Skip to content

RFC-0008: Accept an explicit source_type, validated against the source value - #44

Merged
mprahl merged 2 commits into
mlflow:mainfrom
jwm4:optional-source-type
Sep 1, 2026
Merged

mprahl merged 2 commits into
mlflow:mainfrom
jwm4:optional-source-type

Conversation

@jwm4

@jwm4 jwm4 commented Sep 1, 2026

Copy link
Copy Markdown
Contributor

What

Amends RFC-0008 so registration, version-creation, and import requests may carry an optional explicit source_type (git/oci/zip) for external source pointers. The server validates a submitted type against the source value and rejects contradictions; when no type is submitted, the existing inference rules apply unchanged. An external pointer that can neither be validated nor inferred is rejected with a clear error instead of being misclassified. mlflow and assembled remain flow-derived and are never client-suppliable.

Why

The CLI subcommands (mlflow skills register git/oci/zip) and the SDK's typed source classes (GitSource, OCISource, ZipSource) always know the source type explicitly, but the wire format forbade sending it, so the server re-derived it from URL-shape heuristics (.git suffix, git://, oci://, .zip). Those heuristics fail on common real-world values: an HTTPS Git clone URL without the .git suffix, or an archive URL without a .zip path ending. Discarding a discriminator the client already holds and then guessing it back is strictly worse than carrying it and validating it.

The field became unsendable in #26 (see this thread) as part of a fix whose actual concern was server-controlled artifact paths for MLflow-stored content. That concern is fully preserved here: mlflow content is still flow-derived, and the server still never fetches user-supplied URLs.

Scope

Documentation-only amendment to the merged RFC (main doc summary plus the implementation-details field tables, field-inference rules, request models, SDK docstring, and CLI mapping), per the living-document approach for merged RFCs.

Authored by Bill Murdock with assistance from Claude Code.

🤖 Generated with Claude Code

…fallback

The CLI subcommands (register git/oci/zip) and SDK typed source classes
always know the source type, but the wire format forbade sending it, so
the server re-derived it from URL-shape heuristics that fail on common
values (an HTTPS Git clone URL without a .git suffix, an archive URL
without a .zip ending). Registration, version-creation, and import
requests now accept an optional source_type for external pointers; the
server validates it against the source value and rejects contradictions,
infers the type only when none is submitted, and rejects an external
pointer it can neither validate nor infer instead of misclassifying it.
mlflow and assembled remain flow-derived and are never client-supplied,
preserving the server-controlled artifact-path behavior that motivated
making the field server-set during review (PR mlflow#26,
discussion_r3698026016).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
@jwm4
jwm4 marked this pull request as ready for review September 1, 2026 18:32
With source_type explicit, the .git suffix matters only to the inference
fallback, never to fetching; make that contract explicit so validators
do not re-require the suffix, and direct users pasting provider web URLs
(/tree/ pages) to the clone URL + ref + subpath fields instead.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Comment thread rfcs/0008-mvp-skill-registry/0008-mvp-skill-registry.md
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants