Skip to main content

AEROSIM-TS-37

Project task

Enforce asset provenance, format, and budgets

Automated validation admits only licensed, traceable, supported, and within-budget runtime assets.

AEROSIM-TS-37Canonical ID TASK-0037
Verified flow state
Done
Owner
AeroSim Architecture and Delivery
Component
Web Application / R3F flight scene — Shared asset pipeline — policy validator
Repository
corp-v1-aerosim/corp-v1-aerosim

Delivery scope

Validate every manifest/runtime pair: source and runtime hashes match, license and provenance are present, runtime is a self-contained GLB, and measured bytes, triangles, vertices, texture count, and maximum texture dimension do not exceed that manifest’s approved budget. Primary files: packages/assets/src/validate-asset-registry.ts, packages/assets/src/asset-policy.ts, packages/assets/tests/asset-policy.test.ts, packages/assets/scripts/validate-assets.mjs.

Implementation contract

Implementation artifacts

  • packages/assets/src/validate-asset-registry.ts
  • packages/assets/src/asset-policy.ts
  • packages/assets/tests/asset-policy.test.ts
  • packages/assets/scripts/validate-assets.mjs

Inputs

  • All files under assets/manifests and assets/runtime
  • AssetPolicy with supported schema versions, formats, licenses, and metric ceilings

Outputs

  • AssetValidationReport listing each assetId, measured metrics, and pass status
  • Non-zero validator exit with assetId, policy rule, expected limit, and observed value for each violation

Failure boundaries

  • Fail on an unregistered runtime GLB, manifest without a runtime file, stale hash, disallowed license, external URI, unsupported extension, or any exceeded budget.
  • An unreadable or partially parsed asset is a validation failure, not a skipped warning.

Excluded scope

  • Rendering performance budgets, CDN delivery, malware scanning, and legal license approval are separate controls.

Verification steps

  • pnpm --filter @aerosim/assets validate
  • pnpm --filter @aerosim/assets test -- asset-policy.test.ts; inject unlicensed, orphan, stale-hash, external-URI, and each over-budget fixture.

Traceability

Requirements

Dependencies

UI/UX applicability

non_visual

This Task owns technical or behavioral acceptance and does not claim direct visual conformance to the approved UI/UX package.

Acceptance evidence

Verified delivery: original application PR #49 merged reviewed head 2bf685a5fe1c0d92bc315f602db20acc65d8d514 as 0bb14a6de214b52b36566fff04fa1ca7e3921648; 115 asset tests and current validator/lint/typecheck passed on current integration; duplicate verification PR #126 was closed unmerged after exact-head CI run 4235 passed; current integrated publication and validation runs 4230 and 4231 passed. Release completion verified on product 1.0.0.0 at GitOps revision 5d3712d89dfbf7dacd993348e55f497d126c7bf9 with Argo Synced/Healthy, exact image digests, authenticated API/database access, and three-world configured-flight acceptance.

Current evidence boundary

No current implementation, acceptance, release, or deployment evidence is claimed for this planned Task. Any prior implementation may be used only as prototype and discovery evidence.