Skip to content

Rebuild as trust: Trust Graph CLI + protocol library (clap 4, edition 2024, tests, CI) - #11

Merged
harlantwood merged 4 commits into
masterfrom
claude/trustcraft-cli-modernize-bsuvj4
Oct 5, 2026
Merged

harlantwood merged 4 commits into
masterfrom
claude/trustcraft-cli-modernize-bsuvj4

Conversation

@harlantwood

@harlantwood harlantwood commented Oct 5, 2026 •

Copy link
Copy Markdown
Member

Summary

This replaces the 2022 "hello world" scaffold with a working implementation of the Trust Graph protocol. It's split into a reusable library (crates/trustgraph) and a thin CLI (crates/trust-cli, binary trust). The repo has never been used in production, so this is a full rewrite.

Library: trustgraph

  • TrustAtom (source, target, content, value, timestamp, extra), with validation, canonical JSON (RFC 8785), and Qm… SHA2-256 content IDs.
  • Value: an exact decimal in -1..=1, rounded to 9 significant figures. It uses the same normalization as trustgraph-holochain, whose test tables are ported here.
  • Identities: Ed25519 keys as did:key.
  • Signed atoms are W3C VC 2.0 credentials with eddsa-jcs-2022 Data Integrity proofs.
    • They reproduce the W3C spec test vectors exactly (hashes, signature, published credential).
    • Verification also checks that the issuer is the key that signed.
  • Holochain link-tag codec (Ŧ→ / Ŧ↩, NUL-separated chunks, buckets), byte-compatible with trustgraph-holochain.
    • One intentional difference: for tiny values (|v| < 0.01), the reference format runs past the documented 12-character limit, so we fall back to 9 decimal places. This was found by a property test.
  • Agent Lens / Trust Cascade: strongest-path trust with per-hop decay, a depth limit, topic filters, and distrust that is visible but not passed along. Rollups turn a lens into atoms you can sign and share.
  • Store: an append-only NDJSON file. Signed credentials are verified before they're stored.

CLI: trust

key new|list|show|export|import, atom (accepts --value 4/5, --sign), sign, verify (exit 1 if invalid), id, convert --to atom|credential|canonical|holochain, add, query, lens [--topic --depth --decay --rollup], info, completions.

Every command reads and writes JSON/NDJSON, so they compose with pipes:

trust lens --topic sushi --rollup | trust sign | trust add

Keys are stored with 0600 permissions under $TRUST_HOME (default: the platform data dir).

Housekeeping

  • Cargo workspace, edition 2024, MSRV 1.85, clap 4.6.
  • Clippy pedantic with -D warnings; unsafe is forbidden.
  • Apache-2.0 LICENSE, matching trustgraph/trustgraph and trustgraph-holochain.
  • CI: fmt, clippy, rustdoc, tests on Linux/macOS/Windows, and an MSRV job. Dependabot added.
  • README rewritten. Its Rust example runs as a doctest, so it can't go stale.

Review findings from the original code (all fixed)

  • The TODO block sat between the attributes and the struct (clippy::empty_line_after_outer_attr).
  • --count 0 exited successfully and did nothing.
  • No tests, no CI, no license.

Decisions made here (easy to revisit)

  • Value range -1..=1 (from Holochain) instead of 0..1.
  • Binary name trust.
  • Values are serialized as strings ("0.9"); numbers are accepted on input.
  • The JSON-LD context URL https://trustgraph.net/ns/v1 is provisional and still needs to be published.

Test plan

  • cargo test --workspace: 67 unit, 9 property (proptest), 12 end-to-end, 6 CLI unit, 3 doctests
  • cargo clippy --workspace --all-targets -- -D warnings (Rust 1.97 and 1.99)
  • cargo fmt --all --check, cargo doc with -D warnings
  • cargo +1.85 test --workspace --locked
  • Manual walkthrough: keys → signed atoms → store → lens → rollups → sign → verify; tamper detection; Holochain conversion
  • CI green on this PR (Linux, macOS, Windows, MSRV, lint/docs)

The README links to doc/plan/README.md, which arrives with #12.

🤖 Generated with Claude Code

https://claude.ai/code/session_01UdKneRqUnsbv1t7NyvcT68

claude added 2 commits October 5, 2026 22:14
- Upgrade clap 3.2 -> 4.6 (derive `#[command]`/`#[arg]` syntax) and
  refresh Cargo.lock.
- Move to edition 2024 with rust-version 1.85, add package metadata and
  workspace lints (clippy pedantic, forbid unsafe).
- Split into lib + thin bin so logic is unit-testable; handle broken
  pipes and write errors with proper exit codes.
- Reject `--count 0` (previously exited 0 silently printing nothing).
- Fix clippy::empty_line_after_outer_attr (TODO block sat between the
  derive attributes and the struct) and apply rustfmt.
- Add 12 unit tests and 7 end-to-end tests (assert_cmd).
- Add GitHub Actions CI (fmt, clippy, test on Linux/macOS/Windows, MSRV)
  and Dependabot for cargo and actions.
- Rewrite README with build, dev, and layout instructions.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01UdKneRqUnsbv1t7NyvcT68
Replace the placeholder greeter with a working implementation of the
Trust Graph protocol, split into a reusable library and a thin CLI.

Library (`crates/trustgraph`):
- TrustAtom (source, target, content, value, timestamp, extra) with
  validation, RFC 8785 canonical JSON, and Qm... SHA2-256 content IDs
- Value: exact decimal in -1..=1, nine significant figures, matching
  trustgraph-holochain's normalization (its test tables are ported)
- Ed25519 keys as did:key; Multikey secret/public encodings
- Signed atoms as W3C VC 2.0 with eddsa-jcs-2022 Data Integrity
  proofs, verified against the W3C spec test vectors; verification
  also checks the issuer is the signer
- Holochain link-tag codec (Ŧ→ / Ŧ↩, NUL-separated chunks, buckets)
- Agent Lens / Trust Cascade: bounded strongest-path trust with decay,
  topic filters, non-transitive distrust, and rollup atoms
- Append-only NDJSON store that verifies credentials on the way in

CLI (`crates/trust-cli`, binary `trust`):
key new|list|show|export|import, atom, sign, verify, id, convert,
add, query, lens, info, completions. JSON/NDJSON in and out so
commands compose with pipes; keys stored 0600 under $TRUST_HOME.

Also: cargo workspace, Apache-2.0 LICENSE (matching the other
trustgraph repos), CI adds rustdoc, README rewritten.

Tests: 67 unit, 9 property (proptest), 12 end-to-end, 6 CLI unit,
2 doctests. Clippy pedantic clean; MSRV 1.85 verified.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01UdKneRqUnsbv1t7NyvcT68
@harlantwood harlantwood changed the title Modernize the CLI: clap 4, edition 2024, tests, CI Rebuild as trust: Trust Graph CLI + protocol library (clap 4, edition 2024, tests, CI) Oct 5, 2026
harlantwood pushed a commit that referenced this pull request Oct 5, 2026
Mark what PR #11 delivered (atoms, did:key, VC 2.0 eddsa-jcs-2022,
Holochain tags, store, Agent Lens) and lay out the next phases:
v1 format lock, HTTPS sharing, Holochain conductor adapter, release,
UX, WASM, and hardening. TL;DR and open decisions stay at the top.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01UdKneRqUnsbv1t7NyvcT68
claude added 2 commits October 5, 2026 22:35
CI's stable toolchain (1.99) adds the `assert_is_empty` lint, which
fails the build under `-D warnings`. Use `assert_eq!` so failures show
the actual value.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01UdKneRqUnsbv1t7NyvcT68
The library example in README.md was not compiled anywhere, so it
could silently go stale. Include the README as a doctest-only item and
make the example a complete program.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01UdKneRqUnsbv1t7NyvcT68
@harlantwood
harlantwood merged commit ab62914 into master Oct 5, 2026
5 checks passed
harlantwood pushed a commit that referenced this pull request Oct 5, 2026
The project is Trust Graph; Trustcraft is not a thing. Drop the naming
decision and the trustcraft.net note, point the WASM consumer at
trustgraph.net, renumber the open decisions, and link PR #11.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01UdKneRqUnsbv1t7NyvcT68
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants