Skip to content

Optionally sign simulated mzML with mzprov - #550

Open
theGreatHerrLebert wants to merge 1 commit into
LeidelLab:devfrom
theGreatHerrLebert:sign-with-mzprov
Open

theGreatHerrLebert wants to merge 1 commit into
LeidelLab:devfrom
theGreatHerrLebert:sign-with-mzprov

Conversation

@theGreatHerrLebert

Copy link
Copy Markdown

This adds an opt-in way to mark SMITER output as simulated, using mzprov (Apache-2.0, on PyPI). mzprov signs mass spectrometry files with an Ed25519 provenance record. Simulated files are hard to tell apart from real ones once they leave the output directory, and a signature that names the simulator and its parameters makes that explicit. The same mechanism will be used for the simulators in a benchmark we are preparing, PhantomBENCH, and we would like SMITER to be able to take part on the same terms.

What changes

  • write_mzml(..., sign_with_mzprov=False): off by default, so nothing changes for existing users.
  • When enabled, sign_mzml_with_mzprov() does two things:
    • writes <stem>.smiter_params.json beside the mzML, holding the simulation parameters and the SHA-256 of molecule_summary.csv;
    • signs the mzML as "SMITER" with that file as its configuration, producing <stem>.provenance.json.
  • mzprov verify <file>.mzML then reports any later change to the spectra or to the signed parameters.
  • The dependency is optional: pip install smiter[mzprov]. mzprov supports Python 3.8–3.13 and depends only on cryptography.
  • The README features list gets one line.

Limitation

The ground truth (molecule_summary.csv) is bound only through the hash recorded in the signed parameters. mzprov verify does not re-hash the CSV itself; checking it means comparing it against that hash.

Tests

New tests in tests/test_synthetic_mzml.py:

  • a signed simulation verifies;
  • the recorded hash matches the ground truth;
  • editing the signed parameters fails verification;
  • nothing is signed unless asked.

The signing test is skipped when mzprov isn't installed.

Locally (Python 3.9, requirements.txt), tests/test_synthetic_mzml.py passes 18 of 19. test_write_peptide_gauss_mzml fails with an AttributeError, and it fails the same way on dev without this change. black (line length 88) is clean, and flake8 shows no new warnings.

Happy to adjust naming or placement to fit how you'd like this exposed.

write_mzml(..., sign_with_mzprov=True) writes an mzprov provenance sidecar
declaring the file SMITER-simulated, bound to the simulation parameters and
the SHA-256 of molecule_summary.csv. 'mzprov verify' then detects later
edits to the spectra or the parameters. Off by default; the dependency is
the optional extra smiter[mzprov].
@MKoesters

Copy link
Copy Markdown
Member

Hi, thanks for the PR, appreciate it!
I checked mzprov and it seems like a valuable and very much needed feature.

I'll need some time to test it and fix the failing test before, but I generally want to have mzprov implemented in SMITER.
I might follow up with further questions as necessary

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants