[{"data":1,"prerenderedAt":909},["ShallowReactive",2],{"navigation":3,"\u002Fguides\u002Ftrust-and-security":222,"\u002Fguides\u002Ftrust-and-security-surround":904},[4,8,168,206,210,214,218],{"title":5,"path":6,"stem":7},"Quickstart","\u002Fquickstart","01.quickstart",{"title":9,"path":10,"stem":11,"children":12},"Concepts","\u002Fconcepts","20.concepts",[13,15,19,23,84,88,92,96,100],{"title":9,"path":10,"stem":14},"20.concepts\u002Findex",{"title":16,"path":17,"stem":18},"Preprocessing Graph","\u002Fconcepts\u002Fppg","20.concepts\u002F2.ppg",{"title":20,"path":21,"stem":22},"Plane decomposition","\u002Fconcepts\u002Fplanes","20.concepts\u002F3.planes",{"title":24,"path":25,"stem":26,"children":27},"Codecs","\u002Fconcepts\u002Fcodecs","20.concepts\u002F4.codecs",[28,32,36,40,44,48,52,56,60,64,68,72,76,80],{"title":29,"path":30,"stem":31},"Arithmetic","\u002Fconcepts\u002Fcodecs\u002Farithmetic","20.concepts\u002Fcodecs\u002Farithmetic",{"title":33,"path":34,"stem":35},"Context Mixing Lite","\u002Fconcepts\u002Fcodecs\u002Fcontext-mixing-lite","20.concepts\u002Fcodecs\u002Fcontext-mixing-lite",{"title":37,"path":38,"stem":39},"FPC","\u002Fconcepts\u002Fcodecs\u002Ffpc","20.concepts\u002Fcodecs\u002Ffpc",{"title":41,"path":42,"stem":43},"Huffman LLM 5-Bit","\u002Fconcepts\u002Fcodecs\u002Fhuff-llm","20.concepts\u002Fcodecs\u002Fhuff-llm",{"title":45,"path":46,"stem":47},"Huffman","\u002Fconcepts\u002Fcodecs\u002Fhuffman","20.concepts\u002Fcodecs\u002Fhuffman",{"title":49,"path":50,"stem":51},"Identity","\u002Fconcepts\u002Fcodecs\u002Fidentity","20.concepts\u002Fcodecs\u002Fidentity",{"title":53,"path":54,"stem":55},"Neural Predictor","\u002Fconcepts\u002Fcodecs\u002Fneural-predictor","20.concepts\u002Fcodecs\u002Fneural-predictor",{"title":57,"path":58,"stem":59},"Order-1 Arithmetic","\u002Fconcepts\u002Fcodecs\u002Forder1-arithmetic","20.concepts\u002Fcodecs\u002Forder1-arithmetic",{"title":61,"path":62,"stem":63},"Order-1 Scale AC","\u002Fconcepts\u002Fcodecs\u002Forder1-scale-ac","20.concepts\u002Fcodecs\u002Forder1-scale-ac",{"title":65,"path":66,"stem":67},"Per-Group Codebook","\u002Fconcepts\u002Fcodecs\u002Fper-group-codebook","20.concepts\u002Fcodecs\u002Fper-group-codebook",{"title":69,"path":70,"stem":71},"rANS","\u002Fconcepts\u002Fcodecs\u002Frans","20.concepts\u002Fcodecs\u002Frans",{"title":73,"path":74,"stem":75},"tANS","\u002Fconcepts\u002Fcodecs\u002Ftans","20.concepts\u002Fcodecs\u002Ftans",{"title":77,"path":78,"stem":79},"Zstd","\u002Fconcepts\u002Fcodecs\u002Fzstd","20.concepts\u002Fcodecs\u002Fzstd",{"title":81,"path":82,"stem":83},"Zstd Dictionary","\u002Fconcepts\u002Fcodecs\u002Fzstd-dict","20.concepts\u002Fcodecs\u002Fzstd-dict",{"title":85,"path":86,"stem":87},"Container format","\u002Fconcepts\u002Fcontainer","20.concepts\u002F5.container",{"title":89,"path":90,"stem":91},"Delta compression","\u002Fconcepts\u002Fdelta","20.concepts\u002F6.delta",{"title":93,"path":94,"stem":95},"Extensibility","\u002Fconcepts\u002Fextensibility","20.concepts\u002F7.extensibility",{"title":24,"path":25,"stem":97,"children":98},"20.concepts\u002Fcodecs\u002Findex",[99],{"title":24,"path":25,"stem":97},{"title":101,"path":102,"stem":103,"children":104},"Transforms","\u002Fconcepts\u002Ftransforms","20.concepts\u002Ftransforms\u002Findex",[105,106,110,114,118,122,126,130,134,140,144,148,152,156,160,164],{"title":101,"path":102,"stem":103},{"title":107,"path":108,"stem":109},"Alpha-Stable Normalize","\u002Fconcepts\u002Ftransforms\u002Falpha-stable-normalize","20.concepts\u002Ftransforms\u002Falpha-stable-normalize",{"title":111,"path":112,"stem":113},"Bit Reorder","\u002Fconcepts\u002Ftransforms\u002Fbit-reorder","20.concepts\u002Ftransforms\u002Fbit-reorder",{"title":115,"path":116,"stem":117},"Block Microscaling Repack","\u002Fconcepts\u002Ftransforms\u002Fblock-microscaling-repack","20.concepts\u002Ftransforms\u002Fblock-microscaling-repack",{"title":119,"path":120,"stem":121},"Burrows-Wheeler","\u002Fconcepts\u002Ftransforms\u002Fburrows-wheeler","20.concepts\u002Ftransforms\u002Fburrows-wheeler",{"title":123,"path":124,"stem":125},"Byte Split & Nibble Split","\u002Fconcepts\u002Ftransforms\u002Fbyte-split","20.concepts\u002Ftransforms\u002Fbyte-split",{"title":127,"path":128,"stem":129},"Concat","\u002Fconcepts\u002Ftransforms\u002Fconcat","20.concepts\u002Ftransforms\u002Fconcat",{"title":131,"path":132,"stem":133},"Delta","\u002Fconcepts\u002Ftransforms\u002Fdelta","20.concepts\u002Ftransforms\u002Fdelta",{"title":135,"path":136,"stem":137,"children":138},"Index Bitwidth Pack","\u002Fconcepts\u002Ftransforms\u002Findex-bitwidth-pack","20.concepts\u002Ftransforms\u002Findex-bitwidth-pack",[139],{"title":135,"path":136,"stem":137},{"title":141,"path":142,"stem":143},"IntDelta","\u002Fconcepts\u002Ftransforms\u002Fint-delta","20.concepts\u002Ftransforms\u002Fint-delta",{"title":145,"path":146,"stem":147},"Mantissa Zero Strip","\u002Fconcepts\u002Ftransforms\u002Fmantissa-zero-strip","20.concepts\u002Ftransforms\u002Fmantissa-zero-strip",{"title":149,"path":150,"stem":151},"Move to Front","\u002Fconcepts\u002Ftransforms\u002Fmove-to-front","20.concepts\u002Ftransforms\u002Fmove-to-front",{"title":153,"path":154,"stem":155},"MxFp4 Deinterleave","\u002Fconcepts\u002Ftransforms\u002Fmxfp4-deinterleave","20.concepts\u002Ftransforms\u002Fmxfp4-deinterleave",{"title":157,"path":158,"stem":159},"Predictor XOR","\u002Fconcepts\u002Ftransforms\u002Fpredictor-xor","20.concepts\u002Ftransforms\u002Fpredictor-xor",{"title":161,"path":162,"stem":163},"Reshape","\u002Fconcepts\u002Ftransforms\u002Freshape","20.concepts\u002Ftransforms\u002Freshape",{"title":165,"path":166,"stem":167},"Spherical Normalize","\u002Fconcepts\u002Ftransforms\u002Fspherical-normalize","20.concepts\u002Ftransforms\u002Fspherical-normalize",{"title":169,"path":170,"stem":171,"children":172},"Guides","\u002Fguides","30.guides\u002F00.index",[173,174,178,182,186,190,194,198,202],{"title":169,"path":170,"stem":171},{"title":175,"path":176,"stem":177},"CLI usage","\u002Fguides\u002Fcli","30.guides\u002F01.cli",{"title":179,"path":180,"stem":181},"Python API","\u002Fguides\u002Fpython-api","30.guides\u002F02.python-api",{"title":183,"path":184,"stem":185},"Writing your first extension","\u002Fguides\u002Fextension-authoring","30.guides\u002F03.extension-authoring",{"title":187,"path":188,"stem":189},"Trust and security","\u002Fguides\u002Ftrust-and-security","30.guides\u002F04.trust-and-security",{"title":191,"path":192,"stem":193},"Random access","\u002Fguides\u002Frandom-access","30.guides\u002F10.random-access",{"title":195,"path":196,"stem":197},"Tuning","\u002Fguides\u002Ftuning","30.guides\u002F11.tuning",{"title":199,"path":200,"stem":201},"Safetensors","\u002Fguides\u002Fsafetensors","30.guides\u002F50.safetensors",{"title":203,"path":204,"stem":205},"Transformers","\u002Fguides\u002Ftransformers","30.guides\u002F51.transformers",{"title":207,"path":208,"stem":209},"API reference","\u002Fapi","40.api",{"title":211,"path":212,"stem":213},"Benchmarks","\u002Fbenchmarks","50.benchmarks",{"title":215,"path":216,"stem":217},"Extensions","\u002Fextensions","60.extensions",{"title":219,"path":220,"stem":221},"Contributing","\u002Fcontributing","90.contributing",{"id":223,"title":187,"body":224,"description":898,"extension":899,"kind":900,"language":900,"links":900,"meta":901,"navigation":900,"path":188,"seo":902,"stem":189,"summary":900,"__hash__":903},"docs\u002F30.guides\u002F04.trust-and-security.md",{"type":225,"value":226,"toc":888},"minimark",[227,231,236,239,269,280,288,304,310,314,321,358,373,377,380,493,500,504,529,707,718,725,732,765,783,794,798,807,827,836,840,874,884],[228,229,230],"p",{},"PTWM refuses to load an extension unless its signature chains to a key\nthe user has explicitly trusted. This page covers the trust state\nmachine, the policy controls, and the threat model.",[232,233,235],"h2",{"id":234},"the-bundled-then-pinned-model","The bundled-then-pinned model",[228,237,238],{},"On a fresh install, PTWM ships with no trusted keys at all. Running:",[240,241,246],"pre",{"className":242,"code":243,"language":244,"meta":245,"style":245},"language-sh shiki shiki-themes material-theme-lighter github-light github-dark","ptwm trust add --bundled\n","sh","",[247,248,249],"code",{"__ignoreMap":245},[250,251,254,258,262,265],"span",{"class":252,"line":253},"line",1,[250,255,257],{"class":256},"sbgvK","ptwm",[250,259,261],{"class":260},"s_sjI"," trust",[250,263,264],{"class":260}," add",[250,266,268],{"class":267},"stzsN"," --bundled\n",[228,270,271,272,275,276,279],{},"imports the curated bundled keyring (a snapshot of \"official\"\ncontribution authors) and pins its blake3 hash to\n",[247,273,274],{},"$XDG_CONFIG_HOME\u002Fptwm\u002Ftrust\u002Fbundled.lock",". From that moment on,\nopening a ",[247,277,278],{},".ptwm"," file referencing one of those contributions\nsucceeds.",[228,281,282,283,287],{},"If a subsequent PTWM upgrade ships a ",[284,285,286],"em",{},"different"," bundled keyring — a\nnew author added, a compromised key revoked — the on-disk lock no\nlonger matches. The reader treats the bundled keyring as inactive\nuntil the user explicitly accepts the new state:",[240,289,291],{"className":242,"code":290,"language":244,"meta":245,"style":245},"ptwm trust update --bundled\n",[247,292,293],{"__ignoreMap":245},[250,294,295,297,299,302],{"class":252,"line":253},[250,296,257],{"class":256},[250,298,261],{"class":260},[250,300,301],{"class":260}," update",[250,303,268],{"class":267},[228,305,306,309],{},[247,307,308],{},"update --bundled"," shows you the diff (added \u002F removed keys) before\napplying it. This means a PTWM upgrade can't silently grant a new\npublisher the ability to ship code into your loader — that step always\nrequires consent.",[232,311,313],{"id":312},"three-kinds-of-trust-entry","Three kinds of trust entry",[228,315,316,317,320],{},"Per ",[247,318,319],{},"ptwm trust list",", your keyring may hold:",[322,323,324,334,342],"ul",{},[325,326,327,333],"li",{},[328,329,330],"strong",{},[247,331,332],{},"author_key"," — trust everything signed by this Ed25519 public\nkey. The most common entry. Use for \"I trust everything this\nauthor ships\".",[325,335,336,341],{},[328,337,338],{},[247,339,340],{},"contribution_hash"," — pin trust to a single canonical id (a\nspecific contribution at a specific version). Use for one-off\napprovals where you don't want a key to