feat(openontology): implement OpenOntology Phase 0 + local engine and CLI (#99)
Some checks failed
CI / build (push) Has been cancelled
test / test (push) Has been cancelled

Implements OpenPRD 0001 through Phase 0 (specification, schemas, example,
docs surface) and Phase 1 (local engine, CLI, conformance tests).

Schemas (17 contracts, JSON Schema Draft 2020-12, additionalProperties:false)
  manifest, namespace, entity-type, property, relationship-type, constraint,
  query, action, entity, claim, source, evidence, changeset, review, approval,
  event, package — registered in @logicsrc/validators and exported from
  @logicsrc/schemas under https://logicsrc.com/schemas/openontology/.

@logicsrc/openontology
  - canonical JSON + sha256 package digests; YAML, JSON, NDJSON, and inline
    authoring all compile to the same bytes, so digests are authoring-agnostic
  - id profile: compact / IRI / urn with one canonicalization rule, prefix
    bound by a Namespace object so IRIs reverse unambiguously
  - validation: schema, graph (domain/range, datatypes, dangling refs),
    provenance (source-or-firstParty, agent runId, derivation inputs), policy
    (excerpt limits, licensing, visibility, staleness) and declared
    constraints; four severities, stable codes, text/json/yaml/markdown
  - portable triple-pattern query AST: multi-hop, 14 operators, asOf and
    recordedAsOf, per-status filtering, distinct/order/limit, explanation
    mode, and enforced depth/binding/row limits
  - append-only store: claims are immutable; dispute/retract/supersede append
    status transitions and the effective status is the latest one
  - change sets: 9 operations, atomic pre-flight, conflict detection on stale
    base revisions, semantic diff with duplicate-identity warnings and
    affected-query deltas, per-operation reviewer decisions
  - policy: agents propose but can never apply — the denial keys on actor
    type, so every scope plus high confidence plus --yolo still cannot apply;
    merges need approval, bulk retractions need two, undeclared action side
    effects are denied
  - JSON-LD 1.1 export/import with PROV-O aliases and lossy-field reporting
  - pluggable signature envelope with a jws-ed25519 reference profile and a
    fail-closed trust policy

CLI: logicsrc ontology init|validate|lint|build|inspect, entity, claim, query,
changeset, import, export, audit. Reads take --format, writes default to a
proposal, exit codes are stable for CI.

Example: examples/openontology/ethereum-ecosystem — 12 entity types, 17
relationship types, 63 entities, 169 claims, 25 sources, 31 evidence records,
5 saved queries, every claim lifecycle state, and a pending merge proposal.
All data is fictional; the directory is removable without affecting any core
test.

Docs: docs/openontology{,-governance,-interoperability}.md, a real
/openontology route, homepage + nav + sitemap entries, and a root README
section.

Verification: 112 new tests; full monorepo build and every workspace test
pass; conformance bundle (18 valid + 13 invalid fixtures) runs against the
published schemas alone; Node.js 25 and Bun 1.3 produce byte-identical
digests, revisions, event trails, and query results.

Not included (later PRD phases): MCP resources, REST/SSE, Turso adapter, TUI
and PWA surfaces, RDF/SHACL mappings, source adapters, governed actions.

Refs: prd/0001-add-logicsrc-openontology-spec.md

Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
This commit is contained in:
Anthony Ettinger 2026-07-26 02:10:13 -07:00 • committed by GitHub
parent 0d9dab0447
commit 58c942c67f
No known key found for this signature in database
GPG key ID: B5690EEEBB952194
101 changed files with 11934 additions and 10 deletions

View file

@ -0,0 +1,144 @@
import { createPrivateKey, createPublicKey, generateKeyPairSync, sign, verify } from "node:crypto";
import type { KeyObject } from "node:crypto";
import type { Signature } from "./types.js";
/**
* Pluggable signature envelope.
*
* PRD open question 2 asked whether package signing should start from JWS, a
* DID proof, or Sigstore. This implementation defines the envelope as the
* contract and ships ONE reference profile — `jws-ed25519`, detached, over the
* package digest — so no DID method, wallet, or CA is mandatory (R19). Other
* providers plug in by implementing this interface.
*/
export interface SignatureProvider {
readonly algorithm: string;
readonly signer: string;
readonly keyId?: string;
sign(payload: string): string;
verify(payload: string, signature: string): boolean;
}
export interface VerificationResult {
ok: boolean;
algorithm: string;
signer: string;
reason?: string;
}
const ED25519 = "jws-ed25519";
export function createEd25519Provider(options: {
signer: string;
privateKey: KeyObject | string;
publicKey?: KeyObject | string;
keyId?: string;
}): SignatureProvider {
const privateKey =
typeof options.privateKey === "string" ? createPrivateKey(options.privateKey) : options.privateKey;
const publicKey = options.publicKey
? typeof options.publicKey === "string"
? createPublicKey(options.publicKey)
: options.publicKey
: createPublicKey(privateKey);
return {
algorithm: ED25519,
signer: options.signer,
keyId: options.keyId,
sign(payload) {
return base64url(sign(null, Buffer.from(payload, "utf8"), privateKey));
},
verify(payload, signature) {
try {
return verify(null, Buffer.from(payload, "utf8"), publicKey, fromBase64url(signature));
} catch {
return false;
}
}
};
}
/** Generate a throwaway Ed25519 keypair — used by tests and `init`. */
export function generateEd25519KeyPair(): { privateKey: KeyObject; publicKey: KeyObject } {
return generateKeyPairSync("ed25519");
}
/** Sign a package digest, producing the envelope stored in the manifest. */
export function signDigest(
digest: string,
provider: SignatureProvider,
now: string
): Signature {
return {
algorithm: provider.algorithm,
signer: provider.signer,
value: provider.sign(digest),
created: now,
...(provider.keyId ? { keyId: provider.keyId } : {})
};
}
export function verifyDigestSignature(
digest: string,
signature: Signature,
resolveProvider: (signature: Signature) => SignatureProvider | undefined
): VerificationResult {
const provider = resolveProvider(signature);
if (!provider) {
return {
ok: false,
algorithm: signature.algorithm,
signer: signature.signer,
reason: `No verifier registered for signer ${signature.signer} (${signature.algorithm})`
};
}
if (provider.algorithm !== signature.algorithm) {
return {
ok: false,
algorithm: signature.algorithm,
signer: signature.signer,
reason: `Verifier algorithm ${provider.algorithm} does not match signature ${signature.algorithm}`
};
}
const ok = provider.verify(digest, signature.value);
return {
ok,
algorithm: signature.algorithm,
signer: signature.signer,
reason: ok ? undefined : "Signature does not verify against the package digest"
};
}
/**
* Trust policy for imported maintainers (R112): a package's signatures are
* only meaningful against an explicit list of signers you already trust.
*/
export function verifyPackageSignatures(
digest: string,
signatures: Signature[] | undefined,
trusted: Map<string, SignatureProvider>
): { ok: boolean; results: VerificationResult[]; untrusted: string[] } {
const results: VerificationResult[] = [];
const untrusted: string[] = [];
for (const signature of signatures ?? []) {
if (!trusted.has(signature.signer)) untrusted.push(signature.signer);
results.push(verifyDigestSignature(digest, signature, (s) => trusted.get(s.signer)));
}
return {
ok: results.length > 0 && results.every((r) => r.ok),
results,
untrusted
};
}
function base64url(buffer: Buffer): string {
return buffer.toString("base64").replace(/\+/g, "-").replace(/\//g, "_").replace(/=+$/, "");
}
function fromBase64url(value: string): Buffer {
const padded = value.replace(/-/g, "+").replace(/_/g, "/");
return Buffer.from(padded, "base64");
}