Skip to content

TRACE SDK 0.5.1

Choose a tag to compare

@imran-siddique imran-siddique released this 09 Aug 04:00
· 259 commits to main since this release
e9f0a52

Fixed

  • transparency is optional below Level 2. The model required a non-empty URI on every record, which was stricter than both schema/trace-claim.json (required, no minLength) and the conformance suite, which runs TR-ANC at Level 2 only. A Level 0 or Level 1 record is not anchored, so it has no receipt to name, and that state was unrepresentable. None now means unanchored; an empty string stays rejected, since "" is not a URI and a field that looks populated but resolves to nothing is worse in a trust record than an absent one.

Changed

  • BREAKING: TRACE v0.2 changes the EAT profile URI to tag:agentrust-io.com,2026:trace-v0.2 (was tag:agentrust.io,2026:trace-v0.1). agentrust.io was never a domain this project controlled; it resolves to third-party parked addresses. RFC 4151 permits a tag URI only where the minting authority controlled the named domain on the stated date, so the v0.1 identifier was invalid rather than merely misspelled: it asserted authority over a name someone else could stand up a conflicting definition at.

    Cutover, not coexistence. A v0.2 verifier requires the new URI and rejects the old one; it does not accept both. Dual acceptance would keep the invalid identifier live indefinitely, which is the thing being fixed. Records already issued under v0.1 stay verifiable against spec/trace-v0.1.md and the published agentrust-trace 0.4.x releases, which remain on PyPI. They are v0.1 records and are read as such.

    Nothing else in the record format changed. No field was added, removed, or re-typed, so migration for a producer is the profile string and a dependency bump.

    Moved together: spec/trace-v0.2.md (new, with a "Changes from v0.1" section), spec/trace-v0.1.md (retained, marked superseded), the root schema/trace-claim.json const, the packaged agentrust_trace/schema/trace-v0.2.json, the eat_profile Literal in models.py, the AGT adapter, validate.py's schema resource, the four platform example records, and the docs.

  • Other agentrust.io URLs moved to agentrust-io.com: the registry and verifier hosts in the AGT adapter and the schema $id.

Fixed

  • verify_record() now enforces the profile cutover this changelog already declares. The entry above states that a v0.2 verifier "requires the new URI and rejects the old one; it does not accept both" — but verify_record() never read eat_profile, so a record carrying the v0.1 identifier, a future version, a foreign tag, or no profile at all verified exactly as a v0.2 record, provided its signature checked out. A valid signature over semantics this build does not implement is not evidence, so the profile is now checked first, before any cryptographic work: anything other than TRACE_PROFILE_V0_2 (newly exported) raises ValueError, with a message that says why when the profile is the superseded v0.1 identifier. Same shape as the revocation fix above: an already-merged spec requirement (spec/trace-v0.2.md section 2) that the reference implementation did not carry out. docs/verification.md step 4 notes the check is now built in. No normative text, schema, or record field changed.