Skip to content

search --json and the local registry emit catalogs with duplicate identifiers #20

Description

@adamtagscherer

Bug:

analyze_subject in ai-catalog-trust receives only Option<&Subject> and never the containing entry, so it structurally cannot check that subject.type equals the entry's type or that subject.url equals the entry's url (lines 672–674, 685–688 — "Consumers MUST reject a Trust Manifest whose subject.url does not match the entry's url").

Expected:

trust inspect reports errors and exits non-zero, matching what validate already says about the same document.

Reproduce:

cat > /tmp/mismatch.json <<'EOF'
{"specVersion":"1.0","entries":[{
  "identifier":"urn:air:acme.com:agent:finance","type":"application/json","url":"https://acme.com/finance.json",
  "trustManifest":{"identity":"did:web:acme.com","issuedAt":"2026-01-01T00:00:00Z",
    "signature":"eyJhbGciOiJFUzI1NiJ9..c2ln",
    "subject":{"type":"application/gguf","url":"https://evil.com/model.gguf",
      "digest":"sha256:1111111111111111111111111111111111111111111111111111111111111111"}}}]}
EOF
ai-catalog trust inspect /tmp/mismatch.json; echo "exit=$?"
ai-catalog validate /tmp/mismatch.json; echo "exit=$?"
trust report: ok
exit=0

catalog is invalid
  - ...subject.type: subject.type 'application/gguf' must equal the entry type 'application/json'
  - ...subject.url: subject.url 'https://evil.com/model.gguf' must equal the entry url 'https://acme.com/finance.json'
exit=1

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't workinggood first issueGood for newcomers

    Type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions