onetrace 0.2.0

onetrace

onetrace makes a pipeline write a record as it runs: one receipt per stage, and a manifest that chains the receipts together. Anyone can then check the record, and compare two runs, with tools that don't trust your code.

This is onetrace 0.2.0 and onetrace-verify 0.2.0. Start with the quickstart.

What onetrace is

What onetrace is Each stage of your pipeline writes one receipt. The receipts are hash-chained in the run folder by MANIFEST.json, ending in the chain head; artifacts/ holds each stage's outputs. onetrace-verify reads the run folder and prints one row per check, each PASS, FAIL or NOT-RUN, then the result: exit 0 for PASS, 1 for FAIL, 2 for NOT VERIFIED or refused. Anchors and signatures sit beside the chain, never part of it. your pipeline stage 1 stage 2 stage 3 writes run folder receipt 1 receipt 2 receipt 3 MANIFEST.jsonthe receipts in order, ending in the chain head artifacts/: each stage's outputs onetrace-verifyreads the run folder one row per check:PASS · FAIL · NOT-RUN the resultexit 0: PASS · exit 1: FAILexit 2: NOT VERIFIED or refused anchors/timestamp over the chain head signatures/Ed25519 over the chain head optional: beside the chain, never part of it

Install and run

Install and run, in four steps Step 1, install: pip install onetrace. Step 2, decorate: @ot.run and @ot.stage. Step 3, run it: a run folder is written under runs/. Step 4, verify: onetrace-verify with the run folder. 1 · Installpip installonetrace 2 · Decorate@ot.run@ot.stage 3 · Run ita run folderunder runs/ 4 · Verifyonetrace-verify<run folder>
  1. Install: pip install onetrace. onetrace-verify, the reference verifier, comes with it.
  2. Add two decorators: @ot.run on the function that does the whole job once, and @ot.stage on each step. Change nothing else.
  3. Run it: the run writes a folder under runs/, named by its run id.
  4. Verify it: onetrace-verify --require-artifacts runs/<run id>. When a run closes, onetrace prints that command for it.

Comparing two runs

Comparing two runs onetrace diff A B calls the reference verifier on both runs first, then gives every stage one verdict: same, FIRST DIFFERENCE, downstream, reconverged or COULD NOT CHECK, and one overall result with its exit code: identical 0, diverged 1, not comparable 2, refused 3, could not check 4. localize names the first difference and its cause; diff --text shows the text that changed. run A run B onetrace diff A Bcalls the verifier on both first each stage: one verdictsame · FIRST DIFFERENCEdownstream · reconvergedCOULD NOT CHECK one result, its exit codeidentical 0 · diverged 1 · not comparable 2refused 3 · could not check 4 further localize: the first difference, and its cause diff --text: the text that changed in its outputs
The overall result of diff, and its exit code
ResultExit code
identical0
diverged1
not comparable2
refused3
could not check4

What each verdict and result means.

What it does not show

Everything onetrace does not claim.

Where next