Spaces:
Running
Running
chore(sync): mirror backend .py + Dockerfile to Space (hf-sync-backend)
Browse filesAutomated backend sync from szl-holdings/a11oy main via hf-sync-backend.
Updated (differed from the Space): a11oy_warhacker_obs.py, serve.py
Deleted (gone from the repo + Dockerfile COPY set): (none)
Keeps the Space-built backend (serve.py + the Dockerfile-COPY'd .py
modules) identical to GitHub main so the Space never rebuilds from a
stale backend, new endpoints don't 404 there, and orphaned modules
removed from the repo don't linger in the Space tree.
- a11oy_warhacker_obs.py +18 -9
- serve.py +174 -0
a11oy_warhacker_obs.py
CHANGED
|
@@ -59,17 +59,26 @@ SLSA_NOTE = "SLSA L1 honest build-provenance on the 5 organ images (cosign .att)
|
|
| 59 |
# roles and any *.hf.space probe URL redacted before they reach a JSONResponse.
|
| 60 |
# Single source of truth is the shared szl_codename_gate.MAP (mirrors the JS
|
| 61 |
# sanitizer). Code-internal keys are unchanged; only the served fields are.
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| 62 |
try: # shared module, present in every app image
|
| 63 |
from szl_codename_gate import MAP as _CODENAME_MAP, sanitize as _codename_sanitize
|
| 64 |
-
except Exception: # pragma: no cover —
|
| 65 |
-
|
| 66 |
-
|
| 67 |
-
|
| 68 |
-
|
| 69 |
-
|
| 70 |
-
|
| 71 |
-
|
| 72 |
-
|
|
|
|
|
|
|
| 73 |
|
| 74 |
|
| 75 |
def _public_organ(organ: str) -> str:
|
|
|
|
| 59 |
# roles and any *.hf.space probe URL redacted before they reach a JSONResponse.
|
| 60 |
# Single source of truth is the shared szl_codename_gate.MAP (mirrors the JS
|
| 61 |
# sanitizer). Code-internal keys are unchanged; only the served fields are.
|
| 62 |
+
# The banned codename->public-role map and the sanitizer live in ONE place only:
|
| 63 |
+
# szl_codename_gate (allowlisted enumeration-for-detection, byte-identical across
|
| 64 |
+
# apps, always shipped in the image). We import the map+sanitize from there and
|
| 65 |
+
# DO NOT re-declare the codename literals here, so this file never enumerates a
|
| 66 |
+
# banned token (Doctrine v7 §1 banned-token gate stays green) while still being
|
| 67 |
+
# fully sanitized. The import is robust: normal import first, then a path-based
|
| 68 |
+
# importlib load of the sibling module file if sys.path resolution ever fails.
|
| 69 |
try: # shared module, present in every app image
|
| 70 |
from szl_codename_gate import MAP as _CODENAME_MAP, sanitize as _codename_sanitize
|
| 71 |
+
except Exception: # pragma: no cover — resolve the sibling module by file path
|
| 72 |
+
import importlib.util as _ilu, os as _ilos
|
| 73 |
+
_gate_path = _ilos.path.join(_ilos.path.dirname(_ilos.path.abspath(__file__)),
|
| 74 |
+
"szl_codename_gate.py")
|
| 75 |
+
_spec = _ilu.spec_from_file_location("szl_codename_gate", _gate_path)
|
| 76 |
+
if _spec is None or _spec.loader is None: # truly unreachable in-image
|
| 77 |
+
raise RuntimeError("szl_codename_gate.py not found beside a11oy_warhacker_obs.py")
|
| 78 |
+
_gate = _ilu.module_from_spec(_spec)
|
| 79 |
+
_spec.loader.exec_module(_gate)
|
| 80 |
+
_CODENAME_MAP = _gate.MAP
|
| 81 |
+
_codename_sanitize = _gate.sanitize
|
| 82 |
|
| 83 |
|
| 84 |
def _public_organ(organ: str) -> str:
|
serve.py
CHANGED
|
@@ -5689,6 +5689,180 @@ async def a11oy_command_log_v2() -> JSONResponse:
|
|
| 5689 |
return JSONResponse(_a11oy_build_chain(24))
|
| 5690 |
|
| 5691 |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| 5692 |
@app.get("/api/a11oy/v1/ledger")
|
| 5693 |
async def a11oy_ledger_v2() -> JSONResponse:
|
| 5694 |
ch = _a11oy_build_chain(24)
|
|
|
|
| 5689 |
return JSONResponse(_a11oy_build_chain(24))
|
| 5690 |
|
| 5691 |
|
| 5692 |
+
# ===========================================================================
|
| 5693 |
+
# ADDITIVE (Research-3D live wiring, Forge 2026-06-14): four dedicated, HONEST
|
| 5694 |
+
# data endpoints, one per Research-3D console tab (ouro_spiral, abacus_manifold,
|
| 5695 |
+
# consensus_basin, gemstones_frontier). Each is a SUPERSET of what the tab
|
| 5696 |
+
# already consumed (so the frontend is a URL swap, not a rewrite) and carries a
|
| 5697 |
+
# server-attested `data_kind` provenance field:
|
| 5698 |
+
# live -> derived from a real in-process producer (live router catalog)
|
| 5699 |
+
# proxy -> a clearly-labelled structural heuristic over REAL receipts
|
| 5700 |
+
# sample -> derived, no live per-receipt telemetry in this image
|
| 5701 |
+
# NO fabricated data. Lambda = Conjecture 1; Khipu BFT = Conjecture 2; locked-
|
| 5702 |
+
# proven stays EXACTLY 8 {F1,F4,F7,F11,F12,F18,F19,F22}. The deterministic
|
| 5703 |
+
# in-image receipt chain carries no loop_depth / vote / round metadata, so the
|
| 5704 |
+
# loop-depth + consensus endpoints serve an HONEST proxy that AUTO-UPGRADES to
|
| 5705 |
+
# `live` the moment those fields are emitted. Registered BEFORE the SPA/proxy
|
| 5706 |
+
# catch-all (/{full_path:path}); stdlib-only; fail-safe.
|
| 5707 |
+
# ===========================================================================
|
| 5708 |
+
_R3D_LOCKED8 = "{F1,F4,F7,F11,F12,F18,F19,F22}"
|
| 5709 |
+
|
| 5710 |
+
def _r3d_chain(n: int = 50) -> dict:
|
| 5711 |
+
try:
|
| 5712 |
+
return _a11oy_build_chain(n)
|
| 5713 |
+
except Exception:
|
| 5714 |
+
return {"depth": 0, "chain_verified": False, "receipts": []}
|
| 5715 |
+
|
| 5716 |
+
def _r3d_loop_meta(r: dict):
|
| 5717 |
+
for k in ("loop_depth", "loop", "R", "ut_step"):
|
| 5718 |
+
v = r.get(k)
|
| 5719 |
+
if v is not None:
|
| 5720 |
+
return v
|
| 5721 |
+
return None
|
| 5722 |
+
|
| 5723 |
+
def _r3d_router_metrics_payload() -> dict:
|
| 5724 |
+
rs = _a11oy_router_stats_payload()
|
| 5725 |
+
routes = rs.get("routes", [])
|
| 5726 |
+
live = rs.get("source") == "szl_brain.TIERS"
|
| 5727 |
+
return {
|
| 5728 |
+
"data_kind": "live" if live else "sample",
|
| 5729 |
+
"mode": rs.get("mode", "live"),
|
| 5730 |
+
"routes": routes,
|
| 5731 |
+
"tiers": routes,
|
| 5732 |
+
"servedThisWindow": rs.get("servedThisWindow", 0),
|
| 5733 |
+
"width_depth_available": False,
|
| 5734 |
+
"source": rs.get("source", ""),
|
| 5735 |
+
"doctrine": "v11",
|
| 5736 |
+
"honesty": ("Per-tier throughput / model / license from the router catalog -- LIVE "
|
| 5737 |
+
"when the brain catalog (szl_brain.TIERS) is up, else honest_stub_catalog fallback "
|
| 5738 |
+
"with data_kind DOWNGRADED to sample. Model width/depth shape is NOT measured, so any "
|
| 5739 |
+
"width/depth scaling point stays a clearly-labelled SAMPLE. "
|
| 5740 |
+
"Lambda = Conjecture 1; locked-proven stays exactly 8 " + _R3D_LOCKED8 + "."),
|
| 5741 |
+
}
|
| 5742 |
+
|
| 5743 |
+
def _r3d_routing_graph_payload() -> dict:
|
| 5744 |
+
rs = _a11oy_router_stats_payload()
|
| 5745 |
+
routes = rs.get("routes", [])
|
| 5746 |
+
nodes = [{"id": r.get("tier", "T%d" % i), "organ": r.get("organ", ""),
|
| 5747 |
+
"model": r.get("model", ""), "throughput": r.get("throughput", 0),
|
| 5748 |
+
"license": r.get("license", "")} for i, r in enumerate(routes)]
|
| 5749 |
+
edges = [{"source": routes[i].get("tier"), "target": routes[i + 1].get("tier")}
|
| 5750 |
+
for i in range(len(routes) - 1)]
|
| 5751 |
+
ch = _r3d_chain(50)
|
| 5752 |
+
live = rs.get("source") == "szl_brain.TIERS"
|
| 5753 |
+
return {
|
| 5754 |
+
"data_kind": "live" if live else "sample",
|
| 5755 |
+
"mode": rs.get("mode", "live"),
|
| 5756 |
+
"nodes": nodes,
|
| 5757 |
+
"edges": edges,
|
| 5758 |
+
"routes": routes,
|
| 5759 |
+
"receipts": ch.get("receipts", []),
|
| 5760 |
+
"source": rs.get("source", ""),
|
| 5761 |
+
"surface": ("GraphRouter routing-envelope score s = lambda*e_hat - (1-lambda)*c_hat "
|
| 5762 |
+
"is a DERIVED heuristic, never a measured loss"),
|
| 5763 |
+
"doctrine": "v11",
|
| 5764 |
+
"honesty": ("Routing nodes/edges are the /router/stats per-tier catalog -- LIVE when the "
|
| 5765 |
+
"brain catalog (szl_brain.TIERS) is up, else honest_stub_catalog fallback with "
|
| 5766 |
+
"data_kind DOWNGRADED to sample (real "
|
| 5767 |
+
"organ -> tier -> model escalation path); receipts are the real in-image "
|
| 5768 |
+
"chain. The manifold surface is a derived heuristic, never a measured loss. "
|
| 5769 |
+
"Lambda = Conjecture 1; locked-proven stays exactly 8 " + _R3D_LOCKED8 + "."),
|
| 5770 |
+
}
|
| 5771 |
+
|
| 5772 |
+
def _r3d_loop_depth_payload() -> dict:
|
| 5773 |
+
ch = _r3d_chain(50)
|
| 5774 |
+
recs = ch.get("receipts", [])
|
| 5775 |
+
has_meta = any(_r3d_loop_meta(r) is not None for r in recs)
|
| 5776 |
+
agg = {}
|
| 5777 |
+
for r in recs:
|
| 5778 |
+
track = r.get("caller") or r.get("kind") or "agent"
|
| 5779 |
+
slot = agg.setdefault(track, {"count": 0, "meta": None})
|
| 5780 |
+
slot["count"] += 1
|
| 5781 |
+
mv = _r3d_loop_meta(r)
|
| 5782 |
+
if mv is not None:
|
| 5783 |
+
slot["meta"] = mv
|
| 5784 |
+
tracks = []
|
| 5785 |
+
for k in sorted(agg):
|
| 5786 |
+
slot = agg[k]
|
| 5787 |
+
live_track = has_meta and slot["meta"] is not None
|
| 5788 |
+
tracks.append({
|
| 5789 |
+
"agent": k,
|
| 5790 |
+
"depth": slot["meta"] if live_track else slot["count"],
|
| 5791 |
+
"source": "loop_depth metadata" if live_track else "receipt-density proxy",
|
| 5792 |
+
})
|
| 5793 |
+
return {
|
| 5794 |
+
"data_kind": "live" if has_meta else "proxy",
|
| 5795 |
+
"hasMeta": has_meta,
|
| 5796 |
+
"tracks": tracks,
|
| 5797 |
+
"receipts": recs,
|
| 5798 |
+
"depth": ch.get("depth", len(recs)),
|
| 5799 |
+
"chain_verified": ch.get("chain_verified", False),
|
| 5800 |
+
"doctrine": "v11",
|
| 5801 |
+
"honesty": ("Reasoning loop-depth R is read from receipt loop_depth metadata when "
|
| 5802 |
+
"present (live); receipts in this image carry none, so R is a clearly-"
|
| 5803 |
+
"labelled DEPTH PROXY from per-track receipt density -- a structural "
|
| 5804 |
+
"heuristic, never a measured latent-reasoning depth. Auto-upgrades to live "
|
| 5805 |
+
"when loop_depth is emitted. Lambda = Conjecture 1; locked-proven stays "
|
| 5806 |
+
"exactly 8 " + _R3D_LOCKED8 + "."),
|
| 5807 |
+
}
|
| 5808 |
+
|
| 5809 |
+
def _r3d_consensus_votes_payload() -> dict:
|
| 5810 |
+
ch = _r3d_chain(50)
|
| 5811 |
+
recs = ch.get("receipts", [])
|
| 5812 |
+
has_votes = any((r.get("votes") is not None or r.get("round") is not None) for r in recs)
|
| 5813 |
+
n = len(recs)
|
| 5814 |
+
out = []
|
| 5815 |
+
for idx, r in enumerate(recs):
|
| 5816 |
+
z = (idx + 1) / n if n else 0.0
|
| 5817 |
+
out.append({
|
| 5818 |
+
"seq": r.get("seq", idx),
|
| 5819 |
+
"kind": r.get("kind", ""),
|
| 5820 |
+
"hash": r.get("hash", ""),
|
| 5821 |
+
"prev_hash": r.get("prev_hash", ""),
|
| 5822 |
+
"converged": idx >= n - 1,
|
| 5823 |
+
"z": round(z, 4),
|
| 5824 |
+
"source": "vote/round metadata" if has_votes else "chain-depth proxy",
|
| 5825 |
+
})
|
| 5826 |
+
return {
|
| 5827 |
+
"data_kind": "live" if has_votes else "sample",
|
| 5828 |
+
"chain_verified": ch.get("chain_verified", False),
|
| 5829 |
+
"receipts": out,
|
| 5830 |
+
"quorum": {"n": 4, "f": 1, "rule": "3-of-4 (n >= 3f+1)",
|
| 5831 |
+
"status": "Conjecture 2 (Khipu BFT) -- structural heuristic, NOT a BFT proof"},
|
| 5832 |
+
"doctrine": "v11",
|
| 5833 |
+
"honesty": ("Receipts in this image carry no per-receipt vote/round metadata, so the "
|
| 5834 |
+
"convergence Z is a clearly-labelled chain-depth PROXY over the REAL "
|
| 5835 |
+
"prev_hash chain (F4 acyclicity, F22 layer order). Auto-upgrades to live "
|
| 5836 |
+
"vote/round when emitted. Khipu BFT = Conjecture 2; Lambda = Conjecture 1; "
|
| 5837 |
+
"locked-proven stays exactly 8 " + _R3D_LOCKED8 + "."),
|
| 5838 |
+
}
|
| 5839 |
+
|
| 5840 |
+
@app.get("/api/a11oy/v1/router/metrics")
|
| 5841 |
+
@app.get("/v1/router/metrics")
|
| 5842 |
+
async def _r3d_router_metrics() -> JSONResponse:
|
| 5843 |
+
return JSONResponse(_r3d_router_metrics_payload())
|
| 5844 |
+
|
| 5845 |
+
@app.get("/api/a11oy/v1/chaski/routing-graph")
|
| 5846 |
+
@app.get("/v1/chaski/routing-graph")
|
| 5847 |
+
@app.get("/api/chaski/routing-graph")
|
| 5848 |
+
async def _r3d_routing_graph() -> JSONResponse:
|
| 5849 |
+
return JSONResponse(_r3d_routing_graph_payload())
|
| 5850 |
+
|
| 5851 |
+
@app.get("/api/a11oy/v1/reason/loop-depth")
|
| 5852 |
+
@app.get("/v1/reason/loop-depth")
|
| 5853 |
+
async def _r3d_loop_depth() -> JSONResponse:
|
| 5854 |
+
return JSONResponse(_r3d_loop_depth_payload())
|
| 5855 |
+
|
| 5856 |
+
@app.get("/api/a11oy/v1/consensus/votes")
|
| 5857 |
+
@app.get("/v1/consensus/votes")
|
| 5858 |
+
async def _r3d_consensus_votes() -> JSONResponse:
|
| 5859 |
+
return JSONResponse(_r3d_consensus_votes_payload())
|
| 5860 |
+
|
| 5861 |
+
print("[a11oy] research-3d endpoints registered BEFORE proxy: /api/a11oy/v1/"
|
| 5862 |
+
"{router/metrics,chaski/routing-graph,reason/loop-depth,consensus/votes}",
|
| 5863 |
+
file=sys.stderr)
|
| 5864 |
+
|
| 5865 |
+
|
| 5866 |
@app.get("/api/a11oy/v1/ledger")
|
| 5867 |
async def a11oy_ledger_v2() -> JSONResponse:
|
| 5868 |
ch = _a11oy_build_chain(24)
|