feat(ci): export SPDX symbol table and reject dangling operators (#627 follow-up) registry#630) are vendored in crates/traverse-cli/registry-admission/ with a PIN.json holding the registry commit and each file's sha256. A test must agree with every contract_decidable + newly_added fixture and lists the rest as skipped (FR-019).

  • Differential fuzz (not committed) of the CLI port against registry CI: 0 disagreements across 27,263 cases (5,000 mutated ai objects, 22,263 SPDX expressions).

  • Docs:

    • Decision 109;
    • the Spec 056 v1.1.0 amendment and its approved-specs.json entry;
    • the capability publish help text;
    • the "Registry model attribution" section of the authoring guide.
  • No new dependencies.

Depends on

Validation

  • Spec alignment checked
  • Contract alignment checked
  • cargo test -p traverse-cli-rs: 512 passed, including the corpus parity test
  • cargo clippy -p traverse-cli-rs --all-targets -- -D warnings and cargo fmt --check
  • local_preflight.sh
  • Required validation gates passing (fork CI needs maintainer approval)
  • CLA check passing

🤖 Generated with Claude Code

@github-actions

github-actions Bot commented Oct 1, 2026 •

Copy link
Copy Markdown

All contributors have signed the CLA ✍️ ✅
Posted by the CLA Assistant Lite bot.

@DevChiniwala

Copy link
Copy Markdown
Contributor Author

I have read the CLA Document and I hereby sign the CLA

@DevChiniwala

Copy link
Copy Markdown
Contributor Author

recheck

@DevChiniwala
DevChiniwala marked this pull request as ready for review October 1, 2026 15:19
Copilot AI balanced review requested due to automatic review settings October 1, 2026 15:19

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

@enricopiovesan

Copy link
Copy Markdown
Collaborator

Thanks @DevChiniwala — appreciate the first PR and for closing the door on #1459 (validate and preserve model attribution). CLA is green ✅. Eng will take the code/CI review from here (not merging from this note). If you haven't already, a star on traverse-framework/traverse is always welcome — optional, no pressure.

…raverse-framework#1459)

Port every contract-decidable registry CI rule for the ai object (registry
Spec 001 FR-017 + Spec 026) into crates/traverse-cli/src/ai_admission.rs:
immutable commit pins, SPDX syntax (license-expression semantics over the
spdx crate's id tables), the full rights record, evidence-file shape,
derivation, data obligations, rights_change. ai: null is treated as absent.
Errors carry registry CI codes. Parity is proven against the registry-owned
fixture corpus vendored and pinned at registry f5221c43 (Spec 056 v1.1.0
FR-014..FR-019, Decision 109).

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
enricopiovesan and others added 2 commits October 2, 2026 12:34
…ol table (traverse-framework#1459)

A differential fuzz against registry CI found the spdx crate disagrees with
license-expression on exception classification, its license list,
multi-word aliases and a trailing-operator quirk. Vendor the registry's
exported symbol table (registry#630) under the same pin as the corpus,
resolve ids only through it, merge multi-word aliases, and drop the spdx
dependency. Also fix a trailing-newline edge in the release-URL check.
Fuzz rerun: 0 disagreements over 27,263 cases. Decision 109 amended.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@enricopiovesan
enricopiovesan enabled auto-merge (squash) October 2, 2026 19:55
@enricopiovesan
enricopiovesan merged commit 10f07fe into traverse-framework:main Oct 2, 2026
19 checks passed
@enricopiovesan

Copy link
Copy Markdown
Collaborator

Landed — thanks again @DevChiniwala. Capability publish now rejects contract-decidable bad ai objects offline before any registry Git write, and keeps ai verbatim (Decision 109 / Spec 056 v1.1.0).

Honesty Q&A on the site: https://traverse-framework.com/questions/does-capability-publish-validate-model-attribution.html

If you want another ticket in this area, happy to point you at one.

@DevChiniwala

Copy link
Copy Markdown
Contributor Author

Thanks for carrying the initial fix through full registry-admission parity and for preserving my original commit. I reviewed the landed scope: the pinned corpus/symbol-table parity and contract-decidable boundary are especially useful guidance for future contributions.

I?d be glad to take another bounded, currently prioritized ticket in this area. #1598 looks like the closest follow-up, but I?m happy to follow your preferred ordering if another unclaimed item would be more useful.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

CLI: capability publish requires object-shaped ai.models for model_backed agents

3 participants