Skip to content

feat: in-package signed Core ML variants and conversion tooling - #1646

Merged
enricopiovesan merged 4 commits into
mainfrom
claude/issue-1628-accelerator-variants
Oct 9, 2026
Merged

enricopiovesan merged 4 commits into
mainfrom
claude/issue-1628-accelerator-variants

Conversation

@enricopiovesan

@enricopiovesan enricopiovesan commented Oct 9, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

  • Schema 2.2.0 accepts optional accelerator_variants. A host fetches only the variants its adapters can use, and a tampered or missing selected file fails digest_mismatch with no fallback.
  • traverse-cli model convert-coreml writes a deterministic uncompressed Core ML model, and model add-variant records its digest and conversion provenance. model verify checks every variant in the package.

Governing Spec

  • 138-governed-exact-model-execution
  • 060-wasm-resource-limits
  • 136-native-embedder-publication
  • 062-runtime-target-matrix
  • 051-registry-extraction
  • 004-spec-alignment-gate

Project Item

What Changed

  • Contracts changed: manifest schema 2.2.0 now accepts the accelerator_variants field the contract already described.
  • Runtime behavior changed: registration validates variant shape, and selective fetch verifies only the variants the host lists in supported_adapters.
  • Compatibility impact: existing packages omit the field and keep the previous registration path. The browser validates the shape and does not fetch Core ML files.
  • ADR needed or linked: Decision 110, slice 4. The Swift adapter and device self-check remain Native accelerator adapter framework + Core ML adapter in the Swift host (Decision 110) #1629.

Definition of Done

  • A BirdNET-shaped package (birdnet-v2.4-int8) carries a signed coreml variant, and model verify accepts it.
  • Verification tests cover a tampered variant digest, a missing variant, and selective fetch skipping variants a host can't use.
  • The conversion is reproducible, and its provenance is recorded from rights.derivation.source_digest.
  • CI green.

Validation

  • Spec alignment checked locally against Spec 138 FR-058 and FR-059
  • Contract alignment checked (schema 2.2.0 already listed the field)
  • Tests updated and passing: runtime variant fetch/digest tests, CLI convert/add-variant/verify, web exact-model suite (21 pass)
  • Core coverage preserved (local coverage gate: traverse-runtime 31712/31712)
  • Required validation gates passing

Notes

BirdNET weights are not in the repo. The verify test uses a small ONNX stand-in under model id birdnet-v2.4-int8. convert-coreml packs those bytes into a specificationVersion 3 Core ML CustomModel so the same source always yields the same file. Graph lowering onto the Neural Engine and the Swift adapter are #1629.

The extra governing specs cover files this branch inherited when it merged current main (the .NET host and its CI). They are not new product scope for #1628.

enricopiovesan and others added 4 commits October 9, 2026 10:00
Schema 2.2.0 packages can carry a coreml variant whose digest and conversion provenance are covered by the manifest signature. Hosts fetch only the variants they can use, and model verify rejects a tampered or missing file.

Co-authored-by: Cursor <cursoragent@cursor.com>
The wasm-encoder 0.261 bump left the unused 0.259 package in the lockfile, and version-guard rejects that with --locked.

Co-authored-by: Cursor <cursoragent@cursor.com>
The variant error helper's success arm and a backup member whose declared size understates its bytes were the only misses keeping traverse-runtime under 100%.

Co-authored-by: Cursor <cursoragent@cursor.com>
Main already dropped the stale wasm-encoder lock entry and recorded the .NET host. Keep both changelog notes.

Co-authored-by: Cursor <cursoragent@cursor.com>
@enricopiovesan
enricopiovesan merged commit a900973 into main Oct 9, 2026
42 checks passed
@enricopiovesan
enricopiovesan deleted the claude/issue-1628-accelerator-variants branch October 9, 2026 18:19
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

In-package signed accelerator variants + Core ML conversion tooling (Decision 110)

1 participant