diff --git a/public/llms.txt b/public/llms.txt
index 09d03fb..246e464 100644
--- a/public/llms.txt
+++ b/public/llms.txt
@@ -58,13 +58,13 @@ Current packages: crates.io at 0.14.0 (pin `traverse-registry` at `=0.25.0` if y
- [Changelog](https://traverse-framework.com/changelog.html): release-by-release history.
- [Security & Permanence Audit](https://traverse-framework.com/security-audit.html): every known finding, its GitHub ticket, and its real status — not a marketing page.
- [FAQ](https://traverse-framework.com/faq.html) and [Questions](https://traverse-framework.com/questions.html): 70+ specific Q&A pages, mostly long-tail but accurate.
-- [What is exact-ref model execution?](https://traverse-framework.com/questions/what-is-exact-ref-model-execution.html): signed schema `2.0.0` + `model.sig.json`; host-owned trust; `digits-mlp-1.0.0` (test-only key; prod signing #1567); native+web execute only in v0.14.0 (first landed in v0.12.0). Embedder notes: [v0.14.0: what changed for embedders](https://traverse-framework.com/blog/traverse-0-14-0-what-changed-for-embedders.html) · [Release](https://github.com/traverse-framework/traverse/releases/tag/v0.14.0) · [Announcement #1576](https://github.com/orgs/traverse-framework/discussions/1576).
-- [How do hosts trust signed models?](https://traverse-framework.com/questions/how-do-hosts-trust-signed-models.html): host-owned trust roots gate `register_package`; pin by digest + `model.sig.json`; test-only digits-mlp key; exact-ref execute native+web only — no claimed ONNX generic runner.
+- [What is exact-ref model execution?](https://traverse-framework.com/questions/what-is-exact-ref-model-execution.html): signed schema `2.0.0` + `model.sig.json`; host-owned trust; `digits-mlp-1.0.0` (test-only key; prod signing #1567); native+web+Swift ExactModelHost execute (swift-host-v0.14.0-1 / #1579); Kotlin/.NET not yet (first landed in v0.12.0). Embedder notes: [v0.14.0: what changed for embedders](https://traverse-framework.com/blog/traverse-0-14-0-what-changed-for-embedders.html) · [Release](https://github.com/traverse-framework/traverse/releases/tag/v0.14.0) · [Announcement #1576](https://github.com/orgs/traverse-framework/discussions/1576).
+- [How do hosts trust signed models?](https://traverse-framework.com/questions/how-do-hosts-trust-signed-models.html): host-owned trust roots gate `register_package`; pin by digest + `model.sig.json`; test-only digits-mlp key; exact-ref execute native+web+Swift ExactModelHost; Kotlin/.NET not yet — no claimed ONNX generic runner.
- [How does Traverse complement Hugging Face?](https://traverse-framework.com/questions/how-does-traverse-complement-hugging-face.html): Hub = provenance; Traverse = pinned signed client-first capability; not Transformers.js/Hub replacement; no defer promise until a second executor exists.
## Optional
-- [Blog](https://traverse-framework.com/blog.html): engineering write-ups, dated — treat as historical snapshots, not current-state claims. Latest: [v0.14.0: what changed for embedders](https://traverse-framework.com/blog/traverse-0-14-0-what-changed-for-embedders.html) (signed Spec 138; native+web exact-ref; test-only digits-mlp key). Also: [Where business logic lives (hosts stay thin)](https://traverse-framework.com/blog/where-business-logic-lives.html). Weekly demo: [Same WASM. Browser and Node match. Agent still can’t freestyle.](https://traverse-framework.com/blog/same-wasm-multi-host.html) (v0.13.0 multi-host). Prior: [agent freestyle → blocked](https://traverse-framework.com/blog/agent-freestyle-blocked.html). Authoring: [You don't need Rust to publish a capability](https://traverse-framework.com/blog/you-dont-need-rust-to-publish-a-capability.html).
+- [Blog](https://traverse-framework.com/blog.html): engineering write-ups, dated — treat as historical snapshots, not current-state claims. Latest: [v0.14.0: what changed for embedders](https://traverse-framework.com/blog/traverse-0-14-0-what-changed-for-embedders.html) (signed Spec 138; native+web+Swift ExactModelHost exact-ref; test-only digits-mlp key). Also: [Where business logic lives (hosts stay thin)](https://traverse-framework.com/blog/where-business-logic-lives.html). Weekly demo: [Same WASM. Browser and Node match. Agent still can’t freestyle.](https://traverse-framework.com/blog/same-wasm-multi-host.html) (v0.13.0 multi-host). Prior: [agent freestyle → blocked](https://traverse-framework.com/blog/agent-freestyle-blocked.html). Authoring: [You don't need Rust to publish a capability](https://traverse-framework.com/blog/you-dont-need-rust-to-publish-a-capability.html).
- [Discover](https://traverse-framework.com/discover.html): a live browser demo that pulls the public registry and executes a reviewed plan locally. Read [what it proves](https://traverse-framework.com/blog/what-discover-proves.html) before quoting it.
- [Compare: vs microservices](https://traverse-framework.com/compare/vs-microservices.html), [vs serverless](https://traverse-framework.com/compare/vs-serverless.html), [vs function calling](https://traverse-framework.com/compare/vs-function-calling.html), [vs agent runtimes](https://traverse-framework.com/compare/vs-agent-runtimes.html), [vs WASM runtimes](https://traverse-framework.com/compare/vs-wasm-runtimes.html), [vs cross-platform frameworks](https://traverse-framework.com/compare/vs-cross-platform-frameworks.html)
- [About](https://traverse-framework.com/about.html): project history and motivation.
diff --git a/src/pages/blog/index.astro b/src/pages/blog/index.astro
index db95440..2364f9f 100644
--- a/src/pages/blog/index.astro
+++ b/src/pages/blog/index.astro
@@ -2,7 +2,7 @@
import SubpageLayout from '@layouts/SubpageLayout.astro';
const posts = [
- { href: '/blog/traverse-0-14-0-what-changed-for-embedders.html', title: 'v0.14.0: what changed for embedders', desc: 'Featured · Signed Spec 138 (schema 2.0.0 + model.sig.json), host-owned trust, registerPackage, digits-mlp-1.0.0 (test-only key). Native + web execute; Swift/Kotlin/.NET do not yet. crates/npm 0.14.0; registry 0.25.0.' },
+ { href: '/blog/traverse-0-14-0-what-changed-for-embedders.html', title: 'v0.14.0: what changed for embedders', desc: 'Featured · Signed Spec 138 (schema 2.0.0 + model.sig.json), host-owned trust, registerPackage, digits-mlp-1.0.0 (test-only key). Native + web + Swift ExactModelHost execute; Kotlin/.NET do not yet. crates/npm 0.14.0; registry 0.25.0.' },
{ href: '/blog/same-wasm-multi-host.html', title: 'Same WASM. Browser and Node match. Agent still can’t freestyle.', desc: 'Featured · Weekly demo: identical core.authorize@1.2.0 bytes on Browser + Node deny junior_analyst $2.4M wire; allow treasury_ops + MFA/dual-control. Traverse v0.13.0 multi-host.' },
{ href: '/blog/where-business-logic-lives.html', title: 'Where business logic lives (hosts stay thin)', desc: 'Featured · Narrative companion to the where-logic Q&A: capabilities hold non-UI domain rules; hosts = UI + I/O; utilities ≠ ceiling; apps-not-ready ≠ leave logic in the host.' },
{ href: '/blog/what-is-real-today-start-here.html', title: 'Start here: what is real in Traverse today', desc: 'Featured · Narrative companion to /what-is-real-today: discover→execute→trace, skill-first authoring, one shared runtime.wasm, honest consumers, pre-1.0.' },
diff --git a/src/pages/blog/traverse-0-14-0-what-changed-for-embedders.astro b/src/pages/blog/traverse-0-14-0-what-changed-for-embedders.astro
index a705570..acb6165 100644
--- a/src/pages/blog/traverse-0-14-0-what-changed-for-embedders.astro
+++ b/src/pages/blog/traverse-0-14-0-what-changed-for-embedders.astro
@@ -27,14 +27,18 @@ const _body = `
Traverse v0.14.0 is the signed exact-ref model cut. One shared runtime.wasm. Hosts stay UI + WASI/WIT I/O. Capabilities still discover → execute → trace. The agent proposes; the runtime decides.
- Short version for embedders: model packages are signed, bound to the app that pins them, and checked against host-owned trust roots. Native Rust and the web embedder execute exact-ref models today. Swift / Kotlin / .NET do not — yet.
+ Short version for embedders: model packages are signed, bound to the app that pins them, and checked against host-owned trust roots. Native Rust, the web embedder, and Swift (ExactModelHost) execute exact-ref models today. Kotlin and .NET do not — yet.
+
+
+
+ Update (September 30, 2026): overnight after the v0.14.0 product cut, #1579 closed and the published xcframework swift-host-v0.14.0-1 exposes Spec 138 parity. packages/swift/TraverseEmbedder/Package.swift pins that binary target. Digits conformance is byte-identical on Swift (1,727 / 1,797). Kotlin (#1580) and .NET still do not execute exact-ref.
Breaking for Spec 138 consumers
Manifests move to schema 2.0.0. Every package ships a detached Ed25519 model.sig.json over the exact model.manifest.json bytes.
Host-owned trust roots: TrustedModelKeys (Rust) / trustedPublicKeysHex (web and Swift). Apps never add trust.
register_package / registerPackage replaces insertVerified — signature, trusted key, digest, schema, rights, target, and limits are checked before the package enters the cache. Every execute re-hashes cached bytes.
Pins bind the SHA-256 of those manifest bytes and declare target, expected rights, and an optional signer key_id.
@@ -46,8 +50,9 @@ const _body = `
Honest host matrix
-
Rust native + web — exact-ref execute ships in this cut.
-
Swift / Kotlin / .NET — in-tree embedders continue; they do not execute exact-ref models yet.
+
Rust native + web — exact-ref execute shipped in the v0.14.0 product cut.
+
Swift — ExactModelHost executes signed exact-ref via the published TraverseSwiftHost xcframework (swift-host-v0.14.0-1) and the in-repo Package.swift binary pin. Still not a CocoaPods / Swift Package Index first-class package; distribution is GitHub Release + SPM binary target.
+
Kotlin / .NET — in-tree embedders continue; they do not execute exact-ref models yet.
SDKs, MCP, and CLI are embedders and clients of the same orchestrator — not different Traverse runtimes.
v0.14.0 is a minor lockstep crate + npm release with breaking Spec 138 exact-ref surface changes (0.x minor convention). Model manifests move to schema 2.0.0 with detached Ed25519 model.sig.json; host-owned trust roots; first trained digits-mlp-1.0.0 (test-only key; production signing tracked separately). Exact-ref execute is native + web only — Swift/Kotlin/.NET do not execute exact-ref yet. Pin crates/npm at 0.14.0 and traverse-registry at =0.25.0. Product Release: Traverse v0.14.0.
+
Signed exact-ref models + digits-mlp
v0.14.0 is a minor lockstep crate + npm release with breaking Spec 138 exact-ref surface changes (0.x minor convention). Model manifests move to schema 2.0.0 with detached Ed25519 model.sig.json; host-owned trust roots; first trained digits-mlp-1.0.0 (test-only key; production signing tracked separately). Exact-ref execute is native + web + Swift ExactModelHost (xcframework swift-host-v0.14.0-1 / Package.swift pin; #1579 closed 2026-09-30) — Kotlin/.NET do not execute exact-ref yet. Pin crates/npm at 0.14.0 and traverse-registry at =0.25.0. Product Release: Traverse v0.14.0.
App state machine and target-neutral host authorities
v0.13.0 is a minor lockstep crate + npm release. Its throughline is the discover → execute → trace loop for governed, standalone embedder apps: Spec 139-embedder-app-state-machine-execution lands the app command state machine that drives that loop end to end, and Spec 140-host-authority-wit-adapters gives it target-neutral host authorities — including a real audio-input capability. crates.io and npm packages are at 0.13.0.
