Repository navigation
Rebuild as trust: Trust Graph CLI + protocol library (clap 4, edition 2024, tests, CI) - #11
Merged
Merged
Conversation
- Upgrade clap 3.2 -> 4.6 (derive `#[command]`/`#[arg]` syntax) and refresh Cargo.lock. - Move to edition 2024 with rust-version 1.85, add package metadata and workspace lints (clippy pedantic, forbid unsafe). - Split into lib + thin bin so logic is unit-testable; handle broken pipes and write errors with proper exit codes. - Reject `--count 0` (previously exited 0 silently printing nothing). - Fix clippy::empty_line_after_outer_attr (TODO block sat between the derive attributes and the struct) and apply rustfmt. - Add 12 unit tests and 7 end-to-end tests (assert_cmd). - Add GitHub Actions CI (fmt, clippy, test on Linux/macOS/Windows, MSRV) and Dependabot for cargo and actions. - Rewrite README with build, dev, and layout instructions. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01UdKneRqUnsbv1t7NyvcT68
Replace the placeholder greeter with a working implementation of the Trust Graph protocol, split into a reusable library and a thin CLI. Library (`crates/trustgraph`): - TrustAtom (source, target, content, value, timestamp, extra) with validation, RFC 8785 canonical JSON, and Qm... SHA2-256 content IDs - Value: exact decimal in -1..=1, nine significant figures, matching trustgraph-holochain's normalization (its test tables are ported) - Ed25519 keys as did:key; Multikey secret/public encodings - Signed atoms as W3C VC 2.0 with eddsa-jcs-2022 Data Integrity proofs, verified against the W3C spec test vectors; verification also checks the issuer is the signer - Holochain link-tag codec (Ŧ→ / Ŧ↩, NUL-separated chunks, buckets) - Agent Lens / Trust Cascade: bounded strongest-path trust with decay, topic filters, non-transitive distrust, and rollup atoms - Append-only NDJSON store that verifies credentials on the way in CLI (`crates/trust-cli`, binary `trust`): key new|list|show|export|import, atom, sign, verify, id, convert, add, query, lens, info, completions. JSON/NDJSON in and out so commands compose with pipes; keys stored 0600 under $TRUST_HOME. Also: cargo workspace, Apache-2.0 LICENSE (matching the other trustgraph repos), CI adds rustdoc, README rewritten. Tests: 67 unit, 9 property (proptest), 12 end-to-end, 6 CLI unit, 2 doctests. Clippy pedantic clean; MSRV 1.85 verified. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01UdKneRqUnsbv1t7NyvcT68
trust: Trust Graph CLI + protocol library (clap 4, edition 2024, tests, CI)
harlantwood
pushed a commit
that referenced
this pull request
Oct 5, 2026
Mark what PR #11 delivered (atoms, did:key, VC 2.0 eddsa-jcs-2022, Holochain tags, store, Agent Lens) and lay out the next phases: v1 format lock, HTTPS sharing, Holochain conductor adapter, release, UX, WASM, and hardening. TL;DR and open decisions stay at the top. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01UdKneRqUnsbv1t7NyvcT68
1 task done
CI's stable toolchain (1.99) adds the `assert_is_empty` lint, which fails the build under `-D warnings`. Use `assert_eq!` so failures show the actual value. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01UdKneRqUnsbv1t7NyvcT68
The library example in README.md was not compiled anywhere, so it could silently go stale. Include the README as a doctest-only item and make the example a complete program. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01UdKneRqUnsbv1t7NyvcT68
harlantwood
pushed a commit
that referenced
this pull request
Oct 5, 2026
The project is Trust Graph; Trustcraft is not a thing. Drop the naming decision and the trustcraft.net note, point the WASM consumer at trustgraph.net, renumber the open decisions, and link PR #11. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01UdKneRqUnsbv1t7NyvcT68
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
This replaces the 2022 "hello world" scaffold with a working implementation of the Trust Graph protocol. It's split into a reusable library (
crates/trustgraph) and a thin CLI (crates/trust-cli, binarytrust). The repo has never been used in production, so this is a full rewrite.Library:
trustgraphsource,target,content,value,timestamp,extra), with validation, canonical JSON (RFC 8785), andQm…SHA2-256 content IDs.-1..=1, rounded to 9 significant figures. It uses the same normalization astrustgraph-holochain, whose test tables are ported here.did:key.eddsa-jcs-2022Data Integrity proofs.Ŧ→/Ŧ↩, NUL-separated chunks, buckets), byte-compatible withtrustgraph-holochain.|v| < 0.01), the reference format runs past the documented 12-character limit, so we fall back to 9 decimal places. This was found by a property test.CLI:
trustkey new|list|show|export|import,atom(accepts--value 4/5,--sign),sign,verify(exit 1 if invalid),id,convert --to atom|credential|canonical|holochain,add,query,lens [--topic --depth --decay --rollup],info,completions.Every command reads and writes JSON/NDJSON, so they compose with pipes:
Keys are stored with
0600permissions under$TRUST_HOME(default: the platform data dir).Housekeeping
-D warnings;unsafeis forbidden.trustgraph/trustgraphandtrustgraph-holochain.Review findings from the original code (all fixed)
clippy::empty_line_after_outer_attr).--count 0exited successfully and did nothing.Decisions made here (easy to revisit)
-1..=1(from Holochain) instead of0..1.trust."0.9"); numbers are accepted on input.https://trustgraph.net/ns/v1is provisional and still needs to be published.Test plan
cargo test --workspace: 67 unit, 9 property (proptest), 12 end-to-end, 6 CLI unit, 3 doctestscargo clippy --workspace --all-targets -- -D warnings(Rust 1.97 and 1.99)cargo fmt --all --check,cargo docwith-D warningscargo +1.85 test --workspace --lockedThe README links to
doc/plan/README.md, which arrives with #12.🤖 Generated with Claude Code
https://claude.ai/code/session_01UdKneRqUnsbv1t7NyvcT68