Skip to content

feat(sparq-lws-core): sparq-lws-core: wire per-resource WAC into notification subscribe/receive (the - #6388

Merged
jeswr merged 4 commits into
mainfrom
sparq-agent/issue-6071-33813126681-1
Oct 5, 2026
Merged

jeswr merged 4 commits into
mainfrom
sparq-agent/issue-6071-33813126681-1

Conversation

@sparq-orchestrator

@sparq-orchestrator sparq-orchestrator Bot commented Sep 3, 2026 •

Copy link
Copy Markdown
Contributor

🤖 SPARQ agent

What / why

Automated implementation of the trusted task in #6071, routed to sparq-rust-impl on
Claude Opus 5 (alias opus5, provider model claude-opus-5).

Fixes #6071

Local gate

  • Policy profile: crate-scoped
  • Result: passed before push

Merge posture

DRAFT — pending cross-provider review. Publish never arms; arming happens ONLY in the registry
review-fix approve path (arm_auto_merge=true), gated on an opposite-provider approve
verdict with ci-summary / gate as the objective backstop.

Performance (local, release build, 4 cores, oha -z 10s -c 32 over loopback)

This branch changes subscription authorization only, not the read or write paths. These are the Solid routes, three alternating runs per binary, with SOLID_SERVER_SEED_BENCH=100:

Solid route main 2e90b5a (rps / p99) this PR 124a18f (rps / p99)
GET /bench/public/doc 64,963 · 64,867 · 63,948 / 1.54-1.61 ms 64,718 · 63,003 · 65,506 / 1.50-1.59 ms
GET /bench/listing/ (100 children) 36,407 · 35,811 · 36,871 / 3.01-3.03 ms 36,142 · 37,223 · 38,628 / 2.82-3.00 ms
PUT anonymous (401 path) 33,739 · 32,008 · 33,880 / 2.20-2.41 ms 34,479 · 34,257 · 35,225 / 2.02-2.39 ms

No difference beyond run-to-run noise.


Generated by Claude Code

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
github-actions Bot added a commit to jeswr/agent-account-registry that referenced this pull request Sep 3, 2026
@sparq-orchestrator

Copy link
Copy Markdown
Contributor Author

🤖 SPARQ agent — cross-provider review round 1 recorded.

@sparq-orchestrator

Copy link
Copy Markdown
Contributor Author

🤖 SPARQ agent — cross-provider review round 2 recorded.

@sparq-orchestrator

Copy link
Copy Markdown
Contributor Author

🤖 SPARQ agent — cross-provider review round 3 recorded.

@sparq-orchestrator

Copy link
Copy Markdown
Contributor Author

🤖 SPARQ agent — the autonomous review loop parked this PR: the review round budget is exhausted at 3 round(s) (base 3, hard cap 6) with no extension left — the top fix tier has run, the latest verdict does not grade the PR improving, and no pushed fix at or above the pinned floor awaits re-review; a human must decide

This is the MACHINE-owned capacity park (review:parked), not a human question: it remains a DRAFT and will not be auto-armed. A human can re-admit it by removing the live machine park label(s) — review:parked here and status:parked on the source issue (whichever are present; a needs:user unlabel on either surface also opens the budget window) — the budget restarts from the latest gesture.

@sparq-orchestrator sparq-orchestrator Bot added review:parked Machine-owned capacity park (soft hold; human unlabel, proven recovery, or capped retry) and removed review:needs labels Sep 4, 2026
@sparq-orchestrator

Copy link
Copy Markdown
Contributor Author

🤖 SPARQ agent — automatically re-admitted this MACHINE capacity park: its own starvation cause can no longer be observed, and the fleet is demonstrably healthy.

This park is older than the rolling model-health window, so whether the specific condition that parked it has cleared is NOT provable any more — leaving it would make an automatic hold a permanent one. Instead the fleet has recorded sustained successful runs across multiple accounts with no launch failure, the most recent at 2026-09-04T07:16:58Z (evidence fleet-health/fleet/5f5b2dc3fb8e231b/33846793471.1 — provider/account-fingerprint/run from the model-health window; no raw handle). That is a HEURISTIC about fleet health, not proof that this park's own cause cleared. The machine park label(s) are being removed and the review loop re-admitted with a real budget window.

This consumes that evidence EXACTLY ONCE: the same evidence can never re-admit this PR again, a later park needs FRESH evidence that has not been consumed (for the cause-recovery route, a new outage-and-recovery pair), and at most 2 automatic re-admissions are ever granted to one PR — past that the loop stops and asks a human. A human hold (review:needs-user / needs:user) is never touched by this path, and neither is a park a human applied by stamping one of those human-owned labels. A park a human applied by stamping the MACHINE-owned soft hold is re-admitted here ONLY when this bot's OWN park-reason receipt already classified the episode class=capacity — the machine never clears a park it never classified. To place a hold no machine may lift, use review:needs-user / needs:user.

@sparq-orchestrator sparq-orchestrator Bot added review:needs and removed review:parked Machine-owned capacity park (soft hold; human unlabel, proven recovery, or capped retry) labels Sep 4, 2026
@sparq-orchestrator

Copy link
Copy Markdown
Contributor Author

🤖 SPARQ agent — cross-provider review round 4 recorded.

@sparq-orchestrator

Copy link
Copy Markdown
Contributor Author

🤖 SPARQ agent — cross-provider review round 5 recorded.

@sparq-orchestrator

Copy link
Copy Markdown
Contributor Author

🤖 SPARQ agent — cross-provider review round 6 recorded.

@sparq-orchestrator

Copy link
Copy Markdown
Contributor Author

🤖 SPARQ agent — the autonomous review loop parked this PR: the review round budget is exhausted at 3 round(s) (base 3, hard cap 6) with no extension left — the top fix tier has run, the latest verdict does not grade the PR improving, and no pushed fix at or above the pinned floor awaits re-review; a human must decide

This is the MACHINE-owned capacity park (review:parked), not a human question: it remains a DRAFT and will not be auto-armed. A human can re-admit it by removing the live machine park label(s) — review:parked here and status:parked on the source issue (whichever are present; a needs:user unlabel on either surface also opens the budget window) — the budget restarts from the latest gesture.

@sparq-orchestrator sparq-orchestrator Bot added review:parked Machine-owned capacity park (soft hold; human unlabel, proven recovery, or capped retry) and removed review:needs labels Sep 4, 2026
@sparq-orchestrator

Copy link
Copy Markdown
Contributor Author

🤖 SPARQ agent — automatically re-admitted this MACHINE capacity park: its own starvation cause can no longer be observed, and the fleet is demonstrably healthy.

This park is older than the rolling model-health window, so whether the specific condition that parked it has cleared is NOT provable any more — leaving it would make an automatic hold a permanent one. Instead the fleet has recorded sustained successful runs across multiple accounts with no launch failure, the most recent at 2026-09-04T22:50:46Z (evidence fleet-health/openai/dc2d751954080e13/33926991000.1 — provider/account-fingerprint/run from the model-health window; no raw handle). That is a HEURISTIC about fleet health, not proof that this park's own cause cleared. The machine park label(s) are being removed and the review loop re-admitted with a real budget window.

This consumes that evidence EXACTLY ONCE: the same evidence can never re-admit this PR again, a later park needs FRESH evidence that has not been consumed (for the cause-recovery route, a new outage-and-recovery pair), and at most 2 automatic re-admissions are ever granted to one PR — past that the loop stops and asks a human. A human hold (review:needs-user / needs:user) is never touched by this path, and neither is a park a human applied by stamping one of those human-owned labels. A park a human applied by stamping the MACHINE-owned soft hold is re-admitted here ONLY when this bot's OWN park-reason receipt already classified the episode class=capacity — the machine never clears a park it never classified. To place a hold no machine may lift, use review:needs-user / needs:user.

@sparq-orchestrator sparq-orchestrator Bot added review:needs and removed review:parked Machine-owned capacity park (soft hold; human unlabel, proven recovery, or capped retry) labels Sep 4, 2026
@sparq-orchestrator

Copy link
Copy Markdown
Contributor Author

🤖 SPARQ agent — cross-provider review round 7 recorded.

claude added 2 commits October 5, 2026 19:19
Resolve the skills/solid-lws-server/SKILL.md conflict by keeping both
main's acl:agentGroup paragraph and this branch's notification-WAC
paragraph.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Gz4YZq3SwTb7XN8z1JL2C3
…C gate

The WAC ancestor walk derives its chain from the topic string and always
ends at this pod's root, so an off-pod IRI inherited the root ACL's
acl:default grant and could be subscribed to. Reject a topic that is not
under the storage root with a 400 (decided from the request body and the
server's base URL only, so no existence oracle). Also rustfmt ws.rs.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Gz4YZq3SwTb7XN8z1JL2C3
@jeswr
jeswr marked this pull request as ready for review October 5, 2026 19:34

jeswr commented Oct 5, 2026

Copy link
Copy Markdown
Collaborator

ci-fast is red only because its three jobs (lint, test, conformance) were cancelled before running. GitHub Actions has an open incident where hosted runners are not being assigned. No step of this PR failed. The same steps are now running locally against current main, and the PR will be re-run once runners recover.


Generated by Claude Code

…ockets

Review of the per-resource notification gate found three gaps:
- the gate ran WAC only, so an ODRL deny that refuses a GET still allowed a subscription;
- WAC was re-checked only at connect, so an open socket kept receiving after revocation;
- the receive-side test called the gate helper, not the handler.

The gate now composes the opt-in ODRL verdict as the LDP read path does, the socket re-runs the
gate before every frame and closes with 1008 on denial, and the test drives the receive route.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Gz4YZq3SwTb7XN8z1JL2C3

jeswr commented Oct 5, 2026

Copy link
Copy Markdown
Collaborator

Local ci-fast run while GitHub Actions runners are down (local-gate rule). Head 48e5e79 merged with main bfe8514:

  • clippy (core crates, -D warnings): pass
  • nextest (core crates, --profile ci): pass, 3016 passed, 27 skipped
  • doctests: pass
  • W3C SPARQL conformance: pass, 1225 pass + 4 documented divergences (ratchet 1229)

48e5e79 also fixes three findings from an independent review of this PR: the notification gate now applies the opt-in ODRL deny exactly as GET does; open sockets re-check access before every frame and close with 1008 on revocation; and the receive-side test now drives the receive route itself. Benchmarks are in the PR body.


