betterwithage commited on
Commit
a9bfa38
·
verified ·
1 Parent(s): 6eeba65

chore(sync): mirror backend .py + Dockerfile to Space (hf-sync-backend)

Browse files

Automated backend sync from szl-holdings/a11oy main via hf-sync-backend.
Updated (differed from the Space): serve.py
Deleted (gone from the repo + Dockerfile COPY set): (none)

Keeps the Space-built backend (serve.py + the Dockerfile-COPY'd .py
modules) identical to GitHub main so the Space never rebuilds from a
stale backend, new endpoints don't 404 there, and orphaned modules
removed from the repo don't linger in the Space tree.

Files changed (1) hide show
  1. serve.py +25 -0
serve.py CHANGED
@@ -311,6 +311,23 @@ try:
311
  except Exception as _szl_kv_e: # pragma: no cover
312
  print(f"[a11oy] K-Verify NOT registered: {_szl_kv_e!r}; SPA + API unaffected", file=__import__("sys").stderr)
313
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
314
  # -- Energy LEDGER (signed, hash-chained JouleCharge receipts) -- REGRESSION RESTORE.
315
  # Route /api/a11oy/v1/energy/ledger (+ receipt/{idem}) is the read surface for the
316
  # metering ledger the /energy tab consumes. Its registration was dropped during a
@@ -1075,6 +1092,14 @@ try:
1075
  # page binds to live /code/healthz, /v1/energy/budget, /v1/qbio/coherence.
1076
  app.add_api_route("/energy", _ptg_serve("energy.html"), methods=["GET"], include_in_schema=False)
1077
  app.add_api_route("/a11oy/energy", _ptg_serve("energy.html"), methods=["GET"], include_in_schema=False)
 
 
 
 
 
 
 
 
1078
  # SZL-NEMO CORE tab (Lane I1, 2026-06-14): the sovereign governed agent model
1079
  # skeleton. Standalone sovereign page (0 runtime JS CDN; loads /static/shared
1080
  # label + receipt modules), binds to live /api/a11oy/v1/nemo/* — governed-MoE
 
311
  except Exception as _szl_kv_e: # pragma: no cover
312
  print(f"[a11oy] K-Verify NOT registered: {_szl_kv_e!r}; SPA + API unaffected", file=__import__("sys").stderr)
313
 
314
+ # -- Immune (Hukulla) — HONEST egress-gate surface -- doctrine v11 fix.
315
+ # The immune detector is REAL and LIVE, but historically the only HTTP routes for
316
+ # it were user-visible CODENAME namespaces (a doctrine v11 violation, and the
317
+ # reason /api/a11oy/v1/immune* returned 404). szl_immune exposes the CANONICAL,
318
+ # honest surface wired to the SAME real inspection logic (threat-signature scan +
319
+ # 1 MB size guard + Lambda-gate floor 0.5), fail-closed, signing a Khipu receipt
320
+ # (SZL.Immune.Verdict.v1) per verdict into the SHARED szl_khipu chain. Adds
321
+ # GET /api/a11oy/v1/immune/{healthz,status,gates,threats,feed,verify} and
322
+ # POST /api/a11oy/v1/immune/verdict (dual-registered under /v1/* too). NEVER emits
323
+ # a codename. Additive, try/except-guarded, registered BEFORE the SPA catch-all.
324
+ try:
325
+ import szl_immune as _szl_immune
326
+ _szl_immune.register(app, ns="a11oy")
327
+ print("[a11oy] Immune registered: /api/a11oy/v1/immune/{healthz,status,gates,threats,feed,verify,verdict}", file=__import__("sys").stderr)
328
+ except Exception as _szl_im_e: # pragma: no cover
329
+ print(f"[a11oy] Immune NOT registered: {_szl_im_e!r}; SPA + API unaffected", file=__import__("sys").stderr)
330
+
331
  # -- Energy LEDGER (signed, hash-chained JouleCharge receipts) -- REGRESSION RESTORE.
332
  # Route /api/a11oy/v1/energy/ledger (+ receipt/{idem}) is the read surface for the
333
  # metering ledger the /energy tab consumes. Its registration was dropped during a
 
1092
  # page binds to live /code/healthz, /v1/energy/budget, /v1/qbio/coherence.
1093
  app.add_api_route("/energy", _ptg_serve("energy.html"), methods=["GET"], include_in_schema=False)
1094
  app.add_api_route("/a11oy/energy", _ptg_serve("energy.html"), methods=["GET"], include_in_schema=False)
1095
+ # IMMUNE (Hukulla) tab (2026-06-15): the honest, user-visible egress-gate surface.
1096
+ # Standalone sovereign page (0 runtime CDN), binds to live /api/a11oy/v1/immune/*
1097
+ # (status/gates/feed) + a live "inspect an action" box that POSTs to
1098
+ # /api/a11oy/v1/immune/verdict and shows the REAL deny/allow + signals + signed
1099
+ # Khipu receipt digest. Title "Immune (Hukulla) — fail-closed egress gate". NEVER a
1100
+ # codename. Replaces the prior 200 SPA shell that read nothing real.
1101
+ app.add_api_route("/immune", _ptg_serve("immune.html"), methods=["GET"], include_in_schema=False)
1102
+ app.add_api_route("/a11oy/immune", _ptg_serve("immune.html"), methods=["GET"], include_in_schema=False)
1103
  # SZL-NEMO CORE tab (Lane I1, 2026-06-14): the sovereign governed agent model
1104
  # skeleton. Standalone sovereign page (0 runtime JS CDN; loads /static/shared
1105
  # label + receipt modules), binds to live /api/a11oy/v1/nemo/* — governed-MoE