betterwithage commited on
Commit
8dbce63
·
verified ·
1 Parent(s): fcc3a97

chore(sync): mirror backend .py + Dockerfile to Space (hf-sync-backend)

Browse files

Automated backend sync from szl-holdings/a11oy main via hf-sync-backend.
Updated (differed from the Space): Dockerfile, gdw_attention.py, gdw_proofs.py, gdw_telemetry.py, gdw_workspace.py, routers/gdw_frontier.py, serve.py
Deleted (gone from the repo + Dockerfile COPY set): (none)

Keeps the Space-built backend (serve.py + the Dockerfile-COPY'd .py
modules) identical to GitHub main so the Space never rebuilds from a
stale backend, new endpoints don't 404 there, and orphaned modules
removed from the repo don't linger in the Space tree.

Files changed (7) hide show
  1. Dockerfile +1 -0
  2. gdw_attention.py +141 -0
  3. gdw_proofs.py +77 -0
  4. gdw_telemetry.py +83 -0
  5. gdw_workspace.py +336 -0
  6. routers/gdw_frontier.py +399 -0
  7. serve.py +18 -0
Dockerfile CHANGED
@@ -612,6 +612,7 @@ COPY szl_spend_cap.py ./szl_spend_cap.py
612
  # WAVE R Dev 1 — boot-resilience env/secret preflight. Per-file COPY (this
613
  # … (full rationale: docs/DOCKERFILE_NOTES.md §91)
614
  COPY a11oy_model_intel.py a11oy_experimental_tier.py a11oy_markets.py szl_agent_tts.py szl_gated_delta.py szl_blocksparse.py szl_retrieval_attn.py szl_model_harness.py szl_agent_loop_governed.py szl_crypto_pipeline.py szl_confattest.py szl_agent_operate.py szl_agentloop_brain.py szl_governed_rag.py szl_sovereign_flywheel.py szl_brain_corpus.py szl_verify_transcript.py szl_frontier_index.py szl_whatsnew.py szl_honestywall.py szl_brainmemory.py szl_agentos.py szl_brainground.py szl_brainuncertainty.py szl_brainhealth.py szl_brainwatch.py szl_boot_preflight.py szl_guarded_surface.py szl_status_aggregate.py szl_brainconstitution.py szl_brainagent.py szl_surface_manifests.py szl_source_attestation.py szl_compute_pool_contract.py szl_estateconstitution.py ./
 
615
  COPY static/3d/surfaces/gateddelta.js static/3d/surfaces/blocksparse.js static/3d/surfaces/retrievalattn.js static/3d/surfaces/governedagent.js static/3d/surfaces/cryptopipeline.js static/3d/surfaces/confattest.js static/3d/surfaces/agentops.js static/3d/surfaces/frontierindex.js static/3d/surfaces/whatsnew.js static/3d/surfaces/opsdash.js ./static/3d/surfaces/
616
 
617
  # FORGE-FAMILY WALL (2026-07-14): /api/forge/family — server-side ed25519
 
612
  # WAVE R Dev 1 — boot-resilience env/secret preflight. Per-file COPY (this
613
  # … (full rationale: docs/DOCKERFILE_NOTES.md §91)
614
  COPY a11oy_model_intel.py a11oy_experimental_tier.py a11oy_markets.py szl_agent_tts.py szl_gated_delta.py szl_blocksparse.py szl_retrieval_attn.py szl_model_harness.py szl_agent_loop_governed.py szl_crypto_pipeline.py szl_confattest.py szl_agent_operate.py szl_agentloop_brain.py szl_governed_rag.py szl_sovereign_flywheel.py szl_brain_corpus.py szl_verify_transcript.py szl_frontier_index.py szl_whatsnew.py szl_honestywall.py szl_brainmemory.py szl_agentos.py szl_brainground.py szl_brainuncertainty.py szl_brainhealth.py szl_brainwatch.py szl_boot_preflight.py szl_guarded_surface.py szl_status_aggregate.py szl_brainconstitution.py szl_brainagent.py szl_surface_manifests.py szl_source_attestation.py szl_compute_pool_contract.py szl_estateconstitution.py ./
615
+ COPY gdw_attention.py gdw_workspace.py gdw_telemetry.py gdw_proofs.py ./
616
  COPY static/3d/surfaces/gateddelta.js static/3d/surfaces/blocksparse.js static/3d/surfaces/retrievalattn.js static/3d/surfaces/governedagent.js static/3d/surfaces/cryptopipeline.js static/3d/surfaces/confattest.js static/3d/surfaces/agentops.js static/3d/surfaces/frontierindex.js static/3d/surfaces/whatsnew.js static/3d/surfaces/opsdash.js ./static/3d/surfaces/
617
 
618
  # FORGE-FAMILY WALL (2026-07-14): /api/forge/family — server-side ed25519
gdw_attention.py ADDED
@@ -0,0 +1,141 @@
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
1
+ """Governed Delta Workspace attention-route policy and eager Torch dispatcher.
2
+
3
+ The HTTP service uses the deterministic policy below. The optional Torch router is
4
+ an executable research hook; it is not loaded unless a caller explicitly uses it.
5
+ """
6
+
7
+ from dataclasses import dataclass
8
+ from typing import Any, Callable, Dict, Optional
9
+
10
+
11
+ ROUTE_NAMES = ("kda_local", "laguna_hybrid", "mla_global")
12
+
13
+
14
+ @dataclass(frozen=True)
15
+ class AttentionFeatures:
16
+ novelty: float
17
+ disagreement: float
18
+ risk: float
19
+ context_tokens: int
20
+ active_tool_count: int
21
+ memory_pressure: float
22
+
23
+
24
+ def _clamp(value: float) -> float:
25
+ return max(0.0, min(1.0, float(value)))
26
+
27
+
28
+ def choose_attention_mode(
29
+ features: AttentionFeatures,
30
+ mode_hint: str = "auto",
31
+ ) -> Dict[str, Any]:
32
+ """Choose a governed local, mixed, or global attention budget."""
33
+ if mode_hint in ROUTE_NAMES:
34
+ probabilities = {name: 1.0 if name == mode_hint else 0.0 for name in ROUTE_NAMES}
35
+ return {
36
+ "mode": mode_hint,
37
+ "score": None,
38
+ "probabilities": probabilities,
39
+ "reason": "explicit_validated_hint",
40
+ }
41
+
42
+ context = _clamp(features.context_tokens / 32768.0)
43
+ tools = _clamp(features.active_tool_count / 16.0)
44
+ memory = _clamp(features.memory_pressure)
45
+ score = _clamp(
46
+ 0.20 * _clamp(features.novelty)
47
+ + 0.25 * _clamp(features.disagreement)
48
+ + 0.30 * _clamp(features.risk)
49
+ + 0.15 * context
50
+ + 0.10 * tools
51
+ - 0.25 * memory
52
+ )
53
+
54
+ if memory >= 0.85:
55
+ mode = "kda_local"
56
+ reason = "memory_pressure_guard"
57
+ elif score < 0.33:
58
+ mode = "kda_local"
59
+ reason = "bounded_local_budget"
60
+ elif score < 0.66:
61
+ mode = "laguna_hybrid"
62
+ reason = "mixed_local_global_budget"
63
+ else:
64
+ mode = "mla_global"
65
+ reason = "global_context_budget"
66
+
67
+ centers = (0.16, 0.50, 0.84)
68
+ weights = [max(0.0, 1.0 - abs(score - center) / 0.5) for center in centers]
69
+ total = sum(weights) or 1.0
70
+ probabilities = {
71
+ name: round(weight / total, 6)
72
+ for name, weight in zip(ROUTE_NAMES, weights)
73
+ }
74
+ return {
75
+ "mode": mode,
76
+ "score": round(score, 6),
77
+ "probabilities": probabilities,
78
+ "reason": reason,
79
+ }
80
+
81
+
82
+ try:
83
+ import torch
84
+ from torch import nn
85
+ except Exception:
86
+ torch = None
87
+ nn = None
88
+
89
+
90
+ if nn is not None:
91
+
92
+ class HybridAttentionRouter(nn.Module):
93
+ """Trainable eager-mode KDA/Laguna/MLA route selector."""
94
+
95
+ def __init__(self, d_model: int):
96
+ super().__init__()
97
+ if d_model <= 0:
98
+ raise ValueError("d_model must be positive")
99
+ self.mode_proj = nn.Linear(d_model, 3)
100
+
101
+ def forward(self, summary_state):
102
+ logits = self.mode_proj(summary_state)
103
+ probabilities = torch.softmax(logits, dim=-1)
104
+ return probabilities.argmax(dim=-1), probabilities
105
+
106
+ else:
107
+
108
+ class HybridAttentionRouter:
109
+ def __init__(self, d_model: int):
110
+ raise RuntimeError("Torch is required for HybridAttentionRouter")
111
+
112
+
113
+ def hybrid_attention_dispatch(
114
+ mode,
115
+ x,
116
+ kda_fn: Callable,
117
+ mla_fn: Callable,
118
+ laguna_fn: Callable,
119
+ ):
120
+ """Batch samples by route before dispatch to reduce per-sample divergence."""
121
+ if torch is None:
122
+ raise RuntimeError("Torch is required for hybrid_attention_dispatch")
123
+ if mode.ndim != 1 or mode.shape[0] != x.shape[0]:
124
+ raise ValueError("mode must be a one-dimensional tensor matching batch size")
125
+
126
+ output: Optional[Any] = None
127
+ for route_id, route_fn in ((0, kda_fn), (1, mla_fn), (2, laguna_fn)):
128
+ indexes = torch.nonzero(mode == route_id, as_tuple=False).flatten()
129
+ if indexes.numel() == 0:
130
+ continue
131
+ routed = route_fn(x.index_select(0, indexes))
132
+ if output is None:
133
+ output = torch.empty(
134
+ (x.shape[0],) + tuple(routed.shape[1:]),
135
+ dtype=routed.dtype,
136
+ device=routed.device,
137
+ )
138
+ output.index_copy_(0, indexes, routed)
139
+ if output is None:
140
+ raise ValueError("mode contains no valid route ids")
141
+ return output
gdw_proofs.py ADDED
@@ -0,0 +1,77 @@
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
1
+ """Structured theorem-input export for asynchronous Lean checking."""
2
+
3
+ import hashlib
4
+ import json
5
+ import os
6
+ import tempfile
7
+ from pathlib import Path
8
+ from typing import Any, Dict
9
+
10
+
11
+ def canonical_json(value: Any) -> str:
12
+ return json.dumps(value, sort_keys=True, separators=(",", ":"), ensure_ascii=True)
13
+
14
+
15
+ def sha256_json(value: Any) -> str:
16
+ return hashlib.sha256(canonical_json(value).encode("utf-8")).hexdigest()
17
+
18
+
19
+ def build_proof_payload(
20
+ proposal_id: str,
21
+ request_id: str,
22
+ step: int,
23
+ before_hash: str,
24
+ after_hash: str,
25
+ decision: str,
26
+ scheduler_mode: str,
27
+ receipt_hash: str,
28
+ dry_run: bool,
29
+ ) -> Dict[str, Any]:
30
+ mutates = decision == "ACCEPT" and not dry_run
31
+ payload = {
32
+ "schema": "szl.gdw.proof-input/v1",
33
+ "proposal_id": proposal_id,
34
+ "request_id": request_id,
35
+ "step_id": step,
36
+ "state_before_hash": before_hash,
37
+ "state_after_hash": after_hash,
38
+ "decision": decision,
39
+ "scheduler_mode": scheduler_mode,
40
+ "delta_update_receipt_hash": receipt_hash,
41
+ "invariants": {
42
+ "step_nonnegative": step >= 0,
43
+ "accepted_write_has_receipt": (not mutates) or bool(receipt_hash),
44
+ "non_mutating_preserves_state": mutates or before_hash == after_hash,
45
+ "scheduler_mode_valid": scheduler_mode
46
+ in {"kda_local", "laguna_hybrid", "mla_global"},
47
+ },
48
+ "formal_status": "NOT_RUN",
49
+ }
50
+ payload["payload_sha256"] = sha256_json(payload)
51
+ return payload
52
+
53
+
54
+ def export_proof_payload(payload: Dict[str, Any]) -> Dict[str, Any]:
55
+ root = Path(os.environ.get("GDW_PROOF_DIR", "output/proofs")).resolve()
56
+ root.mkdir(parents=True, exist_ok=True)
57
+ proposal_id = payload["proposal_id"]
58
+ if not proposal_id or any(ch not in "0123456789abcdef" for ch in proposal_id):
59
+ raise ValueError("proposal_id is not a canonical lowercase hexadecimal id")
60
+ destination = root / f"{proposal_id}.json"
61
+ encoded = (json.dumps(payload, indent=2, sort_keys=True) + "\n").encode("utf-8")
62
+ handle, temporary = tempfile.mkstemp(prefix=".gdw-proof-", suffix=".tmp", dir=root)
63
+ try:
64
+ with os.fdopen(handle, "wb") as stream:
65
+ stream.write(encoded)
66
+ stream.flush()
67
+ os.fsync(stream.fileno())
68
+ os.replace(temporary, destination)
69
+ finally:
70
+ if os.path.exists(temporary):
71
+ os.unlink(temporary)
72
+ return {
73
+ "status": "INPUT_EXPORTED",
74
+ "path": str(destination),
75
+ "sha256": hashlib.sha256(encoded).hexdigest(),
76
+ "formal_status": "NOT_RUN",
77
+ }
gdw_telemetry.py ADDED
@@ -0,0 +1,83 @@
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
1
+ """In-process GDW counters and Prometheus text export."""
2
+
3
+ import math
4
+ import threading
5
+ from collections import Counter, deque
6
+ from typing import Any, Dict, Iterable, List
7
+
8
+
9
+ class GDWTelemetry:
10
+ def __init__(self):
11
+ self._lock = threading.Lock()
12
+ self._requests = 0
13
+ self._errors = 0
14
+ self._receipts = 0
15
+ self._decisions = Counter()
16
+ self._routes = Counter()
17
+ self._latencies_ms = deque(maxlen=10000)
18
+
19
+ def observe(
20
+ self,
21
+ latency_ms: float,
22
+ decision: str,
23
+ route: str,
24
+ receipt_emitted: bool,
25
+ error: bool = False,
26
+ ) -> None:
27
+ with self._lock:
28
+ self._requests += 1
29
+ self._errors += int(error)
30
+ self._receipts += int(receipt_emitted)
31
+ self._decisions[decision] += 1
32
+ self._routes[route] += 1
33
+ self._latencies_ms.append(float(latency_ms))
34
+
35
+ @staticmethod
36
+ def _percentile(values: Iterable[float], quantile: float) -> float:
37
+ ordered = sorted(values)
38
+ if not ordered:
39
+ return 0.0
40
+ position = (len(ordered) - 1) * quantile
41
+ lower = math.floor(position)
42
+ upper = math.ceil(position)
43
+ if lower == upper:
44
+ return ordered[lower]
45
+ return ordered[lower] + (ordered[upper] - ordered[lower]) * (position - lower)
46
+
47
+ def snapshot(self) -> Dict[str, Any]:
48
+ with self._lock:
49
+ latencies: List[float] = list(self._latencies_ms)
50
+ return {
51
+ "requests": self._requests,
52
+ "errors": self._errors,
53
+ "receipts": self._receipts,
54
+ "decisions": dict(self._decisions),
55
+ "routes": dict(self._routes),
56
+ "p50_ms": round(self._percentile(latencies, 0.50), 6),
57
+ "p95_ms": round(self._percentile(latencies, 0.95), 6),
58
+ "p99_ms": round(self._percentile(latencies, 0.99), 6),
59
+ }
60
+
61
+ def render(self) -> str:
62
+ snapshot = self.snapshot()
63
+ lines = [
64
+ "# HELP gdw_requests_total Governed Delta Workspace requests.",
65
+ "# TYPE gdw_requests_total counter",
66
+ f"gdw_requests_total {snapshot['requests']}",
67
+ "# HELP gdw_errors_total Governed Delta Workspace errors.",
68
+ "# TYPE gdw_errors_total counter",
69
+ f"gdw_errors_total {snapshot['errors']}",
70
+ "# HELP gdw_receipts_total Persisted transition receipts.",
71
+ "# TYPE gdw_receipts_total counter",
72
+ f"gdw_receipts_total {snapshot['receipts']}",
73
+ ]
74
+ for decision, value in sorted(snapshot["decisions"].items()):
75
+ lines.append(f'gdw_decisions_total{{decision="{decision}"}} {value}')
76
+ for route, value in sorted(snapshot["routes"].items()):
77
+ lines.append(f'gdw_routes_total{{route="{route}"}} {value}')
78
+ for quantile in ("p50", "p95", "p99"):
79
+ lines.append(
80
+ f'gdw_latency_milliseconds{{quantile="{quantile}"}} '
81
+ f"{snapshot[quantile + '_ms']}"
82
+ )
83
+ return "\n".join(lines) + "\n"
gdw_workspace.py ADDED
@@ -0,0 +1,336 @@
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
1
+ """Concurrency-safe SQLite state, idempotency, and receipt storage for GDW."""
2
+
3
+ import contextlib
4
+ import json
5
+ import os
6
+ import sqlite3
7
+ import threading
8
+ from pathlib import Path
9
+ from typing import Any, Dict, Iterator, Optional, Tuple
10
+
11
+
12
+ _SCHEMA_LOCK = threading.RLock()
13
+ _PROCESS_WRITE_LOCK = threading.RLock()
14
+ _INITIALISED_PATHS = set()
15
+
16
+
17
+ class GDWWorkspace:
18
+ def __init__(self, path: Optional[str] = None):
19
+ configured = path or os.environ.get("GDW_DB_PATH", "output/gdw/gdw.sqlite3")
20
+ self.path = Path(configured).resolve()
21
+ self._initialise()
22
+
23
+ def _connect(self) -> sqlite3.Connection:
24
+ connection = sqlite3.connect(
25
+ str(self.path),
26
+ timeout=30.0,
27
+ isolation_level=None,
28
+ check_same_thread=False,
29
+ )
30
+ connection.row_factory = sqlite3.Row
31
+ connection.execute("PRAGMA busy_timeout=30000")
32
+ connection.execute("PRAGMA synchronous=NORMAL")
33
+ connection.execute("PRAGMA foreign_keys=ON")
34
+ return connection
35
+
36
+ def _initialise(self) -> None:
37
+ key = str(self.path)
38
+ if key in _INITIALISED_PATHS:
39
+ return
40
+ with _SCHEMA_LOCK:
41
+ if key in _INITIALISED_PATHS:
42
+ return
43
+ self.path.parent.mkdir(parents=True, exist_ok=True)
44
+ connection = sqlite3.connect(str(self.path), timeout=30.0)
45
+ try:
46
+ connection.execute("PRAGMA journal_mode=WAL")
47
+ connection.execute("PRAGMA synchronous=NORMAL")
48
+ connection.execute("PRAGMA foreign_keys=ON")
49
+ self._ensure_schema(connection)
50
+ connection.commit()
51
+ _INITIALISED_PATHS.add(key)
52
+ finally:
53
+ connection.close()
54
+
55
+ @staticmethod
56
+ def _ensure_schema(connection: sqlite3.Connection) -> None:
57
+ connection.executescript(
58
+ """
59
+ CREATE TABLE IF NOT EXISTS session_state (
60
+ session_id TEXT PRIMARY KEY,
61
+ step INTEGER NOT NULL CHECK(step >= 0),
62
+ state_json TEXT NOT NULL,
63
+ state_hash TEXT NOT NULL,
64
+ updated_at TEXT NOT NULL
65
+ );
66
+ CREATE TABLE IF NOT EXISTS requests (
67
+ request_id TEXT PRIMARY KEY,
68
+ request_digest TEXT NOT NULL,
69
+ session_id TEXT NOT NULL,
70
+ response_json TEXT NOT NULL,
71
+ response_hash TEXT NOT NULL,
72
+ created_at TEXT NOT NULL
73
+ );
74
+ CREATE TABLE IF NOT EXISTS receipts (
75
+ receipt_hash TEXT PRIMARY KEY,
76
+ request_id TEXT NOT NULL UNIQUE,
77
+ session_id TEXT NOT NULL,
78
+ step INTEGER NOT NULL,
79
+ receipt_json TEXT NOT NULL,
80
+ created_at TEXT NOT NULL,
81
+ FOREIGN KEY(request_id) REFERENCES requests(request_id)
82
+ DEFERRABLE INITIALLY DEFERRED
83
+ );
84
+ CREATE TABLE IF NOT EXISTS proof_outbox (
85
+ proposal_id TEXT PRIMARY KEY,
86
+ payload_json TEXT NOT NULL,
87
+ payload_sha256 TEXT NOT NULL,
88
+ status TEXT NOT NULL CHECK(status IN ('PENDING', 'EXPORTED')),
89
+ artifact_json TEXT,
90
+ created_at TEXT NOT NULL,
91
+ exported_at TEXT
92
+ );
93
+ CREATE INDEX IF NOT EXISTS idx_requests_session ON requests(session_id);
94
+ CREATE INDEX IF NOT EXISTS idx_receipts_session ON receipts(session_id, step);
95
+ CREATE INDEX IF NOT EXISTS idx_proof_outbox_status
96
+ ON proof_outbox(status, created_at);
97
+ """
98
+ )
99
+
100
+ @contextlib.contextmanager
101
+ def transaction(self) -> Iterator[sqlite3.Connection]:
102
+ with _PROCESS_WRITE_LOCK:
103
+ connection = self._connect()
104
+ try:
105
+ connection.execute("BEGIN IMMEDIATE")
106
+ yield connection
107
+ connection.execute("COMMIT")
108
+ except Exception:
109
+ connection.execute("ROLLBACK")
110
+ raise
111
+ finally:
112
+ connection.close()
113
+
114
+ @staticmethod
115
+ def cached_request(
116
+ connection: sqlite3.Connection,
117
+ request_id: str,
118
+ ) -> Optional[Tuple[str, Dict[str, Any]]]:
119
+ row = connection.execute(
120
+ "SELECT request_digest, response_json FROM requests WHERE request_id = ?",
121
+ (request_id,),
122
+ ).fetchone()
123
+ if row is None:
124
+ return None
125
+ return row["request_digest"], json.loads(row["response_json"])
126
+
127
+ @staticmethod
128
+ def session_state(
129
+ connection: sqlite3.Connection,
130
+ session_id: str,
131
+ ) -> Optional[Dict[str, Any]]:
132
+ row = connection.execute(
133
+ "SELECT step, state_json, state_hash, updated_at "
134
+ "FROM session_state WHERE session_id = ?",
135
+ (session_id,),
136
+ ).fetchone()
137
+ if row is None:
138
+ return None
139
+ return {
140
+ "session_id": session_id,
141
+ "step": int(row["step"]),
142
+ "state": json.loads(row["state_json"]),
143
+ "state_hash": row["state_hash"],
144
+ "updated_at": row["updated_at"],
145
+ }
146
+
147
+ @staticmethod
148
+ def save_state(
149
+ connection: sqlite3.Connection,
150
+ session_id: str,
151
+ step: int,
152
+ state: Dict[str, Any],
153
+ state_hash: str,
154
+ updated_at: str,
155
+ ) -> None:
156
+ connection.execute(
157
+ """
158
+ INSERT INTO session_state(session_id, step, state_json, state_hash, updated_at)
159
+ VALUES (?, ?, ?, ?, ?)
160
+ ON CONFLICT(session_id) DO UPDATE SET
161
+ step = excluded.step,
162
+ state_json = excluded.state_json,
163
+ state_hash = excluded.state_hash,
164
+ updated_at = excluded.updated_at
165
+ """,
166
+ (
167
+ session_id,
168
+ step,
169
+ json.dumps(state, sort_keys=True, separators=(",", ":")),
170
+ state_hash,
171
+ updated_at,
172
+ ),
173
+ )
174
+
175
+ @staticmethod
176
+ def save_request(
177
+ connection: sqlite3.Connection,
178
+ request_id: str,
179
+ request_digest: str,
180
+ session_id: str,
181
+ response: Dict[str, Any],
182
+ response_hash: str,
183
+ created_at: str,
184
+ ) -> None:
185
+ connection.execute(
186
+ """
187
+ INSERT INTO requests(
188
+ request_id, request_digest, session_id, response_json,
189
+ response_hash, created_at
190
+ ) VALUES (?, ?, ?, ?, ?, ?)
191
+ """,
192
+ (
193
+ request_id,
194
+ request_digest,
195
+ session_id,
196
+ json.dumps(response, sort_keys=True, separators=(",", ":")),
197
+ response_hash,
198
+ created_at,
199
+ ),
200
+ )
201
+
202
+ @staticmethod
203
+ def save_receipt(
204
+ connection: sqlite3.Connection,
205
+ receipt_hash: str,
206
+ request_id: str,
207
+ session_id: str,
208
+ step: int,
209
+ receipt: Dict[str, Any],
210
+ created_at: str,
211
+ ) -> None:
212
+ connection.execute(
213
+ """
214
+ INSERT INTO receipts(
215
+ receipt_hash, request_id, session_id, step, receipt_json, created_at
216
+ ) VALUES (?, ?, ?, ?, ?, ?)
217
+ """,
218
+ (
219
+ receipt_hash,
220
+ request_id,
221
+ session_id,
222
+ step,
223
+ json.dumps(receipt, sort_keys=True, separators=(",", ":")),
224
+ created_at,
225
+ ),
226
+ )
227
+
228
+ @staticmethod
229
+ def save_proof_outbox(
230
+ connection: sqlite3.Connection,
231
+ proposal_id: str,
232
+ payload: Dict[str, Any],
233
+ payload_sha256: str,
234
+ created_at: str,
235
+ ) -> None:
236
+ connection.execute(
237
+ """
238
+ INSERT INTO proof_outbox(
239
+ proposal_id, payload_json, payload_sha256, status, created_at
240
+ ) VALUES (?, ?, ?, 'PENDING', ?)
241
+ """,
242
+ (
243
+ proposal_id,
244
+ json.dumps(payload, sort_keys=True, separators=(",", ":")),
245
+ payload_sha256,
246
+ created_at,
247
+ ),
248
+ )
249
+
250
+ def pending_proofs(self, limit: int = 100) -> list:
251
+ bounded = max(1, min(int(limit), 10000))
252
+ connection = self._connect()
253
+ try:
254
+ rows = connection.execute(
255
+ """
256
+ SELECT proposal_id, payload_json, payload_sha256
257
+ FROM proof_outbox
258
+ WHERE status = 'PENDING'
259
+ ORDER BY created_at, proposal_id
260
+ LIMIT ?
261
+ """,
262
+ (bounded,),
263
+ ).fetchall()
264
+ return [
265
+ {
266
+ "proposal_id": row["proposal_id"],
267
+ "payload": json.loads(row["payload_json"]),
268
+ "payload_sha256": row["payload_sha256"],
269
+ }
270
+ for row in rows
271
+ ]
272
+ finally:
273
+ connection.close()
274
+
275
+ def mark_proof_exported(
276
+ self,
277
+ proposal_id: str,
278
+ artifact: Dict[str, Any],
279
+ exported_at: str,
280
+ ) -> None:
281
+ with self.transaction() as connection:
282
+ connection.execute(
283
+ """
284
+ UPDATE proof_outbox
285
+ SET status = 'EXPORTED', artifact_json = ?, exported_at = ?
286
+ WHERE proposal_id = ? AND status = 'PENDING'
287
+ """,
288
+ (
289
+ json.dumps(artifact, sort_keys=True, separators=(",", ":")),
290
+ exported_at,
291
+ proposal_id,
292
+ ),
293
+ )
294
+
295
+ def read_session(self, session_id: str) -> Optional[Dict[str, Any]]:
296
+ connection = self._connect()
297
+ try:
298
+ return self.session_state(connection, session_id)
299
+ finally:
300
+ connection.close()
301
+
302
+ def integrity(self) -> Dict[str, Any]:
303
+ connection = self._connect()
304
+ try:
305
+ check = connection.execute("PRAGMA integrity_check").fetchone()[0]
306
+ counts = {}
307
+ for table in ("session_state", "requests", "receipts", "proof_outbox"):
308
+ counts[table] = int(
309
+ connection.execute(f"SELECT COUNT(*) FROM {table}").fetchone()[0]
310
+ )
311
+ pending_proofs = int(
312
+ connection.execute(
313
+ "SELECT COUNT(*) FROM proof_outbox WHERE status = 'PENDING'"
314
+ ).fetchone()[0]
315
+ )
316
+ orphan_receipts = int(
317
+ connection.execute(
318
+ """
319
+ SELECT COUNT(*) FROM receipts r
320
+ LEFT JOIN requests q ON q.request_id = r.request_id
321
+ WHERE q.request_id IS NULL
322
+ """
323
+ ).fetchone()[0]
324
+ )
325
+ return {
326
+ "ok": check == "ok" and orphan_receipts == 0,
327
+ "sqlite_integrity": check,
328
+ "orphan_receipts": orphan_receipts,
329
+ "pending_proofs": pending_proofs,
330
+ "counts": counts,
331
+ "path": str(self.path),
332
+ "wal": True,
333
+ "synchronous": "NORMAL",
334
+ }
335
+ finally:
336
+ connection.close()
routers/gdw_frontier.py ADDED
@@ -0,0 +1,399 @@
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
1
+ """Authenticated Governed Delta Workspace API and benchmark surfaces."""
2
+
3
+ import hashlib
4
+ import hmac
5
+ import json
6
+ import os
7
+ import re
8
+ import time
9
+ from datetime import datetime, timezone
10
+ from typing import List, Literal, Optional
11
+
12
+ from fastapi import Header, HTTPException
13
+ from fastapi.responses import PlainTextResponse
14
+ from pydantic import BaseModel, Field
15
+
16
+ from gdw_attention import AttentionFeatures, choose_attention_mode
17
+ from gdw_proofs import build_proof_payload, export_proof_payload, sha256_json
18
+ from gdw_telemetry import GDWTelemetry
19
+ from gdw_workspace import GDWWorkspace
20
+ from szl_receipt_substrate import append_receipt
21
+ from szl_sgh_scheduler import build_plan
22
+
23
+
24
+ _TELEMETRY = GDWTelemetry()
25
+ _ID_PATTERN = re.compile(r"^[A-Za-z0-9._:-]{1,128}$")
26
+ _EXPERTS = {"planner", "retriever", "auditor", "verifier", "operator"}
27
+
28
+
29
+ class GDWStepRequest(BaseModel):
30
+ session_id: str = Field(min_length=1, max_length=128)
31
+ request: str = Field(min_length=1, max_length=4096)
32
+ allowed_experts: List[str] = Field(default_factory=list)
33
+ risk_budget: float = Field(default=0.35, ge=0.0, le=1.0)
34
+ mode_hint: Literal[
35
+ "auto", "kda_local", "laguna_hybrid", "mla_global"
36
+ ] = "auto"
37
+ dry_run: bool = False
38
+ novelty: Optional[float] = Field(default=None, ge=0.0, le=1.0)
39
+ disagreement: Optional[float] = Field(default=None, ge=0.0, le=1.0)
40
+ context_tokens: int = Field(default=0, ge=0, le=1000000)
41
+ active_tool_count: int = Field(default=0, ge=0, le=64)
42
+ memory_pressure: Optional[float] = Field(default=None, ge=0.0, le=1.0)
43
+
44
+ class Config:
45
+ extra = "forbid"
46
+
47
+
48
+ def _dump_model(model):
49
+ if hasattr(model, "model_dump"):
50
+ return model.model_dump(mode="json")
51
+ return model.dict()
52
+
53
+
54
+ def _now() -> str:
55
+ return datetime.now(timezone.utc).isoformat()
56
+
57
+
58
+ def _sha(value) -> str:
59
+ encoded = json.dumps(
60
+ value, sort_keys=True, separators=(",", ":"), ensure_ascii=True
61
+ ).encode("utf-8")
62
+ return hashlib.sha256(encoded).hexdigest()
63
+
64
+
65
+ def _authorise(authorization: Optional[str]) -> None:
66
+ token = os.environ.get("GDW_AUTH_TOKEN")
67
+ if not token:
68
+ raise HTTPException(
69
+ status_code=503,
70
+ detail="GDW_AUTH_TOKEN is not configured; write surface is unavailable",
71
+ )
72
+ supplied = authorization or ""
73
+ expected = "Bearer " + token
74
+ if not hmac.compare_digest(supplied, expected):
75
+ raise HTTPException(status_code=401, detail="invalid bearer token")
76
+
77
+
78
+ def _validate_identifiers(payload: GDWStepRequest, request_id: Optional[str]) -> str:
79
+ if not request_id or not _ID_PATTERN.fullmatch(request_id):
80
+ raise HTTPException(
81
+ status_code=422,
82
+ detail="X-Request-Id must be 1-128 canonical identifier characters",
83
+ )
84
+ if not _ID_PATTERN.fullmatch(payload.session_id):
85
+ raise HTTPException(status_code=422, detail="invalid session_id")
86
+ if len(payload.allowed_experts) > 16:
87
+ raise HTTPException(status_code=422, detail="too many allowed_experts")
88
+ return request_id
89
+
90
+
91
+ def _decision(payload: GDWStepRequest) -> str:
92
+ experts = set(payload.allowed_experts)
93
+ if not experts or not experts.issubset(_EXPERTS):
94
+ return "QUARANTINE"
95
+ if payload.risk_budget >= 0.90:
96
+ return "REJECT"
97
+ if payload.risk_budget >= 0.75:
98
+ return "QUARANTINE"
99
+ return "ACCEPT"
100
+
101
+
102
+ def register(app, ns: str = "a11oy"):
103
+ prefix = f"/api/{ns}/v1/gdw"
104
+
105
+ @app.get(prefix + "/healthz")
106
+ @app.get("/v1/gdw/healthz")
107
+ def gdw_healthz():
108
+ return {
109
+ "service": "gdw-frontier",
110
+ "status": "REAL",
111
+ "write_ready": bool(os.environ.get("GDW_AUTH_TOKEN")),
112
+ "persistence": "SQLITE_WAL",
113
+ "benchmark_claim": "UNMEASURED",
114
+ }
115
+
116
+ @app.get(prefix + "/bench/meta")
117
+ @app.get("/v1/gdw/bench/meta")
118
+ def gdw_bench_meta(
119
+ authorization: Optional[str] = Header(default=None, alias="Authorization"),
120
+ ):
121
+ _authorise(authorization)
122
+ return {
123
+ "service": "gdw-frontier",
124
+ "implementation_status": "REAL",
125
+ "benchmark_status": "UNMEASURED",
126
+ "recommended_burst": 10000,
127
+ "metrics_path": prefix + "/metrics",
128
+ "notes": [
129
+ "A 10k-request run is harness evidence, not a production guarantee.",
130
+ "Use p95, p99, error rate, receipt integrity, and SQLite integrity.",
131
+ ],
132
+ }
133
+
134
+ @app.get(prefix + "/metrics", response_class=PlainTextResponse)
135
+ @app.get("/v1/gdw/metrics", response_class=PlainTextResponse)
136
+ def gdw_metrics(
137
+ authorization: Optional[str] = Header(default=None, alias="Authorization"),
138
+ ):
139
+ _authorise(authorization)
140
+ return PlainTextResponse(
141
+ _TELEMETRY.render(),
142
+ media_type="text/plain; version=0.0.4; charset=utf-8",
143
+ )
144
+
145
+ @app.get(prefix + "/integrity")
146
+ @app.get("/v1/gdw/integrity")
147
+ def gdw_integrity(
148
+ authorization: Optional[str] = Header(default=None, alias="Authorization"),
149
+ ):
150
+ _authorise(authorization)
151
+ return GDWWorkspace().integrity()
152
+
153
+ @app.get(prefix + "/sessions/{session_id}")
154
+ @app.get("/v1/gdw/sessions/{session_id}")
155
+ def gdw_session(
156
+ session_id: str,
157
+ authorization: Optional[str] = Header(default=None, alias="Authorization"),
158
+ ):
159
+ _authorise(authorization)
160
+ if not _ID_PATTERN.fullmatch(session_id):
161
+ raise HTTPException(status_code=422, detail="invalid session_id")
162
+ state = GDWWorkspace().read_session(session_id)
163
+ if state is None:
164
+ raise HTTPException(status_code=404, detail="session not found")
165
+ return state
166
+
167
+ @app.post(prefix + "/step")
168
+ @app.post("/v1/gdw/step")
169
+ def gdw_step(
170
+ payload: GDWStepRequest,
171
+ authorization: Optional[str] = Header(default=None, alias="Authorization"),
172
+ x_request_id: Optional[str] = Header(default=None, alias="X-Request-Id"),
173
+ ):
174
+ started = time.perf_counter()
175
+ _authorise(authorization)
176
+ request_id = _validate_identifiers(payload, x_request_id)
177
+ payload_data = _dump_model(payload)
178
+ request_digest = _sha(payload_data)
179
+ workspace = GDWWorkspace()
180
+ selected_mode = "unresolved"
181
+ decision = "ERROR"
182
+ receipt_hash = ""
183
+
184
+ try:
185
+ with workspace.transaction() as connection:
186
+ cached = workspace.cached_request(connection, request_id)
187
+ if cached is not None:
188
+ cached_digest, cached_response = cached
189
+ if cached_digest != request_digest:
190
+ raise HTTPException(
191
+ status_code=409,
192
+ detail="X-Request-Id was already used with different content",
193
+ )
194
+ cached_response["replayed"] = True
195
+ selected_mode = cached_response["scheduler_mode"]
196
+ decision = cached_response["decision"]
197
+ receipt_hash = cached_response.get("receipt_hash") or ""
198
+ _TELEMETRY.observe(
199
+ (time.perf_counter() - started) * 1000.0,
200
+ decision,
201
+ selected_mode,
202
+ bool(receipt_hash),
203
+ )
204
+ return cached_response
205
+
206
+ previous = workspace.session_state(connection, payload.session_id)
207
+ if previous is None:
208
+ before_step = 0
209
+ before_hash = _sha(
210
+ {
211
+ "session_id": payload.session_id,
212
+ "step": 0,
213
+ "state": "GENESIS",
214
+ }
215
+ )
216
+ else:
217
+ before_step = previous["step"]
218
+ before_hash = previous["state_hash"]
219
+
220
+ features = AttentionFeatures(
221
+ novelty=payload.novelty
222
+ if payload.novelty is not None
223
+ else min(1.0, len(payload.request) / 1024.0),
224
+ disagreement=payload.disagreement
225
+ if payload.disagreement is not None
226
+ else min(1.0, max(0, len(set(payload.allowed_experts)) - 1) / 5.0),
227
+ risk=payload.risk_budget,
228
+ context_tokens=payload.context_tokens
229
+ or max(1, len(payload.request) // 4),
230
+ active_tool_count=payload.active_tool_count,
231
+ memory_pressure=payload.memory_pressure or 0.0,
232
+ )
233
+ routing = choose_attention_mode(features, payload.mode_hint)
234
+ selected_mode = routing["mode"]
235
+ decision = _decision(payload)
236
+ mutates = decision == "ACCEPT" and not payload.dry_run
237
+ step = before_step + 1 if mutates else before_step
238
+ proposal_id = hashlib.sha256(
239
+ (request_id + ":" + request_digest).encode("utf-8")
240
+ ).hexdigest()[:32]
241
+ timestamp = _now()
242
+
243
+ if mutates:
244
+ state = {
245
+ "session_id": payload.session_id,
246
+ "step": step,
247
+ "previous_state_hash": before_hash,
248
+ "request_digest": request_digest,
249
+ "scheduler_mode": selected_mode,
250
+ "allowed_experts": sorted(set(payload.allowed_experts)),
251
+ }
252
+ after_hash = _sha(state)
253
+ workspace.save_state(
254
+ connection,
255
+ payload.session_id,
256
+ step,
257
+ state,
258
+ after_hash,
259
+ timestamp,
260
+ )
261
+ receipt = append_receipt(
262
+ actor_id="gdw-frontier",
263
+ tool_name="gdw.step",
264
+ payload={
265
+ "proposal_id": proposal_id,
266
+ "request_id": request_id,
267
+ "session_id": payload.session_id,
268
+ "step": step,
269
+ "state_before_hash": before_hash,
270
+ "state_after_hash": after_hash,
271
+ "scheduler_mode": selected_mode,
272
+ },
273
+ )
274
+ receipt_hash = receipt.get("receipt_hash") or sha256_json(receipt)
275
+ else:
276
+ state = previous["state"] if previous else {"state": "GENESIS"}
277
+ after_hash = before_hash
278
+ receipt = None
279
+
280
+ proof_payload = build_proof_payload(
281
+ proposal_id=proposal_id,
282
+ request_id=request_id,
283
+ step=step,
284
+ before_hash=before_hash,
285
+ after_hash=after_hash,
286
+ decision=decision,
287
+ scheduler_mode=selected_mode,
288
+ receipt_hash=receipt_hash,
289
+ dry_run=payload.dry_run,
290
+ )
291
+ proof_mode = os.environ.get(
292
+ "GDW_PROOF_EXPORT_MODE", "sync"
293
+ ).strip().lower()
294
+ if proof_mode == "outbox":
295
+ workspace.save_proof_outbox(
296
+ connection,
297
+ proposal_id,
298
+ proof_payload,
299
+ proof_payload["payload_sha256"],
300
+ timestamp,
301
+ )
302
+ proof_artifact = {
303
+ "status": "OUTBOX_PERSISTED",
304
+ "payload_sha256": proof_payload["payload_sha256"],
305
+ "formal_status": "NOT_RUN",
306
+ }
307
+ elif proof_mode == "sync":
308
+ proof_artifact = export_proof_payload(proof_payload)
309
+ else:
310
+ raise ValueError(
311
+ "GDW_PROOF_EXPORT_MODE must be 'sync' or 'outbox'"
312
+ )
313
+ plan = build_plan(
314
+ tasks=("governance", "attention_route", "state_transition", "verify"),
315
+ meta={"proposal_id": proposal_id},
316
+ )
317
+ response = {
318
+ "service": "gdw-frontier",
319
+ "implementation_status": "REAL",
320
+ "benchmark_status": "UNMEASURED",
321
+ "proposal_id": proposal_id,
322
+ "request_id": request_id,
323
+ "session_id": payload.session_id,
324
+ "decision": decision,
325
+ "step": step,
326
+ "state_hash": after_hash,
327
+ "state_before_hash": before_hash,
328
+ "receipt_hash": receipt_hash or None,
329
+ "scheduler_mode": selected_mode,
330
+ "routing": routing,
331
+ "kernel_execution": "NOT_EXECUTED_BY_CONTROL_API",
332
+ "dry_run": payload.dry_run,
333
+ "replayed": False,
334
+ "audit": {
335
+ "governance": "DENY_BY_DEFAULT",
336
+ "allowed_experts": sorted(set(payload.allowed_experts)),
337
+ "plan_version": plan["plan_version"],
338
+ "receipt_substrate": "szl_receipt_substrate"
339
+ if receipt is not None
340
+ else None,
341
+ "proof_export_mode": proof_mode,
342
+ },
343
+ "proof": proof_artifact,
344
+ }
345
+ response_hash = _sha(response)
346
+ workspace.save_request(
347
+ connection,
348
+ request_id,
349
+ request_digest,
350
+ payload.session_id,
351
+ response,
352
+ response_hash,
353
+ timestamp,
354
+ )
355
+ if receipt is not None:
356
+ workspace.save_receipt(
357
+ connection,
358
+ receipt_hash,
359
+ request_id,
360
+ payload.session_id,
361
+ step,
362
+ receipt,
363
+ timestamp,
364
+ )
365
+
366
+ _TELEMETRY.observe(
367
+ (time.perf_counter() - started) * 1000.0,
368
+ decision,
369
+ selected_mode,
370
+ bool(receipt_hash),
371
+ )
372
+ return response
373
+ except HTTPException:
374
+ raise
375
+ except Exception as exc:
376
+ _TELEMETRY.observe(
377
+ (time.perf_counter() - started) * 1000.0,
378
+ "ERROR",
379
+ selected_mode,
380
+ False,
381
+ error=True,
382
+ )
383
+ raise HTTPException(
384
+ status_code=500,
385
+ detail=f"GDW transition failed closed: {type(exc).__name__}",
386
+ ) from exc
387
+
388
+ return {
389
+ "ok": True,
390
+ "state": "REAL",
391
+ "routes": [
392
+ prefix + "/healthz",
393
+ prefix + "/bench/meta",
394
+ prefix + "/metrics",
395
+ prefix + "/integrity",
396
+ prefix + "/sessions/{session_id}",
397
+ prefix + "/step",
398
+ ],
399
+ }
serve.py CHANGED
@@ -550,6 +550,24 @@ async def quantum_utility_receipt_replay(request: Request) -> JSONResponse:
550
  )
551
 
552
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
553
  # External numerical-engine frontier (wave 18). The module accepts only fixed
554
  # matrix solve, symmetric-eigenvalue, and reference-vector operations. GNU
555
  # Octave and MATLAB remain external installations; missing engine, offline
 
550
  )
551
 
552
 
553
+ # Governed Delta Workspace (wave 28): authenticated, deny-by-default state
554
+ # transitions over SQLite WAL, idempotency keys, the shared receipt substrate,
555
+ # structured theorem inputs, and honest benchmark metadata. Runtime route
556
+ # decisions are REAL; benchmark claims remain UNMEASURED until a captured run.
557
+ # Registered before both catch-alls.
558
+ try:
559
+ from routers import gdw_frontier as _gdw_frontier
560
+
561
+ _GDW_FRONTIER_STATUS = _gdw_frontier.register(app, ns="a11oy")
562
+ except Exception as _gdw_frontier_error: # pragma: no cover - fail one surface closed
563
+ _GDW_FRONTIER_STATUS = {
564
+ "ok": False,
565
+ "state": "UNAVAILABLE",
566
+ "reason": type(_gdw_frontier_error).__name__,
567
+ "routes": [],
568
+ }
569
+
570
+
571
  # External numerical-engine frontier (wave 18). The module accepts only fixed
572
  # matrix solve, symmetric-eigenvalue, and reference-vector operations. GNU
573
  # Octave and MATLAB remain external installations; missing engine, offline