betterwithage Claude Opus 4.7 commited on
Commit
b1a586b
·
verified ·
1 Parent(s): 5ca5f97

deploy(hf): sync szl-holdings/a11oy@908cc11509b51fc85f8f1ed8542c32c1e6e77e2e derived COPY set

Browse files

Reusable Dockerfile-COPY-derived deploy from szl-holdings/a11oy 908cc11509b51fc85f8f1ed8542c32c1e6e77e2e.
Files: 1156 Pruned: 0
Derived from Dockerfile COPY sources (NO hand-maintained allowlist).

Signed-off-by: SZL Holdings <noreply@szlholdings.ai>
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>

Files changed (1) hide show
  1. static/3d/surfaces/attestinfer.js +17 -15
static/3d/surfaces/attestinfer.js CHANGED
@@ -21,7 +21,7 @@
21
  //
22
  // HONESTY LABEL: MODELED (deterministic sha256/384 simulation of the attested path keyed on
23
  // (seed, model); NO real TEE, NO real GPU, NO NRAS/KDS network, NO real inference engine).
24
- // The DSSE envelope is REAL ECDSA-P256 in-Space and honestly UNSIGNED-LOCAL locally.
25
  // Label read VERBATIM from JSON; never upgraded. Λ = Conjecture 1 (advisory, gray, never green).
26
  // Nothing here is in the locked-8. Trust never 100% — the attestation is MODELED, not real trust.
27
  //
@@ -39,7 +39,7 @@
39
  // DOCTRINE v11: degrades gracefully (grey) on 404/error; honesty label still shown verbatim.
40
 
41
  const ID = "attestinfer";
42
- const TITLE = "Attested Inference · TEE quote → Λ-gate → signed receipt (live)";
43
 
44
  // Same-origin endpoint (this surface plugs into the a11oy registry, unlike Wave-A cc-attest
45
  // which lived on the isolated killinchu Space).
@@ -72,7 +72,7 @@ const S = {
72
  label: null, seed: null, stages: null,
73
  deviceId: null, chain: null, finalDigest: null, goldenMatch: null,
74
  quoteDigest: null,
75
- lamValue: null, lamFloor: null, lamPass: null,
76
  released: null, outputDigest: null,
77
  dsseSigned: null, dsseLabel: null,
78
  honestNote: null, state: "init",
@@ -200,13 +200,16 @@ function _onSnap(j) {
200
  S.lamFloor = typeof lam.floor === "number" ? lam.floor : null;
201
  S.lamPass = typeof lam.pass === "boolean" ? lam.pass : null;
202
 
 
 
 
203
  const inf = j.inference || {};
204
  S.released = typeof inf.released === "boolean" ? inf.released : null;
205
  S.outputDigest= typeof inf.output_digest === "string" ? inf.output_digest : null;
206
 
207
  const dsse = j.dsse || {};
208
  S.dsseSigned = typeof dsse.signed === "boolean" ? dsse.signed : null;
209
- S.dsseLabel = dsse.local_label || (dsse.signed ? "REAL-SIGNED" : "UNSIGNED-LOCAL");
210
 
211
  S.honestNote = typeof j.honest_note === "string" ? j.honest_note : null;
212
 
@@ -220,7 +223,7 @@ function _onSnap(j) {
220
  function _updateScene() {
221
  const live = S.state === "live";
222
  const bootOk = S.goldenMatch === true;
223
- const gatePass = S.lamPass === true;
224
  const released = S.released === true;
225
 
226
  // tower blocks
@@ -279,7 +282,7 @@ function _onFrame() {
279
  const t = performance.now();
280
  if (_group) _group.rotation.y = Math.sin(t * 0.00009) * 0.12;
281
  if (_identMarker) { _identMarker.rotation.y += 0.015; _identMarker.rotation.x += 0.008; }
282
- if (_lambdaRing && S.lamPass === true) { _lambdaRing.rotation.z += 0.01; const p = 1.0 + 0.06 * Math.sin(t * 0.003); _lambdaRing.scale.setScalar(p); }
283
  if (_inferNode && S.released === true) { _inferNode.rotation.y += 0.02; _inferNode.rotation.x += 0.012; }
284
  for (const b of _blocks) {
285
  if (b.ring.visible && S.goldenMatch === true) { const p = 1.0 + 0.12 * Math.sin(t * 0.0035); b.ring.scale.setScalar(p); }
@@ -310,9 +313,8 @@ function _buildOverlay() {
310
  "A deepening of Wave-A cc-attest into a full <b>attested-inference</b> flow: a device " +
311
  "<b>measured-boot chain</b> \u2192 an attestation <b>quote</b> that binds this inference " +
312
  "(SEV-SNP <b>REPORT_DATA</b> style) \u2192 a <b>\u039b-gate</b> \u2192 gated inference \u2192 a " +
313
- "signed <b>receipt</b> embedding the quote digest + \u039b axes + SLSA provenance. " +
314
- "Honesty <b>MODELED</b> \u2014 no real TEE/GPU/NRAS/network; DSSE is REAL ECDSA-P256 in-Space, " +
315
- "UNSIGNED-LOCAL locally. 0 runtime CDN.";
316
  _overlay.appendChild(sub);
317
 
318
  const brow = document.createElement("div");
@@ -349,7 +351,7 @@ function _buildOverlay() {
349
  grid.appendChild(kpiRow("ai-golden", "measured-boot golden_match \u2014 MODELED"));
350
  grid.appendChild(kpiRow("ai-quote", "attestation quote digest (trunc)"));
351
  grid.appendChild(kpiRow("ai-lambda", "\u039b value / floor \u2014 Conjecture 1"));
352
- grid.appendChild(kpiRow("ai-gate", "\u039b-gate"));
353
  grid.appendChild(kpiRow("ai-infer", "inference released"));
354
  grid.appendChild(kpiRow("ai-dsse", "DSSE receipt"));
355
  grid.appendChild(kpiRow("ai-label", "honesty label"));
@@ -397,8 +399,8 @@ function _applyPlain() {
397
  "run into the quote, then runs a <b>\u039b trust gate</b> that only releases a (fake) inference " +
398
  "when the attestation is good. Right now the measured boot <b>" + boot + "</b> and the " +
399
  "inference is <b>" + rel + "</b>. There is <b>no real GPU, no real key, and no network call</b> " +
400
- "\u2014 it shows how attested inference WORKS, not a working verifier. The receipt is signed for " +
401
- "real (ECDSA-P256) only inside the deployed Space; locally it is honestly UNSIGNED.";
402
  }
403
 
404
  function _tok(s) {
@@ -418,9 +420,9 @@ function _paintOverlay() {
418
  _set("ai-golden", t || (S.goldenMatch === true ? "MATCH" : (S.goldenMatch === false ? "MISMATCH" : "\u2014")));
419
  _set("ai-quote", t || _trunc(S.quoteDigest, 18));
420
  _set("ai-lambda", t || (S.lamValue != null ? (S.lamValue.toFixed(4) + " / " + (S.lamFloor != null ? S.lamFloor.toFixed(2) : "0.90")) : "\u2014"));
421
- _set("ai-gate", t || (S.lamPass === true ? "PASS (release)" : (S.lamPass === false ? "BLOCK (withhold)" : "\u2014")));
422
  _set("ai-infer", t || (S.released === true ? "RELEASED" : (S.released === false ? "WITHHELD" : "\u2014")));
423
- _set("ai-dsse", t || (S.dsseSigned == null ? "\u2014" : (S.dsseSigned ? "REAL-SIGNED (ECDSA-P256)" : "UNSIGNED-LOCAL")));
424
  _set("ai-label", t || (S.label || "MODELED"));
425
  if (_plain) _applyPlain();
426
  }
@@ -445,7 +447,7 @@ export function unmount() {
445
  _el = {}; _badge = null; _plain = false; _frameReg = false;
446
  _stage = _THREE = _ctx = null;
447
  S.label = S.seed = S.stages = S.deviceId = S.chain = S.finalDigest = S.goldenMatch = null;
448
- S.quoteDigest = S.lamValue = S.lamFloor = S.lamPass = null;
449
  S.released = S.outputDigest = S.dsseSigned = S.dsseLabel = S.honestNote = null;
450
  S.state = "init";
451
  }
 
21
  //
22
  // HONESTY LABEL: MODELED (deterministic sha256/384 simulation of the attested path keyed on
23
  // (seed, model); NO real TEE, NO real GPU, NO NRAS/KDS network, NO real inference engine).
24
+ // This GET returns a structurally complete but unsigned DSSE envelope on every runtime.
25
  // Label read VERBATIM from JSON; never upgraded. Λ = Conjecture 1 (advisory, gray, never green).
26
  // Nothing here is in the locked-8. Trust never 100% — the attestation is MODELED, not real trust.
27
  //
 
39
  // DOCTRINE v11: degrades gracefully (grey) on 404/error; honesty label still shown verbatim.
40
 
41
  const ID = "attestinfer";
42
+ const TITLE = "Attested Inference · modeled quote → Λ-gate → unsigned read receipt";
43
 
44
  // Same-origin endpoint (this surface plugs into the a11oy registry, unlike Wave-A cc-attest
45
  // which lived on the isolated killinchu Space).
 
72
  label: null, seed: null, stages: null,
73
  deviceId: null, chain: null, finalDigest: null, goldenMatch: null,
74
  quoteDigest: null,
75
+ lamValue: null, lamFloor: null, lamPass: null, gatePass: null,
76
  released: null, outputDigest: null,
77
  dsseSigned: null, dsseLabel: null,
78
  honestNote: null, state: "init",
 
200
  S.lamFloor = typeof lam.floor === "number" ? lam.floor : null;
201
  S.lamPass = typeof lam.pass === "boolean" ? lam.pass : null;
202
 
203
+ const releaseGate = j.release_gate || {};
204
+ S.gatePass = typeof releaseGate.pass === "boolean" ? releaseGate.pass : null;
205
+
206
  const inf = j.inference || {};
207
  S.released = typeof inf.released === "boolean" ? inf.released : null;
208
  S.outputDigest= typeof inf.output_digest === "string" ? inf.output_digest : null;
209
 