grant transitive trust.",[325,343,344,349,350,353,354,357],{},[328,345,346],{},[247,347,348],{},"key_with_capability_constraints"," — trust this author ",[284,351,352],{},"only","\nfor contributions whose declared capabilities are a subset of an\nallowed list. Use for \"trust author X but only their pure codecs,\nnot anything that declares ",[247,355,356],{},"host_imports","\".",[228,359,360,361,364,365,368,369,372],{},"Add entries with ",[247,362,363],{},"ptwm trust add","; remove with ",[247,366,367],{},"ptwm trust remove \u003Cidentifier>","; inspect with ",[247,370,371],{},"ptwm trust show",".",[232,374,376],{"id":375},"capabilities","Capabilities",[228,378,379],{},"Every contribution declares its requirements in a capability map\nthat's signed alongside the manifest. The v1 baseline keys:",[381,382,383,396],"table",{},[384,385,386],"thead",{},[387,388,389,393],"tr",{},[390,391,392],"th",{},"Key",[390,394,395],{},"Meaning",[397,398,399,410,424,433,455,473,483],"tbody",{},[387,400,401,407],{},[402,403,404],"td",{},[247,405,406],{},"determinism",[402,408,409],{},"Promises byte-identical output across runs \u002F flavors.",[387,411,412,417],{},[402,413,414],{},[247,415,416],{},"native_deps",[402,418,419,420,423],{},"Lists ",[247,421,422],{},"\u003Clibrary>=\u003Cversion-constraint>"," requirements.",[387,425,426,430],{},[402,427,428],{},[247,429,356],{},[402,431,432],{},"WASM host functions the module needs imported.",[387,434,435,440],{},[402,436,437],{},[247,438,439],{},"hardware_class",[402,441,442,445,446,445,449,445,452,372],{},[247,443,444],{},"cpu"," \u002F ",[247,447,448],{},"cuda",[247,450,451],{},"rocm",[247,453,454],{},"mps",[387,456,457,462],{},[402,458,459],{},[247,460,461],{},"sandbox_class",[402,463,464,445,467,445,470,372],{},[247,465,466],{},"pure_decode",[247,468,469],{},"read_only_filesystem",[247,471,472],{},"network",[387,474,475,480],{},[402,476,477],{},[247,478,479],{},"mem_factor",[402,481,482],{},"Multiplier for the default 256 MiB WASM memory budget.",[387,484,485,490],{},[402,486,487],{},[247,488,489],{},"fuel_factor",[402,491,492],{},"Multiplier for the default 100M fuel budget.",[228,494,495,496,499],{},"A capability the host doesn't know is ",[328,497,498],{},"denied"," at verify time, not\nsilently accepted. This means a future PTWM upgrade introducing a new\ncapability key can't be exploited by replaying an old extension that\ndeclared the new key — the contribution authors must re-sign.",[232,501,503],{"id":502},"policy-files","Policy files",[228,505,506,507,510,511,520,521,528],{},"Capabilities + canonical IDs feed into the policy file that\n",[247,508,509],{},"ptwm bench compress --variant"," consumes. The TOML schema is the one\nparsed by ",[512,513,517],"a",{"href":514,"rel":515},"https:\u002F\u002Fgithub.com\u002Fkhwstolle\u002Fptwm\u002Fblob\u002Fmaster\u002Fcrates\u002Fptwm-core\u002Fsrc\u002Fpolicy\u002Ffile.rs",[516],"nofollow",[247,518,519],{},"PolicyFile::from_toml","\nand resolved against the active keyring by\n",[512,522,525],{"href":523,"rel":524},"https:\u002F\u002Fgithub.com\u002Fkhwstolle\u002Fptwm\u002Fblob\u002Fmaster\u002Fcrates\u002Fptwm-core\u002Fsrc\u002Fpolicy\u002Fresolve.rs",[516],[247,526,527],{},"ResolvedPolicy",".