Repository navigation
feat(sparq-lws-core): sparq-lws-core: wire per-resource WAC into notification subscribe/receive (the - #6388
Conversation
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
|
|
|
This is the MACHINE-owned capacity park ( |
This park is older than the rolling model-health window, so whether the specific condition that parked it has cleared is NOT provable any more — leaving it would make an automatic hold a permanent one. Instead the fleet has recorded sustained successful runs across multiple accounts with no launch failure, the most recent at This consumes that evidence EXACTLY ONCE: the same evidence can never re-admit this PR again, a later park needs FRESH evidence that has not been consumed (for the cause-recovery route, a new outage-and-recovery pair), and at most 2 automatic re-admissions are ever granted to one PR — past that the loop stops and asks a human. A human hold ( |
|
|
|
This is the MACHINE-owned capacity park ( |
This park is older than the rolling model-health window, so whether the specific condition that parked it has cleared is NOT provable any more — leaving it would make an automatic hold a permanent one. Instead the fleet has recorded sustained successful runs across multiple accounts with no launch failure, the most recent at This consumes that evidence EXACTLY ONCE: the same evidence can never re-admit this PR again, a later park needs FRESH evidence that has not been consumed (for the cause-recovery route, a new outage-and-recovery pair), and at most 2 automatic re-admissions are ever granted to one PR — past that the loop stops and asks a human. A human hold ( |
|
Resolve the skills/solid-lws-server/SKILL.md conflict by keeping both main's acl:agentGroup paragraph and this branch's notification-WAC paragraph. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Gz4YZq3SwTb7XN8z1JL2C3
…C gate The WAC ancestor walk derives its chain from the topic string and always ends at this pod's root, so an off-pod IRI inherited the root ACL's acl:default grant and could be subscribed to. Reject a topic that is not under the storage root with a 400 (decided from the request body and the server's base URL only, so no existence oracle). Also rustfmt ws.rs. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Gz4YZq3SwTb7XN8z1JL2C3
|
ci-fast is red only because its three jobs (lint, test, conformance) were cancelled before running. GitHub Actions has an open incident where hosted runners are not being assigned. No step of this PR failed. The same steps are now running locally against current main, and the PR will be re-run once runners recover. Generated by Claude Code |
…ockets Review of the per-resource notification gate found three gaps: - the gate ran WAC only, so an ODRL deny that refuses a GET still allowed a subscription; - WAC was re-checked only at connect, so an open socket kept receiving after revocation; - the receive-side test called the gate helper, not the handler. The gate now composes the opt-in ODRL verdict as the LDP read path does, the socket re-runs the gate before every frame and closes with 1008 on denial, and the test drives the receive route. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Gz4YZq3SwTb7XN8z1JL2C3
|
Local ci-fast run while GitHub Actions runners are down (local-gate rule). Head
Generated by Claude Code |
|
Local gate addendum. The gate passed on head 48e5e79 merged with main a496ec9 (clippy, nextest, doctests and SPARQL conformance 1229, all green). Skipped range a496ec9..d2c96e0: one file, Generated by Claude Code |
* docs: bring skills and crate READMEs back in line with main Audit every skills/*/SKILL.md and crates/*/README.md against the public API on main after this week's merges, and fix the drift: - publish status: the 12-crate crates.io set (#6663/#6646) — jsonld, engine-serialize and engine-service are now published; unpublished crates lose crates.io/docs.rs badges and `"0.1"` install snippets - default-members (#6649): introspect, canon, substrate claims - zk-query-proofs / mpc / usage-control-policy recipes now compile against current signatures (prover_toml_for, verify_manifest, revoke_prover_toml, AttestedStatusRef::clear, Session fields) - cli: reason summary to stderr (#6641), dump streaming (#4313), jsonld-compact, bench --json, flag list - substrate: #3825 float comparison boundary fixed by #6671 - vc: proof-option validation (#6589) and EdDSA config change (#6585) - lws: per-resource WAC on notifications (#6388), reclaim race (#6675) - stale API names, test paths, floors, see-also links; router lists trust-graph - trust-expression spec: last github.com/jeswr/sparq link Closes #6327 Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01MUY53os6oSKvmT9gCqdzud * ci(notation3tests): save rust-cache only on main docs-quality quick-gates' cache-posture test fails on every PR (main too) because this step had no save-if. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01MUY53os6oSKvmT9gCqdzud * docs: one git source for collaborating crates in EL/QL and Arrow recipes Mixing a crates.io sparq-core/engine with a git or path sparq-reason-el, sparq-reason-ql or sparq-arrow yields distinct Dict/Query/QueryResult types, so the recipes now take every collaborating crate from git. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01MUY53os6oSKvmT9gCqdzud * docs: strict SERVICE egress in the quickstart; strip model tags - sparq-engine-service quickstart used with_service_egress_allow, which only blocks private addresses; it now uses with_service_egress_policy(true, ..) so only the listed host is dialled, as the comment says. - Remove leftover model tags and "Model:" notes from skills/ and crate READMEs (#6673 removed the convention). Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01MUY53os6oSKvmT9gCqdzud * docs: redo the model-tag strip without touching code syntax The previous strip also deleted every `()` on lines carrying a tag and every " ()" across the touched files, breaking examples such as `.text()`, `.arrayBuffer()` and `Result<(), String>`. Revert it and strip only the tags themselves (plus "Model:" notes); `()` counts and spacing punctuation are now identical to before the strip in every touched file. Keeps the strict SERVICE egress quickstart. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01MUY53os6oSKvmT9gCqdzud * docs: restore academic-paper fence; vendored spargebra in the PROV recipe Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01MUY53os6oSKvmT9gCqdzud * docs: fix markdownlint hits left by the model-tag strip Spaces inside bold markers in skills/mpc, a doubled blank line in two READMEs, and an orphaned provenance comment in sparq-trust. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01MUY53os6oSKvmT9gCqdzud * docs: PROV recipes declare sparq-core/oxrdf; router CLI and JSON-LD status match main Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01MUY53os6oSKvmT9gCqdzud * docs(zk): verify_manifest API line lists all ten parameters Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01MUY53os6oSKvmT9gCqdzud * docs(skills): router entries are each skill's own frontmatter description The router carried frozen copies of old per-skill descriptions and status notes that had drifted from the skills (a JS import subpath the package no longer exports, SHACL strict validation and features reported as missing, stale CLI/JSON-LD notes). Each entry now reproduces the skill's current frontmatter description verbatim. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01MUY53os6oSKvmT9gCqdzud * docs(jsonld): CLI dump has --context only; framing is planned Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01MUY53os6oSKvmT9gCqdzud --------- Co-authored-by: Claude <noreply@anthropic.com>
What / why
Automated implementation of the trusted task in #6071, routed to
sparq-rust-implonClaude Opus 5 (alias
opus5, provider modelclaude-opus-5).Fixes #6071
Local gate
crate-scopedMerge posture
DRAFT — pending cross-provider review. Publish never arms; arming happens ONLY in the registry
review-fix approve path (
arm_auto_merge=true), gated on an opposite-provider approveverdict with
ci-summary / gateas the objective backstop.Performance (local, release build, 4 cores,
oha -z 10s -c 32over loopback)This branch changes subscription authorization only, not the read or write paths. These are the Solid routes, three alternating runs per binary, with
SOLID_SERVER_SEED_BENCH=100:No difference beyond run-to-run noise.
Generated by Claude Code