betterwithage commited on
Commit
b6c8e60
·
verified ·
1 Parent(s): 641dec8

chore(sync): mirror backend .py + Dockerfile to Space (hf-sync-backend)

Browse files

Automated backend sync from szl-holdings/a11oy main via hf-sync-backend.
Updated (differed from the Space): Dockerfile, serve.py, szl3d_holographic.py, szl_frontier_zkinfer.py
Deleted (gone from the repo + Dockerfile COPY set): (none)

Keeps the Space-built backend (serve.py + the Dockerfile-COPY'd .py
modules) identical to GitHub main so the Space never rebuilds from a
stale backend, new endpoints don't 404 there, and orphaned modules
removed from the repo don't linger in the Space tree.

Files changed (4) hide show
  1. Dockerfile +1 -1
  2. serve.py +15 -0
  3. szl3d_holographic.py +1 -0
  4. szl_frontier_zkinfer.py +535 -0
Dockerfile CHANGED
@@ -649,7 +649,7 @@ COPY web/formulas.html web/v4_fleet_panel.html web/operator.html web/fleet-c2.ht
649
  # physical-bounds) and szl_governed_api.py (govern/infer energy reference). Per-file
650
  # COPY (this Dockerfile uses no `COPY . .`) or the guarded import falls back and the
651
  # endpoint 404s / the govern receipt cannot cite the MEASURED reference.
652
- COPY knowledge.json szl_parity_gaps.py compliance_crosswalk.py szl_compliance_mesh.py a11oy_warhacker_obs.py serve.py szl_governed_api.py szl_demo_tier1.py szl_assurance.py govern_showcase.html a11oy_wireA_metrics.py cathedral.html a11oy_operator_organ.py a11oy_hf_assets.py szl_b2_secdata.py gates_manifest.json a11oy_code_orchestrator.py a11oy_agent_loop.py a11oy_org_rag.py a11oy_mcp_client.py szl_rag.py a11oy_code_ide.html wayra_serve.py wayra_snapshot.json wayra_digests_7d.json szl_khipu_os_routes.py szl_spaces_proxy.py szl_spaces_surface.py szl_khipu_consensus.py szl_puriq_formulas.py ayni_os_serve.py szl_live_wires.py live_wires.html live_wires_3d.js szl_intoto.py szl_intoto_routes.py szl_scitt.py szl_dsse.py szl_provenance.py szl_be_hardening.py szl_unay.py szl_khipu_lmdb.py szl_khipu_replicate.py szl_unay_routes.py szl_warhacker_aliases.py a11oy_v4_hickok.py szl_khipu.py szl_formulas.py a11oy_v4_formulas.py szl_anatomy_3d.py szl_anatomy_routes.py _vendor_blobs.py szl_v4_fleet.py operator_shell_v4.py szl_bridge.py szl_bridge_schemas.py agent.html a11oy_bridge_cli.py szl_ken.py a11oy_formula_endpoints.py a11oy_formula_registry_guard.py a11oy_formulas_page.py a11oy_frontier_patch.py a11oy_v4_agent.py szl_brain.py szl_wire.py szl_hub.py szl_rosie_companion.py szl_receipt_substrate.py szl_alloy_embed_fabric.py szl_ayni_quorum.py szl_agentic_loop.py szl_ltc_dynamics.py szl_sgh_scheduler.py szl_formula_wiring.py szl_formula_surfaces.py a11oy_code_engine.py a11oy_code.py a11oy_seismic.py szl_warhacker_real.py szl_warhacker_demos.py NOTICE_warhacker_demos.txt szl_llm_registry.py szl_elite_console.py szl_alloy_models.py szl_scaling.py szl_allodial.py szl_entanglement.py szl_neuroplasticity.py szl_neuromorphic.py szl_chain_of_title.py szl_sovereign_compute.py a11oy_active_flux_router.py szl_energy_budget.py szl_energy_sovereign.py szl_energy_provenance.py szl_heart_blood.py szl_engine_status.py szl_backend_hardening.py revenue_endpoints.py a11oy_harvest_endpoints.py joule_billing.py szl_energy_ledger.py szl_energy_operator.py szl_energy_projection.py szl_cheapest_watt.py szl_energy_live.py szl_orbital_topology.py szl_orbital_projection.py a11oy_orbital_page.py a11oy_frontier_page.py szl_frontier_manifest.py a11oy_code_as_action.py a11oy_governed_kernel.py szl_lambda_tripwire.py szl_provenance_receipt.py szl_khipu_verify.py szl_attest_stack.py szl_demo_sign.py szl_sda.py szl_fabric_surface.py szl_nemo_agents.py szl_kverify.py szl_specdec.py szl_immune.py szl_quant_qbio_holo.py szl_materials.py szl_materials_predict.py a11oy_factory.py a11oy_constitution.py a11oy_nav_wireup.py szl_mbse_cosim.py szl_mbse_nav.py szl_mbse.py szl_factory.py szl_willay_gateway.py a11oy_willay_nav.py szl_waqay.py a11oy_waqay_nav.py szl_yupay.py a11oy_yupay_nav.py a11oy_uds_portability_nav.py szl_pinn_bounds.py physical_bounds_certificate.json agentic_decision_trail.json physical_bounds_certificate.dsse.json szl_pinn_inverse.py szl_governed_ipinn.py szl_calphad_inverse.py szl_pnt_mesh.py quantum_sensing_limits.py pnt_resilience.py nav_coasting.py fundamental_limits.py szl_counter_uas_proxy.py szl_gpu_quant.py szl_joules_truth.py revenue_model.py szl_prod_hardening.py szl_resilience.py szl_observability.py szl_corpus_publish.py szl_lake_store.py szl_lake_ingest.py szl_e8.py szl_trajectory_sign.py szl_nemotron_ingest.py szl_nemotron_corpus.py szl_nemo_verify.py a11oy_nemo_core.py szl_restraint.py szl_sapa.py szl_sapa_patch.py szl_restraint_energy.py a11oy_react_core.py szl_org_lambda.py a11oy_canonical_domain.py a11oy_formula_tiers.py szl_physical_bounds.py ./
653
 
654
  # DEV2 Build 1: TEE/TDX attestation hook (2026-06-30) — imported by serve.py (guarded);
655
  # MUST be per-file COPY'd or /api/a11oy/v1/tee/status + tee_attestation receipt field
 
649
  # physical-bounds) and szl_governed_api.py (govern/infer energy reference). Per-file
650
  # COPY (this Dockerfile uses no `COPY . .`) or the guarded import falls back and the
651
  # endpoint 404s / the govern receipt cannot cite the MEASURED reference.
652
+ COPY knowledge.json szl_parity_gaps.py compliance_crosswalk.py szl_compliance_mesh.py a11oy_warhacker_obs.py serve.py szl_governed_api.py szl_demo_tier1.py szl_assurance.py govern_showcase.html a11oy_wireA_metrics.py cathedral.html a11oy_operator_organ.py a11oy_hf_assets.py szl_b2_secdata.py gates_manifest.json a11oy_code_orchestrator.py a11oy_agent_loop.py a11oy_org_rag.py a11oy_mcp_client.py szl_rag.py a11oy_code_ide.html wayra_serve.py wayra_snapshot.json wayra_digests_7d.json szl_khipu_os_routes.py szl_spaces_proxy.py szl_spaces_surface.py szl_khipu_consensus.py szl_puriq_formulas.py ayni_os_serve.py szl_live_wires.py live_wires.html live_wires_3d.js szl_intoto.py szl_intoto_routes.py szl_scitt.py szl_dsse.py szl_provenance.py szl_be_hardening.py szl_unay.py szl_khipu_lmdb.py szl_khipu_replicate.py szl_unay_routes.py szl_warhacker_aliases.py a11oy_v4_hickok.py szl_khipu.py szl_formulas.py a11oy_v4_formulas.py szl_anatomy_3d.py szl_anatomy_routes.py _vendor_blobs.py szl_v4_fleet.py operator_shell_v4.py szl_bridge.py szl_bridge_schemas.py agent.html a11oy_bridge_cli.py szl_ken.py a11oy_formula_endpoints.py a11oy_formula_registry_guard.py a11oy_formulas_page.py a11oy_frontier_patch.py a11oy_v4_agent.py szl_brain.py szl_wire.py szl_hub.py szl_rosie_companion.py szl_receipt_substrate.py szl_alloy_embed_fabric.py szl_ayni_quorum.py szl_agentic_loop.py szl_ltc_dynamics.py szl_sgh_scheduler.py szl_formula_wiring.py szl_formula_surfaces.py a11oy_code_engine.py a11oy_code.py a11oy_seismic.py szl_warhacker_real.py szl_warhacker_demos.py NOTICE_warhacker_demos.txt szl_llm_registry.py szl_elite_console.py szl_alloy_models.py szl_scaling.py szl_allodial.py szl_entanglement.py szl_neuroplasticity.py szl_neuromorphic.py szl_chain_of_title.py szl_sovereign_compute.py a11oy_active_flux_router.py szl_energy_budget.py szl_energy_sovereign.py szl_energy_provenance.py szl_heart_blood.py szl_engine_status.py szl_backend_hardening.py revenue_endpoints.py a11oy_harvest_endpoints.py joule_billing.py szl_energy_ledger.py szl_energy_operator.py szl_energy_projection.py szl_cheapest_watt.py szl_energy_live.py szl_orbital_topology.py szl_orbital_projection.py a11oy_orbital_page.py a11oy_frontier_page.py szl_frontier_manifest.py szl_frontier_zkinfer.py a11oy_code_as_action.py a11oy_governed_kernel.py szl_lambda_tripwire.py szl_provenance_receipt.py szl_khipu_verify.py szl_attest_stack.py szl_demo_sign.py szl_sda.py szl_fabric_surface.py szl_nemo_agents.py szl_kverify.py szl_specdec.py szl_immune.py szl_quant_qbio_holo.py szl_materials.py szl_materials_predict.py a11oy_factory.py a11oy_constitution.py a11oy_nav_wireup.py szl_mbse_cosim.py szl_mbse_nav.py szl_mbse.py szl_factory.py szl_willay_gateway.py a11oy_willay_nav.py szl_waqay.py a11oy_waqay_nav.py szl_yupay.py a11oy_yupay_nav.py a11oy_uds_portability_nav.py szl_pinn_bounds.py physical_bounds_certificate.json agentic_decision_trail.json physical_bounds_certificate.dsse.json szl_pinn_inverse.py szl_governed_ipinn.py szl_calphad_inverse.py szl_pnt_mesh.py quantum_sensing_limits.py pnt_resilience.py nav_coasting.py fundamental_limits.py szl_counter_uas_proxy.py szl_gpu_quant.py szl_joules_truth.py revenue_model.py szl_prod_hardening.py szl_resilience.py szl_observability.py szl_corpus_publish.py szl_lake_store.py szl_lake_ingest.py szl_e8.py szl_trajectory_sign.py szl_nemotron_ingest.py szl_nemotron_corpus.py szl_nemo_verify.py a11oy_nemo_core.py szl_restraint.py szl_sapa.py szl_sapa_patch.py szl_restraint_energy.py a11oy_react_core.py szl_org_lambda.py a11oy_canonical_domain.py a11oy_formula_tiers.py szl_physical_bounds.py ./
653
 
654
  # DEV2 Build 1: TEE/TDX attestation hook (2026-06-30) — imported by serve.py (guarded);
655
  # MUST be per-file COPY'd or /api/a11oy/v1/tee/status + tee_attestation receipt field
serve.py CHANGED
@@ -625,6 +625,21 @@ try:
625
  except Exception as _szl_fm_e: # pragma: no cover
626
  print(f"[a11oy] Frontier manifest NOT registered: {_szl_fm_e!r}", file=__import__("sys").stderr)
627
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
628
