Repository navigation
build(release): crates.io-ready publish set (12 crates + sparq-spargebra fork) - #6663
Conversation
…fork Cut the crates.io publish set from the 37-crate closure to the focused core (sparq-core, -substrate, -jsonld, -engine-serialize, -engine-service, -engine, -reason, -shacl, -hdt, -serve, -server, -cli). Every other crate is publish = false. - Publish the vendored spargebra as `sparq-spargebra` (lib name unchanged) and depend on it via `package = "sparq-spargebra"`, so published crates keep the SPARQ-PATCHES.md fixes (recursion-depth DoS cap, MULTIPLICITY()). Upstream users in the graph are routed to it through an unpublished re-export shim. - scripts/publish-strip.py removes optional feature edges to unpublished crates (and the features needing them) from packaged manifests; refuses anything it cannot strip soundly. Hermetic tests in scripts/tests/test_publish_strip.py. - release-interval-guard allows optional/dev edges to unpublished crates. - release-plz version group = the 12; publish.yml packages via the strip + one `cargo package --workspace`; runbook bootstrap list updated. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_014tB5DfVUDWY537tfMuLEPi
Ported from the closed #6148 and cut to the 12-crate set; rows are tested against the workspace manifests. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_014tB5DfVUDWY537tfMuLEPi
🔎 Codex reviewer —
|
A [patch] entry with package = "sparq-spargebra" patches nothing named spargebra, so bench/serve's direct spargebra dependency resolved upstream and its parse spikes measured the unpatched parser. Point every detached bench/zk patch at vendor/spargebra-shim instead (Codex review on #6663). Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_014tB5DfVUDWY537tfMuLEPi
|
Fixed in c03c286: the finding was right, and it applied to all 13 detached bench/zk workspaces, not only bench/serve. Each Generated by Claude Code |
|
Local gate (GitHub Actions runners down; maintainer-approved local-gate procedure). Tested PR head
The Codex finding (the bench parser patch) was fixed in c03c286. Generated by Claude Code |
|
Main moved to Generated by Claude Code |
Take main's 12-crate publish set, release-plz.toml, publish.yml and docs/release.md wholesale. Drop this branch's per-package publish-flag machinery (release-plz-publish-mode.py and its tests, the guard's per-package publish reading): crates.io automation now belongs to the #6663 line of work. Kept: soft archive tiers (archive mode only), optional GUI aliases, and the tag-path cadence fix with its test. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_0184oZyLYQNVPp7HYBAr6uYz
Bring in #6649 (workspace default-members, sparq-wrapper-* stubs removed, optional sparq-zk deps), #6646 (release workflows and cadence guard) and #6663 (12-crate crates.io publish set plus the sparq-spargebra fork). Conflict resolution: - crates/sparq-server/Cargo.toml: keep main's removal of the unconditional sparq-trust/sparq-zk dev-dependencies. - crates/sparq-solid/Cargo.toml: keep main's optional sparq-zk dep, with the sparq-trust and sparq-zk requirements at 0.1.4. - docs/release.md: keep main's publish-set and bootstrap text, retarget the bootstrap sentence at the v0.1.4 tag, and drop the stale 37-crate wording. - Cargo.lock: take main's and regenerate with `cargo update -w`. Also bump sparq-lws-core's new optional sparq-zk requirement to 0.1.4, regenerate the standalone bench/fuzz/gui lockfiles with cargo, and note the publish set and wrapper-stub removal in the 0.1.4 changelog entry. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_0184oZyLYQNVPp7HYBAr6uYz
… published parser fork - With id-filter-fastpath, x = x on one stored id returned true before either operand met an active temporal_year_range. The identical-id shortcut now steps aside while that range is active (Codex review of 58794cf). - Main (#6663) publishes the vendored parser as sparq-spargebra and reaches it from upstream-named dependents through vendor/spargebra-shim. The exact evaluator, both guests and native composition now do the same (the shim forwards the deterministic-path and blank-node features); locks and the native lock pin follow. - The registry-only parser gate assumed published crates resolve upstream spargebra 0.4.6, which main replaced with the published fork, so its job, script and tests are removed; the stable parse_versioned_* contract and fork differential stay in the engine tests. The xpath oracle pin test now checks main's fork-and-shim selection. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_019QrHZ34TTVfgvvQxbPEKf7
* docs: bring skills and crate READMEs back in line with main Audit every skills/*/SKILL.md and crates/*/README.md against the public API on main after this week's merges, and fix the drift: - publish status: the 12-crate crates.io set (#6663/#6646) — jsonld, engine-serialize and engine-service are now published; unpublished crates lose crates.io/docs.rs badges and `"0.1"` install snippets - default-members (#6649): introspect, canon, substrate claims - zk-query-proofs / mpc / usage-control-policy recipes now compile against current signatures (prover_toml_for, verify_manifest, revoke_prover_toml, AttestedStatusRef::clear, Session fields) - cli: reason summary to stderr (#6641), dump streaming (#4313), jsonld-compact, bench --json, flag list - substrate: #3825 float comparison boundary fixed by #6671 - vc: proof-option validation (#6589) and EdDSA config change (#6585) - lws: per-resource WAC on notifications (#6388), reclaim race (#6675) - stale API names, test paths, floors, see-also links; router lists trust-graph - trust-expression spec: last github.com/jeswr/sparq link Closes #6327 Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01MUY53os6oSKvmT9gCqdzud * ci(notation3tests): save rust-cache only on main docs-quality quick-gates' cache-posture test fails on every PR (main too) because this step had no save-if. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01MUY53os6oSKvmT9gCqdzud * docs: one git source for collaborating crates in EL/QL and Arrow recipes Mixing a crates.io sparq-core/engine with a git or path sparq-reason-el, sparq-reason-ql or sparq-arrow yields distinct Dict/Query/QueryResult types, so the recipes now take every collaborating crate from git. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01MUY53os6oSKvmT9gCqdzud * docs: strict SERVICE egress in the quickstart; strip model tags - sparq-engine-service quickstart used with_service_egress_allow, which only blocks private addresses; it now uses with_service_egress_policy(true, ..) so only the listed host is dialled, as the comment says. - Remove leftover model tags and "Model:" notes from skills/ and crate READMEs (#6673 removed the convention). Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01MUY53os6oSKvmT9gCqdzud * docs: redo the model-tag strip without touching code syntax The previous strip also deleted every `()` on lines carrying a tag and every " ()" across the touched files, breaking examples such as `.text()`, `.arrayBuffer()` and `Result<(), String>`. Revert it and strip only the tags themselves (plus "Model:" notes); `()` counts and spacing punctuation are now identical to before the strip in every touched file. Keeps the strict SERVICE egress quickstart. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01MUY53os6oSKvmT9gCqdzud * docs: restore academic-paper fence; vendored spargebra in the PROV recipe Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01MUY53os6oSKvmT9gCqdzud * docs: fix markdownlint hits left by the model-tag strip Spaces inside bold markers in skills/mpc, a doubled blank line in two READMEs, and an orphaned provenance comment in sparq-trust. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01MUY53os6oSKvmT9gCqdzud * docs: PROV recipes declare sparq-core/oxrdf; router CLI and JSON-LD status match main Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01MUY53os6oSKvmT9gCqdzud * docs(zk): verify_manifest API line lists all ten parameters Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01MUY53os6oSKvmT9gCqdzud * docs(skills): router entries are each skill's own frontmatter description The router carried frozen copies of old per-skill descriptions and status notes that had drifted from the skills (a JS import subpath the package no longer exports, SHACL strict validation and features reported as missing, stale CLI/JSON-LD notes). Each entry now reproduces the skill's current frontmatter description verbatim. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01MUY53os6oSKvmT9gCqdzud * docs(jsonld): CLI dump has --context only; framing is planned Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01MUY53os6oSKvmT9gCqdzud --------- Co-authored-by: Claude <noreply@anthropic.com>
…) (#6647) * docs(zk): preserve exact SDK licenses and isolate feature smoke fixtures [GPT-6] Copy omitted Apache license files from exact RISC Zero upstream revision and record their URLs/hashes. Verify both synthetic discovery and additive signature API modes in separate temporary catalogs; retain exact upstream source and literal patch whitespace. Co-Authored-By: GPT-6 <noreply@openai.com> * [GPT-6] Add optional deterministic blank-node allocation for graph results Keep anonymous parser labels outside the source-label namespace, choose template namespaces against the active dataset, and freshen per duplicate solution occurrence. Enforce constructed output budgets in this opt-in mode and execute feature-gated regressions in the required feature matrix. Co-Authored-By: GPT-6 <noreply@openai.com> * fix(zk): select derive macros only for consuming SDK features Preserve original ark-crypto-primitives algorithms and derive implementations; feature-gate the dependency and its import. Record exact upstream archive and patch provenance, exercise consumer feature combinations, and retain the SDK pin in both detached locks. Co-Authored-By: GPT-6 <noreply@openai.com> * fix(zk): expose the precise compatibility checker input to CI Use the explicit checker path instead of a repository-root path intermediate. The checker resolves its own repository root; source and evidence checks are unchanged. Co-Authored-By: GPT-6 <noreply@openai.com> * docs(zk): clarify feature-off intent gate and retained size floor Co-Authored-By: GPT-6 <noreply@openai.com> * fix: preserve exact temporal values and fail bounded capacity globally Use borrowed fractional keys across engine and reasoner comparisons, preserve SECONDS output, and enforce temporal year capacity during evaluation. Add native and pending actual-guest regressions with explicit source-bound evidence. Co-Authored-By: GPT-6 <noreply@openai.com> * [GPT-6] Keep cache fuzzing and conformance evidence current Mutate the current v2 cache sidecars while retaining legacy-byte coverage. Update the unsafe inventory and documented W3C fixture-divergence tally; the strict comparator and 1229 ratchet are unchanged. Validation: rustfmt check of the touched target, author preflight, terminology, no-perf-numbers, and diff checks pass. No new fuzz campaign was run. Co-Authored-By: GPT-6 <noreply@openai.com> * [GPT-6] Bound aggregate operands in the exact evaluator profile Reject non-COUNT aggregate operands that may be unbound or come from a fallible expression. Preserve bound RDF terms, COUNT error removal, statically empty groups, and defined numeric type-error/NaN behavior. This deliberately excludes valid arithmetic aggregate expressions pending a runtime guard; it does not redefine the shared engine or claim complete aggregate conformance. Validation: 24 profile cases (12 accepted/12 rejected), original model/corpus tests plus the integrated 139-case builtin runner, scoped Clippy, author preflight and privacy/terminology gates pass. Removing the guest-side Group guard fails the rejection test. Actual guest execution of these new cases remains to be integrated. Co-Authored-By: GPT-6 <noreply@openai.com> * [GPT-6] Gate each detached evaluator dependency graph Require locked vet, advisory and integrity checks plus a complete member SBOM inventory. Keep modified SDK source provenance distinct from upstream release audit obligations. Co-Authored-By: GPT-6 <noreply@openai.com> * [GPT-6] Validate unary numeric operands and cast whitespace Preserve valid unary-plus operand identity while rejecting malformed numeric facets and nonnumeric values. Restrict string cast whitespace to XML characters before lexical parsing, with interpreted/compiled and dense/compressed regressions. Co-Authored-By: GPT-6 <noreply@openai.com> * chore(zk): verify SDK patch reconstruction and selection Check local patch selection in both detached locks and reconstruct each exact upstream tree before replaying its normalized patch. Bound feature metadata checks and describe the measured native validation scope. Co-Authored-By: GPT-6 <noreply@openai.com> * chore(zk): verify SDK patch reconstruction and selection Check local patch selection in both detached locks and reconstruct each exact upstream tree before replaying its normalized patch. Bound feature metadata checks and describe the measured native validation scope. Co-Authored-By: GPT-6 <noreply@openai.com> * feat(zk): prove canonical signed-i64 result predicates in version three Add separately admitted signed presentations and fixed-capacity circuits with constrained lexical reconstruction, policy-derived status depth and independent verifier dispatch. Keep unsigned contracts and legacy keys unchanged; record discriminating witness, real proof and gate evidence. Co-Authored-By: GPT-6 <noreply@openai.com> * docs(zk): declare signed extension feature-off intent Keep independent hosted byte comparisons and WASM size floors as separate gates for PR6499. Co-Authored-By: GPT-6 <noreply@openai.com> * docs(zk): fix signed planner section spacing [GPT-6] Remove the duplicated blank line rejected by the documentation gate. Runtime and proof artifacts are unchanged. Co-Authored-By: GPT-6 <noreply@openai.com> * fix(temporal): cache exact keys and reject year zero in proofs Co-Authored-By: GPT-6 <noreply@openai.com> * test: pin temporal cache ordering and capacity controls Co-Authored-By: GPT-6 <noreply@openai.com> * [GPT-6] Reject numeric capacity overflow in bounded proof evaluation Add default-off strict_numeric_capacity to QueryBudget and enable it in the exact evaluator. Checked scalar and compiled consumers, numeric comparisons and ordering, arithmetic and casts, and aggregates fail the whole evaluation when valid operands or results exceed the existing integer/decimal representation. Preserve direct lexical output, unary-plus identity and ordinary expression errors. Keep capacity state on the calling thread and across reentrant evaluation. Validation: 322 engine unit tests (2 existing ignored), baseline builtin/temporal/numeric integrations, parallel/vectorized/top-k/filter integrations, 73 numeric substrate tests, model capacity and temporal tests, scoped Clippy and author preflight pass. Three real guard-removal mutations fail by assertions. The 21-case capacity corpus is distinct from 167 normative builtin goldens and two legacy capacity controls. Actual guest execution remains pending integrated-source rebuilding; this is not a new proof or audit claim. Co-Authored-By: GPT-6 <noreply@openai.com> * [GPT-6] Pin dependency policy lookup across detached graph calls Use an absolute root deny configuration and test the exact three-manifest inventory and explicit false vendor audit policy rejection. Actual cargo-deny 0.20.2 checks pass from a detached working directory; the original top-level --config ordering is supported. Root vet also passes with all original coverage and four vendor policies preserved. Co-Authored-By: GPT-6 <noreply@openai.com> * [GPT-6] Correct bincode advisory scope for the SDK host graph Preserve the existing maintenance-only RustSec ignore and advisory ID set while documenting the HDT and RISC0 host paths. Remove the unsupported not_affected/code_not_reachable VEX assertion. Distinguish the explicitly selected ExternalProver protobuf response from other SDK bincode RPC and asset/storage paths; no new vulnerability or advisory exception is asserted. Validation: primary RustSec advisory and exact locked SDK/HDT source rechecked; 11 VEX drift tests, live 4-ID equality check, unchanged sibling-entry assertions and author preflight pass. Co-Authored-By: GPT-6 <noreply@openai.com> * test(zk): export source-bound evaluator campaign evidence Wire the complete strict numeric, aggregate, and temporal guest inventories. Native checks and exporter guard mutations pass; current guest compilation, execution, and receipts remain pending the SDK source freeze. Co-Authored-By: GPT-6 <noreply@openai.com> * test(zk): repeat bounded semantic and capacity cases under V2 Native model checks pass; actual dual-version guest executions and receipts remain pending the combined source and SDK freeze. Co-Authored-By: GPT-6 <noreply@openai.com> * test(zk): bind V2 receipt exports to the common guest Both versioned native model inventories pass; actual guest compilation and all five receipts remain pending the combined SDK source freeze. Co-Authored-By: GPT-6 <noreply@openai.com> * [GPT-6] Add a bounded synthetic selected-result experiment adapter Bind the fixed query, released RDF terms, synthetic wallet and relying-party issuer/status policy before comparing first-success and joint planning. Report real inclusive API timing and separate proof/public wire artifacts, explicit unavailable measurements, run challenges, source/tool identity, and strict tamper controls. Local results are noncanonical and selected support does not imply completeness. Co-Authored-By: GPT-6 <noreply@openai.com> * fix(zk): rebuild guest packages in their release target scope Actual read-only Cargo dry runs distinguished default host/debug from the guest release target; the new scope guard is pinned by a failing mutation. No guest artifact or receipt was regenerated. Co-Authored-By: GPT-6 <noreply@openai.com> * [GPT-6] Record real synthetic result experiment evidence Preserve exact source and executable identities, verified binary artifact hashes, inclusive local API measurements and all strict tamper/replay outcomes. The two planner samples share one semantic acceptance digest while retaining distinct actual challenges and public capacity disclosures. These local smoke results are noncanonical, not calibrated performance claims. Co-Authored-By: GPT-6 <noreply@openai.com> * [GPT-6] isolate SDK profiler and kernel dependency edges Preserve the unchanged embedded kernel and SDK defaults while selecting binary and profiler dependencies only from their consumers. Record exact archive reconstruction, graph deltas, native feature controls and the independently reproduced upstream kernel build limitation. Co-Authored-By: GPT-6 <noreply@openai.com> * chore(zk): retain upstream audit obligations at SDK source freeze All six vendored SDK packages require upstream registry audits; existing root imports, policies and exemptions are preserved. Native model and provenance checks pass; current guest execution, receipts and unresolved independent reviews remain pending. Co-Authored-By: GPT-6 <noreply@openai.com> * fix(zk): remove duplicate guest license metadata after V2 merge The first V2 campaign rejected the invalid nested manifest before guest compilation. Locked offline metadata now parses the actual guest graph; V1 source is unaffected. Co-Authored-By: GPT-6 <noreply@openai.com> * [GPT-6] Repair evaluator metadata and retain exact SDK review gates Co-Authored-By: GPT-6 <noreply@openai.com> * [GPT-6] Measure owned proof-driver stages without altering presentations Co-Authored-By: GPT-6 <noreply@openai.com> * Preserve blank-node identity in read-query RDF merges Co-Authored-By: GPT-6 <noreply@openai.com> * [GPT-6] Declare experiment isolation and clarify rejection controls Co-Authored-By: GPT-6 <noreply@openai.com> * Record completed V2 artifact and five-receipt local campaign Co-Authored-By: GPT-6 <noreply@openai.com> * [GPT-6] Record reviewed dependency deltas and exact tracked backlog Preserve the complete accepted import store and every original exemption. Record ten actual source-delta reviews separately from 143 independently screened review-backlog entries; retain source hashes and review limits. All three real vet, advisory and integrity scopes pass with normalized SBOM evidence. Co-Authored-By: GPT-6 <noreply@openai.com> * [GPT-6] Record actual instrumented synthetic proof campaign Preserve the e20 execution checkout, explicit release build, binary and artifact hashes, and schema2 nested driver events. Clarify that runtime checkout metadata is separate from compile-time attestation. No runtime implementation or proof statement changes. Co-Authored-By: GPT-6 <noreply@openai.com> * [GPT-6] Preserve actual hosted evaluator campaign evidence Record PR head and executed merge checkout separately, the completed actual guest inventory, three genuine receipts and verified artifact/source hashes. Publication readiness remains false pending integrated checks and review. Co-Authored-By: GPT-6 <noreply@openai.com> * [GPT-6] Mark evaluator preparation snapshot as historical Retain recorded source hashes and native evidence while linking the completed hosted campaign and reviewed dependency policy. Current pending work is reviews and fresh integrated gates. Co-Authored-By: GPT-6 <noreply@openai.com> * Add bounded native graph-result proof model Co-Authored-By: GPT-6 <noreply@openai.com> * feat(zk): add genuine exact-evaluator experiment adapter Co-Authored-By: GPT-6 <noreply@openai.com> * Declare shared GRAPH correction intent for PR 6501 Co-Authored-By: GPT-6 <noreply@openai.com> * docs(zk): record genuine exact-adapter smoke evidence Co-Authored-By: GPT-6 <noreply@openai.com> * docs(zk): declare exact-adapter feature-OFF intent for PR6502 Co-Authored-By: GPT-6 <noreply@openai.com> * Connect bounded graph results to typed guest and host APIs Co-Authored-By: GPT-6 <noreply@openai.com> * [GPT-6] Reject potentially captured BOUND in the 2013 proof profile Track each EXISTS expression input scope so ambiguous variable-only substitution positions fail admission while body-local BOUND and ordinary native behavior remain intact. Add synthetic native and real-guest fixture definitions; actual guest execution belongs to the next integrated artifact campaign. Co-Authored-By: GPT-6 <noreply@openai.com> * docs(zk): clarify signed profile availability and lexical admission Co-Authored-By: GPT-6 <noreply@openai.com> * [GPT-6] Apply captured EXISTS bindings before MINUS domain subtraction For the bounded BGP/Join/UNION/FILTER/MINUS body, constrain exact captured IRI/literal terms and remove their solution columns before parent operators observe domains. Preserve bag mappings and pre-projection resource accounting. Keep ambiguous blank/BOUND and binder/subquery shapes on explicitly documented native practical paths; proof admission is unchanged in this commit. Retain published 2013 goldens and pinned independent-engine disagreement. Co-Authored-By: GPT-6 <noreply@openai.com> * [GPT-6] Keep EXISTS reference within the crate README template Co-Authored-By: GPT-6 <noreply@openai.com> * [GPT-6] Bind the vectorized scalar oracle vocabulary to its graph lifetime Co-Authored-By: GPT-6 <noreply@openai.com> * [GPT-6] Bind the vectorized scalar oracle vocabulary to its graph lifetime Co-Authored-By: GPT-6 <noreply@openai.com> * [GPT-6] Reject potentially captured BOUND in the 2013 proof profile Track each EXISTS expression input scope so ambiguous variable-only substitution positions fail admission while body-local BOUND and ordinary native behavior remain intact. Add synthetic native and real-guest fixture definitions; actual guest execution belongs to the next integrated artifact campaign. Co-Authored-By: GPT-6 <noreply@openai.com> * [GPT-6] Execute captured-BOUND boundaries across all graph-result wire versions Retain source-blank correlation rejection, require actual guest validation when canonicalization changes, and record native and guest development evidence separately from the pending genuine receipt campaign. Co-Authored-By: GPT-6 <noreply@openai.com> * [GPT-6] Bind SDK provenance checks to exact vendor paths Co-Authored-By: GPT-6 <noreply@openai.com> * [GPT-6] Admit scoped published-2013 EXISTS MINUS domains Preserve the original query, dataset and published a/b/c golden while admitting the independently reviewed IRI/literal domain-substitution branch. Keep captured BOUND, binding targets, subqueries, paths, nested EXISTS and blank/triple captures excluded. Add eight exact result fixtures and a false-ASK discriminator to the real guest runner; native checks pass but new guest execution remains pending. Co-Authored-By: GPT-6 <noreply@openai.com> * [GPT-6] Extend initialized exact temporal memos after dictionary growth Preserve old exact cells under the existing exclusive Graph borrow and validate only appended temporal IDs. Keep unused memos lazy and avoid lookup-path locks. Deterministic parse-work regressions cover dense, compressed, forked and mapped graphs; append-query tests preserve FILTER, COUNT, ORDER and MIN/MAX semantics. Cold mmap eager initialization remains an explicitly unmeasured tradeoff. Co-Authored-By: GPT-6 <noreply@openai.com> * Record eight completed versioned graph-result proofs at frozen d7 Co-Authored-By: GPT-6 <noreply@openai.com> * feat(zk): admit bounded materialized benchmark fixtures Add separately versioned wallet-candidate and named-organization inputs to the existing synthetic adapters, preserving their fixed manifests and proof contracts. Validate exact materialization and independently derived organization counts before execution. Validation: selected example 8 native tests and exact example 6 native tests pass; both scoped Clippy gates pass. Removing the organization input-equality guard fails its truncation control. No new benchmark proof is claimed at this source checkpoint. Co-Authored-By: GPT-6 <noreply@openai.com> * feat(bench): run interleaved synthetic workload campaigns Materialize bounded wallet and named-organization fixtures before measuring supplied local adapters. Preserve exact inputs, separate statement and authority contracts, process-level warmup scope, per-sample failures and unsupported outcomes, raw reports, and explicit unavailable metrics. Validation: seven Python protocol tests and two guard-deletion controls pass; path ownership, Markdown and preflight pass. Generated full schedule contains 96 records; no actual full-profile measurement is claimed. Genuine minimal campaign remains separate evidence. Co-Authored-By: GPT-6 <noreply@openai.com> * [GPT-6] Bind the vectorized scalar oracle vocabulary to its graph lifetime Co-Authored-By: GPT-6 <noreply@openai.com> * [GPT-6] Classify numeric EBV without decimal underflow Validate numeric facets before exact zero classification, retain datatype-sized float semantics, and apply the published invalid numeric/boolean EBV rule. Preserve arithmetic capacity failures and exact output terms with native/model controls and a stronger false-ASK fixture. Guest execution remains pending the new source campaign. Co-Authored-By: GPT-6 <noreply@openai.com> * [GPT-6] Exercise sparse temporal backing during memo extension Add enough ordinary dictionary terms to select the sparse temporal cache, assert that representation and its fork, then apply the same initialized-memo work and value checks. Correct the stale comment about append invalidation. Co-Authored-By: GPT-6 <noreply@openai.com> * fix(bench): retain late output and spawn failure outcomes Recheck the sampled output threshold after child exit, and distinguish failed launches from I/O failures after creation. Keep the observed threshold explicit as a soft polling limit. No Rust adapter or guest code changes. Validation: nine Python tests pass. Removing the post-exit check and moving the started flag before invocation independently fail their regression controls; restored suite and preflight pass. Co-Authored-By: GPT-6 <noreply@openai.com> * [GPT-6] Correct MINUS fixture documentation link Co-Authored-By: GPT-6 <noreply@openai.com> * docs(bench): retain the genuine minimal campaign evidence Preserve four successful local proof samples, two explicit unsupported records and all original per-sample report/artifact hashes. Keep Rust build source5512, runner sourcef18 and independently accepted historical guest048 separate, including its known EBV limitation. No full-sweep, latest-runtime or canonical-performance claim. Co-Authored-By: GPT-6 <noreply@openai.com> * docs: declare workload campaign feature-OFF intent [GPT-6] Co-Authored-By: GPT-6 <noreply@openai.com> * [GPT-6] Admit bounded nullable alternatives and inverses Preserve published bag and endpoint goldens while retaining sequence, nested-quantifier and EXISTS exclusions. Add complete native/actual-guest fixture definitions and retain independent-engine disagreements. Actual new guest execution remains pending. Co-Authored-By: GPT-6 <noreply@openai.com> * fix raw numeric and boolean lexical validation Preserve XML preprocessing for string constructors; regenerate legacy numeric caches under v3 and pin complete native/model/guest-control goldens. Co-Authored-By: GPT-6 <noreply@openai.com> * keep numeric cache inventories on current format Assert current sidecars exist in spill and corruption tests, including compressed permutation versions; preserve legacy migration fixtures. Co-Authored-By: GPT-6 <noreply@openai.com> * feat(zk): authenticate public RDF BGP support with native BBS+ [GPT-6] Co-Authored-By: GPT-6 <noreply@openai.com> * docs(zk): preserve native RDF proof and dependency evidence [GPT-6] Co-Authored-By: GPT-6 <noreply@openai.com> * docs(bench): declare detached native RDF feature intent for PR6504 [GPT-6] Co-Authored-By: GPT-6 <noreply@openai.com> * Integrate strict raw temporals and both versioned lexical corpora Apply reviewed temporal b3a58 with numeric81 integration: both current sidecars are v3, preserving old archives and source terms. Add V2 copies of the unchanged 32 raw-literal and 37+3 temporal matrices and retain every false-ASK branch. Deliberately rebuilt 60 model functions, all-target model Clippy and preflight pass. Actual guest execution remains pending the reviewed EBV dialect and stale-test/docs successor; historical artifacts are unchanged. Co-Authored-By: GPT-6 <noreply@openai.com> * test: align numeric lexical regressions with raw RDF validation Preserve constructor and identical-term controls while rejecting padded raw numeric values in engine, value joins and substrate tests. Correct the corresponding API guidance. Co-Authored-By: GPT-6 <noreply@openai.com> * Fix native Ark tracing compatibility with verified upstream provenance [GPT-6] Co-Authored-By: GPT-6 <noreply@openai.com> * Retain original oxrdf rand dependency while updating native tracing [GPT-6] Co-Authored-By: GPT-6 <noreply@openai.com> * test(zk): add bounded binding corpus and explicit proof replay lanes Co-Authored-By: GPT-6 <noreply@openai.com> * test(zk): preserve backend order across canonical replay serialization Co-Authored-By: GPT-6 <noreply@openai.com> * test(zk): pin native RDF role and capacity contracts [GPT-6] Co-Authored-By: GPT-6 <noreply@openai.com> * docs(engine): finish raw numeric lexical contract corrections Correct remaining cache, wrapper codec, substrate and feature examples. Preserve convenience codec normalization and add bound-term controls without changing production semantics. Co-Authored-By: GPT-6 <noreply@openai.com> * feat(engine): pin query-local EBV semantics and VERSION metadata Keep REC2013 as the native default and proof-profile pin. Preserve every query VERSION announcement, reject incompatible EBV selections, propagate immutable rules through nested and parallel evaluation, and separate result-cache entries. Pin the W3C12 runner to the September 2026 draft without changing expected results or the conformance floor. Co-Authored-By: GPT-6 <noreply@openai.com> * fix(zk): find native support covering every issuer role [GPT-6] Co-Authored-By: GPT-6 <noreply@openai.com> * Require bounded binding proof replay and preserve finite evidence [GPT-6] Run complete declared native and finite Noir cells in the existing real-tool lane, retain exact artifacts and counts, and preserve all previous result tests. Historical ff58 evidence remains distinct from unrun hosted execution and its required importer follow-up. Co-Authored-By: GPT-6 <noreply@openai.com> * docs(zk): retain native follow-up source and gate evidence [GPT-6] Co-Authored-By: GPT-6 <noreply@openai.com> * Preserve imported negative categories and reject ambiguous model errors [GPT-6] Retain original stage and diagnostic expectations, classify only exact known model producers, and keep combined evaluation/resource errors unresolved. Add discriminating controller/model tests and retain original fixture objects without changing production runtime or finite Noir proofs. Co-Authored-By: GPT-6 <noreply@openai.com> * ci(zk): compile original-suite proof exporter in binding lane Co-Authored-By: GPT-6 <noreply@openai.com> * fix(deps): apply reviewed rustls security update Reuse the exact four-package lock update from main PR #6541 for RUSTSEC-2026-0285. Retain every existing stack policy record and inherit only the four corresponding exact-version exemptions from main, including the explicit AWS-LC vendored-core review limitation. No new audit or advisory exception is claimed. Co-Authored-By: GPT-6 <noreply@openai.com> * test(server): drain bounded health requests before mock close Read complete bounded HTTP headers before replying and join the mock tasks with a timeout. Preserve unhealthy-response diagnostics and the response-size assertions. This fixes the macOS reset caused by closing with unread request bytes; production probe behavior is unchanged. Validation: baseline unhealthy mock failed; full server library 239 passed after correction; scoped server library/tests Clippy and exact-diff preflight passed. Co-Authored-By: GPT-6 <noreply@openai.com> * test(zk): add native RDF binding proof adapter Exercise synthetic binding jobs through shared honest preparation and genuine BBS proofs. For nonempty absent candidates, independently validate a weaker statement under the same claim context and nonce, then require the native verifier to reject it. Keep admission-only exclusions separate. Co-Authored-By: GPT-6 <noreply@openai.com> * test(zk): retain version-specific dataset promotion goldens Co-Authored-By: GPT-6 <noreply@openai.com> * test(zk): retain complete native finite binding campaign Bind 72 accepted required proofs, 468 genuine weaker proofs rejected by the required verifier, and 36 admission-only cases to the frozen source, executable, harness and retained artifacts. Record excluded query families and distinguish local campaign from hosted workflow coverage. Co-Authored-By: GPT-6 <noreply@openai.com> * fix(ci): fetch locked native graph before offline provenance Populate optional RDF dependencies explicitly before the fail-closed offline metadata check. Preserve Cargo diagnostics on failure without retrying online or skipping package provenance. Co-Authored-By: GPT-6 <noreply@openai.com> * docs(zk): retain binding replay link within stub limit Content-only consolidation from32 to30 lines. Actual README validator remains pending remote execution under the user-requested local resource hold. Co-Authored-By: GPT-6 <noreply@openai.com> * fix(deps): apply reviewed rustls security update Reuse the exact four-package lock update from main PR #6541 for RUSTSEC-2026-0285. Retain every existing stack policy record and inherit only the four corresponding exact-version exemptions from main, including the explicit AWS-LC vendored-core review limitation. No new audit or advisory exception is claimed. Co-Authored-By: GPT-6 <noreply@openai.com> * fix(engine): retain query dialects and expose typed evaluation causes Combine independently source-reviewed caller metadata and typed budget/capacity changes. Preserve legacy API outcomes and V1 request/journal bytes. Final combined native, mutation and hosted validation remains pending under the local resource hold. Co-Authored-By: GPT-6 <noreply@openai.com> * Validate raw temporal lexicals and migrate stale temporal caches Co-Authored-By: GPT-6 <noreply@openai.com> * fix(deps): apply reviewed rustls security update Reuse the exact four-package lock update from main PR #6541 for RUSTSEC-2026-0285. Retain every existing stack policy record and inherit only the four corresponding exact-version exemptions from main, including the explicit AWS-LC vendored-core review limitation. No new audit or advisory exception is claimed. Co-Authored-By: GPT-6 <noreply@openai.com> (cherry picked from commit 6317c88015e186a0d8106de4f69525aacbc33c54) * Add typed evaluation causes for prepared graph queries Capture CONSTRUCT and DESCRIBE failures within their owning budget frames. Preserve legacy string wrappers and ordinary expression-error graph semantics. Add resource, numeric/temporal, deadline, nested-query and restoration controls; execution remains pending remotely. Co-Authored-By: GPT-6 <noreply@openai.com> * Expose versioned detailed evaluator causes without changing journals V2 and V3 use actual typed table/graph query failures, preserving legacy diagnostics via shared relation code. Public admission retains VERSION metadata and rejects conflicting proof dialects. Add definitions for both authority modes, all 29 original ambiguous fixture IDs, graph-form capacity and original dialect controls. Runtime validation remains pending remotely. Co-Authored-By: GPT-6 <noreply@openai.com> * [GPT-6] Reconcile native dependency policy with reviewed records Preserve foundation, reviewed SDK and accepted-main policy history, add exact license records and existing trusted audit chains, and keep all134 residual native vet units and both maintenance advisories explicit. Carry the previously reviewed bincode rationale/VEX correction with unchanged ignore identifiers. Root TLS update is the preceding reviewed cherry-pick. Validation: candidate-owned frozen metadata; root vet and root deny pass, native bans/sources/licenses pass, native vet and advisories retain their documented failures. Eleven VEX controls, live drift check, preflight and Markdown pass. Independent GPT-6 integration review approves source consistency; no compilation, proof campaign or full dependency-clean claim. Co-Authored-By: GPT-6 <noreply@openai.com> * Import reviewed original-corpus controller without backend runtime history Co-Authored-By: GPT-6 <noreply@openai.com> * Classify actual versioned evaluator causes and retain explicit V3 goldens Co-Authored-By: GPT-6 <noreply@openai.com> * Require complete original-corpus typed replay in exact evaluator CI Co-Authored-By: GPT-6 <noreply@openai.com> * Define current V3 guest corpus and V2 dialect execution controls Co-Authored-By: GPT-6 <noreply@openai.com> * [GPT-6] Require the complete native binding campaign in CI Replay the pinned 576 native jobs and reconcile required accepts, actual weaker-proof verifier rejections, and empty-profile admissions separately. Retain build/tool/source/artifact identities and fail on missing records or altered counters. Always create the native check on merge-authorizing events with fail-closed internal input selection; require its success in ci-summary while avoiding unrelated heavy work. Validation: 225 aggregate tests, 27 shared/native protocol tests, 6 native and 6 exact selector tests, three discriminating guard mutations, static workflow/docs checks and preflight. Historical 89a record hashes were rechecked without rerunning cryptography. New hosted replay remains pending; unchanged docs-quality ShellCheck SC2016 is separately recorded. Co-Authored-By: GPT-6 <noreply@openai.com> * Replace native Wasmer derive diagnostic dependency with syn errors Preserve registry archive reconstruction, generated layout bytes and upstream vet obligations. Add static corruption guards and remote-only diagnostic/layout controls; compilation and native graph validation remain pending under resource hold. Co-Authored-By: GPT-6 <noreply@openai.com> * [GPT-6] Bind native CI runs to the Cargo-reported executable Match the native package and binary target from metadata-v1 to one successful compiler-artifact event and require the supplied resolved binary path. CI provides both retained records; manual calls may explicitly omit both. This records build linkage without claiming independent reproduction or signed attestation. Validation: 30 shared/native protocol tests including package, target, path, missing and ambiguous record controls; 6 selector tests; actionlint, Markdown, preflight. Removing executable-path equality makes the wrong-path assertion fail. No compiler or proof execution was performed for this follow-up. Co-Authored-By: GPT-6 <noreply@openai.com> * Retain existing fuzz seeds across explicit native storage variants Add source-pinned replay records and a complete matrix controller without changing the original generator or oracle comparisons. Keep raw term identity, unresolved comparisons and future backend proof preparation distinct. Rust and actual matrix execution remain remote gates under the resource hold. Co-Authored-By: GPT-6 <noreply@openai.com> * ci(zk): execute pinned Wasmer diagnostic controls Run exact baseline fetch and offline layout/token/compile-fail controls in the native lane, retaining partial evidence. Preserve upstream vet obligations and record the bounded cached graph results. Co-Authored-By: GPT-6 <noreply@openai.com> * [GPT-6] Record two scoped native dependency source audits Record independent GPT-6 safe-to-deploy review of num-iter 0.1.45 to 0.1.46 and cranelift-codegen-shared 0.110.3 with exact source and baseline provenance. Preserve prior policies and failures; frozen candidate vet still reports 132 native units and root vet passes. Co-Authored-By: GPT-6 <noreply@openai.com> * Pin exact regression rejection causes and detached parser selection Preserve original VERSION and capacity fixtures while distinguishing preparation, profile and specific resource failures. Require exact numeric, temporal or row causes in replay and actual-V3 preflight; retain original goldens and lockfiles. Pin the fork version used by detached in-repo consumers, restore fixture ownership, document public behavior changes and declare intentional feature-OFF changes for PR6576. Registry-only parser API compatibility remains a separate required source follow-up; no runtime checks or proofs executed locally. Co-Authored-By: GPT-6 <noreply@openai.com> * docs(zk): declare native diagnostic feature scope Record PR6578 intent without claiming measured feature-OFF neutrality. Runtime and dependency gates remain required. Co-Authored-By: GPT-6 <noreply@openai.com> * [OPUS-5.5] Preserve VERSION labels through stable parser APIs Retain leading-prologue metadata through engine-owned query and update helpers, preserving configured parsers, Unicode preprocessing modes and original request bytes. Migrate all production fork-only calls and add fixed and generated differential controls. Source reviewed by GPT-6; Rust and downstream compilation are pending. The registry-only hosted gate remains a required follow-up before publication. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * [OPUS-5.5] Gate stable parser compatibility against crates.io Add a detached registry consumer, both Unicode modes, fork differential runs, explicit source/lock/compiler evidence and bounded command logs. Make the mandatory exact-evaluator job depend on the separate compatibility gate; classify all migrated caller inputs. Preserve source locks and original fixtures. 29 controller tests,10 selector tests,2 parser-pin tests, two guard-removal mutations with restored controls, author preflight, actionlint and Markdown checks passed locally. Real Rust and guest/proof execution remain pending on EC2/CI. Root fixed the Python dataclass import-loader registration and independently reviewed the source. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * Fix ownership in versioned rejection assertions Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * Specify credential query proof-method contracts Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * Add retained engine-input preparation and V3 proof adapter Source checkpoint for remote validation; new native and genuine-proof tests have not yet executed. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * Fix engine replay JSON fixture compilation and document adapter Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * Add typed credential query method contracts and exact capability admission Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * test: prepare retained query fixtures and persist genuine replay receipts Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * test: preserve replay job parse errors in assertions Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * feat: bind stored query requests and share original challenges Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * docs: align query contract README with crate template Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * fix: retain explicit columns when importing query goldens Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * docs: keep request contract quickstart concise and explicit Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * docs: keep challenge consumption inside the proof verifier Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * feat: adapt credential query contracts to exact V3 proofs Source checkpoint authored by Claude Opus 5.5. Remote compilation, native gates and genuine protocol receipt validation remain pending. Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com> * fix: reject pre-epoch verifier clock failures Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com> * test(core): reject raw padded temporal lexicals Align the temporal boundary regression with the existing strict raw-literal parser; preserve positive and midnight controls. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * test(zk): observe omitted-statement guest rejection directly Retain SDK error-chain evidence for an unchanged verifier-agreed anchor after removing a source statement, with an independently checked execution baseline and strict rejection classification. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * test(zk): exercise genuine query protocol receipts and controls Define six contract-authority proof cases and a cryptographically valid row-bound rejection, with retained artifacts and a verify-only hook-order regression. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * docs(zk): require retained evidence for replay outcome claims Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * fix(zk): validate pinned tool versions on raw output Share exact version-field matching between successful-result proof paths and the experiment driver. Reject near matches, malformed UTF-8, failed commands and Nargo output that only matches after trimming. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * test(zk): fix protocol proof assertion lint Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * feat(zk): specialize result-public triple patterns Opt-in experimental V4 relation preserves credential authentication and private membership. Native, constraint and genuine proof validation plus measured gate baselines are pending. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * test(zk): record observed omission rejection consistently Use the actual exact guest-abort classification in the pre-assertion evidence and retain the existing fail-closed assertion. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * test(zk): cover public-pattern proofs in the binding corpus Reuse the declared finite oracle and require direct malicious-witness rejection for absent V4 bindings. Real execution remains a separate source-bound gate. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * Retain public-pattern proof evidence in the Noir CI sweep Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * Bind public-pattern measurements to circuit sources and gate catalogs Record independently checked static evidence at14d426; retain legacy ACIR/ABI/key baselines. Generated catalog checks and evidence corruption controls pass; combined Rust gates and remaining Markdown fix follow before publication. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * feat(zk): add paired public-pattern ablation mode Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * docs(vcq): bind adapter availability to certified V3 capabilities Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * Document the available experimental VCQ method adapter Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * fix(zk): preserve evidence path containment without input audit ambiguity Resolve the manifest directory before selecting the checkout ancestor so symlink containment matches the original guard. This is an output-location check, with no repository data input. Thirty path-ownership tests and three filesystem equivalence controls passed. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * feat(zk): model issuer-authenticated RDF query inputs Add a default-off versioned native relation that verifies bounded EdDSA RDFC credentials against a verifier-owned authorization table and evaluates their internally mapped union. Preserve both dataset-authority modes and the existing V1-V3 source prefix. Include published-vector and adversarial tests; EC2 native validation and guest integration are pending. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * fix(zk): validate authenticated commitment resource policies Share the existing V3 policy-ceiling validator with authenticated dataset commitments before table or source processing. Add a focused native regression and positive control. Valid-policy commitment encoding is unchanged; compilation and EC2 tests remain pending. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * chore(zk): lock authenticated evaluator dependencies Preserve all existing package versions and checksums; add only the exact Ed25519 dependency closure required by the default-off authenticated RDF model. Generated on the authorized EC2 instance and independently compared before acceptance. Native and guest validation remain separate. * fix(zk): sort authenticated documents by their digest key Use the equivalent key-based sort required by the scoped Clippy gate. Preserve document ordering and authenticated commitment semantics. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * feat(zk): add separate authenticated RDF guest and verifier API Add default-off V5 guest and low-level accepted-artifact APIs with direct guest and genuine-proof drivers. Preserve the exact guest inputs and register the new detached dependency graph. Source checkpoint for bounded EC2 validation; the new guest lock, compilation and execution remain pending. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * build(zk): lock authenticated guest dependencies * test(zk): require explicit authenticated proof cases per job Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * feat(zk): bind authenticated RDF queries to VCQ method contracts Add a default-off V5 adapter with verifier-owned issuer policy, separate descriptor domains, authenticated scope claims, and consume-on-success challenge handling. Reuse existing V3 shape/result/nonce checks, add native and explicitly selected genuine test cases, and retain unvalidated registry status pending execution. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * test(zk): gate authenticated VCQ and direct guest execution (zkp-14.6) * docs(zk): record authenticated guest execution and proof limit (zkp-14.5) * docs(zk): record authenticated VCQ receipt evidence (zkp-14.6) Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * ci(zk): run the genuine V5 adapter driver per declared case Adds a branch-scoped workflow that exports both guests from the commit, proves one declared vcq_authenticated_genuine case per matrix job and uploads the driver's evidence directory. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_019QrHZ34TTVfgvvQxbPEKf7 * test(zk): prove the payment false-ASK example over a signed credential (zkp-14.6) Adds a synthetic payment-history credential in the eddsa-rdfc-2022 profile, signed with the public RFC 8032 TEST 1 key, and two genuine driver cases asking "was any payment returned?" (false) under a verifier-agreed anchor and under holder-declared authority. Cases now carry their dataset; the driver builds one verifier context per dataset. A native test checks both answers, both authorities and a wrong-key rejection. The branch workflow proves each declared case in its own job. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_019QrHZ34TTVfgvvQxbPEKf7 * ci(zk): prove only the payment cases on this branch Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_019QrHZ34TTVfgvvQxbPEKf7 * chore(zk): refresh lockfiles for the v0.1.3 workspace version Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_019QrHZ34TTVfgvvQxbPEKf7 * docs(zk): record the payment false-ASK genuine receipt audit (zkp-14.6) Audit record for the verifier-agreed 'was any payment returned?' case, in the sparq.independent-genuine-evidence-audit.v1 schema, for citation through paper-evidence.json. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_019QrHZ34TTVfgvvQxbPEKf7 * docs(zk): record the six CI genuine V5 adapter receipts (zkp-14.6) Audit records, in the same schema as the payment false-ASK record, for the remaining declared cases proved by run 37340835239: ASK true (verifier-agreed), ASK false (holder-declared), bag SELECT (holder-declared), CONSTRUCT under both authorities, and the genuine row-bound receipt the protocol rejects. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_019QrHZ34TTVfgvvQxbPEKf7 * docs(engine): keep README within the 120-line template cap Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_019QrHZ34TTVfgvvQxbPEKf7 * research(zk): audit record for the holder-declared payment false-ASK receipt Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_019QrHZ34TTVfgvvQxbPEKf7 * zk(native): re-pin reviewed native lock after the 0.1.3 path-crate bump The only Cargo.lock change since the reviewed candidate is sparq-canon and sparq-core moving 0.1.1 -> 0.1.3 (local path crates); no registry package changed. verify.py --smoke passes. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_019QrHZ34TTVfgvvQxbPEKf7 * ci(zk): make the genuine V5 receipt workflow dispatch-only over all nine cases Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_019QrHZ34TTVfgvvQxbPEKf7 * fix: address Codex review on the ZK stack - sparq-engine: CONSTRUCT/DESCRIBE entry points install their own query BASE, so IRI() never resolves against a previous query's BASE (native and guest now agree on graph results). - sparq-engine: the result-cache key includes temporal_year_range and strict_numeric_capacity, so a result cached under one capacity setting is never served for another. - zk evidence: case records name the dataset's own source, so payment receipts are no longer labelled as published W3C vectors. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_019QrHZ34TTVfgvvQxbPEKf7 * fix(engine): keep deterministic CONSTRUCT template nodes clear of computed blank nodes The deterministic template namespace now also avoids blank-node labels in the WHERE solutions, so an extension function returning e.g. _:tc0_0_0 can no longer collide with a fresh template node. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_019QrHZ34TTVfgvvQxbPEKf7 * perf(engine): let cached instants decide far-apart temporal comparisons Exact temporal keys made every dateTime/date comparison probe a hash memo and compare i128 keys, which slowed temporal FILTERs against main. The scan pushdown and both general comparison paths now first compare the cached f64 instants: a difference beyond a rounding margin (plus the fourteen-hour window for mixed timezone presence) has the sign of the exact difference, so it decides the row; near-ties, capacity-checked evaluations and uncached terms still use the exact keys. YEAR() and the other accessors validate with the borrowed exact parser instead of parsing twice. A differential test checks pushed-down, general and compiled comparisons against the exact reference over near-tie corpora. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_019QrHZ34TTVfgvvQxbPEKf7 * perf(engine): read dateTime components from validated fixed-width digits YEAR() and the other accessors validated the lexical and then re-parsed every component as f64. Read the digits the validator already checked instead, which removes the accessor slowdown against main. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_019QrHZ34TTVfgvvQxbPEKf7 * perf: validate exact numerics and civil dates without per-row overhead - Compiled FILTER constants cache their exact-numeric validity once. - Integer and decimal literals take a direct validation path ahead of the integer subtype list; decimal validation is a single byte pass. - Civil-date day numbers use i64 arithmetic below 2^40 years and widen to i128 only beyond that. - The exact temporal scan fallback moves out of line so the cached comparison inlines into scans. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_019QrHZ34TTVfgvvQxbPEKf7 * fix(spargebra): give deterministic anonymous nodes valid, collision-free labels Under sparq-deterministic-blank-nodes, anonymous nodes were labelled '#sparq-anon#N', which serializes to invalid SPARQL (_:#sparq-anon#0), so wrap_for_view, dataset overrides and SERVICE forwarding could not reparse it. Labels are now a counter behind a per-parse prefix ('sparqanon' plus as many 'x' as needed) that occurs nowhere in the parser input, so no written label can collide and the serialization round-trips. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_019QrHZ34TTVfgvvQxbPEKf7 * fix: honour temporal year ranges on identical operands; follow main's published parser fork - With id-filter-fastpath, x = x on one stored id returned true before either operand met an active temporal_year_range. The identical-id shortcut now steps aside while that range is active (Codex review of 58794cf0). - Main (#6663) publishes the vendored parser as sparq-spargebra and reaches it from upstream-named dependents through vendor/spargebra-shim. The exact evaluator, both guests and native composition now do the same (the shim forwards the deterministic-path and blank-node features); locks and the native lock pin follow. - The registry-only parser gate assumed published crates resolve upstream spargebra 0.4.6, which main replaced with the published fork, so its job, script and tests are removed; the stable parse_versioned_* contract and fork differential stay in the engine tests. The xpath oracle pin test now checks main's fork-and-shim selection. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_019QrHZ34TTVfgvvQxbPEKf7 * fix(engine): give language-tagged strings length-based EBV under SPARQL 1.1 SPARQL 1.1 (REC 2013) section 17.2.2 assigns every plain literal, language-tagged ones included, a length-based effective boolean value; only the 1.2 draft makes rdf:langString a type error. Rec2013 (the default, and the proof dialects' pin) now follows the Recommendation; Draft20260912 and directional strings keep the type error (Codex review of a5e85cde). Engine and evaluator-model tests cover FILTER and IF with non-empty and empty tagged strings in both dialects. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_019QrHZ34TTVfgvvQxbPEKf7 * test(supply-chain): follow main's push/nightly supply-chain workflow Lean CI (#6673) removed the PR path filter from supply-chain.yml; the coverage self-test now checks that the workflow runs on every main push without a path filter instead of matching the deleted filter patterns. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_019QrHZ34TTVfgvvQxbPEKf7 * fix(engine): sameTerm compares computed values as RDF terms sameTerm only matched two stored terms, so arithmetic and boolean results never compared equal to their literal: ASK { FILTER(!sameTerm(1 + 0, 1)) } answered true, and the proved evaluator admits this shape. Computed operands now compare as the literal a BIND produces, and an unbound or error operand is a type error instead of false. Both evaluator branches share the helper. Also refreshes the lock entries for the 0.1.4 workspace version (root, zk evaluator and guests, native composition) and re-pins the native lock delta. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_019QrHZ34TTVfgvvQxbPEKf7 * chore: drop model tags from lines this PR adds Model attribution tags stay out of repository content. Hash- or inventory-pinned artifacts (vendored SDK patches, native-composition vendor support, JSON evidence and fixtures) keep their bytes so their pins hold. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_019QrHZ34TTVfgvvQxbPEKf7 * docs(canon): keep the README within the 120-line template cap Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_019QrHZ34TTVfgvvQxbPEKf7 * chore(zk-compose): restore hash-pinned sources byte-for-byte The model-tag cleanup touched Noir sources and their helpers whose bytes are pinned by the result evidence (verify_result_evidence.py source hashes), so the foundation-key rebuild failed. Restore those files exactly; the tags stay until the evidence is regenerated. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_019QrHZ34TTVfgvvQxbPEKf7 * fix(server): stop advertising SPARQL 1.2 on Update-capable services sd:supportedVersion describes the whole service, but UPDATE refuses VERSION "1.2", so a client that picked a writable endpoint through service discovery got an unsupported-version error for a version it was told was supported. A service that advertises Update now lists 1.0 and 1.1 only; read-only services keep 1.2. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_019QrHZ34TTVfgvvQxbPEKf7 * fix(server): stop advertising sparql:version-1.2 sd:supportedVersion claims the whole language version, but VERSION "1.2" selects only the pinned draft EBV rule: temporal values keep the REC 2013 lexical space (no year 0000) and UPDATE refuses 1.2 announcements. The service description now lists 1.0 and 1.1 only, with tripwire tests that fail once 1.2 updates or year-zero dateTimes start working. Replaces the Update-only filter from the previous commit. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_019QrHZ34TTVfgvvQxbPEKf7 * fix(engine): NaN is not = to itself in ordinary execution op:numeric-equal(NaN, NaN) is false, but the identical-term shortcut in values_equal and the compiled equal-id fast path answered true for a stored "NaN"^^xsd:double/float, while strict numeric capacity (the proved evaluator's mode) answered false. Both shortcuts now skip float/double NaN, so the two modes agree. The proptest oracle and its known-answer case encoded the old shortcut and now follow op:numeric-equal; sameTerm stays true. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_019QrHZ34TTVfgvvQxbPEKf7 * fix(engine): NaN orders false, not a type error, in ordinary execution A stored "NaN"^^xsd:double/float misses the numeric cache, so `<`, `<=`, `>` and `>=` reached relational_value and raised a type error, while strict numeric capacity (the proved evaluator's mode) returned false as XPath numeric comparisons require. `!(?n < 0)` therefore kept the row only in strict mode. relational_value now returns false for any NaN operand. Adds a parity test running every comparison and arithmetic operator over NaN, +-INF, signed zero and mixed numeric tiers (projected, filtered and negated) in both modes, and moves the proptest oracle's NaN ordering from error to false. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_019QrHZ34TTVfgvvQxbPEKf7 * test(engine): widen the normal/strict numeric parity matrix Adds unary plus, ROUND/CEIL/FLOOR, NOT IN, IN lists, conjunctions and disjunctions, COALESCE/IF, casts, ORDER BY, DISTINCT, GROUP BY, MIN/MAX/ SUM/AVG, joins on a stored numeric, constant-object index lookups and VALUES joins over NaN, +-INF, signed zero and mixed tiers. All agree. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_019QrHZ34TTVfgvvQxbPEKf7 * build: refresh path-dependent lockfiles after the RDFC vendoring sparq-canon no longer depends on rdf-canon at runtime, so every separate workspace that reaches it drops rdf-canon (and, where nothing else used them, tracing*). bench/trust-graph also picks up the engine's existing oxiri/percent-encoding edges. No registry package version changed. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_019QrHZ34TTVfgvvQxbPEKf7 * zk(bindings): re-pin the replay generator hash after main's #6699 #6699 changed crates/sparq-bench/src/fuzz.rs (ORDER BY order check on blank-node answers), so the engine replay matrix's pinned hash of the original generator (fuzz.rs minus the replay module hook) no longer matched. The hook itself is unchanged; only the pin moves. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_019QrHZ34TTVfgvvQxbPEKf7 --------- Co-authored-by: GPT-6 <noreply@openai.com> Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
#6782) #6663 published the vendored parser as `sparq-spargebra`, but the release-wasm profile still keyed its opt-level "z" override by the old package name, so it matched nothing and the parser built at opt-level 3. That accounts for about 92 KB of the wasm_bundle_bytes growth the nightly Benchmarks run flagged. Claude-Session: https://claude.ai/code/session_01SLLS3hw4QZ3pVQypYFwdKc Co-authored-by: Claude <noreply@anthropic.com>
Requested by Jesse · project thread
Summary
Before: nothing from sparq was publishable to crates.io in practice. The registry closure was 37 crates (28 reached from the core alone through optional research features like ZK, trust, policy and terse), and published crates would have built against unpatched upstream
spargebra, silently losing the SPARQ-PATCHES.md fixes, including the §8 recursion-depth cap that guards the unauthenticated/sparqlendpoint.After: a deliberate 12-crate publish set plus the parser fork.
cargo publish --workspace --dry-runpackages and verifies all 13 in dependency order, and the bootstrap list indocs/release.md§4 is the exact command sequence.How
sparq-core,-substrate,-jsonld,-engine-serialize,-engine-service,-engine,-reason,-shacl,-hdt,-serve,-server,-cli. The 25 other formerly-publishable crates are nowpublish = false.release-plz.toml's version group is those 12.sparq-spargebra:vendor/spargebrais renamed to the packagesparq-spargebra(library name stillspargebra, so no source changes). The workspace dependency isspargebra = { package = "sparq-spargebra", version = "0.4.6", path = "vendor/spargebra" }. Third-party crates that name upstreamspargebra(oxigraph/spareval/sparopt in the bench and differential harnesses) are routed to the same fork through an unpublished re-export shim,vendor/spargebra-shim, because Cargo matches[patch]by package name. The 13 detached bench/zk workspaces point their own[patch.crates-io] spargebraat the same shim, so directspargebrausers there (e.g. bench/serve's parse spikes) also get the fork. It is versioned independently and published by hand when it changes.scripts/publish-strip.py: at packaging time it removes optional dependencies onpublish = falsecrates from the publishable manifests, together with every feature that needs them (transitively), orphaned optional deps, dev-deps on unpublished crates, and gated examples. It trims the workspace to the publish set, and with--with-vendoredit adds the fork. It refuses a non-optional edge to an unpublished crate, a strippeddefaultfeature, or a published crate enabling another's stripped feature.--checkprints the plan. Today it stripsel/tersefromsparq-cliandcomplete,facets,federation-descriptors,geo,http3,odrl-authz,solid-authz,solid-authz-trust,tersefromsparq-server. Those stay available from a git build. No default feature is affected.release-interval-guard.pynow allows optional and dev edges to unpublished crates, since the strip removes them. Non-optional edges still refuse.publish.ymlcratesjob: runs the strip, then onecargo package --workspace --no-verify --allow-dirty. The old per-cratecargo package -ploop could not resolve unpublished workspace deps.tomlkitis hash-pinned in.github/requirements/publish-strip.txt.docs/release.md§4 has the publish set and the bootstrap sequence. It notes the crates.io new-crate rate limit (a short burst, then about one new name per 10 minutes, so about 90 minutes for 13). §8c has the release-plz flip, which adds the strip step beforerelease-plz release.Why strip instead of a restructure: the research edges are
#[cfg(feature)]blocks insidesparq-server(http.rs,solid_authz.rs) andsparq-cli. Inverting them into separate crates means moving a lot of code that the LWS and ZK threads are actively changing. The strip keeps every in-repo feature working, and its refusal rules keep it sound. To publish a capability later, flip its crate out ofpublish = falseand add it to the version group. The strip then stops removing it.Overlap with #6649: merges cleanly on top of it, and with #6649 the strip no longer needs to remove
sparq-server's zk/trust dev-deps.Follow-up (not here): upstream
spargebra0.4.7 is now out. §7–§10 are sparq-local, so the fork stays; rebasing it onto 0.4.7 is separate work.Verified locally
python3 scripts/publish-strip.py --with-vendored && cargo publish --workspace --dry-run --allow-dirty: all 13 crates packaged and verified, exit 0.publish.ymlpackaging step, run locally: 13.cratefiles, matching the expected count.cargo check --workspace --exclude sparq-py: clean.cargo test --manifest-path vendor/spargebra/Cargo.toml: 28 passed (recursion-depth + custom-aggregate regressions).python3 -m unittest scripts/tests/test_release_publish_guard.py scripts/tests/test_publish_strip.py: 86 + 6 OK.release-interval-guard.py --dry-run: 12 crates, version group covers all 12.cargo metadataon bench/parse, bench/serve, zk/xpath/differential: resolve.Base gate (always required)
cargo build --workspacesucceeds (cargo check --workspace --exclude sparq-pyclean locally; CI runs the build).cargo clippy --workspace --exclude sparq-py --all-targets -- -D warnings: no Rust source changed; left to CI.cargo testpasses for every crate this PR touches (the vendored fork's tests).Targeted re-evaluation (check the rows that apply to your change)
spargebra): package rename only, with byte-identical sources. Lock diff adds justsparq-spargebraand keeps one parser in the graph via the shim. The conformance ratchet runs in CI.spargebracargo-vet policy/exemption still applies to the shim.cargo deny/vet run in CI.Ratchets and conventions
Security
🤖 Generated with Claude Code
https://claude.ai/code/session_014tB5DfVUDWY537tfMuLEPi
Generated by Claude Code