Skip to main content

AEROSIM-TS-146

Project task

Onboard the nine shortlisted aircraft models

AeroSim has three governed Trainer candidates, three governed Fighter candidates, and three governed Utility candidates available through its internal asset registry and aircraft catalogue instead of the synthetic one-triangle fixture.

AEROSIM-TS-146Canonical ID TASK-0146
Verified flow state
Done
Owner
AeroSim Architecture and Delivery
Component
Onboard nine governed aircraft model candidates
Repository
corp-v1-aerosim/corp-v1-aerosim

Delivery scope

Acquire and onboard all nine linked Sketchfab source entries: three Trainer, three Fighter, and three Utility candidates. Treat every download as untrusted: acquire into quarantine, enforce bounded extraction and safe paths, preflight content before parser invocation, and process it in an isolated network-disabled sandbox. Extend the versioned manifest schema for governed AssetManifest records, plus its TypeScript contract, policy, validator, and tests so every source, attribution obligation, runtime measurement, and verification screenshot is deterministically represented and linked. For each source, preserve the immutable source URL and acquired bytes, create a governed manifest, optimize a browser-ready GLB, assign stable model and aircraft identifiers, and make the resulting candidate available to the aircraft catalogue. When a linked source is a pack or collection, select and govern one representative aircraft from that source as the corresponding catalogue candidate; do not silently ingest unreviewed pack contents.

Implementation contract

Implementation artifacts

  • corp-v1-aerosim/corp-v1-aerosim:assets/source/
  • corp-v1-aerosim/corp-v1-aerosim:assets/manifests/
  • corp-v1-aerosim/corp-v1-aerosim:assets/runtime/
  • corp-v1-aerosim/corp-v1-aerosim:applications/web/src/aircraft/aircraft-catalogue.ts
  • corp-v1-aerosim/corp-v1-aerosim:packages/assets/src/validate-asset-registry.ts
  • corp-v1-aerosim/corp-v1-aerosim:packages/assets/src/secure-asset-intake.ts
  • corp-v1-aerosim/corp-v1-aerosim:packages/assets/src/asset-manifest.schema.json
  • corp-v1-aerosim/corp-v1-aerosim:packages/assets/src/asset-manifest.ts
  • corp-v1-aerosim/corp-v1-aerosim:packages/assets/src/asset-policy.ts
  • corp-v1-aerosim/corp-v1-aerosim:packages/assets/tests/asset-manifest.test.ts
  • corp-v1-aerosim/corp-v1-aerosim:packages/assets/tests/secure-asset-intake.test.ts

Inputs

  • Trainer — de Havilland Canada DHC-1 Chipmunk by helijah: https://sketchfab.com/3d-models/de-havilland-canada-dhc-1-chipmunk-45c3156183aa464fa0a04bf428230bdc
  • Trainer — North American T-6 Texan by helijah: https://sketchfab.com/3d-models/north-american-t-6-texan-b5298f03e97e4624a41df3482fcfe508
  • Trainer — North American T-28 Trojan by helijah: https://sketchfab.com/3d-models/north-american-t-28-trojan-aea0923d7cda48eba3a16a03eccc1bf8
  • Fighter — Fighter Jet Pack by iedalton: https://sketchfab.com/3d-models/fighter-jet-pack-c111df75444249b58d6d6e072c714abb
  • Fighter — FREE Fighter Jet Collection Low Poly by bohmerang: https://sketchfab.com/3d-models/free-fighter-jet-collection-low-poly-cb5966c988d9403895be89b364c2252f
  • Fighter — Fighter Jet by VertaScan: https://sketchfab.com/3d-models/fighter-jet-764f2b85b86c4107b077a4c207f9a9e4
  • Utility — Low Poly IPTN N219 Nurtanio by Sofyan Kurniawan: https://sketchfab.com/3d-models/low-poly-iptn-n219-nurtanio-8a8d50c261674d69ad398378f7d33722
  • Utility — Dornier Do 228 by helijah: https://sketchfab.com/3d-models/dornier-do-228-f24b42d883e744118244d29f5867bdea
  • Utility — CASA C-212 Aviocar by helijah: https://sketchfab.com/3d-models/casa-c-212-aviocar-2364de016cd34129a008c02918b667dc
  • Sketchfab API inspection on 2026-09-14 reported every linked source as downloadable under Creative Commons Attribution 4.0; acquisition must revalidate this exact asset-level state before use.

Outputs

  • Nine versioned manifest records preserve the exact registry URL, creator, material name, licence URL, attribution text, supplied copyright or licence notice, supplied disclaimer, modification statement identifying optimization as modified material, acquisition date, source hash, source format, and original bytes.
  • Nine deterministic browser-ready GLB candidates have runtime hashes plus measured byte, triangle, vertex, draw-call, texture, animation, and memory characteristics.
  • The aircraft catalogue exposes three Trainer, three Fighter, and three Utility candidates through stable identifiers and model asset references.
  • Aircraft selection and active-flight loading resolve only the governed runtime assets and never fall back to representative-aircraft.glb.

Failure boundaries

  • Reject downloads before extraction when the policy download-size limit is exceeded; abort quarantine extraction when the expanded-byte limit or file-count limit is exceeded.
  • Reject archive entries containing absolute paths, path traversal, symlink, hardlink, device, socket, FIFO, or unsupported file types; verify extensions plus content signatures before promotion.
  • Reject glTF external URI references, remote URLs, and escaping relative paths before full parser invocation; perform extraction and parsing in a time-, CPU-, memory-, and filesystem-bounded network-disabled sandbox with read-only quarantined input.
  • Reject any source whose exact asset page is no longer downloadable, does not permit commercial reuse with attribution, changes licence or creator, or cannot be preserved with immutable acquisition evidence.
  • Reject any optimized result that exceeds its approved browser budget, loses required visible geometry or materials, has an invalid pivot, scale, or orientation, or cannot load and dispose cleanly in the production WebGL path.
  • Fail release acceptance if any of the nine catalogue candidates resolves to the synthetic one-triangle fixture, an unregistered file, or a different source than its governed manifest.

Excluded scope

  • Do not acquire models outside the nine human-selected source links in this Task.
  • Do not treat a Sketchfab search result, preview image, platform-wide policy, or API label alone as sufficient licence and provenance evidence.
  • Do not self-approve the models for release or claim visual acceptance before browser inspection of each optimized candidate.

Verification steps

  • Run negative secure-intake tests with oversized downloads, archive bombs, excessive archive entries, path traversal, links and device entries, mismatched content types, glTF external URI references, parser timeout, and every configured resource limit; verify nothing is promoted from quarantine.
  • Validate the versioned manifest schema and TypeScript contract reject missing creator, licence, attribution, modification, measurement, and screenshot fields as well as unknown fields.
  • At acquisition time, read each exact source page and API record; verify downloadable state, creator, Creative Commons Attribution 4.0 terms, attribution requirements, and the acquired source-file hash.
  • Run the governed asset optimizer and validator for all nine candidates and require deterministic hashes, complete manifests, supported self-contained GLBs, and all measured budgets to pass.
  • Open Flight Setup and verify three Trainer, three Fighter, and three Utility candidates are individually identifiable and selectable without loading an unregistered asset.
  • Launch each candidate in the production browser, capture nine individually attributable recognizable-aircraft screenshots, exercise the chase camera and controls, inspect console and network failures, and verify cleanup after end flight.

Traceability

Requirements

Dependencies

Acceptance evidence

Verified delivery: application PR #193 onboarded all nine governed Trainer, Fighter, and Utility candidates with manifest-bound runtime assets, catalogue selection, and individually named visual evidence. Candidate CI runs 5138 and 5139, integration validation run 5141, and image publication run 5140 passed on the exact reviewed and integration revisions. Production rollout and authenticated deployed acceptance remain Release-owned. Release completion verified on product 1.0.0.0 at GitOps revision 5d3712d89dfbf7dacd993348e55f497d126c7bf9 with Argo Synced/Healthy, exact image digests, authenticated API/database access, and three-world configured-flight acceptance.

Current evidence boundary

No current implementation, acceptance, release, or deployment evidence is claimed for this planned Task. Any prior implementation may be used only as prototype and discovery evidence.