Spaces:
Running
Running
File size: 8,217 Bytes
518343a | 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131 132 133 134 135 136 137 138 139 140 141 142 143 144 145 146 147 148 149 150 151 152 153 154 155 156 157 158 159 160 161 162 163 164 165 166 167 168 169 170 171 172 173 174 175 176 177 178 179 180 181 182 183 184 185 186 187 188 189 190 191 192 193 194 195 196 197 198 199 200 201 202 203 204 205 206 207 208 209 210 211 212 213 214 215 216 217 218 219 220 221 222 223 224 225 226 227 228 229 230 231 232 233 234 235 236 237 238 239 240 241 242 243 244 245 246 247 248 249 250 251 252 253 254 | import controlsEvidenceMap from "../../../../docs/controls-evidence-map.json" with { type: "json" };
import actionContractManifest from "../../../../docs/action-contract-manifest.json" with { type: "json" };
import {
createToolEnvelope,
emitReceipt,
type EmitReceiptOptions,
type OperationalReceipt,
type ToolEnvelope,
} from "@szl-holdings/a11oy-receipt-substrate";
export type ControlClaimStatus =
| "verified-runtime"
| "release-payload"
| "lean-backed-current-green"
| "lean-backed-needs-upstream-ci"
| "thesis-anchor"
| "historical"
| "roadmap";
export interface ControlEvidenceEntry {
readonly controlId: string;
readonly title: string;
readonly description: string;
readonly claimStatus: ControlClaimStatus;
readonly evidencePaths: readonly string[];
readonly validationCommands: readonly string[];
readonly receiptHook: {
readonly eventType: string;
readonly status: "runtime-available" | "roadmap" | "staged";
readonly description: string;
};
readonly hfExposure: string;
readonly udsExposure: string;
readonly invariants: readonly string[];
}
export interface ControlEvidenceMap {
readonly schemaVersion: number;
readonly generatedBy: string;
readonly observedAt: string;
readonly canonicalRule: string;
readonly cleanRoomRule: string;
readonly controls: readonly ControlEvidenceEntry[];
}
export interface ActionContractManifest {
readonly schemaVersion: "a11oy.action-contract.v0.1";
readonly contractId: string;
readonly claimStatus: ControlClaimStatus;
readonly canonicalRule: string;
readonly cleanRoom: {
readonly sourcePatternIds: readonly string[];
readonly copyingRule: "pattern-only";
readonly endorsementBoundary: string;
};
readonly intent: {
readonly title: string;
readonly requestedAction: string;
readonly actionClass: string;
readonly vertical: string;
readonly regime: string;
readonly riskTier: string;
readonly lambdaAxes: readonly string[];
};
readonly identity: {
readonly actorId: string;
readonly actorKind: string;
readonly orgUnit: string;
readonly sessionId: string;
readonly signerVerifier: string;
};
readonly policy: {
readonly policyDocumentRef: string;
readonly policyHash: string;
readonly mandatoryAxes: readonly string[];
readonly minimumLambdaCoverage: number;
readonly approvalGate: string;
};
readonly evidence: {
readonly manifestRefs: readonly string[];
readonly attestationRefs: readonly string[];
readonly sourceCommit: string;
readonly payloadDigest: string;
readonly testCommands: readonly string[];
readonly localEvidenceRefs: readonly string[];
readonly claimRefs: readonly string[];
};
readonly receiptSinks: {
readonly primaryJsonl: string;
readonly payloadBundlePath: string;
readonly udsManifestRef: string;
readonly retentionDays: number;
readonly chainMode: "hash-chain";
};
readonly replayBounds: {
readonly deterministicInputs: readonly string[];
readonly idempotencyKey: string;
readonly maxReplays: number;
readonly replayWindowSeconds: number;
readonly seedPolicy: string;
readonly expectedRoot: string;
readonly clockRule: string;
};
readonly egressLimits: {
readonly defaultDeny: boolean;
readonly allowedDestinations: readonly string[];
readonly deniedCapabilities: readonly string[];
readonly maxBytesPerAction: number;
readonly secretHandling: string;
readonly exportClasses: readonly string[];
};
readonly udsProofPoint: {
readonly wording: string;
readonly forbiddenClaims: readonly string[];
readonly catalogGradeBlockers: readonly string[];
