Spaces:
Running
Running
chore(sync): mirror backend .py + Dockerfile to Space (hf-sync-backend)
Browse filesAutomated backend sync from szl-holdings/a11oy main via hf-sync-backend.
Updated (differed from the Space): a11oy_frontier_patch.py, serve.py
Deleted (gone from the repo + Dockerfile COPY set): (none)
Keeps the Space-built backend (serve.py + the Dockerfile-COPY'd .py
modules) identical to GitHub main so the Space never rebuilds from a
stale backend, new endpoints don't 404 there, and orphaned modules
removed from the repo don't linger in the Space tree.
- a11oy_frontier_patch.py +20 -0
- serve.py +114 -4
a11oy_frontier_patch.py
CHANGED
|
@@ -49,6 +49,26 @@ async def _a11oy_frontier_version(request: Request):
|
|
| 49 |
"cosign": "cosign verify ghcr.io/szl-holdings/a11oy:v1.0.0 --certificate-identity-regexp=szl-holdings",
|
| 50 |
"sbom": "https://github.com/szl-holdings/a11oy/releases/download/v1.0.0/a11oy-sbom.cdx.json",
|
| 51 |
},
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| 52 |
"ts": _NOW(),
|
| 53 |
})
|
| 54 |
|
|
|
|
| 49 |
"cosign": "cosign verify ghcr.io/szl-holdings/a11oy:v1.0.0 --certificate-identity-regexp=szl-holdings",
|
| 50 |
"sbom": "https://github.com/szl-holdings/a11oy/releases/download/v1.0.0/a11oy-sbom.cdx.json",
|
| 51 |
},
|
| 52 |
+
# ADDITIVE (waveL Dev2): machine-readable release record of the waves'
|
| 53 |
+
# shipped capabilities, HONEST labels. Canonical human record: CHANGELOG.md.
|
| 54 |
+
# This is the front-moved live /v1/version handler, so the release record
|
| 55 |
+
# must live here (not only in serve.py's shadowed copy). Lambda=Conjecture 1.
|
| 56 |
+
"changelog": "https://github.com/szl-holdings/a11oy/blob/main/CHANGELOG.md",
|
| 57 |
+
"capabilities": [
|
| 58 |
+
{"name": "governed behavior-transfer harness", "label": "MEASURED", "prs": [759, 763]},
|
| 59 |
+
{"name": "governed eval / red-team arena", "label": "MEASURED", "prs": [766]},
|
| 60 |
+
{"name": "governed RAG (retrieval-with-receipts)", "label": "MEASURED", "prs": [776]},
|
| 61 |
+
{"name": "governed agent loop (signed composite run)", "label": "MEASURED", "prs": [773, 757]},
|
| 62 |
+
{"name": "governed VQC / QML frontier", "label": "SIMULATION-ONLY", "prs": [764, 782]},
|
| 63 |
+
{"name": "attested inference (TEE-bound receipt)", "label": "UNAVAILABLE-on-CPU (MEASURED on live TDX/Nitro)", "prs": [767]},
|
| 64 |
+
{"name": "durable bounded receipt/energy ledger + storage-pressure signal", "label": "MEASURED", "prs": [774]},
|
| 65 |
+
{"name": "measured energy channel (NVML counter-delta)", "label": "MEASURED-behind-live-meter (else UNAVAILABLE)", "prs": [785, 789, 790]},
|
| 66 |
+
{"name": "substrate consolidation (68/68 movable modules, guarded fallback)", "label": "MEASURED", "prs": [792]},
|
| 67 |
+
{"name": "transitive COPY-completeness deploy guard", "label": "MEASURED", "prs": []},
|
| 68 |
+
{"name": "/healthz release rollup (storage/signer/frontier)", "label": "MEASURED", "prs": []},
|
| 69 |
+
],
|
| 70 |
+
"lambda": "Conjecture 1 (never a theorem)",
|
| 71 |
+
"locked_8": 8,
|
| 72 |
"ts": _NOW(),
|
| 73 |
})
