Skip to content

Add DKG Experiment Ledger - #30

Open
btusbefw wants to merge 1 commit into
OriginTrail:mainfrom
btusbefw:add-dkg-experiment-ledger
Open

btusbefw wants to merge 1 commit into
OriginTrail:mainfrom
btusbefw:add-dkg-experiment-ledger

Conversation

@btusbefw

Copy link
Copy Markdown

Round 1 bounty submission: cfi-dkgv10-r1.

What this PR does

Adds DKG Experiment Ledger, a CLI/library and Python notebook bridge for recording measured experiment runs in project-scoped Working Memory, comparing compatible metrics, and explicitly requesting Curator-authorized sealed SHARE through the public HTTP API. Records preserve source/data fingerprints and remain self-attested.

Integration links

Scope & faithfulness

  • Integration uses only the supported public interfaces (HTTP API, dkg CLI, MCP). It does not import internal DKG packages, patch node source, or write to SPARQL directly (bypassing the assertion lifecycle / Curator).
  • memoryLayers correctly reflects which layer(s) the integration touches.
  • v10PrimitivesUsed correctly reflects which primitives are exercised.
  • Terminology matches the v10 vocabulary (Context Graph, Sub-graph, Assertion, Knowledge Asset, Knowledge Collection, Curator, Entity, WM/SWM/VM).

Security declarations (Section 8a)

  • security.networkEgress lists every external host the integration contacts beyond the local DKG node.
  • security.writeAuthority lists every DKG write operation the integration performs. Curator-authority ops (PUBLISH, SHARE, endorse, verify) are called out explicitly if used.
  • security.credentialsHandled lists every third-party credential the installer will prompt for.
  • The published package has no preinstall / install / postinstall scripts, or the exceptions are explained in security.notes.
  • The package is published with build provenance (npm publish --provenance) when applicable.
  • The pinned git SHA is the exact commit the published package was built from.

Contributor attestation

  • This integration is my own work or properly licensed.
  • It contains no intentional backdoors, malicious logic, or data-exfiltration paths beyond what is declared in security.networkEgress.
  • I understand that the integration may be delisted for any material misrepresentation in the registry entry.
  • I commit to a minimum 6-month maintenance window post-acceptance (bounty submissions).

Notes for the committee

Maintainer: @btusbefw. I commit to at least six months of maintenance after acceptance.

Validation:

  • 13 unit tests pass; the GitHub release ran them before publishing.
  • Real DKG 10.0.16 integration tests cover write/read-back, duplicate detection, project scoping, invalid-token rejection, compatible metric comparison and sealed SHARE.
  • A persisted record retained its digest after restarting the local node.
  • A fresh npm install ran the included deterministic regression example successfully. npm audit signatures verified one registry signature and one attestation.
  • Current registry schema and package security scripts both pass with zero errors or warnings.

The walkthrough is an actual asciinema recording; its readable transcript is in the same demo directory. The lab used a mock chain and zero external peers. Public replication, on-chain publication, independent experiment verification and statistical significance are not claimed. The Python bridge consumes explicit records; it does not read notebook history. Remote DKG access is opt-in HTTPS, as explained in the entry's security notes.

Release/provenance run: https://github.com/btusbefw/dkg-experiment-ledger/actions/runs/34448960509

Please consider this in the high-quality integration tier, with a requested award of 5,000 TRAC. Please confirm the available Round 1 allocation and any remaining acceptance requirements. The intended payee is an existing French SASU; please confirm company onboarding, invoice requirements, payout network and timing. No award is assumed until agreed.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant