Skip to content

Traverse v0.14.0

Latest

Choose a tag to compare

@enricopiovesan enricopiovesan released this 29 Sep 20:00
· 30 commits to main since this release
Immutable release. Only release title and notes can be modified.
4dac877

Released 2026-09-29.

Traverse v0.14.0 is a minor lockstep crate + npm release. It carries
breaking changes to the Spec 138 exact-ref model surface, and following
this repo's 0.x convention those use a minor bump, not a patch. Its
throughline is governed, signed model execution: exact model packages
are now signed, bound to the application that pins them, carry
machine-readable rights, and the first real trained model runs through
that pipeline identically on native and browser hosts.

Highlights

Signed exact-ref model packages (Spec 138 0.4.0, Decision 101, #1565 / #1566)

  • Breaking: model manifests move to schema 2.0.0.
    • Every package ships a detached Ed25519 model.sig.json over the exact
      model.manifest.json bytes.
    • An application's exact_model_dependencies pin binds the SHA-256 of
      those manifest bytes, and declares target, the expected rights, and
      an optional signer key_id.
  • Host-owned trust roots: TrustedModelKeys (Rust) and
    trustedPublicKeysHex (web). Apps can never add trust.
  • Packages enter the cache only through register_package /
    registerPackage, which verifies:
    • the signature and trusted key;
    • the digest against exactly one pin;
    • the manifest schema (unknown fields fail closed), rights, target, and
      limits.
      Every execute re-hashes the cached bytes.
  • Rights: a required rights object (license_id, attribution,
    redistribution, commercial_use, source_url) is checked against the
    pin and exposed to hosts and UIs unchanged.
  • Failures keep model_unavailable / model_incompatible and add a stable
    reason (signature_invalid, key_untrusted, digest_mismatch,
    rights_mismatch, target_unsupported, crypto_unavailable,
    candidate_unsupported, …).
  • Browser: WebCrypto Ed25519 only, failing closed without it. Typed
    results carry model_ref, target, and a redacted trace. AbortSignal
    cancellation and timeouts are supported. Resolution is single exact-ref
    wasm-cpu
    (mixed-candidate resolution is #1460). Registration and
    execution make zero network calls.
  • Versioned JSON schemas for the pin, manifest, and signature live under
    contracts/connectors/traverse.model-runtime/schemas/.

First trained exact-ref model (Spec 138 0.5.0, Decision 102, ADR-0077, #1461 / #1569)

  • digits-mlp-1.0.0: a 64→32→10 MLP trained on the UCI Optical
    Recognition of Handwritten Digits dataset (CC BY 4.0). It scores
    96.10% on the held-out split, bit-identically in the trainer, the
    native host, and the browser host.
  • It comes with the vendored, pinned dataset, a seeded offline trainer
    (traverse-model-trainer, not published), and a no_std wasm32 guest
    with an audited ABI unsafe boundary (ADR-0077).
  • A CI job proves the checked-in model.wasm rebuilds byte-identically,
    with zero imports, on Linux and macOS.
  • The package is signed with the test-only key. Production model
    signing is #1567 (Decision 103).

Swift and Kotlin fixes since v0.13.0

  • Swift: the default fuel budget is fixed, and bridge errors now surface
    structured codes (#1564). HostError::json() produces valid JSON (#1563).
    wasmi portable dispatch prevents a stack overflow (#1557).
  • Kotlin: Maven Central releases now actually release (automaticRelease)
    (#1556).

Upgrade notes

See docs/upgrade-to-v0.14.0.md. In short:

  • Re-sign and re-pin every Spec 138 model package. Schema 1.0.0
    manifests no longer verify.
  • ExactModelHostConnector::new(pins, trusted_keys) and
    new ExactModelBrowserHost(pins, { trustedPublicKeysHex }) now require
    trust roots.
  • registerPackage(manifestBytes, wasm, signatureBytes) replaces
    insertVerified.
  • Pin traverse-embedder-web@0.14.0 together with crates at 0.14.0
    (lockstep, Decision 85).
  • Exact-ref model execution is implemented in the Rust native runtime and
    the web embedder. The Swift, Kotlin, and .NET embedders do not execute
    exact-ref models yet.

Validation

  • The tagged commit passes the GitHub version-guard, repository-checks
    (including the new digits-guest reproducibility check), coverage-gate,
    and stress jobs before the tag-triggered publishes.
  • This cut needed a traverse-registry bump (registry#617 / registry#618,
    0.25.0): the published traverse-registry@0.24.0 capped
    traverse-contracts below 0.14.0, the same recurring pattern as v0.13.0.

Links