Generated by Claude Code

jeswr commented Oct 5, 2026

Copy link
Copy Markdown
Collaborator

Local gate addendum. The gate passed on head 48e5e79 merged with main a496ec9 (clippy, nextest, doctests and SPARQL conformance 1229, all green).

Skipped range a496ec9..d2c96e0: one file, research/noir-bounded-vec-capacity-assert-5027.md. It is docs only, no ci-fast inputs, and is not pulled in by any include_str! under crates/. Merging on that basis under the coordinator's updated rule 4.


Generated by Claude Code

@jeswr
jeswr merged commit f6ee2ec into main Oct 5, 2026
3 checks passed
@jeswr
jeswr deleted the sparq-agent/issue-6071-33813126681-1 branch October 5, 2026 21:02
jeswr added a commit that referenced this pull request Oct 9, 2026
* docs: bring skills and crate READMEs back in line with main

Audit every skills/*/SKILL.md and crates/*/README.md against the public
API on main after this week's merges, and fix the drift:

- publish status: the 12-crate crates.io set (#6663/#6646) — jsonld,
  engine-serialize and engine-service are now published; unpublished
  crates lose crates.io/docs.rs badges and `"0.1"` install snippets
- default-members (#6649): introspect, canon, substrate claims
- zk-query-proofs / mpc / usage-control-policy recipes now compile
  against current signatures (prover_toml_for, verify_manifest,
  revoke_prover_toml, AttestedStatusRef::clear, Session fields)
- cli: reason summary to stderr (#6641), dump streaming (#4313),
  jsonld-compact, bench --json, flag list
- substrate: #3825 float comparison boundary fixed by #6671
- vc: proof-option validation (#6589) and EdDSA config change (#6585)
- lws: per-resource WAC on notifications (#6388), reclaim race (#6675)
- stale API names, test paths, floors, see-also links; router lists
  trust-graph
- trust-expression spec: last github.com/jeswr/sparq link

Closes #6327

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01MUY53os6oSKvmT9gCqdzud

* ci(notation3tests): save rust-cache only on main

docs-quality quick-gates' cache-posture test fails on every PR (main
too) because this step had no save-if.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01MUY53os6oSKvmT9gCqdzud

* docs: one git source for collaborating crates in EL/QL and Arrow recipes

Mixing a crates.io sparq-core/engine with a git or path sparq-reason-el,
sparq-reason-ql or sparq-arrow yields distinct Dict/Query/QueryResult
types, so the recipes now take every collaborating crate from git.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01MUY53os6oSKvmT9gCqdzud

* docs: strict SERVICE egress in the quickstart; strip model tags

- sparq-engine-service quickstart used with_service_egress_allow, which
  only blocks private addresses; it now uses
  with_service_egress_policy(true, ..) so only the listed host is dialled,
  as the comment says.
- Remove leftover model tags and "Model:" notes from skills/ and crate
  READMEs (#6673 removed the convention).

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01MUY53os6oSKvmT9gCqdzud

* docs: redo the model-tag strip without touching code syntax

The previous strip also deleted every `()` on lines carrying a tag and
every " ()" across the touched files, breaking examples such as
`.text()`, `.arrayBuffer()` and `Result<(), String>`. Revert it and
strip only the tags themselves (plus "Model:" notes); `()` counts and
spacing punctuation are now identical to before the strip in every
touched file. Keeps the strict SERVICE egress quickstart.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01MUY53os6oSKvmT9gCqdzud

* docs: restore academic-paper fence; vendored spargebra in the PROV recipe

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01MUY53os6oSKvmT9gCqdzud

* docs: fix markdownlint hits left by the model-tag strip

Spaces inside bold markers in skills/mpc, a doubled blank line in two
READMEs, and an orphaned provenance comment in sparq-trust.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01MUY53os6oSKvmT9gCqdzud

* docs: PROV recipes declare sparq-core/oxrdf; router CLI and JSON-LD status match main

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01MUY53os6oSKvmT9gCqdzud

* docs(zk): verify_manifest API line lists all ten parameters

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01MUY53os6oSKvmT9gCqdzud

* docs(skills): router entries are each skill's own frontmatter description

The router carried frozen copies of old per-skill descriptions and status
notes that had drifted from the skills (a JS import subpath the package
no longer exports, SHACL strict validation and features reported as
missing, stale CLI/JSON-LD notes). Each entry now reproduces the
skill's current frontmatter description verbatim.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01MUY53os6oSKvmT9gCqdzud

* docs(jsonld): CLI dump has --context only; framing is planned

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01MUY53os6oSKvmT9gCqdzud

---------

Co-authored-by: Claude <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

sparq-lws-core: wire per-resource WAC into notification subscribe/receive (the M2-next seam is now UNBLOCKED)

2 participants