Spaces:
Running
Running
chore(sync): mirror backend .py + Dockerfile to Space (hf-sync-backend)
Browse filesAutomated backend sync from szl-holdings/a11oy main via hf-sync-backend.
Updated (differed from the Space): Dockerfile, serve.py, szl3d_holographic.py, szl_crypto_pipeline.py
Deleted (gone from the repo + Dockerfile COPY set): (none)
Keeps the Space-built backend (serve.py + the Dockerfile-COPY'd .py
modules) identical to GitHub main so the Space never rebuilds from a
stale backend, new endpoints don't 404 there, and orphaned modules
removed from the repo don't linger in the Space tree.
- Dockerfile +12 -0
- serve.py +33 -0
- szl3d_holographic.py +1 -0
- szl_crypto_pipeline.py +383 -0
Dockerfile
CHANGED
|
@@ -1371,6 +1371,18 @@ COPY harness_profiles/ ./harness_profiles/
|
|
| 1371 |
# Λ = Conjecture 1 (advisory). Real DSSE in-Space, honest UNSIGNED-LOCAL locally.
|
| 1372 |
COPY szl_agent_loop_governed.py ./szl_agent_loop_governed.py
|
| 1373 |
COPY static/3d/surfaces/governedagent.js ./static/3d/surfaces/governedagent.js
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| 1374 |
# BRAIN FEED for the governed loop (Wave P · Dev 4, 2026-07-07): szl_agentloop_brain.py is
|
| 1375 |
# the thin GUARDED bridge szl_agent_loop_governed.py imports to make the loop Brain-POWERED —
|
| 1376 |
# (a) it pulls advisory context from the Brain vault (corpus="brain") and (e) requests a
|
|
|
|
| 1371 |
# Λ = Conjecture 1 (advisory). Real DSSE in-Space, honest UNSIGNED-LOCAL locally.
|
| 1372 |
COPY szl_agent_loop_governed.py ./szl_agent_loop_governed.py
|
| 1373 |
COPY static/3d/surfaces/governedagent.js ./static/3d/surfaces/governedagent.js
|
| 1374 |
+
# WAVE-Q FRONTIER (feat/frontier-q-cryptopipeline, Dev 2): szl_crypto_pipeline.py
|
| 1375 |
+
# registers GET /api/a11oy/v1/cryptopipeline/transcript — the end-to-end AI-lifecycle
|
| 1376 |
+
# (data→train→infer→unlearn) hash-commit chain composing into ONE verifiable transcript
|
| 1377 |
+
# (surface id `cryptopipeline`). Commit/link/root hashing is REAL; per-stage zk proofs
|
| 1378 |
+
# are SIMULATED (no SNARK). Chains GUARDED read-only to the DSSE/durable-ledger spine
|
| 1379 |
+
# (never signs on the GET). MUST be per-file COPY'd (this Dockerfile uses no `COPY . .`)
|
| 1380 |
+
# or the guarded import in serve.py falls back and the endpoint 404s (merged-but-not-
|
| 1381 |
+
# live). The cryptopipeline.js surface also ships via `COPY static/3d/ ./static/3d/`
|
| 1382 |
+
# above; copied explicitly here too so the tab can never go dark. Additive; label
|
| 1383 |
+
# MODELED, UNSIGNED-LOCAL locally. Λ = Conjecture 1; adds nothing to the locked-8.
|
| 1384 |
+
COPY szl_crypto_pipeline.py ./szl_crypto_pipeline.py
|
| 1385 |
+
COPY static/3d/surfaces/cryptopipeline.js ./static/3d/surfaces/cryptopipeline.js
|
| 1386 |
# BRAIN FEED for the governed loop (Wave P · Dev 4, 2026-07-07): szl_agentloop_brain.py is
|
| 1387 |
# the thin GUARDED bridge szl_agent_loop_governed.py imports to make the loop Brain-POWERED —
|
| 1388 |
# (a) it pulls advisory context from the Brain vault (corpus="brain") and (e) requests a
|
serve.py
CHANGED
|
@@ -12120,6 +12120,39 @@ except Exception as _wq_e1: # additive: never break the Space
|
|
| 12120 |
# ============================================================================
|
| 12121 |
|
| 12122 |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| 12123 |
# ============================================================================
|
| 12124 |
# REVENUE LAYER (feat/revenue-layer): ADDITIVE honest revenue ESTIMATORS.
|
| 12125 |
# Doctrine v11 LOCKED — revenue figures demand maximum honesty; no fabricated
|
|
|
|
| 12120 |
# ============================================================================
|
| 12121 |
|
| 12122 |
|
| 12123 |
+
# ============================================================================
|
| 12124 |
+
# WAVE-Q FRONTIER (feat/frontier-q-cryptopipeline, Dev 2): a11oy-NATIVE cited
|
| 12125 |
+
# backend for a NEW surface `cryptopipeline` — the linkable cryptographic-proof
|
| 12126 |
+
# chain across the FULL AI lifecycle (data-sourcing → training → inference →
|
| 12127 |
+
# unlearning), each stage emitting a REAL SHA-256 content commitment + a linkable
|
| 12128 |
+
# proof that composes into ONE end-to-end verifiable transcript (hash-linked chain
|
| 12129 |
+
# + Merkle-style transcript root). The commit/link/root hashing is REAL and
|
| 12130 |
+
# recomputable; the per-stage zk PROOF objects are SIMULATED (NO SNARK generated
|
| 12131 |
+
# or checked). Distinct from zkinfer/attestinfer (inference-only). Chains GUARDED,
|
| 12132 |
+
# READ-ONLY to the DSSE / durable-ledger spine (advisory availability only — never
|
| 12133 |
+
# signs or writes on this GET; doctrine v11 receipt-on-write, not on-read).
|
| 12134 |
+
# Deterministic, stdlib-only, try/except-guarded, returns a renderable 200 with an
|
| 12135 |
+
# honest MODELED label + UNSIGNED-LOCAL receipt. Registered BEFORE the SPA
|
| 12136 |
+
# catch-all; register() uses @app.get (APPENDS) so we front-move to router
|
| 12137 |
+
# position 0 (reuses _wn_frontmove). Cites arXiv:2503.22573 (end-to-end pipeline
|
| 12138 |
+
# verifiability), 2404.16109 (zkLLM), 2409.12055 (Artemis commit-and-prove zkML),
|
| 12139 |
+
# 1706.10268 (SafetyNets). Λ = Conjecture 1; adds NOTHING to the locked-8.
|
| 12140 |
+
# ============================================================================
|
| 12141 |
+
try:
|
| 12142 |
+
import sys as _wq_sys
|
| 12143 |
+
# NOTE: explicit per-module import + <module>.register(app, ...) — the a11oy
|
| 12144 |
+
# surface-wiring contract the register-invocation guard statically verifies.
|
| 12145 |
+
import szl_crypto_pipeline as _szl_crypto_pipeline
|
| 12146 |
+
_wq_s1 = _szl_crypto_pipeline.register(app, ns="a11oy")
|
| 12147 |
+
_wn_frontmove("/api/a11oy/v1/cryptopipeline/transcript")
|
| 12148 |
+
print(f"[a11oy] WAVE-Q FRONTIER szl_crypto_pipeline registered (front-moved): {_wq_s1}", file=_wq_sys.stderr)
|
| 12149 |
+
except Exception as _wq_e1: # additive: never break the Space
|
| 12150 |
+
print(f"[a11oy] WAVE-Q FRONTIER szl_crypto_pipeline NOT registered (non-fatal): {_wq_e1!r}; SPA + API unaffected", file=__import__("sys").stderr)
|
| 12151 |
+
# ============================================================================
|
| 12152 |
+
# END: WAVE-Q FRONTIER (crypto-pipeline end-to-end verifiable transcript)
|
| 12153 |
+
# ============================================================================
|
| 12154 |
+
|
| 12155 |
+
|
| 12156 |
# ============================================================================
|
| 12157 |
# REVENUE LAYER (feat/revenue-layer): ADDITIVE honest revenue ESTIMATORS.
|
| 12158 |
# Doctrine v11 LOCKED — revenue figures demand maximum honesty; no fabricated
|
szl3d_holographic.py
CHANGED
|
@@ -119,6 +119,7 @@ SURFACES: List[Dict[str, str]] = [
|
|
| 119 |
{"id": "braincommand", "cat": "brain", "title": "Brain Command · pulse · subscribe/budget · signed receipt (Brain powering the ecosystem)", "owner": "WaveO-Dev5"},
|
| 120 |
{"id": "mesh", "cat": "defense", "title": "Sovereign Mesh · Cross-Node Orchestration (status/route/quorum)", "owner": "WaveP-Dev2"},
|
| 121 |
{"id": "agenttts", "cat": "reasoning", "title": "Agent Test-Time Compute · Multi-Agent TTC (best-of-N agents + verifier-guided selection)", "owner": "WaveQ-Dev3"},
|
|
|
|
| 122 |
]
|
| 123 |
|
| 124 |
# Content-type by extension (the only extensions we serve from the 3d tree).
|
|
|
|
| 119 |
{"id": "braincommand", "cat": "brain", "title": "Brain Command · pulse · subscribe/budget · signed receipt (Brain powering the ecosystem)", "owner": "WaveO-Dev5"},
|
| 120 |
{"id": "mesh", "cat": "defense", "title": "Sovereign Mesh · Cross-Node Orchestration (status/route/quorum)", "owner": "WaveP-Dev2"},
|
| 121 |
{"id": "agenttts", "cat": "reasoning", "title": "Agent Test-Time Compute · Multi-Agent TTC (best-of-N agents + verifier-guided selection)", "owner": "WaveQ-Dev3"},
|
| 122 |
+
{"id": "cryptopipeline", "cat": "proof", "title": "Crypto-Pipeline · End-to-End AI Lifecycle Verifiable Transcript (MODELED)", "owner": "WaveQ-Dev2"},
|
| 123 |
]
|
| 124 |
|
| 125 |
# Content-type by extension (the only extensions we serve from the 3d tree).
|
szl_crypto_pipeline.py
ADDED
|
@@ -0,0 +1,383 @@
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| 1 |
+
# SPDX-License-Identifier: Apache-2.0
|
| 2 |
+
# © 2026 Lutar, Stephen P. Jr. — SZL Holdings · ORCID 0009-0001-0110-4173 · Doctrine v11
|
| 3 |
+
# Doctrine v11 LOCKED: locked-proven=8 · Λ=Conjecture 1 · SLSA L1 honest / L2 attested / L3 roadmap
|
| 4 |
+
"""
|
| 5 |
+
szl_crypto_pipeline.py — ADDITIVE a11oy-NATIVE cited backend for the holographic
|
| 6 |
+
frontier surface static/3d/surfaces/cryptopipeline.js (surface id `cryptopipeline`).
|
| 7 |
+
|
| 8 |
+
WHY THIS EXISTS
|
| 9 |
+
The estate already has zkinfer / attestinfer — but both are INFERENCE-ONLY trust
|
| 10 |
+
branches (a single forward pass). No surface modeled cryptographic verifiability
|
| 11 |
+
across the FULL AI lifecycle. This module models the linkable cryptographic-proof
|
| 12 |
+
chain over the whole pipeline —
|
| 13 |
+
data-sourcing → training → inference → unlearning
|
| 14 |
+
— where each stage emits a CONTENT COMMITMENT + a LINKABLE proof object, and the
|
| 15 |
+
stages compose into ONE end-to-end verifiable transcript (a hash-linked chain with a
|
| 16 |
+
Merkle-style transcript root). This is the governance-native fit for SZL's
|
| 17 |
+
receipt/DSSE spine: the same "commit-then-link-then-verify" discipline the Khipu
|
| 18 |
+
receipts already use, generalized across the lifecycle.
|
| 19 |
+
|
| 20 |
+
METHOD (hash-commit chain — MODELED / SIMULATED; NOT a real SNARK)
|
| 21 |
+
For each lifecycle stage we build a canonical content dict, take a REAL SHA-256
|
| 22 |
+
commitment over it, and chain it to the previous stage:
|
| 23 |
+
commit[k] = sha256(canonical(stage_content[k]))
|
| 24 |
+
link[k] = sha256(link[k-1] || commit[k]) (link[-1] = genesis)
|
| 25 |
+
transcript_root = sha256(commit[0] || commit[1] || ... || commit[n-1])
|
| 26 |
+
The HASH-CHAIN LINKAGE is genuinely, deterministically verifiable — a `verify` pass
|
| 27 |
+
recomputes every link + the root from the stage commits and reports per-link
|
| 28 |
+
`link_ok` and a whole-chain `chain_consistent`. That part is REAL and honest.
|
| 29 |
+
|
| 30 |
+
Each stage ALSO carries a `proof` object naming a zk system from the literature
|
| 31 |
+
(zkLLM / commit-and-prove / SafetyNets) with a MODELED proof_size_bytes and a MODELED
|
| 32 |
+
verify_ms drawn deterministically from the seed. THIS IS SIMULATED: no zero-knowledge
|
| 33 |
+
argument is generated or checked. proof.label == "SIMULATED" is returned VERBATIM and
|
| 34 |
+
NEVER upgraded. We NEVER claim a real zk/SNARK proof, and NEVER emit "PROVEN".
|
| 35 |
+
|
| 36 |
+
To make the honesty legible we also run a TAMPER demo: flipping one stage's committed
|
| 37 |
+
content is shown to break its link (link_ok=False) and the whole `chain_consistent`,
|
| 38 |
+
proving the chain detects mutation — a property of the hash chain, not of any zk proof.
|
| 39 |
+
|
| 40 |
+
SPINE CHAIN (guarded, READ-ONLY — doctrine v11: NEVER sign on a GET)
|
| 41 |
+
If szl_dsse / szl_durable_ledger are importable we surface, advisory-only, whether a
|
| 42 |
+
DSSE signing key + a durable ledger are available in this environment (so the surface
|
| 43 |
+
can show "would be co-signed / anchored in-Space"). We do NOT sign, and we do NOT
|
| 44 |
+
write a ledger record, on this read path. Locally the transcript receipt is honestly
|
| 45 |
+
UNSIGNED-LOCAL.
|
| 46 |
+
|
| 47 |
+
LEADERS ADOPTED & CITED (clean-room; NOT claimed as SZL's own; VERIFY real):
|
| 48 |
+
* Waiwitya, Cheng, Kang et al. (2025) "A Framework for Cryptographic Verifiability of
|
| 49 |
+
End-to-End AI Pipelines", arXiv:2503.22573. https://arxiv.org/abs/2503.22573
|
| 50 |
+
* Sun, Li, Zhang (2024) "zkLLM: Zero Knowledge Proofs for Large Language Models",
|
| 51 |
+
arXiv:2404.16109 (ACM CCS'24). https://arxiv.org/abs/2404.16109
|
| 52 |
+
* "Artemis: Efficient Commit-and-Prove SNARKs for zkML", arXiv:2409.12055.
|
| 53 |
+
https://arxiv.org/abs/2409.12055
|
| 54 |
+
* Ghodsi, Gu, Garg (2017) "SafetyNets: Verifiable Execution of Deep Neural Networks
|
| 55 |
+
on an Untrusted Cloud", arXiv:1706.10268 (NeurIPS'17).
|
| 56 |
+
https://arxiv.org/abs/1706.10268
|
| 57 |
+
|
| 58 |
+
HONESTY SPINE (Doctrine v11)
|
| 59 |
+
* Label "MODELED" — returned VERBATIM, read verbatim by cryptopipeline.js, NEVER
|
| 60 |
+
upgraded. The COMMITMENT/LINK/ROOT hashing is real; the per-stage zk PROOF objects
|
| 61 |
+
are SIMULATED (no SNARK). No "PROVEN"/"VERIFIED"/"1.0" anywhere; trust ceiling 0.97.
|
| 62 |
+
* Advisory only. Λ = Conjecture 1; adds NOTHING to the locked-8; nothing to locked-8.
|
| 63 |
+
|
| 64 |
+
ENDPOINT (mounted BEFORE the SPA catch-all; front-moved to router position 0 by serve.py)
|
| 65 |
+
GET /api/a11oy/v1/cryptopipeline/transcript?seed=&tamper_stage=
|
| 66 |
+
-> renderable 200 JSON compatible with cryptopipeline.js:
|
| 67 |
+
{label:"MODELED", surface, title, stages[], transcript_root,
|
| 68 |
+
chain_consistent, tamper{...}, spine{...}, receipt{...},
|
| 69 |
+
citations[], doctrine, honesty}
|
| 70 |
+
"""
|
| 71 |
+
import hashlib
|
| 72 |
+
import json
|
| 73 |
+
import time
|
| 74 |
+
from typing import Any, Dict, List, Optional
|
| 75 |
+
|
| 76 |
+
from fastapi import FastAPI
|
| 77 |
+
from fastapi.responses import JSONResponse
|
| 78 |
+
|
| 79 |
+
DOCTRINE = {"version": "v11", "counts": "749/14/163", "lambda": "Conjecture 1",
|
| 80 |
+
"locked_proven": 8, "trust_ceiling": 0.97}
|
| 81 |
+
|
| 82 |
+
CITATIONS = [
|
| 83 |
+
{"id": "e2e_verifiability_2025",
|
| 84 |
+
"cite": ("A Framework for Cryptographic Verifiability of End-to-End AI Pipelines "
|
| 85 |
+
"(2025) — data→train→infer verifiability across the lifecycle."),
|
| 86 |
+
"url": "https://arxiv.org/abs/2503.22573"},
|
| 87 |
+
{"id": "zkllm_2024",
|
| 88 |
+
"cite": "Sun, Li, Zhang (2024) zkLLM: Zero Knowledge Proofs for Large Language Models (CCS'24).",
|
| 89 |
+
"url": "https://arxiv.org/abs/2404.16109"},
|
| 90 |
+
{"id": "artemis_2024",
|
| 91 |
+
"cite": "Artemis: Efficient Commit-and-Prove SNARKs for zkML (2024).",
|
| 92 |
+
"url": "https://arxiv.org/abs/2409.12055"},
|
| 93 |
+
{"id": "safetynets_2017",
|
| 94 |
+
"cite": ("Ghodsi, Gu, Garg (2017) SafetyNets: Verifiable Execution of Deep Neural "
|
| 95 |
+
"Networks on an Untrusted Cloud (NeurIPS'17)."),
|
| 96 |
+
"url": "https://arxiv.org/abs/1706.10268"},
|
| 97 |
+
]
|
| 98 |
+
|
| 99 |
+
# The four AI-lifecycle stages, each mapped to a proof-system LINEAGE from the cited
|
| 100 |
+
# literature. proof_system is a NAME ONLY — the object is SIMULATED, never generated.
|
| 101 |
+
_STAGES = [
|
| 102 |
+
{"stage": "data_sourcing",
|
| 103 |
+
"title": "Data Sourcing",
|
| 104 |
+
"proof_system": "commit-and-prove (Merkle dataset commitment)",
|
| 105 |
+
"cite": "artemis_2024",
|
| 106 |
+
"claim": "committed dataset root; provenance of every training shard"},
|
| 107 |
+
{"stage": "training",
|
| 108 |
+
"title": "Training",
|
| 109 |
+
"proof_system": "SafetyNets-style verifiable computation",
|
| 110 |
+
"cite": "safetynets_2017",
|
| 111 |
+
"claim": "weights commitment bound to the committed dataset + training transcript"},
|
| 112 |
+
{"stage": "inference",
|
| 113 |
+
"title": "Inference",
|
| 114 |
+
"proof_system": "zkLLM proof-of-inference",
|
| 115 |
+
"cite": "zkllm_2024",
|
| 116 |
+
"claim": "output produced by the committed weights on the committed input"},
|
| 117 |
+
{"stage": "unlearning",
|
| 118 |
+
"title": "Unlearning",
|
| 119 |
+
"proof_system": "commit-and-prove recomputation",
|
| 120 |
+
"cite": "artemis_2024",
|
| 121 |
+
"claim": "target record's influence removed; new weights commitment recomputed"},
|
| 122 |
+
]
|
| 123 |
+
|
| 124 |
+
_GENESIS = "0" * 64
|
| 125 |
+
|
| 126 |
+
|
| 127 |
+
def _rng(seed: int):
|
| 128 |
+
"""Deterministic stdlib LCG (no numpy) — same convention as szl_kv_cache."""
|
| 129 |
+
state = (int(seed) * 6364136223846793005 + 1442695040888963407) & ((1 << 64) - 1)
|
| 130 |
+
|
| 131 |
+
def nxt() -> float:
|
| 132 |
+
nonlocal state
|
| 133 |
+
state = (state * 6364136223846793005 + 1442695040888963407) & ((1 << 64) - 1)
|
| 134 |
+
return ((state >> 11) & ((1 << 53) - 1)) / float(1 << 53)
|
| 135 |
+
|
| 136 |
+
return nxt
|
| 137 |
+
|
| 138 |
+
|
| 139 |
+
def _canon(obj: Any) -> bytes:
|
| 140 |
+
return json.dumps(obj, sort_keys=True, separators=(",", ":")).encode("utf-8")
|
| 141 |
+
|
| 142 |
+
|
| 143 |
+
def _sha(b: bytes) -> str:
|
| 144 |
+
return hashlib.sha256(b).hexdigest()
|
| 145 |
+
|
| 146 |
+
|
| 147 |
+
def _stage_content(spec: Dict[str, str], seed: int, idx: int) -> Dict[str, Any]:
|
| 148 |
+
"""Canonical committed content for a stage. Deterministic in (seed, idx)."""
|
| 149 |
+
rnd = _rng(seed * 131 + idx)
|
| 150 |
+
# a MODELED per-stage artifact digest (stands in for the real object hashed in-Space)
|
| 151 |
+
artifact = _sha(f"{spec['stage']}:{seed}:{idx}:{rnd():.12f}".encode("utf-8"))
|
| 152 |
+
return {
|
| 153 |
+
"stage": spec["stage"],
|
| 154 |
+
"claim": spec["claim"],
|
| 155 |
+
"artifact_digest": artifact,
|
| 156 |
+
"proof_system": spec["proof_system"],
|
| 157 |
+
}
|
| 158 |
+
|
| 159 |
+
|
| 160 |
+
def _proof_object(spec: Dict[str, str], seed: int, idx: int) -> Dict[str, Any]:
|
| 161 |
+
"""A SIMULATED zk-proof object. proof_size / verify_ms are MODELED figures drawn
|
| 162 |
+
deterministically from the literature's rough regime — NOT a generated argument."""
|
| 163 |
+
rnd = _rng(seed * 977 + idx)
|
| 164 |
+
# succinct-argument regime: kilobyte-scale proofs, millisecond-scale verify (MODELED).
|
| 165 |
+
proof_size_bytes = int(1024 * (1.5 + 6.0 * rnd())) # ~1.5–7.5 kB
|
| 166 |
+
verify_ms = round(2.0 + 40.0 * rnd(), 3) # ~2–42 ms (MODELED)
|
| 167 |
+
return {
|
| 168 |
+
"label": "SIMULATED",
|
| 169 |
+
"proof_system": spec["proof_system"],
|
| 170 |
+
"proof_size_bytes": proof_size_bytes,
|
| 171 |
+
"modeled_verify_ms": verify_ms,
|
| 172 |
+
"note": ("SIMULATED proof object — no zero-knowledge argument is generated or "
|
| 173 |
+
"checked; size/verify are MODELED regime figures, not a benchmark."),
|
| 174 |
+
}
|
| 175 |
+
|
| 176 |
+
|
| 177 |
+
def _build_chain(seed: int, tamper_stage: Optional[str]) -> Dict[str, Any]:
|
| 178 |
+
"""Build the four-stage lifecycle transcript: per-stage commit + linkable proof,
|
| 179 |
+
hash-linked into one chain with a Merkle-style transcript root. The linkage is REAL
|
| 180 |
+
(recomputable); the per-stage zk proofs are SIMULATED."""
|
| 181 |
+
stages: List[Dict[str, Any]] = []
|
| 182 |
+
prev_link = _GENESIS
|
| 183 |
+
commits: List[str] = []
|
| 184 |
+
for idx, spec in enumerate(_STAGES):
|
| 185 |
+
tampered = (tamper_stage == spec["stage"])
|
| 186 |
+
content = _stage_content(spec, seed, idx)
|
| 187 |
+
# commit + link are computed over the HONEST content (as they would have been
|
| 188 |
+
# emitted at stage time). Tampering then mutates the content AFTER the commit is
|
| 189 |
+
# fixed, so the recorded commit no longer matches — the chain detects it on verify.
|
| 190 |
+
commit = _sha(_canon(content))
|
| 191 |
+
link = _sha((prev_link + commit).encode("utf-8"))
|
| 192 |
+
if tampered:
|
| 193 |
+
content = dict(content)
|
| 194 |
+
content["artifact_digest"] = _sha((commit + ":TAMPERED").encode("utf-8"))
|
| 195 |
+
commits.append(commit)
|
| 196 |
+
stages.append({
|
| 197 |
+
"index": idx,
|
| 198 |
+
"stage": spec["stage"],
|
| 199 |
+
"title": spec["title"],
|
| 200 |
+
"claim": spec["claim"],
|
| 201 |
+
"cite": spec["cite"],
|
| 202 |
+
"content": content,
|
| 203 |
+
"commit": commit,
|
| 204 |
+
"prev_link": prev_link,
|
| 205 |
+
"link": link,
|
| 206 |
+
"tampered": tampered,
|
| 207 |
+
"proof": _proof_object(spec, seed, idx),
|
| 208 |
+
})
|
| 209 |
+
prev_link = link
|
| 210 |
+
transcript_root = _sha("".join(commits).encode("utf-8"))
|
| 211 |
+
return {"stages": stages, "transcript_root": transcript_root}
|
| 212 |
+
|
| 213 |
+
|
| 214 |
+
def _verify_chain(stages: List[Dict[str, Any]], transcript_root: str) -> Dict[str, Any]:
|
| 215 |
+
"""Re-check the hash-linked chain from the stage commits (REAL, deterministic).
|
| 216 |
+
Returns per-link recomputation results + whole-chain consistency. This verifies the
|
| 217 |
+
COMMITMENT LINKAGE only — NOT a zk proof (those are SIMULATED)."""
|
| 218 |
+
prev_link = _GENESIS
|
| 219 |
+
per_link = []
|
| 220 |
+
all_ok = True
|
| 221 |
+
commits = []
|
| 222 |
+
for st in stages:
|
| 223 |
+
commit = st["commit"]
|
| 224 |
+
commits.append(commit)
|
| 225 |
+
expect_link = _sha((prev_link + commit).encode("utf-8"))
|
| 226 |
+
link_ok = (expect_link == st["link"]) and (st["prev_link"] == prev_link)
|
| 227 |
+
# if the committed content was tampered, the recomputed commit won't match
|
| 228 |
+
content_ok = (_sha(_canon(st["content"])) == commit)
|
| 229 |
+
ok = bool(link_ok and content_ok)
|
| 230 |
+
all_ok = all_ok and ok
|
| 231 |
+
per_link.append({"stage": st["stage"], "link_ok": ok,
|
| 232 |
+
"content_ok": content_ok})
|
| 233 |
+
prev_link = st["link"]
|
| 234 |
+
root_ok = (_sha("".join(commits).encode("utf-8")) == transcript_root)
|
| 235 |
+
return {"per_link": per_link, "root_ok": bool(root_ok),
|
| 236 |
+
"chain_consistent": bool(all_ok and root_ok)}
|
| 237 |
+
|
| 238 |
+
|
| 239 |
+
def _spine(transcript_root: str) -> Dict[str, Any]:
|
| 240 |
+
"""GUARDED, READ-ONLY chain to the DSSE / durable-ledger spine. Reports whether a
|
| 241 |
+
signing key + durable ledger are available (advisory) — does NOT sign or write on
|
| 242 |
+
this GET (doctrine v11: receipt-on-write, never on-read)."""
|
| 243 |
+
out: Dict[str, Any] = {"dsse": "UNAVAILABLE", "ledger": "UNAVAILABLE",
|
| 244 |
+
"signed_on_read": False,
|
| 245 |
+
"note": ("advisory read-only: DSSE co-signing + ledger "
|
| 246 |
+
"anchoring happen on WRITE in-Space, never on this GET.")}
|
| 247 |
+
try:
|
| 248 |
+
import szl_dsse as _dsse # type: ignore
|
| 249 |
+
avail = bool(_dsse.signing_available())
|
| 250 |
+
out["dsse"] = "SIGNING-KEY-PRESENT" if avail else "UNSIGNED-LOCAL"
|
| 251 |
+
try:
|
| 252 |
+
out["dsse_pubkey_fpr"] = _dsse.public_key_fingerprint()[:16]
|
| 253 |
+
except Exception:
|
| 254 |
+
pass
|
| 255 |
+
except Exception:
|
| 256 |
+
out["dsse"] = "UNAVAILABLE"
|
| 257 |
+
try:
|
| 258 |
+
import szl_durable_ledger as _dl # type: ignore
|
| 259 |
+
# class presence is enough for an advisory availability read; do NOT append.
|
| 260 |
+
out["ledger"] = "AVAILABLE" if hasattr(_dl, "DurableStore") else "UNAVAILABLE"
|
| 261 |
+
except Exception:
|
| 262 |
+
out["ledger"] = "UNAVAILABLE"
|
| 263 |
+
return out
|
| 264 |
+
|
| 265 |
+
|
| 266 |
+
def _receipt(payload: Dict[str, Any], seed: int) -> Dict[str, Any]:
|
| 267 |
+
blob = _canon(payload)
|
| 268 |
+
return {
|
| 269 |
+
"digest_sha256": _sha(blob),
|
| 270 |
+
"seed": seed,
|
| 271 |
+
"signature": "UNSIGNED-LOCAL",
|
| 272 |
+
"note": ("content digest over the MODELED transcript; deterministic in the seed. "
|
| 273 |
+
"No DSSE signature claimed locally (UNSIGNED-LOCAL); real co-signing "
|
| 274 |
+
"happens on WRITE in-Space, not on this read path."),
|
| 275 |
+
}
|
| 276 |
+
|
| 277 |
+
|
| 278 |
+
def build_transcript(seed: int = 42, tamper_stage: Optional[str] = None) -> Dict[str, Any]:
|
| 279 |
+
"""Public core: build + verify the end-to-end lifecycle transcript."""
|
| 280 |
+
seed = int(seed) & 0xFFFFFFFF
|
| 281 |
+
valid_stages = {s["stage"] for s in _STAGES}
|
| 282 |
+
ts = tamper_stage if tamper_stage in valid_stages else None
|
| 283 |
+
|
| 284 |
+
chain = _build_chain(seed, ts)
|
| 285 |
+
verify = _verify_chain(chain["stages"], chain["transcript_root"])
|
| 286 |
+
|
| 287 |
+
# tamper demo: an INDEPENDENT chain with one stage mutated, showing the link breaks.
|
| 288 |
+
demo_target = ts or "training"
|
| 289 |
+
tam_chain = _build_chain(seed, demo_target)
|
| 290 |
+
tam_verify = _verify_chain(tam_chain["stages"], tam_chain["transcript_root"])
|
| 291 |
+
tamper = {
|
| 292 |
+
"tampered_stage": demo_target,
|
| 293 |
+
"chain_consistent_after_tamper": tam_verify["chain_consistent"],
|
| 294 |
+
"note": ("flipping one committed artifact breaks that stage's link and the "
|
| 295 |
+
"whole-chain consistency — the hash chain detects mutation. This is a "
|
| 296 |
+
"property of the COMMITMENT chain, not of any zk proof (SIMULATED)."),
|
| 297 |
+
}
|
| 298 |
+
|
| 299 |
+
digest_src = {"transcript_root": chain["transcript_root"],
|
| 300 |
+
"stage_commits": [s["commit"] for s in chain["stages"]],
|
| 301 |
+
"chain_consistent": verify["chain_consistent"]}
|
| 302 |
+
|
| 303 |
+
return {
|
| 304 |
+
"label": "MODELED",
|
| 305 |
+
"surface": "cryptopipeline",
|
| 306 |
+
"title": "Crypto-Pipeline · End-to-End AI Lifecycle Verifiable Transcript (MODELED)",
|
| 307 |
+
"method": ("real SHA-256 commitment + hash-chain linkage across the AI lifecycle "
|
| 308 |
+
"(data→train→infer→unlearn); per-stage zk PROOF objects are SIMULATED "
|
| 309 |
+
"(no SNARK generated/checked). Deterministic in the seed."),
|
| 310 |
+
"lifecycle": [s["stage"] for s in _STAGES],
|
| 311 |
+
"stages": chain["stages"],
|
| 312 |
+
"transcript_root": chain["transcript_root"],
|
| 313 |
+
"verify": verify,
|
| 314 |
+
"chain_consistent": verify["chain_consistent"],
|
| 315 |
+
"tamper": tamper,
|
| 316 |
+
"spine": _spine(chain["transcript_root"]),
|
| 317 |
+
"receipt": _receipt(digest_src, seed),
|
| 318 |
+
"citations": CITATIONS,
|
| 319 |
+
"doctrine": DOCTRINE,
|
| 320 |
+
"honesty": ("MODELED: the commit/link/root hashing is REAL and recomputable; the "
|
| 321 |
+
"per-stage zk proofs are SIMULATED (hash-commit chain, NOT a real "
|
| 322 |
+
"SNARK/zk proof). No real zk argument is asserted; no VERIFIED/1.0 "
|
| 323 |
+
"state. Λ=Conjecture 1; adds nothing to the locked-8; trust ceiling "
|
| 324 |
+
"0.97, never 100%."),
|
| 325 |
+
}
|
| 326 |
+
|
| 327 |
+
|
| 328 |
+
def register(app: FastAPI, ns: str = "a11oy") -> str:
|
| 329 |
+
@app.get(f"/api/{ns}/v1/cryptopipeline/transcript", include_in_schema=False)
|
| 330 |
+
async def _transcript(seed: int = 42, tamper_stage: str = "") -> JSONResponse:
|
| 331 |
+
t0 = time.time()
|
| 332 |
+
try:
|
| 333 |
+
body = build_transcript(int(seed), tamper_stage or None)
|
| 334 |
+
except Exception as e:
|
| 335 |
+
return JSONResponse({"label": "UNAVAILABLE",
|
| 336 |
+
"detail": f"transcript build failed: {type(e).__name__}",
|
| 337 |
+
"doctrine": DOCTRINE, "citations": CITATIONS},
|
| 338 |
+
status_code=200)
|
| 339 |
+
body["elapsed_ms"] = round((time.time() - t0) * 1000, 2)
|
| 340 |
+
return JSONResponse(body, status_code=200)
|
| 341 |
+
|
| 342 |
+
return (f"crypto-pipeline transcript mounted: "
|
| 343 |
+
f"GET /api/{ns}/v1/cryptopipeline/transcript (label MODELED)")
|
| 344 |
+
|
| 345 |
+
|
| 346 |
+
def _selftest() -> None:
|
| 347 |
+
tx = build_transcript(42, None)
|
| 348 |
+
# structure
|
| 349 |
+
assert tx["label"] == "MODELED", "label must be MODELED"
|
| 350 |
+
assert len(tx["stages"]) == 4, "four lifecycle stages"
|
| 351 |
+
assert tx["lifecycle"] == ["data_sourcing", "training", "inference", "unlearning"]
|
| 352 |
+
# the honest hash chain must verify for an untampered transcript
|
| 353 |
+
assert tx["chain_consistent"] is True, "untampered chain must be consistent"
|
| 354 |
+
assert tx["verify"]["root_ok"] is True, "transcript root must recompute"
|
| 355 |
+
assert all(l["link_ok"] for l in tx["verify"]["per_link"]), "all links must recompute"
|
| 356 |
+
# per-stage zk proofs must be SIMULATED, never upgraded
|
| 357 |
+
for st in tx["stages"]:
|
| 358 |
+
assert st["proof"]["label"] == "SIMULATED", "proof objects must be SIMULATED"
|
| 359 |
+
assert st["proof"]["proof_size_bytes"] > 0
|
| 360 |
+
# tamper demo: mutating a stage MUST break the chain (honesty proof)
|
| 361 |
+
tam = build_transcript(42, "training")
|
| 362 |
+
assert tam["chain_consistent"] is False, "tampered chain must be inconsistent"
|
| 363 |
+
assert tam["tamper"]["chain_consistent_after_tamper"] is False
|
| 364 |
+
# determinism
|
| 365 |
+
assert build_transcript(42, None)["transcript_root"] == tx["transcript_root"], \
|
| 366 |
+
"non-deterministic for fixed seed"
|
| 367 |
+
# different seed -> different root
|
| 368 |
+
assert build_transcript(7, None)["transcript_root"] != tx["transcript_root"], \
|
| 369 |
+
"seed must vary the transcript"
|
| 370 |
+
# honesty: no fabricated signature, no PROVEN token
|
| 371 |
+
assert tx["receipt"]["signature"] == "UNSIGNED-LOCAL", "must not fabricate a signature"
|
| 372 |
+
assert tx["spine"]["signed_on_read"] is False, "must never sign on a read path"
|
| 373 |
+
import re as _re
|
| 374 |
+
blob = json.dumps(tx).upper()
|
| 375 |
+
assert not _re.search(r"\bPROVEN\b", blob), "must never claim PROVEN"
|
| 376 |
+
assert "SNARK PROOF GENERATED" not in blob and "ZK PROOF VERIFIED" not in blob, \
|
| 377 |
+
"must never claim a real proof was generated/verified"
|
| 378 |
+
print("szl_crypto_pipeline: ALL OK (real hash-chain links verify, tamper breaks chain, "
|
| 379 |
+
"zk proofs SIMULATED, deterministic, UNSIGNED-LOCAL receipt, no sign-on-read)")
|
| 380 |
+
|
| 381 |
+
|
| 382 |
+
if __name__ == "__main__":
|
| 383 |
+
_selftest()
|