1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
//! **What `commercial-face-arcface` gates, asserted from both sides — and what
//! it deliberately does not gate.**
//!
//! The feature governs what coremlit WIRES: the `embeddings::face::arcface`
//! manifest module, the `MODELS_LOCK` table that stages InsightFace's
//! `w600k_r50` bundle for CI, and the four gated suites in `tests/face/`. It
//! does not — and must not — govern what a caller may load.
//! [`FaceEmbedder::load`] takes a caller-supplied path and a caller-written
//! [`FaceModel`], and nothing but a digest would separate a product's own
//! commercially licensed ArcFace-shaped model from InsightFace's. That residual
//! is issue #138 §8's ("the register governs what the crate's *features* wire;
//! `Model::load` is public and any consumer can load any bytes") and is stated
//! in `tests/model_licences.rs`'s module doc.
//!
//! So this file asserts what is TRUE rather than installing a denylist, and it
//! is written to be read by whoever later reaches for one:
//!
//! - **the gate's half.** Under `commercial-face-arcface` the manifest
//! constant exists, and it is the same VALUE a caller can write by hand —
//! which is the point: only provenance, never the value, distinguishes
//! coremlit's registered manifest from anyone else's. The absent half is a
//! `compile_fail` doctest on the `embeddings::face` module page, attached
//! only when the feature is OFF, because absence is a resolution failure
//! and no runtime assertion can see it.
//! - **the door's half.** Under plain `face`,
//! `FaceModel::new("data", "embedding", 512)` is constructible and this
//! door accepts it, refusing a wrong artifact on the CONTRACT and never on
//! the identity of its bytes. **That is deliberate, and this test exists so
//! it cannot be "fixed" into a denylist by accident.** Refusing this
//! manifest, or these bytes by digest, would be (1) policy enforcement on
//! bytes, which issue #138 §8's stated residual already places outside this
//! library, (2) bypassed by calling `coremlit::Model::load` directly, and
//! (3) a contradiction of this door's founding principle that a manifest is
//! a value — a caller with a commercially licensed ArcFace model of their
//! own must be able to write its manifest and load it under plain `face`.
//!
//! Hermetic, and NOT `#[ignore]`d: the one bundle loaded here is
//! `Models/vadkit/silero-vad-unified-256ms-v6.2.1.mlmodelc`, 1.1 MiB of
//! committed bytes staged by no download.
// The workspace-root anchor `Models/` is resolved against. FOUND by searching
// upward for the `[workspace]` manifest rather than counted in `../` hops — see
// its module doc.
use ;
/// The manifest for InsightFace's `w600k_r50`, spelled out here exactly as a
/// caller of the plain `face` feature has to spell it.
///
/// Hand-written on purpose. Importing `arcface::MODEL` would make this file
/// need the gated feature and would prove nothing about what a caller without
/// it can do.
const CALLER_WRITTEN: FaceModel = new;
/// **A caller can write this artifact's manifest under plain `face`.**
///
/// The deliberate assertion. `FaceModel::new` is `const` and total, so the
/// value exists whatever feature set is on; what this pins is that it stays
/// that way — a later refusal keyed on these strings and this width would be a
/// denylist over a caller's own property, and it would red here.
/// **The door refuses a wrong artifact on its CONTRACT, never on the identity
/// of its bytes.**
///
/// Driven with the hand-written manifest above over the committed silero
/// bundle, so it runs with no download: silero declares `audio_input`, not
/// `data`, and the refusal must name that missing feature. A refusal on any
/// other ground — a digest, a path, a bundle name — would be this door judging
/// bytes the caller supplied, which is exactly what issue #138 §8's residual
/// says this library does not do.
/// **Under `commercial-face-arcface` the manifest module exists, and it is that
/// same value.**
///
/// The other side of the two-sided claim; the absent side is the `compile_fail`
/// doctest on the `embeddings::face` module page, which exists only when this
/// feature is off. What the equality says is the whole reason the register is a
/// claim about WIRING and not about bytes: coremlit's registered manifest is
/// not a privileged value, it is the same four fields any caller can write, and
/// what the feature adds is the staging, the tests and the licence row behind
/// them.