File size: 5,491 Bytes
518343a
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
// SparseAttentionEnvelope — typed regime claim under which a sparse plan
// is permitted. Re-expressed from MiniMax's M1→M2 reveal: hybrid-sparse
// wins benchmarks but loses multi-hop reasoning at scale, so a sparse
// regime MUST name the envelope outside which the orchestrator escalates
// to full attention.
//
// This file is dependency-free on purpose: it must be importable from a
// browser bundle, a node worker, and an edge runtime without dragging
// zod or any other validator in. A separate `@workspace/api-spec` zod
// schema mirrors these fields at the route boundary.

import type { SparseReceiptCommon } from "./receipts.js";

export type TenantClass =
  | "operator"
  | "reviewer"
  | "ledger"
  | "control-plane"
  | "tactical-edge";

export interface SparseAttentionEnvelope {
  /** Stable identifier for the regime claim — used as parentRef in downstream receipts. */
  readonly regimeId: string;
  /** Tenant class permitted to *consume* this regime. Cross-tenant use is a Sentra fail-closed event. */
  readonly tenantClass: TenantClass;
  /** Maximum number of attention blocks the sparse plan may name. */
  readonly maxBlocks: number;
  /** Maximum reasoning-hop depth the plan claims to support without escalation. */
  readonly maxHopDepth: number;
  /**
   * Minimum agreement (∈ [0,1]) between the index branch's top-k prediction
   * and the sparse branch's actual attended block-set under which the plan
   * may execute. Below this, the contradiction-probe MUST trigger escalation.
   */
  readonly minIndexAgreement: number;
  /** Block size in tokens. Treat as policy, never hardcode. */
  readonly blockSizeTokens: number;
  /** IO bandwidth budget in bytes (HBM round-trips). FlashAttention discipline. */
  readonly ioBudgetBytes: number;
  /** Validity window in seconds — outside this, the regime must be re-admitted. */
  readonly ttlSeconds: number;
  /** Freshness nonce produced at admission. */
  readonly freshnessNonce: string;
  /** ISO-8601 UTC. */
  readonly issuedAt: string;
}

export interface SparseRegimeAdmittedReceipt extends SparseReceiptCommon {
  readonly receiptClass: "sparse.regime.admitted.v1";
  readonly envelope: SparseAttentionEnvelope;
}

export interface SparseRegimeRejectedReceipt extends SparseReceiptCommon {
  readonly receiptClass: "sparse.regime.rejected.v1";
  readonly proposedEnvelope: SparseAttentionEnvelope;
  readonly violatedRule:
    | "block-size-too-large"
    | "hop-depth-too-deep"
    | "index-agreement-too-low"
    | "io-budget-negative"
    | "ttl-out-of-range"
    | "tenant-not-permitted";
  readonly explanation: string;
}

export interface AdmissionPolicy {
  readonly maxBlockSizeTokens: number;
  readonly maxHopDepth: number;
  readonly minIndexAgreement: number;
  readonly maxTtlSeconds: number;
  readonly permittedTenantClasses: ReadonlyArray<TenantClass>;
}

export interface AdmitInput {
  readonly proposed: SparseAttentionEnvelope;
  readonly policy: AdmissionPolicy;
  readonly tenant: string;
  readonly issuedAt?: string;
}

export type AdmitOutput =
  | { ok: true; receipt: SparseRegimeAdmittedReceipt }
  | { ok: false; receipt: SparseRegimeRejectedReceipt };

/**
 * Pure admission: never throws, never emits — caller writes the returned
 * receipt to the ledger. Deny-by-default; the absence of any explicit
 * permit clause is treated as a rejection.
 */
export function admit(input: AdmitInput): AdmitOutput {
  const { proposed, policy, tenant } = input;
  const issuedAt = input.issuedAt ?? new Date().toISOString();

  const rejectWith = (
    rule: SparseRegimeRejectedReceipt["violatedRule"],
    explanation: string,
  ): AdmitOutput => ({
    ok: false,
    receipt: {
      receiptClass: "sparse.regime.rejected.v1",
      freshnessNonce: proposed.freshnessNonce,
      issuedAt,
      tenant,
      proposedEnvelope: proposed,
      violatedRule: rule,
      explanation,
    },
  });

  if (!policy.permittedTenantClasses.includes(proposed.tenantClass)) {
    return rejectWith(
      "tenant-not-permitted",
      `tenant class ${proposed.tenantClass} not in permitted set [${policy.permittedTenantClasses.join(", ")}]`,
    );
  }
  if (proposed.blockSizeTokens <= 0 || proposed.blockSizeTokens > policy.maxBlockSizeTokens) {
    return rejectWith(
      "block-size-too-large",
      `blockSizeTokens=${proposed.blockSizeTokens} not in (0, ${policy.maxBlockSizeTokens}]`,
    );
  }
  if (proposed.maxHopDepth <= 0 || proposed.maxHopDepth > policy.maxHopDepth) {
    return rejectWith(
      "hop-depth-too-deep",
      `maxHopDepth=${proposed.maxHopDepth} not in (0, ${policy.maxHopDepth}]`,
    );
  }
  if (proposed.minIndexAgreement < policy.minIndexAgreement || proposed.minIndexAgreement > 1) {
    return rejectWith(
      "index-agreement-too-low",
      `minIndexAgreement=${proposed.minIndexAgreement} below policy floor ${policy.minIndexAgreement}`,
    );
  }
  if (proposed.ioBudgetBytes <= 0) {
    return rejectWith("io-budget-negative", `ioBudgetBytes must be > 0, got ${proposed.ioBudgetBytes}`);
  }
  if (proposed.ttlSeconds <= 0 || proposed.ttlSeconds > policy.maxTtlSeconds) {
    return rejectWith(
      "ttl-out-of-range",
      `ttlSeconds=${proposed.ttlSeconds} not in (0, ${policy.maxTtlSeconds}]`,
    );
  }

  return {
    ok: true,
    receipt: {
      receiptClass: "sparse.regime.admitted.v1",
      freshnessNonce: proposed.freshnessNonce,
      issuedAt,
      tenant,
      envelope: proposed,
    },
  };
}