Skip to content

build(release): crates.io-ready publish set (12 crates + sparq-spargebra fork) - #6663

Merged
jeswr merged 4 commits into
mainfrom
claude/crates-io-readiness
Oct 5, 2026
Merged

jeswr merged 4 commits into
mainfrom
claude/crates-io-readiness

Conversation

@jeswr

@jeswr jeswr commented Oct 5, 2026 •

Copy link
Copy Markdown
Collaborator

Requested by Jesse · project thread

Summary

Before: nothing from sparq was publishable to crates.io in practice. The registry closure was 37 crates (28 reached from the core alone through optional research features like ZK, trust, policy and terse), and published crates would have built against unpatched upstream spargebra, silently losing the SPARQ-PATCHES.md fixes, including the §8 recursion-depth cap that guards the unauthenticated /sparql endpoint.

After: a deliberate 12-crate publish set plus the parser fork. cargo publish --workspace --dry-run packages and verifies all 13 in dependency order, and the bootstrap list in docs/release.md §4 is the exact command sequence.

How

  • Publish set (12): sparq-core, -substrate, -jsonld, -engine-serialize, -engine-service, -engine, -reason, -shacl, -hdt, -serve, -server, -cli. The 25 other formerly-publishable crates are now publish = false. release-plz.toml's version group is those 12.
  • spargebra fork → sparq-spargebra: vendor/spargebra is renamed to the package sparq-spargebra (library name still spargebra, so no source changes). The workspace dependency is spargebra = { package = "sparq-spargebra", version = "0.4.6", path = "vendor/spargebra" }. Third-party crates that name upstream spargebra (oxigraph/spareval/sparopt in the bench and differential harnesses) are routed to the same fork through an unpublished re-export shim, vendor/spargebra-shim, because Cargo matches [patch] by package name. The 13 detached bench/zk workspaces point their own [patch.crates-io] spargebra at the same shim, so direct spargebra users there (e.g. bench/serve's parse spikes) also get the fork. It is versioned independently and published by hand when it changes.
  • scripts/publish-strip.py: at packaging time it removes optional dependencies on publish = false crates from the publishable manifests, together with every feature that needs them (transitively), orphaned optional deps, dev-deps on unpublished crates, and gated examples. It trims the workspace to the publish set, and with --with-vendored it adds the fork. It refuses a non-optional edge to an unpublished crate, a stripped default feature, or a published crate enabling another's stripped feature. --check prints the plan. Today it strips el/terse from sparq-cli and complete, facets, federation-descriptors, geo, http3, odrl-authz, solid-authz, solid-authz-trust, terse from sparq-server. Those stay available from a git build. No default feature is affected.
  • Guard: release-interval-guard.py now allows optional and dev edges to unpublished crates, since the strip removes them. Non-optional edges still refuse.
  • publish.yml crates job: runs the strip, then one cargo package --workspace --no-verify --allow-dirty. The old per-crate cargo package -p loop could not resolve unpublished workspace deps. tomlkit is hash-pinned in .github/requirements/publish-strip.txt.
  • Runbook: docs/release.md §4 has the publish set and the bootstrap sequence. It notes the crates.io new-crate rate limit (a short burst, then about one new name per 10 minutes, so about 90 minutes for 13). §8c has the release-plz flip, which adds the strip step before release-plz release.
  • Book: a short "Rust crates" page listing the set, with rows tested against the manifests. This ports the useful part of the closed docs(docs): Backfill: existing published crates have no website page and no guide chapter #6148.

Why strip instead of a restructure: the research edges are #[cfg(feature)] blocks inside sparq-server (http.rs, solid_authz.rs) and sparq-cli. Inverting them into separate crates means moving a lot of code that the LWS and ZK threads are actively changing. The strip keeps every in-repo feature working, and its refusal rules keep it sound. To publish a capability later, flip its crate out of publish = false and add it to the version group. The strip then stops removing it.

Overlap with #6649: merges cleanly on top of it, and with #6649 the strip no longer needs to remove sparq-server's zk/trust dev-deps.

Follow-up (not here): upstream spargebra 0.4.7 is now out. §7–§10 are sparq-local, so the fork stays; rebasing it onto 0.4.7 is separate work.

Verified locally

  • python3 scripts/publish-strip.py --with-vendored && cargo publish --workspace --dry-run --allow-dirty: all 13 crates packaged and verified, exit 0.
  • The new publish.yml packaging step, run locally: 13 .crate files, matching the expected count.
  • cargo check --workspace --exclude sparq-py: clean. cargo test --manifest-path vendor/spargebra/Cargo.toml: 28 passed (recursion-depth + custom-aggregate regressions).
  • python3 -m unittest scripts/tests/test_release_publish_guard.py scripts/tests/test_publish_strip.py: 86 + 6 OK.
  • release-interval-guard.py --dry-run: 12 crates, version group covers all 12.
  • cargo metadata on bench/parse, bench/serve, zk/xpath/differential: resolve.

Base gate (always required)

  • cargo build --workspace succeeds (cargo check --workspace --exclude sparq-py clean locally; CI runs the build).
  • cargo clippy --workspace --exclude sparq-py --all-targets -- -D warnings: no Rust source changed; left to CI.
  • The code this PR touches is formatted (manifests, Python, markdown).
  • cargo test passes for every crate this PR touches (the vendored fork's tests).

Targeted re-evaluation (check the rows that apply to your change)

  • Parser (spargebra): package rename only, with byte-identical sources. Lock diff adds just sparq-spargebra and keeps one parser in the graph via the shim. The conformance ratchet runs in CI.
  • Cargo dependencies: Cargo.lock only renames the fork (no version changes). The spargebra cargo-vet policy/exemption still applies to the shim. cargo deny/vet run in CI.

Ratchets and conventions

  • No ratchet lowered.
  • No hard-coded performance numbers.
  • Docs made false by this change are updated in the same change (release runbook, SPARQ-PATCHES.md, release-plz.toml, guard docstring).

Security

  • No regression. This closes a gap: published crates now keep the parser recursion-depth DoS cap (SPARQ-PATCHES.md §8).

🤖 Generated with Claude Code

https://claude.ai/code/session_014tB5DfVUDWY537tfMuLEPi


Generated by Claude Code

claude added 3 commits October 5, 2026 19:14
…fork

Cut the crates.io publish set from the 37-crate closure to the focused core
(sparq-core, -substrate, -jsonld, -engine-serialize, -engine-service, -engine,
-reason, -shacl, -hdt, -serve, -server, -cli). Every other crate is
publish = false.

- Publish the vendored spargebra as `sparq-spargebra` (lib name unchanged) and
  depend on it via `package = "sparq-spargebra"`, so published crates keep the
  SPARQ-PATCHES.md fixes (recursion-depth DoS cap, MULTIPLICITY()). Upstream
  users in the graph are routed to it through an unpublished re-export shim.
- scripts/publish-strip.py removes optional feature edges to unpublished
  crates (and the features needing them) from packaged manifests; refuses
  anything it cannot strip soundly. Hermetic tests in
  scripts/tests/test_publish_strip.py.
- release-interval-guard allows optional/dev edges to unpublished crates.
- release-plz version group = the 12; publish.yml packages via the strip +
  one `cargo package --workspace`; runbook bootstrap list updated.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_014tB5DfVUDWY537tfMuLEPi
Ported from the closed #6148 and cut to the 12-crate set; rows are tested
against the workspace manifests.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_014tB5DfVUDWY537tfMuLEPi
@jeswr jeswr self-assigned this Oct 5, 2026
@jeswr

jeswr commented Oct 5, 2026

Copy link
Copy Markdown
Collaborator Author

🔎 Codex reviewer — gpt-6.1-sol

Automated review by the Codex reviewer (OpenAI gpt-6.1-sol via Codex CLI) of head 1907d1c0379d. Scope: correctness, security, soundness and design; style nits omitted. A new head gets a fresh review.

Findings

  1. [low] Serving spikes measure the wrong parser — bench/serve/Cargo.toml:18

    Adding package = "sparq-spargebra" makes this patch apply to the fork, while the direct dependency on line 26 still requests upstream spargebra. The updated lockfile confirms both resolve separately. Consequently, cache_spike and point_spike measure upstream parsing when estimating the parsing cost of engine queries, which use the patched fork.

    Rename the direct dependency to sparq-spargebra, or point the upstream patch at vendor/spargebra-shim, then regenerate the lockfile.

Verdict: Fix the parser-measurement regression before merging.