  # Composite inference-provenance receipt (THE CAPSTONE) — POST /api/a11oy/v1/provenance/
629
  # receipt composes, by CALLING the already-live surfaces IN-PROCESS, ONE signed Khipu
630
  # envelope binding every guarantee for a single governed action: the REAL immune verdict
 
625
  except Exception as _szl_fm_e: # pragma: no cover
626
  print(f"[a11oy] Frontier manifest NOT registered: {_szl_fm_e!r}", file=__import__("sys").stderr)
627
 
628
+ # zkML Proof-of-Inference ("Cryptographic Receipts") — GET /api/a11oy/v1/frontier/zkinfer
629
+ # returns the CRYPTOGRAPHIC-PROOF trust branch of verifiable inference (counterpart to the
630
+ # TEE branch, ccattest): literature-parameterized zkML proof-cost models (prover time / proof
631
+ # size / verify time vs model size × seq length, every value citing its arXiv ID / DOI), a
632
+ # cryptographic-vs-TEE trust-model matrix, and ONE real commit→prove→verify micro-artifact
633
+ # computed in-process (MEASURED for that narrow claim only; HONEST-STUB on failure). Top label
634
+ # MODELED (explicitly NOT VERIFIED). Adds NOTHING to the locked-8; Λ stays Conjecture 1; trust
635
+ # ceiling 0.97, never 100%. Additive, try/except-guarded, same register() pattern.
636
+ try:
637
+ import szl_frontier_zkinfer as _szl_frontier_zkinfer
638
+ _szl_frontier_zkinfer.register(app, ns="a11oy")
639
+ print("[a11oy] Frontier zkinfer registered: /api/a11oy/v1/frontier/zkinfer (MODELED zkML proof-of-inference)", file=__import__("sys").stderr)
640
+ except Exception as _szl_zk_e: # pragma: no cover
641
+ print(f"[a11oy] Frontier zkinfer NOT registered: {_szl_zk_e!r}", file=__import__("sys").stderr)
642
+
643
  # Composite inference-provenance receipt (THE CAPSTONE) — POST /api/a11oy/v1/provenance/
644
  # receipt composes, by CALLING the already-live surfaces IN-PROCESS, ONE signed Khipu
645
  # envelope binding every guarantee for a single governed action: the REAL immune verdict
szl3d_holographic.py CHANGED
@@ -94,6 +94,7 @@ SURFACES: List[Dict[str, str]] = [
94
  {"id": "ctxready", "title": "Context-Ready Transformer", "owner": "Wave15"},
95
  {"id": "opera", "title": "OPERA Perplexity-Reward Alignment", "owner": "Wave15"},
96
  {"id": "brain", "title": "Formula-Graph Brain", "owner": "Wave15"},
 
97
  ]
98
 
99
  # Content-type by extension (the only extensions we serve from the 3d tree).
 
94
  {"id": "ctxready", "title": "Context-Ready Transformer", "owner": "Wave15"},
95
  {"id": "opera", "title": "OPERA Perplexity-Reward Alignment", "owner": "Wave15"},
96
  {"id": "brain", "title": "Formula-Graph Brain", "owner": "Wave15"},
97
+ {"id": "zkinfer", "title": "zkML Proof-of-Inference (Cryptographic Receipts)", "owner": "Wave18"},
98
  ]
99
 
100
  # Content-type by extension (the only extensions we serve from the 3d tree).
szl_frontier_zkinfer.py ADDED
@@ -0,0 +1,535 @@
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
1
+ #!/usr/bin/env python3
2
+ # SPDX-License-Identifier: Apache-2.0
3
+ # © 2026 Lutar, Stephen P. Jr. — SZL Holdings · ORCID 0009-0001-0110-4173
4
+ # Doctrine v11 LOCKED · Λ = Conjecture 1
5
+ # Sign-off: Stephen P. Lutar <stephenlutar2@gmail.com>
6
+ """szl_frontier_zkinfer.py — zkML Proof-of-Inference ("Cryptographic Receipts").
7
+
8
+ GET /api/a11oy/v1/frontier/zkinfer returns the cryptographic-proof trust branch of
9
+ verifiable inference — the counterpart to the estate's TEE/hardware branch
10
+ (`ccattest`). A prover (model host) emits a succinct zero-knowledge argument that a
11
+ COMMITTED model produced a specific output, checkable by anyone against only a public
12
+ weight commitment — no trusted hardware, no vendor in the trust base.
13
+
14
+ TOP-LEVEL HONESTY LABEL: MODELED (explicitly NOT VERIFIED). The estate is NOT running a
15
+ production zk-SNARK prover over a live LLM forward pass (that costs minutes + specialized
16
+ CUDA per the zkLLM result). The endpoint therefore returns:
17
+
18
+ 1. proof_cost_model (MODELED) — prover time / proof size / verify time as functions of
19
+ model size × sequence length × proof system, PARAMETERIZED from the five literature
20
+ sources below. EVERY numeric value carries its citing arXiv ID / DOI in-band.
21
+ 2. trust_model_matrix (STRUCTURAL) — cryptographic branch (standard hardness assumptions,
22
+ no trusted hardware) vs. the estate's TEE branch (`ccattest`). Definitional only.
23
+ 3. micro_artifact (MEASURED for its OWN narrow claim only) — a genuine Fiat–Shamir-style
24
+ commit → prove → verify roundtrip over a tiny toy linear circuit, computed IN-PROCESS
25
+ at request time (Merkle commitment over a small weight vector + a transcript hash the
26
+ client can independently recompute + a real verify check). MEASURED means "this
27
+ roundtrip really executed in-process now", NOT a hardware/joule measurement and NOT a
28
+ claim that it scales to an LLM. If the roundtrip cannot run honestly, it downgrades to
29
+ HONEST-STUB — never a fabricated passing proof.
30
+
31
+ PRIMARY SOURCES (all verified to resolve 2026-07-06):
32
+ * zkLLM: Zero Knowledge Proofs for Large Language Models — Sun, Li, Zhang (2024),
33
+ arXiv:2404.16109 (ACM CCS 2024). 13B-param full-inference proof < 15 min; proof < 200 kB;
34
+ hides parameters. Introduces tlookup + zkAttn.
35
+ * Scaling up Trustless DNN Inference with Zero-Knowledge Proofs — Kang, Hashimoto, Stoica,
36
+ Sun (2022), arXiv:2210.08674. First ImageNet-scale non-interactive ZK-SNARK proof of
37
+ valid inference (79% top-5); MLaaS verification protocols.
38
+ * ZKML: An Optimizing System for ML Inference in Zero-Knowledge Proofs — EuroSys 2024,
39
+ DOI 10.1145/3627703.3650088. TensorFlow→halo2 compiler; up to 5× larger provable models,
40
+ 5× faster verify, 22× smaller proofs vs prior work (EZKL / ddkang line).
41
+ * Verifiable evaluations of machine learning models using zkSNARKs — South, Camuto, Jain,
42
+ et al. (2024), arXiv:2402.02675. ZK inference proofs packaged as verifiable evaluation
43
+ attestations (a model with fixed private weights provably hits a stated benchmark).
44
+ * A Survey of Zero-Knowledge Proof Based Verifiable Machine Learning — Peng, Wang, Zhao,
45
+ et al. (2025), arXiv:2502.18535. Documents the three honest bottlenecks: limited circuit
46
+ expressiveness, high proving cost, deployment complexity.
47
+
48
+ DOCTRINE v11:
49
+ - Adds NOTHING to the locked-8 {F1,F4,F7,F11,F12,F18,F19,F22} @ kernel c7c0ba17; touches
50
+ no locked formula and no kernel.
51
+ - Λ stays Conjecture 1 (advisory); introduces no theorem, no green/1.0, no proof of Λ.
52
+ BFT remains Conjecture 2. Trust ceiling 0.97, never 100%.
53
+ - No label is ever upgraded. MODELED stays MODELED; the micro-artifact tile is MEASURED
54
+ ONLY for the narrow "roundtrip really ran" claim, or an honest HONEST-STUB otherwise.
55
+ - Additive route; canonical domain a-11-oy.com; 0 runtime CDN on the surface; no
56
+ user-visible codenames.
57
+ """
58
+ from __future__ import annotations
59
+
60
+ import datetime
61
+ import hashlib
62
+ from typing import Any
63
+
64
+ # Honesty-label vocabulary (doctrine v11) — tests grep these exact strings.
65
+ MODELED = "MODELED"
66
+ MEASURED = "MEASURED"
67
+ HONEST_STUB = "HONEST-STUB"
68
+ STRUCTURAL = "STRUCTURAL-ONLY"
69
+
70
+ # Trust ceiling — advisory, never 100% (doctrine v11).
71
+ TRUST_CEILING = 0.97
72
+
73
+ # Primary sources, keyed by the short id each numeric value cites in-band.
74
+ SOURCES: dict[str, dict[str, str]] = {
75
+ "2404.16109": {
76
+ "id": "arXiv:2404.16109",
77
+ "title": "zkLLM: Zero Knowledge Proofs for Large Language Models",
78
+ "venue": "ACM CCS 2024",
79
+ "url": "https://arxiv.org/abs/2404.16109",
80
+ },
81
+ "2210.08674": {
82
+ "id": "arXiv:2210.08674",
83
+ "title": "Scaling up Trustless DNN Inference with Zero-Knowledge Proofs",
84
+ "venue": "arXiv 2022 (DOI 10.48550/arXiv.2210.08674)",
85
+ "url": "https://arxiv.org/abs/2210.08674",
86
+ },
87
+ "10.1145/3627703.3650088": {
88
+ "id": "DOI 10.1145/3627703.3650088",
89
+ "title": "ZKML: An Optimizing System for ML Inference in Zero-Knowledge Proofs",
90
+ "venue": "EuroSys 2024",
91
+ "url": "https://dl.acm.org/doi/10.1145/3627703.3650088",
92
+ },
93
+ "2402.02675": {
94
+ "id": "arXiv:2402.02675",
95
+ "title": "Verifiable evaluations of machine learning models using zkSNARKs",
96
+ "venue": "arXiv 2024 (DOI 10.48550/arXiv.2402.02675)",
97
+ "url": "https://arxiv.org/abs/2402.02675",
98
+ },
99
+ "2502.18535": {
100
+ "id": "arXiv:2502.18535",
101
+ "title": "A Survey of Zero-Knowledge Proof Based Verifiable Machine Learning",
102
+ "venue": "arXiv 2025 (DOI 10.48550/arXiv.2502.18535)",
103
+ "url": "https://arxiv.org/abs/2502.18535",
104
+ },
105
+ }
106
+
107
+
108
+ def _now_iso() -> str:
109
+ return datetime.datetime.now(datetime.timezone.utc).isoformat()
110
+
111
+
112
+ def _sha256_hex(*parts: bytes) -> str:
113
+ h = hashlib.sha256()
114
+ for p in parts:
115
+ h.update(p)
116
+ return h.hexdigest()
117
+
118
+
119
+ # ---------------------------------------------------------------------------
120
+ # 1. Proof-cost model (MODELED) — literature anchor points + a MODELED scaling grid.
