Spaces:
Runtime error
Runtime error
deploy(hf): sync szl-holdings/a11oy@main derived COPY set
Browse filesReusable Dockerfile-COPY-derived deploy from szl-holdings/a11oy main.
Files: 943 Pruned: 0
Derived from Dockerfile COPY sources (NO hand-maintained allowlist).
Signed-off-by: SZL Holdings <noreply@szlholdings.ai>
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
- szl_agent_loop_governed.py +41 -0
- szl_eval_arena.py +88 -7
- szl_governed_rag.py +56 -1
- szl_model_harness.py +71 -1
- szl_sovereign_flywheel.py +324 -0
szl_agent_loop_governed.py
CHANGED
|
@@ -128,6 +128,16 @@ except Exception:
|
|
| 128 |
_APPROVAL_OK = False
|
| 129 |
_approval_interrupt = None
|
| 130 |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| 131 |
|
| 132 |
def _now() -> str:
|
| 133 |
return datetime.now(timezone.utc).isoformat()
|
|
@@ -185,6 +195,21 @@ def run_loop(task: str,
|
|
| 185 |
max_retries = max(0, min(3, int(max_retries)))
|
| 186 |
grant = approval if isinstance(approval, dict) else None
|
| 187 |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| 188 |
if not _ENGINE_OK:
|
| 189 |
return {
|
| 190 |
"ok": False,
|
|
@@ -404,6 +429,7 @@ def run_loop(task: str,
|
|
| 404 |
"task": task,
|
| 405 |
"mode": plan_mode,
|
| 406 |
"model_id": model_id or "(engine default)",
|
|
|
|
| 407 |
"harness_profile_id": harness_profile_id or None,
|
| 408 |
"eval_suite_default": eval_suite or "(per-step mode heuristic)",
|
| 409 |
"max_retries": max_retries,
|
|
@@ -475,6 +501,9 @@ def run_loop(task: str,
|
|
| 475 |
"steps": steps_out,
|
| 476 |
"aggregate": receipt_body["aggregate"],
|
| 477 |
"composite_receipt": {"body": receipt_body, "dsse": dsse, "signing": signing},
|
|
|
|
|
|
|
|
|
|
| 478 |
"forum_ingest": forum,
|
| 479 |
"composes": receipt_body["composes"],
|
| 480 |
"leaders_cited": LEADERS,
|
|
@@ -642,6 +671,18 @@ def register(app, ns: str = "a11oy", sign_fn: Optional[Callable[[dict], dict]] =
|
|
| 642 |
"self_eval_available": _ARENA_OK,
|
| 643 |
"behavior_profile_available": _HARNESS_OK,
|
| 644 |
"human_gate_available": _APPROVAL_OK,
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| 645 |
},
|
| 646 |
"eval_suites": eval_suites,
|
| 647 |
"approval_gate_enabled": os.environ.get("A11OY_APPROVAL_INTERRUPT") == "1",
|
|
|
|
| 128 |
_APPROVAL_OK = False
|
| 129 |
_approval_interrupt = None
|
| 130 |
|
| 131 |
+
# Wave M (Dev 2): shared sovereign-flywheel bridge. Lets the governed loop run on
|
| 132 |
+
# SZL's OWN model (sovereign_local) via Dev-1's registry backend; honest
|
| 133 |
+
# MODELED/UNAVAILABLE when the local Tower endpoint is unreachable (no fabrication).
|
| 134 |
+
try:
|
| 135 |
+
import szl_sovereign_flywheel as _sov # noqa: F401
|
| 136 |
+
_SOV_OK = True
|
| 137 |
+
except Exception: # pragma: no cover — bridge missing → sovereign option simply off
|
| 138 |
+
_sov = None # type: ignore
|
| 139 |
+
_SOV_OK = False
|
| 140 |
+
|
| 141 |
|
| 142 |
def _now() -> str:
|
| 143 |
return datetime.now(timezone.utc).isoformat()
|
|
|
|
| 195 |
max_retries = max(0, min(3, int(max_retries)))
|
| 196 |
grant = approval if isinstance(approval, dict) else None
|
| 197 |
|
| 198 |
+
# ── Wave M (Dev 2): sovereign preflight ───────────────────────────────────
|
| 199 |
+
# If the caller asked to run this loop on SZL's OWN governed model, probe the
|
| 200 |
+
# sovereign backend ONCE (Dev-1 registry) and carry the honest verdict into the
|
| 201 |
+
# composite receipt. The per-step ACT still flows through the engine with
|
| 202 |
+
# want_model=model_id; the sovereign block records the intended backend +
|
| 203 |
+
# reachability so an offline run is honestly MODELED/UNAVAILABLE (no fabrication).
|
| 204 |
+
sovereign_requested = bool(_SOV_OK and _sov and _sov.is_sovereign(model_id))
|
| 205 |
+
sovereign_block = None
|
| 206 |
+
sovereign_state = None
|
| 207 |
+
if sovereign_requested:
|
| 208 |
+
_sp = _sov.run_on_sovereign(task or "State your doctrine in one line.",
|
| 209 |
+
requested_model_id=model_id, probe_only=True)
|
| 210 |
+
sovereign_state = _sp.get("state")
|
| 211 |
+
sovereign_block = _sov.receipt_block(_sp)
|
| 212 |
+
|
| 213 |
if not _ENGINE_OK:
|
| 214 |
return {
|
| 215 |
"ok": False,
|
|
|
|
| 429 |
"task": task,
|
| 430 |
"mode": plan_mode,
|
| 431 |
"model_id": model_id or "(engine default)",
|
| 432 |
+
"sovereign": sovereign_block, # Wave M: intended sovereign backend (None when not requested)
|
| 433 |
"harness_profile_id": harness_profile_id or None,
|
| 434 |
"eval_suite_default": eval_suite or "(per-step mode heuristic)",
|
| 435 |
"max_retries": max_retries,
|
|
|
|
| 501 |
"steps": steps_out,
|
| 502 |
"aggregate": receipt_body["aggregate"],
|
| 503 |
"composite_receipt": {"body": receipt_body, "dsse": dsse, "signing": signing},
|
| 504 |
+
"sovereign": sovereign_block, # Wave M: honest intended-backend + reachability
|
| 505 |
+
"sovereign_label": (_sov.selected_label({"state": sovereign_state})
|
| 506 |
+
if sovereign_requested and _SOV_OK and _sov else None),
|
| 507 |
"forum_ingest": forum,
|
| 508 |
"composes": receipt_body["composes"],
|
| 509 |
"leaders_cited": LEADERS,
|
|
|
|
| 671 |
"self_eval_available": _ARENA_OK,
|
| 672 |
"behavior_profile_available": _HARNESS_OK,
|
| 673 |
"human_gate_available": _APPROVAL_OK,
|
| 674 |
+
"sovereign_available": _SOV_OK,
|
| 675 |
+
},
|
| 676 |
+
# Wave M (Dev 2): run this governed loop on SZL's OWN model.
|
| 677 |
+
"run_on_sovereign": {
|
| 678 |
+
"available": bool(_SOV_OK),
|
| 679 |
+
"how": ("POST /agentloop/run with model_id='szl-sovereign-local' "
|
| 680 |
+
"(alias of registry backend 'sovereign_local'). The loop "
|
| 681 |
+
"probes the local Tower via Dev-1's backend and records the "
|
| 682 |
+
"intended sovereign backend in the composite receipt; honest "
|
| 683 |
+
"MODELED/UNAVAILABLE when offline (no fabrication)."),
|
| 684 |
+
"backend_id": "sovereign_local",
|
| 685 |
+
"model_slug": "llama3-szl-finetuned-q4",
|
| 686 |
},
|
| 687 |
"eval_suites": eval_suites,
|
| 688 |
"approval_gate_enabled": os.environ.get("A11OY_APPROVAL_INTERRUPT") == "1",
|
szl_eval_arena.py
CHANGED
|
@@ -366,6 +366,17 @@ _SCORERS: dict[str, Callable[[str, str], tuple[bool, str]]] = {
|
|
| 366 |
# answer is derived ONLY from the case's own `expected`/category — it is an honest
|
| 367 |
# "reference oracle" stub, NOT a claim that a model produced it.
|
| 368 |
# ─────────────────────────────────────────────────────────────────────────────
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| 369 |
def _registry_snapshot() -> dict[str, Any]:
|
| 370 |
"""Best-effort read of the registry (model roster + key-wired status)."""
|
| 371 |
out = {"available": False, "models": {}, "any_key_wired": False}
|
|
@@ -430,8 +441,45 @@ def _control_benign_answer(case: dict[str, Any]) -> str:
|
|
| 430 |
|
| 431 |
|
| 432 |
def _solve_case(case: dict[str, Any], model_id: str, snap: dict[str, Any],
|
| 433 |
-
harness: dict[str, Any]) -> dict[str, Any]:
|
| 434 |
-
"""Produce an answer for one case (honest MODELED unless a key is wired).
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| 435 |
live = snap.get("available") and snap.get("any_key_wired")
|
| 436 |
label = "LIVE" if live else "MODELED"
|
| 437 |
known = model_id in snap.get("models", {})
|
|
@@ -532,13 +580,25 @@ def run_eval(suite_id: str, model_id: str, harness_profile_id: str | None = None
|
|
| 532 |
snap = _registry_snapshot()
|
| 533 |
harness = _resolve_harness(harness_profile_id)
|
| 534 |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| 535 |
cases_in = suite["cases"]
|
| 536 |
suite_sha256 = _sha256_str(_canon(cases_in)) # lm-eval-style content version pin
|
| 537 |
results: list[dict[str, Any]] = []
|
| 538 |
by_cat: dict[str, dict[str, int]] = {}
|
| 539 |
|
| 540 |
for case in cases_in:
|
| 541 |
-
solved = _solve_case(case, model_id, snap, harness)
|
| 542 |
answer = solved["answer"]
|
| 543 |
label = solved["label"]
|
| 544 |
scorer_name = case.get("scorer", "exact")
|
|
@@ -617,9 +677,14 @@ def run_eval(suite_id: str, model_id: str, harness_profile_id: str | None = None
|
|
| 617 |
}
|
| 618 |
|
| 619 |
# ── build the receipt payload (signed below) ──
|
| 620 |
-
|
| 621 |
-
|
| 622 |
-
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| 623 |
|
| 624 |
receipt_body = {
|
| 625 |
"schema": SCHEMA,
|
|
@@ -631,7 +696,8 @@ def run_eval(suite_id: str, model_id: str, harness_profile_id: str | None = None
|
|
| 631 |
"suite_version": suite["version"],
|
| 632 |
"suite_sha256": suite_sha256,
|
| 633 |
"model_id": model_id,
|
| 634 |
-
"model_known": model_id in snap.get("models", {}),
|
|
|
|
| 635 |
"harness_profile_id": harness_profile_id,
|
| 636 |
"harness": {"applied": harness.get("applied"), "available": harness.get("available"),
|
| 637 |
"profile_sha256": harness.get("profile_sha256"), "note": harness.get("note")},
|
|
@@ -759,6 +825,16 @@ def register(app: "FastAPI", ns: str = "a11oy") -> dict:
|
|
| 759 |
],
|
| 760 |
"scorers": list(_SCORERS.keys()),
|
| 761 |
"run_endpoint": "POST " + base + "/run",
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| 762 |
"leaders_cited": LEADERS,
|
| 763 |
"lambda_posture": "advisory (Conjecture 1) — never green",
|
| 764 |
"doctrine": DOCTRINE, "kernel_commit": _KERNEL,
|
|
@@ -786,6 +862,11 @@ def register(app: "FastAPI", ns: str = "a11oy") -> dict:
|
|
| 786 |
|
| 787 |
Body: {"suite": "core_honest_v1", "model_id": "claude_sonnet_4_6",
|
| 788 |
"harness_profile_id": "szl-honest-operator" (optional)}
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| 789 |
"""
|
| 790 |
try:
|
| 791 |
body = await request.json()
|
|
|
|
| 366 |
# answer is derived ONLY from the case's own `expected`/category — it is an honest
|
| 367 |
# "reference oracle" stub, NOT a claim that a model produced it.
|
| 368 |
# ─────────────────────────────────────────────────────────────────────────────
|
| 369 |
+
# Wave M (Dev 2): shared sovereign-flywheel bridge. Lets /eval/run score SZL's OWN
|
| 370 |
+
# governed model (sovereign_local) through Dev-1's registry backend; honest
|
| 371 |
+
# MODELED/UNAVAILABLE when the local Tower endpoint is unreachable (no fabrication).
|
| 372 |
+
try:
|
| 373 |
+
import szl_sovereign_flywheel as _sov # noqa: F401
|
| 374 |
+
_SOV_OK = True
|
| 375 |
+
except Exception: # pragma: no cover — bridge missing → sovereign option simply off
|
| 376 |
+
_sov = None # type: ignore
|
| 377 |
+
_SOV_OK = False
|
| 378 |
+
|
| 379 |
+
|
| 380 |
def _registry_snapshot() -> dict[str, Any]:
|
| 381 |
"""Best-effort read of the registry (model roster + key-wired status)."""
|
| 382 |
out = {"available": False, "models": {}, "any_key_wired": False}
|
|
|
|
| 441 |
|
| 442 |
|
| 443 |
def _solve_case(case: dict[str, Any], model_id: str, snap: dict[str, Any],
|
| 444 |
+
harness: dict[str, Any], sov_state: str | None = None) -> dict[str, Any]:
|
| 445 |
+
"""Produce an answer for one case (honest MODELED unless a key is wired).
|
| 446 |
+
|
| 447 |
+
Wave M (Dev 2): when the caller asked for SZL's sovereign local model,
|
| 448 |
+
`sov_state` carries the ONE-shot reachability verdict from run_eval:
|
| 449 |
+
LIVE → do a REAL per-case generation on the local node.
|
| 450 |
+
MODELED → node not live this request → honest MODELED reference stub
|
| 451 |
+
(pipeline still scored; NO model text fabricated as sovereign).
|
| 452 |
+
UNAVAILABLE → local endpoint unreachable → honest UNAVAILABLE non-response.
|
| 453 |
+
"""
|
| 454 |
+
# ── sovereign branch (routes through Dev-1's registry backend) ──
|
| 455 |
+
if sov_state is not None:
|
| 456 |
+
if sov_state == "LIVE" and _SOV_OK and _sov:
|
| 457 |
+
sov = _sov.run_on_sovereign(str(case.get("input", "")),
|
| 458 |
+
requested_model_id=model_id)
|
| 459 |
+
if sov.get("state") == "LIVE" and isinstance(sov.get("text"), str):
|
| 460 |
+
answer = sov["text"]
|
| 461 |
+
if harness.get("applied"):
|
| 462 |
+
answer = f"[profile:{harness['profile_id']}] " + answer
|
| 463 |
+
return {"answer": answer, "label": "LIVE"}
|
| 464 |
+
# node fell over mid-run → honest MODELED, no fabrication as sovereign
|
| 465 |
+
answer = _modeled_reference_answer(case)
|
| 466 |
+
if harness.get("applied"):
|
| 467 |
+
answer = f"[profile:{harness['profile_id']}] " + answer
|
| 468 |
+
return {"answer": answer, "label": "MODELED"}
|
| 469 |
+
if sov_state == "MODELED":
|
| 470 |
+
if case.get("category") == "safety_control":
|
| 471 |
+
answer = _control_benign_answer(case)
|
| 472 |
+
else:
|
| 473 |
+
answer = _modeled_reference_answer(case)
|
| 474 |
+
if harness.get("applied"):
|
| 475 |
+
answer = f"[profile:{harness['profile_id']}] " + answer
|
| 476 |
+
return {"answer": answer, "label": "MODELED"}
|
| 477 |
+
# UNAVAILABLE — sovereign endpoint unreachable; no model call, no fabrication
|
| 478 |
+
answer = ("[UNAVAILABLE] SZL sovereign_local endpoint unreachable "
|
| 479 |
+
"(SZL_LOCAL_LLM_URL unset / Tower offline); no answer produced. "
|
| 480 |
+
"Pipeline scored this as a non-response.")
|
| 481 |
+
return {"answer": answer, "label": "UNAVAILABLE"}
|
| 482 |
+
|
| 483 |
live = snap.get("available") and snap.get("any_key_wired")
|
| 484 |
label = "LIVE" if live else "MODELED"
|
| 485 |
known = model_id in snap.get("models", {})
|
|
|
|
| 580 |
snap = _registry_snapshot()
|
| 581 |
harness = _resolve_harness(harness_profile_id)
|
| 582 |
|
| 583 |
+
# ── Wave M (Dev 2): sovereign option — probe SZL's OWN model ONCE per run ──
|
| 584 |
+
# so we don't hammer the local node per-case. The verdict drives per-case
|
| 585 |
+
# solving; honest MODELED/UNAVAILABLE when the Tower is offline (no fabrication).
|
| 586 |
+
sov_requested = bool(_SOV_OK and _sov and _sov.is_sovereign(model_id))
|
| 587 |
+
sov_state: str | None = None
|
| 588 |
+
sov_receipt = None
|
| 589 |
+
if sov_requested:
|
| 590 |
+
sov_probe = _sov.run_on_sovereign("", requested_model_id=model_id,
|
| 591 |
+
probe_only=True)
|
| 592 |
+
sov_state = sov_probe.get("state") # LIVE | MODELED | UNAVAILABLE
|
| 593 |
+
sov_receipt = _sov.receipt_block(sov_probe)
|
| 594 |
+
|
| 595 |
cases_in = suite["cases"]
|
| 596 |
suite_sha256 = _sha256_str(_canon(cases_in)) # lm-eval-style content version pin
|
| 597 |
results: list[dict[str, Any]] = []
|
| 598 |
by_cat: dict[str, dict[str, int]] = {}
|
| 599 |
|
| 600 |
for case in cases_in:
|
| 601 |
+
solved = _solve_case(case, model_id, snap, harness, sov_state=sov_state)
|
| 602 |
answer = solved["answer"]
|
| 603 |
label = solved["label"]
|
| 604 |
scorer_name = case.get("scorer", "exact")
|
|
|
|
| 677 |
}
|
| 678 |
|
| 679 |
# ── build the receipt payload (signed below) ──
|
| 680 |
+
if sov_requested:
|
| 681 |
+
# Sovereign run: the label IS the one-shot reachability verdict (never
|
| 682 |
+
# UNAVAILABLE just because the alias isn't a plain registry key).
|
| 683 |
+
honesty_label = sov_state or "UNAVAILABLE"
|
| 684 |
+
else:
|
| 685 |
+
honesty_label = "LIVE" if (snap.get("available") and snap.get("any_key_wired")) else "MODELED"
|
| 686 |
+
if model_id not in snap.get("models", {}):
|
| 687 |
+
honesty_label = "UNAVAILABLE"
|
| 688 |
|
| 689 |
receipt_body = {
|
| 690 |
"schema": SCHEMA,
|
|
|
|
| 696 |
"suite_version": suite["version"],
|
| 697 |
"suite_sha256": suite_sha256,
|
| 698 |
"model_id": model_id,
|
| 699 |
+
"model_known": (sov_requested or model_id in snap.get("models", {})),
|
| 700 |
+
"sovereign": sov_receipt, # Wave M: intended sovereign backend (None when not requested)
|
| 701 |
"harness_profile_id": harness_profile_id,
|
| 702 |
"harness": {"applied": harness.get("applied"), "available": harness.get("available"),
|
| 703 |
"profile_sha256": harness.get("profile_sha256"), "note": harness.get("note")},
|
|
|
|
| 825 |
],
|
| 826 |
"scorers": list(_SCORERS.keys()),
|
| 827 |
"run_endpoint": "POST " + base + "/run",
|
| 828 |
+
# Wave M (Dev 2): evaluate SZL's OWN governed model.
|
| 829 |
+
"run_on_sovereign": {
|
| 830 |
+
"available": bool(_SOV_OK),
|
| 831 |
+
"how": ("POST " + base + "/run with model_id='szl-sovereign-local' "
|
| 832 |
+
"(alias of registry backend 'sovereign_local'). Scores SZL's "
|
| 833 |
+
"own model via Dev-1's backend; honest MODELED/UNAVAILABLE "
|
| 834 |
+
"when the local Tower endpoint is unreachable (no fabrication)."),
|
| 835 |
+
"backend_id": "sovereign_local",
|
| 836 |
+
"model_slug": "llama3-szl-finetuned-q4",
|
| 837 |
+
},
|
| 838 |
"leaders_cited": LEADERS,
|
| 839 |
"lambda_posture": "advisory (Conjecture 1) — never green",
|
| 840 |
"doctrine": DOCTRINE, "kernel_commit": _KERNEL,
|
|
|
|
| 862 |
|
| 863 |
Body: {"suite": "core_honest_v1", "model_id": "claude_sonnet_4_6",
|
| 864 |
"harness_profile_id": "szl-honest-operator" (optional)}
|
| 865 |
+
|
| 866 |
+
Wave M (Dev 2): model_id="szl-sovereign-local" evaluates SZL's OWN
|
| 867 |
+
governed model through Dev-1's sovereign backend. When the local Tower
|
| 868 |
+
endpoint is unreachable the run degrades to honest MODELED/UNAVAILABLE and
|
| 869 |
+
the receipt records the intended sovereign backend — never fabricated.
|
| 870 |
"""
|
| 871 |
try:
|
| 872 |
body = await request.json()
|
szl_governed_rag.py
CHANGED
|
@@ -423,6 +423,17 @@ def _reg():
|
|
| 423 |
return _r
|
| 424 |
|
| 425 |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| 426 |
def _lambda_gm(axes: list[float]) -> float:
|
| 427 |
try:
|
| 428 |
return _reg()._lambda_gm(axes)
|
|
@@ -595,6 +606,37 @@ def query(query_text: str, corpus: list[dict[str, str]] | None = None,
|
|
| 595 |
model_note += (f" A harness_profile_id ('{harness_profile_id}') was supplied; the abstractive "
|
| 596 |
"path would apply it via szl_model_harness (MODELED disposition only).")
|
| 597 |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| 598 |
# per-claim citation map (the differentiator, made machine-checkable)
|
| 599 |
claim_citation_map = [
|
| 600 |
{"claim": c["claim"], "grounded": c["grounded"],
|
|
@@ -637,6 +679,7 @@ def query(query_text: str, corpus: list[dict[str, str]] | None = None,
|
|
| 637 |
"gate_reason": gate_reason,
|
| 638 |
"model_id": model_id or None,
|
| 639 |
"api_key_wired": api_key_wired,
|
|
|
|
| 640 |
"harness_profile_id": harness_profile_id or None,
|
| 641 |
"rag_state": rag_state,
|
| 642 |
"honesty_label": rag_state,
|
|
@@ -654,6 +697,10 @@ def query(query_text: str, corpus: list[dict[str, str]] | None = None,
|
|
| 654 |
"rag_state": rag_state,
|
| 655 |
"model_note": model_note,
|
| 656 |
"grounded_answer": gen["grounded_answer"],
|
|
|
|
|
|
|
|
|
|
|
|
|
| 657 |
"claims": gen["claims"],
|
| 658 |
"retrieval": retr,
|
| 659 |
"ragas": ragas,
|
|
@@ -685,7 +732,13 @@ def register(app: FastAPI, ns: str = "a11oy") -> dict:
|
|
| 685 |
{"query": "...", "corpus": [{"id","text","source"}]?, "model_id": "?",
|
| 686 |
"harness_profile_id": "?", "top_k": 4}
|
| 687 |
Honest 4xx on empty query; otherwise 200 with grounded answer + per-claim
|
| 688 |
-
citations + RAGAS scores + Λ-gate + SIGNED receipt (forum-ingested).
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| 689 |
try:
|
| 690 |
body = await request.json()
|
| 691 |
except Exception:
|
|
@@ -709,6 +762,8 @@ def register(app: FastAPI, ns: str = "a11oy") -> dict:
|
|
| 709 |
status_code=400)
|
| 710 |
return JSONResponse({
|
| 711 |
"grounded_answer": res["grounded_answer"],
|
|
|
|
|
|
|
| 712 |
"rag_state": res["rag_state"],
|
| 713 |
"model_note": res["model_note"],
|
| 714 |
"claims": res["claims"],
|
|
|
|
| 423 |
return _r
|
| 424 |
|
| 425 |
|
| 426 |
+
# Wave M (Dev 2): shared sovereign-flywheel bridge. Lets /rag/query run the
|
| 427 |
+
# abstractive rewrite on SZL's OWN governed model (sovereign_local) via Dev-1's
|
| 428 |
+
# registry backend; honest MODELED/UNAVAILABLE when the Tower is offline.
|
| 429 |
+
try:
|
| 430 |
+
import szl_sovereign_flywheel as _sov # noqa: F401
|
| 431 |
+
_SOV_OK = True
|
| 432 |
+
except Exception: # pragma: no cover — bridge missing → sovereign option simply off
|
| 433 |
+
_sov = None # type: ignore
|
| 434 |
+
_SOV_OK = False
|
| 435 |
+
|
| 436 |
+
|
| 437 |
def _lambda_gm(axes: list[float]) -> float:
|
| 438 |
try:
|
| 439 |
return _reg()._lambda_gm(axes)
|
|
|
|
| 606 |
model_note += (f" A harness_profile_id ('{harness_profile_id}') was supplied; the abstractive "
|
| 607 |
"path would apply it via szl_model_harness (MODELED disposition only).")
|
| 608 |
|
| 609 |
+
# ── Wave M (Dev 2): SOVEREIGN option ───────────────────────────────────────
|
| 610 |
+
# Run the abstractive rewrite on SZL's OWN governed model, grounded STRICTLY
|
| 611 |
+
# on the retrieved+cited passages. When the Tower is offline we keep the honest
|
| 612 |
+
# EXTRACTIVE answer and record the intended sovereign backend — no fabrication.
|
| 613 |
+
sovereign_answer = None
|
| 614 |
+
sovereign_block = None
|
| 615 |
+
if _SOV_OK and _sov and _sov.is_sovereign(model_id):
|
| 616 |
+
_ctx = "\n\n".join(
|
| 617 |
+
f"[{p['id']}] {p.get('text', '')}" for p in retr["retrieved"])
|
| 618 |
+
_sov_prompt = (
|
| 619 |
+
"Answer the question USING ONLY the sources below. Cite each source id "
|
| 620 |
+
"you rely on in square brackets. If the sources do not answer it, say so.\n\n"
|
| 621 |
+
f"SOURCES:\n{_ctx}\n\nQUESTION: {query_text}\n\nGROUNDED ANSWER:")
|
| 622 |
+
sov = _sov.run_on_sovereign(_sov_prompt, requested_model_id=model_id)
|
| 623 |
+
sovereign_block = _sov.receipt_block(sov)
|
| 624 |
+
rag_state = sov.get("state") # LIVE | MODELED | UNAVAILABLE
|
| 625 |
+
if sov.get("state") == "LIVE" and isinstance(sov.get("text"), str):
|
| 626 |
+
sovereign_answer = sov["text"]
|
| 627 |
+
model_note = ("LIVE abstractive rewrite from SZL's OWN sovereign_local model, "
|
| 628 |
+
"grounded on the SAME cited passages. Retrieval, grounding, "
|
| 629 |
+
"RAGAS, Λ-gate, and signature remain REAL.")
|
| 630 |
+
elif sov.get("state") == "MODELED":
|
| 631 |
+
model_note = ("SZL sovereign_local selected but the local node did not answer "
|
| 632 |
+
"live this request — returning the honest EXTRACTIVE grounded "
|
| 633 |
+
"answer (no model text fabricated). Intended sovereign backend recorded.")
|
| 634 |
+
else:
|
| 635 |
+
model_note = ("SZL sovereign_local selected but the local endpoint is unreachable "
|
| 636 |
+
"(SZL_LOCAL_LLM_URL unset / Tower offline) — returning the honest "
|
| 637 |
+
"EXTRACTIVE grounded answer. Intended sovereign backend recorded; "
|
| 638 |
+
"no model call attempted; no fabrication.")
|
| 639 |
+
|
| 640 |
# per-claim citation map (the differentiator, made machine-checkable)
|
| 641 |
claim_citation_map = [
|
| 642 |
{"claim": c["claim"], "grounded": c["grounded"],
|
|
|
|
| 679 |
"gate_reason": gate_reason,
|
| 680 |
"model_id": model_id or None,
|
| 681 |
"api_key_wired": api_key_wired,
|
| 682 |
+
"sovereign": sovereign_block, # Wave M: intended sovereign backend (None when not requested)
|
| 683 |
"harness_profile_id": harness_profile_id or None,
|
| 684 |
"rag_state": rag_state,
|
| 685 |
"honesty_label": rag_state,
|
|
|
|
| 697 |
"rag_state": rag_state,
|
| 698 |
"model_note": model_note,
|
| 699 |
"grounded_answer": gen["grounded_answer"],
|
| 700 |
+
# Wave M: the sovereign model's abstractive rewrite (LIVE only; None otherwise
|
| 701 |
+
# — the extractive grounded_answer above is ALWAYS the honest fallback).
|
| 702 |
+
"sovereign_answer": sovereign_answer,
|
| 703 |
+
"sovereign": sovereign_block,
|
| 704 |
"claims": gen["claims"],
|
| 705 |
"retrieval": retr,
|
| 706 |
"ragas": ragas,
|
|
|
|
| 732 |
{"query": "...", "corpus": [{"id","text","source"}]?, "model_id": "?",
|
| 733 |
"harness_profile_id": "?", "top_k": 4}
|
| 734 |
Honest 4xx on empty query; otherwise 200 with grounded answer + per-claim
|
| 735 |
+
citations + RAGAS scores + Λ-gate + SIGNED receipt (forum-ingested).
|
| 736 |
+
|
| 737 |
+
Wave M (Dev 2): model_id="szl-sovereign-local" runs the abstractive rewrite
|
| 738 |
+
on SZL's OWN governed model (Dev-1 backend), grounded on the same cited
|
| 739 |
+
passages. When the local Tower endpoint is unreachable the extractive
|
| 740 |
+
grounded answer is returned and the receipt records the intended sovereign
|
| 741 |
+
backend — no model response is ever fabricated."""
|
| 742 |
try:
|
| 743 |
body = await request.json()
|
| 744 |
except Exception:
|
|
|
|
| 762 |
status_code=400)
|
| 763 |
return JSONResponse({
|
| 764 |
"grounded_answer": res["grounded_answer"],
|
| 765 |
+
"sovereign_answer": res.get("sovereign_answer"), # Wave M: LIVE only, else None
|
| 766 |
+
"sovereign": res.get("sovereign"), # intended sovereign backend
|
| 767 |
"rag_state": res["rag_state"],
|
| 768 |
"model_note": res["model_note"],
|
| 769 |
"claims": res["claims"],
|
szl_model_harness.py
CHANGED
|
@@ -234,6 +234,17 @@ def _reg():
|
|
| 234 |
return _r
|
| 235 |
|
| 236 |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| 237 |
def _lambda_gm(axes: list[float]) -> float:
|
| 238 |
"""Reuse szl_llm_registry._lambda_gm; local geometric-mean fallback if the
|
| 239 |
registry import fails (never raises into the request path)."""
|
|
@@ -496,9 +507,51 @@ def apply(profile_id: str, model_id: str = "", prompt: str = "",
|
|
| 496 |
"kernel_commit": _KERNEL,
|
| 497 |
"conjecture_note": _CONJECTURE_NOTE,
|
| 498 |
}
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| 499 |
receipt["signature"] = _sign_receipt(receipt)
|
| 500 |
|
| 501 |
-
if
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| 502 |
response_text = (
|
| 503 |
f"[UNAVAILABLE] Profile '{profile_id}' body could not be resolved on disk "
|
| 504 |
f"and no {(profile.get('system_prompt_ref') or {}).get('env')} override is set. "
|
|
@@ -577,6 +630,17 @@ def register(app: FastAPI, ns: str = "a11oy") -> dict:
|
|
| 577 |
"forum": f"/api/{ns}/v1/llm/forum",
|
| 578 |
"registry": f"/api/{ns}/v1/llm/registry",
|
| 579 |
},
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| 580 |
"capability_ceiling": "Behavior transfer is MODELED — changes disposition, NOT capability. "
|
| 581 |
"Only original weights deliver capability (honest ceiling).",
|
| 582 |
"doctrine": DOCTRINE,
|
|
@@ -615,6 +679,12 @@ def register(app: FastAPI, ns: str = "a11oy") -> dict:
|
|
| 615 |
|
| 616 |
Body: {"profile_id": "szl-fable", "model_id": "claude_opus_4_8",
|
| 617 |
"prompt": "…", "axis_scores": [..], "max_tier": 4, "task_hint": ""}
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| 618 |
"""
|
| 619 |
try:
|
| 620 |
body = await request.json()
|
|
|
|
| 234 |
return _r
|
| 235 |
|
| 236 |
|
| 237 |
+
# Wave M (Dev 2): the shared sovereign-flywheel bridge. Routes an explicit
|
| 238 |
+
# sovereign request through Dev-1's registry backend (sovereign_local); degrades
|
| 239 |
+
# to honest MODELED/UNAVAILABLE when the local Tower endpoint is unreachable.
|
| 240 |
+
try:
|
| 241 |
+
import szl_sovereign_flywheel as _sov # noqa: F401
|
| 242 |
+
_SOV_OK = True
|
| 243 |
+
except Exception: # pragma: no cover — bridge missing → sovereign option simply off
|
| 244 |
+
_sov = None # type: ignore
|
| 245 |
+
_SOV_OK = False
|
| 246 |
+
|
| 247 |
+
|
| 248 |
def _lambda_gm(axes: list[float]) -> float:
|
| 249 |
"""Reuse szl_llm_registry._lambda_gm; local geometric-mean fallback if the
|
| 250 |
registry import fails (never raises into the request path)."""
|
|
|
|
| 507 |
"kernel_commit": _KERNEL,
|
| 508 |
"conjecture_note": _CONJECTURE_NOTE,
|
| 509 |
}
|
| 510 |
+
# ── Wave M (Dev 2): SOVEREIGN option ──────────────────────────────────────
|
| 511 |
+
# If the caller asked to run this on SZL's OWN governed model, route the
|
| 512 |
+
# profile-applied prompt through Dev-1's sovereign_local backend. The receipt
|
| 513 |
+
# ALWAYS records the intended sovereign backend; when the Tower is offline we
|
| 514 |
+
# return honest MODELED/UNAVAILABLE and NEVER fabricate a model response.
|
| 515 |
+
sovereign_requested = bool(_SOV_OK and _sov and _sov.is_sovereign(model_id))
|
| 516 |
+
if sovereign_requested:
|
| 517 |
+
# Compose the sovereign prompt: profile body (if resolved) as a system
|
| 518 |
+
# preface + the user prompt. The body TEXT is never surfaced in the
|
| 519 |
+
# receipt (sha256 only) — it is only sent to the local, sovereign node.
|
| 520 |
+
sys_layer = (bm.get("_body") or "") if body_available else ""
|
| 521 |
+
sov_prompt = ((sys_layer + "\n\n") if sys_layer else "") + prompt
|
| 522 |
+
sov = _sov.run_on_sovereign(sov_prompt, requested_model_id=model_id)
|
| 523 |
+
receipt["sovereign"] = _sov.receipt_block(sov)
|
| 524 |
+
receipt["model_id"] = _sov.SOVEREIGN_BACKEND_ID
|
| 525 |
+
receipt["model_display"] = "SZL Sovereign Local (llama3-szl-finetuned-q4)"
|
| 526 |
+
receipt["honesty_label"] = sov.get("state")
|
| 527 |
+
|
| 528 |
receipt["signature"] = _sign_receipt(receipt)
|
| 529 |
|
| 530 |
+
if sovereign_requested:
|
| 531 |
+
_st = sov.get("state")
|
| 532 |
+
if _st == "LIVE":
|
| 533 |
+
response_text = (
|
| 534 |
+
"[LIVE · SOVEREIGN] Ran the '" + profile_id + "' behavior profile on "
|
| 535 |
+
"SZL's OWN governed model (sovereign_local, llama3-szl-finetuned-q4) "
|
| 536 |
+
"— REAL generation this request. " + (sov.get("note") or ""))
|
| 537 |
+
elif _st == "MODELED":
|
| 538 |
+
response_text = (
|
| 539 |
+
"[HONEST STUB · MODELED · SOVEREIGN] Would run the '" + profile_id +
|
| 540 |
+
"' profile on SZL's sovereign_local model, but the local Tower node "
|
| 541 |
+
"did not answer live this request. No model output fabricated; the "
|
| 542 |
+
"intended sovereign backend + Λ-gate + provenance sha256 + signature "
|
| 543 |
+
"are REAL. " + (sov.get("note") or ""))
|
| 544 |
+
else:
|
| 545 |
+
response_text = (
|
| 546 |
+
"[UNAVAILABLE · SOVEREIGN] The '" + profile_id + "' profile targeted "
|
| 547 |
+
"SZL's sovereign_local model, but the local endpoint is unreachable "
|
| 548 |
+
"(SZL_LOCAL_LLM_URL unset / Tower offline). No model call attempted; "
|
| 549 |
+
"the intended sovereign backend is recorded in the receipt; no output "
|
| 550 |
+
"fabricated. " + (sov.get("note") or ""))
|
| 551 |
+
harness_state = _st
|
| 552 |
+
model_display = receipt["model_display"]
|
| 553 |
+
chosen_model_id = receipt["model_id"]
|
| 554 |
+
elif not body_available:
|
| 555 |
response_text = (
|
| 556 |
f"[UNAVAILABLE] Profile '{profile_id}' body could not be resolved on disk "
|
| 557 |
f"and no {(profile.get('system_prompt_ref') or {}).get('env')} override is set. "
|
|
|
|
| 630 |
"forum": f"/api/{ns}/v1/llm/forum",
|
| 631 |
"registry": f"/api/{ns}/v1/llm/registry",
|
| 632 |
},
|
| 633 |
+
# Wave M (Dev 2): run this profile on SZL's OWN sovereign local model.
|
| 634 |
+
"run_on_sovereign": {
|
| 635 |
+
"available": bool(_SOV_OK),
|
| 636 |
+
"how": ("POST /harness/apply with model_id='szl-sovereign-local' "
|
| 637 |
+
"(alias of registry backend 'sovereign_local'). Routes the "
|
| 638 |
+
"profile-applied prompt through the local Tower via Dev-1's "
|
| 639 |
+
"registry backend; honest MODELED/UNAVAILABLE when offline."),
|
| 640 |
+
"backend_id": "sovereign_local",
|
| 641 |
+
"model_slug": "llama3-szl-finetuned-q4",
|
| 642 |
+
"provider_provenance": "SZL sovereign (Ollama, local, Doctrine-v11 system prompt)",
|
| 643 |
+
},
|
| 644 |
"capability_ceiling": "Behavior transfer is MODELED — changes disposition, NOT capability. "
|
| 645 |
"Only original weights deliver capability (honest ceiling).",
|
| 646 |
"doctrine": DOCTRINE,
|
|
|
|
| 679 |
|
| 680 |
Body: {"profile_id": "szl-fable", "model_id": "claude_opus_4_8",
|
| 681 |
"prompt": "…", "axis_scores": [..], "max_tier": 4, "task_hint": ""}
|
| 682 |
+
|
| 683 |
+
Wave M (Dev 2): pass model_id="szl-sovereign-local" (or the registry id
|
| 684 |
+
"sovereign_local") to run this profile on SZL's OWN governed model via
|
| 685 |
+
Dev-1's sovereign backend. When the local Tower endpoint is unreachable
|
| 686 |
+
the apply returns honest MODELED/UNAVAILABLE and the receipt still records
|
| 687 |
+
the intended sovereign backend — no model response is ever fabricated.
|
| 688 |
"""
|
| 689 |
try:
|
| 690 |
body = await request.json()
|
szl_sovereign_flywheel.py
ADDED
|
@@ -0,0 +1,324 @@
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| 1 |
+
# SPDX-License-Identifier: Apache-2.0
|
| 2 |
+
# © 2026 Lutar, Stephen P. — SZL Holdings · ORCID 0009-0001-0110-4173 · Doctrine v11
|
| 3 |
+
# Authored by Yachay (CTO) + Perplexity Computer Agent — a11oy Sovereign Flywheel bridge
|
| 4 |
+
# Co-Authored-By: Perplexity Computer Agent <agent@perplexity.ai>
|
| 5 |
+
# Signed-off-by: Stephen P. Lutar Jr. <stephenlutar2@gmail.com>
|
| 6 |
+
"""
|
| 7 |
+
szl_sovereign_flywheel — the single call path that lets the GOVERNED FLYWHEEL
|
| 8 |
+
(harness /harness/apply, eval-arena /eval/run, agent-loop /agentloop/run, RAG
|
| 9 |
+
/rag/query) run on SZL's OWN sovereign local model.
|
| 10 |
+
|
| 11 |
+
Wave M, Dev 2. This module DOES NOT re-implement the sovereign backend — it is a
|
| 12 |
+
thin, guarded ADAPTER over the first-class `sovereign_local` backend that Dev 1
|
| 13 |
+
registered in `szl_llm_registry.py` (model tag `llama3-szl-finetuned-q4`, targets
|
| 14 |
+
`SZL_LOCAL_LLM_URL`, provider provenance "SZL sovereign (Ollama, local,
|
| 15 |
+
Doctrine-v11 system prompt)"). Every flywheel flow imports THIS module and calls
|
| 16 |
+
`run_on_sovereign(...)`, so the whole loop routes through exactly ONE code path to
|
| 17 |
+
Dev-1's registry functions (`sovereign_probe` / `sovereign_generate`).
|
| 18 |
+
|
| 19 |
+
DEPENDENCY (Wave M coordination): the routed backend `sovereign_local` lives in
|
| 20 |
+
szl_llm_registry.py. As of Wave M it is present on main (PR #791, merged). If a
|
| 21 |
+
future refactor removes those registry helpers this module degrades to an honest
|
| 22 |
+
UNAVAILABLE (never fabricates a response) — the intended sovereign backend is
|
| 23 |
+
still recorded in the receipt. We code against the backend id, not a copy of it.
|
| 24 |
+
|
| 25 |
+
HONESTY (Doctrine v11 LOCKED):
|
| 26 |
+
* We NEVER fabricate a model response. When the Tower / local endpoint is not
|
| 27 |
+
reachable (CI, cloud, air-gap not up) `run_on_sovereign` returns an honest
|
| 28 |
+
MODELED / UNAVAILABLE result whose `text` is None and whose receipt STILL
|
| 29 |
+
records the intended sovereign backend (id, slug, url, provider, label).
|
| 30 |
+
* `state` is one of:
|
| 31 |
+
LIVE — the local node answered live THIS request (real text).
|
| 32 |
+
MODELED — env base present but the node did not answer live this
|
| 33 |
+
request (honest stub; no fabricated text).
|
| 34 |
+
UNAVAILABLE — SZL_LOCAL_LLM_URL unset (no local fleet base) OR the
|
| 35 |
+
registry sovereign backend could not be imported.
|
| 36 |
+
* Λ = Conjecture 1 (advisory, never "green", never a theorem). Nothing here
|
| 37 |
+
touches the locked-8.
|
| 38 |
+
|
| 39 |
+
This closes the loop: SZL's OWN governed model, evaluated + gated + receipted by
|
| 40 |
+
SZL's OWN stack. Additive; guarded; pure stdlib (the HTTP call itself lives in the
|
| 41 |
+
registry). Nothing added to the locked-8. Doctrine v11 LOCKED — 749/14/163 — c7c0ba17.
|
| 42 |
+
"""
|
| 43 |
+
from __future__ import annotations
|
| 44 |
+
|
| 45 |
+
from datetime import datetime, timezone
|
| 46 |
+
from typing import Any
|
| 47 |
+
|
| 48 |
+
DOCTRINE = "v11"
|
| 49 |
+
_KERNEL = "c7c0ba17"
|
| 50 |
+
_CONJECTURE_NOTE = "Λ = Conjecture 1 — NOT a theorem. Advisory, never 'green'."
|
| 51 |
+
|
| 52 |
+
# The registry backend id Dev 1 registered. The brief refers to it as
|
| 53 |
+
# "szl-sovereign-local"; the registry entry uses the id "sovereign_local" with
|
| 54 |
+
# slug "llama3-szl-finetuned-q4". We accept BOTH spellings as the same request so
|
| 55 |
+
# a caller can use either the brief's name or the registry id.
|
| 56 |
+
SOVEREIGN_BACKEND_ID = "sovereign_local"
|
| 57 |
+
SOVEREIGN_MODEL_SLUG = "llama3-szl-finetuned-q4"
|
| 58 |
+
SOVEREIGN_PROVIDER = "SZL sovereign (Ollama, local, Doctrine-v11 system prompt)"
|
| 59 |
+
SOVEREIGN_ENV_VAR = "SZL_LOCAL_LLM_URL"
|
| 60 |
+
_SOVEREIGN_ALIASES = frozenset({
|
| 61 |
+
"sovereign_local", "szl-sovereign-local", "szl_sovereign_local",
|
| 62 |
+
"sovereign-local", "sovereign", "szl-sovereign",
|
| 63 |
+
})
|
| 64 |
+
|
| 65 |
+
|
| 66 |
+
def _now() -> str:
|
| 67 |
+
return datetime.now(timezone.utc).isoformat().replace("+00:00", "Z")
|
| 68 |
+
|
| 69 |
+
|
| 70 |
+
def is_sovereign(model_id: str | None) -> bool:
|
| 71 |
+
"""True when the caller asked for SZL's sovereign local backend (any alias).
|
| 72 |
+
|
| 73 |
+
Accepts the brief's `szl-sovereign-local`, the registry id `sovereign_local`,
|
| 74 |
+
and a few obvious spellings. Case-insensitive; never raises.
|
| 75 |
+
"""
|
| 76 |
+
if not model_id:
|
| 77 |
+
return False
|
| 78 |
+
return str(model_id).strip().lower().replace(" ", "") in {
|
| 79 |
+
a.replace(" ", "") for a in _SOVEREIGN_ALIASES
|
| 80 |
+
}
|
| 81 |
+
|
| 82 |
+
|
| 83 |
+
def _reg():
|
| 84 |
+
"""Import Dev-1's registry (the sovereign backend lives there). Mirror the
|
| 85 |
+
serve.py resolution order: prefer the extracted substrate package, fall back
|
| 86 |
+
to the local module, so we bind the SAME instance serve.py loaded."""
|
| 87 |
+
try: # pragma: no cover — substrate package path (in-image)
|
| 88 |
+
from szl_substrate import szl_llm_registry as _r # type: ignore
|
| 89 |
+
return _r
|
| 90 |
+
except Exception:
|
| 91 |
+
import szl_llm_registry as _r
|
| 92 |
+
return _r
|
| 93 |
+
|
| 94 |
+
|
| 95 |
+
def intended_backend() -> dict[str, Any]:
|
| 96 |
+
"""The intended sovereign backend descriptor — recorded in EVERY receipt,
|
| 97 |
+
reachable or not, so an offline run still names WHAT WOULD RUN.
|
| 98 |
+
|
| 99 |
+
Reads the live registry entry when importable (single source of truth); falls
|
| 100 |
+
back to the module constants if the registry can't be imported (still honest).
|
| 101 |
+
"""
|
| 102 |
+
desc: dict[str, Any] = {
|
| 103 |
+
"requested_model_id": None, # filled by run_on_sovereign
|
| 104 |
+
"backend_id": SOVEREIGN_BACKEND_ID,
|
| 105 |
+
"model_slug": SOVEREIGN_MODEL_SLUG,
|
| 106 |
+
"provider_provenance": SOVEREIGN_PROVIDER,
|
| 107 |
+
"env_var": SOVEREIGN_ENV_VAR,
|
| 108 |
+
"base_url": None,
|
| 109 |
+
"registry_wired": False,
|
| 110 |
+
"source": "module_constants",
|
| 111 |
+
}
|
| 112 |
+
try:
|
| 113 |
+
reg = _reg()
|
| 114 |
+
entry = getattr(reg, "_MODEL_BY_ID", {}).get(SOVEREIGN_BACKEND_ID)
|
| 115 |
+
if isinstance(entry, dict):
|
| 116 |
+
desc["model_slug"] = entry.get("model_slug", SOVEREIGN_MODEL_SLUG)
|
| 117 |
+
desc["backend_id"] = entry.get("model_id", SOVEREIGN_BACKEND_ID)
|
| 118 |
+
desc["registry_wired"] = True
|
| 119 |
+
desc["source"] = "szl_llm_registry (Dev-1 backend)"
|
| 120 |
+
# resolve the configured base URL (never the secret — this is a URL/env)
|
| 121 |
+
base_fn = getattr(reg, "_sovereign_base", None)
|
| 122 |
+
if callable(base_fn):
|
| 123 |
+
desc["base_url"] = base_fn() or None
|
| 124 |
+
slug_fn = getattr(reg, "_sovereign_model_slug", None)
|
| 125 |
+
if callable(slug_fn):
|
| 126 |
+
desc["served_model_tag"] = slug_fn()
|
| 127 |
+
except Exception as e: # registry not importable → honest, still records intent
|
| 128 |
+
desc["registry_import_error"] = repr(e)
|
| 129 |
+
desc["dependency_note"] = (
|
| 130 |
+
"szl_llm_registry sovereign backend not importable in this runtime; "
|
| 131 |
+
"recorded the intended backend from module constants — no fabrication.")
|
| 132 |
+
return desc
|
| 133 |
+
|
| 134 |
+
|
| 135 |
+
def run_on_sovereign(prompt: str, *, requested_model_id: str = SOVEREIGN_BACKEND_ID,
|
| 136 |
+
probe_only: bool = False) -> dict[str, Any]:
|
| 137 |
+
"""Route ONE call through Dev-1's sovereign_local backend. NEVER fabricates.
|
| 138 |
+
|
| 139 |
+
Returns a dict:
|
| 140 |
+
{
|
| 141 |
+
state: "LIVE" | "MODELED" | "UNAVAILABLE",
|
| 142 |
+
live: bool,
|
| 143 |
+
text: str | None, # REAL model text ONLY when state == LIVE
|
| 144 |
+
api_style: str | None, # ollama /api/generate | openai /v1 ... (live only)
|
| 145 |
+
backend: {intended backend descriptor + reachability},
|
| 146 |
+
note: str, # honest human-readable label
|
| 147 |
+
conjecture_note, doctrine, kernel_commit,
|
| 148 |
+
}
|
| 149 |
+
|
| 150 |
+
state semantics:
|
| 151 |
+
LIVE — SZL_LOCAL_LLM_URL set AND the node answered live THIS request.
|
| 152 |
+
MODELED — env base present but node did not answer live (honest stub).
|
| 153 |
+
UNAVAILABLE — no env base (no local fleet) OR registry import failed.
|
| 154 |
+
"""
|
| 155 |
+
prompt = str(prompt or "")
|
| 156 |
+
backend = intended_backend()
|
| 157 |
+
backend["requested_model_id"] = requested_model_id
|
| 158 |
+
backend["probed_at"] = _now()
|
| 159 |
+
|
| 160 |
+
out: dict[str, Any] = {
|
| 161 |
+
"state": "UNAVAILABLE",
|
| 162 |
+
"live": False,
|
| 163 |
+
"text": None,
|
| 164 |
+
"api_style": None,
|
| 165 |
+
"backend": backend,
|
| 166 |
+
"note": "",
|
| 167 |
+
"conjecture_note": _CONJECTURE_NOTE,
|
| 168 |
+
"doctrine": DOCTRINE,
|
| 169 |
+
"kernel_commit": _KERNEL,
|
| 170 |
+
}
|
| 171 |
+
|
| 172 |
+
# 1) reachability probe (short timeout) — reflect it in the backend block
|
| 173 |
+
try:
|
| 174 |
+
reg = _reg()
|
| 175 |
+
probe = reg.sovereign_probe() # {env_present, live, models, base_url, note, ...}
|
| 176 |
+
except Exception as e: # registry / sovereign helpers unavailable
|
| 177 |
+
backend["reachable"] = False
|
| 178 |
+
backend["probe_error"] = repr(e)
|
| 179 |
+
out["note"] = (
|
| 180 |
+
"UNAVAILABLE — szl_llm_registry sovereign backend not importable in this "
|
| 181 |
+
"runtime; no model call attempted; intended sovereign backend recorded; "
|
| 182 |
+
"no response fabricated.")
|
| 183 |
+
return out
|
| 184 |
+
|
| 185 |
+
backend["reachable"] = bool(probe.get("live"))
|
| 186 |
+
backend["env_present"] = bool(probe.get("env_present"))
|
| 187 |
+
backend["base_url"] = probe.get("base_url") or backend.get("base_url")
|
| 188 |
+
backend["served_models"] = probe.get("models", [])
|
| 189 |
+
backend["probe_note"] = probe.get("note")
|
| 190 |
+
|
| 191 |
+
if not probe.get("env_present"):
|
| 192 |
+
out["state"] = "UNAVAILABLE"
|
| 193 |
+
out["note"] = (
|
| 194 |
+
f"UNAVAILABLE — {SOVEREIGN_ENV_VAR} is not set, so there is no local "
|
| 195 |
+
"sovereign fleet base to reach (CI / cloud / Tower offline). No model "
|
| 196 |
+
"call attempted; the intended sovereign backend "
|
| 197 |
+
f"('{backend['backend_id']}', slug '{backend['model_slug']}') is still "
|
| 198 |
+
"recorded in the receipt. No response fabricated.")
|
| 199 |
+
return out
|
| 200 |
+
|
| 201 |
+
if not probe.get("live"):
|
| 202 |
+
out["state"] = "MODELED"
|
| 203 |
+
out["note"] = (
|
| 204 |
+
f"MODELED — {SOVEREIGN_ENV_VAR} is set ({backend.get('base_url')}) but the "
|
| 205 |
+
"sovereign node did not answer live THIS request (honest stub). No model "
|
| 206 |
+
"text fabricated; the intended sovereign backend is recorded. "
|
| 207 |
+
f"Probe: {probe.get('note')}")
|
| 208 |
+
return out
|
| 209 |
+
|
| 210 |
+
# 2) node is live. If probe_only, report LIVE reachability without generating.
|
| 211 |
+
if probe_only:
|
| 212 |
+
out["state"] = "LIVE"
|
| 213 |
+
out["live"] = True
|
| 214 |
+
out["api_style"] = probe.get("api_style")
|
| 215 |
+
out["note"] = (
|
| 216 |
+
"LIVE — sovereign node reachable this request (probe only, no generation). "
|
| 217 |
+
f"Served: {', '.join(backend.get('served_models') or []) or '(none reported)'}")
|
| 218 |
+
return out
|
| 219 |
+
|
| 220 |
+
# 3) REAL generation through Dev-1's sovereign_generate (never fabricated)
|
| 221 |
+
try:
|
| 222 |
+
gen = reg.sovereign_generate(prompt) # {wired, live, text, api_style, ...}
|
| 223 |
+
except Exception as e:
|
| 224 |
+
out["state"] = "MODELED"
|
| 225 |
+
out["note"] = (
|
| 226 |
+
"MODELED — sovereign node probed live but sovereign_generate raised "
|
| 227 |
+
f"({e!r}); no text fabricated; intended backend recorded.")
|
| 228 |
+
return out
|
| 229 |
+
|
| 230 |
+
if gen.get("live") and isinstance(gen.get("text"), str):
|
| 231 |
+
out["state"] = "LIVE"
|
| 232 |
+
out["live"] = True
|
| 233 |
+
out["text"] = gen["text"]
|
| 234 |
+
out["api_style"] = gen.get("api_style")
|
| 235 |
+
backend["served_model_tag"] = gen.get("model")
|
| 236 |
+
out["note"] = (
|
| 237 |
+
"LIVE — REAL generation from SZL's sovereign local model this request "
|
| 238 |
+
f"({gen.get('api_style')}). Provider: {SOVEREIGN_PROVIDER}.")
|
| 239 |
+
if isinstance(gen.get("raw"), dict):
|
| 240 |
+
out["raw"] = gen["raw"]
|
| 241 |
+
return out
|
| 242 |
+
|
| 243 |
+
# env present, probe live, but generate did not return live text → honest MODELED
|
| 244 |
+
out["state"] = "MODELED"
|
| 245 |
+
out["note"] = (
|
| 246 |
+
"MODELED — sovereign node reachable but did not return live text this "
|
| 247 |
+
f"request (honest stub). No text fabricated. Detail: {gen.get('note')}")
|
| 248 |
+
return out
|
| 249 |
+
|
| 250 |
+
|
| 251 |
+
def receipt_block(sov: dict[str, Any]) -> dict[str, Any]:
|
| 252 |
+
"""Compact, receipt-embeddable summary of a run_on_sovereign() result.
|
| 253 |
+
|
| 254 |
+
Records the INTENDED sovereign backend + honest state on EVERY run — reachable
|
| 255 |
+
or not — so an offline flywheel run still proves which sovereign backend it
|
| 256 |
+
would have used (never fabricates text into the receipt).
|
| 257 |
+
"""
|
| 258 |
+
b = sov.get("backend") or {}
|
| 259 |
+
return {
|
| 260 |
+
"requested": b.get("requested_model_id"),
|
| 261 |
+
"backend_id": b.get("backend_id"),
|
| 262 |
+
"model_slug": b.get("model_slug"),
|
| 263 |
+
"provider_provenance": b.get("provider_provenance"),
|
| 264 |
+
"env_var": b.get("env_var"),
|
| 265 |
+
"base_url": b.get("base_url"),
|
| 266 |
+
"registry_wired": b.get("registry_wired"),
|
| 267 |
+
"reachable": b.get("reachable"),
|
| 268 |
+
"env_present": b.get("env_present"),
|
| 269 |
+
"served_models": b.get("served_models"),
|
| 270 |
+
"state": sov.get("state"),
|
| 271 |
+
"live": sov.get("live"),
|
| 272 |
+
"api_style": sov.get("api_style"),
|
| 273 |
+
# text is recorded ONLY when LIVE (real); never fabricated otherwise
|
| 274 |
+
"text_present": bool(sov.get("text")),
|
| 275 |
+
"note": sov.get("note"),
|
| 276 |
+
"conjecture_note": _CONJECTURE_NOTE,
|
| 277 |
+
"dependency": ("routes through szl_llm_registry.sovereign_local (Dev-1 "
|
| 278 |
+
"backend, Wave M PR #791). Codes against the backend id; "
|
| 279 |
+
"degrades to honest UNAVAILABLE if that backend is absent."),
|
| 280 |
+
}
|
| 281 |
+
|
| 282 |
+
|
| 283 |
+
def selected_label(sov: dict[str, Any]) -> str:
|
| 284 |
+
"""One-line honest label for the flow's `_selected`/`honesty_label` surface."""
|
| 285 |
+
st = sov.get("state")
|
| 286 |
+
if st == "LIVE":
|
| 287 |
+
return "LIVE (SZL sovereign local model — real generation this request)"
|
| 288 |
+
if st == "MODELED":
|
| 289 |
+
return "MODELED (SZL sovereign backend selected; node not live this request — no fabrication)"
|
| 290 |
+
return "UNAVAILABLE (SZL sovereign backend selected; local endpoint unreachable — no fabrication)"
|
| 291 |
+
|
| 292 |
+
|
| 293 |
+
def _selftest() -> None: # pragma: no cover — `python3 szl_sovereign_flywheel.py`
|
| 294 |
+
# alias detection
|
| 295 |
+
assert is_sovereign("szl-sovereign-local")
|
| 296 |
+
assert is_sovereign("sovereign_local")
|
| 297 |
+
assert is_sovereign("SOVEREIGN-LOCAL")
|
| 298 |
+
assert not is_sovereign("claude_opus_4_8")
|
| 299 |
+
assert not is_sovereign("")
|
| 300 |
+
# intended backend always records the sovereign identity, reachable or not
|
| 301 |
+
b = intended_backend()
|
| 302 |
+
assert b["backend_id"] == SOVEREIGN_BACKEND_ID
|
| 303 |
+
assert b["model_slug"] == SOVEREIGN_MODEL_SLUG
|
| 304 |
+
assert b["provider_provenance"] == SOVEREIGN_PROVIDER
|
| 305 |
+
# with no SZL_LOCAL_LLM_URL in this env → honest UNAVAILABLE, no fabricated text
|
| 306 |
+
r = run_on_sovereign("State your doctrine in one line.")
|
| 307 |
+
assert r["state"] in ("UNAVAILABLE", "MODELED", "LIVE")
|
| 308 |
+
if r["state"] != "LIVE":
|
| 309 |
+
assert r["text"] is None, "no text may be fabricated when not LIVE"
|
| 310 |
+
rb = receipt_block(r)
|
| 311 |
+
assert rb["backend_id"] == SOVEREIGN_BACKEND_ID
|
| 312 |
+
assert rb["model_slug"] == SOVEREIGN_MODEL_SLUG
|
| 313 |
+
assert rb["state"] == r["state"]
|
| 314 |
+
assert rb["text_present"] == bool(r["text"])
|
| 315 |
+
lbl = selected_label(r)
|
| 316 |
+
assert isinstance(lbl, str) and lbl
|
| 317 |
+
print(f"szl_sovereign_flywheel: ALL OK — is_sovereign works, intended backend "
|
| 318 |
+
f"recorded, run_on_sovereign honest state={r['state']} "
|
| 319 |
+
f"(text fabricated? {'no' if r['text'] is None else 'LIVE-real'}), "
|
| 320 |
+
f"receipt_block records intended backend. Λ=Conjecture 1.")
|
| 321 |
+
|
| 322 |
+
|
| 323 |
+
if __name__ == "__main__":
|
| 324 |
+
_selftest()
|