readonly packageInspectionCommands: readonly string[];
};
}
export interface ControlReceiptInput {
readonly controlId: string;
readonly actorId: string;
readonly sourceCommit?: string;
readonly validationCommand?: string;
readonly outcome: "pass" | "fail" | "staged";
readonly details?: Record<string, unknown>;
}
export interface ActionContractReceiptInput {
readonly actorId: string;
readonly sourceCommit?: string;
readonly payloadDigest?: string;
readonly policyHash?: string;
readonly outcome: "preflight-pass" | "preflight-fail" | "staged";
readonly details?: Record<string, unknown>;
}
const controlsMap = controlsEvidenceMap as ControlEvidenceMap;
const actionContract = actionContractManifest as ActionContractManifest;
export function getControlsEvidenceMap(): ControlEvidenceMap {
return controlsMap;
}
export function getActionContractManifest(): ActionContractManifest {
return actionContract;
}
export function getControlEvidence(controlId: string): ControlEvidenceEntry {
const control = controlsMap.controls.find((entry) => entry.controlId === controlId);
if (!control) {
throw new Error(`Unknown A11oy control: ${controlId}`);
}
return control;
}
export function createControlEvidenceEnvelope(input: ControlReceiptInput): ToolEnvelope {
const control = getControlEvidence(input.controlId);
const validationCommand = input.validationCommand ?? control.validationCommands[0];
if (!validationCommand) {
throw new Error(`Control ${control.controlId} has no validation command`);
}
return createToolEnvelope({
protocol: "a11oy",
actor_id: input.actorId,
tool_name: "a11oy_control_evidence",
lambda_axes: [
"moralGrounding",
"measurabilityHonesty",
"provenanceIntegrity",
],
payload: {
controlId: control.controlId,
title: control.title,
claimStatus: control.claimStatus,
evidencePaths: control.evidencePaths,
validationCommand,
outcome: input.outcome,
receiptHook: control.receiptHook,
hfExposure: control.hfExposure,
udsExposure: control.udsExposure,
invariants: control.invariants,
sourceCommit: input.sourceCommit ?? "unknown",
details: input.details ?? {},
},
metadata: {
manifest: "docs/controls-evidence-map.json",
cleanRoomRule: controlsMap.cleanRoomRule,
},
});
}
export function emitControlEvidenceReceipt(
input: ControlReceiptInput,
options: EmitReceiptOptions = {},
): OperationalReceipt {
return emitReceipt(createControlEvidenceEnvelope(input), {
...options,
eventType: "A11OY_OPERATION",
policy: {
vertical: "a11oy-controls",
regime: "doctrine-v6",
...options.policy,
},
});
}
export function createActionContractEnvelope(input: ActionContractReceiptInput): ToolEnvelope {
return createToolEnvelope({
protocol: "a11oy",
actor_id: input.actorId,
tool_name: "a11oy_action_contract_preflight",
lambda_axes: actionContract.intent.lambdaAxes,
payload: {
contractId: actionContract.contractId,
claimStatus: actionContract.claimStatus,
requestedAction: actionContract.intent.requestedAction,
actionClass: actionContract.intent.actionClass,
riskTier: actionContract.intent.riskTier,
approvalGate: actionContract.policy.approvalGate,
policyHash: input.policyHash ?? actionContract.policy.policyHash,
payloadDigest: input.payloadDigest ?? actionContract.evidence.payloadDigest,
sourceCommit: input.sourceCommit ?? actionContract.evidence.sourceCommit,
receiptSink: actionContract.receiptSinks.primaryJsonl,
replayBounds: actionContract.replayBounds,
egressLimits: actionContract.egressLimits,
udsProofPoint: actionContract.udsProofPoint,
outcome: input.outcome,
details: input.details ?? {},
},
metadata: {
manifest: "docs/action-contract-manifest.json",
copyingRule: actionContract.cleanRoom.copyingRule,
endorsementBoundary: actionContract.cleanRoom.endorsementBoundary,
},
});
}
export function emitActionContractReceipt(
input: ActionContractReceiptInput,
options: EmitReceiptOptions = {},
): OperationalReceipt {
return emitReceipt(createActionContractEnvelope(input), {
...options,
eventType: "A11OY_OPERATION",
policy: {
vertical: actionContract.intent.vertical,
regime: actionContract.intent.regime,
...options.policy,
},
});
}
|