121
+ # Every numeric value carries the citing source id.
122
+ # ---------------------------------------------------------------------------
123
+
124
+ def _anchor_points() -> list[dict[str, Any]]:
125
+ """Literature HEADLINE figures only — no field is invented. Where a paper does not
126
+ headline a number we leave it null rather than fabricate one."""
127
+ return [
128
+ {
129
+ "system": "zkLLM",
130
+ "model": "LLaMa-2 13B (full inference)",
131
+ "params": 13_000_000_000,
132
+ "prover_time_s": {"value": 900, "relation": "<", "note": "under 15 minutes",
133
+ "source": "2404.16109"},
134
+ "proof_size_kb": {"value": 200, "relation": "<", "note": "succinct proof",
135
+ "source": "2404.16109"},
136
+ "verify_time_s": {"value": None, "note": "not headlined as a single figure by the paper",
137
+ "source": "2404.16109"},
138
+ "hides_parameters": True,
139
+ "label": MODELED,
140
+ },
141
+ {
142
+ "system": "Kang et al. (halo2 zk-SNARK)",
143
+ "model": "ImageNet-scale DNN (MobileNet-class)",
144
+ "params": None,
145
+ "prover_time_s": {"value": None, "note": "reported minutes-scale; no single headline value used",
146
+ "source": "2210.08674"},
147
+ "proof_size_kb": {"value": None, "note": "tens-of-kB order; exact value not reproduced here",
148
+ "source": "2210.08674"},
149
+ "verify_time_s": {"value": None, "note": "sub-second order; exact value not reproduced here",
150
+ "source": "2210.08674"},
151
+ "accuracy_top5": {"value": 0.79,
152
+ "note": "first ImageNet-scale non-interactive ZK-SNARK proof of valid inference",
153
+ "source": "2210.08674"},
154
+ "label": MODELED,
155
+ },
156
+ {
157
+ "system": "ZKML / EZKL (TensorFlow→halo2)",
158
+ "model": "relative to prior zkML toolchains",
159
+ "params": None,
160
+ "provable_model_size_gain_x": {"value": 5, "relation": "up to",
161
+ "source": "10.1145/3627703.3650088"},
162
+ "verify_speedup_x": {"value": 5, "source": "10.1145/3627703.3650088"},
163
+ "proof_size_reduction_x": {"value": 22, "source": "10.1145/3627703.3650088"},
164
+ "label": MODELED,
165
+ },
166
+ ]
167
+
168
+
169
+ def _cost_grid() -> dict[str, Any]:
170
+ """A MODELED prover-time surface over (model size × sequence length), anchored to the
171
+ zkLLM headline point (13B params → ~900 s). This is an EXTRAPOLATION, not a measurement:
172
+ prover_time_s ≈ k · (params/1e9)^a · (seq_len/1024)^b, with k fixed so the anchor
173
+ reproduces. Labeled MODELED; the anchor's source is cited. NOT VERIFIED."""
174
+ # Anchor: 13e9 params, 1024-token seq -> 900 s (zkLLM headline "< 15 min").
175
+ a, b = 1.0, 0.5 # near-linear in params, sublinear in seq (MODELED assumption).
176
+ anchor_params_b = 13.0
177
+ anchor_seq = 1024.0
178
+ anchor_time = 900.0
179
+ k = anchor_time / ((anchor_params_b ** a) * ((anchor_seq / 1024.0) ** b))
180
+
181
+ params_axis_b = [0.13, 0.5, 1.3, 7.0, 13.0, 70.0] # billions of params
182
+ seq_axis = [512, 1024, 2048, 4096, 8192] # tokens
183
+
184
+ def prover_time(params_b: float, seq: int) -> float:
185
+ return round(k * (params_b ** a) * ((seq / 1024.0) ** b), 2)
186
+
187
+ # Proof size stays roughly succinct/near-constant (zkLLM: < 200 kB; NANOZK-style
188
+ # layerwise proofs are near constant-size). MODELED: hold at the zkLLM ceiling.
189
+ proof_size_kb = 200.0
190
+
191
+ rows = []
192
+ for pb in params_axis_b:
193
+ rows.append({
194
+ "params_b": pb,
195
+ "prover_time_s": [prover_time(pb, s) for s in seq_axis],
196
+ })
197
+
198
+ return {
199
+ "label": MODELED,
200
+ "not_verified": True,
201
+ "formula": "prover_time_s = k · (params_b)^a · (seq_len/1024)^b",
202
+ "coefficients": {"k": round(k, 4), "a": a, "b": b},
203
+ "anchor": {"params_b": anchor_params_b, "seq_len": int(anchor_seq),
204
+ "prover_time_s": anchor_time, "source": "2404.16109",
205
+ "note": "zkLLM headline: 13B full inference proved in under 15 minutes"},
206
+ "axes": {"params_b": params_axis_b, "seq_len": seq_axis},
207
+ "prover_time_grid_s": rows,
208
+ "proof_size_kb_modeled": {"value": proof_size_kb, "source": "2404.16109",
209
+ "note": "held near the zkLLM succinct-proof ceiling; "
210
+ "layerwise systems target near-constant size"},
211
+ "honest_note": ("EXTRAPOLATED from a single literature anchor — a design surface, not "
212
+ "a benchmark. Real prover cost is proof-system, hardware and circuit "
213
+ "dependent; treat every off-anchor cell as MODELED, never MEASURED."),
214
+ }
215
+
216
+
217
+ # ---------------------------------------------------------------------------
218
+ # 2. Trust-model matrix (STRUCTURAL) — cryptographic branch vs. the TEE branch.
219
+ # ---------------------------------------------------------------------------
220
+
221
+ def _trust_matrix() -> dict[str, Any]:
222
+ return {
223
+ "label": STRUCTURAL,
224
+ "note": ("definitional contrast only — no measurement. This surface is the "
225
+ "cryptographic branch; `ccattest` is the estate's TEE/hardware branch."),
226
+ "axes": [
227
+ "trust_base", "trusted_hardware_in_TCB", "vendor_in_trust_base",
228
+ "verifier_re_runs_model", "hides_model_parameters", "assumption",
229
+ ],
230
+ "branches": {
231
+ "cryptographic_zkml (this surface)": {
232
+ "trust_base": "standard cryptographic hardness assumptions only",
233
+ "trusted_hardware_in_TCB": False,
234
+ "vendor_in_trust_base": False,
235
+ "verifier_re_runs_model": False,
236
+ "hides_model_parameters": True,
237
+ "assumption": "soundness of the ZK argument (e.g. discrete-log / lattice / hash)",
238
+ "source": "2404.16109",
239
+ },
240
+ "tee_attestation (ccattest)": {
241
+ "trust_base": "hardware root of trust (SGX / SEV-SNP / H100 CC quote)",
242
+ "trusted_hardware_in_TCB": True,
243
+ "vendor_in_trust_base": True,
244
+ "verifier_re_runs_model": False,
245
+ "hides_model_parameters": True,
246
+ "assumption": "enclave + silicon vendor attestation service are honest/uncompromised",
247
+ "source": None,
248
+ "cross_surface": "/api/a11oy/v1/frontier/manifest (ccattest tile)",
249
+ },
250
+ },
251
+ "bottlenecks_honest": {
252
+ "source": "2502.18535",
253
+ "items": [
254
+ "limited circuit expressiveness (non-arithmetic ops need lookup arguments)",
255
+ "high proving cost (minutes + specialized compute at LLM scale)",
256
+ "deployment complexity (toolchain, circuit compilation, key management)",
257
+ ],
258
+ },
259
+ "receipt_thesis": {
260
+ "source": "2402.02675",
261
+ "note": ("zk inference proofs package into verifiable evaluation attestations — a "
262
+ "model with fixed private weights provably achieves a stated benchmark; "
263
+ "the cryptographic counterpart to the estate's receipt/attestation thesis."),
264
+ },
265
+ }
266
+
267
+
268
+ # ---------------------------------------------------------------------------
269
+ # 3. Real, honest micro-artifact — commit → prove → verify roundtrip IN-PROCESS.
270
+ # MEASURED ONLY for the narrow "this roundtrip really ran now" claim.
271
+ # ---------------------------------------------------------------------------
272
+
273
+ def _merkle_root(leaves: list[bytes]) -> tuple[str, list[str]]:
274
+ """Compute a plain SHA-256 Merkle root over `leaves` (duplicate-last padding). Returns
275
+ (root_hex, level0_leaf_hashes_hex). Real, deterministic, client-recomputable."""
276
+ level = [hashlib.sha256(b"leaf:" + lf).digest() for lf in leaves]
277
+ leaf_hex = [d.hex() for d in level]
278
+ if not level:
279
+ return hashlib.sha256(b"empty").hexdigest(), []
280
+ while len(level) > 1:
281
+ if len(level) % 2 == 1:
282
+ level.append(level[-1]) # duplicate-last padding
283
+ level = [hashlib.sha256(b"node:" + level[i] + level[i + 1]).digest()
284
+ for i in range(0, len(level), 2)]
285
+ return level[0].hex(), leaf_hex
286
+
287
+
288
+ def _micro_artifact() -> dict[str, Any]:
289
+ """A genuine Fiat–Shamir-style commit-and-check over a tiny toy linear circuit y = w·x.
290
+
291
+ The whole roundtrip runs at request time; every value is client-recomputable:
292
+ commit : Merkle root over the committed weight vector w
293
+ challenge : r = SHA256(root || x) (Fiat–Shamir, non-interactive)
294
+ output : y = Σ w_i · x_i (the toy "inference")
295
+ transcript : SHA256(root || x || y || r)
296
+ verify : recompute root from w, recompute r, recompute y, recompute transcript, compare
297
+
298
+ HONESTY: this proves the commit→prove→verify PLUMBING is real; it is NOT a zk-SNARK,
299
+ reveals w (no zero-knowledge here), and does NOT scale to an LLM. Labeled MEASURED ONLY
300
+ for the narrow claim "this roundtrip executed in-process now"; on any failure it is
301
+ reported HONEST-STUB, never a fabricated pass."""
302
+ try:
303
+ # Tiny committed "weight vector" and public input (toy circuit).
304
+ w = [3, 1, 4, 1, 5, 9, 2, 6]
305
+ x = [1, 0, 1, 1, 0, 1, 0, 1]
306
+
307
+ w_leaves = [str(v).encode() for v in w]
308
+ root, leaf_hashes = _merkle_root(w_leaves)
309
+
310
+ x_bytes = (",".join(str(v) for v in x)).encode()
311
+ challenge = _sha256_hex(bytes.fromhex(root), x_bytes)
312
+
313
+ y = sum(wi * xi for wi, xi in zip(w, x)) # the toy inference output
314
+ transcript = _sha256_hex(bytes.fromhex(root), x_bytes, str(y).encode(),
315
+ bytes.fromhex(challenge))
316
+
317
+ # Independent verify: recompute EVERYTHING from the committed inputs.
318
+ root2, _ = _merkle_root(w_leaves)
319
+ challenge2 = _sha256_hex(bytes.fromhex(root2), x_bytes)
320
+ y2 = sum(wi * xi for wi, xi in zip(w, x))
321
+ transcript2 = _sha256_hex(bytes.fromhex(root2), x_bytes, str(y2).encode(),
322
+ bytes.fromhex(challenge2))
323
+ verify_ok = (root2 == root and challenge2 == challenge
324
+ and y2 == y and transcript2 == transcript)
325
+
326
+ if not verify_ok: # pragma: no cover — deterministic; would indicate a real fault
327
+ return {
328
+ "label": HONEST_STUB,
329
+ "verify_ok": False,
330
+ "note": ("commit-verify roundtrip did NOT reconcile in-process; reported "
331
+ "honestly as HONEST-STUB, not faked."),
332
+ }
333
+
334
+ return {
335
+ "label": MEASURED,
336
+ "measured_claim": ("ONLY that this commit→prove→verify roundtrip executed "
337
+ "in-process at request time and reconciled; NOT a joule/hardware "
338
+ "measurement, NOT zero-knowledge (w is revealed), NOT LLM-scale."),
339
+ "scheme": "SHA-256 Merkle commitment + Fiat–Shamir transcript over a toy linear circuit",
340
+ "commit": {"weight_vector": w, "merkle_root": root, "leaf_hashes": leaf_hashes},
341
+ "public_input": x,
342
+ "challenge_fiat_shamir": challenge,
343
+ "output_y": y,
344
+ "transcript_hash": transcript,
345
+ "verify_ok": True,
346
+ "client_recompute": {
347
+ "root": "SHA256('node:'||L||R) over SHA256('leaf:'||str(w_i)), duplicate-last pad",
348
+ "challenge": "SHA256(root_bytes || b'x0,x1,...')",
349
+ "output": "y = sum(w_i * x_i)",
350
+ "transcript": "SHA256(root_bytes || x_bytes || str(y) || challenge_bytes)",
351
+ },
352
+ "honest_note": ("real plumbing, deliberately tiny. Scaling this to a hiding, "
353
+ "succinct LLM proof is exactly the MODELED cost above and the "
354
+ "three bottlenecks in arXiv:2502.18535."),
355
+ }
356
+ except Exception as exc: # noqa: BLE001 — degrade honestly, never fabricate a pass
357
+ return {
358
+ "label": HONEST_STUB,
359
+ "verify_ok": False,
360
+ "note": f"micro-artifact could not run honestly in-process: {exc}",
361
+ }
362
+
363
+
364
+ # ---------------------------------------------------------------------------
365
+ # Payload assembly
366
+ # ---------------------------------------------------------------------------
367
+
368
+ def build_payload() -> dict[str, Any]:
369
+ """Compose the zkinfer surface payload. Pure read; mints/ signs nothing (receipts
370
+ belong on writes, never on GETs)."""
371
+ micro = _micro_artifact()
372
+ return {
373
+ "ok": True,
374
+ "endpoint": "frontier/zkinfer",
375
+ "service": "a11oy.frontier.zkinfer",
376
+ "title": "zkML Proof-of-Inference (Cryptographic Receipts)",
377
+ # TOP-LEVEL honesty banner — VERBATIM, explicitly NOT VERIFIED.
378
+ "label": MODELED,
379
+ "claim": MODELED,
380
+ "not_verified": True,
381
+ "no_trusted_hardware_in_TCB": True,
382
+ "what": ("the cryptographic-proof trust branch of verifiable inference: a succinct "
383
+ "zero-knowledge argument that a COMMITTED model produced a specific output, "
384
+ "checkable against only a public weight commitment — no trusted hardware, no "
385
+ "vendor in the trust base. Orthogonal to the estate's TEE branch (ccattest)."),
386
+ "doctrine": {
387
+ "label_top": MODELED,
388
+ "not_verified": True,
389
+ "locked_proven": 8,
390
+ "locked_set": ["F1", "F4", "F7", "F11", "F12", "F18", "F19", "F22"],
391
+ "kernel_commit": "c7c0ba17",
392
+ "adds_to_locked_8": 0,
393
+ "lambda": "Conjecture 1",
394
+ "khipu_bft": "Conjecture 2",
395
+ "trust_ceiling": TRUST_CEILING,
396
+ "trust_100_percent": False,
397
+ "runtime_cdn": 0,
398
+ "note": ("additive MODELED surface; touches no locked formula and no kernel; "
399
+ "introduces no theorem, no green/1.0, no proof of Λ."),
400
+ },
401
+ "proof_cost_model": {
402
+ "label": MODELED,
403
+ "not_verified": True,
404
+ "anchor_points": _anchor_points(),
405
+ "cost_frontier": _cost_grid(),
406
+ },
407
+ "trust_model_matrix": _trust_matrix(),
408
+ "micro_artifact": micro,
409
+ "sources": SOURCES,
410
+ "labels_legend": {
411
+ MODELED: "design/parametric quantity derived from the literature — NOT verified",
412
+ MEASURED: "the micro-artifact roundtrip really executed in-process now (narrow claim only)",
413
+ HONEST_STUB: "an honest placeholder — the roundtrip could not run; never a faked pass",
414
+ STRUCTURAL: "definitional/structural contrast only — no measurement",
415
+ },
416
+ "timestamp_utc": _now_iso(),
417
+ }
418
+
419
+
420
+ def handle() -> dict[str, Any]:
421
+ """GET /frontier/zkinfer handler used by FastAPI and __main__."""
422
+ try:
423
+ return build_payload()
424
+ except Exception as exc: # never 500: honest degraded response
425
+ return {
426
+ "ok": False,
427
+ "endpoint": "frontier/zkinfer",
428
+ "label": MODELED,
429
+ "error": str(exc),
430
+ "doctrine": "v11: surface unavailable; no fabricated proof/cost emitted.",
431
+ "timestamp_utc": _now_iso(),
432
+ }
433
+
434
+
435
+ # ---------------------------------------------------------------------------
436
+ # FastAPI router registration — mirrors szl_frontier_manifest.register() exactly.
437
+ # ---------------------------------------------------------------------------
438
+
439
+ def register(app, ns: str = "a11oy") -> str:
440
+ """Mount the zkinfer surface endpoint on the FastAPI ``app``. Returns a status string."""
441
+ from fastapi.responses import JSONResponse
442
+
443
+ base = f"/api/{ns}/v1/frontier"
444
+
445
+ @app.get(f"{base}/zkinfer")
446
+ async def _frontier_zkinfer():
447
+ """zkML proof-of-inference cost model + trust matrix + a real commit-verify micro-artifact."""
448
+ return JSONResponse(handle())
449
+
450
+ return "frontier-zkinfer-wired:1"
451
+
452
+
453
+ # ---------------------------------------------------------------------------
454
+ # Self-test — honest labels, no upgrade, real roundtrip, sources cited.
455
+ # ---------------------------------------------------------------------------
456
+
457
+ if __name__ == "__main__":
458
+ import json as _json
459
+ import sys as _sys
460
+
461
+ print("=" * 72)
462
+ print("szl_frontier_zkinfer — self-test (MODELED surface, honest labels)")
463
+ print("=" * 72)
464
+
465
+ p = build_payload()
466
+ blob = _json.dumps(p)
467
+
468
+ # 1) top-level MODELED, explicitly NOT VERIFIED, no trusted hardware in TCB.
469
+ assert p["ok"] is True
470
+ assert p["label"] == MODELED and p["claim"] == MODELED
471
+ assert p["not_verified"] is True
472
+ assert p["no_trusted_hardware_in_TCB"] is True
473
+ assert "VERIFIED" not in {p["label"], p["claim"]}
474
+ print("[1] top-level MODELED / not_verified / no trusted hardware OK")
475
+
476
+ # 2) doctrine: locked-8 exact, adds nothing, Λ Conjecture 1, trust ceiling 0.97 not 100%.
477
+ d = p["doctrine"]
478
+ assert d["locked_proven"] == 8
479
+ assert d["locked_set"] == ["F1", "F4", "F7", "F11", "F12", "F18", "F19", "F22"]
480
+ assert d["adds_to_locked_8"] == 0
481
+ assert d["lambda"] == "Conjecture 1" and d["khipu_bft"] == "Conjecture 2"
482
+ assert d["trust_ceiling"] == 0.97 and d["trust_100_percent"] is False
483
+ assert d["runtime_cdn"] == 0
484
+ print("[2] doctrine: locked-8 exact, +0, Λ=Conjecture 1, trust 0.97 (not 100%) OK")
485
+
486
+ # 3) every numeric cost value carries a citing source.
487
+ def _walk_sources(node):
488
+ found = []
489
+ if isinstance(node, dict):
490
+ if "source" in node and node["source"] is not None:
491
+ found.append(node["source"])
492
+ for v in node.values():
493
+ found += _walk_sources(v)
494
+ elif isinstance(node, list):
495
+ for v in node:
496
+ found += _walk_sources(v)
497
+ return found
498
+
499
+ cited = set(_walk_sources(p["proof_cost_model"]))
500
+ assert cited, "no source citations found in proof_cost_model"
501
+ assert cited <= set(SOURCES), f"cost model cites an unknown source: {cited - set(SOURCES)}"
502
+ # all five primary sources present in the payload.
503
+ for sid in ("2404.16109", "2210.08674", "10.1145/3627703.3650088",
504
+ "2402.02675", "2502.18535"):
505
+ assert sid in blob, f"missing primary source {sid}"
506
+ print(f"[3] cost values cite sources {sorted(cited)}; all 5 primary sources present OK")
507
+
508
+ # 4) the real micro-artifact roundtrip ran + reconciled (MEASURED narrow claim) and is
509
+ # independently recomputable; verify_ok is COMPUTED, never asserted true blindly.
510
+ m = p["micro_artifact"]
511
+ assert m["label"] in (MEASURED, HONEST_STUB)
512
+ if m["label"] == MEASURED:
513
+ assert m["verify_ok"] is True
514
+ # recompute the whole roundtrip independently here to prove it is honest.
515
+ w = m["commit"]["weight_vector"]
516
+ x = m["public_input"]
517
+ root2, _ = _merkle_root([str(v).encode() for v in w])
518
+ assert root2 == m["commit"]["merkle_root"], "Merkle root not client-recomputable"
519
+ xb = (",".join(str(v) for v in x)).encode()
520
+ ch2 = _sha256_hex(bytes.fromhex(root2), xb)
521
+ assert ch2 == m["challenge_fiat_shamir"], "Fiat–Shamir challenge not recomputable"
522
+ assert sum(wi * xi for wi, xi in zip(w, x)) == m["output_y"], "output y not recomputable"
523
+ print(f"[4] micro-artifact label={m['label']}, verify_ok={m.get('verify_ok')}, "
524
+ "independently recomputed OK")
525
+
526
+ # 5) no green/1.0 verified state; trust ceiling never 100%.
527
+ assert d["trust_100_percent"] is False and d["trust_ceiling"] < 1.0
528
+ assert "VERIFIED" not in p["label"]
529
+ print("[5] no VERIFIED/green-1.0 top state; trust never 100% OK")
530
+
531
+ print("\n--- payload keys ---")
532
+ for k in p:
533
+ print(f" - {k}")
534
+ print("\nok:true checks:5")
535
+ _sys.exit(0)