* docs: bring skills and crate READMEs back in line with main
Audit every skills/*/SKILL.md and crates/*/README.md against the public
API on main after this week's merges, and fix the drift:
- publish status: the 12-crate crates.io set (#6663/#6646) — jsonld,
engine-serialize and engine-service are now published; unpublished
crates lose crates.io/docs.rs badges and `"0.1"` install snippets
- default-members (#6649): introspect, canon, substrate claims
- zk-query-proofs / mpc / usage-control-policy recipes now compile
against current signatures (prover_toml_for, verify_manifest,
revoke_prover_toml, AttestedStatusRef::clear, Session fields)
- cli: reason summary to stderr (#6641), dump streaming (#4313),
jsonld-compact, bench --json, flag list
- substrate: #3825 float comparison boundary fixed by #6671
- vc: proof-option validation (#6589) and EdDSA config change (#6585)
- lws: per-resource WAC on notifications (#6388), reclaim race (#6675)
- stale API names, test paths, floors, see-also links; router lists
trust-graph
- trust-expression spec: last github.com/jeswr/sparq link
Closes #6327
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01MUY53os6oSKvmT9gCqdzud
* ci(notation3tests): save rust-cache only on main
docs-quality quick-gates' cache-posture test fails on every PR (main
too) because this step had no save-if.
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01MUY53os6oSKvmT9gCqdzud
* docs: one git source for collaborating crates in EL/QL and Arrow recipes
Mixing a crates.io sparq-core/engine with a git or path sparq-reason-el,
sparq-reason-ql or sparq-arrow yields distinct Dict/Query/QueryResult
types, so the recipes now take every collaborating crate from git.
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01MUY53os6oSKvmT9gCqdzud
* docs: strict SERVICE egress in the quickstart; strip model tags
- sparq-engine-service quickstart used with_service_egress_allow, which
only blocks private addresses; it now uses
with_service_egress_policy(true, ..) so only the listed host is dialled,
as the comment says.
- Remove leftover model tags and "Model:" notes from skills/ and crate
READMEs (#6673 removed the convention).
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01MUY53os6oSKvmT9gCqdzud
* docs: redo the model-tag strip without touching code syntax
The previous strip also deleted every `()` on lines carrying a tag and
every " ()" across the touched files, breaking examples such as
`.text()`, `.arrayBuffer()` and `Result<(), String>`. Revert it and
strip only the tags themselves (plus "Model:" notes); `()` counts and
spacing punctuation are now identical to before the strip in every
touched file. Keeps the strict SERVICE egress quickstart.
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01MUY53os6oSKvmT9gCqdzud
* docs: restore academic-paper fence; vendored spargebra in the PROV recipe
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01MUY53os6oSKvmT9gCqdzud
* docs: fix markdownlint hits left by the model-tag strip
Spaces inside bold markers in skills/mpc, a doubled blank line in two
READMEs, and an orphaned provenance comment in sparq-trust.
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01MUY53os6oSKvmT9gCqdzud
* docs: PROV recipes declare sparq-core/oxrdf; router CLI and JSON-LD status match main
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01MUY53os6oSKvmT9gCqdzud
* docs(zk): verify_manifest API line lists all ten parameters
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01MUY53os6oSKvmT9gCqdzud
* docs(skills): router entries are each skill's own frontmatter description
The router carried frozen copies of old per-skill descriptions and status
notes that had drifted from the skills (a JS import subpath the package
no longer exports, SHACL strict validation and features reported as
missing, stale CLI/JSON-LD notes). Each entry now reproduces the
skill's current frontmatter description verbatim.
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01MUY53os6oSKvmT9gCqdzud
* docs(jsonld): CLI dump has --context only; framing is planned
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01MUY53os6oSKvmT9gCqdzud
---------
Co-authored-by: Claude <noreply@anthropic.com>
Malformed typed proof options could reach signing and verification, and four compact proof-purpose terms expanded to the wrong IRIs. Validate absolute verification-method IRIs, the five supported VC-v2 purpose terms or explicit absolute IRIs, and optional XSD 1.1 date-time literals before canonicalization, graph materialization or DID resolution. Preserve valid literals exactly in the signed statement. A checked configuration type is shared by all four public entry points.
Correct the four purpose expansions against the published VC-v2 context.
assertionMethodremains compatible; proofs that used the other four incorrectly expanded terms must be re-signed. There is no compatibility fallback. Add public API tests covering all four entry points, independent fixed purpose IRIs, date boundaries, non-normalization, resolver ordering and property inputs; update the public skill and docs.Validation on EC2 at
fa986f62070e67b512f6796aebe7869d3e51998b: 55 all-feature native test functions plus two doctests, 49 no-default-feature functions plus two doctests, scoped all-target Clippy, rustdoc and README checks passed. The new public API suite contains nine ordinary tests and one property test with 64 cases. Deliberately skipping created validation and using the wrong authentication-purpose IRI each failed its intended public-test runtime assertion after successful compilation. The restored suite passed; all 487 recorded source hashes and 22 lockfiles matched clean source. Independent audit SHA-256:d77bee72cb3174f86e300362dd36e7a5d218bc0e95ee076a682d7121cec01868. Local mechanical preflight passed. An earlier SSH dispatch timeout executed no tests and is retained separately.This is lexical validation of the existing typed RDF signature API. It does not add issuer-key authorization, verifier purpose/freshness/status policy, arbitrary JSON-LD proof ingestion, JSON signature suites, or credential authentication inside a query proof. No ZK proofs are generated by these tests. Draft stacked on #6585; full repository and hosted landing gates remain required.