mirror of
https://github.com/profullstack/logicsrc.git
synced 2026-10-03 05:07:10 +00:00
feat(openontology): implement OpenOntology Phase 0 + local engine and CLI (#99)
Implements OpenPRD 0001 through Phase 0 (specification, schemas, example, docs surface) and Phase 1 (local engine, CLI, conformance tests). Schemas (17 contracts, JSON Schema Draft 2020-12, additionalProperties:false) manifest, namespace, entity-type, property, relationship-type, constraint, query, action, entity, claim, source, evidence, changeset, review, approval, event, package — registered in @logicsrc/validators and exported from @logicsrc/schemas under https://logicsrc.com/schemas/openontology/. @logicsrc/openontology - canonical JSON + sha256 package digests; YAML, JSON, NDJSON, and inline authoring all compile to the same bytes, so digests are authoring-agnostic - id profile: compact / IRI / urn with one canonicalization rule, prefix bound by a Namespace object so IRIs reverse unambiguously - validation: schema, graph (domain/range, datatypes, dangling refs), provenance (source-or-firstParty, agent runId, derivation inputs), policy (excerpt limits, licensing, visibility, staleness) and declared constraints; four severities, stable codes, text/json/yaml/markdown - portable triple-pattern query AST: multi-hop, 14 operators, asOf and recordedAsOf, per-status filtering, distinct/order/limit, explanation mode, and enforced depth/binding/row limits - append-only store: claims are immutable; dispute/retract/supersede append status transitions and the effective status is the latest one - change sets: 9 operations, atomic pre-flight, conflict detection on stale base revisions, semantic diff with duplicate-identity warnings and affected-query deltas, per-operation reviewer decisions - policy: agents propose but can never apply — the denial keys on actor type, so every scope plus high confidence plus --yolo still cannot apply; merges need approval, bulk retractions need two, undeclared action side effects are denied - JSON-LD 1.1 export/import with PROV-O aliases and lossy-field reporting - pluggable signature envelope with a jws-ed25519 reference profile and a fail-closed trust policy CLI: logicsrc ontology init|validate|lint|build|inspect, entity, claim, query, changeset, import, export, audit. Reads take --format, writes default to a proposal, exit codes are stable for CI. Example: examples/openontology/ethereum-ecosystem — 12 entity types, 17 relationship types, 63 entities, 169 claims, 25 sources, 31 evidence records, 5 saved queries, every claim lifecycle state, and a pending merge proposal. All data is fictional; the directory is removable without affecting any core test. Docs: docs/openontology{,-governance,-interoperability}.md, a real /openontology route, homepage + nav + sitemap entries, and a root README section. Verification: 112 new tests; full monorepo build and every workspace test pass; conformance bundle (18 valid + 13 invalid fixtures) runs against the published schemas alone; Node.js 25 and Bun 1.3 produce byte-identical digests, revisions, event trails, and query results. Not included (later PRD phases): MCP resources, REST/SSE, Turso adapter, TUI and PWA surfaces, RDF/SHACL mappings, source adapters, governed actions. Refs: prd/0001-add-logicsrc-openontology-spec.md Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
This commit is contained in:
parent
0d9dab0447
commit
58c942c67f
101 changed files with 11934 additions and 10 deletions
144
packages/openontology/src/signature.ts
Normal file
144
packages/openontology/src/signature.ts
Normal file
|
|
@ -0,0 +1,144 @@
|
|||
import { createPrivateKey, createPublicKey, generateKeyPairSync, sign, verify } from "node:crypto";
|
||||
import type { KeyObject } from "node:crypto";
|
||||
import type { Signature } from "./types.js";
|
||||
|
||||
/**
|
||||
* Pluggable signature envelope.
|
||||
*
|
||||
* PRD open question 2 asked whether package signing should start from JWS, a
|
||||
* DID proof, or Sigstore. This implementation defines the envelope as the
|
||||
* contract and ships ONE reference profile — `jws-ed25519`, detached, over the
|
||||
* package digest — so no DID method, wallet, or CA is mandatory (R19). Other
|
||||
* providers plug in by implementing this interface.
|
||||
*/
|
||||
export interface SignatureProvider {
|
||||
readonly algorithm: string;
|
||||
readonly signer: string;
|
||||
readonly keyId?: string;
|
||||
sign(payload: string): string;
|
||||
verify(payload: string, signature: string): boolean;
|
||||
}
|
||||
|
||||
export interface VerificationResult {
|
||||
ok: boolean;
|
||||
algorithm: string;
|
||||
signer: string;
|
||||
reason?: string;
|
||||
}
|
||||
|
||||
const ED25519 = "jws-ed25519";
|
||||
|
||||
export function createEd25519Provider(options: {
|
||||
signer: string;
|
||||
privateKey: KeyObject | string;
|
||||
publicKey?: KeyObject | string;
|
||||
keyId?: string;
|
||||
}): SignatureProvider {
|
||||
const privateKey =
|
||||
typeof options.privateKey === "string" ? createPrivateKey(options.privateKey) : options.privateKey;
|
||||
const publicKey = options.publicKey
|
||||
? typeof options.publicKey === "string"
|
||||
? createPublicKey(options.publicKey)
|
||||
: options.publicKey
|
||||
: createPublicKey(privateKey);
|
||||
|
||||
return {
|
||||
algorithm: ED25519,
|
||||
signer: options.signer,
|
||||
keyId: options.keyId,
|
||||
sign(payload) {
|
||||
return base64url(sign(null, Buffer.from(payload, "utf8"), privateKey));
|
||||
},
|
||||
verify(payload, signature) {
|
||||
try {
|
||||
return verify(null, Buffer.from(payload, "utf8"), publicKey, fromBase64url(signature));
|
||||
} catch {
|
||||
return false;
|
||||
}
|
||||
}
|
||||
};
|
||||
}
|
||||
|
||||
/** Generate a throwaway Ed25519 keypair — used by tests and `init`. */
|
||||
export function generateEd25519KeyPair(): { privateKey: KeyObject; publicKey: KeyObject } {
|
||||
return generateKeyPairSync("ed25519");
|
||||
}
|
||||
|
||||
/** Sign a package digest, producing the envelope stored in the manifest. */
|
||||
export function signDigest(
|
||||
digest: string,
|
||||
provider: SignatureProvider,
|
||||
now: string
|
||||
): Signature {
|
||||
return {
|
||||
algorithm: provider.algorithm,
|
||||
signer: provider.signer,
|
||||
value: provider.sign(digest),
|
||||
created: now,
|
||||
...(provider.keyId ? { keyId: provider.keyId } : {})
|
||||
};
|
||||
}
|
||||
|
||||
export function verifyDigestSignature(
|
||||
digest: string,
|
||||
signature: Signature,
|
||||
resolveProvider: (signature: Signature) => SignatureProvider | undefined
|
||||
): VerificationResult {
|
||||
const provider = resolveProvider(signature);
|
||||
if (!provider) {
|
||||
return {
|
||||
ok: false,
|
||||
algorithm: signature.algorithm,
|
||||
signer: signature.signer,
|
||||
reason: `No verifier registered for signer ${signature.signer} (${signature.algorithm})`
|
||||
};
|
||||
}
|
||||
if (provider.algorithm !== signature.algorithm) {
|
||||
return {
|
||||
ok: false,
|
||||
algorithm: signature.algorithm,
|
||||
signer: signature.signer,
|
||||
reason: `Verifier algorithm ${provider.algorithm} does not match signature ${signature.algorithm}`
|
||||
};
|
||||
}
|
||||
const ok = provider.verify(digest, signature.value);
|
||||
return {
|
||||
ok,
|
||||
algorithm: signature.algorithm,
|
||||
signer: signature.signer,
|
||||
reason: ok ? undefined : "Signature does not verify against the package digest"
|
||||
};
|
||||
}
|
||||
|
||||
/**
|
||||
* Trust policy for imported maintainers (R112): a package's signatures are
|
||||
* only meaningful against an explicit list of signers you already trust.
|
||||
*/
|
||||
export function verifyPackageSignatures(
|
||||
digest: string,
|
||||
signatures: Signature[] | undefined,
|
||||
trusted: Map<string, SignatureProvider>
|
||||
): { ok: boolean; results: VerificationResult[]; untrusted: string[] } {
|
||||
const results: VerificationResult[] = [];
|
||||
const untrusted: string[] = [];
|
||||
|
||||
for (const signature of signatures ?? []) {
|
||||
if (!trusted.has(signature.signer)) untrusted.push(signature.signer);
|
||||
results.push(verifyDigestSignature(digest, signature, (s) => trusted.get(s.signer)));
|
||||
}
|
||||
|
||||
return {
|
||||
ok: results.length > 0 && results.every((r) => r.ok),
|
||||
results,
|
||||
untrusted
|
||||
};
|
||||
}
|
||||
|
||||
function base64url(buffer: Buffer): string {
|
||||
return buffer.toString("base64").replace(/\+/g, "-").replace(/\//g, "_").replace(/=+$/, "");
|
||||
}
|
||||
|
||||
function fromBase64url(value: string): Buffer {
|
||||
const padded = value.replace(/-/g, "+").replace(/_/g, "/");
|
||||
return Buffer.from(padded, "base64");
|
||||
}
|
||||
Loading…
Add table
Add a link
Reference in a new issue