Cookwala / SDK and scenarios / 091

A directory entry points at a conformance report by hash

The organization directory lists one entry, the operator of cookwala.ai, because nobody else has asked yet. Validate the entry, then hash the reference conformance report and see that the entry's conformance pointer is exactly that hash.

Audience: registry operator · Goal: Robots for people · Level: intermediate

Read first: /docs/REGISTRY/ /docs/CERTIFICATION/

Steps

  1. Validate the DirectoryEntry (catalog schema). The reference hub's validate checks the document against the schema file's root; this schema keeps its kinds under $defs, so today this call reports ok for any document, and `cookwala validate` (the CLI line) is the real check. validate

  2. Hash the reference ConformanceReport. The directory entry's conformance list holds this same value, so a reader can fetch the report and check it was not altered. hash

  3. Hash the entry itself; a registry publishes this so mirrors can be checked byte for byte. hash

Outcome

You can list an organization with a verifiable conformance pointer and know that listing is not endorsement. Next: 092 reads the report and the hub's own claim.

Command line

cookwala hash examples/conformance/report-reference.json
jq '.conformance[0]' examples/registry/directory-entry.json
cookwala validate

Recorded output

Status: ok

[1] validate: {"ok": true, "errors": []}
[2] hash: {"hash": "sha256:85da323d7ac0c25cf8ff5e7041c266c894c83382deee8b80e9fe24640985bc58"}
[3] hash: {"hash": "sha256:6ea6cd68ead9442e75283854ae596a313ca07bb810f7a9c6013fcc1b8ff9e5e1"}

Code

Run: python scenarios/out/091-directory-entry-points-at-a-report-by-hash/python.py

# Scenario 091: A directory entry points at a conformance report by hash
# The organization directory lists one entry, the operator of cookwala.ai, because nobody else has asked yet. Validate the entry, then hash the reference conformance report and see that the entry's conformance pointer is exactly that hash.
# Run a hub first: python hub/cookwala_hub.py --recipes examples
import json, os
from cookwala.client import CookwalaClient, CookwalaProblem

def load(path):
    with open(path, encoding="utf-8") as f:
        return json.load(f)

def pick(obj, path):
    for part in path.replace("]", "").replace("[", ".").split("."):
        obj = obj[int(part)] if part.isdigit() else (len(obj) if part == "length" else obj.get(part))
    return obj

c = CookwalaClient(os.environ.get("COOKWALA_HUB", "http://localhost:7878"))


# Step 1: Validate the DirectoryEntry (catalog schema). The reference hub's validate checks the document against the schema file's root; this schema keeps its kinds under $defs, so today this call reports ok for any document, and `cookwala validate` (the CLI line) is the real check.
entry = c.validate("catalog", load("examples/registry/directory-entry.json"))
assert pick(entry, "ok") == True, pick(entry, "ok")
print("ok", "ok", "=", True)

# Step 2: Hash the reference ConformanceReport. The directory entry's conformance list holds this same value, so a reader can fetch the report and check it was not altered.
report = c.hash(load("examples/conformance/report-reference.json"))
assert pick(report, "hash") == "sha256:85da323d7ac0c25cf8ff5e7041c266c894c83382deee8b80e9fe24640985bc58", pick(report, "hash")
print("ok", "hash", "=", "sha256:85da323d7ac0c25cf8ff5e7041c266c894c83382deee8b80e9fe24640985bc58")

# Step 3: Hash the entry itself; a registry publishes this so mirrors can be checked byte for byte.
entryHash = c.hash(load("examples/registry/directory-entry.json"))
assert pick(entryHash, "hash") == "sha256:6ea6cd68ead9442e75283854ae596a313ca07bb810f7a9c6013fcc1b8ff9e5e1", pick(entryHash, "hash")
print("ok", "hash", "=", "sha256:6ea6cd68ead9442e75283854ae596a313ca07bb810f7a9c6013fcc1b8ff9e5e1")

print("scenario complete")

scenarios/091-directory-entry-points-at-a-report-by-hash.json

Previous: 090 Next: 092