AEROSIM-TS-37
Enforce asset provenance, format, and budgets
Automated validation admits only licensed, traceable, supported, and within-budget runtime assets.
- Verified flow state
- Done
- Owner
- AeroSim Architecture and Delivery
- Feature
- AEROSIM-FT-48
- Component
- Web Application / R3F flight scene — Shared asset pipeline — policy validator
- Repository
- corp-v1-aerosim/corp-v1-aerosim
Delivery scope
Validate every manifest/runtime pair: source and runtime hashes match, license and provenance are present, runtime is a self-contained GLB, and measured bytes, triangles, vertices, texture count, and maximum texture dimension do not exceed that manifest’s approved budget. Primary files: packages/assets/src/validate-asset-registry.ts, packages/assets/src/asset-policy.ts, packages/assets/tests/asset-policy.test.ts, packages/assets/scripts/validate-assets.mjs.
Implementation contract
Implementation artifacts
- packages/assets/src/validate-asset-registry.ts
- packages/assets/src/asset-policy.ts
- packages/assets/tests/asset-policy.test.ts
- packages/assets/scripts/validate-assets.mjs
Inputs
- All files under assets/manifests and assets/runtime
- AssetPolicy with supported schema versions, formats, licenses, and metric ceilings
Outputs
- AssetValidationReport listing each assetId, measured metrics, and pass status
- Non-zero validator exit with assetId, policy rule, expected limit, and observed value for each violation
Failure boundaries
- Fail on an unregistered runtime GLB, manifest without a runtime file, stale hash, disallowed license, external URI, unsupported extension, or any exceeded budget.
- An unreadable or partially parsed asset is a validation failure, not a skipped warning.
Excluded scope
- Rendering performance budgets, CDN delivery, malware scanning, and legal license approval are separate controls.
Verification steps
- pnpm --filter @aerosim/assets validate
- pnpm --filter @aerosim/assets test -- asset-policy.test.ts; inject unlicensed, orphan, stale-hash, external-URI, and each over-budget fixture.
Traceability
Dependencies
- AEROSIM-TS-36Canonical ID: TASK-0036
UI/UX applicability
non_visual
This Task owns technical or behavioral acceptance and does not claim direct visual conformance to the approved UI/UX package.
Acceptance evidence
Verified delivery: original application PR #49 merged reviewed head 2bf685a5fe1c0d92bc315f602db20acc65d8d514 as 0bb14a6de214b52b36566fff04fa1ca7e3921648; 115 asset tests and current validator/lint/typecheck passed on current integration; duplicate verification PR #126 was closed unmerged after exact-head CI run 4235 passed; current integrated publication and validation runs 4230 and 4231 passed. Release completion verified on product 1.0.0.0 at GitOps revision 5d3712d89dfbf7dacd993348e55f497d126c7bf9 with Argo Synced/Healthy, exact image digests, authenticated API/database access, and three-world configured-flight acceptance.
Current evidence boundary
No current implementation, acceptance, release, or deployment evidence is claimed for this planned Task. Any prior implementation may be used only as prototype and discovery evidence.