\nExample:",[240,530,534],{"className":531,"code":532,"language":533,"meta":245,"style":245},"language-toml shiki shiki-themes material-theme-lighter github-light github-dark","[allow]\nextra = [\n    \"blake3:5c3a4cd0c46825ae6dbb471459e63347ea6e1d62c8a0dbfdf5d532a124525f09\",\n]\n\n[ignore]\nextensions = [\n    \"blake3:da39a3ee5e6b4b0d3255bfef95601890afd80709…\",\n]\n\n[per_role.scale]\ndeny = [\"blake3:\u003Ccanonical-id>\"]\n\n[capabilities]\nallow_host_imports = []   # WASM modules with host_imports declared → rejected\ndeny_native_deps_unverified = true\n","toml",[247,535,536,548,561,577,582,589,599,609,621,626,631,646,666,671,680,695],{"__ignoreMap":245},[250,537,538,542,545],{"class":252,"line":253},[250,539,541],{"class":540},"sP7_E","[",[250,543,544],{"class":256},"allow",[250,546,547],{"class":540},"]\n",[250,549,551,555,558],{"class":252,"line":550},2,[250,552,554],{"class":553},"su5hD","extra ",[250,556,557],{"class":540},"=",[250,559,560],{"class":540}," [\n",[250,562,564,568,571,574],{"class":252,"line":563},3,[250,565,567],{"class":566},"sjJ54","    \"",[250,569,570],{"class":260},"blake3:5c3a4cd0c46825ae6dbb471459e63347ea6e1d62c8a0dbfdf5d532a124525f09",[250,572,573],{"class":566},"\"",[250,575,576],{"class":540},",\n",[250,578,580],{"class":252,"line":579},4,[250,581,547],{"class":540},[250,583,585],{"class":252,"line":584},5,[250,586,588],{"emptyLinePlaceholder":587},true,"\n",[250,590,592,594,597],{"class":252,"line":591},6,[250,593,541],{"class":540},[250,595,596],{"class":256},"ignore",[250,598,547],{"class":540},[250,600,602,605,607],{"class":252,"line":601},7,[250,603,604],{"class":553},"extensions ",[250,606,557],{"class":540},[250,608,560],{"class":540},[250,610,612,614,617,619],{"class":252,"line":611},8,[250,613,567],{"class":566},[250,615,616],{"class":260},"blake3:da39a3ee5e6b4b0d3255bfef95601890afd80709…",[250,618,573],{"class":566},[250,620,576],{"class":540},[250,622,624],{"class":252,"line":623},9,[250,625,547],{"class":540},[250,627,629],{"class":252,"line":628},10,[250,630,588],{"emptyLinePlaceholder":587},[250,632,634,636,639,641,644],{"class":252,"line":633},11,[250,635,541],{"class":540},[250,637,638],{"class":256},"per_role",[250,640,372],{"class":553},[250,642,643],{"class":256},"scale",[250,645,547],{"class":540},[250,647,649,652,654,657,659,662,664],{"class":252,"line":648},12,[250,650,651],{"class":553},"deny ",[250,653,557],{"class":540},[250,655,656],{"class":540}," [",[250,658,573],{"class":566},[250,660,661],{"class":260},"blake3:\u003Ccanonical-id>",[250,663,573],{"class":566},[250,665,547],{"class":540},[250,667,669],{"class":252,"line":668},13,[250,670,588],{"emptyLinePlaceholder":587},[250,672,674,676,678],{"class":252,"line":673},14,[250,675,541],{"class":540},[250,677,375],{"class":256},[250,679,547],{"class":540},[250,681,683,686,688,691],{"class":252,"line":682},15,[250,684,685],{"class":553},"allow_host_imports ",[250,687,557],{"class":540},[250,689,690],{"class":540}," []",[250,692,694],{"class":693},"sutJx","   # WASM modules with host_imports declared → rejected\n",[250,696,698,701,703],{"class":252,"line":697},16,[250,699,700],{"class":553},"deny_native_deps_unverified ",[250,702,557],{"class":540},[250,704,706],{"class":705},"syTEX"," true\n",[228,708,709,710,713,714,717],{},"The resolved policy enters the encoder via\n",[247,711,712],{},"CompressionConfig.from_resolved_policy(rp)"," and constrains the\ndispatcher's trial-encode menu per-plane. An empty intersection (the\npolicy excludes every codec a plane can use) is a hard ",[247,715,716],{},"InvalidContainer","\nerror — silent identity fallback would falsify ablation numbers.",[232,719,721,724],{"id":720},"contributionuntrusted-at-decode",[247,722,723],{},"ContributionUntrusted"," at decode",[228,726,727,728,731],{},"When ",[247,729,730],{},"ContainerReader::open"," encounters an extension-table entry\nreferring to a non-builtin canonical id, it:",[733,734,735,746,753,760],"ol",{},[325,736,737,738,741,742,745],{},"Looks up the matching installed bundle on disk\n(",[247,739,740],{},"$PTWM_EXTENSION_PATH"," or ",[247,743,744],{},"$XDG_DATA_HOME\u002Fptwm\u002Fextensions\u002F",").",[325,747,748,749,752],{},"Recomputes ",[247,750,751],{},"blake3(manifest ‖ binaries)"," from the on-disk files.",[325,754,755,756,759],{},"Verifies the bundle's ",[247,757,758],{},"signature.bin"," against the author key from\nthe manifest.",[325,761,762,763,745],{},"Confirms the author key is in the active keyring (or that the\ncanonical id is pinned via ",[247,764,340],{},[228,766,767,768,770,771,774,775,778,779,782],{},"Failure at any step surfaces as a ",[247,769,723],{}," error with a\nspecific reason. The reader does ",[328,772,773],{},"not"," silently downgrade; tampered\nbinaries fail loudly. (Verified by the\n",[247,776,777],{},"open_verifies_signed_bundle_end_to_end"," test in\n",[247,780,781],{},"crates\u002Fptwm-core\u002Fsrc\u002Fcontainer.rs",".)",[228,784,785,786,789,790,793],{},"If you genuinely want to inspect a container that references an\nuntrusted extension (e.g. listing tensor names without executing\ncodec code), pass ",[247,787,788],{},"skip_missing=True"," to ",[247,791,792],{},"Decompressor",". Decoding any\ntensor that needs the untrusted extension still fails.",[232,795,797],{"id":796},"threat-model-in-two-paragraphs","Threat model in two paragraphs",[228,799,800,803,804,806],{},[328,801,802],{},"Assets:"," the user's signing keys, the on-disk extensions directory\n(",[247,805,744],{},"), and the integrity of decompressed\ntensor bytes flowing into a training\u002Finference loop.",[228,808,809,812,813,816,817,819,820,819,823,826],{},[328,810,811],{},"Mitigations:"," WASM extensions execute in a Wasmtime sandbox with no\nhost imports granted by default, finite fuel, finite memory, and no\nfilesystem or network access. Native cdylib extensions have no\nsandbox — their security boundary is the signing key, which is why\nthe verifier always checks the on-disk binary hash, not just the\nheader signature. The trust state is ",[328,814,815],{},"never updated silently",":\nevery change requires an explicit ",[247,818,363],{},"\u002F",[247,821,822],{},"update",[247,824,825],{},"remove","\ninvocation. The bundled keyring is treated as untrusted on hash\nmismatch, so a malicious PTWM upgrade can't graft new publishers\ninto your loader.",[228,828,829,832,833,835],{},[328,830,831],{},"Out of scope:"," confidentiality of compressed weights (use\nfilesystem-level encryption), denial-of-service via deliberately slow\nextensions (use ",[247,834,489],{}," to bound), and side-channel attacks\nagainst the signing key (use a hardware token).",[232,837,839],{"id":838},"recommended-workflow","Recommended workflow",[228,841,842,843,846,847,850,851,854,855,858,859,862,863,866,867,870,871,357],{},"For ",[284,844,845],{},"researchers",": keep ",[247,848,849],{},"ptwm trust add --bundled"," plus a single\nlocal ",[247,852,853],{},"--key"," for your own development. Re-sign on every commit; the\nv1 CLI doesn't ship a ",[247,856,857],{},"gen-key"," subcommand, so generate the 32-byte\nraw seed yourself (",[247,860,861],{},"openssl rand 32 > key.priv",") and re-feed it to\n",[247,864,865],{},"ptwm ext sign --key key.priv",". Key rotation is \"generate a new\nseed, add the new public key with ",[247,868,869],{},"ptwm trust add --key",", then\nremove the old entry with ",[247,872,873],{},"ptwm trust remove \u003Clabel>",[228,875,842,876,879,880,883],{},[284,877,878],{},"operators"," shipping models with custom codecs: don't ship the\nprivate key with the model. Sign at release time, distribute the\npublic key out-of-band (e.g. in the model card), and let downstream\nusers explicitly ",[247,881,882],{},"ptwm trust add --key …",". The bundled keyring\nupdate flow makes this audit-trail-friendly.",[885,886,887],"style",{},"html pre.shiki code .sbgvK, html code.shiki .sbgvK{--shiki-light:#E2931D;--shiki-default:#6F42C1;--shiki-dark:#B392F0}html pre.shiki code .s_sjI, html code.shiki .s_sjI{--shiki-light:#91B859;--shiki-default:#032F62;--shiki-dark:#9ECBFF}html pre.shiki code .stzsN, html code.shiki .stzsN{--shiki-light:#91B859;--shiki-default:#005CC5;--shiki-dark:#79B8FF}html .light .shiki span {color: var(--shiki-light);background: var(--shiki-light-bg);font-style: var(--shiki-light-font-style);font-weight: var(--shiki-light-font-weight);text-decoration: var(--shiki-light-text-decoration);}html.light .shiki span {color: var(--shiki-light);background: var(--shiki-light-bg);font-style: var(--shiki-light-font-style);font-weight: var(--shiki-light-font-weight);text-decoration: var(--shiki-light-text-decoration);}html .default .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .dark .shiki span {color: var(--shiki-dark);background: var(--shiki-dark-bg);font-style: var(--shiki-dark-font-style);font-weight: var(--shiki-dark-font-weight);text-decoration: var(--shiki-dark-text-decoration);}html.dark .shiki span {color: var(--shiki-dark);background: var(--shiki-dark-bg);font-style: var(--shiki-dark-font-style);font-weight: var(--shiki-dark-font-weight);text-decoration: var(--shiki-dark-text-decoration);}html pre.shiki code .sP7_E, html code.shiki .sP7_E{--shiki-light:#39ADB5;--shiki-default:#24292E;--shiki-dark:#E1E4E8}html pre.shiki code .su5hD, html code.shiki .su5hD{--shiki-light:#90A4AE;--shiki-default:#24292E;--shiki-dark:#E1E4E8}html pre.shiki code .sjJ54, html code.shiki .sjJ54{--shiki-light:#39ADB5;--shiki-default:#032F62;--shiki-dark:#9ECBFF}html pre.shiki code .sutJx, html code.shiki .sutJx{--shiki-light:#90A4AE;--shiki-light-font-style:italic;--shiki-default:#6A737D;--shiki-default-font-style:inherit;--shiki-dark:#6A737D;--shiki-dark-font-style:inherit}html pre.shiki code .syTEX, html code.shiki .syTEX{--shiki-light:#FF5370;--shiki-default:#005CC5;--shiki-dark:#79B8FF}",{"title":245,"searchDepth":563,"depth":563,"links":889},[890,891,892,893,894,896,897],{"id":234,"depth":550,"text":235},{"id":312,"depth":550,"text":313},{"id":375,"depth":550,"text":376},{"id":502,"depth":550,"text":503},{"id":720,"depth":550,"text":895},"ContributionUntrusted at decode",{"id":796,"depth":550,"text":797},{"id":838,"depth":550,"text":839},"How PTWM decides whether to load an extension — keyring, capabilities, and the threat model.","md",null,{},{"title":187,"description":898},"oHd_P_oAZbN4kKvIBZ-fHMXM6PsXEDGEYApmKvtbSXk",[905,907],{"title":183,"path":184,"stem":185,"description":906,"children":-1},"Step-by-step walkthrough from `ptwm ext init` to a signed, installed plane codec.",{"title":191,"path":192,"stem":193,"description":908,"children":-1},"Open a `.ptwm` bundle and fetch individual tensors without decompressing the whole file.",1784796353819]