|
| 74 |
|
serve.py
CHANGED
|
@@ -3300,23 +3300,114 @@ def _ledger_storage_signal(ttl: float = 15.0) -> dict:
|
|
| 3300 |
return val
|
| 3301 |
|
| 3302 |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| 3303 |
@app.get("/api/a11oy/healthz")
|
| 3304 |
async def healthz() -> JSONResponse:
|
| 3305 |
dep = await _healthz_dep_ping()
|
| 3306 |
_ca = dep.get("checked_at")
|
| 3307 |
_storage = _ledger_storage_signal()
|
| 3308 |
-
|
| 3309 |
-
|
| 3310 |
-
# PRESSURE is advisory (still "ok" overall but
|
| 3311 |
-
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| 3312 |
return JSONResponse({
|
| 3313 |
"status": _overall,
|
|
|
|
| 3314 |
"service": "a11oy",
|
| 3315 |
"version": "2.0.0",
|
| 3316 |
"surface": "Brand Orchestration Layer",
|
| 3317 |
"base_path": "/",
|
| 3318 |
"doctrine": "v11",
|
| 3319 |
"uptime_s": round(_hz_time.time() - _A11OY_START_TIME, 1),
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| 3320 |
"storage": _storage,
|
| 3321 |
"dependency": {"node_backend": {"status": dep.get("status"), "backend_alive": dep.get("backend_alive"), "last_checked_age_s": round(_hz_time.time() - _ca, 1) if _ca else None}},
|
| 3322 |
"gates": len(_gates_list),
|
|
@@ -5673,6 +5764,25 @@ async def a11oy_version():
|
|
| 5673 |
"sbom": "https://github.com/szl-holdings/a11oy/releases/download/v1.0.0/a11oy-sbom.cdx.json",
|
| 5674 |
"honest": "https://szlholdings-a11oy.hf.space/api/a11oy/v1/honest",
|
| 5675 |
},
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| 5676 |
}
|
| 5677 |
|
| 5678 |
|
|
|
|
| 3300 |
return val
|
| 3301 |
|
| 3302 |
|
| 3303 |
+
# ADDITIVE (waveL Dev2 — release-engineering observability rollup): two more tiny
|
| 3304 |
+
# cached, guarded probes so /healthz reports an HONEST release rollup alongside the
|
| 3305 |
+
# durable-ledger storage-pressure signal:
|
| 3306 |
+
# (a) DSSE SIGNER AVAILABILITY — is the cosign/DSSE private key present in this
|
| 3307 |
+
# Space (live signing) or are we emitting UNSIGNED-LOCAL envelopes? Read
|
| 3308 |
+
# straight from szl_dsse.signing_available(); never fabricated.
|
| 3309 |
+
# (b) FRONTIER-ENDPOINT LIVENESS COUNT — how many governed-provenance frontier
|
| 3310 |
+
# tiles are live vs degraded, read from szl_frontier_manifest's already-
|
| 3311 |
+
# cached, real-probe-only manifest summary. A down sub-source is reported
|
| 3312 |
+
# honestly (UNAVAILABLE), never faked green.
|
| 3313 |
+
# Both are guarded + cached (never block the health path, never crash it, never
|
| 3314 |
+
# fabricate). Λ = Conjecture 1; no label is upgraded here.
|
| 3315 |
+
_SIGNER_HEALTH_CACHE: dict = {}
|
| 3316 |
+
_FRONTIER_HEALTH_CACHE: dict = {}
|
| 3317 |
+
|
| 3318 |
+
|
| 3319 |
+
def _signer_availability_signal(ttl: float = 30.0) -> dict:
|
| 3320 |
+
now = _hz_time.time()
|
| 3321 |
+
ca = _SIGNER_HEALTH_CACHE.get("checked_at")
|
| 3322 |
+
if ca is not None and (now - ca) < ttl:
|
| 3323 |
+
return _SIGNER_HEALTH_CACHE.get("value", {})
|
| 3324 |
+
try:
|
| 3325 |
+
import szl_dsse as _szl_dsse_health
|
| 3326 |
+
available = bool(_szl_dsse_health.signing_available())
|
| 3327 |
+
val = {
|
| 3328 |
+
# honest label: DSSE-LIVE only when a real private key is present in
|
| 3329 |
+
# this Space; otherwise UNSIGNED-LOCAL (receipts explicitly unsigned).
|
| 3330 |
+
"status": "DSSE-LIVE" if available else "UNSIGNED-LOCAL",
|
| 3331 |
+
"signing_available": available,
|
| 3332 |
+
"scheme": "DSSEv1 / ECDSA-P256 (cosign keyless OIDC at release)",
|
| 3333 |
+
}
|
| 3334 |
+
try:
|
| 3335 |
+
val["public_key_fingerprint"] = _szl_dsse_health.public_key_fingerprint()
|
| 3336 |
+
except Exception:
|
| 3337 |
+
pass
|
| 3338 |
+
except Exception as exc:
|
| 3339 |
+
val = {"status": "unavailable", "signing_available": None,
|
| 3340 |
+
"error": f"{type(exc).__name__}: {exc}"}
|
| 3341 |
+
_SIGNER_HEALTH_CACHE.update({"checked_at": now, "value": val})
|
| 3342 |
+
return val
|
| 3343 |
+
|
| 3344 |
+
|
| 3345 |
+
def _frontier_liveness_signal(ttl: float = 30.0) -> dict:
|
| 3346 |
+
now = _hz_time.time()
|
| 3347 |
+
ca = _FRONTIER_HEALTH_CACHE.get("checked_at")
|
| 3348 |
+
if ca is not None and (now - ca) < ttl:
|
| 3349 |
+
return _FRONTIER_HEALTH_CACHE.get("value", {})
|
| 3350 |
+
try:
|
| 3351 |
+
import szl_frontier_manifest as _szl_fm_health
|
| 3352 |
+
manifest = _szl_fm_health.build_manifest()
|
| 3353 |
+
summary = manifest.get("summary", {}) if isinstance(manifest, dict) else {}
|
| 3354 |
+
total = int(summary.get("tiles", 0) or 0)
|
| 3355 |
+
degraded = summary.get("degraded_tiles", []) or []
|
| 3356 |
+
degraded_n = len(degraded)
|
| 3357 |
+
live_n = max(total - degraded_n, 0)
|
| 3358 |
+
val = {
|
| 3359 |
+
# honest: a down sub-source is a degraded tile, not a fake OK.
|
| 3360 |
+
"status": "ok" if degraded_n == 0 else "degraded",
|
| 3361 |
+
"endpoints_total": total,
|
| 3362 |
+
"endpoints_live": live_n,
|
| 3363 |
+
"endpoints_degraded": degraded_n,
|
| 3364 |
+
"degraded_tiles": degraded[:12],
|
| 3365 |
+
"all_sources_live": bool(summary.get("all_sources_live", degraded_n == 0)),
|
| 3366 |
+
}
|
| 3367 |
+
except Exception as exc:
|
| 3368 |
+
val = {"status": "unavailable", "endpoints_total": None,
|
| 3369 |
+
"endpoints_live": None,
|
| 3370 |
+
"error": f"{type(exc).__name__}: {exc}"}
|
| 3371 |
+
_FRONTIER_HEALTH_CACHE.update({"checked_at": now, "value": val})
|
| 3372 |
+
return val
|
| 3373 |
+
|
| 3374 |
+
|
| 3375 |
@app.get("/api/a11oy/healthz")
|
| 3376 |
async def healthz() -> JSONResponse:
|
| 3377 |
dep = await _healthz_dep_ping()
|
| 3378 |
_ca = dep.get("checked_at")
|
| 3379 |
_storage = _ledger_storage_signal()
|
| 3380 |
+
_signer = _signer_availability_signal()
|
| 3381 |
+
_frontier = _frontier_liveness_signal()
|
| 3382 |
+
# Honest overall status. PRESSURE is advisory (still "ok" overall but
|
| 3383 |
+
# surfaced). Never fake green.
|
| 3384 |
+
# Overall degrades on a hard storage failure (disk full / read-only). The
|
| 3385 |
+
# signer being UNSIGNED-LOCAL and frontier tiles being degraded are surfaced
|
| 3386 |
+
# honestly but do NOT flip the overall status (they are expected on a CPU
|
| 3387 |
+
# Space / when sub-sources are idle) — an UNAVAILABLE probe on either, or a
|
| 3388 |
+
# storage failure, does degrade so an orchestrator catches a real fault.
|
| 3389 |
+
_degraded_reasons = []
|
| 3390 |
+
if str(_storage.get("status")) == "unavailable":
|
| 3391 |
+
_degraded_reasons.append("storage-unavailable")
|
| 3392 |
+
if str(_signer.get("status")) == "unavailable":
|
| 3393 |
+
_degraded_reasons.append("signer-probe-unavailable")
|
| 3394 |
+
if str(_frontier.get("status")) == "unavailable":
|
| 3395 |
+
_degraded_reasons.append("frontier-probe-unavailable")
|
| 3396 |
+
_overall = "degraded" if _degraded_reasons else "ok"
|
| 3397 |
return JSONResponse({
|
| 3398 |
"status": _overall,
|
| 3399 |
+
"degraded_reasons": _degraded_reasons,
|
| 3400 |
"service": "a11oy",
|
| 3401 |
"version": "2.0.0",
|
| 3402 |
"surface": "Brand Orchestration Layer",
|
| 3403 |
"base_path": "/",
|
| 3404 |
"doctrine": "v11",
|
| 3405 |
"uptime_s": round(_hz_time.time() - _A11OY_START_TIME, 1),
|
| 3406 |
+
"rollup": {
|
| 3407 |
+
"storage": _storage,
|
| 3408 |
+
"signer": _signer,
|
| 3409 |
+
"frontier": _frontier,
|
| 3410 |
+
},
|
| 3411 |
"storage": _storage,
|
| 3412 |
"dependency": {"node_backend": {"status": dep.get("status"), "backend_alive": dep.get("backend_alive"), "last_checked_age_s": round(_hz_time.time() - _ca, 1) if _ca else None}},
|
| 3413 |
"gates": len(_gates_list),
|
|
|
|
| 5764 |
"sbom": "https://github.com/szl-holdings/a11oy/releases/download/v1.0.0/a11oy-sbom.cdx.json",
|
| 5765 |
"honest": "https://szlholdings-a11oy.hf.space/api/a11oy/v1/honest",
|
| 5766 |
},
|
| 5767 |
+
# ADDITIVE (waveL Dev2): machine-readable release record of the waves'
|
| 5768 |
+
# shipped capabilities with HONEST labels. Mirrors CHANGELOG.md; the
|
| 5769 |
+
# canonical human record is CHANGELOG.md. Λ = Conjecture 1; no upgrades.
|
| 5770 |
+
"changelog": "https://github.com/szl-holdings/a11oy/blob/main/CHANGELOG.md",
|
| 5771 |
+
"capabilities": [
|
| 5772 |
+
{"name": "governed behavior-transfer harness", "label": "MEASURED", "prs": [759, 763]},
|
| 5773 |
+
{"name": "governed eval / red-team arena", "label": "MEASURED", "prs": [766]},
|
| 5774 |
+
{"name": "governed RAG (retrieval-with-receipts)", "label": "MEASURED", "prs": [776]},
|
| 5775 |
+
{"name": "governed agent loop (signed composite run)", "label": "MEASURED", "prs": [773, 757]},
|
| 5776 |
+
{"name": "governed VQC / QML frontier", "label": "SIMULATION-ONLY", "prs": [764, 782]},
|
| 5777 |
+
{"name": "attested inference (TEE-bound receipt)", "label": "UNAVAILABLE-on-CPU (MEASURED on live TDX/Nitro)", "prs": [767]},
|
| 5778 |
+
{"name": "durable bounded receipt/energy ledger + storage-pressure signal", "label": "MEASURED", "prs": [774]},
|
| 5779 |
+
{"name": "measured energy channel (NVML counter-delta)", "label": "MEASURED-behind-live-meter (else UNAVAILABLE)", "prs": [785, 789, 790]},
|
| 5780 |
+
{"name": "substrate consolidation (68/68 movable modules, guarded fallback)", "label": "MEASURED", "prs": [792]},
|
| 5781 |
+
{"name": "transitive COPY-completeness deploy guard", "label": "MEASURED", "prs": []},
|
| 5782 |
+
{"name": "/healthz release rollup (storage/signer/frontier)", "label": "MEASURED", "prs": []},
|
| 5783 |
+
],
|
| 5784 |
+
"lambda": "Conjecture 1 (never a theorem)",
|
| 5785 |
+
"locked_8": 8,
|
| 5786 |
}
|
| 5787 |
|
| 5788 |
|