betterwithage Claude Opus 4.7 commited on
Commit
401058f
·
verified ·
1 Parent(s): c107f18

deploy(hf): sync szl-holdings/a11oy@main derived COPY set

Browse files

Reusable Dockerfile-COPY-derived deploy from szl-holdings/a11oy main.
Files: 943 Pruned: 0
Derived from Dockerfile COPY sources (NO hand-maintained allowlist).

Signed-off-by: SZL Holdings <noreply@szlholdings.ai>
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>

szl_agent_loop_governed.py CHANGED
@@ -128,6 +128,16 @@ except Exception:
128
  _APPROVAL_OK = False
129
  _approval_interrupt = None
130
 
 
 
 
 
 
 
 
 
 
 
131
 
132
  def _now() -> str:
133
  return datetime.now(timezone.utc).isoformat()
@@ -185,6 +195,21 @@ def run_loop(task: str,
185
  max_retries = max(0, min(3, int(max_retries)))
186
  grant = approval if isinstance(approval, dict) else None
187
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
188
  if not _ENGINE_OK:
189
  return {
190
  "ok": False,
@@ -404,6 +429,7 @@ def run_loop(task: str,
404
  "task": task,
405
  "mode": plan_mode,
406
  "model_id": model_id or "(engine default)",
 
407
  "harness_profile_id": harness_profile_id or None,
408
  "eval_suite_default": eval_suite or "(per-step mode heuristic)",
409
  "max_retries": max_retries,
@@ -475,6 +501,9 @@ def run_loop(task: str,
475
  "steps": steps_out,
476
  "aggregate": receipt_body["aggregate"],
477
  "composite_receipt": {"body": receipt_body, "dsse": dsse, "signing": signing},
 
 
 
478
  "forum_ingest": forum,
479
  "composes": receipt_body["composes"],
480
  "leaders_cited": LEADERS,
@@ -642,6 +671,18 @@ def register(app, ns: str = "a11oy", sign_fn: Optional[Callable[[dict], dict]] =
642
  "self_eval_available": _ARENA_OK,
643
  "behavior_profile_available": _HARNESS_OK,
644
  "human_gate_available": _APPROVAL_OK,
 
 
 
 
 
 
 
 
 
 
 
 
645
  },
646
  "eval_suites": eval_suites,
647
  "approval_gate_enabled": os.environ.get("A11OY_APPROVAL_INTERRUPT") == "1",
 
128
  _APPROVAL_OK = False
129
  _approval_interrupt = None
130
 
131
+ # Wave M (Dev 2): shared sovereign-flywheel bridge. Lets the governed loop run on
132
+ # SZL's OWN model (sovereign_local) via Dev-1's registry backend; honest
133
+ # MODELED/UNAVAILABLE when the local Tower endpoint is unreachable (no fabrication).
134
+ try:
135
+ import szl_sovereign_flywheel as _sov # noqa: F401
136
+ _SOV_OK = True
137
+ except Exception: # pragma: no cover — bridge missing → sovereign option simply off
138
+ _sov = None # type: ignore
139
+ _SOV_OK = False
140
+
141
 
142
  def _now() -> str:
143
  return datetime.now(timezone.utc).isoformat()
 
195
  max_retries = max(0, min(3, int(max_retries)))
196
  grant = approval if isinstance(approval, dict) else None
197
 
198
+ # ── Wave M (Dev 2): sovereign preflight ───────────────────────────────────
199
+ # If the caller asked to run this loop on SZL's OWN governed model, probe the
200
+ # sovereign backend ONCE (Dev-1 registry) and carry the honest verdict into the
201
+ # composite receipt. The per-step ACT still flows through the engine with
202
+ # want_model=model_id; the sovereign block records the intended backend +
203
+ # reachability so an offline run is honestly MODELED/UNAVAILABLE (no fabrication).
204
+ sovereign_requested = bool(_SOV_OK and _sov and _sov.is_sovereign(model_id))
205
+ sovereign_block = None
206
+ sovereign_state = None
207
+ if sovereign_requested:
208
+ _sp = _sov.run_on_sovereign(task or "State your doctrine in one line.",
209
+ requested_model_id=model_id, probe_only=True)
210
+ sovereign_state = _sp.get("state")
211
+ sovereign_block = _sov.receipt_block(_sp)
212
+
213
  if not _ENGINE_OK:
214
  return {
215
  "ok": False,
 
429
  "task": task,
430
  "mode": plan_mode,
431
  "model_id": model_id or "(engine default)",
432
+ "sovereign": sovereign_block, # Wave M: intended sovereign backend (None when not requested)
433
  "harness_profile_id": harness_profile_id or None,
434
  "eval_suite_default": eval_suite or "(per-step mode heuristic)",
435
  "max_retries": max_retries,
 
501
  "steps": steps_out,
502
  "aggregate": receipt_body["aggregate"],
503
  "composite_receipt": {"body": receipt_body, "dsse": dsse, "signing": signing},
504
+ "sovereign": sovereign_block, # Wave M: honest intended-backend + reachability
505
+ "sovereign_label": (_sov.selected_label({"state": sovereign_state})
506
+ if sovereign_requested and _SOV_OK and _sov else None),
507
  "forum_ingest": forum,
508
  "composes": receipt_body["composes"],
509
  "leaders_cited": LEADERS,
 
671
  "self_eval_available": _ARENA_OK,
672
  "behavior_profile_available": _HARNESS_OK,
673
  "human_gate_available": _APPROVAL_OK,
674
+ "sovereign_available": _SOV_OK,
675
+ },
676
+ # Wave M (Dev 2): run this governed loop on SZL's OWN model.
677
+ "run_on_sovereign": {
678
+ "available": bool(_SOV_OK),
679
+ "how": ("POST /agentloop/run with model_id='szl-sovereign-local' "
680
+ "(alias of registry backend 'sovereign_local'). The loop "
681
+ "probes the local Tower via Dev-1's backend and records the "
682
+ "intended sovereign backend in the composite receipt; honest "
683
+ "MODELED/UNAVAILABLE when offline (no fabrication)."),
684
+ "backend_id": "sovereign_local",
685
+ "model_slug": "llama3-szl-finetuned-q4",
686
  },
687
  "eval_suites": eval_suites,
688
  "approval_gate_enabled": os.environ.get("A11OY_APPROVAL_INTERRUPT") == "1",
szl_eval_arena.py CHANGED
@@ -366,6 +366,17 @@ _SCORERS: dict[str, Callable[[str, str], tuple[bool, str]]] = {
366
  # answer is derived ONLY from the case's own `expected`/category — it is an honest
367
  # "reference oracle" stub, NOT a claim that a model produced it.
368
  # ─────────────────────────────────────────────────────────────────────────────
 
 
 
 
 
 
 
 
 
 
 
369
  def _registry_snapshot() -> dict[str, Any]:
370
  """Best-effort read of the registry (model roster + key-wired status)."""
371
  out = {"available": False, "models": {}, "any_key_wired": False}
@@ -430,8 +441,45 @@ def _control_benign_answer(case: dict[str, Any]) -> str:
430
 
431
 
432
  def _solve_case(case: dict[str, Any], model_id: str, snap: dict[str, Any],
433
- harness: dict[str, Any]) -> dict[str, Any]:
434
- """Produce an answer for one case (honest MODELED unless a key is wired)."""
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
435
  live = snap.get("available") and snap.get("any_key_wired")
436
  label = "LIVE" if live else "MODELED"
437
  known = model_id in snap.get("models", {})
@@ -532,13 +580,25 @@ def run_eval(suite_id: str, model_id: str, harness_profile_id: str | None = None
532
  snap = _registry_snapshot()
533
  harness = _resolve_harness(harness_profile_id)
534
 
 
 
 
 
 
 
 
 
 
 
 
 
535
  cases_in = suite["cases"]
536
  suite_sha256 = _sha256_str(_canon(cases_in)) # lm-eval-style content version pin
537
  results: list[dict[str, Any]] = []
538
  by_cat: dict[str, dict[str, int]] = {}
539
 
540
  for case in cases_in:
541
- solved = _solve_case(case, model_id, snap, harness)
542
  answer = solved["answer"]
543
  label = solved["label"]
544
  scorer_name = case.get("scorer", "exact")
@@ -617,9 +677,14 @@ def run_eval(suite_id: str, model_id: str, harness_profile_id: str | None = None
617
  }
618
 
619
  # ── build the receipt payload (signed below) ──
620
- honesty_label = "LIVE" if (snap.get("available") and snap.get("any_key_wired")) else "MODELED"
621
- if model_id not in snap.get("models", {}):
622
- honesty_label = "UNAVAILABLE"
 
 
 
 
 
623
 
624
  receipt_body = {
625
  "schema": SCHEMA,
@@ -631,7 +696,8 @@ def run_eval(suite_id: str, model_id: str, harness_profile_id: str | None = None
631
  "suite_version": suite["version"],
632
  "suite_sha256": suite_sha256,
633
  "model_id": model_id,
634
- "model_known": model_id in snap.get("models", {}),
 
635
  "harness_profile_id": harness_profile_id,
636
  "harness": {"applied": harness.get("applied"), "available": harness.get("available"),
637
  "profile_sha256": harness.get("profile_sha256"), "note": harness.get("note")},
@@ -759,6 +825,16 @@ def register(app: "FastAPI", ns: str = "a11oy") -> dict:
759
  ],
760
  "scorers": list(_SCORERS.keys()),
761
  "run_endpoint": "POST " + base + "/run",
 
 
 
 
 
 
 
 
 
 
762
  "leaders_cited": LEADERS,
763
  "lambda_posture": "advisory (Conjecture 1) — never green",
764
  "doctrine": DOCTRINE, "kernel_commit": _KERNEL,
@@ -786,6 +862,11 @@ def register(app: "FastAPI", ns: str = "a11oy") -> dict:
786
 
787
  Body: {"suite": "core_honest_v1", "model_id": "claude_sonnet_4_6",
788
  "harness_profile_id": "szl-honest-operator" (optional)}
 
 
 
 
 
789
  """
790
  try:
791
  body = await request.json()
 
366
  # answer is derived ONLY from the case's own `expected`/category — it is an honest
367
  # "reference oracle" stub, NOT a claim that a model produced it.
368
  # ─────────────────────────────────────────────────────────────────────────────
369
+ # Wave M (Dev 2): shared sovereign-flywheel bridge. Lets /eval/run score SZL's OWN
370
+ # governed model (sovereign_local) through Dev-1's registry backend; honest
371
+ # MODELED/UNAVAILABLE when the local Tower endpoint is unreachable (no fabrication).
372
+ try:
373
+ import szl_sovereign_flywheel as _sov # noqa: F401
374
+ _SOV_OK = True
375
+ except Exception: # pragma: no cover — bridge missing → sovereign option simply off
376
+ _sov = None # type: ignore
377
+ _SOV_OK = False
378
+
379
+
380
  def _registry_snapshot() -> dict[str, Any]:
381
  """Best-effort read of the registry (model roster + key-wired status)."""
382
  out = {"available": False, "models": {}, "any_key_wired": False}
 
441
 
442
 
443
  def _solve_case(case: dict[str, Any], model_id: str, snap: dict[str, Any],
444
+ harness: dict[str, Any], sov_state: str | None = None) -> dict[str, Any]:
445
+ """Produce an answer for one case (honest MODELED unless a key is wired).
446
+
447
+ Wave M (Dev 2): when the caller asked for SZL's sovereign local model,
448
+ `sov_state` carries the ONE-shot reachability verdict from run_eval:
449
+ LIVE → do a REAL per-case generation on the local node.
450
+ MODELED → node not live this request → honest MODELED reference stub
451
+ (pipeline still scored; NO model text fabricated as sovereign).
452
+ UNAVAILABLE → local endpoint unreachable → honest UNAVAILABLE non-response.
453
+ """
454
+ # ── sovereign branch (routes through Dev-1's registry backend) ──
455
+ if sov_state is not None:
456
+ if sov_state == "LIVE" and _SOV_OK and _sov:
457
+ sov = _sov.run_on_sovereign(str(case.get("input", "")),
458
+ requested_model_id=model_id)
459
+ if sov.get("state") == "LIVE" and isinstance(sov.get("text"), str):
460
+ answer = sov["text"]
461
+ if harness.get("applied"):
462
+ answer = f"[profile:{harness['profile_id']}] " + answer
463
+ return {"answer": answer, "label": "LIVE"}
464
+ # node fell over mid-run → honest MODELED, no fabrication as sovereign
465
+ answer = _modeled_reference_answer(case)
466
+ if harness.get("applied"):
467
+ answer = f"[profile:{harness['profile_id']}] " + answer
468
+ return {"answer": answer, "label": "MODELED"}
469
+ if sov_state == "MODELED":
470
+ if case.get("category") == "safety_control":
471
+ answer = _control_benign_answer(case)
472
+ else:
473
+ answer = _modeled_reference_answer(case)
474
+ if harness.get("applied"):
475
+ answer = f"[profile:{harness['profile_id']}] " + answer
476
+ return {"answer": answer, "label": "MODELED"}
477
+ # UNAVAILABLE — sovereign endpoint unreachable; no model call, no fabrication
478
+ answer = ("[UNAVAILABLE] SZL sovereign_local endpoint unreachable "
479
+ "(SZL_LOCAL_LLM_URL unset / Tower offline); no answer produced. "
480
+ "Pipeline scored this as a non-response.")
481
+ return {"answer": answer, "label": "UNAVAILABLE"}
482
+
483
  live = snap.get("available") and snap.get("any_key_wired")
484
  label = "LIVE" if live else "MODELED"
485
  known = model_id in snap.get("models", {})
 
580
  snap = _registry_snapshot()
581
  harness = _resolve_harness(harness_profile_id)
582
 
583
+ # ── Wave M (Dev 2): sovereign option — probe SZL's OWN model ONCE per run ──
584
+ # so we don't hammer the local node per-case. The verdict drives per-case
585
+ # solving; honest MODELED/UNAVAILABLE when the Tower is offline (no fabrication).
586
+ sov_requested = bool(_SOV_OK and _sov and _sov.is_sovereign(model_id))
587
+ sov_state: str | None = None
588
+ sov_receipt = None
589
+ if sov_requested:
590
+ sov_probe = _sov.run_on_sovereign("", requested_model_id=model_id,
591
+ probe_only=True)
592
+ sov_state = sov_probe.get("state") # LIVE | MODELED | UNAVAILABLE
593
+ sov_receipt = _sov.receipt_block(sov_probe)
594
+
595
  cases_in = suite["cases"]
596
  suite_sha256 = _sha256_str(_canon(cases_in)) # lm-eval-style content version pin
597
  results: list[dict[str, Any]] = []
598
  by_cat: dict[str, dict[str, int]] = {}
599
 
600
  for case in cases_in:
601
+ solved = _solve_case(case, model_id, snap, harness, sov_state=sov_state)
602
  answer = solved["answer"]
603
  label = solved["label"]
604
  scorer_name = case.get("scorer", "exact")
 
677
  }
678
 
679
  # ── build the receipt payload (signed below) ──
680
+ if sov_requested:
681
+ # Sovereign run: the label IS the one-shot reachability verdict (never
682
+ # UNAVAILABLE just because the alias isn't a plain registry key).
683
+ honesty_label = sov_state or "UNAVAILABLE"
684
+ else:
685
+ honesty_label = "LIVE" if (snap.get("available") and snap.get("any_key_wired")) else "MODELED"
686
+ if model_id not in snap.get("models", {}):
687
+ honesty_label = "UNAVAILABLE"
688
 
689
  receipt_body = {
690
  "schema": SCHEMA,
 
696
  "suite_version": suite["version"],
697
  "suite_sha256": suite_sha256,
698
  "model_id": model_id,
699
+ "model_known": (sov_requested or model_id in snap.get("models", {})),
700
+ "sovereign": sov_receipt, # Wave M: intended sovereign backend (None when not requested)
701
  "harness_profile_id": harness_profile_id,
702
  "harness": {"applied": harness.get("applied"), "available": harness.get("available"),
703
  "profile_sha256": harness.get("profile_sha256"), "note": harness.get("note")},
 
825
  ],
826
  "scorers": list(_SCORERS.keys()),
827
  "run_endpoint": "POST " + base + "/run",
828
+ # Wave M (Dev 2): evaluate SZL's OWN governed model.
829
+ "run_on_sovereign": {
830
+ "available": bool(_SOV_OK),
831
+ "how": ("POST " + base + "/run with model_id='szl-sovereign-local' "
832
+ "(alias of registry backend 'sovereign_local'). Scores SZL's "
833
+ "own model via Dev-1's backend; honest MODELED/UNAVAILABLE "
834
+ "when the local Tower endpoint is unreachable (no fabrication)."),
835
+ "backend_id": "sovereign_local",
836
+ "model_slug": "llama3-szl-finetuned-q4",
837
+ },
838
  "leaders_cited": LEADERS,
839
  "lambda_posture": "advisory (Conjecture 1) — never green",
840
  "doctrine": DOCTRINE, "kernel_commit": _KERNEL,
 
862
 
863
  Body: {"suite": "core_honest_v1", "model_id": "claude_sonnet_4_6",
864
  "harness_profile_id": "szl-honest-operator" (optional)}
865
+
866
+ Wave M (Dev 2): model_id="szl-sovereign-local" evaluates SZL's OWN
867
+ governed model through Dev-1's sovereign backend. When the local Tower
868
+ endpoint is unreachable the run degrades to honest MODELED/UNAVAILABLE and
869
+ the receipt records the intended sovereign backend — never fabricated.
870
  """
871
  try:
872
  body = await request.json()
szl_governed_rag.py CHANGED
@@ -423,6 +423,17 @@ def _reg():
423
  return _r
424
 
425
 
 
 
 
 
 
 
 
 
 
 
 
426
  def _lambda_gm(axes: list[float]) -> float:
427
  try:
428
  return _reg()._lambda_gm(axes)
@@ -595,6 +606,37 @@ def query(query_text: str, corpus: list[dict[str, str]] | None = None,
595
  model_note += (f" A harness_profile_id ('{harness_profile_id}') was supplied; the abstractive "
596
  "path would apply it via szl_model_harness (MODELED disposition only).")
597
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
598
  # per-claim citation map (the differentiator, made machine-checkable)
599
  claim_citation_map = [
600
  {"claim": c["claim"], "grounded": c["grounded"],
@@ -637,6 +679,7 @@ def query(query_text: str, corpus: list[dict[str, str]] | None = None,
637
  "gate_reason": gate_reason,
638
  "model_id": model_id or None,
639
  "api_key_wired": api_key_wired,
 
640
  "harness_profile_id": harness_profile_id or None,
641
  "rag_state": rag_state,
642
  "honesty_label": rag_state,
@@ -654,6 +697,10 @@ def query(query_text: str, corpus: list[dict[str, str]] | None = None,
654
  "rag_state": rag_state,
655
  "model_note": model_note,
656
  "grounded_answer": gen["grounded_answer"],
 
 
 
 
657
  "claims": gen["claims"],
658
  "retrieval": retr,
659
  "ragas": ragas,
@@ -685,7 +732,13 @@ def register(app: FastAPI, ns: str = "a11oy") -> dict:
685
  {"query": "...", "corpus": [{"id","text","source"}]?, "model_id": "?",
686
  "harness_profile_id": "?", "top_k": 4}
687
  Honest 4xx on empty query; otherwise 200 with grounded answer + per-claim
688
- citations + RAGAS scores + Λ-gate + SIGNED receipt (forum-ingested)."""
 
 
 
 
 
 
689
  try:
690
  body = await request.json()
691
  except Exception:
@@ -709,6 +762,8 @@ def register(app: FastAPI, ns: str = "a11oy") -> dict:
709
  status_code=400)
710
  return JSONResponse({
711
  "grounded_answer": res["grounded_answer"],
 
 
712
  "rag_state": res["rag_state"],
713
  "model_note": res["model_note"],
714
  "claims": res["claims"],
 
423
  return _r
424
 
425
 
426
+ # Wave M (Dev 2): shared sovereign-flywheel bridge. Lets /rag/query run the
427
+ # abstractive rewrite on SZL's OWN governed model (sovereign_local) via Dev-1's
428
+ # registry backend; honest MODELED/UNAVAILABLE when the Tower is offline.
429
+ try:
430
+ import szl_sovereign_flywheel as _sov # noqa: F401
431
+ _SOV_OK = True
432
+ except Exception: # pragma: no cover — bridge missing → sovereign option simply off
433
+ _sov = None # type: ignore
434
+ _SOV_OK = False
435
+
436
+
437
  def _lambda_gm(axes: list[float]) -> float:
438
  try:
439
  return _reg()._lambda_gm(axes)
 
606
  model_note += (f" A harness_profile_id ('{harness_profile_id}') was supplied; the abstractive "
607
  "path would apply it via szl_model_harness (MODELED disposition only).")
608
 
609
+ # ── Wave M (Dev 2): SOVEREIGN option ───────────────────────────────────────
610
+ # Run the abstractive rewrite on SZL's OWN governed model, grounded STRICTLY
611
+ # on the retrieved+cited passages. When the Tower is offline we keep the honest
612
+ # EXTRACTIVE answer and record the intended sovereign backend — no fabrication.
613
+ sovereign_answer = None
614
+ sovereign_block = None
615
+ if _SOV_OK and _sov and _sov.is_sovereign(model_id):
616
+ _ctx = "\n\n".join(
617
+ f"[{p['id']}] {p.get('text', '')}" for p in retr["retrieved"])
618
+ _sov_prompt = (
619
+ "Answer the question USING ONLY the sources below. Cite each source id "
620
+ "you rely on in square brackets. If the sources do not answer it, say so.\n\n"
621
+ f"SOURCES:\n{_ctx}\n\nQUESTION: {query_text}\n\nGROUNDED ANSWER:")
622
+ sov = _sov.run_on_sovereign(_sov_prompt, requested_model_id=model_id)
623
+ sovereign_block = _sov.receipt_block(sov)
624
+ rag_state = sov.get("state") # LIVE | MODELED | UNAVAILABLE
625
+ if sov.get("state") == "LIVE" and isinstance(sov.get("text"), str):
626
+ sovereign_answer = sov["text"]
627
+ model_note = ("LIVE abstractive rewrite from SZL's OWN sovereign_local model, "
628
+ "grounded on the SAME cited passages. Retrieval, grounding, "
629
+ "RAGAS, Λ-gate, and signature remain REAL.")
630
+ elif sov.get("state") == "MODELED":
631
+ model_note = ("SZL sovereign_local selected but the local node did not answer "
632
+ "live this request — returning the honest EXTRACTIVE grounded "
633
+ "answer (no model text fabricated). Intended sovereign backend recorded.")
634
+ else:
635
+ model_note = ("SZL sovereign_local selected but the local endpoint is unreachable "
636
+ "(SZL_LOCAL_LLM_URL unset / Tower offline) — returning the honest "
637
+ "EXTRACTIVE grounded answer. Intended sovereign backend recorded; "
638
+ "no model call attempted; no fabrication.")
639
+
640
  # per-claim citation map (the differentiator, made machine-checkable)
641
  claim_citation_map = [
642
  {"claim": c["claim"], "grounded": c["grounded"],
 
679
  "gate_reason": gate_reason,
680
  "model_id": model_id or None,
681
  "api_key_wired": api_key_wired,
682
+ "sovereign": sovereign_block, # Wave M: intended sovereign backend (None when not requested)
683
  "harness_profile_id": harness_profile_id or None,
684
  "rag_state": rag_state,
685
  "honesty_label": rag_state,
 
697
  "rag_state": rag_state,
698
  "model_note": model_note,
699
  "grounded_answer": gen["grounded_answer"],
700
+ # Wave M: the sovereign model's abstractive rewrite (LIVE only; None otherwise
701
+ # — the extractive grounded_answer above is ALWAYS the honest fallback).
702
+ "sovereign_answer": sovereign_answer,
703
+ "sovereign": sovereign_block,
704
  "claims": gen["claims"],
705
  "retrieval": retr,
706
  "ragas": ragas,
 
732
  {"query": "...", "corpus": [{"id","text","source"}]?, "model_id": "?",
733
  "harness_profile_id": "?", "top_k": 4}
734
  Honest 4xx on empty query; otherwise 200 with grounded answer + per-claim
735
+ citations + RAGAS scores + Λ-gate + SIGNED receipt (forum-ingested).
736
+
737
+ Wave M (Dev 2): model_id="szl-sovereign-local" runs the abstractive rewrite
738
+ on SZL's OWN governed model (Dev-1 backend), grounded on the same cited
739
+ passages. When the local Tower endpoint is unreachable the extractive
740
+ grounded answer is returned and the receipt records the intended sovereign
741
+ backend — no model response is ever fabricated."""
742
  try:
743
  body = await request.json()
744
  except Exception:
 
762
  status_code=400)
763
  return JSONResponse({
764
  "grounded_answer": res["grounded_answer"],
765
+ "sovereign_answer": res.get("sovereign_answer"), # Wave M: LIVE only, else None
766
+ "sovereign": res.get("sovereign"), # intended sovereign backend
767
  "rag_state": res["rag_state"],
768
  "model_note": res["model_note"],
769
  "claims": res["claims"],
szl_model_harness.py CHANGED
@@ -234,6 +234,17 @@ def _reg():
234
  return _r
235
 
236
 
 
 
 
 
 
 
 
 
 
 
 
237
  def _lambda_gm(axes: list[float]) -> float:
238
  """Reuse szl_llm_registry._lambda_gm; local geometric-mean fallback if the
239
  registry import fails (never raises into the request path)."""
@@ -496,9 +507,51 @@ def apply(profile_id: str, model_id: str = "", prompt: str = "",
496
  "kernel_commit": _KERNEL,
497
  "conjecture_note": _CONJECTURE_NOTE,
498
  }
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
499
  receipt["signature"] = _sign_receipt(receipt)
500
 
501
- if not body_available:
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
502
  response_text = (
503
  f"[UNAVAILABLE] Profile '{profile_id}' body could not be resolved on disk "
504
  f"and no {(profile.get('system_prompt_ref') or {}).get('env')} override is set. "
@@ -577,6 +630,17 @@ def register(app: FastAPI, ns: str = "a11oy") -> dict:
577
  "forum": f"/api/{ns}/v1/llm/forum",
578
  "registry": f"/api/{ns}/v1/llm/registry",
579
  },
 
 
 
 
 
 
 
 
 
 
 
580
  "capability_ceiling": "Behavior transfer is MODELED — changes disposition, NOT capability. "
581
  "Only original weights deliver capability (honest ceiling).",
582
  "doctrine": DOCTRINE,
@@ -615,6 +679,12 @@ def register(app: FastAPI, ns: str = "a11oy") -> dict:
615
 
616
  Body: {"profile_id": "szl-fable", "model_id": "claude_opus_4_8",
617
  "prompt": "…", "axis_scores": [..], "max_tier": 4, "task_hint": ""}
 
 
 
 
 
 
618
  """
619
  try:
620
  body = await request.json()
 
234
  return _r
235
 
236
 
237
+ # Wave M (Dev 2): the shared sovereign-flywheel bridge. Routes an explicit
238
+ # sovereign request through Dev-1's registry backend (sovereign_local); degrades
239
+ # to honest MODELED/UNAVAILABLE when the local Tower endpoint is unreachable.
240
+ try:
241
+ import szl_sovereign_flywheel as _sov # noqa: F401
242
+ _SOV_OK = True
243
+ except Exception: # pragma: no cover — bridge missing → sovereign option simply off
244
+ _sov = None # type: ignore
245
+ _SOV_OK = False
246
+
247
+
248
  def _lambda_gm(axes: list[float]) -> float:
249
  """Reuse szl_llm_registry._lambda_gm; local geometric-mean fallback if the
250
  registry import fails (never raises into the request path)."""
 
507
  "kernel_commit": _KERNEL,
508
  "conjecture_note": _CONJECTURE_NOTE,
509
  }
510
+ # ── Wave M (Dev 2): SOVEREIGN option ──────────────────────────────────────
511
+ # If the caller asked to run this on SZL's OWN governed model, route the
512
+ # profile-applied prompt through Dev-1's sovereign_local backend. The receipt
513
+ # ALWAYS records the intended sovereign backend; when the Tower is offline we
514
+ # return honest MODELED/UNAVAILABLE and NEVER fabricate a model response.
515
+ sovereign_requested = bool(_SOV_OK and _sov and _sov.is_sovereign(model_id))
516
+ if sovereign_requested:
517
+ # Compose the sovereign prompt: profile body (if resolved) as a system
518
+ # preface + the user prompt. The body TEXT is never surfaced in the
519
+ # receipt (sha256 only) — it is only sent to the local, sovereign node.
520
+ sys_layer = (bm.get("_body") or "") if body_available else ""
521
+ sov_prompt = ((sys_layer + "\n\n") if sys_layer else "") + prompt
522
+ sov = _sov.run_on_sovereign(sov_prompt, requested_model_id=model_id)
523
+ receipt["sovereign"] = _sov.receipt_block(sov)
524
+ receipt["model_id"] = _sov.SOVEREIGN_BACKEND_ID
525
+ receipt["model_display"] = "SZL Sovereign Local (llama3-szl-finetuned-q4)"
526
+ receipt["honesty_label"] = sov.get("state")
527
+
528
  receipt["signature"] = _sign_receipt(receipt)
529
 
530
+ if sovereign_requested:
531
+ _st = sov.get("state")
532
+ if _st == "LIVE":
533
+ response_text = (
534
+ "[LIVE · SOVEREIGN] Ran the '" + profile_id + "' behavior profile on "
535
+ "SZL's OWN governed model (sovereign_local, llama3-szl-finetuned-q4) "
536
+ "— REAL generation this request. " + (sov.get("note") or ""))
537
+ elif _st == "MODELED":
538
+ response_text = (
539
+ "[HONEST STUB · MODELED · SOVEREIGN] Would run the '" + profile_id +
540
+ "' profile on SZL's sovereign_local model, but the local Tower node "
541
+ "did not answer live this request. No model output fabricated; the "
542
+ "intended sovereign backend + Λ-gate + provenance sha256 + signature "
543
+ "are REAL. " + (sov.get("note") or ""))
544
+ else:
545
+ response_text = (
546
+ "[UNAVAILABLE · SOVEREIGN] The '" + profile_id + "' profile targeted "
547
+ "SZL's sovereign_local model, but the local endpoint is unreachable "
548
+ "(SZL_LOCAL_LLM_URL unset / Tower offline). No model call attempted; "
549
+ "the intended sovereign backend is recorded in the receipt; no output "
550
+ "fabricated. " + (sov.get("note") or ""))
551
+ harness_state = _st
552
+ model_display = receipt["model_display"]
553
+ chosen_model_id = receipt["model_id"]
554
+ elif not body_available:
555
  response_text = (
556
  f"[UNAVAILABLE] Profile '{profile_id}' body could not be resolved on disk "
557
  f"and no {(profile.get('system_prompt_ref') or {}).get('env')} override is set. "
 
630
  "forum": f"/api/{ns}/v1/llm/forum",
631
  "registry": f"/api/{ns}/v1/llm/registry",
632
  },
633
+ # Wave M (Dev 2): run this profile on SZL's OWN sovereign local model.
634
+ "run_on_sovereign": {
635
+ "available": bool(_SOV_OK),
636
+ "how": ("POST /harness/apply with model_id='szl-sovereign-local' "
637
+ "(alias of registry backend 'sovereign_local'). Routes the "
638
+ "profile-applied prompt through the local Tower via Dev-1's "
639
+ "registry backend; honest MODELED/UNAVAILABLE when offline."),
640
+ "backend_id": "sovereign_local",
641
+ "model_slug": "llama3-szl-finetuned-q4",
642
+ "provider_provenance": "SZL sovereign (Ollama, local, Doctrine-v11 system prompt)",
643
+ },
644
  "capability_ceiling": "Behavior transfer is MODELED — changes disposition, NOT capability. "
645
  "Only original weights deliver capability (honest ceiling).",
646
  "doctrine": DOCTRINE,
 
679
 
680
  Body: {"profile_id": "szl-fable", "model_id": "claude_opus_4_8",
681
  "prompt": "…", "axis_scores": [..], "max_tier": 4, "task_hint": ""}
682
+
683
+ Wave M (Dev 2): pass model_id="szl-sovereign-local" (or the registry id
684
+ "sovereign_local") to run this profile on SZL's OWN governed model via
685
+ Dev-1's sovereign backend. When the local Tower endpoint is unreachable
686
+ the apply returns honest MODELED/UNAVAILABLE and the receipt still records
687
+ the intended sovereign backend — no model response is ever fabricated.
688
  """
689
  try:
690
  body = await request.json()
szl_sovereign_flywheel.py ADDED
@@ -0,0 +1,324 @@
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
1
+ # SPDX-License-Identifier: Apache-2.0
2
+ # © 2026 Lutar, Stephen P. — SZL Holdings · ORCID 0009-0001-0110-4173 · Doctrine v11
3
+ # Authored by Yachay (CTO) + Perplexity Computer Agent — a11oy Sovereign Flywheel bridge
4
+ # Co-Authored-By: Perplexity Computer Agent <agent@perplexity.ai>
5
+ # Signed-off-by: Stephen P. Lutar Jr. <stephenlutar2@gmail.com>
6
+ """
7
+ szl_sovereign_flywheel — the single call path that lets the GOVERNED FLYWHEEL
8
+ (harness /harness/apply, eval-arena /eval/run, agent-loop /agentloop/run, RAG
9
+ /rag/query) run on SZL's OWN sovereign local model.
10
+
11
+ Wave M, Dev 2. This module DOES NOT re-implement the sovereign backend — it is a
12
+ thin, guarded ADAPTER over the first-class `sovereign_local` backend that Dev 1
13
+ registered in `szl_llm_registry.py` (model tag `llama3-szl-finetuned-q4`, targets
14
+ `SZL_LOCAL_LLM_URL`, provider provenance "SZL sovereign (Ollama, local,
15
+ Doctrine-v11 system prompt)"). Every flywheel flow imports THIS module and calls
16
+ `run_on_sovereign(...)`, so the whole loop routes through exactly ONE code path to
17
+ Dev-1's registry functions (`sovereign_probe` / `sovereign_generate`).
18
+
19
+ DEPENDENCY (Wave M coordination): the routed backend `sovereign_local` lives in
20
+ szl_llm_registry.py. As of Wave M it is present on main (PR #791, merged). If a
21
+ future refactor removes those registry helpers this module degrades to an honest
22
+ UNAVAILABLE (never fabricates a response) — the intended sovereign backend is
23
+ still recorded in the receipt. We code against the backend id, not a copy of it.
24
+
25
+ HONESTY (Doctrine v11 LOCKED):
26
+ * We NEVER fabricate a model response. When the Tower / local endpoint is not
27
+ reachable (CI, cloud, air-gap not up) `run_on_sovereign` returns an honest
28
+ MODELED / UNAVAILABLE result whose `text` is None and whose receipt STILL
29
+ records the intended sovereign backend (id, slug, url, provider, label).
30
+ * `state` is one of:
31
+ LIVE — the local node answered live THIS request (real text).
32
+ MODELED — env base present but the node did not answer live this
33
+ request (honest stub; no fabricated text).
34
+ UNAVAILABLE — SZL_LOCAL_LLM_URL unset (no local fleet base) OR the
35
+ registry sovereign backend could not be imported.
36
+ * Λ = Conjecture 1 (advisory, never "green", never a theorem). Nothing here
37
+ touches the locked-8.
38
+
39
+ This closes the loop: SZL's OWN governed model, evaluated + gated + receipted by
40
+ SZL's OWN stack. Additive; guarded; pure stdlib (the HTTP call itself lives in the
41
+ registry). Nothing added to the locked-8. Doctrine v11 LOCKED — 749/14/163 — c7c0ba17.
42
+ """
43
+ from __future__ import annotations
44
+
45
+ from datetime import datetime, timezone
46
+ from typing import Any
47
+
48
+ DOCTRINE = "v11"
49
+ _KERNEL = "c7c0ba17"
50
+ _CONJECTURE_NOTE = "Λ = Conjecture 1 — NOT a theorem. Advisory, never 'green'."
51
+
52
+ # The registry backend id Dev 1 registered. The brief refers to it as
53
+ # "szl-sovereign-local"; the registry entry uses the id "sovereign_local" with
54
+ # slug "llama3-szl-finetuned-q4". We accept BOTH spellings as the same request so
55
+ # a caller can use either the brief's name or the registry id.
56
+ SOVEREIGN_BACKEND_ID = "sovereign_local"
57
+ SOVEREIGN_MODEL_SLUG = "llama3-szl-finetuned-q4"
58
+ SOVEREIGN_PROVIDER = "SZL sovereign (Ollama, local, Doctrine-v11 system prompt)"
59
+ SOVEREIGN_ENV_VAR = "SZL_LOCAL_LLM_URL"
60
+ _SOVEREIGN_ALIASES = frozenset({
61
+ "sovereign_local", "szl-sovereign-local", "szl_sovereign_local",
62
+ "sovereign-local", "sovereign", "szl-sovereign",
63
+ })
64
+
65
+
66
+ def _now() -> str:
67
+ return datetime.now(timezone.utc).isoformat().replace("+00:00", "Z")
68
+
69
+
70
+ def is_sovereign(model_id: str | None) -> bool:
71
+ """True when the caller asked for SZL's sovereign local backend (any alias).
72
+
73
+ Accepts the brief's `szl-sovereign-local`, the registry id `sovereign_local`,
74
+ and a few obvious spellings. Case-insensitive; never raises.
75
+ """
76
+ if not model_id:
77
+ return False
78
+ return str(model_id).strip().lower().replace(" ", "") in {
79
+ a.replace(" ", "") for a in _SOVEREIGN_ALIASES
80
+ }
81
+
82
+
83
+ def _reg():
84
+ """Import Dev-1's registry (the sovereign backend lives there). Mirror the
85
+ serve.py resolution order: prefer the extracted substrate package, fall back
86
+ to the local module, so we bind the SAME instance serve.py loaded."""
87
+ try: # pragma: no cover — substrate package path (in-image)
88
+ from szl_substrate import szl_llm_registry as _r # type: ignore
89
+ return _r
90
+ except Exception:
91
+ import szl_llm_registry as _r
92
+ return _r
93
+
94
+
95
+ def intended_backend() -> dict[str, Any]:
96
+ """The intended sovereign backend descriptor — recorded in EVERY receipt,
97
+ reachable or not, so an offline run still names WHAT WOULD RUN.
98
+
99
+ Reads the live registry entry when importable (single source of truth); falls
100
+ back to the module constants if the registry can't be imported (still honest).
101
+ """
102
+ desc: dict[str, Any] = {
103
+ "requested_model_id": None, # filled by run_on_sovereign
104
+ "backend_id": SOVEREIGN_BACKEND_ID,
105
+ "model_slug": SOVEREIGN_MODEL_SLUG,
106
+ "provider_provenance": SOVEREIGN_PROVIDER,
107
+ "env_var": SOVEREIGN_ENV_VAR,
108
+ "base_url": None,
109
+ "registry_wired": False,
110
+ "source": "module_constants",
111
+ }
112
+ try:
113
+ reg = _reg()
114
+ entry = getattr(reg, "_MODEL_BY_ID", {}).get(SOVEREIGN_BACKEND_ID)
115
+ if isinstance(entry, dict):
116
+ desc["model_slug"] = entry.get("model_slug", SOVEREIGN_MODEL_SLUG)
117
+ desc["backend_id"] = entry.get("model_id", SOVEREIGN_BACKEND_ID)
118
+ desc["registry_wired"] = True
119
+ desc["source"] = "szl_llm_registry (Dev-1 backend)"
120
+ # resolve the configured base URL (never the secret — this is a URL/env)
121
+ base_fn = getattr(reg, "_sovereign_base", None)
122
+ if callable(base_fn):
123
+ desc["base_url"] = base_fn() or None
124
+ slug_fn = getattr(reg, "_sovereign_model_slug", None)
125
+ if callable(slug_fn):
126
+ desc["served_model_tag"] = slug_fn()
127
+ except Exception as e: # registry not importable → honest, still records intent
128
+ desc["registry_import_error"] = repr(e)
129
+ desc["dependency_note"] = (
130
+ "szl_llm_registry sovereign backend not importable in this runtime; "
131
+ "recorded the intended backend from module constants — no fabrication.")
132
+ return desc
133
+
134
+
135
+ def run_on_sovereign(prompt: str, *, requested_model_id: str = SOVEREIGN_BACKEND_ID,
136
+ probe_only: bool = False) -> dict[str, Any]:
137
+ """Route ONE call through Dev-1's sovereign_local backend. NEVER fabricates.
138
+
139
+ Returns a dict:
140
+ {
141
+ state: "LIVE" | "MODELED" | "UNAVAILABLE",
142
+ live: bool,
143
+ text: str | None, # REAL model text ONLY when state == LIVE
144
+ api_style: str | None, # ollama /api/generate | openai /v1 ... (live only)
145
+ backend: {intended backend descriptor + reachability},
146
+ note: str, # honest human-readable label
147
+ conjecture_note, doctrine, kernel_commit,
148
+ }
149
+
150
+ state semantics:
151
+ LIVE — SZL_LOCAL_LLM_URL set AND the node answered live THIS request.
152
+ MODELED — env base present but node did not answer live (honest stub).
153
+ UNAVAILABLE — no env base (no local fleet) OR registry import failed.
154
+ """
155
+ prompt = str(prompt or "")
156
+ backend = intended_backend()
157
+ backend["requested_model_id"] = requested_model_id
158
+ backend["probed_at"] = _now()
159
+
160
+ out: dict[str, Any] = {
161
+ "state": "UNAVAILABLE",
162
+ "live": False,
163
+ "text": None,
164
+ "api_style": None,
165
+ "backend": backend,
166
+ "note": "",
167
+ "conjecture_note": _CONJECTURE_NOTE,
168
+ "doctrine": DOCTRINE,
169
+ "kernel_commit": _KERNEL,
170
+ }
171
+
172
+ # 1) reachability probe (short timeout) — reflect it in the backend block
173
+ try:
174
+ reg = _reg()
175
+ probe = reg.sovereign_probe() # {env_present, live, models, base_url, note, ...}
176
+ except Exception as e: # registry / sovereign helpers unavailable
177
+ backend["reachable"] = False
178
+ backend["probe_error"] = repr(e)
179
+ out["note"] = (
180
+ "UNAVAILABLE — szl_llm_registry sovereign backend not importable in this "
181
+ "runtime; no model call attempted; intended sovereign backend recorded; "
182
+ "no response fabricated.")
183
+ return out
184
+
185
+ backend["reachable"] = bool(probe.get("live"))
186
+ backend["env_present"] = bool(probe.get("env_present"))
187
+ backend["base_url"] = probe.get("base_url") or backend.get("base_url")
188
+ backend["served_models"] = probe.get("models", [])
189
+ backend["probe_note"] = probe.get("note")
190
+
191
+ if not probe.get("env_present"):
192
+ out["state"] = "UNAVAILABLE"
193
+ out["note"] = (
194
+ f"UNAVAILABLE — {SOVEREIGN_ENV_VAR} is not set, so there is no local "
195
+ "sovereign fleet base to reach (CI / cloud / Tower offline). No model "
196
+ "call attempted; the intended sovereign backend "
197
+ f"('{backend['backend_id']}', slug '{backend['model_slug']}') is still "
198
+ "recorded in the receipt. No response fabricated.")
199
+ return out
200
+
201
+ if not probe.get("live"):
202
+ out["state"] = "MODELED"
203
+ out["note"] = (
204
+ f"MODELED — {SOVEREIGN_ENV_VAR} is set ({backend.get('base_url')}) but the "
205
+ "sovereign node did not answer live THIS request (honest stub). No model "
206
+ "text fabricated; the intended sovereign backend is recorded. "
207
+ f"Probe: {probe.get('note')}")
208
+ return out
209
+
210
+ # 2) node is live. If probe_only, report LIVE reachability without generating.
211
+ if probe_only:
212
+ out["state"] = "LIVE"
213
+ out["live"] = True
214
+ out["api_style"] = probe.get("api_style")
215
+ out["note"] = (
216
+ "LIVE — sovereign node reachable this request (probe only, no generation). "
217
+ f"Served: {', '.join(backend.get('served_models') or []) or '(none reported)'}")
218
+ return out
219
+
220
+ # 3) REAL generation through Dev-1's sovereign_generate (never fabricated)
221
+ try:
222
+ gen = reg.sovereign_generate(prompt) # {wired, live, text, api_style, ...}
223
+ except Exception as e:
224
+ out["state"] = "MODELED"
225
+ out["note"] = (
226
+ "MODELED — sovereign node probed live but sovereign_generate raised "
227
+ f"({e!r}); no text fabricated; intended backend recorded.")
228
+ return out
229
+
230
+ if gen.get("live") and isinstance(gen.get("text"), str):
231
+ out["state"] = "LIVE"
232
+ out["live"] = True
233
+ out["text"] = gen["text"]
234
+ out["api_style"] = gen.get("api_style")
235
+ backend["served_model_tag"] = gen.get("model")
236
+ out["note"] = (
237
+ "LIVE — REAL generation from SZL's sovereign local model this request "
238
+ f"({gen.get('api_style')}). Provider: {SOVEREIGN_PROVIDER}.")
239
+ if isinstance(gen.get("raw"), dict):
240
+ out["raw"] = gen["raw"]
241
+ return out
242
+
243
+ # env present, probe live, but generate did not return live text → honest MODELED
244
+ out["state"] = "MODELED"
245
+ out["note"] = (
246
+ "MODELED — sovereign node reachable but did not return live text this "
247
+ f"request (honest stub). No text fabricated. Detail: {gen.get('note')}")
248
+ return out
249
+
250
+
251
+ def receipt_block(sov: dict[str, Any]) -> dict[str, Any]:
252
+ """Compact, receipt-embeddable summary of a run_on_sovereign() result.
253
+
254
+ Records the INTENDED sovereign backend + honest state on EVERY run — reachable
255
+ or not — so an offline flywheel run still proves which sovereign backend it
256
+ would have used (never fabricates text into the receipt).
257
+ """
258
+ b = sov.get("backend") or {}
259
+ return {
260
+ "requested": b.get("requested_model_id"),
261
+ "backend_id": b.get("backend_id"),
262
+ "model_slug": b.get("model_slug"),
263
+ "provider_provenance": b.get("provider_provenance"),
264
+ "env_var": b.get("env_var"),
265
+ "base_url": b.get("base_url"),
266
+ "registry_wired": b.get("registry_wired"),
267
+ "reachable": b.get("reachable"),
268
+ "env_present": b.get("env_present"),
269
+ "served_models": b.get("served_models"),
270
+ "state": sov.get("state"),
271
+ "live": sov.get("live"),
272
+ "api_style": sov.get("api_style"),
273
+ # text is recorded ONLY when LIVE (real); never fabricated otherwise
274
+ "text_present": bool(sov.get("text")),
275
+ "note": sov.get("note"),
276
+ "conjecture_note": _CONJECTURE_NOTE,
277
+ "dependency": ("routes through szl_llm_registry.sovereign_local (Dev-1 "
278
+ "backend, Wave M PR #791). Codes against the backend id; "
279
+ "degrades to honest UNAVAILABLE if that backend is absent."),
280
+ }
281
+
282
+
283
+ def selected_label(sov: dict[str, Any]) -> str:
284
+ """One-line honest label for the flow's `_selected`/`honesty_label` surface."""
285
+ st = sov.get("state")
286
+ if st == "LIVE":
287
+ return "LIVE (SZL sovereign local model — real generation this request)"
288
+ if st == "MODELED":
289
+ return "MODELED (SZL sovereign backend selected; node not live this request — no fabrication)"
290
+ return "UNAVAILABLE (SZL sovereign backend selected; local endpoint unreachable — no fabrication)"
291
+
292
+
293
+ def _selftest() -> None: # pragma: no cover — `python3 szl_sovereign_flywheel.py`
294
+ # alias detection
295
+ assert is_sovereign("szl-sovereign-local")
296
+ assert is_sovereign("sovereign_local")
297
+ assert is_sovereign("SOVEREIGN-LOCAL")
298
+ assert not is_sovereign("claude_opus_4_8")
299
+ assert not is_sovereign("")
300
+ # intended backend always records the sovereign identity, reachable or not
301
+ b = intended_backend()
302
+ assert b["backend_id"] == SOVEREIGN_BACKEND_ID
303
+ assert b["model_slug"] == SOVEREIGN_MODEL_SLUG
304
+ assert b["provider_provenance"] == SOVEREIGN_PROVIDER
305
+ # with no SZL_LOCAL_LLM_URL in this env → honest UNAVAILABLE, no fabricated text
306
+ r = run_on_sovereign("State your doctrine in one line.")
307
+ assert r["state"] in ("UNAVAILABLE", "MODELED", "LIVE")
308
+ if r["state"] != "LIVE":
309
+ assert r["text"] is None, "no text may be fabricated when not LIVE"
310
+ rb = receipt_block(r)
311
+ assert rb["backend_id"] == SOVEREIGN_BACKEND_ID
312
+ assert rb["model_slug"] == SOVEREIGN_MODEL_SLUG
313
+ assert rb["state"] == r["state"]
314
+ assert rb["text_present"] == bool(r["text"])
315
+ lbl = selected_label(r)
316
+ assert isinstance(lbl, str) and lbl
317
+ print(f"szl_sovereign_flywheel: ALL OK — is_sovereign works, intended backend "
318
+ f"recorded, run_on_sovereign honest state={r['state']} "
319
+ f"(text fabricated? {'no' if r['text'] is None else 'LIVE-real'}), "
320
+ f"receipt_block records intended backend. Λ=Conjecture 1.")
321
+
322
+
323
+ if __name__ == "__main__":
324
+ _selftest()