Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 2 additions & 0 deletions public/llms.txt
Original file line number Diff line number Diff line change
Expand Up @@ -16,6 +16,7 @@ Current packages: crates.io at 0.14.0 (pin `traverse-registry` at `=0.25.0` if y
- [What is real today](https://traverse-framework.com/what-is-real-today.html): citeable snapshot — skill-first, one shared `runtime.wasm`, honest consumers, pre-1.0, no invented customers.
- [What does discover → execute → trace mean?](https://traverse-framework.com/questions/what-does-discover-execute-trace-mean.html): the value loop in plain language — agent proposes, runtime decides.
- [Where does business logic live?](https://traverse-framework.com/questions/where-does-business-logic-live-in-traverse.html): capabilities = non-UI domain rules; hosts = UI + I/O; one concern per package; “apps not ready” ≠ leave logic in the host; utilities teach the pipe, not the ceiling. Narrative: [Where business logic lives (hosts stay thin)](https://traverse-framework.com/blog/where-business-logic-lives.html).
- [What does “apps are not ready” mean?](https://traverse-framework.com/questions/what-does-apps-not-ready-mean.html) · [Is Traverse only for tiny utilities?](https://traverse-framework.com/questions/is-traverse-only-for-tiny-utilities.html): help-wanted door phrase (no product-shell PRs); utilities teach the pipe, not a size ceiling; domain packs in scope.
- [What does “the agent proposes; the runtime decides” mean?](https://traverse-framework.com/questions/what-does-agent-proposes-runtime-decides-mean.html): boundary in one page — agents search/plan/suggest; runtime validates, executes or denies, leaves a trace.
- [What is one shared runtime.wasm?](https://traverse-framework.com/questions/what-is-one-shared-runtime-wasm.html): embedders are clients; honest consumer list.
- [The agent freestyled a $2.4M wire. The runtime said no.](https://traverse-framework.com/blog/agent-freestyle-blocked.html): project direction in one scene — agent proposes, runtime decides (deny + trace).
Expand Down Expand Up @@ -58,6 +59,7 @@ Current packages: crates.io at 0.14.0 (pin `traverse-registry` at `=0.25.0` if y
- [Security & Permanence Audit](https://traverse-framework.com/security-audit.html): every known finding, its GitHub ticket, and its real status — not a marketing page.
- [FAQ](https://traverse-framework.com/faq.html) and [Questions](https://traverse-framework.com/questions.html): 70+ specific Q&A pages, mostly long-tail but accurate.
- [What is exact-ref model execution?](https://traverse-framework.com/questions/what-is-exact-ref-model-execution.html): signed schema `2.0.0` + `model.sig.json`; host-owned trust; `digits-mlp-1.0.0` (test-only key; prod signing #1567); native+web execute only in v0.14.0 (first landed in v0.12.0). Embedder notes: [v0.14.0: what changed for embedders](https://traverse-framework.com/blog/traverse-0-14-0-what-changed-for-embedders.html) · [Release](https://github.com/traverse-framework/traverse/releases/tag/v0.14.0) · [Announcement #1576](https://github.com/orgs/traverse-framework/discussions/1576).
- [How do hosts trust signed models?](https://traverse-framework.com/questions/how-do-hosts-trust-signed-models.html): host-owned trust roots gate `register_package`; pin by digest + `model.sig.json`; test-only digits-mlp key; exact-ref execute native+web only — no claimed ONNX generic runner.
- [How does Traverse complement Hugging Face?](https://traverse-framework.com/questions/how-does-traverse-complement-hugging-face.html): Hub = provenance; Traverse = pinned signed client-first capability; not Transformers.js/Hub replacement; no defer promise until a second executor exists.

## Optional
Expand Down
48 changes: 48 additions & 0 deletions src/pages/questions/can-domain-logic-stay-in-javascript.astro
Original file line number Diff line number Diff line change
@@ -0,0 +1,48 @@
---
import QuestionLayout from '@layouts/QuestionLayout.astro';

const jsonLd = JSON.stringify({
'@context': 'https://schema.org',
'@type': 'FAQPage',
mainEntity: [{
'@type': 'Question',
name: 'Can domain logic stay in JavaScript forever?',
acceptedAnswer: {
'@type': 'Answer',
text: 'Single-host glue can stay in JavaScript. Shared non-UI rules that must match across hosts belong in Traverse capabilities under discover → execute → trace. Deny-by-default I/O (stdin/stdout JSON today) limits authority, not how rich the rule can be. The React guide’s “never touches Rust/WASM directly” means use the embedder client — not reimplement the business rule in React. One shared runtime.wasm; there is no Python SDK (CLI shell-out only). Check Platforms for honest host status.',
},
}],
});

const relatedLinks = [
{ href: '/questions/where-does-business-logic-live-in-traverse.html', label: 'Where does business logic live in Traverse?' },
{ href: '/questions/what-does-apps-not-ready-mean.html', label: 'What does “apps are not ready” mean?' },
{ href: '/questions/can-i-use-traverse-with-react.html', label: 'Can I use Traverse with React?' },
{ href: '/docs/guides/react-integration.html', label: 'React integration guide' },
{ href: '/platforms.html', label: 'Platforms' },
{ href: '/questions/does-traverse-have-a-python-sdk.html', label: 'Does Traverse have a Python SDK?' },
{ href: '/blog/where-business-logic-lives.html', label: 'Where business logic lives (hosts stay thin)' },
];
---
<QuestionLayout
title="Can domain logic stay in JavaScript forever?"
description="Host glue can stay in JS. Shared non-UI rules that must match across hosts belong in capabilities. Deny-by-default I/O limits authority, not richness. Use the embedder — do not reimplement rules in React."
canonical="https://traverse-framework.com/questions/can-domain-logic-stay-in-javascript.html"
category="Contracts and capabilities"
relatedLinks={relatedLinks}
jsonLd={jsonLd}
>
<p><strong>Short answer:</strong> glue that only one host needs can stay in JavaScript. Shared non-UI rules that must behave the same everywhere belong in capabilities — not forever in the React tree “because WASM cannot touch disk.”</p>

<h2>When JS is fine</h2>
<p>Session wiring, view-model mapping, one-off UI helpers, and host-local adapters that never need to match another OS or client can live in JS/TS. That is normal host work. Traverse does not ask you to WASM every line of a front-end app.</p>

<h2>When it should leave the host</h2>
<p>If two hosts disagreeing would be a bug — pricing, eligibility, consent, codecs, scorers, export gates — put the rule in a capability under discover → execute → trace. The host calls the capability; it does not re-own the rule. See <a href="/questions/where-does-business-logic-live-in-traverse.html">Where does business logic live in Traverse?</a></p>

<h2>Deny-by-default I/O is not “keep it in React”</h2>
<p>Capabilities do not get ambient filesystem or network access. Today’s common boundary is stdin/stdout JSON through the embedder. That limits <em>authority</em>, not how rich the domain rule can be. “WASM can’t open a file, so the rule stays in JS” is the wrong conclusion. Call the capability; keep the host thin.</p>

<h2>What the React guide actually says</h2>
<p>The React integration guide’s “app never touches Rust/WASM directly” means you go through the published embedder client (<code>traverse-embedder-web</code>). It does <strong>not</strong> mean reimplement business rules in React components. One shared <code>runtime.wasm</code> everywhere; language SDKs are clients, not second runtimes. There is <strong>no Python SDK</strong> — Python shells out to the CLI today. Check <a href="/platforms.html">Platforms</a> before assuming a host is shipped.</p>
</QuestionLayout>
46 changes: 46 additions & 0 deletions src/pages/questions/how-do-hosts-trust-signed-models.astro
Original file line number Diff line number Diff line change
@@ -0,0 +1,46 @@
---
import QuestionLayout from '@layouts/QuestionLayout.astro';

const jsonLd = JSON.stringify({
'@context': 'https://schema.org',
'@type': 'FAQPage',
mainEntity: [{
'@type': 'Question',
name: 'How do hosts trust signed models in Traverse?',
acceptedAnswer: {
'@type': 'Answer',
text: 'As of Traverse v0.14.0 (signed Spec 138), model packages use schema 2.0.0 manifests plus a detached Ed25519 model.sig.json. Host-owned trust roots gate register_package / registerPackage; apps never add trust. Pin by digest and signature, never a naked URL. The first trained package digits-mlp-1.0.0 ships with a test-only key; production signing is #1567. Exact-ref execute is native Rust and web only — Swift, Kotlin, and .NET do not execute exact-ref yet. ONNX as a generic runner is not shipped.',
},
}],
});

const relatedLinks = [
{ href: '/questions/what-is-exact-ref-model-execution.html', label: 'What is exact-ref model execution?' },
{ href: '/blog/traverse-0-14-0-what-changed-for-embedders.html', label: 'v0.14.0: what changed for embedders' },
{ href: '/questions/how-do-i-verify-a-signed-capability-artifact.html', label: 'How do I verify a signed capability artifact?' },
{ href: '/questions/what-is-the-wasm-sandbox.html', label: 'What is the WASM sandbox?' },
{ href: '/platforms.html', label: 'Platforms' },
];
---
<QuestionLayout
title="How do hosts trust signed models in Traverse?"
description="v0.14.0 signed Spec 138: schema 2.0.0 + model.sig.json; host-owned trust roots; pin by digest; digits-mlp test-only key; exact-ref execute on native+web only."
canonical="https://traverse-framework.com/questions/how-do-hosts-trust-signed-models.html"
category="Runtime and Architecture"
relatedLinks={relatedLinks}
jsonLd={jsonLd}
>
<p><strong>Short answer:</strong> the host owns the trust roots. Packages enter only through <code>register_package</code> / <code>registerPackage</code> after signature and digest checks against pins the app already declared. A naked URL is never identity.</p>

<h2>Signed packages (v0.14.0)</h2>
<p><a href="https://github.com/traverse-framework/traverse/releases/tag/v0.14.0">Traverse v0.14.0</a> lands signed Spec 138: schema <code>2.0.0</code> manifests and a detached Ed25519 <code>model.sig.json</code> over the exact <code>model.manifest.json</code> bytes. App manifests pin those bytes (SHA-256), plus <code>target</code>, expected <code>rights</code>, and an optional signer <code>key_id</code>. Embedder notes: <a href="/blog/traverse-0-14-0-what-changed-for-embedders.html">what changed for embedders</a>. Announcement: <a href="https://github.com/orgs/traverse-framework/discussions/1576">Discussion #1576</a>.</p>

<h2>Host-owned trust roots</h2>
<p>Trust lists live on the host (<code>TrustedModelKeys</code> on Rust, <code>trustedPublicKeysHex</code> on web). Applications cannot inject keys. Registration verifies the signature against a trusted key, the digest against exactly one pin, and the manifest schema (unknown fields fail closed), rights, target, and limits. Every execute re-hashes cached bytes. Failures stay typed (<code>model_unavailable</code> / <code>model_incompatible</code>) with a stable <code>reason</code>.</p>

<h2>Test-only key vs production</h2>
<p>The first trained package <code>digits-mlp-1.0.0</code> is signed with a <strong>test-only</strong> key so CI and demos can exercise the path. Production model signing is tracked separately as <a href="https://github.com/traverse-framework/traverse/issues/1567">#1567</a>. Do not treat the test key as a production trust root.</p>

<h2>Host honesty</h2>
<p>Exact-ref execute is implemented on native Rust and the web embedder today. Swift, Kotlin, and .NET embedders do <em>not</em> execute exact-ref models yet — check <a href="/platforms.html">Platforms</a>. This page is about signed-model trust for Spec 138 exact-ref; it does <strong>not</strong> claim a generic ONNX runner is shipped. Deeper loop: <a href="/questions/what-is-exact-ref-model-execution.html">What is exact-ref model execution?</a></p>
</QuestionLayout>
4 changes: 4 additions & 0 deletions src/pages/questions/index.astro
Original file line number Diff line number Diff line change
Expand Up @@ -24,6 +24,9 @@ const groups = [
label: 'Contracts and capabilities',
items: [
['where-does-business-logic-live-in-traverse.html', 'Where does business logic live in Traverse?'],
['what-does-apps-not-ready-mean.html', 'What does “apps are not ready” mean in Traverse?'],
['is-traverse-only-for-tiny-utilities.html', 'Is Traverse only for tiny utilities?'],
['can-domain-logic-stay-in-javascript.html', 'Can domain logic stay in JavaScript forever?'],
['what-is-a-contract-in-traverse.html', 'What is a contract in Traverse?'],
['what-is-contract-driven.html', 'What does "contract-driven" mean in Traverse?'],
['how-do-i-write-a-capability-contract.html', 'How do I write a capability contract?'],
Expand Down Expand Up @@ -51,6 +54,7 @@ const groups = [
['what-is-the-capability-registry.html', 'What is the capability registry?'],
['what-is-governed-composition.html', 'What is governed composition in Traverse?'],
['what-is-exact-ref-model-execution.html', 'What is exact-ref model execution in Traverse?'],
['how-do-hosts-trust-signed-models.html', 'How do hosts trust signed models in Traverse?'],
['what-does-the-discover-page-do.html', 'What does the Traverse /discover page do?'],
['how-do-placement-targets-work.html', 'How do placement targets work in Traverse?'],
['what-is-a-trace-artifact.html', 'What is a trace artifact in Traverse?'],
Expand Down
47 changes: 47 additions & 0 deletions src/pages/questions/is-traverse-only-for-tiny-utilities.astro
Original file line number Diff line number Diff line change
@@ -0,0 +1,47 @@
---
import QuestionLayout from '@layouts/QuestionLayout.astro';

