betterwithage Claude Opus 4.7 commited on
Commit
332e1b6
·
verified ·
1 Parent(s): 403d567

deploy(hf): sync szl-holdings/a11oy@9adabb6a301ee28c8023587e7a48768504449539 derived COPY set

Browse files

Reusable Dockerfile-COPY-derived deploy from szl-holdings/a11oy 9adabb6a301ee28c8023587e7a48768504449539.
Files: 1211 Pruned: 0
Derived from Dockerfile COPY sources (NO hand-maintained allowlist).

Signed-off-by: SZL Holdings <noreply@szlholdings.ai>
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>

a11oy_landing.html CHANGED
@@ -396,6 +396,7 @@
396
  <button type="button" class="menu-toggle" id="menu-toggle" aria-label="Open menu" aria-controls="site-nav" aria-expanded="false">☰</button>
397
  <nav class="nav-links" id="site-nav">
398
  <a class="hide-sm" href="#surfaces">Surfaces</a>
 
399
  <a class="hide-sm" href="/ecosystem">Ecosystem</a>
400
  <a class="hide-sm" href="/anatomy-v5">Anatomy v5</a>
401
  <a class="hide-sm" href="#proof">The proof</a>
@@ -425,7 +426,7 @@
425
  <b>BLOCKED</b> instead of a confident guess.</p>
426
  <div class="cta-row">
427
  <a class="btn btn-primary" href="/console">Open the command center →</a>
428
- <a class="btn btn-lattice" href="/ecosystem">Explore the ecosystem</a>
429
  <a class="btn btn-ghost" href="/verify">Verify a receipt offline</a>
430
  </div>
431
  <div class="hero-stats">
@@ -498,7 +499,7 @@
498
  <a class="card surface-card" href="/console#mesh"><div class="ic">◇</div><h3>Mesh</h3><p>The BFT-quorum mesh graph — 3-of-4 consensus, live state read from <span class="mono">/api/a11oy/v1/mesh/state</span>.</p><div class="golinks"><span class="go">Open the mesh →</span></div></a>
499
  <a class="card surface-card" href="/formulas"><div class="ic">Σ</div><h3>Formulas</h3><p>The PURIQ agentic formula genome — live-recomputed values, each carrying its own Khipu receipt.</p><div class="golinks"><span class="go">Open /formulas →</span></div></a>
500
  <a class="card surface-card" href="/trust"><div class="ic">✓</div><h3>Evidence</h3><p>The trust center: the locked-8 with truthful Lean refs, Theorem&nbsp;U vs Conjecture&nbsp;1, the receipt ledger, offline verify.</p><div class="golinks"><span class="go">Open the evidence →</span></div></a>
501
- <a class="card surface-card" href="/static/viz/router/"><div class="ic mono">⇄</div><h3>LLM Router</h3><p>STALE NOT_MEASURED · snapshot 2026-07-11. Router health is not live, not healthy, and not MEASURED.</p><div class="golinks"><span class="go">Open the router →</span></div></a>
502
  </div>
503
  </section>
504
 
@@ -751,7 +752,8 @@
751
  <a href="/verify">Verify a receipt</a>
752
  <a href="/living-anatomy">Living anatomy · 3D</a>
753
  <a href="/elite">killinchu · counter-UAS</a>
754
- <a href="https://szlholdings-immune.hf.space" target="_blank" rel="noopener">IMMUNE · live investor demo</a></div>
 
755
  <div class="lk"><strong style="color:var(--ink)">Evidence</strong>
756
  <a href="/trust">Trust center</a>
757
  <a href="/api/a11oy/v1/ledger">Receipt ledger</a>
 
396
  <button type="button" class="menu-toggle" id="menu-toggle" aria-label="Open menu" aria-controls="site-nav" aria-expanded="false">☰</button>
397
  <nav class="nav-links" id="site-nav">
398
  <a class="hide-sm" href="#surfaces">Surfaces</a>
399
+ <a class="hide-sm" href="/immune">IMMUNE</a>
400
  <a class="hide-sm" href="/ecosystem">Ecosystem</a>
401
  <a class="hide-sm" href="/anatomy-v5">Anatomy v5</a>
402
  <a class="hide-sm" href="#proof">The proof</a>
 
426
  <b>BLOCKED</b> instead of a confident guess.</p>
427
  <div class="cta-row">
428
  <a class="btn btn-primary" href="/console">Open the command center →</a>
429
+ <a class="btn btn-lattice" href="/immune">Open IMMUNE</a>
430
  <a class="btn btn-ghost" href="/verify">Verify a receipt offline</a>
431
  </div>
432
  <div class="hero-stats">
 
499
  <a class="card surface-card" href="/console#mesh"><div class="ic">◇</div><h3>Mesh</h3><p>The BFT-quorum mesh graph — 3-of-4 consensus, live state read from <span class="mono">/api/a11oy/v1/mesh/state</span>.</p><div class="golinks"><span class="go">Open the mesh →</span></div></a>
500
  <a class="card surface-card" href="/formulas"><div class="ic">Σ</div><h3>Formulas</h3><p>The PURIQ agentic formula genome — live-recomputed values, each carrying its own Khipu receipt.</p><div class="golinks"><span class="go">Open /formulas →</span></div></a>
501
  <a class="card surface-card" href="/trust"><div class="ic">✓</div><h3>Evidence</h3><p>The trust center: the locked-8 with truthful Lean refs, Theorem&nbsp;U vs Conjecture&nbsp;1, the receipt ledger, offline verify.</p><div class="golinks"><span class="go">Open the evidence →</span></div></a>
502
+ <a class="card surface-card" href="/immune"><div class="ic">⬡</div><h3>IMMUNE</h3><p>Fail-closed Hukulla kernel (Channel A) plus Field lattice (Channel B): exile, mesh, quorum, delta. Hunt / isolate / deceive — never strike people. Same-origin tab. Never fabricates LIVE or PASS.</p><div class="golinks"><span class="go">Open /immune →</span></div></a>
503
  </div>
504
  </section>
505
 
 
752
  <a href="/verify">Verify a receipt</a>
753
  <a href="/living-anatomy">Living anatomy · 3D</a>
754
  <a href="/elite">killinchu · counter-UAS</a>
755
+ <a href="/immune">IMMUNE · Hukulla + live kernel</a>
756
+ <a href="https://szlholdings-immune.hf.space" target="_blank" rel="noopener">IMMUNE kernel Space</a></div>
757
  <div class="lk"><strong style="color:var(--ink)">Evidence</strong>
758
  <a href="/trust">Trust center</a>
759
  <a href="/api/a11oy/v1/ledger">Receipt ledger</a>
a11oy_nav_wireup.py CHANGED
@@ -63,6 +63,7 @@ _SURFACES = [
63
  ("/cockpit", "\u2318", "Command Cockpit"), # ⌘
64
  ("/sovereign", "\u26D3", "Sovereign Ledger"), # khipu health+spend
65
  ("/nemo", "\u25C6", "SZL-Nemo"), # ◆
 
66
  ("/autoreview", "\u2713", "Auto-Review (Governed Autonomy)"), # ✓
67
  ("/factory", "\u2699", "Governed Factory"), # ⚙
68
  ("/constitution", "\u00A7", "Constitution"), # §
@@ -91,6 +92,7 @@ _SURFACE_GROUP_OF = {
91
  "/cockpit": "Sovereign & Agentic Core",
92
  "/sovereign": "Sovereign & Agentic Core",
93
  "/nemo": "Sovereign & Agentic Core",
 
94
  "/autoreview": "Sovereign & Agentic Core",
95
  "/factory": "Sovereign & Agentic Core",
96
  "/constitution": "Sovereign & Agentic Core",
@@ -209,7 +211,7 @@ _REL_MARKER = b'data-related-surfaces="qa10"'
209
  # Flagship surfaces that get the cross-link strip. /restraint-bench (the REAL
210
  # Restraint page) is used, not /restraint (generic shell fallthrough).
211
  _FLAGSHIP_PATHS = {
212
- "/nemo", "/autoreview", "/factory", "/constitution",
213
  "/energy", "/agent-loop", "/quant", "/grc", "/restraint-bench",
214
  "/code", "/fleet-c2", "/living-anatomy",
215
  }
@@ -220,6 +222,7 @@ def _build_related_strip(current_path: str) -> bytes:
220
  other. Inline-styled (0 CDN). Honest labels; the current page is omitted."""
221
  rel = [
222
  ("/nemo", "SZL-Nemo"),
 
223
  ("/autoreview", "Auto-Review"),
224
  ("/factory", "Factory"),
225
  ("/constitution", "Constitution"),
@@ -558,6 +561,7 @@ if __name__ == "__main__":
558
  assert n2.count('data-related-surfaces="qa10"') == 1, "related strip must be idempotent"
559
  assert "Auto-Review" in n1 and "/autoreview" in n1, "strip must cross-link surfaces"
560
  assert "/restraint-bench" in n1, "strip must cross-link the real Restraint page"
 
561
  assert "/nemo" not in n1.split('data-related-surfaces="qa10"')[1].split("</nav>")[0], \
562
  "related strip must omit the current page (/nemo)"
563
  assert n1 == n2, "second nemo render must be byte-identical"
 
63
  ("/cockpit", "\u2318", "Command Cockpit"), # ⌘
64
  ("/sovereign", "\u26D3", "Sovereign Ledger"), # khipu health+spend
65
  ("/nemo", "\u25C6", "SZL-Nemo"), # ◆
66
+ ("/immune", "\u2B21", "IMMUNE"), # ⬡
67
  ("/autoreview", "\u2713", "Auto-Review (Governed Autonomy)"), # ✓
68
  ("/factory", "\u2699", "Governed Factory"), # ⚙
69
  ("/constitution", "\u00A7", "Constitution"), # §
 
92
  "/cockpit": "Sovereign & Agentic Core",
93
  "/sovereign": "Sovereign & Agentic Core",
94
  "/nemo": "Sovereign & Agentic Core",
95
+ "/immune": "Sovereign & Agentic Core",
96
  "/autoreview": "Sovereign & Agentic Core",
97
  "/factory": "Sovereign & Agentic Core",
98
  "/constitution": "Sovereign & Agentic Core",
 
211
  # Flagship surfaces that get the cross-link strip. /restraint-bench (the REAL
212
  # Restraint page) is used, not /restraint (generic shell fallthrough).
213
  _FLAGSHIP_PATHS = {
214
+ "/nemo", "/immune", "/autoreview", "/factory", "/constitution",
215
  "/energy", "/agent-loop", "/quant", "/grc", "/restraint-bench",
216
  "/code", "/fleet-c2", "/living-anatomy",
217
  }
 
222
  other. Inline-styled (0 CDN). Honest labels; the current page is omitted."""
223
  rel = [
224
  ("/nemo", "SZL-Nemo"),
225
+ ("/immune", "IMMUNE"),
226
  ("/autoreview", "Auto-Review"),
227
  ("/factory", "Factory"),
228
  ("/constitution", "Constitution"),
 
561
  assert n2.count('data-related-surfaces="qa10"') == 1, "related strip must be idempotent"
562
  assert "Auto-Review" in n1 and "/autoreview" in n1, "strip must cross-link surfaces"
563
  assert "/restraint-bench" in n1, "strip must cross-link the real Restraint page"
564
+ assert "/immune" in n1, "strip must cross-link the IMMUNE tab"
565
  assert "/nemo" not in n1.split('data-related-surfaces="qa10"')[1].split("</nav>")[0], \
566
  "related strip must omit the current page (/nemo)"
567
  assert n1 == n2, "second nemo render must be byte-identical"
serve.py CHANGED
@@ -4020,8 +4020,8 @@ try:
4020
  # /api/a11oy/v1/immune/verdict and shows the REAL deny/allow + signals + signed
4021
  # Khipu receipt digest. Title "Immune (Hukulla) — fail-closed egress gate". NEVER a
4022
  # codename. Replaces the prior 200 SPA shell that read nothing real.
4023
- app.add_api_route("/immune", _ptg_serve("immune.html"), methods=["GET"], include_in_schema=False)
4024
- app.add_api_route("/a11oy/immune", _ptg_serve("immune.html"), methods=["GET"], include_in_schema=False)
4025
  # MATERIALS (Q'allariy) tab (2026-06-16): the honest, user-visible Verifiable
4026
  # Alloy & Crystal Discovery surface. Standalone sovereign page (0 runtime CDN),
4027
  # binds to live /api/a11oy/v1/materials/* — a crystal-novelty form that POSTs to
 
4020
  # /api/a11oy/v1/immune/verdict and shows the REAL deny/allow + signals + signed
4021
  # Khipu receipt digest. Title "Immune (Hukulla) — fail-closed egress gate". NEVER a
4022
  # codename. Replaces the prior 200 SPA shell that read nothing real.
4023
+ app.add_api_route("/immune", _ptg_serve("immune.html"), methods=["GET", "HEAD"], include_in_schema=False)
4024
+ app.add_api_route("/a11oy/immune", _ptg_serve("immune.html"), methods=["GET", "HEAD"], include_in_schema=False)
4025
  # MATERIALS (Q'allariy) tab (2026-06-16): the honest, user-visible Verifiable
4026
  # Alloy & Crystal Discovery surface. Standalone sovereign page (0 runtime CDN),
4027
  # binds to live /api/a11oy/v1/materials/* — a crystal-novelty form that POSTs to
szl_immune.py CHANGED
@@ -30,6 +30,16 @@ ENDPOINTS (dual-registered under /api/a11oy/v1/immune/* AND /v1/immune/*):
30
  real feed; resets on restart — empty = IDLE, never faked).
31
  GET /threats -> the threats_full STIX/MITRE corpus.
32
  GET /verify -> re-walk the immune Khipu chain (judge-verifiable integrity).
 
 
 
 
 
 
 
 
 
 
33
 
34
  INSPECTION LOGIC (byte-identical to serve.py's embedded immune block):
35
  _THREAT_SIGNATURES = ["DROP TABLE","rm -rf","<script","eval(","subprocess","../../etc"]
@@ -53,9 +63,12 @@ import collections
53
  import datetime
54
  import hashlib
55
  import json
 
56
  import secrets
57
  import threading
58
  import time
 
 
59
  from typing import Any, Optional
60
 
61
  from fastapi import Request
@@ -84,6 +97,24 @@ _LEAN_PROOFS = [
84
  _LOCKED_PROVEN = ["F1", "F4", "F7", "F11", "F12", "F18", "F19", "F22"] # EXACTLY 8 @ c7c0ba17
85
  _KERNEL_COMMIT = "c7c0ba17"
86
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
87
  # ---------------------------------------------------------------------------
88
  # REAL inspection logic — byte-identical to serve.py's embedded immune block.
89
  # ---------------------------------------------------------------------------
@@ -382,6 +413,157 @@ def _verify_chain() -> dict:
382
  }
383
 
384
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
385
  # ---------------------------------------------------------------------------
386
  # Registration — dual-register under /api/{ns}/v1/immune/* AND /v1/immune/*.
387
  # Mirrors szl_kverify's add_api_route pattern. Registered BEFORE the SPA catch-
@@ -425,6 +607,12 @@ def register(app, ns: str = "a11oy") -> dict:
425
  async def _h_verify(): # noqa: ANN202
426
  return JSONResponse(_verify_chain())
427
 
 
 
 
 
 
 
428
  prefixes = [f"/api/{ns}/v1/immune", "/v1/immune"]
429
  routes: list[str] = []
430
  for p in prefixes:
@@ -435,8 +623,10 @@ def register(app, ns: str = "a11oy") -> dict:
435
  app.add_api_route(f"{p}/feed", _h_feed, methods=["GET"], include_in_schema=True)
436
  app.add_api_route(f"{p}/verdict", _h_verdict, methods=["POST", "GET"], include_in_schema=True)
437
  app.add_api_route(f"{p}/verify", _h_verify, methods=["GET"], include_in_schema=True)
 
 
438
  routes.extend([f"{p}/healthz", f"{p}/status", f"{p}/gates", f"{p}/threats",
439
- f"{p}/feed", f"{p}/verdict", f"{p}/verify"])
440
 
441
  print(f"[{ns}] szl_immune routes registered "
442
  f"(Immune (Hukulla) fail-closed egress gate, {len(routes)} routes)", flush=True)
 
30
  real feed; resets on restart — empty = IDLE, never faked).
31
  GET /threats -> the threats_full STIX/MITRE corpus.
32
  GET /verify -> re-walk the immune Khipu chain (judge-verifiable integrity).
33
+ GET /kernel -> same-origin probe of the public IMMUNE kernel Space
34
+ (SZLHOLDINGS/immune /readyz). REACHABLE vs UNAVAILABLE only;
35
+ never fabricates LIVE or PASS. write_ready is forwarded
36
+ verbatim when the probe succeeds.
37
+ GET /field -> same-origin probe of Channel B Field catalog
38
+ (SZLHOLDINGS/immune-lattice /api/field). RANGE cells
39
+ compiled as hunt/isolate/deceive — never strike people.
40
+ REACHABLE vs UNAVAILABLE only; never LIVE or PASS.
41
+ Actuation is SIMULATED. This flagship does not become a
42
+ second COP.
43
 
44
  INSPECTION LOGIC (byte-identical to serve.py's embedded immune block):
45
  _THREAT_SIGNATURES = ["DROP TABLE","rm -rf","<script","eval(","subprocess","../../etc"]
 
63
  import datetime
64
  import hashlib
65
  import json
66
+ import os
67
  import secrets
68
  import threading
69
  import time
70
+ import urllib.error
71
+ import urllib.request
72
  from typing import Any, Optional
73
 
74
  from fastapi import Request
 
97
  _LOCKED_PROVEN = ["F1", "F4", "F7", "F11", "F12", "F18", "F19", "F22"] # EXACTLY 8 @ c7c0ba17
98
  _KERNEL_COMMIT = "c7c0ba17"
99
 
100
+ # Public kernel Space (Channel A). Browser CSP is connect-src 'self', so this
101
+ # page cannot fetch hf.space directly — the product tab probes same-origin.
102
+ # Channel B (immune-lattice) is the COP overlay sibling; its /readyz is intercepted
103
+ # by the HF proxy (502 HTML). Do not treat that 502 as kernel death.
104
+ _KERNEL_SPACE_URL = os.environ.get(
105
+ "IMMUNE_KERNEL_BASE", "https://szlholdings-immune.hf.space"
106
+ ).rstrip("/")
107
+ _KERNEL_LATTICE_URL = os.environ.get(
108
+ "IMMUNE_LATTICE_BASE", "https://szlholdings-immune-lattice.hf.space"
109
+ ).rstrip("/")
110
+ _KERNEL_TIMEOUT = float(os.environ.get("IMMUNE_KERNEL_TIMEOUT", "8"))
111
+ _KERNEL_CACHE_TTL = float(os.environ.get("IMMUNE_KERNEL_CACHE_TTL", "8"))
112
+ _KERNEL_UA = (
113
+ "Mozilla/5.0 (compatible; a11oy-immune-kernel-probe/1.0; +https://a-11-oy.com/immune)"
114
+ )
115
+ _KERNEL_CACHE: dict[str, Any] = {"at": 0.0, "payload": None}
116
+ _FIELD_CACHE: dict[str, Any] = {"at": 0.0, "payload": None}
117
+
118
  # ---------------------------------------------------------------------------
119
  # REAL inspection logic — byte-identical to serve.py's embedded immune block.
120
  # ---------------------------------------------------------------------------
 
413
  }
414
 
415
 
416
+ def _probe_json(url: str) -> tuple[Optional[int], Any, Optional[str]]:
417
+ """Public read-only GET. Fail closed: never invent a JSON body."""
418
+ req = urllib.request.Request(
419
+ url,
420
+ headers={"Accept": "application/json", "User-Agent": _KERNEL_UA},
421
+ method="GET",
422
+ )
423
+ try:
424
+ with urllib.request.urlopen(req, timeout=_KERNEL_TIMEOUT) as resp: # nosec - public read-only
425
+ raw = resp.read(65536)
426
+ status = int(getattr(resp, "status", 200) or 200)
427
+ text = raw.decode("utf-8", "replace").strip()
428
+ if not text:
429
+ return status, None, "empty body"
430
+ try:
431
+ return status, json.loads(text), None
432
+ except json.JSONDecodeError:
433
+ return status, None, "upstream non-JSON"
434
+ except urllib.error.HTTPError as exc:
435
+ return int(exc.code), None, "HTTP " + str(exc.code)
436
+ except Exception as exc: # noqa: BLE001 — honest UNAVAILABLE, never crash the organ
437
+ return None, None, type(exc).__name__
438
+
439
+
440
+ def _kernel(now: Optional[float] = None, probe=_probe_json) -> dict:
441
+ """Same-origin kernel probe. REACHABLE / UNAVAILABLE only — never LIVE or PASS."""
442
+ ts = time.time() if now is None else float(now)
443
+ cached = _KERNEL_CACHE.get("payload")
444
+ cached_at = float(_KERNEL_CACHE.get("at") or 0)
445
+ if cached and (ts - cached_at) < _KERNEL_CACHE_TTL:
446
+ out = dict(cached)
447
+ out["cached"] = True
448
+ return out
449
+
450
+ status, data, err = probe(_KERNEL_SPACE_URL + "/readyz")
451
+ body = data if isinstance(data, dict) else {}
452
+ write_ready = body.get("write_ready") if isinstance(body.get("write_ready"), bool) else None
453
+ authority = body.get("authority")
454
+ if isinstance(authority, dict):
455
+ key_id = authority.get("keyId") or authority.get("key_id") or authority.get("kid")
456
+ evidence_state = authority.get("evidenceState") or authority.get("evidence_state")
457
+ else:
458
+ key_id = body.get("keyId") or body.get("key_id") or body.get("kid")
459
+ evidence_state = body.get("evidenceState") or body.get("evidence_state")
460
+ authority = authority if authority is not None else evidence_state
461
+ ledger = body.get("receiptCount")
462
+ if ledger is None:
463
+ ledger = body.get("ledger")
464
+ reachable = status == 200 and isinstance(data, dict)
465
+ payload = {
466
+ "ok": reachable,
467
+ "reachability": "REACHABLE" if reachable else "UNAVAILABLE",
468
+ "write_ready": write_ready if reachable else None,
469
+ "authority": authority if reachable else None,
470
+ "evidence_state": evidence_state if reachable else None,
471
+ "key_id": key_id if reachable else None,
472
+ "ledger": ledger if reachable else None,
473
+ "blockers": body.get("blockers") if reachable else None,
474
+ "upstream_status": body.get("status") if reachable else None,
475
+ "upstream_http": status,
476
+ "error": None if reachable else (err or "kernel unobserved"),
477
+ "channel_a": {
478
+ "space": "SZLHOLDINGS/immune",
479
+ "url": _KERNEL_SPACE_URL,
480
+ "contract": "/readyz",
481
+ },
482
+ "channel_b": {
483
+ "space": "SZLHOLDINGS/immune-lattice",
484
+ "url": _KERNEL_LATTICE_URL,
485
+ "contract": "/api/field",
486
+ "note": "COP overlay sibling (Field cells). HF proxy intercepts /readyz; a 502 HTML there is not kernel death.",
487
+ },
488
+ "product_tab": "/immune",
489
+ "honesty": {
490
+ "lambda": "Conjecture 1 (NOT a theorem)",
491
+ "never_fabricate": ["LIVE", "PASS"],
492
+ "first_paint": "CONNECTING",
493
+ "failed_probe": "UNAVAILABLE",
494
+ "write_ready_true": "REACHABLE (not LIVE)",
495
+ },
496
+ "organ": _ORGAN_NAME,
497
+ "cached": False,
498
+ }
499
+ enveloped = _gov(payload, status="REAL" if reachable else "DEGRADED")
500
+ _KERNEL_CACHE["at"] = ts
501
+ _KERNEL_CACHE["payload"] = enveloped
502
+ return enveloped
503
+
504
+
505
+ def _field(now: Optional[float] = None, probe=_probe_json) -> dict:
506
+ """Same-origin Channel B Field probe. REACHABLE / UNAVAILABLE only — never LIVE or PASS."""
507
+ ts = time.time() if now is None else float(now)
508
+ cached = _FIELD_CACHE.get("payload")
509
+ cached_at = float(_FIELD_CACHE.get("at") or 0)
510
+ if cached and (ts - cached_at) < _KERNEL_CACHE_TTL:
511
+ out = dict(cached)
512
+ out["cached"] = True
513
+ return out
514
+
515
+ status, data, err = probe(_KERNEL_LATTICE_URL + "/api/field")
516
+ body = data if isinstance(data, dict) else {}
517
+ reachable = status == 200 and isinstance(data, dict)
518
+ raw_cells = body.get("cells") if reachable else None
519
+ cells = raw_cells if isinstance(raw_cells, list) else None
520
+ raw_hunts = body.get("hunts") if reachable else None
521
+ hunts = None
522
+ if isinstance(raw_hunts, list):
523
+ hunts = []
524
+ for item in raw_hunts:
525
+ if not isinstance(item, dict):
526
+ continue
527
+ hunts.append({
528
+ "id": item.get("id"),
529
+ "name": item.get("name"),
530
+ "cluster": item.get("cluster") or item.get("attck") or item.get("pack"),
531
+ })
532
+ payload = {
533
+ "ok": reachable,
534
+ "reachability": "REACHABLE" if reachable else "UNAVAILABLE",
535
+ "lambda_status": body.get("lambda_status") if reachable else None,
536
+ "actuation": body.get("actuation") if reachable else None,
537
+ "rule": body.get("rule") if reachable else None,
538
+ "cells": cells,
539
+ "hunts": hunts,
540
+ "cell_count": len(cells) if cells is not None else None,
541
+ "upstream_http": status,
542
+ "error": None if reachable else (err or "field unobserved"),
543
+ "channel": "B",
544
+ "space": "SZLHOLDINGS/immune-lattice",
545
+ "contract": "/api/field",
546
+ "url": _KERNEL_LATTICE_URL + "/api/field",
547
+ "product_tab": "/immune",
548
+ "honesty": {
549
+ "lambda": "Conjecture 1 (NOT a theorem)",
550
+ "never_fabricate": ["LIVE", "PASS"],
551
+ "first_paint": "CONNECTING",
552
+ "failed_probe": "UNAVAILABLE",
553
+ "actuation": "SIMULATED",
554
+ "rule": "hunt isolate deceive — never strike people",
555
+ "not_a_second_cop": True,
556
+ },
557
+ "organ": _ORGAN_NAME,
558
+ "cached": False,
559
+ "field_doctrine": body.get("doctrine") if reachable else None,
560
+ }
561
+ enveloped = _gov(payload, status="REAL" if reachable else "DEGRADED")
562
+ _FIELD_CACHE["at"] = ts
563
+ _FIELD_CACHE["payload"] = enveloped
564
+ return enveloped
565
+
566
+
567
  # ---------------------------------------------------------------------------
568
  # Registration — dual-register under /api/{ns}/v1/immune/* AND /v1/immune/*.
569
  # Mirrors szl_kverify's add_api_route pattern. Registered BEFORE the SPA catch-
 
607
  async def _h_verify(): # noqa: ANN202
608
  return JSONResponse(_verify_chain())
609
 
610
+ async def _h_kernel(): # noqa: ANN202
611
+ return JSONResponse(_kernel())
612
+
613
+ async def _h_field(): # noqa: ANN202
614
+ return JSONResponse(_field())
615
+
616
  prefixes = [f"/api/{ns}/v1/immune", "/v1/immune"]
617
  routes: list[str] = []
618
  for p in prefixes:
 
623
  app.add_api_route(f"{p}/feed", _h_feed, methods=["GET"], include_in_schema=True)
624
  app.add_api_route(f"{p}/verdict", _h_verdict, methods=["POST", "GET"], include_in_schema=True)
625
  app.add_api_route(f"{p}/verify", _h_verify, methods=["GET"], include_in_schema=True)
626
+ app.add_api_route(f"{p}/kernel", _h_kernel, methods=["GET", "HEAD"], include_in_schema=True)
627
+ app.add_api_route(f"{p}/field", _h_field, methods=["GET", "HEAD"], include_in_schema=True)
628
  routes.extend([f"{p}/healthz", f"{p}/status", f"{p}/gates", f"{p}/threats",
629
+ f"{p}/feed", f"{p}/verdict", f"{p}/verify", f"{p}/kernel", f"{p}/field"])
630
 
631
  print(f"[{ns}] szl_immune routes registered "
632
  f"(Immune (Hukulla) fail-closed egress gate, {len(routes)} routes)", flush=True)
tools/readiness-harness/tabs.json CHANGED
@@ -18,10 +18,10 @@
18
  "UNAVAILABLE": "The source or evidence is not available; no replacement value is fabricated."
19
  },
20
  "summary": {
21
- "tabs": 141,
22
  "endpoints": 100,
23
- "tabsWithCitations": 36,
24
- "staticTabs": 41
25
  },
26
  "endpoints": {
27
  "/api/a11oy/v1/lambda": {
@@ -3584,24 +3584,6 @@
3584
  "failOnMissingCitation": false
3585
  }
3586
  },
3587
- {
3588
- "key": "estate",
3589
- "title": "estate",
3590
- "group": "Console",
3591
- "route": "/console#estate",
3592
- "endpoints": [
3593
- "/api/a11oy/v1/models/series-a",
3594
- "/api/a11oy/v1/honest"
3595
- ],
3596
- "citationsRequired": true,
3597
- "sampleLabelAllowed": false,
3598
- "static": false,
3599
- "degradedRules": {
3600
- "allowSampleLabel": false,
3601
- "failOnUnlabeledPlaceholder": true,
3602
- "failOnMissingCitation": true
3603
- }
3604
- },
3605
  {
3606
  "key": "evidence",
3607
  "title": "evidence",
@@ -4040,21 +4022,6 @@
4040
  "failOnMissingCitation": false
4041
  }
4042
  },
4043
- {
4044
- "key": "investor",
4045
- "title": "investor",
4046
- "group": "Console",
4047
- "route": "/console#investor",
4048
- "endpoints": [],
4049
- "citationsRequired": false,
4050
- "sampleLabelAllowed": false,
4051
- "static": true,
4052
- "degradedRules": {
4053
- "allowSampleLabel": false,
4054
- "failOnUnlabeledPlaceholder": true,
4055
- "failOnMissingCitation": false
4056
- }
4057
- },
4058
  {
4059
  "key": "kamay",
4060
  "title": "KAMAY — Agentic Coding",
 
18
  "UNAVAILABLE": "The source or evidence is not available; no replacement value is fabricated."
19
  },
20
  "summary": {
21
+ "tabs": 139,
22
  "endpoints": 100,
23
+ "tabsWithCitations": 35,
24
+ "staticTabs": 40
25
  },
26
  "endpoints": {
27
  "/api/a11oy/v1/lambda": {
 
3584
  "failOnMissingCitation": false
3585
  }
3586
  },
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
3587
  {
3588
  "key": "evidence",
3589
  "title": "evidence",
 
4022
  "failOnMissingCitation": false
4023
  }
4024
  },
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
4025
  {
4026
  "key": "kamay",
4027
  "title": "KAMAY — Agentic Coding",
web/immune.html CHANGED
@@ -3,8 +3,8 @@
3
  <head>
4
  <meta charset="UTF-8"/>
5
  <meta name="viewport" content="width=device-width, initial-scale=1.0"/>
6
- <title>Immune (Hukulla) — fail-closed egress gate · SZL Holdings</title>
7
- <meta name="description" content="Honest operational view of the Immune organ (Quechua role 'Hukulla') — a fail-closed, deny-by-default egress gate. Status, trace, signature, and Khipu-chain evidence are shown only when returned by the live backend. Lambda = Conjecture 1; Khipu = Conjecture 2; trust never 100%."/>
8
  <!-- 0 runtime CDN (doctrine v11): system fonts only — no Google Fonts, no external assets. -->
9
  <style>
10
  :root{
@@ -69,6 +69,10 @@ textarea:focus,input:focus{outline:none;border-color:var(--teal-line);}
69
  button.run{margin-top:.6rem;padding:.55rem 1.1rem;border-radius:7px;border:1px solid var(--teal-line);background:var(--teal-soft);color:var(--teal);font-family:var(--mono);font-size:12px;letter-spacing:.06em;text-transform:uppercase;cursor:pointer;transition:.15s;}
70
  button.run:hover{background:rgba(95,179,163,.18);color:var(--cream);}
71
  button.run:focus-visible,.preset:focus-visible,.flag:focus-visible{outline:2px solid var(--teal);outline-offset:2px;}
 
 
 
 
72
  .preset{display:inline-block;margin:.3rem .3rem 0 0;padding:.2rem .5rem;border-radius:5px;border:1px solid var(--gold-line);color:var(--muted);font-family:var(--mono);font-size:10.5px;cursor:pointer;}
73
  .preset:hover{color:var(--cream);border-color:var(--teal-line);}
74
  .verdict-box{margin-top:.8rem;border:1px solid var(--gold-line);border-radius:8px;padding:.85rem 1rem;background:var(--panel2);font-family:var(--mono);font-size:12px;line-height:1.8;}
@@ -104,9 +108,10 @@ code{font-family:var(--mono);color:var(--teal);}
104
  <body>
105
  <div class="topbar">
106
  <span>SZL HOLDINGS</span><span class="sep">/</span><span>a11oy</span>
107
- <span class="live"><span class="live-dot" id="liveDot"></span><span id="liveTag" aria-live="polite">IMMUNE · PROBING</span></span>
108
  <span class="switcher">
109
  <a class="flag active" href="/immune">Immune</a>
 
110
  <a class="flag" href="/energy">Energy</a>
111
  <a class="flag" href="/fleet-c2">Fleet C2</a>
112
  <a class="flag" href="/living-anatomy">Living Anatomy</a>
@@ -115,12 +120,21 @@ code{font-family:var(--mono);color:var(--teal);}
115
  </div>
116
 
117
  <div class="wrap">
118
- <h1>Immune (Hukulla) — fail-closed egress gate<span class="badge" id="organBadge">deny-by-default · evidence pending</span></h1>
119
  <p class="lede">
120
- The <b>Immune</b> organ (Quechua role <b>Hukulla</b>) is a <b>fail-closed, deny-by-default</b> egress gate.
121
- Submitted actions are sent to the live threat-signature, size, and
122
- <b>&Lambda;-gate</b> inspection path (MIN of supplied trust axes &lt; 0.5 &rarr; deny). When the backend
123
- returns a Khipu receipt, its digest, sequence, signature, chain result, and trace context are shown below.
 
 
 
 
 
 
 
 
 
124
  No receipt or signature state is inferred by this page. Proven Lean backing:
125
  <code>ImmuneNeymanPearsonOpt.lean</code> (Neyman&ndash;Pearson-optimal egress) and
126
  <code>FrontierWelfordVariance.lean</code> (Welford online variance). These back the gate but are
@@ -128,6 +142,54 @@ code{font-family:var(--mono);color:var(--teal);}
128
  Khipu = Conjecture&nbsp;2; trust is never 100%; effectors simulated; no fabricated data.
129
  </p>
130
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
131
  <div class="cards">
132
  <div class="card"><div class="lbl">Verdicts (this process)</div><div class="big" id="cVerdicts">—</div><div class="sub" id="cVerdictsSub">resets on restart</div></div>
133
  <div class="card"><div class="lbl">Deny rate</div><div class="big" id="cDenyRate">—</div><div class="sub" id="cDenySub">deny / total</div></div>
@@ -157,7 +219,7 @@ code{font-family:var(--mono);color:var(--teal);}
157
 
158
  <div class="panel">
159
  <h2>Live status <span class="meta" id="statusEp">GET /api/a11oy/v1/immune/status</span></h2>
160
- <div class="kv" id="statusKv" aria-live="polite"><span class="k">status</span><span class="v">PROBING</span></div>
161
  <div class="simnote" id="honestyNote">
162
  Λ = Conjecture 1 (NOT a theorem). Khipu = Conjecture 2. Trust never 100%. Effectors simulated.
163
  Decision feed is in-memory (resets on restart) — empty means IDLE, never faked.
@@ -178,7 +240,7 @@ code{font-family:var(--mono);color:var(--teal);}
178
  <div class="footnote" id="leanFoot">
179
  Proven Lean backing: Lutar/Wave11/ImmuneNeymanPearsonOpt.lean · Lutar/Innovations/round11/FrontierWelfordVariance.lean.
180
  Locked-proven set = EXACTLY 8 {F1,F4,F7,F11,F12,F18,F19,F22} @ kernel c7c0ba17 — the immune Lean backing is cited, NOT folded in.
181
- SLSA L1/L2/L3-roadmap · 0 runtime CDN. This page reads only the live /api/a11oy/v1/immune/* endpoints.
182
  </div>
183
  </div>
184
 
@@ -324,9 +386,107 @@ document.querySelectorAll(".preset").forEach(p=>p.addEventListener("click",()=>{
324
  }));
325
  document.getElementById("runBtn").addEventListener("click",runVerdict);
326
 
327
- async function loadAll(){ await Promise.all([loadStatus(),loadGates(),loadFeed()]); }
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
328
  loadAll();
329
  setInterval(loadStatus, 8000);
 
 
330
  </script>
331
  </body>
332
  </html>
 
3
  <head>
4
  <meta charset="UTF-8"/>
5
  <meta name="viewport" content="width=device-width, initial-scale=1.0"/>
6
+ <title>IMMUNE — fail-closed kernel · SZL Holdings</title>
7
+ <meta name="description" content="Public IMMUNE tab: Hukulla fail-closed egress gate, same-origin Channel A kernel probe, and Channel B Field lattice (exile/mesh/quorum/delta). Hunt/isolate/deceive — never strike people. Status is CONNECTING, REACHABLE, or UNAVAILABLE — never fabricated LIVE or PASS. Lambda = Conjecture 1; Khipu = Conjecture 2; trust never 100%."/>
8
  <!-- 0 runtime CDN (doctrine v11): system fonts only — no Google Fonts, no external assets. -->
9
  <style>
10
  :root{
 
69
  button.run{margin-top:.6rem;padding:.55rem 1.1rem;border-radius:7px;border:1px solid var(--teal-line);background:var(--teal-soft);color:var(--teal);font-family:var(--mono);font-size:12px;letter-spacing:.06em;text-transform:uppercase;cursor:pointer;transition:.15s;}
70
  button.run:hover{background:rgba(95,179,163,.18);color:var(--cream);}
71
  button.run:focus-visible,.preset:focus-visible,.flag:focus-visible{outline:2px solid var(--teal);outline-offset:2px;}
72
+ .kernel-actions{display:flex;flex-wrap:wrap;gap:.45rem;margin-top:.7rem;}
73
+ .kernel-actions a,.kernel-actions button{min-height:44px;display:inline-flex;align-items:center;}
74
+ #kernelFrameHost{margin-top:.8rem;}
75
+ #kernelFrameHost iframe{width:100%;min-height:72vh;border:1px solid var(--gold-line);border-radius:8px;background:#000;}
76
  .preset{display:inline-block;margin:.3rem .3rem 0 0;padding:.2rem .5rem;border-radius:5px;border:1px solid var(--gold-line);color:var(--muted);font-family:var(--mono);font-size:10.5px;cursor:pointer;}
77
  .preset:hover{color:var(--cream);border-color:var(--teal-line);}
78
  .verdict-box{margin-top:.8rem;border:1px solid var(--gold-line);border-radius:8px;padding:.85rem 1rem;background:var(--panel2);font-family:var(--mono);font-size:12px;line-height:1.8;}
 
108
  <body>
109
  <div class="topbar">
110
  <span>SZL HOLDINGS</span><span class="sep">/</span><span>a11oy</span>
111
+ <span class="live"><span class="live-dot" id="liveDot"></span><span id="liveTag" aria-live="polite">IMMUNE · CONNECTING</span></span>
112
  <span class="switcher">
113
  <a class="flag active" href="/immune">Immune</a>
114
+ <a class="flag" href="/nemo">Nemo</a>
115
  <a class="flag" href="/energy">Energy</a>
116
  <a class="flag" href="/fleet-c2">Fleet C2</a>
117
  <a class="flag" href="/living-anatomy">Living Anatomy</a>
 
120
  </div>
121
 
122
  <div class="wrap">
123
+ <h1>IMMUNE — fail-closed kernel<span class="badge" id="organBadge">deny-by-default · connecting</span></h1>
124
  <p class="lede">
125
+ The <b>IMMUNE</b> kernel (organ role <b>Hukulla</b>) is a <b>fail-closed, deny-by-default</b> admission
126
+ and egress gate: SENTRA inspection, YAWAR SHA-256 receipts, HUKLLA tripwires, MESH 3-of-4, NEMO R1–R5.
127
+ This tab is first-class on a-11-oy.com. The public kernel lives at
128
+ <a href="https://szlholdings-immune.hf.space"><code>SZLHOLDINGS/immune</code></a>;
129
+ the COP overlay sibling is
130
+ <a href="https://szlholdings-immune-lattice.hf.space"><code>SZLHOLDINGS/immune-lattice</code></a>.
131
+ Neither Space is deleted. Channel B Field cells (RANGE.CLOUD.EXILE, RANGE.FALLBACK.MESH,
132
+ CERT.CELL.QUORUM, FIELD.LATTICE.DELTA) compile public Ukraine COP doctrine as
133
+ <b>hunt / isolate / deceive</b> — never strike people. RANGE twins only; actuation is SIMULATED.
134
+ This flagship tab cites the lattice; it is not a second COP. This page never fabricates <b>LIVE</b> or <b>PASS</b> —
135
+ first paint is <b>CONNECTING</b>; a failed probe is <b>UNAVAILABLE</b>; a successful
136
+ <code>/readyz</code> read is <b>REACHABLE</b> (and <b>WRITE-READY</b> only when the kernel says so).
137
+ Submitted actions below hit the live Hukulla inspection path (MIN of supplied trust axes < 0.5 &rarr; deny).
138
  No receipt or signature state is inferred by this page. Proven Lean backing:
139
  <code>ImmuneNeymanPearsonOpt.lean</code> (Neyman&ndash;Pearson-optimal egress) and
140
  <code>FrontierWelfordVariance.lean</code> (Welford online variance). These back the gate but are
 
142
  Khipu = Conjecture&nbsp;2; trust is never 100%; effectors simulated; no fabricated data.
143
  </p>
144
 
145
+ <div class="panel" id="kernelPanel">
146
+ <h2>Live kernel <span class="meta">GET /api/a11oy/v1/immune/kernel → SZLHOLDINGS/immune /readyz</span></h2>
147
+ <p class="lede" style="margin:.2rem 0 .6rem;font-size:.86rem;">
148
+ Same-origin probe so this page stays 0-CDN. Channel A is the public kernel.
149
+ Channel B is the lattice COP overlay — its <code>/readyz</code> is intercepted by the Hub proxy;
150
+ that 502 HTML is not kernel death. Click-to-embed is operator-initiated, never first-paint.
151
+ </p>
152
+ <div class="cards">
153
+ <div class="card"><div class="lbl">Reachability</div><div class="big" id="kReach">CONNECTING</div><div class="sub" id="kReachSub">first paint — not UNAVAILABLE</div></div>
154
+ <div class="card"><div class="lbl">Write-ready</div><div class="big" id="kWrite">—</div><div class="sub" id="kWriteSub">forwarded only when observed</div></div>
155
+ <div class="card"><div class="lbl">Authority</div><div class="big" id="kAuth">—</div><div class="sub" id="kAuthSub">never inferred PASS</div></div>
156
+ <div class="card"><div class="lbl">Receipts / kid</div><div class="big" id="kLedger">—</div><div class="sub" id="kKidSub">ledger + key id</div></div>
157
+ </div>
158
+ <div class="kv" id="kernelKv" aria-live="polite"><span class="k">status</span><span class="v">CONNECTING</span></div>
159
+ <div class="kernel-actions">
160
+ <a class="flag" href="https://szlholdings-immune.hf.space" target="_blank" rel="noopener">Open Channel A kernel</a>
161
+ <a class="flag" href="https://szlholdings-immune-lattice.hf.space" target="_blank" rel="noopener">Open Channel B lattice</a>
162
+ <a class="flag" href="https://github.com/szl-holdings/immune" target="_blank" rel="noopener">GitHub kernel</a>
163
+ <button class="run" id="embedBtn" type="button">Embed live kernel</button>
164
+ </div>
165
+ <div id="kernelFrameHost"></div>
166
+ </div>
167
+
168
+ <div class="panel" id="fieldPanel">
169
+ <h2>Field lattice <span class="meta">GET /api/a11oy/v1/immune/field → Channel B /api/field</span></h2>
170
+ <p class="lede" style="margin:.2rem 0 .6rem;font-size:.86rem;">
171
+ Same-origin probe of <code>SZLHOLDINGS/immune-lattice</code>. Cells are compiled as
172
+ hunt / isolate / deceive — never strike people. First paint is <b>CONNECTING</b>.
173
+ A failed probe is <b>UNAVAILABLE</b> (cells are not invented). A JSON catalog is
174
+ <b>REACHABLE</b>, not LIVE. This page is a citation, not a second COP.
175
+ </p>
176
+ <div class="cards">
177
+ <div class="card"><div class="lbl">Reachability</div><div class="big" id="fReach">CONNECTING</div><div class="sub" id="fReachSub">first paint — not UNAVAILABLE</div></div>
178
+ <div class="card"><div class="lbl">Λ / doctrine</div><div class="big" id="fDoc">—</div><div class="sub" id="fLam">Conjecture 1 — not a theorem</div></div>
179
+ <div class="card"><div class="lbl">Actuation</div><div class="big" id="fAct">—</div><div class="sub">SIMULATED only</div></div>
180
+ <div class="card"><div class="lbl">Rule</div><div class="big" id="fRule">—</div><div class="sub" id="fRuleSub">never strike people</div></div>
181
+ </div>
182
+ <div class="cards" id="fieldCells"></div>
183
+ <div class="kv" id="fieldKv" aria-live="polite"><span class="k">status</span><span class="v">CONNECTING</span></div>
184
+ <div class="kernel-actions">
185
+ <a class="flag" href="https://szlholdings-immune-lattice.hf.space" target="_blank" rel="noopener">Open Channel B lattice</a>
186
+ <a class="flag" href="https://github.com/szl-holdings/immune-lattice" target="_blank" rel="noopener">GitHub lattice</a>
187
+ <a class="flag" href="https://a11oy.net/" target="_blank" rel="noopener">Proof registry</a>
188
+ <button class="run" id="embedFieldBtn" type="button">Embed live lattice</button>
189
+ </div>
190
+ <div id="fieldFrameHost"></div>
191
+ </div>
192
+
193
  <div class="cards">
194
  <div class="card"><div class="lbl">Verdicts (this process)</div><div class="big" id="cVerdicts">—</div><div class="sub" id="cVerdictsSub">resets on restart</div></div>
195
  <div class="card"><div class="lbl">Deny rate</div><div class="big" id="cDenyRate">—</div><div class="sub" id="cDenySub">deny / total</div></div>
 
219
 
220
  <div class="panel">
221
  <h2>Live status <span class="meta" id="statusEp">GET /api/a11oy/v1/immune/status</span></h2>
222
+ <div class="kv" id="statusKv" aria-live="polite"><span class="k">status</span><span class="v">CONNECTING</span></div>
223
  <div class="simnote" id="honestyNote">
224
  Λ = Conjecture 1 (NOT a theorem). Khipu = Conjecture 2. Trust never 100%. Effectors simulated.
225
  Decision feed is in-memory (resets on restart) — empty means IDLE, never faked.
 
240
  <div class="footnote" id="leanFoot">
241
  Proven Lean backing: Lutar/Wave11/ImmuneNeymanPearsonOpt.lean · Lutar/Innovations/round11/FrontierWelfordVariance.lean.
242
  Locked-proven set = EXACTLY 8 {F1,F4,F7,F11,F12,F18,F19,F22} @ kernel c7c0ba17 — the immune Lean backing is cited, NOT folded in.
243
+ SLSA L1/L2/L3-roadmap · 0 runtime CDN. This page reads only the live /api/a11oy/v1/immune/* endpoints (Hukulla organ + same-origin kernel and Field probes). Channel A = SZLHOLDINGS/immune. Channel B = SZLHOLDINGS/immune-lattice Field (exile/mesh/quorum/delta). Neither Space is deleted. Hunt / isolate / deceive — never strike people.
244
  </div>
245
  </div>
246
 
 
386
  }));
387
  document.getElementById("runBtn").addEventListener("click",runVerdict);
388
 
389
+ function kernelAuthorityLabel(s){
390
+ if(!s||typeof s!=="object")return null;
391
+ if(present(s.evidence_state))return s.evidence_state;
392
+ if(typeof s.authority==="string")return s.authority;
393
+ if(s.authority&&typeof s.authority==="object"){
394
+ return s.authority.evidenceState||s.authority.evidence_state||s.authority.status||null;
395
+ }
396
+ return null;
397
+ }
398
+
399
+ async function loadKernel(){
400
+ const result = await requestJSON(BASE + "/kernel");
401
+ const kv = document.getElementById("kernelKv");
402
+ const s = result.data||{};
403
+ const reach = result.ok && s.reachability==="REACHABLE" ? "REACHABLE" : (result.ok||result.status!=null ? "UNAVAILABLE" : "UNAVAILABLE");
404
+ document.getElementById("kReach").textContent = reach;
405
+ document.getElementById("kReachSub").textContent = reach==="REACHABLE" ? "Channel A /readyz answered JSON" : requestFailure(result);
406
+ const writeReady = s.write_ready===true;
407
+ document.getElementById("kWrite").textContent = typeof s.write_ready==="boolean"?String(s.write_ready):"—";
408
+ document.getElementById("kWriteSub").textContent = writeReady?"WRITE-READY (not LIVE)":"not claimed";
409
+ const auth = kernelAuthorityLabel(s);
410
+ document.getElementById("kAuth").textContent = present(auth)?String(auth):"—";
411
+ document.getElementById("kLedger").textContent = present(s.ledger)?String(s.ledger):"—";
412
+ document.getElementById("kKidSub").textContent = present(s.key_id)?"kid "+s.key_id:"key id unobserved";
413
+ kv.innerHTML =
414
+ row("reachability",reach)+
415
+ row("write_ready",typeof s.write_ready==="boolean"?String(s.write_ready):null)+
416
+ row("evidence",s.evidence_state)+
417
+ row("key id",s.key_id)+
418
+ row("ledger",s.ledger)+
419
+ row("channel A",s.channel_a&&s.channel_a.space)+
420
+ row("channel B",s.channel_b&&s.channel_b.space)+
421
+ row("error",s.error||(!result.ok?requestFailure(result):null))+
422
+ row("observed at",s.fetchedAt||s.observed_at)+
423
+ '<div><span class="k">kernel</span><span class="pill '+(reach==="REACHABLE"?(writeReady?"green":"yellow"):"red")+'">'+esc(reach+(writeReady?" · WRITE-READY":""))+'</span></div>';
424
+ }
425
+
426
+ document.getElementById("embedBtn").addEventListener("click",function(){
427
+ const host=document.getElementById("kernelFrameHost");
428
+ if(host.querySelector("iframe"))return;
429
+ const f=document.createElement("iframe");
430
+ f.title="IMMUNE kernel Space";
431
+ f.src="https://szlholdings-immune.hf.space";
432
+ f.setAttribute("loading","lazy");
433
+ host.appendChild(f);
434
+ this.textContent="Kernel embedded";
435
+ });
436
+
437
+ async function loadField(){
438
+ const result = await requestJSON(BASE + "/field");
439
+ const kv = document.getElementById("fieldKv");
440
+ const s = result.data||{};
441
+ const reach = result.ok && s.reachability==="REACHABLE" ? "REACHABLE" : "UNAVAILABLE";
442
+ document.getElementById("fReach").textContent = reach;
443
+ document.getElementById("fReachSub").textContent = reach==="REACHABLE" ? "Channel B /api/field answered JSON" : requestFailure(result);
444
+ document.getElementById("fDoc").textContent = present(s.field_doctrine)?String(s.field_doctrine):(present(s.lambda_status)?String(s.lambda_status):"—");
445
+ document.getElementById("fLam").textContent = present(s.lambda_status)?String(s.lambda_status):"Conjecture 1 — not a theorem";
446
+ document.getElementById("fAct").textContent = present(s.actuation)?String(s.actuation):"—";
447
+ document.getElementById("fRule").textContent = present(s.rule)?String(s.rule).slice(0,42):"—";
448
+ document.getElementById("fRuleSub").textContent = "never strike people";
449
+ const host = document.getElementById("fieldCells");
450
+ const cells = Array.isArray(s.cells)?s.cells:[];
451
+ if(reach!=="REACHABLE" || !cells.length){
452
+ host.replaceChildren();
453
+ }else{
454
+ host.innerHTML = cells.map(function(c){
455
+ const name=c&&c.name||c&&c.id||"cell";
456
+ const verb=c&&c.verb||"—";
457
+ const take=c&&c.take||"";
458
+ return '<div class="card"><div class="lbl">'+esc(name)+'</div><div class="big">'+esc(verb)+'</div><div class="sub">'+esc(take)+'</div></div>';
459
+ }).join("");
460
+ }
461
+ kv.innerHTML =
462
+ row("reachability",reach)+
463
+ row("doctrine",s.field_doctrine)+
464
+ row("lambda",s.lambda_status)+
465
+ row("actuation",s.actuation)+
466
+ row("rule",s.rule)+
467
+ row("cells",typeof s.cell_count==="number"?String(s.cell_count):null)+
468
+ row("channel",s.space)+
469
+ row("error",s.error||(!result.ok?requestFailure(result):null))+
470
+ row("observed at",s.fetchedAt||s.observed_at)+
471
+ '<div><span class="k">field</span><span class="pill '+(reach==="REACHABLE"?"green":"red")+'">'+esc(reach)+'</span></div>';
472
+ }
473
+
474
+ document.getElementById("embedFieldBtn").addEventListener("click",function(){
475
+ const host=document.getElementById("fieldFrameHost");
476
+ if(host.querySelector("iframe"))return;
477
+ const f=document.createElement("iframe");
478
+ f.title="IMMUNE lattice Space";
479
+ f.src="https://szlholdings-immune-lattice.hf.space";
480
+ f.setAttribute("loading","lazy");
481
+ host.appendChild(f);
482
+ this.textContent="Lattice embedded";
483
+ });
484
+
485
+ async function loadAll(){ await Promise.all([loadStatus(),loadGates(),loadFeed(),loadKernel(),loadField()]); }
486
  loadAll();
487
  setInterval(loadStatus, 8000);
488
+ setInterval(loadKernel, 8000);
489
+ setInterval(loadField, 8000);
490
  </script>
491
  </body>
492
  </html>