App state machine (Spec 139):app_command envelopes (embedder-api 1.1.0) and the state machine driver across Swift, Kotlin, .NET, and web, validated against one shared cross-host golden event log. Decision 99: invoke.input_from resolves host_connector_result.<field> at runtime; app validate rejects an unreachable reference.
Host authorities and audio-input (Spec 140): WIT host-adapter interfaces make host authorities target-neutral and runtime-owned (Decision 97), landing first for traverse.audio-input. Real adapters: Apple AVAudioEngine (verified on physical microphone hardware) and browser capture / permission. Bounded artifact staging shared by runtime, web, and Swift.
Native publish pipelines: automated release workflows for Maven Central, nuget.org, and the Swift TraverseSwiftHost.xcframework; Kotlin TraverseEmbedder at embedder-api 1.1.0 parity.
Security hardening (Decision 100):RuntimeWasmHost runs under explicit fuel and memory limits and fails closed on an out-of-bounds guest response; backup restore bounds decompressed archive-member size.
Web fixes: event order under reentrant subscriptions, pinned and zero-major registry version ranges, non-string IndexedDB state keys rejected, accurate browser planner truncation, matching JSON types required in browser plans.
Upgrade note: pin traverse-embedder-web@0.13.0 with crates at 0.13.0 (lockstep). Apps using invoke.input_from with host_connector_result.<field> need Spec 139 0.2.0 / Spec 138 0.3.0 or later. Swift consumers: TraverseSwiftHost now resolves from the swift-host-v0.13.0 release — there is no GitHub Release object for v0.13.0 (immutable-releases policy). The certified runtime.wasm digest changes in this cut (sha256:a254c161…).
v0.12.0 is a minor lockstep crate + npm release. Spec 138-governed-exact-model-execution / ADR-0074 lands host-staged traverse.model-runtime / model.execute for exact pinned WASM model packages on native and browser wasm-cpu. crates.io and npm packages are at 0.12.0.
CPU-WASM guest ABI with the echo fixture under fixtures/models/fixture-echo-1.0.0/; connector contract traverse.model-runtime 2.0.0.
traverse-embedder-web exports matching stage / execute / read helpers so browser hosts share the same envelope contract as native ExactModelHostConnector.
Upgrade note: apps that want local exact-ref models must declare exact_model_dependencies and use matching model_ref digests — provider authority fields on model.execute payloads fail closed. Pin traverse-embedder-web@0.12.0 with crates at 0.12.0. Pin traverse-registry =0.22.0 if you consume it directly. Certified runtime.wasm digest is unchanged from 0.11.0.
v0.11.0 is a minor lockstep crate + npm release. Native hosts and traverse-embedder-web drive the same nested-wasmi capability executor inside an application-owned runtime.wasm, instead of a canned WAT fixture or a hand-rolled TypeScript WASI/emit_event path. Spec 1402 is complete. crates.io and npm packages are at 0.11.0.
Nested-wasmi executor in traverse-runtime-wasm; shared engine-agnostic emit_event and placement validation in traverse-contracts.
Production RuntimeWasmHost driver; Swift/wasmi, Kotlin/Chicory, and .NET/Wasmtime conform against the real artifact; digest published via the native runtime artifact registry.
Browser BundleEmbedder and composedWorkflow load digest-verified runtime/runtime.wasm from the app bundle and retire the interim TypeScript executor.
Upgrade note: app bundles must include runtime/runtime.wasm and runtime/runtime.wasm.sha256. Bundles without them fail closed at init. Pin traverse-registry =0.21.0 if you consume it directly.
diff --git a/src/pages/questions/how-do-hosts-trust-signed-models.astro b/src/pages/questions/how-do-hosts-trust-signed-models.astro
index b83ec84..4c2ab8f 100644
--- a/src/pages/questions/how-do-hosts-trust-signed-models.astro
+++ b/src/pages/questions/how-do-hosts-trust-signed-models.astro
@@ -9,7 +9,7 @@ const jsonLd = JSON.stringify({
name: 'How do hosts trust signed models in Traverse?',
acceptedAnswer: {
'@type': 'Answer',
- text: 'As of Traverse v0.14.0 (signed Spec 138), model packages use schema 2.0.0 manifests plus a detached Ed25519 model.sig.json. Host-owned trust roots gate register_package / registerPackage; apps never add trust. Pin by digest and signature, never a naked URL. The first trained package digits-mlp-1.0.0 ships with a test-only key; production signing is #1567. Exact-ref execute is native Rust and web only — Swift, Kotlin, and .NET do not execute exact-ref yet. ONNX as a generic runner is not shipped.',
+ text: 'As of Traverse v0.14.0 (signed Spec 138), model packages use schema 2.0.0 manifests plus a detached Ed25519 model.sig.json. Host-owned trust roots gate register_package / registerPackage; apps never add trust. Pin by digest and signature, never a naked URL. The first trained package digits-mlp-1.0.0 ships with a test-only key; production signing is #1567. Exact-ref execute is native Rust, web, and Swift ExactModelHost (swift-host-v0.14.0-1); Kotlin and .NET do not execute exact-ref yet. ONNX as a generic runner is not shipped.',
},
}],
});
@@ -24,7 +24,7 @@ const relatedLinks = [
---
Traverse v0.14.0 lands signed Spec 138: schema 2.0.0 manifests and a detached Ed25519 model.sig.json over the exact model.manifest.json bytes. App manifests pin those bytes (SHA-256), plus target, expected rights, and an optional signer key_id. Embedder notes: what changed for embedders. Announcement: Discussion #1576.
Host-owned trust roots
-
Trust lists live on the host (TrustedModelKeys on Rust, trustedPublicKeysHex on web). Applications cannot inject keys. Registration verifies the signature against a trusted key, the digest against exactly one pin, and the manifest schema (unknown fields fail closed), rights, target, and limits. Every execute re-hashes cached bytes. Failures stay typed (model_unavailable / model_incompatible) with a stable reason.
+
Trust lists live on the host (TrustedModelKeys on Rust, trustedPublicKeysHex on web and Swift ExactModelHost). Applications cannot inject keys. Registration verifies the signature against a trusted key, the digest against exactly one pin, and the manifest schema (unknown fields fail closed), rights, target, and limits. Every execute re-hashes cached bytes. Failures stay typed (model_unavailable / model_incompatible) with a stable reason.
Test-only key vs production
The first trained package digits-mlp-1.0.0 is signed with a test-only key so CI and demos can exercise the path. Production model signing is tracked separately as #1567. Do not treat the test key as a production trust root.
Host honesty
-
Exact-ref execute is implemented on native Rust and the web embedder today. Swift, Kotlin, and .NET embedders do not execute exact-ref models yet — check Platforms. This page is about signed-model trust for Spec 138 exact-ref; it does not claim a generic ONNX runner is shipped. Deeper loop: What is exact-ref model execution?
+
Exact-ref execute is implemented on native Rust, the web embedder, and Swift ExactModelHost (xcframework swift-host-v0.14.0-1 + Package.swift pin). Kotlin and .NET do not execute exact-ref yet — check Platforms. This page is about signed-model trust for Spec 138 exact-ref; it does not claim a generic ONNX runner is shipped. Deeper loop: What is exact-ref model execution?
diff --git a/src/pages/questions/what-is-exact-ref-model-execution.astro b/src/pages/questions/what-is-exact-ref-model-execution.astro
index d1fb44d..c993565 100644
--- a/src/pages/questions/what-is-exact-ref-model-execution.astro
+++ b/src/pages/questions/what-is-exact-ref-model-execution.astro
@@ -9,7 +9,7 @@ const jsonLd = JSON.stringify({
name: 'What is exact-ref model execution in Traverse?',
acceptedAnswer: {
'@type': 'Answer',
- text: 'Exact-ref model execution is how Traverse runs a WASM model package that an app has pinned by digest and signature — never by a naked URL. Hosts call the Spec 137 model.execute surface with opaque input_ref / output_ref handles. As of Traverse v0.14.0, packages use schema 2.0.0 manifests plus a detached Ed25519 model.sig.json; host-owned trust roots gate register_package; the first trained digits-mlp-1.0.0 ships signed with a test-only key (production signing is separate). Exact-ref execute is implemented on native Rust and web only — Swift, Kotlin, and .NET do not execute exact-ref yet. First landed in v0.12.0.',
+ text: 'Exact-ref model execution is how Traverse runs a WASM model package that an app has pinned by digest and signature — never by a naked URL. Hosts call the Spec 137 model.execute surface with opaque input_ref / output_ref handles. As of Traverse v0.14.0, packages use schema 2.0.0 manifests plus a detached Ed25519 model.sig.json; host-owned trust roots gate register_package; the first trained digits-mlp-1.0.0 ships signed with a test-only key (production signing is separate). Exact-ref execute is implemented on native Rust, web, and Swift ExactModelHost (Package.swift pin to swift-host-v0.14.0-1); Kotlin and .NET do not execute exact-ref yet. First landed in v0.12.0; Swift parity closed #1579 on 2026-09-30.',
},
}],
});
@@ -26,7 +26,7 @@ const relatedLinks = [
---
Traverse app manifests declare exact model references. As of v0.14.0, manifests use schema 2.0.0 and every package ships a detached Ed25519 model.sig.json over the exact model.manifest.json bytes. An application's exact_model_dependencies pin binds the SHA-256 of those manifest bytes and declares target, expected rights, and an optional signer key_id. You cannot “upgrade” a model by swapping the file behind a URL.
Host-owned trust
-
Trust roots are host-owned (TrustedModelKeys on Rust, trustedPublicKeysHex on web). Apps can never add trust. Packages enter the cache only through register_package / registerPackage, which verifies the signature and trusted key, the digest against exactly one pin, and the manifest schema (unknown fields fail closed), rights, target, and limits. Every execute re-hashes the cached bytes. Failures keep model_unavailable / model_incompatible and add a stable reason.
+
Trust roots are host-owned (TrustedModelKeys on Rust, trustedPublicKeysHex on web and Swift ExactModelHost). Apps can never add trust. Packages enter the cache only through register_package / registerPackage, which verifies the signature and trusted key, the digest against exactly one pin, and the manifest schema (unknown fields fail closed), rights, target, and limits. Every execute re-hashes the cached bytes. Failures keep model_unavailable / model_incompatible and add a stable reason.
One envelope, any host that implements it
The call surface is the existing Spec 137 model.execute host-connector command — not a new public guest import, and not Spec 045’s candidate/LLM resolution track. Request and response are versioned. Inputs and outputs travel as opaque input_ref / output_ref handles. Browser and native use the same envelopes when both implement execute.
What landed in v0.14.0
Spec 138 first shipped in v0.12.0 (see the historical v0.12.0 write-up). v0.14.0 adds signed packages, host-owned trust, machine-readable rights, and the first trained model digits-mlp-1.0.0 (64→32→10 MLP on UCI digits, CC BY 4.0, 96.10% held-out, bit-identical trainer / native / browser). That package is signed with the test-only key; production model signing is #1567.
-
Host honesty: exact-ref execute is implemented in the Rust native runtime and the web embedder today. The Swift, Kotlin, and .NET embedders do not execute exact-ref models yet. Pin crates.io and npm at 0.14.0 (and traverse-registry at =0.25.0 if you consume it directly).
+
Host honesty: exact-ref execute is implemented in the Rust native runtime, the web embedder, and Swift ExactModelHost (published xcframework swift-host-v0.14.0-1; Package.swift binary pin; digits conformance byte-identical). Kotlin and .NET do not execute exact-ref yet. Pin crates.io and npm at 0.14.0 (and traverse-registry at =0.25.0 if you consume it directly).
What it is not
-
It is not “the model is in charge.” It is not Spec 045. It is not a guest model_invoke import — that stays out of scope for Spec 138 v1. And it is not permission to treat a URL as a model identity, or to assume every native embedder language already executes exact-ref.
+
It is not “the model is in charge.” It is not Spec 045. It is not a guest model_invoke import — that stays out of scope for Spec 138 v1. And it is not permission to treat a URL as a model identity, or to assume Kotlin/.NET already execute exact-ref.