The exceptions table gains the calibration's own near-duplicate dedup.
It is not a close call in either direction: at 1 - 1e-7 it tests vector
identity rather than similarity, and it runs on the fit's input, so a
calibrated comparison there would have to be calibrated by the fit it is
feeding.
More importantly, the invariant now has the enforcement its register row
always claimed. check_raw_cosine.py blocks in CI, and it caught a live
violation on its first run -- the identity matcher's no-calibration
fallback, which thresholded raw cosine distance and then fed
max(0, cosine) into the Bayesian accumulation as a posterior, past a
contract that says in terms it cannot be handed an uncalibrated number.
The note is explicit about what a pass does not prove: the check cannot
follow a cosine through a variable across statements, and says nothing
about the GEMM similarity matrix. Both remain conventions backed by
review. Writing that down is the point -- a checker trusted for more
than it does is how the raw-cosine fallback survived being read past.
TRACES: AR-024 | SR-002
hero/ and dvu-hero/ are ~140 MB of film clips, DVU annotations and the
gallery built from them. All reproducible via scripts/fetch_dvu.sh plus the
DVU movie.shots set, and the replay fixtures derived from them ship through
the artifact registry — so none of it belongs in git.
The matrix section still claimed PR-005 "has no software row at all" and could
be verified only by prohibition. jRay's register has carried four rows against
it since the schema-v2 landing: JR-038 (Done), JR-034 and JR-039 (both High,
both T1, both still Planned), and JR-040 (T4). jRay is the component that
actually performs egress, so that is where the goal became verifiable rather
than merely preserved.
Three of the four are untagged in the matrix. That is unbuilt work, not a
broken chain, and saying so here keeps the rollup from reading as an
inconsistency. The structural guarantees still hold PR-005 from the other
side; nothing about SR-004 or GR-005 changes.
jRay/SPEC.md already stated this in the past tense. The vendored copy under
jRay/scripts/vendor/jray-project is a nested checkout of this repo, so it
follows on the next vendor bump rather than needing its own edit.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
TRACES: JR-034, JR-039 | PR-005
The README asserted "GPLv3, matching the Jellyfin plugin it serves" with no
LICENSE file behind it. That answer conflicts with the architecture the same
README describes forty lines earlier, in two ways.
This repository is vendored *into* the other three, which carry three different
licences (MIT, GPL-3.0, GPL-3.0-or-later). Copyleft here pushes obligations
downstream into repositories that did not choose them, for the sake of a build
script. The dependency also runs inward, so "matching the plugin" had the
direction backwards — this repo does not serve the plugin, the plugin consumes
it. CC0 imposes nothing on any of the three.
A specification also has to be freely implementable. The design assumes third
parties reimplement it: the audio-signature conformance fixture exists so that
"an implementation can be written from that file alone", and federation is
worthless if only one server implementation may exist. A software licence on a
specification invites the question of whether an implementation written from it
is a derivative work; CC0 removes the question rather than answering it.
Same reasoning as the CC0 licence on contributed manifests (JRay-public-server
UR-019): where an artefact's whole purpose is to be copied and reimplemented,
asserting rights over it costs more than it protects.
Text from creativecommons.org, not transcribed.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Replaces the copy taken earlier with the newer version from
scene-actor-extraction's traceability-tooling branch, which had moved on: it
takes per-repo settings from a traceability.toml rather than the CLI flags
added here, validates them, and names languages ("rust") rather than making
each repo spell out extensions. That is the better design, so the flags go and
this becomes the single source.
Two fixes on top:
- Config discovery searched from the working directory only, so --root pointed
at another tree found no traceability.toml and failed with
"requirement_types is empty" while a perfectly good config sat in the
directory named. That breaks both intended callers: CI passing --root, and a
wrapper running the vendored copy. Discovery now starts from --root.
- The test suite had not been migrated with the Config refactor and failed on
the branch as well as here. All 53 now pass: entry points take a Config,
ci_executable moved to the Register which owns tier policy, fixtures write a
real traceability.toml so config discovery is exercised rather than bypassed,
and the live-register tests take LIVE_REGISTER from the environment since the
project home holds no component register of its own.
The README becomes a project overview rather than a table of contents: what the
problem is, why a paused-frame answer is the wrong question, why gallery data
never leaves the instance, and why the manifest server can hold no binary.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Commits that implement, change, or withdraw a requirement carry a TRACES
trailer using the same token and syntax as the code tags, so one grep pattern
serves both.
This is the last link. Code tags say where a requirement lives; commit trailers
say when and why it changed, and `git log --grep=AR-012` then reconstructs a
requirement's whole history — which no other artifact provides.
A commit serving no requirement omits the trailer: absence is meaningful, and
inventing a tag to satisfy the form is how orphan tags get created. Withdrawing
a requirement counts as changing it, so the withdrawal stays findable.
Also updates the chain diagram, which still referenced the retired @implements
tag and the thematic A1..E8 IDs.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Moves the extractor, its tests and the gate from scene-actor-extraction into
the project home, so all three components run one implementation rather than
each growing its own. The gate logic is unchanged; what changes is that the
two repo-specific constants become arguments.
Both were hard blockers rather than inconveniences. LOCAL_TYPES was fixed at
the extraction set, so a register using UR/DR parsed to zero requirements;
SOURCE_SUFFIXES covered C++/Python only, so a Rust or C# tree scanned zero
files. The gate correctly refuses to report coverage in either state, which is
how both surfaced. They are now --types, --suffixes and --scan-roots, with the
extraction defaults preserved: that repo runs unchanged with no flags.
traceability-gate.sh gains REPO_ROOT, REQUIREMENTS, TYPES, SUFFIXES and
SCAN_ROOTS environment overrides. Its REPO_ROOT default of SCRIPT_DIR/../..
is correct when the tooling sits in the repo it checks, but resolves to the
submodule itself once vendored, so a consuming repo must set it.
Fixes a latent bug found while testing the override: iter_source_files bound
SCAN_ROOTS as a default argument, evaluated at import, so configure_scan_roots
could never affect it.
58 tests pass. The two that read a live register now take LIVE_REGISTER from
the environment and skip without it — they asserted against AR-012/AR-027,
which belong to scene-actor-extraction rather than to a shared tool.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Gives the system specification an owner. It defines the PR-nnn project
requirements and SR-nnn cross-component contracts that every component spec
traces up to, and until now it lived in no repository at all.
The three component repositories are linked from the README and gitignored
here rather than added as submodules. A submodule pins a commit, so with
feature branches and worktrees in flight across the components, every
component commit would leave this repository's pointer stale. The dependency
is meant to run the other way: components pull this repository in for the
shared tooling and system spec, both of which change rarely.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>