From 0d83a087726d74bf79c69c12db75b6e35390f08f Mon Sep 17 00:00:00 2001 From: Enrico Piovesan Date: Mon, 5 Oct 2026 14:56:49 -0600 Subject: [PATCH] =?UTF-8?q?docs(blog):=20Tue=20=E2=80=94=20model=20rights?= =?UTF-8?q?=20are=20data,=20not=20a=20README?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit --- public/llms.txt | 2 +- src/pages/blog/index.astro | 1 + src/pages/blog/model-rights-are-data.astro | 141 ++++++++++++++++++ ...oes-the-registry-record-model-rights.astro | 1 + 4 files changed, 144 insertions(+), 1 deletion(-) create mode 100644 src/pages/blog/model-rights-are-data.astro diff --git a/public/llms.txt b/public/llms.txt index 3add1e9..9088940 100644 --- a/public/llms.txt +++ b/public/llms.txt @@ -73,7 +73,7 @@ Current packages: crates.io at 0.14.0 (pin `traverse-registry` at `=0.25.0` if y ## Optional -- [Blog](https://traverse-framework.com/blog.html): engineering write-ups, dated — treat as historical snapshots, not current-state claims. Latest: [Signed model. Exact pin. Bit-identical hosts.](https://traverse-framework.com/blog/signed-exact-ref-digits.html) (v0.14.0 weekly demo; Browser+Node; test-only key). Also: [Domain packs are in scope: print-support](https://traverse-framework.com/blog/print-support-domain-pack.html) (capability pack; none published yet). Also: [v0.14.0: what changed for embedders](https://traverse-framework.com/blog/traverse-0-14-0-what-changed-for-embedders.html) (signed Spec 138; native+web+Swift ExactModelHost exact-ref; test-only digits-mlp key). Also: [Where business logic lives (hosts stay thin)](https://traverse-framework.com/blog/where-business-logic-lives.html). Weekly demo: [Same WASM. Browser and Node match. Agent still can’t freestyle.](https://traverse-framework.com/blog/same-wasm-multi-host.html) (v0.13.0 multi-host). Prior: [agent freestyle → blocked](https://traverse-framework.com/blog/agent-freestyle-blocked.html). Authoring: [You don't need Rust to publish a capability](https://traverse-framework.com/blog/you-dont-need-rust-to-publish-a-capability.html). +- [Blog](https://traverse-framework.com/blog.html): engineering write-ups, dated — treat as historical snapshots, not current-state claims. Latest: [Model rights are data, not a README](https://traverse-framework.com/blog/model-rights-are-data.html) (AI model rights from contract to host; publish checks on main, signed registry spec 026 record, host trust roots; runtime enforcement #1598 and prod signing #1567 still open). Also: [Signed model. Exact pin. Bit-identical hosts.](https://traverse-framework.com/blog/signed-exact-ref-digits.html) (v0.14.0 weekly demo; Browser+Node; test-only key). Also: [Domain packs are in scope: print-support](https://traverse-framework.com/blog/print-support-domain-pack.html) (capability pack; none published yet). Also: [v0.14.0: what changed for embedders](https://traverse-framework.com/blog/traverse-0-14-0-what-changed-for-embedders.html) (signed Spec 138; native+web+Swift ExactModelHost exact-ref; test-only digits-mlp key). Also: [Where business logic lives (hosts stay thin)](https://traverse-framework.com/blog/where-business-logic-lives.html). Weekly demo: [Same WASM. Browser and Node match. Agent still can’t freestyle.](https://traverse-framework.com/blog/same-wasm-multi-host.html) (v0.13.0 multi-host). Prior: [agent freestyle → blocked](https://traverse-framework.com/blog/agent-freestyle-blocked.html). Authoring: [You don't need Rust to publish a capability](https://traverse-framework.com/blog/you-dont-need-rust-to-publish-a-capability.html). - [Discover](https://traverse-framework.com/discover.html): a live browser demo that pulls the public registry and executes a reviewed plan locally. Read [what it proves](https://traverse-framework.com/blog/what-discover-proves.html) before quoting it. - [Compare: vs microservices](https://traverse-framework.com/compare/vs-microservices.html), [vs serverless](https://traverse-framework.com/compare/vs-serverless.html), [vs function calling](https://traverse-framework.com/compare/vs-function-calling.html), [vs agent runtimes](https://traverse-framework.com/compare/vs-agent-runtimes.html), [vs WASM runtimes](https://traverse-framework.com/compare/vs-wasm-runtimes.html), [vs cross-platform frameworks](https://traverse-framework.com/compare/vs-cross-platform-frameworks.html) - [About](https://traverse-framework.com/about.html): project history and motivation. diff --git a/src/pages/blog/index.astro b/src/pages/blog/index.astro index e7d62ec..334849e 100644 --- a/src/pages/blog/index.astro +++ b/src/pages/blog/index.astro @@ -2,6 +2,7 @@ import SubpageLayout from '@layouts/SubpageLayout.astro'; const posts = [ + { href: '/blog/model-rights-are-data.html', title: 'Model rights are data, not a README', desc: 'Featured · Oct 6 · AI model rights from contract to host: offline publish checks, signed registry rights record, host trust roots, and what is still open.' }, { href: '/blog/signed-exact-ref-digits.html', title: 'Signed model. Exact pin. Bit-identical hosts.', desc: 'Featured · Weekly demo: signed digits-mlp-1.0.0 exact-ref package, same bytes on Browser + Node via ExactModelBrowserHost; tamper fail-closed (digest_mismatch). Traverse v0.14.0. Test-only key.' }, { href: '/blog/print-support-domain-pack.html', title: 'Domain packs are in scope: print-support without an app rewrite', desc: 'Featured · Manufacturing-shaped capability pack under discover→execute→trace; apps-not-ready ≠ no domain packs; hosts stay thin; none of the print.* capabilities published yet. registry#596 · #597–#604 · Discussion #1540.' }, { href: '/blog/traverse-0-14-0-what-changed-for-embedders.html', title: 'v0.14.0: what changed for embedders', desc: 'Featured · Signed Spec 138 (schema 2.0.0 + model.sig.json), host-owned trust, registerPackage, digits-mlp-1.0.0 (test-only key). Native + web + Swift ExactModelHost execute; Kotlin/.NET do not yet. crates/npm 0.14.0; registry 0.25.0.' }, diff --git a/src/pages/blog/model-rights-are-data.astro b/src/pages/blog/model-rights-are-data.astro new file mode 100644 index 0000000..9652f59 --- /dev/null +++ b/src/pages/blog/model-rights-are-data.astro @@ -0,0 +1,141 @@ +--- +import SubpageLayout from '@layouts/SubpageLayout.astro'; + +const _body = ` +
+
+
+ + + AI models + Registry + Honesty +
+

Model rights are data, not a README

+ +
+
+ +
+
+ +
+ +

Some Traverse capabilities carry third-party model weights inside their WASM artifact, and the registry redistributes those artifacts publicly. So a fair question from anyone wiring one into a product is: am I allowed to use this model commercially? The usual answer in open source is “read the README and the upstream license.” That doesn't hold up once an agent is the one picking the capability.

+ +

This post walks the chain Traverse uses instead, from authoring to the host, and is plain about which links are shipped and which are still open.

+ +
+ Same loop as everything else: discover → execute → trace. Rights travel with the contract, so an agent or app can read them at discover time, before anything runs. The agent proposes; the runtime decides. +
+ +

1. Authoring: the contract carries an ai record

+ +

You still author capabilities skill-first with traverse-capability-author; you don't need to write Rust. For a model-backed capability, the contract's ai object names each model with an immutable upstream pin (a full commit id, not a branch or tag), an SPDX license expression, and the rights fields the registry requires.

+ +

2. Publish: rejected offline, before any registry write

+ +

As of traverse#1597, traverse-cli capability publish rejects an ai object offline when registry CI would reject it on rules the contract alone can decide: object-shaped models when model_backed is true, commit pins, SPDX syntax, and the rights-record shape. Each failure uses the same error code registry CI uses. It also keeps the ai object verbatim in the generated registry contract, where it used to be dropped. Proving evidence bytes and rights drift stays in registry CI, because the CLI doesn't fetch from the network.

+ +

Honest status: this is on Traverse main, merged after v0.14.0, and isn't in a tagged release yet. Details: Does capability publish validate model attribution?

+ +

3. Registry: a signed rights record

+ +

Registry spec 026 makes every newly added model-backed contract declare commercial_use, redistribution and derivatives for each model, as allowed, forbidden or conditional. unknown fails, because the registry won't redistribute weights on unknown rights. LICENSE and NOTICE files are pinned by sha256, any conversion of the weights (like quantization) is recorded with its digest, and the contract bytes themselves are signed with the registry key, so the rights fields are authenticated and not just the WASM.

+ +

The index then projects a usage_class per model: unrestricted, evaluation-only or conditional, and the consumer guidance is deny-by-default on conditional. That's a field an agent can filter on at discover time instead of a paragraph it has to interpret. More: Does the registry record model rights?

+ +

What it is not: a legal certification. The signature proves the maintainer's declaration wasn't altered. It doesn't prove the declaration is right, and it isn't legal advice.

+ +

4. Host: trust roots belong to the host

+ +

Traverse v0.14.0 shipped signed model packages (schema 2.0.0 manifests plus a detached Ed25519 model.sig.json). The app pins the manifest digest and the expected rights; the host owns the trusted keys, and apps can't inject their own. A naked URL is never identity. Exact-ref execute runs on native Rust, the web embedder and Swift today; Kotlin and .NET don't execute exact-ref yet. See How do hosts trust signed models?

+ +

What's still open (as of October 6, 2026)

+ +
    +
  • Runtime enforcement. Showing the full rights record in traverse-cli, honoring revoked at runtime, and verifying the contract signature are tracked in traverse#1598. Not in a release yet.
  • +
  • Existing model-backed agents. Published versions are never judged retroactively; compliant new MINOR versions are tracked in registry#623.
  • +
  • Production model signing. The first trained package, digits-mlp-1.0.0, uses a test-only key. Key custody, rotation and revocation are traverse#1567. See Is production model signing ready?
  • +
+ +

Why bother

+ +

When a person picks a library, a README is fine. When an agent proposes a capability, the rights question has to be answerable from data the runtime can check, at the same moment it checks the contract. That's the whole idea: the rule lives in one governed place, and every host reads the same answer.

+ +

If you're building a model-backed capability and want to help close one of the open items above, the tickets are linked and the door for first-time contributors is open: How do I contribute?

+ +
+ + + +
+
+ +`; +--- + + + + diff --git a/src/pages/questions/does-the-registry-record-model-rights.astro b/src/pages/questions/does-the-registry-record-model-rights.astro index c493b84..b58c5e4 100644 --- a/src/pages/questions/does-the-registry-record-model-rights.astro +++ b/src/pages/questions/does-the-registry-record-model-rights.astro @@ -15,6 +15,7 @@ const jsonLd = JSON.stringify({ }); const relatedLinks = [ + { href: '/blog/model-rights-are-data.html', label: 'Model rights are data, not a README (blog)' }, { href: '/questions/does-capability-publish-validate-model-attribution.html', label: 'Does capability publish validate model attribution?' }, { href: '/questions/what-happens-when-a-capability-version-is-revoked.html', label: 'What happens when a capability version is deprecated or revoked?' }, { href: '/questions/how-do-i-verify-a-signed-capability-artifact.html', label: 'How do I verify a signed capability artifact?' },