const jsonLd = JSON.stringify({
'@context': 'https://schema.org',
'@type': 'FAQPage',
mainEntity: [{
'@type': 'Question',
name: 'Is Traverse only for tiny utilities?',
acceptedAnswer: {
'@type': 'Answer',
text: 'No. Utility helpers in the registry teach the publish pipeline and CI gates. They are legitimate, but they are not the product identity and not a size ceiling. “One small capability” means one concern per package. Preferred publishes are business-shaped: pricing, eligibility, scorers, gates, codecs — non-UI domain rules under discover → execute → trace.',
},
}],
});

const relatedLinks = [
{ href: '/questions/where-does-business-logic-live-in-traverse.html', label: 'Where does business logic live in Traverse?' },
{ href: '/questions/what-does-apps-not-ready-mean.html', label: 'What does “apps are not ready” mean?' },
{ href: '/blog/where-business-logic-lives.html', label: 'Where business logic lives (hosts stay thin)' },
{ href: '/questions/what-is-a-wasm-capability.html', label: 'What is a WASM capability?' },
{ href: '/questions/can-i-use-traverse-for-pricing-logic.html', label: 'Can I use Traverse for pricing logic?' },
{ href: '/what-is-real-today.html', label: 'What is real today' },
];
---
<QuestionLayout
title="Is Traverse only for tiny utilities?"
description="No. Slugify-style helpers teach the publish pipe — they are not the ceiling. Preferred capabilities are business-shaped: pricing, eligibility, scorers, gates, codecs."
canonical="https://traverse-framework.com/questions/is-traverse-only-for-tiny-utilities.html"
category="Contracts and capabilities"
relatedLinks={relatedLinks}
jsonLd={jsonLd}
>
<p><strong>Short answer:</strong> no. Small utility helpers teach the publish pipeline. They are not Traverse’s product identity and not a size limit on what a capability may contain.</p>

<h2>Why utilities exist</h2>
<p>The registry includes helpers such as slugify, truncate, and email validate. Those packages exercise contracts, digests, CI gates, and the human-reviewed PR path with a small surface. That is useful onboarding. It is not a statement that “real” work stays in the host.</p>

<h2>“One small capability” means one concern</h2>
<p>When docs say keep a capability small, they mean <strong>one concern per package</strong> — a clear contract boundary, not “keep the bytes tiny forever.” A pricing rule, an eligibility check, a mesh codec, or an export gate can be substantial and still be one capability. Split by concern when two rules would evolve or authorize differently; do not split because someone equated WASM with toy utils.</p>

<h2>Preferred publishes are business-shaped</h2>
<p>What we want in the catalog: deterministic decisions, domain transforms, policy gates, scorers, codecs — anything that must match across hosts and leave a trace. Put that under discover → execute → trace. Leave UI, session, and ambient I/O in the host. Narrative: <a href="/blog/where-business-logic-lives.html">Where business logic lives (hosts stay thin)</a>.</p>

<h2>Related misconceptions</h2>
<p>“Apps are not ready” blocks product-shell PRs, not domain packs — see <a href="/questions/what-does-apps-not-ready-mean.html">What does “apps are not ready” mean?</a> Placement in one page: <a href="/questions/where-does-business-logic-live-in-traverse.html">Where does business logic live in Traverse?</a></p>
</QuestionLayout>
Loading
Loading