master
5
Commits
| Author | SHA1 | Message | Date | |
|---|---|---|---|---|
|
|
4afa36e7a2 |
feat(licence): contributed manifests are CC0 1.0
Contributed manifests were in no declared condition at all, which left §9a replication with no grant flowing through it: peers mirror each other's catalogues wholesale, and every hop of that was unlicensed. CC0 rather than a share-alike licence, because a share-alike works by asserting a right in the data and then conditioning its use. The position in docs/legal-posture.md §3 is that presence timings are facts rather than protectable expression — asserting copyright in them in order to license them would contradict that argument in the same repository, and that contradiction is worth more to an opponent than the licence is worth to us. CC0 also waives the sui generis database right by name, closing the EU-specific residual exposure from the contributor's side. The grant is taken at token issuance, and that is not incidental. There are no accounts, so there is no sign-up to attach terms to, and a manifest arrives over POST /manifests with no channel to negotiate over. Acquiring the contribute capability is the only moment a grant can be made, so POST /tokens now returns the licence and its terms alongside the token — a licence the server publishes but never delivers is one no contributor agreed to. The test pins the scope limit as well as the identifier. Bounding the grant to the manifest is the half that can fail silently: a reworded term reading onto the underlying work would purport to grant what no contributor can. Also records the settled code-licence position across all four repositories in the legal posture, correcting an earlier claim there that the plugin and extraction repos declared nothing. Both already carried LICENSE files. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> TRACES: UR-019 | PR-006 |
||
|
|
0ff1018bcc |
Withdraw the file-hash tier; document the legal posture
Removes `cut.video_hash` and the `exact` match tier on legal grounds. The OpenSubtitles hash was the strongest technical signal available — it identifies a specific file, so it cannot produce a false positive — and that is exactly the problem. Every tier must be a claim about a *cut*, never about a copy. A TMDB id discloses "some copy of this film", which is what a library catalogue discloses. A file hash discloses "this exact release": it made a read endpoint into a release-level oracle, and made an instance's database a mapping from file fingerprints to the instances holding them. That is a far more specific disclosure than PR-005 permits, and a dataset no volunteer operator should be asked to hold. The audio signature is the replacement: derived from content, it identifies the cut rather than the copy, so two encodes of the same edit agree. The field is deleted rather than kept as a vestigial null, on the same reasoning §2 applied to `anneal_sec` — a key naming a signal the format no longer has is actively misleading — so an upload carrying one is now an unknown-field 400, with a test asserting it. **Every content_id changes**, including for manifests that never carried a hash, because the canonical `cut` object lost a key. The golden vector is regenerated and re-verified against an independent Python implementation; the plugin and extraction repos must adopt the new value or federation deduplication silently breaks. Free now, pre-release; not free later. Adds docs/legal-posture.md, the operator-facing half of what §5a asks for: what an instance holds exhaustively, what it structurally cannot do, and how that sits against the intermediary-liability regimes that plausibly apply. 208 tests. Coverage 25/32. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> TRACES: UR-011 | SR-004, PR-005 |
||
|
|
88c7264094 |
Ship the SR-003 schema bump: jmanifest_version 2
Moves the exchange envelope to version 2 in lockstep with the truth file's schema_version, per SR-003's requirement that breaking changes be batched and ship together rather than piecemeal. The plugin had already moved to schema_version 2; the server declaring 1 while accepting the new fields defeated the point of having a version at all. Flag day, not dual-accept (JR-003): version 1 is now rejected outright. All three components are pre-release, and a v1 read path would be the one nobody exercises, so it is the one that would rot while being dragged through every later change to the reader. A pipeline still emitting v1 is incompatible until updated — stated plainly rather than papered over with a shim nobody tests. scenes become objects carrying belief and route (extraction AR-017) instead of float pairs. Belief is bounded to [0, 1] rather than merely stored: §5a's Threat 1 argument rests on every accepted value being bounded, and an unbounded float is a 64-bit channel however harmless it looks. route is a closed enum, so an invented value cannot be stored. UR-018 is the requirement with the trap in it, and the reason content_id.rs is untouched by this commit: belief is a producer-side estimate that may legitimately differ between pipeline versions for identical timings, so including it in the canonical form would give two servers different ids for the same content — the exact failure mode §9a quantises centiseconds to avoid, reintroduced one field along. It replicates as an attribute, exactly as audio_signature does. The golden vector still passes unchanged, which is the evidence rather than the claim. 191 tests. UR-015..018 move from Planned to Done; coverage 24/32 (75%). Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> TRACES: UR-014, UR-015, UR-016, UR-017, UR-018 | SR-003 |
||
|
|
c73f417d45 |
Traceability: move per-repo settings into traceability.toml
The shared extractor now takes its per-repo taxonomy from a config file rather than CLI flags, so the wrapper shrinks to the one thing it alone knows: the repo root, which the vendored gate cannot infer because its own default resolves inside the submodule. Coverage unchanged at 23/32; the gate reports the scan as '26 (.rs under src, tests)', which is the config being read rather than defaults being guessed. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> |
||
|
|
a848750a65 |
Initial implementation: core vertical slice
Implements the core of SPEC.md — the manifest exchange, less audio-tier matching (§3) and federation (§9a), both of which the spec sequences as later work. - §2 Jmanifest format and series bundles - §3 cut matching: exact / runtime / loose tiers - §4 API, less POST /manifests/search - §5 rate limiting; §5a trust model, anonymous bearer tokens - §6 upload validation, all four stages - §7 relational storage, no JSON blob on the write path - §8 Rust + Axum + SQLite, single serialized writer, in-process job queue - §9a content addressing, computed on upload Reconciled against the system spec: - anneal_sec removed, withdrawn upstream by AR-012/AR-013. Presence follows track extent, so a track survives its own gaps and there is nothing to anneal. Its successor extinction_sec and the new gallery_scope are accepted and stored; scope enters the §7 ranking. A manifest still carrying anneal_sec is a hard 400, not silently ignored — it came from a pipeline whose window semantics differ from what this server assumes. - Audio signature: media under 120 s now emits no signature at all, matching scene-actor-extraction IR-007. The earlier §3 draft allowed a shortened window under 150 s, which was the weaker rule — a caller-varying length is the property SR-004 forbids. - UR IDs regularised to UR-nnn; docs/requirements.md registers 32 requirements, each tracing to an SR-nnn or PR-nnn. 189 tests: unit, end-to-end through the real router, and an injection suite covering SQL, JSON, header and Unicode payloads. Writing that suite found two real gaps, both fixed here: compatibility homoglyphs passed the §5a character class, and a one-frame audio signature was accepted on a feature-length item. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> |