210
  const dsse = j.dsse || {};
211
  S.dsseSigned = typeof dsse.signed === "boolean" ? dsse.signed : null;
212
+ S.dsseLabel = dsse.local_label || (dsse.signed ? "SIGNED-WRITE" : "UNSIGNED-READ");
213
 
214
  S.honestNote = typeof j.honest_note === "string" ? j.honest_note : null;
215
 
 
223
  function _updateScene() {
224
  const live = S.state === "live";
225
  const bootOk = S.goldenMatch === true;
226
+ const gatePass = S.gatePass === true;
227
  const released = S.released === true;
228
 
229
  // tower blocks
 
282
  const t = performance.now();
283
  if (_group) _group.rotation.y = Math.sin(t * 0.00009) * 0.12;
284
  if (_identMarker) { _identMarker.rotation.y += 0.015; _identMarker.rotation.x += 0.008; }
285
+ if (_lambdaRing && S.gatePass === true) { _lambdaRing.rotation.z += 0.01; const p = 1.0 + 0.06 * Math.sin(t * 0.003); _lambdaRing.scale.setScalar(p); }
286
  if (_inferNode && S.released === true) { _inferNode.rotation.y += 0.02; _inferNode.rotation.x += 0.012; }
287
  for (const b of _blocks) {
288
  if (b.ring.visible && S.goldenMatch === true) { const p = 1.0 + 0.12 * Math.sin(t * 0.0035); b.ring.scale.setScalar(p); }
 
313
  "A deepening of Wave-A cc-attest into a full <b>attested-inference</b> flow: a device " +
314
  "<b>measured-boot chain</b> \u2192 an attestation <b>quote</b> that binds this inference " +
315
  "(SEV-SNP <b>REPORT_DATA</b> style) \u2192 a <b>\u039b-gate</b> \u2192 gated inference \u2192 a " +
316
+ "structurally complete, <b>unsigned read receipt</b> embedding the quote digest + \u039b axes + SLSA provenance. " +
317
+ "Honesty <b>MODELED</b> \u2014 no real TEE/GPU/NRAS/network; this GET never signs. 0 runtime CDN.";
 
318
  _overlay.appendChild(sub);
319
 
320
  const brow = document.createElement("div");
 
351
  grid.appendChild(kpiRow("ai-golden", "measured-boot golden_match \u2014 MODELED"));
352
  grid.appendChild(kpiRow("ai-quote", "attestation quote digest (trunc)"));
353
  grid.appendChild(kpiRow("ai-lambda", "\u039b value / floor \u2014 Conjecture 1"));
354
+ grid.appendChild(kpiRow("ai-gate", "effective release gate (\u039b + attestation)"));
355
  grid.appendChild(kpiRow("ai-infer", "inference released"));
356
  grid.appendChild(kpiRow("ai-dsse", "DSSE receipt"));
357
  grid.appendChild(kpiRow("ai-label", "honesty label"));
 
399
  "run into the quote, then runs a <b>\u039b trust gate</b> that only releases a (fake) inference " +
400
  "when the attestation is good. Right now the measured boot <b>" + boot + "</b> and the " +
401
  "inference is <b>" + rel + "</b>. There is <b>no real GPU, no real key, and no network call</b> " +
402
+ "\u2014 it shows how attested inference works, not a working verifier. The response carries a " +
403
+ "complete DSSE payload binding but remains <b>UNSIGNED-READ</b>; signing is reserved for an authorized write.";
404
  }
405
 
406
  function _tok(s) {
 
420
  _set("ai-golden", t || (S.goldenMatch === true ? "MATCH" : (S.goldenMatch === false ? "MISMATCH" : "\u2014")));
421
  _set("ai-quote", t || _trunc(S.quoteDigest, 18));
422
  _set("ai-lambda", t || (S.lamValue != null ? (S.lamValue.toFixed(4) + " / " + (S.lamFloor != null ? S.lamFloor.toFixed(2) : "0.90")) : "\u2014"));
423
+ _set("ai-gate", t || (S.gatePass === true ? "RELEASE" : (S.gatePass === false ? "BLOCK (withhold)" : "\u2014")));
424
  _set("ai-infer", t || (S.released === true ? "RELEASED" : (S.released === false ? "WITHHELD" : "\u2014")));
425
+ _set("ai-dsse", t || (S.dsseSigned == null ? "\u2014" : (S.dsseSigned ? "SIGNED-WRITE" : "UNSIGNED-READ")));
426
  _set("ai-label", t || (S.label || "MODELED"));
427
  if (_plain) _applyPlain();
428
  }
 
447
  _el = {}; _badge = null; _plain = false; _frameReg = false;
448
  _stage = _THREE = _ctx = null;
449
  S.label = S.seed = S.stages = S.deviceId = S.chain = S.finalDigest = S.goldenMatch = null;
450
+ S.quoteDigest = S.lamValue = S.lamFloor = S.lamPass = S.gatePass = null;
451
  S.released = S.outputDigest = S.dsseSigned = S.dsseLabel = S.honestNote = null;
452
  S.state = "init";
453
  }