Bug:
analyze_subject in ai-catalog-trust receives only Option<&Subject> and never the containing entry, so it structurally cannot check that subject.type equals the entry's type or that subject.url equals the entry's url (lines 672–674, 685–688 — "Consumers MUST reject a Trust Manifest whose subject.url does not match the entry's url").
Expected:
trust inspect reports errors and exits non-zero, matching what validate already says about the same document.
Reproduce:
cat > /tmp/mismatch.json <<'EOF'
{"specVersion":"1.0","entries":[{
"identifier":"urn:air:acme.com:agent:finance","type":"application/json","url":"https://acme.com/finance.json",
"trustManifest":{"identity":"did:web:acme.com","issuedAt":"2026-01-01T00:00:00Z",
"signature":"eyJhbGciOiJFUzI1NiJ9..c2ln",
"subject":{"type":"application/gguf","url":"https://evil.com/model.gguf",
"digest":"sha256:1111111111111111111111111111111111111111111111111111111111111111"}}}]}
EOF
ai-catalog trust inspect /tmp/mismatch.json; echo "exit=$?"
ai-catalog validate /tmp/mismatch.json; echo "exit=$?"
trust report: ok
exit=0
catalog is invalid
- ...subject.type: subject.type 'application/gguf' must equal the entry type 'application/json'
- ...subject.url: subject.url 'https://evil.com/model.gguf' must equal the entry url 'https://acme.com/finance.json'
exit=1
Bug:
analyze_subjectinai-catalog-trustreceives onlyOption<&Subject>and never the containing entry, so it structurally cannot check thatsubject.typeequals the entry'stypeor thatsubject.urlequals the entry's url (lines 672–674, 685–688 — "Consumers MUST reject a Trust Manifest whose subject.url does not match the entry's url").Expected:
trust inspectreports errors and exits non-zero, matching whatvalidatealready says about the same document.Reproduce: