Skip to content
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -22,7 +22,7 @@ and this project adheres to

### Added

- Native-first provenance backfills (Phase 2):
- Native-first provenance backfills (native SPDX backfill):
- `hasConcludedLicense` vs. `hasDeclaredLicense` separation
for detected vs. author-asserted licenses.
- Native `ExternalIdentifier` (DOI) and `ExternalRef`
Expand Down
2 changes: 1 addition & 1 deletion src/pitloom/assemble/spdx3/ai.py
Original file line number Diff line number Diff line change
Expand Up @@ -203,7 +203,7 @@ def _add_base_model_lineage(
ai_model: AiModelMetadata,
ctx: _LineageContext,
) -> None:
"""Add native Relationship (descendantOf) linking ai_pkg to its base model (N5)."""
"""Add native descendantOf Relationship linking ai_pkg to its base model."""
base_model_id = ai_model.base_model or ai_model.extra_data.get("hf.base_model")
if not base_model_id:
return
Expand Down
6 changes: 3 additions & 3 deletions src/pitloom/assemble/spdx3/fragments.py
Original file line number Diff line number Diff line change
Expand Up @@ -50,7 +50,7 @@
#: genuinely *distinct* id into the survivor ("these two different ids are the
#: same bytes"), which SPDX cannot express and which the merge would otherwise
#: discard. A same-id registry match (dropped id == survivor id) carries no such
#: fact -- its only content is the fragment origin, which belongs to the Phase-2
#: fact -- its only content is the fragment origin, which belongs to the native
#: ``SpdxDocument.imports`` native anchor, not here. Agent/Tool structural dedup
#: (every fragment mints its own "Pitloom") is likewise excluded.
_UnificationEvents = dict[str, dict[str, dict[str, set[str]]]]
Expand Down Expand Up @@ -475,7 +475,7 @@ def _merge_fragment_set(
if by_id is not None:
# Same-id (registry) match: the fragment reused an existing id, so
# nothing distinct is folded. Its only fact is the fragment origin,
# which is Phase-2 SpdxDocument.imports territory -- not annotated
# which is SpdxDocument.imports territory -- not annotated
# here (see _UnificationEvents). Properties are still merged.
_merge_properties(_as_element(by_id), _as_element(obj))
remap[obj] = require_spdx_id(_as_element(by_id))
Expand Down Expand Up @@ -598,7 +598,7 @@ def _add_fragment_imports(
fragment_imports: list[spdx3.ExternalMap],
) -> None:
"""Populate ``main_doc.import_`` with ``ExternalMap`` entries for merged
fragment documents (N1)."""
fragment documents."""
if not fragment_imports:
return
existing_imports = list(main_doc.import_ or [])
Expand Down
2 changes: 1 addition & 1 deletion src/pitloom/assemble/spdx3/provenance.py
Original file line number Diff line number Diff line change
Expand Up @@ -304,7 +304,7 @@ def build_unification_annotation(
the survivor *subject_spdx_id* (A1).

SPDX has no native home for this: the merged-away ids vanish from the graph
and ``SpdxDocument.imports`` (a Phase-2 native anchor, see the design doc)
and ``SpdxDocument.imports`` (a native anchor, see the design doc)
can only say an element came from a fragment, not the matching *criterion*.

Args:
Expand Down
3 changes: 2 additions & 1 deletion tests/test_fragments.py
Original file line number Diff line number Diff line change
Expand Up @@ -990,7 +990,8 @@ def test_unification_annotation_records_sha256_merge() -> None:

def test_merge_fragments_populates_spdx_document_imports(tmp_path: Path) -> None:
"""merge_fragments() must populate main_doc.import_ with ExternalMap
entries naming each merged fragment's SpdxDocument spdxId and location hint (N1).
entries naming each merged fragment's SpdxDocument spdxId and location hint
(fragment origin).
"""
frag_namespace = "https://spdx.org/spdxdocs/fragment-import-test"
envelope_fragment = {
Expand Down
8 changes: 5 additions & 3 deletions tests/test_generator.py
Original file line number Diff line number Diff line change
Expand Up @@ -1388,7 +1388,7 @@ def test_build_model_without_license() -> None:

def test_build_model_external_identifiers() -> None:
"""build_model() must emit ExternalIdentifier for DOI and ExternalRef for
arXiv paper IDs and model page URLs (N4).
arXiv paper IDs and model page URLs (external identifiers).
"""
model = AiModelMetadata(
format_info=AiModelFormatInfo(model_format=AiModelFormat.SAFETENSORS),
Expand Down Expand Up @@ -1440,7 +1440,8 @@ def test_build_model_external_identifiers() -> None:

def test_build_model_with_dataset_creator() -> None:
"""build_model() for a model linked to a dataset with creator metadata
must emit an Agent element and a publishedBy Relationship (N6).
must emit an Agent element and a publishedBy Relationship
(dataset creator attribution).
"""
ds_meta = DatasetMetadata(name="squad", creator="Stanford NLP")
ds_ref = DatasetReference(role="trainedOn", metadata=ds_meta)
Expand Down Expand Up @@ -1619,7 +1620,8 @@ def test_generate_deployed_sbom_mocked_pipdeptree(

def test_build_model_base_model_lineage() -> None:
"""build_model() must emit a stub base model ai_AIPackage and a descendantOf
Relationship when base_model and base_model_relation are present (N5).
Relationship when base_model and base_model_relation are present
(base-model lineage).
"""
meta = AiModelMetadata(
name="my-finetuned-model",
Expand Down
Loading