betterwithage commited on
Commit
6f1d2fc
·
verified ·
1 Parent(s): e830cd0

chore(sync): mirror backend .py + Dockerfile to Space (hf-sync-backend)

Browse files

Automated backend sync from szl-holdings/a11oy main via hf-sync-backend.
Updated (differed from the Space): a11oy_frontier_patch.py, serve.py
Deleted (gone from the repo + Dockerfile COPY set): (none)

Keeps the Space-built backend (serve.py + the Dockerfile-COPY'd .py
modules) identical to GitHub main so the Space never rebuilds from a
stale backend, new endpoints don't 404 there, and orphaned modules
removed from the repo don't linger in the Space tree.

Files changed (2) hide show
  1. a11oy_frontier_patch.py +20 -0
  2. serve.py +114 -4
a11oy_frontier_patch.py CHANGED
@@ -49,6 +49,26 @@ async def _a11oy_frontier_version(request: Request):
49
  "cosign": "cosign verify ghcr.io/szl-holdings/a11oy:v1.0.0 --certificate-identity-regexp=szl-holdings",
50
  "sbom": "https://github.com/szl-holdings/a11oy/releases/download/v1.0.0/a11oy-sbom.cdx.json",
51
  },
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
52
  "ts": _NOW(),
53
  })
54
 
 
49
  "cosign": "cosign verify ghcr.io/szl-holdings/a11oy:v1.0.0 --certificate-identity-regexp=szl-holdings",
50
  "sbom": "https://github.com/szl-holdings/a11oy/releases/download/v1.0.0/a11oy-sbom.cdx.json",
51
  },
52
+ # ADDITIVE (waveL Dev2): machine-readable release record of the waves'
53
+ # shipped capabilities, HONEST labels. Canonical human record: CHANGELOG.md.
54
+ # This is the front-moved live /v1/version handler, so the release record
55
+ # must live here (not only in serve.py's shadowed copy). Lambda=Conjecture 1.
56
+ "changelog": "https://github.com/szl-holdings/a11oy/blob/main/CHANGELOG.md",
57
+ "capabilities": [
58
+ {"name": "governed behavior-transfer harness", "label": "MEASURED", "prs": [759, 763]},
59
+ {"name": "governed eval / red-team arena", "label": "MEASURED", "prs": [766]},
60
+ {"name": "governed RAG (retrieval-with-receipts)", "label": "MEASURED", "prs": [776]},
61
+ {"name": "governed agent loop (signed composite run)", "label": "MEASURED", "prs": [773, 757]},
62
+ {"name": "governed VQC / QML frontier", "label": "SIMULATION-ONLY", "prs": [764, 782]},
63
+ {"name": "attested inference (TEE-bound receipt)", "label": "UNAVAILABLE-on-CPU (MEASURED on live TDX/Nitro)", "prs": [767]},
64
+ {"name": "durable bounded receipt/energy ledger + storage-pressure signal", "label": "MEASURED", "prs": [774]},
65
+ {"name": "measured energy channel (NVML counter-delta)", "label": "MEASURED-behind-live-meter (else UNAVAILABLE)", "prs": [785, 789, 790]},
66
+ {"name": "substrate consolidation (68/68 movable modules, guarded fallback)", "label": "MEASURED", "prs": [792]},
67
+ {"name": "transitive COPY-completeness deploy guard", "label": "MEASURED", "prs": []},
68
+ {"name": "/healthz release rollup (storage/signer/frontier)", "label": "MEASURED", "prs": []},
69
+ ],
70
+ "lambda": "Conjecture 1 (never a theorem)",
71
+ "locked_8": 8,
72
  "ts": _NOW(),
73
  })
74
 
serve.py CHANGED
@@ -3300,23 +3300,114 @@ def _ledger_storage_signal(ttl: float = 15.0) -> dict:
3300
  return val
3301
 
3302
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
3303
  @app.get("/api/a11oy/healthz")
3304
  async def healthz() -> JSONResponse:
3305
  dep = await _healthz_dep_ping()
3306
  _ca = dep.get("checked_at")
3307
  _storage = _ledger_storage_signal()
3308
- # Honest overall status: degrade the probe when the receipt/energy store is
3309
- # UNAVAILABLE (disk full / read-only) so an orchestrator/healthcheck catches it.
3310
- # PRESSURE is advisory (still "ok" overall but surfaced). Never fake green.
3311
- _overall = "degraded" if str(_storage.get("status")) == "unavailable" else "ok"
 
 
 
 
 
 
 
 
 
 
 
 
 
3312
  return JSONResponse({
3313
  "status": _overall,
 
3314
  "service": "a11oy",
3315
  "version": "2.0.0",
3316
  "surface": "Brand Orchestration Layer",
3317
  "base_path": "/",
3318
  "doctrine": "v11",
3319
  "uptime_s": round(_hz_time.time() - _A11OY_START_TIME, 1),
 
 
 
 
 
3320
  "storage": _storage,
3321
  "dependency": {"node_backend": {"status": dep.get("status"), "backend_alive": dep.get("backend_alive"), "last_checked_age_s": round(_hz_time.time() - _ca, 1) if _ca else None}},
3322
  "gates": len(_gates_list),
@@ -5673,6 +5764,25 @@ async def a11oy_version():
5673
  "sbom": "https://github.com/szl-holdings/a11oy/releases/download/v1.0.0/a11oy-sbom.cdx.json",
5674
  "honest": "https://szlholdings-a11oy.hf.space/api/a11oy/v1/honest",
5675
  },
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
5676
  }
5677
 
5678
 
 
3300
  return val
3301
 
3302
 
3303
+ # ADDITIVE (waveL Dev2 — release-engineering observability rollup): two more tiny
3304
+ # cached, guarded probes so /healthz reports an HONEST release rollup alongside the
3305
+ # durable-ledger storage-pressure signal:
3306
+ # (a) DSSE SIGNER AVAILABILITY — is the cosign/DSSE private key present in this
3307
+ # Space (live signing) or are we emitting UNSIGNED-LOCAL envelopes? Read
3308
+ # straight from szl_dsse.signing_available(); never fabricated.
3309
+ # (b) FRONTIER-ENDPOINT LIVENESS COUNT — how many governed-provenance frontier
3310
+ # tiles are live vs degraded, read from szl_frontier_manifest's already-
3311
+ # cached, real-probe-only manifest summary. A down sub-source is reported
3312
+ # honestly (UNAVAILABLE), never faked green.
3313
+ # Both are guarded + cached (never block the health path, never crash it, never
3314
+ # fabricate). Λ = Conjecture 1; no label is upgraded here.
3315
+ _SIGNER_HEALTH_CACHE: dict = {}
3316
+ _FRONTIER_HEALTH_CACHE: dict = {}
3317
+
3318
+
3319
+ def _signer_availability_signal(ttl: float = 30.0) -> dict:
3320
+ now = _hz_time.time()
3321
+ ca = _SIGNER_HEALTH_CACHE.get("checked_at")
3322
+ if ca is not None and (now - ca) < ttl:
3323
+ return _SIGNER_HEALTH_CACHE.get("value", {})
3324
+ try:
3325
+ import szl_dsse as _szl_dsse_health
3326
+ available = bool(_szl_dsse_health.signing_available())
3327
+ val = {
3328
+ # honest label: DSSE-LIVE only when a real private key is present in
3329
+ # this Space; otherwise UNSIGNED-LOCAL (receipts explicitly unsigned).
3330
+ "status": "DSSE-LIVE" if available else "UNSIGNED-LOCAL",
3331
+ "signing_available": available,
3332
+ "scheme": "DSSEv1 / ECDSA-P256 (cosign keyless OIDC at release)",
3333
+ }
3334
+ try:
3335
+ val["public_key_fingerprint"] = _szl_dsse_health.public_key_fingerprint()
3336
+ except Exception:
3337
+ pass
3338
+ except Exception as exc:
3339
+ val = {"status": "unavailable", "signing_available": None,
3340
+ "error": f"{type(exc).__name__}: {exc}"}
3341
+ _SIGNER_HEALTH_CACHE.update({"checked_at": now, "value": val})
3342
+ return val
3343
+
3344
+
3345
+ def _frontier_liveness_signal(ttl: float = 30.0) -> dict:
3346
+ now = _hz_time.time()
3347
+ ca = _FRONTIER_HEALTH_CACHE.get("checked_at")
3348
+ if ca is not None and (now - ca) < ttl:
3349
+ return _FRONTIER_HEALTH_CACHE.get("value", {})
3350
+ try:
3351
+ import szl_frontier_manifest as _szl_fm_health
3352
+ manifest = _szl_fm_health.build_manifest()
3353
+ summary = manifest.get("summary", {}) if isinstance(manifest, dict) else {}
3354
+ total = int(summary.get("tiles", 0) or 0)
3355
+ degraded = summary.get("degraded_tiles", []) or []
3356
+ degraded_n = len(degraded)
3357
+ live_n = max(total - degraded_n, 0)
3358
+ val = {
3359
+ # honest: a down sub-source is a degraded tile, not a fake OK.
3360
+ "status": "ok" if degraded_n == 0 else "degraded",
3361
+ "endpoints_total": total,
3362
+ "endpoints_live": live_n,
3363
+ "endpoints_degraded": degraded_n,
3364
+ "degraded_tiles": degraded[:12],
3365
+ "all_sources_live": bool(summary.get("all_sources_live", degraded_n == 0)),
3366
+ }
3367
+ except Exception as exc:
3368
+ val = {"status": "unavailable", "endpoints_total": None,
3369
+ "endpoints_live": None,
3370
+ "error": f"{type(exc).__name__}: {exc}"}
3371
+ _FRONTIER_HEALTH_CACHE.update({"checked_at": now, "value": val})
3372
+ return val
3373
+
3374
+
3375
  @app.get("/api/a11oy/healthz")
3376
  async def healthz() -> JSONResponse:
3377
  dep = await _healthz_dep_ping()
3378
  _ca = dep.get("checked_at")
3379
  _storage = _ledger_storage_signal()
3380
+ _signer = _signer_availability_signal()
3381
+ _frontier = _frontier_liveness_signal()
3382
+ # Honest overall status. PRESSURE is advisory (still "ok" overall but
3383
+ # surfaced). Never fake green.
3384
+ # Overall degrades on a hard storage failure (disk full / read-only). The
3385
+ # signer being UNSIGNED-LOCAL and frontier tiles being degraded are surfaced
3386
+ # honestly but do NOT flip the overall status (they are expected on a CPU
3387
+ # Space / when sub-sources are idle) — an UNAVAILABLE probe on either, or a
3388
+ # storage failure, does degrade so an orchestrator catches a real fault.
3389
+ _degraded_reasons = []
3390
+ if str(_storage.get("status")) == "unavailable":
3391
+ _degraded_reasons.append("storage-unavailable")
3392
+ if str(_signer.get("status")) == "unavailable":
3393
+ _degraded_reasons.append("signer-probe-unavailable")
3394
+ if str(_frontier.get("status")) == "unavailable":
3395
+ _degraded_reasons.append("frontier-probe-unavailable")
3396
+ _overall = "degraded" if _degraded_reasons else "ok"
3397
  return JSONResponse({
3398
  "status": _overall,
3399
+ "degraded_reasons": _degraded_reasons,
3400
  "service": "a11oy",
3401
  "version": "2.0.0",
3402
  "surface": "Brand Orchestration Layer",
3403
  "base_path": "/",
3404
  "doctrine": "v11",
3405
  "uptime_s": round(_hz_time.time() - _A11OY_START_TIME, 1),
3406
+ "rollup": {
3407
+ "storage": _storage,
3408
+ "signer": _signer,
3409
+ "frontier": _frontier,
3410
+ },
3411
  "storage": _storage,
3412
  "dependency": {"node_backend": {"status": dep.get("status"), "backend_alive": dep.get("backend_alive"), "last_checked_age_s": round(_hz_time.time() - _ca, 1) if _ca else None}},
3413
  "gates": len(_gates_list),
 
5764
  "sbom": "https://github.com/szl-holdings/a11oy/releases/download/v1.0.0/a11oy-sbom.cdx.json",
5765
  "honest": "https://szlholdings-a11oy.hf.space/api/a11oy/v1/honest",
5766
  },
5767
+ # ADDITIVE (waveL Dev2): machine-readable release record of the waves'
5768
+ # shipped capabilities with HONEST labels. Mirrors CHANGELOG.md; the
5769
+ # canonical human record is CHANGELOG.md. Λ = Conjecture 1; no upgrades.
5770
+ "changelog": "https://github.com/szl-holdings/a11oy/blob/main/CHANGELOG.md",
5771
+ "capabilities": [
5772
+ {"name": "governed behavior-transfer harness", "label": "MEASURED", "prs": [759, 763]},
5773
+ {"name": "governed eval / red-team arena", "label": "MEASURED", "prs": [766]},
5774
+ {"name": "governed RAG (retrieval-with-receipts)", "label": "MEASURED", "prs": [776]},
5775
+ {"name": "governed agent loop (signed composite run)", "label": "MEASURED", "prs": [773, 757]},
5776
+ {"name": "governed VQC / QML frontier", "label": "SIMULATION-ONLY", "prs": [764, 782]},
5777
+ {"name": "attested inference (TEE-bound receipt)", "label": "UNAVAILABLE-on-CPU (MEASURED on live TDX/Nitro)", "prs": [767]},
5778
+ {"name": "durable bounded receipt/energy ledger + storage-pressure signal", "label": "MEASURED", "prs": [774]},
5779
+ {"name": "measured energy channel (NVML counter-delta)", "label": "MEASURED-behind-live-meter (else UNAVAILABLE)", "prs": [785, 789, 790]},
5780
+ {"name": "substrate consolidation (68/68 movable modules, guarded fallback)", "label": "MEASURED", "prs": [792]},
5781
+ {"name": "transitive COPY-completeness deploy guard", "label": "MEASURED", "prs": []},
5782
+ {"name": "/healthz release rollup (storage/signer/frontier)", "label": "MEASURED", "prs": []},
5783
+ ],
5784
+ "lambda": "Conjecture 1 (never a theorem)",
5785
+ "locked_8": 8,
5786
  }
5787
 
5788