An agent tries to swap a model. Traverse only admits the exact signed package. Friday’s demo classifies a handwritten digit with the same digits-mlp-1.0.0 bytes on Browser and Node. Change one WASM byte and the host fails closed. This is not a pricing explainer, and it is not Hugging Face.
model.sig.json against host-owned trust roots, then registerPackage on ExactModelBrowserHost. Same package. Same npm embedder. Browser and Node. Discover → execute → trace.
+ Public proof is this write-up and the screenshots. The runnable folder weekly-demos/2026-10-02-signed-exact-ref is for people who already have access. weekly-demos is still not publicly cloneable (.github#30). There is no public-clone CTA. Status of the earlier deny demo: How do I run the agent-blocked weekly demo?.
+ traverse-embedder-web@0.14.0 package.Why the pin is the product
+ +Traverse v0.14.0 ships signed exact-ref model packages. Manifest schema 2.0.0. A detached Ed25519 model.sig.json covers the manifest bytes. Trust roots live on the host — the app cannot add a key. Pins bind the SHA-256 of those manifest bytes and declare target, expected rights, and an optional key_id.
The first trained package in this demo is digits-mlp-1.0.0 (traverse.digits-mlp@1.0.0): a 64→32→10 MLP on UCI Optical Recognition of Handwritten Digits (CC BY 4.0), 96.10% held-out, as recorded with the package. One shared runtime.wasm. Hosts are UI + I/O, not a second runtime.
The Node column is that published web embedder under Node — ExactModelBrowserHost plus registerPackage. It is not a separate native Rust CLI, and it is not a different runtime.
What happened
+ +| Check | Result |
|---|---|
| Node classify | Digits 0 → 0, 7 → 7, 4 → 4. Output frames match the conformance fixture byte for byte. |
| Browser ↔ Node | Label 0 on the browser host is bit_identical to the Node case (same package bytes, same outputHex). |
| Tamper | Swap one WASM byte → fail closed. Code model_incompatible, reason digest_mismatch. |
| Empty trust | No host trust roots → key_untrusted. |
+
+ Hosts in this demo
+ +| Column | What it is |
|---|---|
| Browser | ExactModelBrowserHost from traverse-embedder-web@0.14.0. registerPackage(manifestBytes, wasm, signatureBytes). |
| Node | The same npm host under Node. Not a native Rust CLI invoke. |
| Not in this proof | Swift, Kotlin, and .NET do not execute exact-ref on the published v0.14.0 pins used here. |
Facts for agents
+ +-
+
- Theme: Signed model. Exact pin. Bit-identical hosts (week of 2026-10-02). +
- Public proof: this post and its screenshots. Runnable tree (access required, repo private): 2026-10-02-signed-exact-ref. Not a public clone — .github#30. +
- Product pins: tags
v0.14.0andweb-v0.14.0@4dac877c2fe0b28491848016747850ae31327ebc. npmtraverse-embedder-web@0.14.0.
+ - Model:
traverse.digits-mlp@1.0.0. Manifest schema2.0.0. Governing spec138-governed-exact-model-execution.
+ - Manifest / pin sha256:
3068f3ae464fbbb43b45b089ab225a1371060a94a214c10629b4d8e402e8eadf
+ - WASM sha256:
6eeea06029ce4210842edfe70d7e0d8d7e926953ead5f18a0dca3c351ad5dc88
+ - Path:
ExactModelBrowserHost+registerPackage(notinsertVerified). Host-owned trust roots only.
+ - Smoke: 0→0, 7→7, 4→4 on Node; Browser label 0 bit-identical to Node; tamper →
digest_mismatch; empty trust →key_untrusted.
+ - Signing key: test-only fixture. Production signing is traverse#1567. Do not trust this key in a real host. +
- Not claimed: Hugging Face. Catalog
model.execute(the catalog still has none). Swift / Kotlin / .NET exact-ref execute on published 0.14.0. A separate native CLI. A second runtime.
+ - Lead claim: one shared
runtime.wasm. Hosts = UI + I/O. Discover → execute → trace.
+
Same signed bytes. Visible trace. A swapped byte does not get to run.
+ +