Skip to content

feat(discover): migrate the generate panel to traverse-embedder-web 0.14 registerPackage (#139) - #140

Open
enricopiovesan wants to merge 1 commit into
mainfrom
claude/issue-139-embedder-0.14
Open

enricopiovesan wants to merge 1 commit into
mainfrom
claude/issue-139-embedder-0.14

Conversation

@enricopiovesan

Copy link
Copy Markdown
Collaborator

Summary

This migrates the public website from traverse-embedder-web@^0.13.0 to ^0.14.0 (npm 0.14.0, lockstep with Traverse v0.14.0). It moves the /discover generate panel onto the 0.14 signed admission path. Closes #139.

  • src/scripts/discover-generate.js admits the fixture.responder@1.0.0 conformance fixture through registerPackage(manifestBytes, wasm, signatureBytes). It embeds the real signed package files from traverse-framework/traverse fixtures/models/fixture-responder-1.0.0/: the exact model.manifest.json bytes and the detached Ed25519 model.sig.json, next to the same 491-byte model.wasm it already embedded.
    • The host trusts only Traverse's test-only fixture public key, labelled as such in the code. No production trust is claimed.
    • The host verifies the signature over the exact manifest bytes, the pin digest (now the SHA-256 of the signed manifest), the WASM digest, rights, target, and limits. Any mismatch throws, so no fabricated success path exists.
    • The run log names the signature check and shows both digests.
  • The fixture stays honest: it is the same small deterministic responder ("hi" → "hi there", otherwise "hmm"), still described as not a trained language model.
  • Tests (tests/discover-generate.test.mjs): the WASM digest still equals the Traverse fixture's wasm_digest (bf04760b…), and the pin digest equals the SHA-256 of its signed manifest (50b74bd3…). A new test asserts admission via registerPackage with no insertVerified left.
  • Honesty copy: the embedder-pin Q&A said the site "currently pins ^0.13.0" and that /discover "still uses insertVerified". Both are false after this change, so the page and its llms.txt entry now describe the 0.14 pin and signed admission, and keep the "the site can lag future releases; pin published packages" guidance. Dated blog posts are historical snapshots and are unchanged.

Honesty locks

  • Demo-only behaviour; no new governing spec. Spec 138 (signed exact-ref packages) and Decision 95 are as documented in the script header.
  • The test-only key is never presented as production trust.

Test plan

  • npm ls traverse-embedder-web reports 0.14.0
  • npm test: 11/11 pass, including real signed admission and execution in Node
  • npx playwright test tests/e2e: 6/6 pass against the built site. Run locally on a static server on port 4399, because another session's Astro preview held port 4321; the repo's Playwright config is unchanged.
  • npm run build succeeds
  • CI green (cla, baseline, node --test, playwright)
  • Live /discover generate panel runs on 0.14 after deploy

🤖 Generated with Claude Code

….14 registerPackage (#139)

- pin traverse-embedder-web ^0.14.0 (npm 0.14.0)
- discover-generate admits fixture.responder@1.0.0 through registerPackage
  with its real signed manifest bytes and detached Ed25519 signature,
  trusting only Traverse's labelled test-only fixture key; the pin digest
  is now the SHA-256 of the signed manifest (wasm digest unchanged)
- tests assert both digests against the traverse fixture and that
  insertVerified is gone
- embedder-pin Q&A and llms.txt updated: the ^0.13.0 sentence is no longer
  true

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[Task]: Migrate website discover-generate to traverse-embedder-web 0.14 registerPackage

1 participant