docs(architecture): audit Provenance records group against implementation - #4798
docs(architecture): audit Provenance records group against implementation#4798ggbdpq wants to merge 2 commits into
Conversation
…tion Audit docs/code-origin-audit.md from the apache#3522 documentation audit against the current implementation (22715e8). Every re-checkable claim holds: the baseline and bootstrap commits resolve; the LICENSE registrations for the AI SDK packages, Astryx, trycua/cua, opencode, and models.dev are present; model-protocol.ts carries the Apache modification notice; tool-output.ts and edit-replace.ts state their opencode adaptation; the spot-checked "absent from current main" entries are indeed absent; the generated model-metadata file is untracked as described. No drift found, so the only change is the standard frontmatter with last_verified. Refs apache#3522 Generated-by: GLM-5.3-Flash (ZCode)
ea82e17 to
b67cf4e
Compare
Astro-Han
left a comment
There was a problem hiding this comment.
Reviewed current head b67cf4ed69d031758c8a6bbc4f15bd4a1b27be9b (OPEN). The actual diff is 12 lines of frontmatter in docs/code-origin-audit.md — no implementation changes. No P0–P3 or simplification findings.
Verified against the current checkout: provenance snapshot authority, generated outputs, runtime-host one-shot in-memory refresh, privacy/proxy credential gates, history anchors, LICENSE/source notices, absent-marked paths, and source-only metadata. Host and WebFetch share the same outbound policy/transport boundary. The doc's own bootstrap confirmations remain explicitly open items, as stated.
Evidence: exact-head hosted test green; local ASF header check and git diff --check pass; ASF/source-legal/models.dev sync/upkeep tests 69/69. What I could not judge: npm run format:check was not run locally (no node_modules in the checkout; the hosted docs-only planner skips that step).
Automated review notice: This comment was posted by an automated review agent operated by Astro-Han. It is not an independent human review and does not replace one.
简体中文
本条结论全部来自 @未开智选手 的审查。我自己没有读这份 diff;我核的是当前 head 有没有漂移。当前 head 是 b67cf4e,未关闭。实际改动只有 12 行元信息,无新增实现,无可定级问题。
Summary
Audits the Provenance records group (1 document) from #3522:
docs/code-origin-audit.md, against the current implementation (22715e8).Every re-checkable claim holds on the current tree:
15184428…) and the initial commit (8fd91a43…) both resolve;LICENSEregistrations named by the report are present:@ai-sdk/provider-utils,@ai-sdk/provider, Astryx (two fixed revisions),trycua/cua, opencode, and models.dev;packages/runtime/src/model-protocol.tscarries the Apache-2.0 modification notice the report says was added;packages/runtime/src/tool-output.tsandedit-replace.tsstate their opencode adaptation in their headers;models.devsnapshot authority chain is intact (scripts/model-metadata/models-dev-api.snapshot.jsoncommitted;packages/core/src/model-metadata.generated.tsuntracked, as the report describes);main" are indeed absent;No drift found, so the only change is the standard frontmatter with
last_verified. The report's own open items (bootstrap contributor confirmation, the human legal/ASF determination) are recorded as pending by the document itself and are not changed by this audit.Verification
git cat-file -t <sha>(both)commitLICENSEfor the six named sourcesmodel-protocol.ts/tool-output.ts/edit-replace.tsgit ls-files packages/core/src/model-metadata.generated.tsnpm run format:check/npm run check:asf-headersAI use
Prepared with ZCode (GLM-5.3-Flash): the agent read the report, re-verified each current-state claim against the tree, and added the frontmatter. The commit carries the
Generated-bytrailer.Checklist
Refs #3522in the commit messagelast_verifiedset to the audit date (2026-09-04)