A [patch] entry with package = "sparq-spargebra" patches nothing named
spargebra, so bench/serve's direct spargebra dependency resolved upstream
and its parse spikes measured the unpatched parser. Point every detached
bench/zk patch at vendor/spargebra-shim instead (Codex review on #6663).

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_014tB5DfVUDWY537tfMuLEPi

jeswr commented Oct 5, 2026

Copy link
Copy Markdown
Collaborator Author

Fixed in c03c286: the finding was right, and it applied to all 13 detached bench/zk workspaces, not only bench/serve. Each [patch.crates-io] spargebra now points at vendor/spargebra-shim, so direct spargebra users resolve to the fork. bench/serve's lock now has spargebra (shim) → sparq-spargebra and no registry spargebra. cargo metadata resolves for all 13.


Generated by Claude Code

@jeswr
jeswr marked this pull request as ready for review October 5, 2026 20:28

jeswr commented Oct 5, 2026

Copy link
Copy Markdown
Collaborator Author

Local gate (GitHub Actions runners down; maintainer-approved local-gate procedure). Tested PR head c03c2860 merged with main cbabccec64117480b503ea7c0645064715a3462f, running ci-fast.yml's steps:

  • clippy -D warnings on the core crates (--all-targets): pass
  • cargo nextest run on the core crates with --profile ci: 3007 passed, 27 skipped
  • doctests on the core crates: 38 passed, 0 failed
  • W3C SPARQL conformance: 1225 pass / 0 fail / 4 documented divergences, for a total of 1229, which meets the ratchet (>= 1229)
  • publish-strip.py --with-vendored followed by cargo publish --workspace --dry-run --allow-dirty: 13/13 crates packaged and verified
  • scripts/tests/test_release_publish_guard.py and test_publish_strip.py: OK

The Codex finding (the bench parser patch) was fixed in c03c286.


Generated by Claude Code

jeswr commented Oct 5, 2026

Copy link
Copy Markdown
Collaborator Author

Main moved to f6457876b5e60505919851f501128b251fbe2367 (two npm lockfile bumps), so I re-ran the gate on PR head c03c2860 merged with it. Results were identical: clippy pass; nextest 3007 passed; doctests 38 passed; conformance 1225 + 4 = 1229 (meets the ratchet); publish dry-run 13/13; script tests OK.


Generated by Claude Code

@jeswr
jeswr merged commit 4381c49 into main Oct 5, 2026
10 of 17 checks passed
@jeswr
jeswr deleted the claude/crates-io-readiness branch October 5, 2026 20:32
jeswr pushed a commit that referenced this pull request Oct 5, 2026
Take main's 12-crate publish set, release-plz.toml, publish.yml and
docs/release.md wholesale. Drop this branch's per-package publish-flag
machinery (release-plz-publish-mode.py and its tests, the guard's
per-package publish reading): crates.io automation now belongs to the
#6663 line of work. Kept: soft archive tiers (archive mode only),
optional GUI aliases, and the tag-path cadence fix with its test.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0184oZyLYQNVPp7HYBAr6uYz
jeswr pushed a commit that referenced this pull request Oct 5, 2026
Bring in #6649 (workspace default-members, sparq-wrapper-* stubs removed,
optional sparq-zk deps), #6646 (release workflows and cadence guard) and
#6663 (12-crate crates.io publish set plus the sparq-spargebra fork).

Conflict resolution:
- crates/sparq-server/Cargo.toml: keep main's removal of the unconditional
  sparq-trust/sparq-zk dev-dependencies.
- crates/sparq-solid/Cargo.toml: keep main's optional sparq-zk dep, with the
  sparq-trust and sparq-zk requirements at 0.1.4.
- docs/release.md: keep main's publish-set and bootstrap text, retarget the
  bootstrap sentence at the v0.1.4 tag, and drop the stale 37-crate wording.
- Cargo.lock: take main's and regenerate with `cargo update -w`.

Also bump sparq-lws-core's new optional sparq-zk requirement to 0.1.4,
regenerate the standalone bench/fuzz/gui lockfiles with cargo, and note the
publish set and wrapper-stub removal in the 0.1.4 changelog entry.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0184oZyLYQNVPp7HYBAr6uYz
jeswr pushed a commit that referenced this pull request Oct 5, 2026
… published parser fork

- With id-filter-fastpath, x = x on one stored id returned true before either
  operand met an active temporal_year_range. The identical-id shortcut now
  steps aside while that range is active (Codex review of 58794cf).
- Main (#6663) publishes the vendored parser as sparq-spargebra and reaches it
  from upstream-named dependents through vendor/spargebra-shim. The exact
  evaluator, both guests and native composition now do the same (the shim
  forwards the deterministic-path and blank-node features); locks and the
  native lock pin follow.
- The registry-only parser gate assumed published crates resolve upstream
  spargebra 0.4.6, which main replaced with the published fork, so its job,
  script and tests are removed; the stable parse_versioned_* contract and
  fork differential stay in the engine tests. The xpath oracle pin test now
  checks main's fork-and-shim selection.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_019QrHZ34TTVfgvvQxbPEKf7
jeswr added a commit that referenced this pull request Oct 9, 2026
* docs: bring skills and crate READMEs back in line with main

Audit every skills/*/SKILL.md and crates/*/README.md against the public
API on main after this week's merges, and fix the drift:

- publish status: the 12-crate crates.io set (#6663/#6646) — jsonld,
  engine-serialize and engine-service are now published; unpublished
  crates lose crates.io/docs.rs badges and `"0.1"` install snippets
- default-members (#6649): introspect, canon, substrate claims
- zk-query-proofs / mpc / usage-control-policy recipes now compile
  against current signatures (prover_toml_for, verify_manifest,
  revoke_prover_toml, AttestedStatusRef::clear, Session fields)
- cli: reason summary to stderr (#6641), dump streaming (#4313),
  jsonld-compact, bench --json, flag list
- substrate: #3825 float comparison boundary fixed by #6671
- vc: proof-option validation (#6589) and EdDSA config change (#6585)
- lws: per-resource WAC on notifications (#6388), reclaim race (#6675)
- stale API names, test paths, floors, see-also links; router lists
  trust-graph
- trust-expression spec: last github.com/jeswr/sparq link

Closes #6327

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01MUY53os6oSKvmT9gCqdzud

* ci(notation3tests): save rust-cache only on main

docs-quality quick-gates' cache-posture test fails on every PR (main
too) because this step had no save-if.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01MUY53os6oSKvmT9gCqdzud

* docs: one git source for collaborating crates in EL/QL and Arrow recipes

Mixing a crates.io sparq-core/engine with a git or path sparq-reason-el,
sparq-reason-ql or sparq-arrow yields distinct Dict/Query/QueryResult
types, so the recipes now take every collaborating crate from git.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01MUY53os6oSKvmT9gCqdzud

* docs: strict SERVICE egress in the quickstart; strip model tags

- sparq-engine-service quickstart used with_service_egress_allow, which
  only blocks private addresses; it now uses
  with_service_egress_policy(true, ..) so only the listed host is dialled,
  as the comment says.
- Remove leftover model tags and "Model:" notes from skills/ and crate
  READMEs (#6673 removed the convention).

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01MUY53os6oSKvmT9gCqdzud

* docs: redo the model-tag strip without touching code syntax

The previous strip also deleted every `()` on lines carrying a tag and
every " ()" across the touched files, breaking examples such as
`.text()`, `.arrayBuffer()` and `Result<(), String>`. Revert it and
strip only the tags themselves (plus "Model:" notes); `()` counts and
spacing punctuation are now identical to before the strip in every
touched file. Keeps the strict SERVICE egress quickstart.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01MUY53os6oSKvmT9gCqdzud

* docs: restore academic-paper fence; vendored spargebra in the PROV recipe

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01MUY53os6oSKvmT9gCqdzud

* docs: fix markdownlint hits left by the model-tag strip

Spaces inside bold markers in skills/mpc, a doubled blank line in two
READMEs, and an orphaned provenance comment in sparq-trust.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01MUY53os6oSKvmT9gCqdzud

* docs: PROV recipes declare sparq-core/oxrdf; router CLI and JSON-LD status match main

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01MUY53os6oSKvmT9gCqdzud

* docs(zk): verify_manifest API line lists all ten parameters

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01MUY53os6oSKvmT9gCqdzud

* docs(skills): router entries are each skill's own frontmatter description

The router carried frozen copies of old per-skill descriptions and status
notes that had drifted from the skills (a JS import subpath the package
no longer exports, SHACL strict validation and features reported as
missing, stale CLI/JSON-LD notes). Each entry now reproduces the
skill's current frontmatter description verbatim.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01MUY53os6oSKvmT9gCqdzud

* docs(jsonld): CLI dump has --context only; framing is planned

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01MUY53os6oSKvmT9gCqdzud

---------

Co-authored-by: Claude <noreply@anthropic.com>
jeswr added a commit that referenced this pull request Oct 9, 2026
…) (#6647)

* docs(zk): preserve exact SDK licenses and isolate feature smoke fixtures

[GPT-6] Copy omitted Apache license files from exact RISC Zero upstream revision and record their URLs/hashes. Verify both synthetic discovery and additive signature API modes in separate temporary catalogs; retain exact upstream source and literal patch whitespace.

Co-Authored-By: GPT-6 <noreply@openai.com>

* [GPT-6] Add optional deterministic blank-node allocation for graph results

Keep anonymous parser labels outside the source-label namespace, choose template namespaces against the active dataset, and freshen per duplicate solution occurrence. Enforce constructed output budgets in this opt-in mode and execute feature-gated regressions in the required feature matrix.

Co-Authored-By: GPT-6 <noreply@openai.com>

* fix(zk): select derive macros only for consuming SDK features

Preserve original ark-crypto-primitives algorithms and derive implementations; feature-gate the dependency and its import. Record exact upstream archive and patch provenance, exercise consumer feature combinations, and retain the SDK pin in both detached locks.

Co-Authored-By: GPT-6 <noreply@openai.com>

* fix(zk): expose the precise compatibility checker input to CI

Use the explicit checker path instead of a repository-root path intermediate. The checker resolves its own repository root; source and evidence checks are unchanged.

Co-Authored-By: GPT-6 <noreply@openai.com>

* docs(zk): clarify feature-off intent gate and retained size floor

Co-Authored-By: GPT-6 <noreply@openai.com>

* fix: preserve exact temporal values and fail bounded capacity globally

Use borrowed fractional keys across engine and reasoner comparisons, preserve SECONDS output, and enforce temporal year capacity during evaluation. Add native and pending actual-guest regressions with explicit source-bound evidence.

Co-Authored-By: GPT-6 <noreply@openai.com>

* [GPT-6] Keep cache fuzzing and conformance evidence current

Mutate the current v2 cache sidecars while retaining legacy-byte coverage. Update the unsafe inventory and documented W3C fixture-divergence tally; the strict comparator and 1229 ratchet are unchanged.

Validation: rustfmt check of the touched target, author preflight, terminology, no-perf-numbers, and diff checks pass. No new fuzz campaign was run.

Co-Authored-By: GPT-6 <noreply@openai.com>

* [GPT-6] Bound aggregate operands in the exact evaluator profile

Reject non-COUNT aggregate operands that may be unbound or come from a fallible expression. Preserve bound RDF terms, COUNT error removal, statically empty groups, and defined numeric type-error/NaN behavior. This deliberately excludes valid arithmetic aggregate expressions pending a runtime guard; it does not redefine the shared engine or claim complete aggregate conformance.

Validation: 24 profile cases (12 accepted/12 rejected), original model/corpus tests plus the integrated 139-case builtin runner, scoped Clippy, author preflight and privacy/terminology gates pass. Removing the guest-side Group guard fails the rejection test. Actual guest execution of these new cases remains to be integrated.

Co-Authored-By: GPT-6 <noreply@openai.com>

* [GPT-6] Gate each detached evaluator dependency graph

Require locked vet, advisory and integrity checks plus a complete member SBOM inventory. Keep modified SDK source provenance distinct from upstream release audit obligations.

Co-Authored-By: GPT-6 <noreply@openai.com>

* [GPT-6] Validate unary numeric operands and cast whitespace

Preserve valid unary-plus operand identity while rejecting malformed numeric facets and nonnumeric values. Restrict string cast whitespace to XML characters before lexical parsing, with interpreted/compiled and dense/compressed regressions.

Co-Authored-By: GPT-6 <noreply@openai.com>

* chore(zk): verify SDK patch reconstruction and selection

Check local patch selection in both detached locks and reconstruct each exact upstream tree before replaying its normalized patch. Bound feature metadata checks and describe the measured native validation scope.

Co-Authored-By: GPT-6 <noreply@openai.com>

* chore(zk): verify SDK patch reconstruction and selection

Check local patch selection in both detached locks and reconstruct each exact upstream tree before replaying its normalized patch. Bound feature metadata checks and describe the measured native validation scope.

Co-Authored-By: GPT-6 <noreply@openai.com>

* feat(zk): prove canonical signed-i64 result predicates in version three

Add separately admitted signed presentations and fixed-capacity circuits with constrained lexical reconstruction, policy-derived status depth and independent verifier dispatch. Keep unsigned contracts and legacy keys unchanged; record discriminating witness, real proof and gate evidence.

Co-Authored-By: GPT-6 <noreply@openai.com>

* docs(zk): declare signed extension feature-off intent

Keep independent hosted byte comparisons and WASM size floors as separate gates for PR6499.

Co-Authored-By: GPT-6 <noreply@openai.com>

* docs(zk): fix signed planner section spacing

[GPT-6] Remove the duplicated blank line rejected by the documentation gate. Runtime and proof artifacts are unchanged.

Co-Authored-By: GPT-6 <noreply@openai.com>

* fix(temporal): cache exact keys and reject year zero in proofs

Co-Authored-By: GPT-6 <noreply@openai.com>

* test: pin temporal cache ordering and capacity controls

Co-Authored-By: GPT-6 <noreply@openai.com>

* [GPT-6] Reject numeric capacity overflow in bounded proof evaluation

Add default-off strict_numeric_capacity to QueryBudget and enable it in the exact evaluator. Checked scalar and compiled consumers, numeric comparisons and ordering, arithmetic and casts, and aggregates fail the whole evaluation when valid operands or results exceed the existing integer/decimal representation. Preserve direct lexical output, unary-plus identity and ordinary expression errors. Keep capacity state on the calling thread and across reentrant evaluation.

Validation: 322 engine unit tests (2 existing ignored), baseline builtin/temporal/numeric integrations, parallel/vectorized/top-k/filter integrations, 73 numeric substrate tests, model capacity and temporal tests, scoped Clippy and author preflight pass. Three real guard-removal mutations fail by assertions. The 21-case capacity corpus is distinct from 167 normative builtin goldens and two legacy capacity controls. Actual guest execution remains pending integrated-source rebuilding; this is not a new proof or audit claim.

Co-Authored-By: GPT-6 <noreply@openai.com>

* [GPT-6] Pin dependency policy lookup across detached graph calls

Use an absolute root deny configuration and test the exact three-manifest inventory and explicit false vendor audit policy rejection. Actual cargo-deny 0.20.2 checks pass from a detached working directory; the original top-level --config ordering is supported. Root vet also passes with all original coverage and four vendor policies preserved.

Co-Authored-By: GPT-6 <noreply@openai.com>

* [GPT-6] Correct bincode advisory scope for the SDK host graph

Preserve the existing maintenance-only RustSec ignore and advisory ID set while documenting the HDT and RISC0 host paths. Remove the unsupported not_affected/code_not_reachable VEX assertion. Distinguish the explicitly selected ExternalProver protobuf response from other SDK bincode RPC and asset/storage paths; no new vulnerability or advisory exception is asserted.

Validation: primary RustSec advisory and exact locked SDK/HDT source rechecked; 11 VEX drift tests, live 4-ID equality check, unchanged sibling-entry assertions and author preflight pass.

Co-Authored-By: GPT-6 <noreply@openai.com>

* test(zk): export source-bound evaluator campaign evidence

Wire the complete strict numeric, aggregate, and temporal guest inventories. Native checks and exporter guard mutations pass; current guest compilation, execution, and receipts remain pending the SDK source freeze.

Co-Authored-By: GPT-6 <noreply@openai.com>

* test(zk): repeat bounded semantic and capacity cases under V2

Native model checks pass; actual dual-version guest executions and receipts remain pending the combined source and SDK freeze.

Co-Authored-By: GPT-6 <noreply@openai.com>

* test(zk): bind V2 receipt exports to the common guest

Both versioned native model inventories pass; actual guest compilation and all five receipts remain pending the combined SDK source freeze.

Co-Authored-By: GPT-6 <noreply@openai.com>

* [GPT-6] Add a bounded synthetic selected-result experiment adapter

Bind the fixed query, released RDF terms, synthetic wallet and relying-party issuer/status policy before comparing first-success and joint planning. Report real inclusive API timing and separate proof/public wire artifacts, explicit unavailable measurements, run challenges, source/tool identity, and strict tamper controls. Local results are noncanonical and selected support does not imply completeness.

Co-Authored-By: GPT-6 <noreply@openai.com>

* fix(zk): rebuild guest packages in their release target scope

Actual read-only Cargo dry runs distinguished default host/debug from the guest release target; the new scope guard is pinned by a failing mutation. No guest artifact or receipt was regenerated.

Co-Authored-By: GPT-6 <noreply@openai.com>

* [GPT-6] Record real synthetic result experiment evidence

Preserve exact source and executable identities, verified binary artifact hashes, inclusive local API measurements and all strict tamper/replay outcomes. The two planner samples share one semantic acceptance digest while retaining distinct actual challenges and public capacity disclosures. These local smoke results are noncanonical, not calibrated performance claims.

Co-Authored-By: GPT-6 <noreply@openai.com>

* [GPT-6] isolate SDK profiler and kernel dependency edges

Preserve the unchanged embedded kernel and SDK defaults while selecting binary and profiler dependencies only from their consumers. Record exact archive reconstruction, graph deltas, native feature controls and the independently reproduced upstream kernel build limitation.

Co-Authored-By: GPT-6 <noreply@openai.com>

* chore(zk): retain upstream audit obligations at SDK source freeze

All six vendored SDK packages require upstream registry audits; existing root imports, policies and exemptions are preserved. Native model and provenance checks pass; current guest execution, receipts and unresolved independent reviews remain pending.

Co-Authored-By: GPT-6 <noreply@openai.com>

* fix(zk): remove duplicate guest license metadata after V2 merge

The first V2 campaign rejected the invalid nested manifest before guest compilation. Locked offline metadata now parses the actual guest graph; V1 source is unaffected.

Co-Authored-By: GPT-6 <noreply@openai.com>

* [GPT-6] Repair evaluator metadata and retain exact SDK review gates

Co-Authored-By: GPT-6 <noreply@openai.com>

* [GPT-6] Measure owned proof-driver stages without altering presentations

Co-Authored-By: GPT-6 <noreply@openai.com>

* Preserve blank-node identity in read-query RDF merges

Co-Authored-By: GPT-6 <noreply@openai.com>

* [GPT-6] Declare experiment isolation and clarify rejection controls

Co-Authored-By: GPT-6 <noreply@openai.com>

* Record completed V2 artifact and five-receipt local campaign

Co-Authored-By: GPT-6 <noreply@openai.com>

* [GPT-6] Record reviewed dependency deltas and exact tracked backlog

Preserve the complete accepted import store and every original exemption. Record ten actual source-delta reviews separately from 143 independently screened review-backlog entries; retain source hashes and review limits. All three real vet, advisory and integrity scopes pass with normalized SBOM evidence.

Co-Authored-By: GPT-6 <noreply@openai.com>

* [GPT-6] Record actual instrumented synthetic proof campaign

Preserve the e20 execution checkout, explicit release build, binary and artifact hashes, and schema2 nested driver events. Clarify that runtime checkout metadata is separate from compile-time attestation. No runtime implementation or proof statement changes.

Co-Authored-By: GPT-6 <noreply@openai.com>

* [GPT-6] Preserve actual hosted evaluator campaign evidence

Record PR head and executed merge checkout separately, the completed actual guest inventory, three genuine receipts and verified artifact/source hashes. Publication readiness remains false pending integrated checks and review.

Co-Authored-By: GPT-6 <noreply@openai.com>

* [GPT-6] Mark evaluator preparation snapshot as historical

Retain recorded source hashes and native evidence while linking the completed hosted campaign and reviewed dependency policy. Current pending work is reviews and fresh integrated gates.

Co-Authored-By: GPT-6 <noreply@openai.com>

* Add bounded native graph-result proof model

Co-Authored-By: GPT-6 <noreply@openai.com>

* feat(zk): add genuine exact-evaluator experiment adapter

Co-Authored-By: GPT-6 <noreply@openai.com>

* Declare shared GRAPH correction intent for PR 6501

Co-Authored-By: GPT-6 <noreply@openai.com>

* docs(zk): record genuine exact-adapter smoke evidence

Co-Authored-By: GPT-6 <noreply@openai.com>

* docs(zk): declare exact-adapter feature-OFF intent for PR6502

Co-Authored-By: GPT-6 <noreply@openai.com>

* Connect bounded graph results to typed guest and host APIs

Co-Authored-By: GPT-6 <noreply@openai.com>

* [GPT-6] Reject potentially captured BOUND in the 2013 proof profile

Track each EXISTS expression input scope so ambiguous variable-only substitution positions fail admission while body-local BOUND and ordinary native behavior remain intact. Add synthetic native and real-guest fixture definitions; actual guest execution belongs to the next integrated artifact campaign.

Co-Authored-By: GPT-6 <noreply@openai.com>

* docs(zk): clarify signed profile availability and lexical admission

Co-Authored-By: GPT-6 <noreply@openai.com>

* [GPT-6] Apply captured EXISTS bindings before MINUS domain subtraction

For the bounded BGP/Join/UNION/FILTER/MINUS body, constrain exact captured IRI/literal terms and remove their solution columns before parent operators observe domains. Preserve bag mappings and pre-projection resource accounting. Keep ambiguous blank/BOUND and binder/subquery shapes on explicitly documented native practical paths; proof admission is unchanged in this commit. Retain published 2013 goldens and pinned independent-engine disagreement.

Co-Authored-By: GPT-6 <noreply@openai.com>

* [GPT-6] Keep EXISTS reference within the crate README template

Co-Authored-By: GPT-6 <noreply@openai.com>

* [GPT-6] Bind the vectorized scalar oracle vocabulary to its graph lifetime

Co-Authored-By: GPT-6 <noreply@openai.com>

* [GPT-6] Bind the vectorized scalar oracle vocabulary to its graph lifetime

Co-Authored-By: GPT-6 <noreply@openai.com>

* [GPT-6] Reject potentially captured BOUND in the 2013 proof profile

Track each EXISTS expression input scope so ambiguous variable-only substitution positions fail admission while body-local BOUND and ordinary native behavior remain intact. Add synthetic native and real-guest fixture definitions; actual guest execution belongs to the next integrated artifact campaign.

Co-Authored-By: GPT-6 <noreply@openai.com>

* [GPT-6] Execute captured-BOUND boundaries across all graph-result wire versions

Retain source-blank correlation rejection, require actual guest validation when canonicalization changes, and record native and guest development evidence separately from the pending genuine receipt campaign.

Co-Authored-By: GPT-6 <noreply@openai.com>

* [GPT-6] Bind SDK provenance checks to exact vendor paths

Co-Authored-By: GPT-6 <noreply@openai.com>

* [GPT-6] Admit scoped published-2013 EXISTS MINUS domains

Preserve the original query, dataset and published a/b/c golden while admitting the independently reviewed IRI/literal domain-substitution branch. Keep captured BOUND, binding targets, subqueries, paths, nested EXISTS and blank/triple captures excluded. Add eight exact result fixtures and a false-ASK discriminator to the real guest runner; native checks pass but new guest execution remains pending.

Co-Authored-By: GPT-6 <noreply@openai.com>

* [GPT-6] Extend initialized exact temporal memos after dictionary growth

Preserve old exact cells under the existing exclusive Graph borrow and validate only appended temporal IDs. Keep unused memos lazy and avoid lookup-path locks. Deterministic parse-work regressions cover dense, compressed, forked and mapped graphs; append-query tests preserve FILTER, COUNT, ORDER and MIN/MAX semantics. Cold mmap eager initialization remains an explicitly unmeasured tradeoff.

Co-Authored-By: GPT-6 <noreply@openai.com>

* Record eight completed versioned graph-result proofs at frozen d7

Co-Authored-By: GPT-6 <noreply@openai.com>

* feat(zk): admit bounded materialized benchmark fixtures

Add separately versioned wallet-candidate and named-organization inputs to the existing synthetic adapters, preserving their fixed manifests and proof contracts. Validate exact materialization and independently derived organization counts before execution.

Validation: selected example 8 native tests and exact example 6 native tests pass; both scoped Clippy gates pass. Removing the organization input-equality guard fails its truncation control. No new benchmark proof is claimed at this source checkpoint.

Co-Authored-By: GPT-6 <noreply@openai.com>

* feat(bench): run interleaved synthetic workload campaigns

Materialize bounded wallet and named-organization fixtures before measuring supplied local adapters. Preserve exact inputs, separate statement and authority contracts, process-level warmup scope, per-sample failures and unsupported outcomes, raw reports, and explicit unavailable metrics.

Validation: seven Python protocol tests and two guard-deletion controls pass; path ownership, Markdown and preflight pass. Generated full schedule contains 96 records; no actual full-profile measurement is claimed. Genuine minimal campaign remains separate evidence.

Co-Authored-By: GPT-6 <noreply@openai.com>

* [GPT-6] Bind the vectorized scalar oracle vocabulary to its graph lifetime

Co-Authored-By: GPT-6 <noreply@openai.com>

* [GPT-6] Classify numeric EBV without decimal underflow

Validate numeric facets before exact zero classification, retain datatype-sized float semantics, and apply the published invalid numeric/boolean EBV rule. Preserve arithmetic capacity failures and exact output terms with native/model controls and a stronger false-ASK fixture. Guest execution remains pending the new source campaign.

Co-Authored-By: GPT-6 <noreply@openai.com>

* [GPT-6] Exercise sparse temporal backing during memo extension

Add enough ordinary dictionary terms to select the sparse temporal cache, assert that representation and its fork, then apply the same initialized-memo work and value checks. Correct the stale comment about append invalidation.

Co-Authored-By: GPT-6 <noreply@openai.com>

* fix(bench): retain late output and spawn failure outcomes

Recheck the sampled output threshold after child exit, and distinguish failed launches from I/O failures after creation. Keep the observed threshold explicit as a soft polling limit. No Rust adapter or guest code changes.

Validation: nine Python tests pass. Removing the post-exit check and moving the started flag before invocation independently fail their regression controls; restored suite and preflight pass.

Co-Authored-By: GPT-6 <noreply@openai.com>

* [GPT-6] Correct MINUS fixture documentation link

Co-Authored-By: GPT-6 <noreply@openai.com>

* docs(bench): retain the genuine minimal campaign evidence

Preserve four successful local proof samples, two explicit unsupported records and all original per-sample report/artifact hashes. Keep Rust build source5512, runner sourcef18 and independently accepted historical guest048 separate, including its known EBV limitation. No full-sweep, latest-runtime or canonical-performance claim.

Co-Authored-By: GPT-6 <noreply@openai.com>

* docs: declare workload campaign feature-OFF intent [GPT-6]

Co-Authored-By: GPT-6 <noreply@openai.com>

* [GPT-6] Admit bounded nullable alternatives and inverses

Preserve published bag and endpoint goldens while retaining sequence, nested-quantifier and EXISTS exclusions. Add complete native/actual-guest fixture definitions and retain independent-engine disagreements. Actual new guest execution remains pending.

Co-Authored-By: GPT-6 <noreply@openai.com>

* fix raw numeric and boolean lexical validation

Preserve XML preprocessing for string constructors; regenerate legacy numeric caches under v3 and pin complete native/model/guest-control goldens.

Co-Authored-By: GPT-6 <noreply@openai.com>

* keep numeric cache inventories on current format

Assert current sidecars exist in spill and corruption tests, including compressed permutation versions; preserve legacy migration fixtures.

Co-Authored-By: GPT-6 <noreply@openai.com>

* feat(zk): authenticate public RDF BGP support with native BBS+ [GPT-6]

Co-Authored-By: GPT-6 <noreply@openai.com>

* docs(zk): preserve native RDF proof and dependency evidence [GPT-6]

Co-Authored-By: GPT-6 <noreply@openai.com>

* docs(bench): declare detached native RDF feature intent for PR6504 [GPT-6]

Co-Authored-By: GPT-6 <noreply@openai.com>

* Integrate strict raw temporals and both versioned lexical corpora

Apply reviewed temporal b3a58 with numeric81 integration: both current sidecars are v3, preserving old archives and source terms. Add V2 copies of the unchanged 32 raw-literal and 37+3 temporal matrices and retain every false-ASK branch. Deliberately rebuilt 60 model functions, all-target model Clippy and preflight pass. Actual guest execution remains pending the reviewed EBV dialect and stale-test/docs successor; historical artifacts are unchanged.

Co-Authored-By: GPT-6 <noreply@openai.com>

* test: align numeric lexical regressions with raw RDF validation

Preserve constructor and identical-term controls while rejecting padded raw numeric values in engine, value joins and substrate tests. Correct the corresponding API guidance.

Co-Authored-By: GPT-6 <noreply@openai.com>

* Fix native Ark tracing compatibility with verified upstream provenance [GPT-6]

Co-Authored-By: GPT-6 <noreply@openai.com>

* Retain original oxrdf rand dependency while updating native tracing [GPT-6]

Co-Authored-By: GPT-6 <noreply@openai.com>

* test(zk): add bounded binding corpus and explicit proof replay lanes

Co-Authored-By: GPT-6 <noreply@openai.com>

* test(zk): preserve backend order across canonical replay serialization

Co-Authored-By: GPT-6 <noreply@openai.com>

* test(zk): pin native RDF role and capacity contracts [GPT-6]

Co-Authored-By: GPT-6 <noreply@openai.com>

* docs(engine): finish raw numeric lexical contract corrections

Correct remaining cache, wrapper codec, substrate and feature examples. Preserve convenience codec normalization and add bound-term controls without changing production semantics.

Co-Authored-By: GPT-6 <noreply@openai.com>

* feat(engine): pin query-local EBV semantics and VERSION metadata

Keep REC2013 as the native default and proof-profile pin. Preserve every query VERSION announcement, reject incompatible EBV selections, propagate immutable rules through nested and parallel evaluation, and separate result-cache entries. Pin the W3C12 runner to the September 2026 draft without changing expected results or the conformance floor.

Co-Authored-By: GPT-6 <noreply@openai.com>

* fix(zk): find native support covering every issuer role [GPT-6]

Co-Authored-By: GPT-6 <noreply@openai.com>

* Require bounded binding proof replay and preserve finite evidence [GPT-6]

Run complete declared native and finite Noir cells in the existing real-tool lane, retain exact artifacts and counts, and preserve all previous result tests. Historical ff58 evidence remains distinct from unrun hosted execution and its required importer follow-up.

Co-Authored-By: GPT-6 <noreply@openai.com>

* docs(zk): retain native follow-up source and gate evidence [GPT-6]

Co-Authored-By: GPT-6 <noreply@openai.com>

* Preserve imported negative categories and reject ambiguous model errors [GPT-6]

Retain original stage and diagnostic expectations, classify only exact known model producers, and keep combined evaluation/resource errors unresolved. Add discriminating controller/model tests and retain original fixture objects without changing production runtime or finite Noir proofs.

Co-Authored-By: GPT-6 <noreply@openai.com>

* ci(zk): compile original-suite proof exporter in binding lane

Co-Authored-By: GPT-6 <noreply@openai.com>

* fix(deps): apply reviewed rustls security update

Reuse the exact four-package lock update from main PR #6541 for RUSTSEC-2026-0285. Retain every existing stack policy record and inherit only the four corresponding exact-version exemptions from main, including the explicit AWS-LC vendored-core review limitation. No new audit or advisory exception is claimed.

Co-Authored-By: GPT-6 <noreply@openai.com>

* test(server): drain bounded health requests before mock close

Read complete bounded HTTP headers before replying and join the mock tasks with a timeout. Preserve unhealthy-response diagnostics and the response-size assertions. This fixes the macOS reset caused by closing with unread request bytes; production probe behavior is unchanged.

Validation: baseline unhealthy mock failed; full server library 239 passed after correction; scoped server library/tests Clippy and exact-diff preflight passed.

Co-Authored-By: GPT-6 <noreply@openai.com>

* test(zk): add native RDF binding proof adapter

Exercise synthetic binding jobs through shared honest preparation and genuine BBS proofs. For nonempty absent candidates, independently validate a weaker statement under the same claim context and nonce, then require the native verifier to reject it. Keep admission-only exclusions separate.

Co-Authored-By: GPT-6 <noreply@openai.com>

* test(zk): retain version-specific dataset promotion goldens

Co-Authored-By: GPT-6 <noreply@openai.com>

* test(zk): retain complete native finite binding campaign

Bind 72 accepted required proofs, 468 genuine weaker proofs rejected by the required verifier, and 36 admission-only cases to the frozen source, executable, harness and retained artifacts. Record excluded query families and distinguish local campaign from hosted workflow coverage.

Co-Authored-By: GPT-6 <noreply@openai.com>

* fix(ci): fetch locked native graph before offline provenance

Populate optional RDF dependencies explicitly before the fail-closed offline metadata check. Preserve Cargo diagnostics on failure without retrying online or skipping package provenance.

Co-Authored-By: GPT-6 <noreply@openai.com>

* docs(zk): retain binding replay link within stub limit

Content-only consolidation from32 to30 lines. Actual README validator remains pending remote execution under the user-requested local resource hold.

Co-Authored-By: GPT-6 <noreply@openai.com>

* fix(deps): apply reviewed rustls security update

Reuse the exact four-package lock update from main PR #6541 for RUSTSEC-2026-0285. Retain every existing stack policy record and inherit only the four corresponding exact-version exemptions from main, including the explicit AWS-LC vendored-core review limitation. No new audit or advisory exception is claimed.

Co-Authored-By: GPT-6 <noreply@openai.com>

* fix(engine): retain query dialects and expose typed evaluation causes

Combine independently source-reviewed caller metadata and typed budget/capacity changes. Preserve legacy API outcomes and V1 request/journal bytes. Final combined native, mutation and hosted validation remains pending under the local resource hold.

Co-Authored-By: GPT-6 <noreply@openai.com>

* Validate raw temporal lexicals and migrate stale temporal caches

Co-Authored-By: GPT-6 <noreply@openai.com>

* fix(deps): apply reviewed rustls security update

Reuse the exact four-package lock update from main PR #6541 for RUSTSEC-2026-0285. Retain every existing stack policy record and inherit only the four corresponding exact-version exemptions from main, including the explicit AWS-LC vendored-core review limitation. No new audit or advisory exception is claimed.

Co-Authored-By: GPT-6 <noreply@openai.com>
(cherry picked from commit 6317c88015e186a0d8106de4f69525aacbc33c54)

* Add typed evaluation causes for prepared graph queries

Capture CONSTRUCT and DESCRIBE failures within their owning budget frames. Preserve legacy string wrappers and ordinary expression-error graph semantics. Add resource, numeric/temporal, deadline, nested-query and restoration controls; execution remains pending remotely.

Co-Authored-By: GPT-6 <noreply@openai.com>

* Expose versioned detailed evaluator causes without changing journals

V2 and V3 use actual typed table/graph query failures, preserving legacy diagnostics via shared relation code. Public admission retains VERSION metadata and rejects conflicting proof dialects. Add definitions for both authority modes, all 29 original ambiguous fixture IDs, graph-form capacity and original dialect controls. Runtime validation remains pending remotely.

Co-Authored-By: GPT-6 <noreply@openai.com>

* [GPT-6] Reconcile native dependency policy with reviewed records

Preserve foundation, reviewed SDK and accepted-main policy history, add exact license records and existing trusted audit chains, and keep all134 residual native vet units and both maintenance advisories explicit. Carry the previously reviewed bincode rationale/VEX correction with unchanged ignore identifiers. Root TLS update is the preceding reviewed cherry-pick.

Validation: candidate-owned frozen metadata; root vet and root deny pass, native bans/sources/licenses pass, native vet and advisories retain their documented failures. Eleven VEX controls, live drift check, preflight and Markdown pass. Independent GPT-6 integration review approves source consistency; no compilation, proof campaign or full dependency-clean claim.

Co-Authored-By: GPT-6 <noreply@openai.com>

* Import reviewed original-corpus controller without backend runtime history

Co-Authored-By: GPT-6 <noreply@openai.com>

* Classify actual versioned evaluator causes and retain explicit V3 goldens

Co-Authored-By: GPT-6 <noreply@openai.com>

* Require complete original-corpus typed replay in exact evaluator CI

Co-Authored-By: GPT-6 <noreply@openai.com>

* Define current V3 guest corpus and V2 dialect execution controls

Co-Authored-By: GPT-6 <noreply@openai.com>

* [GPT-6] Require the complete native binding campaign in CI

Replay the pinned 576 native jobs and reconcile required accepts, actual weaker-proof verifier rejections, and empty-profile admissions separately. Retain build/tool/source/artifact identities and fail on missing records or altered counters. Always create the native check on merge-authorizing events with fail-closed internal input selection; require its success in ci-summary while avoiding unrelated heavy work.

Validation: 225 aggregate tests, 27 shared/native protocol tests, 6 native and 6 exact selector tests, three discriminating guard mutations, static workflow/docs checks and preflight. Historical 89a record hashes were rechecked without rerunning cryptography. New hosted replay remains pending; unchanged docs-quality ShellCheck SC2016 is separately recorded.

Co-Authored-By: GPT-6 <noreply@openai.com>

* Replace native Wasmer derive diagnostic dependency with syn errors

Preserve registry archive reconstruction, generated layout bytes and upstream vet obligations. Add static corruption guards and remote-only diagnostic/layout controls; compilation and native graph validation remain pending under resource hold.

Co-Authored-By: GPT-6 <noreply@openai.com>

* [GPT-6] Bind native CI runs to the Cargo-reported executable

Match the native package and binary target from metadata-v1 to one successful compiler-artifact event and require the supplied resolved binary path. CI provides both retained records; manual calls may explicitly omit both. This records build linkage without claiming independent reproduction or signed attestation.

Validation: 30 shared/native protocol tests including package, target, path, missing and ambiguous record controls; 6 selector tests; actionlint, Markdown, preflight. Removing executable-path equality makes the wrong-path assertion fail. No compiler or proof execution was performed for this follow-up.

Co-Authored-By: GPT-6 <noreply@openai.com>

* Retain existing fuzz seeds across explicit native storage variants

Add source-pinned replay records and a complete matrix controller without changing the original generator or oracle comparisons. Keep raw term identity, unresolved comparisons and future backend proof preparation distinct. Rust and actual matrix execution remain remote gates under the resource hold.

Co-Authored-By: GPT-6 <noreply@openai.com>

* ci(zk): execute pinned Wasmer diagnostic controls

Run exact baseline fetch and offline layout/token/compile-fail controls in the native lane, retaining partial evidence. Preserve upstream vet obligations and record the bounded cached graph results.

Co-Authored-By: GPT-6 <noreply@openai.com>

* [GPT-6] Record two scoped native dependency source audits

Record independent GPT-6 safe-to-deploy review of num-iter 0.1.45 to 0.1.46 and cranelift-codegen-shared 0.110.3 with exact source and baseline provenance. Preserve prior policies and failures; frozen candidate vet still reports 132 native units and root vet passes.

Co-Authored-By: GPT-6 <noreply@openai.com>

* Pin exact regression rejection causes and detached parser selection

Preserve original VERSION and capacity fixtures while distinguishing preparation, profile and specific resource failures. Require exact numeric, temporal or row causes in replay and actual-V3 preflight; retain original goldens and lockfiles. Pin the fork version used by detached in-repo consumers, restore fixture ownership, document public behavior changes and declare intentional feature-OFF changes for PR6576. Registry-only parser API compatibility remains a separate required source follow-up; no runtime checks or proofs executed locally.

Co-Authored-By: GPT-6 <noreply@openai.com>

* docs(zk): declare native diagnostic feature scope

Record PR6578 intent without claiming measured feature-OFF neutrality. Runtime and dependency gates remain required.

Co-Authored-By: GPT-6 <noreply@openai.com>

* [OPUS-5.5] Preserve VERSION labels through stable parser APIs

Retain leading-prologue metadata through engine-owned query and update helpers, preserving configured parsers, Unicode preprocessing modes and original request bytes. Migrate all production fork-only calls and add fixed and generated differential controls. Source reviewed by GPT-6; Rust and downstream compilation are pending. The registry-only hosted gate remains a required follow-up before publication.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* [OPUS-5.5] Gate stable parser compatibility against crates.io

Add a detached registry consumer, both Unicode modes, fork differential runs, explicit source/lock/compiler evidence and bounded command logs. Make the mandatory exact-evaluator job depend on the separate compatibility gate; classify all migrated caller inputs. Preserve source locks and original fixtures.

29 controller tests,10 selector tests,2 parser-pin tests, two guard-removal mutations with restored controls, author preflight, actionlint and Markdown checks passed locally. Real Rust and guest/proof execution remain pending on EC2/CI. Root fixed the Python dataclass import-loader registration and independently reviewed the source.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* Fix ownership in versioned rejection assertions

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* Specify credential query proof-method contracts

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* Add retained engine-input preparation and V3 proof adapter

Source checkpoint for remote validation; new native and genuine-proof tests have not yet executed.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* Fix engine replay JSON fixture compilation and document adapter

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* Add typed credential query method contracts and exact capability admission

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* test: prepare retained query fixtures and persist genuine replay receipts

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* test: preserve replay job parse errors in assertions

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* feat: bind stored query requests and share original challenges

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* docs: align query contract README with crate template

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* fix: retain explicit columns when importing query goldens

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* docs: keep request contract quickstart concise and explicit

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* docs: keep challenge consumption inside the proof verifier

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* feat: adapt credential query contracts to exact V3 proofs

Source checkpoint authored by Claude Opus 5.5. Remote compilation, native gates and genuine protocol receipt validation remain pending.

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>

* fix: reject pre-epoch verifier clock failures

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>

* test(core): reject raw padded temporal lexicals

Align the temporal boundary regression with the existing strict raw-literal parser; preserve positive and midnight controls.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* test(zk): observe omitted-statement guest rejection directly

Retain SDK error-chain evidence for an unchanged verifier-agreed anchor after removing a source statement, with an independently checked execution baseline and strict rejection classification.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* test(zk): exercise genuine query protocol receipts and controls

Define six contract-authority proof cases and a cryptographically valid row-bound rejection, with retained artifacts and a verify-only hook-order regression.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* docs(zk): require retained evidence for replay outcome claims

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* fix(zk): validate pinned tool versions on raw output

Share exact version-field matching between successful-result proof paths and the experiment driver. Reject near matches, malformed UTF-8, failed commands and Nargo output that only matches after trimming.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* test(zk): fix protocol proof assertion lint

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* feat(zk): specialize result-public triple patterns

Opt-in experimental V4 relation preserves credential authentication and private membership. Native, constraint and genuine proof validation plus measured gate baselines are pending.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* test(zk): record observed omission rejection consistently

Use the actual exact guest-abort classification in the pre-assertion evidence and retain the existing fail-closed assertion.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* test(zk): cover public-pattern proofs in the binding corpus

Reuse the declared finite oracle and require direct malicious-witness rejection for absent V4 bindings. Real execution remains a separate source-bound gate.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* Retain public-pattern proof evidence in the Noir CI sweep

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* Bind public-pattern measurements to circuit sources and gate catalogs

Record independently checked static evidence at14d426; retain legacy ACIR/ABI/key baselines. Generated catalog checks and evidence corruption controls pass; combined Rust gates and remaining Markdown fix follow before publication.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* feat(zk): add paired public-pattern ablation mode

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* docs(vcq): bind adapter availability to certified V3 capabilities

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* Document the available experimental VCQ method adapter

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* fix(zk): preserve evidence path containment without input audit ambiguity

Resolve the manifest directory before selecting the checkout ancestor so symlink containment matches the original guard. This is an output-location check, with no repository data input. Thirty path-ownership tests and three filesystem equivalence controls passed.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* feat(zk): model issuer-authenticated RDF query inputs

Add a default-off versioned native relation that verifies bounded EdDSA RDFC credentials against a verifier-owned authorization table and evaluates their internally mapped union. Preserve both dataset-authority modes and the existing V1-V3 source prefix. Include published-vector and adversarial tests; EC2 native validation and guest integration are pending.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* fix(zk): validate authenticated commitment resource policies

Share the existing V3 policy-ceiling validator with authenticated dataset commitments before table or source processing. Add a focused native regression and positive control. Valid-policy commitment encoding is unchanged; compilation and EC2 tests remain pending.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* chore(zk): lock authenticated evaluator dependencies

Preserve all existing package versions and checksums; add only the exact Ed25519 dependency closure required by the default-off authenticated RDF model. Generated on the authorized EC2 instance and independently compared before acceptance. Native and guest validation remain separate.

* fix(zk): sort authenticated documents by their digest key

Use the equivalent key-based sort required by the scoped Clippy gate. Preserve document ordering and authenticated commitment semantics.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* feat(zk): add separate authenticated RDF guest and verifier API

Add default-off V5 guest and low-level accepted-artifact APIs with direct guest and genuine-proof drivers. Preserve the exact guest inputs and register the new detached dependency graph. Source checkpoint for bounded EC2 validation; the new guest lock, compilation and execution remain pending.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* build(zk): lock authenticated guest dependencies

* test(zk): require explicit authenticated proof cases per job

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* feat(zk): bind authenticated RDF queries to VCQ method contracts

Add a default-off V5 adapter with verifier-owned issuer policy, separate descriptor domains, authenticated scope claims, and consume-on-success challenge handling. Reuse existing V3 shape/result/nonce checks, add native and explicitly selected genuine test cases, and retain unvalidated registry status pending execution.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* test(zk): gate authenticated VCQ and direct guest execution (zkp-14.6)

* docs(zk): record authenticated guest execution and proof limit (zkp-14.5)

* docs(zk): record authenticated VCQ receipt evidence (zkp-14.6)

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* ci(zk): run the genuine V5 adapter driver per declared case

Adds a branch-scoped workflow that exports both guests from the commit,
proves one declared vcq_authenticated_genuine case per matrix job and
uploads the driver's evidence directory.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_019QrHZ34TTVfgvvQxbPEKf7

* test(zk): prove the payment false-ASK example over a signed credential (zkp-14.6)

Adds a synthetic payment-history credential in the eddsa-rdfc-2022
profile, signed with the public RFC 8032 TEST 1 key, and two genuine
driver cases asking "was any payment returned?" (false) under a
verifier-agreed anchor and under holder-declared authority. Cases now
carry their dataset; the driver builds one verifier context per dataset.
A native test checks both answers, both authorities and a wrong-key
rejection. The branch workflow proves each declared case in its own job.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_019QrHZ34TTVfgvvQxbPEKf7

* ci(zk): prove only the payment cases on this branch

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_019QrHZ34TTVfgvvQxbPEKf7

* chore(zk): refresh lockfiles for the v0.1.3 workspace version

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_019QrHZ34TTVfgvvQxbPEKf7

* docs(zk): record the payment false-ASK genuine receipt audit (zkp-14.6)

Audit record for the verifier-agreed 'was any payment returned?' case,
in the sparq.independent-genuine-evidence-audit.v1 schema, for citation
through paper-evidence.json.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_019QrHZ34TTVfgvvQxbPEKf7

* docs(zk): record the six CI genuine V5 adapter receipts (zkp-14.6)

Audit records, in the same schema as the payment false-ASK record, for
the remaining declared cases proved by run 37340835239: ASK true
(verifier-agreed), ASK false (holder-declared), bag SELECT
(holder-declared), CONSTRUCT under both authorities, and the genuine
row-bound receipt the protocol rejects.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_019QrHZ34TTVfgvvQxbPEKf7

* docs(engine): keep README within the 120-line template cap

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_019QrHZ34TTVfgvvQxbPEKf7

* research(zk): audit record for the holder-declared payment false-ASK receipt

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_019QrHZ34TTVfgvvQxbPEKf7

* zk(native): re-pin reviewed native lock after the 0.1.3 path-crate bump

The only Cargo.lock change since the reviewed candidate is sparq-canon and
sparq-core moving 0.1.1 -> 0.1.3 (local path crates); no registry package
changed. verify.py --smoke passes.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_019QrHZ34TTVfgvvQxbPEKf7

* ci(zk): make the genuine V5 receipt workflow dispatch-only over all nine cases

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_019QrHZ34TTVfgvvQxbPEKf7

* fix: address Codex review on the ZK stack

- sparq-engine: CONSTRUCT/DESCRIBE entry points install their own query BASE,
  so IRI() never resolves against a previous query's BASE (native and guest
  now agree on graph results).
- sparq-engine: the result-cache key includes temporal_year_range and
  strict_numeric_capacity, so a result cached under one capacity setting is
  never served for another.
- zk evidence: case records name the dataset's own source, so payment receipts
  are no longer labelled as published W3C vectors.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_019QrHZ34TTVfgvvQxbPEKf7

* fix(engine): keep deterministic CONSTRUCT template nodes clear of computed blank nodes

The deterministic template namespace now also avoids blank-node labels in the
WHERE solutions, so an extension function returning e.g. _:tc0_0_0 can no longer
collide with a fresh template node.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_019QrHZ34TTVfgvvQxbPEKf7

* perf(engine): let cached instants decide far-apart temporal comparisons

Exact temporal keys made every dateTime/date comparison probe a hash memo and
compare i128 keys, which slowed temporal FILTERs against main. The scan pushdown
and both general comparison paths now first compare the cached f64 instants:
a difference beyond a rounding margin (plus the fourteen-hour window for mixed
timezone presence) has the sign of the exact difference, so it decides the row;
near-ties, capacity-checked evaluations and uncached terms still use the exact
keys. YEAR() and the other accessors validate with the borrowed exact parser
instead of parsing twice. A differential test checks pushed-down, general and
compiled comparisons against the exact reference over near-tie corpora.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_019QrHZ34TTVfgvvQxbPEKf7

* perf(engine): read dateTime components from validated fixed-width digits

YEAR() and the other accessors validated the lexical and then re-parsed
every component as f64. Read the digits the validator already checked
instead, which removes the accessor slowdown against main.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_019QrHZ34TTVfgvvQxbPEKf7

* perf: validate exact numerics and civil dates without per-row overhead

- Compiled FILTER constants cache their exact-numeric validity once.
- Integer and decimal literals take a direct validation path ahead of the
  integer subtype list; decimal validation is a single byte pass.
- Civil-date day numbers use i64 arithmetic below 2^40 years and widen to
  i128 only beyond that.
- The exact temporal scan fallback moves out of line so the cached
  comparison inlines into scans.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_019QrHZ34TTVfgvvQxbPEKf7

* fix(spargebra): give deterministic anonymous nodes valid, collision-free labels

Under sparq-deterministic-blank-nodes, anonymous nodes were labelled
'#sparq-anon#N', which serializes to invalid SPARQL (_:#sparq-anon#0), so
wrap_for_view, dataset overrides and SERVICE forwarding could not reparse
it. Labels are now a counter behind a per-parse prefix ('sparqanon' plus
as many 'x' as needed) that occurs nowhere in the parser input, so no
written label can collide and the serialization round-trips.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_019QrHZ34TTVfgvvQxbPEKf7

* fix: honour temporal year ranges on identical operands; follow main's published parser fork

- With id-filter-fastpath, x = x on one stored id returned true before either
  operand met an active temporal_year_range. The identical-id shortcut now
  steps aside while that range is active (Codex review of 58794cf0).
- Main (#6663) publishes the vendored parser as sparq-spargebra and reaches it
  from upstream-named dependents through vendor/spargebra-shim. The exact
  evaluator, both guests and native composition now do the same (the shim
  forwards the deterministic-path and blank-node features); locks and the
  native lock pin follow.
- The registry-only parser gate assumed published crates resolve upstream
  spargebra 0.4.6, which main replaced with the published fork, so its job,
  script and tests are removed; the stable parse_versioned_* contract and
  fork differential stay in the engine tests. The xpath oracle pin test now
  checks main's fork-and-shim selection.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_019QrHZ34TTVfgvvQxbPEKf7

* fix(engine): give language-tagged strings length-based EBV under SPARQL 1.1

SPARQL 1.1 (REC 2013) section 17.2.2 assigns every plain literal, language-tagged
ones included, a length-based effective boolean value; only the 1.2 draft makes
rdf:langString a type error. Rec2013 (the default, and the proof dialects' pin)
now follows the Recommendation; Draft20260912 and directional strings keep the
type error (Codex review of a5e85cde). Engine and evaluator-model tests cover
FILTER and IF with non-empty and empty tagged strings in both dialects.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_019QrHZ34TTVfgvvQxbPEKf7

* test(supply-chain): follow main's push/nightly supply-chain workflow

Lean CI (#6673) removed the PR path filter from supply-chain.yml; the coverage
self-test now checks that the workflow runs on every main push without a path
filter instead of matching the deleted filter patterns.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_019QrHZ34TTVfgvvQxbPEKf7

* fix(engine): sameTerm compares computed values as RDF terms

sameTerm only matched two stored terms, so arithmetic and boolean results
never compared equal to their literal: ASK { FILTER(!sameTerm(1 + 0, 1)) }
answered true, and the proved evaluator admits this shape. Computed operands
now compare as the literal a BIND produces, and an unbound or error operand is
a type error instead of false. Both evaluator branches share the helper.

Also refreshes the lock entries for the 0.1.4 workspace version (root, zk
evaluator and guests, native composition) and re-pins the native lock delta.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_019QrHZ34TTVfgvvQxbPEKf7

* chore: drop model tags from lines this PR adds

Model attribution tags stay out of repository content. Hash- or
inventory-pinned artifacts (vendored SDK patches, native-composition vendor
support, JSON evidence and fixtures) keep their bytes so their pins hold.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_019QrHZ34TTVfgvvQxbPEKf7

* docs(canon): keep the README within the 120-line template cap

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_019QrHZ34TTVfgvvQxbPEKf7

* chore(zk-compose): restore hash-pinned sources byte-for-byte

The model-tag cleanup touched Noir sources and their helpers whose bytes are
pinned by the result evidence (verify_result_evidence.py source hashes), so
the foundation-key rebuild failed. Restore those files exactly; the tags stay
until the evidence is regenerated.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_019QrHZ34TTVfgvvQxbPEKf7

* fix(server): stop advertising SPARQL 1.2 on Update-capable services

sd:supportedVersion describes the whole service, but UPDATE refuses
VERSION "1.2", so a client that picked a writable endpoint through
service discovery got an unsupported-version error for a version it was
told was supported. A service that advertises Update now lists 1.0 and
1.1 only; read-only services keep 1.2.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_019QrHZ34TTVfgvvQxbPEKf7

* fix(server): stop advertising sparql:version-1.2

sd:supportedVersion claims the whole language version, but VERSION "1.2"
selects only the pinned draft EBV rule: temporal values keep the REC 2013
lexical space (no year 0000) and UPDATE refuses 1.2 announcements. The
service description now lists 1.0 and 1.1 only, with tripwire tests that
fail once 1.2 updates or year-zero dateTimes start working. Replaces the
Update-only filter from the previous commit.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_019QrHZ34TTVfgvvQxbPEKf7

* fix(engine): NaN is not = to itself in ordinary execution

op:numeric-equal(NaN, NaN) is false, but the identical-term shortcut in
values_equal and the compiled equal-id fast path answered true for a
stored "NaN"^^xsd:double/float, while strict numeric capacity (the proved
evaluator's mode) answered false. Both shortcuts now skip float/double NaN,
so the two modes agree. The proptest oracle and its known-answer case
encoded the old shortcut and now follow op:numeric-equal; sameTerm stays
true.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_019QrHZ34TTVfgvvQxbPEKf7

* fix(engine): NaN orders false, not a type error, in ordinary execution

A stored "NaN"^^xsd:double/float misses the numeric cache, so `<`, `<=`,
`>` and `>=` reached relational_value and raised a type error, while strict
numeric capacity (the proved evaluator's mode) returned false as XPath
numeric comparisons require. `!(?n < 0)` therefore kept the row only in
strict mode. relational_value now returns false for any NaN operand.

Adds a parity test running every comparison and arithmetic operator over
NaN, +-INF, signed zero and mixed numeric tiers (projected, filtered and
negated) in both modes, and moves the proptest oracle's NaN ordering from
error to false.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_019QrHZ34TTVfgvvQxbPEKf7

* test(engine): widen the normal/strict numeric parity matrix

Adds unary plus, ROUND/CEIL/FLOOR, NOT IN, IN lists, conjunctions and
disjunctions, COALESCE/IF, casts, ORDER BY, DISTINCT, GROUP BY, MIN/MAX/
SUM/AVG, joins on a stored numeric, constant-object index lookups and
VALUES joins over NaN, +-INF, signed zero and mixed tiers. All agree.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_019QrHZ34TTVfgvvQxbPEKf7

* build: refresh path-dependent lockfiles after the RDFC vendoring

sparq-canon no longer depends on rdf-canon at runtime, so every separate
workspace that reaches it drops rdf-canon (and, where nothing else used
them, tracing*). bench/trust-graph also picks up the engine's existing
oxiri/percent-encoding edges. No registry package version changed.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_019QrHZ34TTVfgvvQxbPEKf7

* zk(bindings): re-pin the replay generator hash after main's #6699

#6699 changed crates/sparq-bench/src/fuzz.rs (ORDER BY order check on
blank-node answers), so the engine replay matrix's pinned hash of the
original generator (fuzz.rs minus the replay module hook) no longer
matched. The hook itself is unchanged; only the pin moves.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_019QrHZ34TTVfgvvQxbPEKf7

---------

Co-authored-by: GPT-6 <noreply@openai.com>
Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
jeswr added a commit that referenced this pull request Oct 9, 2026
#6782)

#6663 published the vendored parser as `sparq-spargebra`, but the
release-wasm profile still keyed its opt-level "z" override by the old
package name, so it matched nothing and the parser built at opt-level 3.
That accounts for about 92 KB of the wasm_bundle_bytes growth the nightly
Benchmarks run flagged.


Claude-Session: https://claude.ai/code/session_01SLLS3hw4QZ3pVQypYFwdKc

Co-authored-by: Claude <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants