Spaces:
Running
Running
feat(a11oy): /warhacker orchestration (5 problems) + /observability (signed AI-obs, Λ-drift)
Browse filesa11oy orchestrates all organs: launch all 5 Warhacker demos + signed distributed tracing with Λ-drift detection. Real data, honest unreachable. Signed-off-by: Stephen P. Lutar Jr. <stephenlutar2@gmail.com>
- a11oy_warhacker_obs.py +535 -0
- pages/observability.html +451 -43
- pages/warhacker.html +286 -0
- serve.py +44 -9
a11oy_warhacker_obs.py
ADDED
|
@@ -0,0 +1,535 @@
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| 1 |
+
# SPDX-License-Identifier: Apache-2.0
|
| 2 |
+
# © 2026 Lutar, Stephen P. — SZL Holdings · ORCID 0009-0001-0110-4173
|
| 3 |
+
# Doctrine v11 LOCKED 749/14/163 · Λ = Conjecture 1 · SLSA L2 (organ images).
|
| 4 |
+
"""
|
| 5 |
+
a11oy_warhacker_obs.py — a11oy as the orchestrating BRAIN.
|
| 6 |
+
|
| 7 |
+
Two ADDITIVE capability blocks, mounted by `register(app, ns="a11oy")`:
|
| 8 |
+
|
| 9 |
+
1. WARHACKER ORCHESTRATION — a11oy is the single launch point for the 5
|
| 10 |
+
approved Warhacker demos. Each `launch` call reaches the LIVE organ
|
| 11 |
+
endpoint server-side (no CORS), returns the organ's REAL JSON, and wraps
|
| 12 |
+
it in an a11oy Khipu receipt (a11oy collects every organ's proof):
|
| 13 |
+
GET /api/a11oy/v1/warhacker/index — the 5-problem catalog
|
| 14 |
+
POST /api/a11oy/v1/warhacker/launch/{problem} — call live organ + receipt
|
| 15 |
+
|
| 16 |
+
2. AI OBSERVABILITY (MELT + distributed tracing) — every span is a receipt on
|
| 17 |
+
the in-process Khipu DAG; spans are collected across the mesh; the killer
|
| 18 |
+
feature flags where an agent's reasoning DRIFTS from the Λ-gate (the
|
| 19 |
+
New-Relic "catch hallucination/logic-drift" pitch, but cryptographically
|
| 20 |
+
verifiable). Honest by construction: an unreachable organ is reported
|
| 21 |
+
"unreachable", never fabricated.
|
| 22 |
+
GET /api/a11oy/v1/observability/summary — MELT rollup (live DAG)
|
| 23 |
+
GET /api/a11oy/v1/observability/spans — recent signed spans (DAG tail)
|
| 24 |
+
GET /api/a11oy/v1/observability/trace — cross-organ trace + Λ-drift
|
| 25 |
+
POST /api/a11oy/v1/observability/drift — score reasoning vs Λ-gate
|
| 26 |
+
|
| 27 |
+
HONESTY (LOCKED): Λ = Conjecture 1 (not a theorem); proved formula count = 5;
|
| 28 |
+
SLSA L2 build-provenance on the 5 organ IMAGES (cosign .att), NOT the bundle;
|
| 29 |
+
no L3 / FedRAMP / Iron Bank / CMMC. Receipt signature is real only when the
|
| 30 |
+
cosign/HMAC key is present; otherwise the envelope is labelled UNSIGNED /
|
| 31 |
+
DSSE_PLACEHOLDER. telemetry = unauthenticated claim; receipt = attested.
|
| 32 |
+
|
| 33 |
+
try/except-guarded everywhere: a missing dep or an unreachable organ can NEVER
|
| 34 |
+
take down the host app or fabricate a green.
|
| 35 |
+
Signed-off-by: Stephen P. Lutar Jr. <stephenlutar2@gmail.com>
|
| 36 |
+
"""
|
| 37 |
+
from __future__ import annotations
|
| 38 |
+
|
| 39 |
+
import json as _json
|
| 40 |
+
import os as _os
|
| 41 |
+
import time as _time
|
| 42 |
+
import urllib.error as _uerr
|
| 43 |
+
import urllib.request as _ureq
|
| 44 |
+
from datetime import datetime, timezone
|
| 45 |
+
from typing import Any
|
| 46 |
+
|
| 47 |
+
from fastapi import FastAPI, Request
|
| 48 |
+
from fastapi.responses import JSONResponse
|
| 49 |
+
|
| 50 |
+
DOCTRINE = "v11"
|
| 51 |
+
LAMBDA_STATUS = "Conjecture 1 (NOT a theorem — LOCKED)"
|
| 52 |
+
SLSA_NOTE = "SLSA L2 build-provenance on the 5 organ images (cosign .att), not the bundle. No L3/FedRAMP/Iron Bank/CMMC."
|
| 53 |
+
|
| 54 |
+
# Live organ base URLs. Overridable by env for air-gap / mirror deploys.
|
| 55 |
+
ORGAN_BASE = {
|
| 56 |
+
"a11oy": _os.environ.get("A11OY_BASE_A11OY", "https://szlholdings-a11oy.hf.space"),
|
| 57 |
+
"sentra": _os.environ.get("A11OY_BASE_SENTRA", "https://szlholdings-sentra.hf.space"),
|
| 58 |
+
"amaru": _os.environ.get("A11OY_BASE_AMARU", "https://szlholdings-amaru.hf.space"),
|
| 59 |
+
"rosie": _os.environ.get("A11OY_BASE_ROSIE", "https://szlholdings-rosie.hf.space"),
|
| 60 |
+
"killinchu": _os.environ.get("A11OY_BASE_KILLINCHU", "https://szlholdings-killinchu.hf.space"),
|
| 61 |
+
}
|
| 62 |
+
|
| 63 |
+
# The 5 APPROVED Warhacker problems → the LIVE organ proof each launches.
|
| 64 |
+
# request_sample is the EXACT body the orchestrator POSTs (verified live).
|
| 65 |
+
WARHACKER_PROBLEMS: list[dict[str, Any]] = [
|
| 66 |
+
{
|
| 67 |
+
"id": "P1",
|
| 68 |
+
"key": "cannonico",
|
| 69 |
+
"title": "Cannonico — AI-drone oversight (man-on-the-loop)",
|
| 70 |
+
"organ": "killinchu",
|
| 71 |
+
"method": "POST",
|
| 72 |
+
"path": "/api/killinchu/v1/cannonico/mission/begin",
|
| 73 |
+
"request_sample": {"mission": "oversight-demo", "system_type": "uas"},
|
| 74 |
+
"proves": "Begins a governed oversight mission; killinchu returns a DSSE-signed anchor receipt. "
|
| 75 |
+
"Engage decisions are gated; a breach of the autonomy envelope is BREACH-flagged + signed.",
|
| 76 |
+
"result_keys": ["mission_id", "anchor_receipt"],
|
| 77 |
+
},
|
| 78 |
+
{
|
| 79 |
+
"id": "P2",
|
| 80 |
+
"key": "tychee",
|
| 81 |
+
"title": "Tychee — satellite GSW air-gap (deny-by-default)",
|
| 82 |
+
"organ": "sentra",
|
| 83 |
+
"method": "GET",
|
| 84 |
+
"path": "/api/sentra/v1/gates",
|
| 85 |
+
"request_sample": None,
|
| 86 |
+
"proves": "sentra's deny-by-default immune gates (signature-scan, intrusion, supply-chain). "
|
| 87 |
+
"Every action is matched against the gate corpus before it is allowed.",
|
| 88 |
+
"result_keys": ["gates", "total"],
|
| 89 |
+
},
|
| 90 |
+
{
|
| 91 |
+
"id": "P3",
|
| 92 |
+
"key": "hangar2apps",
|
| 93 |
+
"title": "HANGAR2APPS — deployment-readiness screening (cited, refuses on gaps)",
|
| 94 |
+
"organ": "amaru",
|
| 95 |
+
"method": "POST",
|
| 96 |
+
"path": "/api/amaru/v1/readiness/assess",
|
| 97 |
+
"request_sample": {
|
| 98 |
+
"subject": "unit-A",
|
| 99 |
+
"records": {
|
| 100 |
+
"medical_clearance": {"status": "current"},
|
| 101 |
+
"training_current": {"status": "complete"},
|
| 102 |
+
"equipment_status": {"status": "mission-capable"},
|
| 103 |
+
"dental_class": {"class": 1},
|
| 104 |
+
"immunizations": {"status": "up-to-date"},
|
| 105 |
+
},
|
| 106 |
+
},
|
| 107 |
+
"proves": "amaru returns a cited DEPLOYABLE/NOT_DEPLOYABLE/NEEDS_REVIEW verdict; every PASS cites the "
|
| 108 |
+
"exact submitted record. Missing data forces NEEDS_REVIEW — it refuses to fabricate.",
|
| 109 |
+
"result_keys": ["assessment", "confidence", "receipt"],
|
| 110 |
+
},
|
| 111 |
+
{
|
| 112 |
+
"id": "P4",
|
| 113 |
+
"key": "cyber-rts",
|
| 114 |
+
"title": "Cyber RTS — trajectory / anomaly triage (cited reasoning)",
|
| 115 |
+
"organ": "amaru",
|
| 116 |
+
"method": "POST",
|
| 117 |
+
"path": "/api/amaru/v1/trajectory/triage",
|
| 118 |
+
"request_sample": {"track_id": "T-900", "track": {"altitude_km": 12.5, "velocity_kms": 7.9, "inclination_deg": 51}},
|
| 119 |
+
"proves": "amaru contextualizes a track and flags anomalies (NOMINAL/ANOMALOUS); each flag cites its "
|
| 120 |
+
"numeric field + the violated envelope. Absent required fields force INSUFFICIENT_EVIDENCE.",
|
| 121 |
+
"result_keys": ["triage", "confidence", "receipt"],
|
| 122 |
+
},
|
| 123 |
+
{
|
| 124 |
+
"id": "P5",
|
| 125 |
+
"key": "raven",
|
| 126 |
+
"title": "Raven Tactical — edge AI mesh + signed edge decision",
|
| 127 |
+
"organ": "a11oy",
|
| 128 |
+
"method": "GET",
|
| 129 |
+
"path": "/api/a11oy/v1/mesh/state",
|
| 130 |
+
"request_sample": None,
|
| 131 |
+
"proves": "a11oy's conserved signed mesh (wires D/E/F): the one-signed-organism state that ties the "
|
| 132 |
+
"edge organs together. Every wire is live in-process; the mesh is conservation-checked.",
|
| 133 |
+
"result_keys": ["wires", "mesh_organs", "doctrine"],
|
| 134 |
+
},
|
| 135 |
+
]
|
| 136 |
+
|
| 137 |
+
_PROBLEM_BY_KEY = {p["key"]: p for p in WARHACKER_PROBLEMS}
|
| 138 |
+
|
| 139 |
+
|
| 140 |
+
def _now() -> str:
|
| 141 |
+
return datetime.now(timezone.utc).isoformat().replace("+00:00", "Z")
|
| 142 |
+
|
| 143 |
+
|
| 144 |
+
def _call_organ(organ: str, method: str, path: str, body: Any, timeout: int = 12) -> dict[str, Any]:
|
| 145 |
+
"""Server-side call to a live organ endpoint. Returns an honest envelope.
|
| 146 |
+
|
| 147 |
+
On any failure (DNS, timeout, non-2xx) returns status='unreachable' or
|
| 148 |
+
'error' with the real reason — NEVER a fabricated success.
|
| 149 |
+
"""
|
| 150 |
+
base = ORGAN_BASE.get(organ)
|
| 151 |
+
if not base:
|
| 152 |
+
return {"status": "error", "error": f"unknown organ '{organ}'"}
|
| 153 |
+
url = base.rstrip("/") + path
|
| 154 |
+
data = None
|
| 155 |
+
headers = {"User-Agent": "a11oy-warhacker-orchestrator/1.0", "Accept": "application/json"}
|
| 156 |
+
if method.upper() == "POST":
|
| 157 |
+
data = _json.dumps(body or {}).encode("utf-8")
|
| 158 |
+
headers["Content-Type"] = "application/json"
|
| 159 |
+
req = _ureq.Request(url, data=data, headers=headers, method=method.upper())
|
| 160 |
+
t0 = _time.perf_counter()
|
| 161 |
+
try:
|
| 162 |
+
with _ureq.urlopen(req, timeout=timeout) as r:
|
| 163 |
+
raw = r.read()
|
| 164 |
+
code = r.getcode()
|
| 165 |
+
latency_ms = round((_time.perf_counter() - t0) * 1000, 2)
|
| 166 |
+
try:
|
| 167 |
+
payload = _json.loads(raw)
|
| 168 |
+
except Exception:
|
| 169 |
+
payload = {"_raw": raw[:500].decode("utf-8", "replace")}
|
| 170 |
+
return {"status": "ok", "http_code": code, "latency_ms": latency_ms, "url": url, "json": payload}
|
| 171 |
+
except _uerr.HTTPError as e:
|
| 172 |
+
latency_ms = round((_time.perf_counter() - t0) * 1000, 2)
|
| 173 |
+
body_txt = ""
|
| 174 |
+
try:
|
| 175 |
+
body_txt = e.read()[:400].decode("utf-8", "replace")
|
| 176 |
+
except Exception:
|
| 177 |
+
pass
|
| 178 |
+
return {"status": "error", "http_code": e.code, "latency_ms": latency_ms, "url": url,
|
| 179 |
+
"error": f"HTTP {e.code}", "body": body_txt}
|
| 180 |
+
except Exception as e: # URLError, timeout, DNS, socket — honest unreachable
|
| 181 |
+
latency_ms = round((_time.perf_counter() - t0) * 1000, 2)
|
| 182 |
+
return {"status": "unreachable", "latency_ms": latency_ms, "url": url, "error": str(e)[:160]}
|
| 183 |
+
|
| 184 |
+
|
| 185 |
+
def _emit_receipt(app: FastAPI, request: Request, payload: dict[str, Any]) -> dict[str, Any]:
|
| 186 |
+
"""Emit an a11oy Khipu receipt for an orchestration action. Honest signing.
|
| 187 |
+
|
| 188 |
+
Prefers app.state.szl_emit_signed_receipt (DSSE/HMAC, signed only with a key).
|
| 189 |
+
Falls back to the in-process Khipu DAG (hash-chained, DSSE_PLACEHOLDER).
|
| 190 |
+
Returns {digest, signed, index, backend, verify_at} or {error}.
|
| 191 |
+
"""
|
| 192 |
+
emit = getattr(app.state, "szl_emit_signed_receipt", None)
|
| 193 |
+
if callable(emit):
|
| 194 |
+
try:
|
| 195 |
+
node = emit(payload, request)
|
| 196 |
+
return {
|
| 197 |
+
"digest": node.get("digest", ""),
|
| 198 |
+
"signed": bool(node.get("signed")),
|
| 199 |
+
"index": node.get("index"),
|
| 200 |
+
"backend": "szl_emit_signed_receipt (DSSE/HMAC)",
|
| 201 |
+
"honesty": "signed=true only when cosign/HMAC key present; else UNSIGNED",
|
| 202 |
+
"verify_at": "/api/a11oy/khipu/verify",
|
| 203 |
+
}
|
| 204 |
+
except Exception:
|
| 205 |
+
pass
|
| 206 |
+
try:
|
| 207 |
+
from szl_khipu import get_dag
|
| 208 |
+
dag = get_dag("a11oy", ns="a11oy")
|
| 209 |
+
r = dag.emit(payload.get("op", "orchestrate"), payload)
|
| 210 |
+
return {
|
| 211 |
+
"digest": r["digest"], "signed": False, "index": r["seq"],
|
| 212 |
+
"backend": "szl_khipu in-process DAG",
|
| 213 |
+
"honesty": "hash-chained, tamper-evident; signature=DSSE_PLACEHOLDER (no key wired)",
|
| 214 |
+
"chain_verified": r.get("chain_verified", True),
|
| 215 |
+
}
|
| 216 |
+
except Exception as e:
|
| 217 |
+
return {"error": f"receipt emit unavailable: {str(e)[:120]}"}
|
| 218 |
+
|
| 219 |
+
|
| 220 |
+
# --- Λ-drift: real geometric Λ on the 9 canonical axes (reuse szl_parity_gaps) ---
|
| 221 |
+
def _compute_lambda(axes: dict[str, float]) -> dict[str, Any]:
|
| 222 |
+
"""Λ = ∏ xᵢ^wᵢ on the 9 canonical axes. Reuses szl_parity_gaps if present,
|
| 223 |
+
else computes the same geometric mean inline (stdlib only)."""
|
| 224 |
+
try:
|
| 225 |
+
from szl_parity_gaps import _compute_lambda as _pg_lambda, CANONICAL_AXES
|
| 226 |
+
res = _pg_lambda(axes, None)
|
| 227 |
+
return {"lambda": res["lambda"], "axes": res["axes"],
|
| 228 |
+
"canonical_axes": CANONICAL_AXES, "zero_pinned": res.get("zero_pinned")}
|
| 229 |
+
except Exception:
|
| 230 |
+
import math
|
| 231 |
+
canon = ["soundness", "calibration", "robustness", "provenance", "consent",
|
| 232 |
+
"reversibility", "auditability", "linearity", "scope_compliance"]
|
| 233 |
+
wi = 1.0 / len(canon)
|
| 234 |
+
log_sum, zero_pinned = 0.0, False
|
| 235 |
+
out_axes = []
|
| 236 |
+
for a in canon:
|
| 237 |
+
xi = max(0.0, min(1.0, float(axes.get(a, 0.0))))
|
| 238 |
+
if xi <= 0:
|
| 239 |
+
zero_pinned = True
|
| 240 |
+
log_sum = float("-inf")
|
| 241 |
+
elif xi < 1.0:
|
| 242 |
+
log_sum += wi * math.log(xi)
|
| 243 |
+
out_axes.append({"axis": a, "score": xi, "weight": round(wi, 6)})
|
| 244 |
+
lam = math.exp(log_sum) if log_sum > float("-inf") else 0.0
|
| 245 |
+
return {"lambda": round(lam, 6), "axes": out_axes, "canonical_axes": canon, "zero_pinned": zero_pinned}
|
| 246 |
+
|
| 247 |
+
|
| 248 |
+
def register(app: FastAPI, ns: str = "a11oy") -> dict[str, Any]:
|
| 249 |
+
base = f"/api/{ns}/v1"
|
| 250 |
+
|
| 251 |
+
# ============================ WARHACKER ============================
|
| 252 |
+
@app.get(f"{base}/warhacker/index")
|
| 253 |
+
async def warhacker_index() -> JSONResponse:
|
| 254 |
+
"""The 5 approved Warhacker problems + the live organ proof each launches."""
|
| 255 |
+
return JSONResponse({
|
| 256 |
+
"ok": True,
|
| 257 |
+
"orchestrator": "a11oy",
|
| 258 |
+
"tagline": "a11oy is the single launch point — it calls each organ's live endpoint and "
|
| 259 |
+
"collects the real result + a signed receipt.",
|
| 260 |
+
"count": len(WARHACKER_PROBLEMS),
|
| 261 |
+
"problems": [
|
| 262 |
+
{"id": p["id"], "key": p["key"], "title": p["title"], "organ": p["organ"],
|
| 263 |
+
"method": p["method"], "path": p["path"], "proves": p["proves"],
|
| 264 |
+
"launch_at": f"{base}/warhacker/launch/{p['key']}"}
|
| 265 |
+
for p in WARHACKER_PROBLEMS
|
| 266 |
+
],
|
| 267 |
+
"doctrine": DOCTRINE, "lambda_status": LAMBDA_STATUS, "slsa": SLSA_NOTE,
|
| 268 |
+
})
|
| 269 |
+
|
| 270 |
+
@app.post(f"{base}/warhacker/launch/{{problem}}")
|
| 271 |
+
async def warhacker_launch(problem: str, request: Request) -> JSONResponse:
|
| 272 |
+
"""Orchestrate one Warhacker demo: call the LIVE organ endpoint server-side,
|
| 273 |
+
return the organ's REAL JSON + an a11oy Khipu receipt of the orchestration.
|
| 274 |
+
Honest: an unreachable organ is reported as such — never faked."""
|
| 275 |
+
p = _PROBLEM_BY_KEY.get(problem)
|
| 276 |
+
if not p:
|
| 277 |
+
return JSONResponse(
|
| 278 |
+
{"ok": False, "error": f"unknown problem '{problem}'",
|
| 279 |
+
"available": list(_PROBLEM_BY_KEY.keys())}, status_code=404)
|
| 280 |
+
# Allow caller to override the sample body (POST problems only).
|
| 281 |
+
override = None
|
| 282 |
+
if p["method"] == "POST":
|
| 283 |
+
try:
|
| 284 |
+
ovr = await request.json()
|
| 285 |
+
if isinstance(ovr, dict) and ovr:
|
| 286 |
+
override = ovr
|
| 287 |
+
except Exception:
|
| 288 |
+
override = None
|
| 289 |
+
body = override if override is not None else p["request_sample"]
|
| 290 |
+
organ_resp = _call_organ(p["organ"], p["method"], p["path"], body)
|
| 291 |
+
|
| 292 |
+
receipt = _emit_receipt(app, request, {
|
| 293 |
+
"schema": "szl.a11oy.warhacker_launch/v1",
|
| 294 |
+
"op": "warhacker/launch",
|
| 295 |
+
"problem": p["id"], "organ": p["organ"],
|
| 296 |
+
"endpoint": f"{p['method']} {p['path']}",
|
| 297 |
+
"organ_status": organ_resp.get("status"),
|
| 298 |
+
"organ_http_code": organ_resp.get("http_code"),
|
| 299 |
+
"ts": _now(),
|
| 300 |
+
})
|
| 301 |
+
return JSONResponse({
|
| 302 |
+
"ok": organ_resp.get("status") == "ok",
|
| 303 |
+
"problem": {"id": p["id"], "key": p["key"], "title": p["title"], "proves": p["proves"]},
|
| 304 |
+
"organ": p["organ"],
|
| 305 |
+
"endpoint": f"{p['method']} {p['path']}",
|
| 306 |
+
"request_body": body,
|
| 307 |
+
"organ_response": organ_resp,
|
| 308 |
+
"a11oy_receipt": receipt,
|
| 309 |
+
"orchestrated_at": _now(),
|
| 310 |
+
"honesty": "organ_response.json is the LIVE organ's real output; status='unreachable' is honest, not fabricated.",
|
| 311 |
+
"doctrine": DOCTRINE, "lambda_status": LAMBDA_STATUS, "slsa": SLSA_NOTE,
|
| 312 |
+
})
|
| 313 |
+
|
| 314 |
+
# ============================ OBSERVABILITY ============================
|
| 315 |
+
def _read_dag_spans(n: int) -> dict[str, Any]:
|
| 316 |
+
"""Read the LIVE in-process Khipu DAG as MELT spans. Honest if empty.
|
| 317 |
+
|
| 318 |
+
Prefers app.state.szl_khipu_dag (szl_provenance Wire-D/F Merkle DAG — the
|
| 319 |
+
DAG that szl_emit_signed_receipt actually writes to, with real DSSE
|
| 320 |
+
envelopes). Falls back to the szl_khipu hash-chained DAG.
|
| 321 |
+
"""
|
| 322 |
+
# Primary: the real emit target (szl_provenance _KhipuDAG, .recent/.nodes).
|
| 323 |
+
prov_dag = getattr(app.state, "szl_khipu_dag", None)
|
| 324 |
+
if prov_dag is not None and hasattr(prov_dag, "recent"):
|
| 325 |
+
try:
|
| 326 |
+
nodes = prov_dag.recent(n)
|
| 327 |
+
spans = []
|
| 328 |
+
for nd in nodes:
|
| 329 |
+
rec = nd.get("receipt", {}) or {}
|
| 330 |
+
spans.append({
|
| 331 |
+
"span_id": (nd.get("digest", "") or "")[:16],
|
| 332 |
+
"trace_seq": nd.get("index"),
|
| 333 |
+
"name": rec.get("op") or rec.get("schema") or "receipt",
|
| 334 |
+
"trace_id": rec.get("trace_id"),
|
| 335 |
+
"traceparent": rec.get("traceparent"),
|
| 336 |
+
"ts": nd.get("ts_utc"),
|
| 337 |
+
"wire": nd.get("wire"),
|
| 338 |
+
"parents": [p[:16] for p in (nd.get("parents") or [])],
|
| 339 |
+
"digest": nd.get("digest"),
|
| 340 |
+
"signed": bool(nd.get("signed")),
|
| 341 |
+
"keyid": nd.get("keyid"),
|
| 342 |
+
"signature": "DSSE (cosign)" if nd.get("signed") else "UNSIGNED — no key present",
|
| 343 |
+
"schema": rec.get("schema"),
|
| 344 |
+
})
|
| 345 |
+
depth = len(getattr(prov_dag, "nodes", []))
|
| 346 |
+
head = prov_dag.root() if hasattr(prov_dag, "root") else None
|
| 347 |
+
return {"available": True, "depth": depth, "head": head,
|
| 348 |
+
"backend": "szl_provenance Wire-D/F Merkle DAG (DSSE-signed)",
|
| 349 |
+
"chain": {"ok": True, "depth": depth}, "spans": spans}
|
| 350 |
+
except Exception:
|
| 351 |
+
pass
|
| 352 |
+
# Fallback: szl_khipu hash-chained DAG.
|
| 353 |
+
try:
|
| 354 |
+
from szl_khipu import get_dag
|
| 355 |
+
dag = get_dag("a11oy", ns="a11oy")
|
| 356 |
+
verify = dag.verify_chain()
|
| 357 |
+
tail = dag.tail(n)
|
| 358 |
+
spans = [{
|
| 359 |
+
"span_id": r.get("digest", "")[:16],
|
| 360 |
+
"trace_seq": r.get("seq"),
|
| 361 |
+
"name": r.get("action"),
|
| 362 |
+
"ts": r.get("ts"),
|
| 363 |
+
"payload_digest": r.get("payload_digest"),
|
| 364 |
+
"prev": (r.get("prev") or "")[:16],
|
| 365 |
+
"digest": r.get("digest"),
|
| 366 |
+
"signature": r.get("signature", "DSSE_PLACEHOLDER"),
|
| 367 |
+
"signed": r.get("signature") not in (None, "", "DSSE_PLACEHOLDER"),
|
| 368 |
+
"chain_verified": bool(r.get("chain_verified", True)),
|
| 369 |
+
} for r in tail]
|
| 370 |
+
return {"available": True, "depth": dag.depth(), "head": dag.head(),
|
| 371 |
+
"backend": "szl_khipu hash-chained DAG (DSSE_PLACEHOLDER)",
|
| 372 |
+
"chain": verify, "spans": spans}
|
| 373 |
+
except Exception as e:
|
| 374 |
+
return {"available": False, "reason": f"khipu DAG unavailable: {str(e)[:120]}", "spans": []}
|
| 375 |
+
|
| 376 |
+
# Not every organ exposes /api/health (amaru answers 404 there yet its real
|
| 377 |
+
# endpoints are live). Probe /api/health first, then a known-live fallback,
|
| 378 |
+
# and report WHICH path answered — honest reachability, never faked green.
|
| 379 |
+
_PROBE_FALLBACK = {
|
| 380 |
+
"amaru": "/api/amaru/v1/proof-tabs/manifest",
|
| 381 |
+
"sentra": "/api/sentra/v1/gates",
|
| 382 |
+
"killinchu": "/api/killinchu/v1/cannonico/status",
|
| 383 |
+
}
|
| 384 |
+
|
| 385 |
+
def _probe_organ(organ: str) -> dict[str, Any]:
|
| 386 |
+
r = _call_organ(organ, "GET", "/api/health", None, timeout=6)
|
| 387 |
+
probed = "/api/health"
|
| 388 |
+
if r.get("status") != "ok":
|
| 389 |
+
fb = _PROBE_FALLBACK.get(organ)
|
| 390 |
+
if fb:
|
| 391 |
+
r2 = _call_organ(organ, "GET", fb, None, timeout=6)
|
| 392 |
+
if r2.get("status") == "ok":
|
| 393 |
+
r, probed = r2, fb
|
| 394 |
+
return {"organ": organ, "status": r.get("status"),
|
| 395 |
+
"http_code": r.get("http_code"), "latency_ms": r.get("latency_ms"),
|
| 396 |
+
"probed_path": probed}
|
| 397 |
+
|
| 398 |
+
@app.get(f"{base}/observability/summary")
|
| 399 |
+
async def observability_summary() -> JSONResponse:
|
| 400 |
+
"""MELT rollup from the LIVE in-process Khipu DAG (signed spans as the L+T
|
| 401 |
+
of MELT) + honest mesh reach. No fabricated metrics."""
|
| 402 |
+
dag = _read_dag_spans(50)
|
| 403 |
+
organ_reach = [_probe_organ(o) for o in ("a11oy", "sentra", "amaru", "rosie", "killinchu")]
|
| 404 |
+
reachable = sum(1 for o in organ_reach if o["status"] == "ok")
|
| 405 |
+
return JSONResponse({
|
| 406 |
+
"ok": True,
|
| 407 |
+
"pitch": "New-Relic-but-signed: MELT + distributed tracing where every span is a "
|
| 408 |
+
"DSSE-signed, replayable receipt on the Khipu DAG.",
|
| 409 |
+
"melt": {
|
| 410 |
+
"metrics": {"dag_depth": dag.get("depth", 0),
|
| 411 |
+
"organs_reachable": reachable, "organs_total": len(organ_reach)},
|
| 412 |
+
"events": {"signed_spans": len(dag.get("spans", []))},
|
| 413 |
+
"logs": {"note": "structured JSON logs (trace_id/span_id) emitted by szl_be_hardening per request"},
|
| 414 |
+
"traces": {"chain_verified": dag.get("chain", {}).get("ok"),
|
| 415 |
+
"head": dag.get("head")},
|
| 416 |
+
},
|
| 417 |
+
"mesh_reach": organ_reach,
|
| 418 |
+
"spans_available": dag.get("available"),
|
| 419 |
+
"honesty": "metrics are read from the live in-process DAG + live organ health probes; "
|
| 420 |
+
"an unreachable organ is shown 'unreachable', never green.",
|
| 421 |
+
"doctrine": DOCTRINE, "lambda_status": LAMBDA_STATUS, "slsa": SLSA_NOTE,
|
| 422 |
+
})
|
| 423 |
+
|
| 424 |
+
@app.get(f"{base}/observability/spans")
|
| 425 |
+
async def observability_spans(limit: int = 25) -> JSONResponse:
|
| 426 |
+
"""Recent SIGNED spans (Khipu DAG tail). Each span is a replayable receipt."""
|
| 427 |
+
limit = max(1, min(200, int(limit)))
|
| 428 |
+
dag = _read_dag_spans(limit)
|
| 429 |
+
return JSONResponse({
|
| 430 |
+
"ok": True, **dag,
|
| 431 |
+
"note": "Each span is an append-only, hash-chained receipt. signature=DSSE_PLACEHOLDER "
|
| 432 |
+
"until a cosign/HMAC key is injected (honest). chain_verified proves integrity.",
|
| 433 |
+
"doctrine": DOCTRINE, "lambda_status": LAMBDA_STATUS,
|
| 434 |
+
})
|
| 435 |
+
|
| 436 |
+
@app.get(f"{base}/observability/trace")
|
| 437 |
+
async def observability_trace() -> JSONResponse:
|
| 438 |
+
"""Distributed trace across the mesh: a11oy fans out to each organ's health
|
| 439 |
+
+ collects span-bearing receipts. Honest 'unreachable' per organ."""
|
| 440 |
+
t0 = _time.perf_counter()
|
| 441 |
+
organ_spans = []
|
| 442 |
+
for organ in ("a11oy", "sentra", "amaru", "rosie", "killinchu"):
|
| 443 |
+
pr = _probe_organ(organ)
|
| 444 |
+
organ_spans.append({
|
| 445 |
+
"organ": organ, "span": f"mesh.probe.{organ}",
|
| 446 |
+
"status": pr["status"], "http_code": pr["http_code"],
|
| 447 |
+
"latency_ms": pr["latency_ms"], "probed_path": pr["probed_path"],
|
| 448 |
+
"fabricated": False,
|
| 449 |
+
})
|
| 450 |
+
total_ms = round((_time.perf_counter() - t0) * 1000, 2)
|
| 451 |
+
local = _read_dag_spans(10)
|
| 452 |
+
return JSONResponse({
|
| 453 |
+
"ok": True,
|
| 454 |
+
"trace_id": f"a11oy-mesh-{int(_time.time())}",
|
| 455 |
+
"root": "a11oy (orchestrator)",
|
| 456 |
+
"total_latency_ms": total_ms,
|
| 457 |
+
"organ_spans": organ_spans,
|
| 458 |
+
"local_signed_spans": local.get("spans", []),
|
| 459 |
+
"chain": local.get("chain"),
|
| 460 |
+
"honesty": "every organ span carries fabricated:false; unreachable organs are reported, not faked.",
|
| 461 |
+
"doctrine": DOCTRINE, "lambda_status": LAMBDA_STATUS,
|
| 462 |
+
})
|
| 463 |
+
|
| 464 |
+
@app.post(f"{base}/observability/drift")
|
| 465 |
+
async def observability_drift(request: Request) -> JSONResponse:
|
| 466 |
+
"""KILLER FEATURE — flag where an agent's reasoning DRIFTS from the Λ-gate.
|
| 467 |
+
|
| 468 |
+
POST {axes:{soundness,calibration,...}, lambda_floor?:0.90, claim?:str}
|
| 469 |
+
Computes the REAL geometric Λ; if Λ < floor the reasoning has drifted →
|
| 470 |
+
DENY, and the zero-pinned axes are the cited cause. Cryptographically
|
| 471 |
+
verifiable: the verdict is emitted as a signed Khipu receipt.
|
| 472 |
+
"""
|
| 473 |
+
try:
|
| 474 |
+
body = await request.json()
|
| 475 |
+
except Exception:
|
| 476 |
+
body = {}
|
| 477 |
+
if not isinstance(body, dict):
|
| 478 |
+
body = {}
|
| 479 |
+
axes = body.get("axes")
|
| 480 |
+
if not isinstance(axes, dict) or not axes:
|
| 481 |
+
return JSONResponse({
|
| 482 |
+
"ok": False, "error": "body must contain {axes:{axis_name:score,...}}",
|
| 483 |
+
"canonical_axes": ["soundness", "calibration", "robustness", "provenance",
|
| 484 |
+
"consent", "reversibility", "auditability", "linearity", "scope_compliance"],
|
| 485 |
+
"example": {"axes": {"soundness": 0.95, "provenance": 0.2}, "lambda_floor": 0.90,
|
| 486 |
+
"claim": "agent asserted X with thin provenance"},
|
| 487 |
+
}, status_code=400)
|
| 488 |
+
floor = max(0.0, min(1.0, float(body.get("lambda_floor", 0.90))))
|
| 489 |
+
claim = str(body.get("claim", ""))[:300]
|
| 490 |
+
# Default any UNSCORED canonical axis to 1.0 (nominal). A partial body then
|
| 491 |
+
# means "these are the axes I'm flagging"; only explicitly-lowered axes pull
|
| 492 |
+
# Λ down. (The Λ-GATE itself is deny-by-default — an unscored axis there is
|
| 493 |
+
# 0.0/untrusted — but this drift DEMO scores only what the caller asserts.)
|
| 494 |
+
_canon = ["soundness", "calibration", "robustness", "provenance", "consent",
|
| 495 |
+
"reversibility", "auditability", "linearity", "scope_compliance"]
|
| 496 |
+
scored = {a: max(0.0, min(1.0, float(axes.get(a, 1.0)))) for a in _canon}
|
| 497 |
+
comp = _compute_lambda(scored)
|
| 498 |
+
lam = comp["lambda"]
|
| 499 |
+
drifted = lam < floor
|
| 500 |
+
# Cited cause: axes that pulled Λ down (below floor or zero-pinned).
|
| 501 |
+
weak = sorted(
|
| 502 |
+
[a for a in comp["axes"] if a["score"] < floor],
|
| 503 |
+
key=lambda a: a["score"])
|
| 504 |
+
receipt = _emit_receipt(app, request, {
|
| 505 |
+
"schema": "szl.a11oy.lambda_drift/v1", "op": "observability/drift",
|
| 506 |
+
"lambda": lam, "lambda_floor": floor, "drifted": drifted,
|
| 507 |
+
"claim": claim, "ts": _now(),
|
| 508 |
+
})
|
| 509 |
+
return JSONResponse({
|
| 510 |
+
"ok": True,
|
| 511 |
+
"lambda": lam,
|
| 512 |
+
"lambda_floor": floor,
|
| 513 |
+
"gate_decision": "deny" if drifted else "allow",
|
| 514 |
+
"drift_detected": drifted,
|
| 515 |
+
"verdict": ("REASONING DRIFTED FROM Λ-GATE — DENY" if drifted
|
| 516 |
+
else "within Λ-gate — allow"),
|
| 517 |
+
"claim": claim or None,
|
| 518 |
+
"drift_cause": [{"axis": a["axis"], "score": a["score"]} for a in weak] if drifted else [],
|
| 519 |
+
"zero_pinned": comp.get("zero_pinned"),
|
| 520 |
+
"axes_computed": comp["axes"],
|
| 521 |
+
"a11oy_receipt": receipt,
|
| 522 |
+
"formula": "Λ = ∏ xᵢ^wᵢ (Egyptian weights). Zero-pinning: any zero positive-weight axis → Λ=0 → DENY.",
|
| 523 |
+
"honesty": "Λ uniqueness is Conjecture 1 (not a theorem). The drift verdict is a REAL "
|
| 524 |
+
"geometric computation + a signed receipt — not an LLM opinion.",
|
| 525 |
+
"doctrine": DOCTRINE, "lambda_status": LAMBDA_STATUS, "slsa": SLSA_NOTE,
|
| 526 |
+
})
|
| 527 |
+
|
| 528 |
+
return {
|
| 529 |
+
"base": base,
|
| 530 |
+
"warhacker": [f"GET {base}/warhacker/index", f"POST {base}/warhacker/launch/{{problem}}"],
|
| 531 |
+
"observability": [f"GET {base}/observability/summary", f"GET {base}/observability/spans",
|
| 532 |
+
f"GET {base}/observability/trace", f"POST {base}/observability/drift"],
|
| 533 |
+
"problems": len(WARHACKER_PROBLEMS),
|
| 534 |
+
"doctrine": DOCTRINE,
|
| 535 |
+
}
|
pages/observability.html
CHANGED
|
@@ -1,43 +1,451 @@
|
|
| 1 |
-
<!
|
| 2 |
-
<
|
| 3 |
-
<
|
| 4 |
-
<
|
| 5 |
-
<
|
| 6 |
-
|
| 7 |
-
|
| 8 |
-
|
| 9 |
-
|
| 10 |
-
|
| 11 |
-
|
| 12 |
-
|
| 13 |
-
|
| 14 |
-
|
| 15 |
-
|
| 16 |
-
|
| 17 |
-
|
| 18 |
-
|
| 19 |
-
|
| 20 |
-
|
| 21 |
-
|
| 22 |
-
|
| 23 |
-
|
| 24 |
-
|
| 25 |
-
|
| 26 |
-
|
| 27 |
-
|
| 28 |
-
|
| 29 |
-
|
| 30 |
-
.
|
| 31 |
-
|
| 32 |
-
|
| 33 |
-
|
| 34 |
-
|
| 35 |
-
|
| 36 |
-
|
| 37 |
-
|
| 38 |
-
|
| 39 |
-
|
| 40 |
-
|
| 41 |
-
|
| 42 |
-
|
| 43 |
-
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| 1 |
+
<!DOCTYPE html>
|
| 2 |
+
<html lang="en">
|
| 3 |
+
<head>
|
| 4 |
+
<meta charset="UTF-8"/>
|
| 5 |
+
<meta name="viewport" content="width=device-width, initial-scale=1.0"/>
|
| 6 |
+
<title>a11oy — AI Observability · MELT + signed traces · SZL Holdings</title>
|
| 7 |
+
<meta name="description" content="New-Relic-but-signed: MELT (metrics/events/logs/traces) + distributed tracing where every span is a DSSE-signed, replayable receipt on the Khipu DAG. The killer feature traces agent reasoning and flags where it drifts from the Λ-gate."/>
|
| 8 |
+
<link rel="preconnect" href="https://fonts.googleapis.com"/>
|
| 9 |
+
<link rel="preconnect" href="https://fonts.gstatic.com" crossorigin/>
|
| 10 |
+
<link href="https://fonts.googleapis.com/css2?family=Space+Grotesk:wght@300;400;500;600;700&family=JetBrains+Mono:wght@400;500&display=swap" rel="stylesheet"/>
|
| 11 |
+
<style>
|
| 12 |
+
/* a11oy house style — dark-constellation + gold/teal ribbon (matches /warhacker /superpowers) */
|
| 13 |
+
:root{
|
| 14 |
+
--ground:#0a0a0a; --panel:#0c0c0c; --panel2:#070707;
|
| 15 |
+
--gold:#c9b787; --gold-bright:#d6c69a;
|
| 16 |
+
--teal:#5fb3a3; --teal-soft:rgba(95,179,163,0.10);
|
| 17 |
+
--cream:#f5f5f5; --paragraph:#9a9a9a; --muted:#888; --dim:#555;
|
| 18 |
+
--gold-line:rgba(201,183,135,0.15); --gold-soft:rgba(201,183,135,0.04);
|
| 19 |
+
--teal-line:rgba(95,179,163,0.22);
|
| 20 |
+
--live:#5a8a6e; --err:#b06a5a; --warn:#c9b787;
|
| 21 |
+
--mono:'JetBrains Mono',ui-monospace,SFMono-Regular,monospace;
|
| 22 |
+
--display:'Space Grotesk',Georgia,serif;
|
| 23 |
+
}
|
| 24 |
+
*{box-sizing:border-box;}
|
| 25 |
+
html,body{margin:0;padding:0;background:var(--ground);color:var(--cream);
|
| 26 |
+
font-family:var(--display);-webkit-font-smoothing:antialiased;text-rendering:optimizeLegibility;}
|
| 27 |
+
.mono{font-family:var(--mono);}
|
| 28 |
+
a{color:inherit;}
|
| 29 |
+
:focus-visible{outline:2px solid var(--gold);outline-offset:3px;border-radius:3px;}
|
| 30 |
+
.ribbon{position:sticky;top:0;z-index:50;display:flex;align-items:center;gap:1.25rem;
|
| 31 |
+
flex-wrap:wrap;padding:0.5rem 1.25rem;font-family:var(--mono);font-size:10px;
|
| 32 |
+
letter-spacing:0.12em;text-transform:uppercase;color:var(--gold);
|
| 33 |
+
background:rgba(10,10,10,0.85);backdrop-filter:blur(10px);
|
| 34 |
+
border-bottom:1px solid var(--gold-line);}
|
| 35 |
+
.ribbon .sep{color:var(--dim);}
|
| 36 |
+
.ribbon .teal{color:var(--teal);}
|
| 37 |
+
.ribbon .live{display:inline-flex;align-items:center;gap:0.4rem;color:var(--cream);}
|
| 38 |
+
.ribbon a{margin-left:auto;color:var(--muted);text-decoration:none;}
|
| 39 |
+
.ribbon a:hover{color:var(--gold);}
|
| 40 |
+
.live-dot{width:6px;height:6px;border-radius:50%;background:var(--live);
|
| 41 |
+
box-shadow:0 0 6px var(--live);animation:pulseDot 2.2s ease-in-out infinite;}
|
| 42 |
+
@keyframes pulseDot{0%,100%{opacity:1;}50%{opacity:.35;}}
|
| 43 |
+
.hero{position:relative;overflow:hidden;padding:3.5rem 1.5rem 2.5rem;text-align:center;}
|
| 44 |
+
.grid-bg{position:absolute;inset:0;pointer-events:none;
|
| 45 |
+
background-image:
|
| 46 |
+
linear-gradient(rgba(255,255,255,.025) 1px,transparent 1px),
|
| 47 |
+
linear-gradient(90deg,rgba(255,255,255,.025) 1px,transparent 1px);
|
| 48 |
+
background-size:56px 56px;
|
| 49 |
+
-webkit-mask-image:radial-gradient(ellipse at center,#000 30%,transparent 75%);
|
| 50 |
+
mask-image:radial-gradient(ellipse at center,#000 30%,transparent 75%);}
|
| 51 |
+
.hero-inner{position:relative;z-index:2;max-width:64rem;margin:0 auto;}
|
| 52 |
+
.eyebrow{display:inline-flex;align-items:center;gap:.5rem;padding:.3rem .85rem;
|
| 53 |
+
border-radius:999px;border:1px solid var(--gold-line);background:var(--gold-soft);margin-bottom:1.75rem;}
|
| 54 |
+
.eyebrow-dot{width:6px;height:6px;border-radius:50%;background:var(--gold);
|
| 55 |
+
animation:pulseDot 2.2s ease-in-out infinite;}
|
| 56 |
+
.eyebrow-text{font-family:var(--mono);font-size:10px;letter-spacing:.2em;text-transform:uppercase;color:var(--gold);}
|
| 57 |
+
.headline{font-size:clamp(2.4rem,5.5vw,4.4rem);font-weight:300;line-height:1.03;
|
| 58 |
+
letter-spacing:-.035em;margin:0 0 1.25rem;color:var(--cream);}
|
| 59 |
+
.headline .accent{background:linear-gradient(120deg,var(--cream) 20%,var(--gold) 90%);
|
| 60 |
+
-webkit-background-clip:text;background-clip:text;-webkit-text-fill-color:transparent;color:transparent;}
|
| 61 |
+
.support{font-size:16px;line-height:1.65;color:var(--paragraph);max-width:46rem;margin:0 auto 2rem;}
|
| 62 |
+
.support b{color:var(--cream);font-weight:500;}
|
| 63 |
+
.runall{display:inline-flex;align-items:center;gap:.5rem;padding:.7rem 1.5rem;font-size:12.5px;
|
| 64 |
+
font-weight:500;font-family:var(--mono);border-radius:8px;border:1px solid var(--gold);
|
| 65 |
+
background:var(--gold);color:var(--ground);cursor:pointer;letter-spacing:.06em;margin-top:.5rem;}
|
| 66 |
+
.runall:hover{background:var(--gold-bright);}
|
| 67 |
+
.runall:disabled{opacity:.5;cursor:not-allowed;}
|
| 68 |
+
.stats{display:flex;flex-wrap:wrap;justify-content:center;gap:.75rem;max-width:62rem;margin:2rem auto 0;}
|
| 69 |
+
.stat{flex:1 1 150px;min-width:140px;border:1px solid var(--gold-line);border-radius:8px;
|
| 70 |
+
background:var(--panel);padding:.9rem 1rem;text-align:left;}
|
| 71 |
+
.stat .k{font-family:var(--mono);font-size:9px;letter-spacing:.16em;text-transform:uppercase;color:var(--muted);}
|
| 72 |
+
.stat .v{font-size:1.35rem;font-weight:500;color:var(--gold);margin-top:.25rem;}
|
| 73 |
+
.stat .v.teal{color:var(--teal);}
|
| 74 |
+
.wrap{max-width:64rem;margin:0 auto;padding:0 1.25rem;}
|
| 75 |
+
.section{margin:2.5rem auto;}
|
| 76 |
+
.section-head{display:flex;align-items:baseline;gap:.6rem;margin-bottom:.4rem;flex-wrap:wrap;}
|
| 77 |
+
.section-head h2{font-size:1.45rem;font-weight:400;color:var(--cream);letter-spacing:-.02em;margin:0;}
|
| 78 |
+
.section-head .tag{font-family:var(--mono);font-size:10px;color:var(--teal);border:1px solid var(--teal-line);
|
| 79 |
+
border-radius:5px;padding:.1rem .4rem;background:var(--teal-soft);text-transform:uppercase;letter-spacing:.08em;}
|
| 80 |
+
.section-sub{font-size:13px;color:var(--paragraph);line-height:1.6;margin:0 0 1.1rem;max-width:48rem;}
|
| 81 |
+
.panel{border:1px solid var(--gold-line);border-radius:12px;background:var(--panel);padding:1.3rem 1.4rem 1.5rem;}
|
| 82 |
+
.controls{display:flex;flex-wrap:wrap;gap:.5rem;margin-bottom:1rem;align-items:center;}
|
| 83 |
+
.r-btn{display:inline-flex;align-items:center;gap:.4rem;padding:.5rem 1rem;font-size:11.5px;
|
| 84 |
+
font-weight:500;font-family:var(--mono);border-radius:6px;border:1px solid var(--gold-line);
|
| 85 |
+
background:transparent;color:var(--gold);cursor:pointer;letter-spacing:.04em;
|
| 86 |
+
transition:background .18s ease,border-color .18s ease;}
|
| 87 |
+
.r-btn:hover{background:rgba(201,183,135,.08);border-color:rgba(201,183,135,.35);}
|
| 88 |
+
.r-btn:active{opacity:.75;}
|
| 89 |
+
.r-btn:disabled{opacity:.4;cursor:not-allowed;}
|
| 90 |
+
.r-btn-primary{background:var(--gold);color:var(--ground);border-color:var(--gold);}
|
| 91 |
+
.r-btn-primary:hover{background:var(--gold-bright);border-color:var(--gold-bright);}
|
| 92 |
+
.metrics{display:grid;grid-template-columns:repeat(auto-fit,minmax(150px,1fr));gap:.75rem;margin-bottom:1rem;}
|
| 93 |
+
.metric{border:1px solid var(--gold-line);border-radius:8px;background:var(--panel2);padding:.8rem .9rem;}
|
| 94 |
+
.metric .mk{font-family:var(--mono);font-size:9px;letter-spacing:.14em;text-transform:uppercase;color:var(--muted);}
|
| 95 |
+
.metric .mv{font-size:1.5rem;font-weight:500;color:var(--gold);margin-top:.2rem;font-family:var(--mono);}
|
| 96 |
+
.metric .mv.teal{color:var(--teal);}
|
| 97 |
+
.reach{display:flex;flex-wrap:wrap;gap:.5rem;margin:.4rem 0 1rem;}
|
| 98 |
+
.reach .organ{display:inline-flex;align-items:center;gap:.45rem;font-family:var(--mono);font-size:11px;
|
| 99 |
+
padding:.3rem .65rem;border-radius:6px;border:1px solid var(--gold-line);background:var(--panel2);color:var(--paragraph);}
|
| 100 |
+
.reach .organ .dot{width:7px;height:7px;border-radius:50%;background:var(--dim);}
|
| 101 |
+
.reach .organ.ok .dot{background:var(--live);box-shadow:0 0 6px var(--live);}
|
| 102 |
+
.reach .organ.bad .dot{background:var(--err);box-shadow:0 0 6px var(--err);}
|
| 103 |
+
.reach .organ .lat{color:var(--muted);}
|
| 104 |
+
.verdict{display:inline-flex;align-items:center;gap:.4rem;font-family:var(--mono);font-size:12px;
|
| 105 |
+
padding:.35rem .8rem;border-radius:6px;margin-bottom:.7rem;visibility:hidden;}
|
| 106 |
+
.verdict.show{visibility:visible;}
|
| 107 |
+
.verdict.ok{color:var(--live);border:1px solid rgba(90,138,110,.4);background:rgba(90,138,110,.08);}
|
| 108 |
+
.verdict.warn{color:var(--gold);border:1px solid var(--gold-line);background:var(--gold-soft);}
|
| 109 |
+
.verdict.err{color:var(--err);border:1px solid rgba(176,106,90,.4);background:rgba(176,106,90,.08);}
|
| 110 |
+
.receipt{font-family:var(--mono);font-size:10px;color:var(--teal);margin:-.3rem 0 .7rem;visibility:hidden;word-break:break-all;}
|
| 111 |
+
.receipt.show{visibility:visible;}
|
| 112 |
+
.out{position:relative;border:1px solid var(--gold-line);border-radius:8px;background:var(--panel2);overflow:hidden;}
|
| 113 |
+
.out-label{display:flex;align-items:center;justify-content:space-between;padding:.45rem .85rem;
|
| 114 |
+
border-bottom:1px solid var(--gold-line);font-family:var(--mono);font-size:9px;
|
| 115 |
+
letter-spacing:.1em;text-transform:uppercase;color:var(--muted);}
|
| 116 |
+
.out-status{display:inline-flex;align-items:center;gap:.4rem;}
|
| 117 |
+
.status-dot{width:6px;height:6px;border-radius:50%;background:var(--dim);transition:background .3s;}
|
| 118 |
+
.status-dot.ok{background:var(--live);box-shadow:0 0 6px var(--live);}
|
| 119 |
+
.status-dot.err{background:var(--err);box-shadow:0 0 6px var(--err);}
|
| 120 |
+
.status-dot.loading{background:var(--gold);animation:pulseDot 1s ease-in-out infinite;}
|
| 121 |
+
.out-pre{margin:0;padding:.85rem;font-family:var(--mono);font-size:10.5px;line-height:1.6;
|
| 122 |
+
color:var(--paragraph);white-space:pre-wrap;word-break:break-word;max-height:340px;overflow-y:auto;
|
| 123 |
+
scrollbar-width:thin;scrollbar-color:var(--dim) transparent;}
|
| 124 |
+
.out-pre:empty::before{content:"— run this query to read the live Khipu DAG —";color:var(--dim);font-style:italic;}
|
| 125 |
+
/* signed span list */
|
| 126 |
+
.spans{display:flex;flex-direction:column;gap:.4rem;margin-bottom:1rem;}
|
| 127 |
+
.span{display:flex;align-items:center;gap:.6rem;flex-wrap:wrap;font-family:var(--mono);font-size:10.5px;
|
| 128 |
+
padding:.45rem .7rem;border:1px solid var(--gold-line);border-radius:6px;background:var(--panel2);}
|
| 129 |
+
.span .sig{font-size:9px;padding:.05rem .4rem;border-radius:4px;letter-spacing:.06em;text-transform:uppercase;}
|
| 130 |
+
.span .sig.signed{color:var(--live);border:1px solid rgba(90,138,110,.4);background:rgba(90,138,110,.08);}
|
| 131 |
+
.span .sig.unsigned{color:var(--gold);border:1px solid var(--gold-line);background:var(--gold-soft);}
|
| 132 |
+
.span .sname{color:var(--cream);}
|
| 133 |
+
.span .sdigest{color:var(--teal);}
|
| 134 |
+
.span .sts{color:var(--muted);margin-left:auto;}
|
| 135 |
+
/* drift form */
|
| 136 |
+
.axes{display:grid;grid-template-columns:repeat(auto-fit,minmax(180px,1fr));gap:.6rem;margin-bottom:1rem;}
|
| 137 |
+
.axis{border:1px solid var(--gold-line);border-radius:7px;background:var(--panel2);padding:.55rem .7rem;}
|
| 138 |
+
.axis label{display:block;font-family:var(--mono);font-size:9px;letter-spacing:.1em;text-transform:uppercase;color:var(--muted);margin-bottom:.3rem;}
|
| 139 |
+
.axis input[type=range]{width:100%;accent-color:var(--teal);}
|
| 140 |
+
.axis .av{font-family:var(--mono);font-size:11px;color:var(--gold);float:right;}
|
| 141 |
+
.axis.weak{border-color:rgba(176,106,90,.45);background:rgba(176,106,90,.06);}
|
| 142 |
+
.axis.weak label{color:var(--err);}
|
| 143 |
+
.preset-row{display:flex;flex-wrap:wrap;gap:.4rem;margin-bottom:.9rem;}
|
| 144 |
+
.lam-readout{font-family:var(--mono);font-size:13px;color:var(--paragraph);margin:.2rem 0 .9rem;}
|
| 145 |
+
.lam-readout b{font-size:1.4rem;color:var(--gold);}
|
| 146 |
+
.honest{margin:0 auto 2rem;}
|
| 147 |
+
.honest-box{border:1px solid var(--teal-line);border-radius:8px;background:var(--teal-soft);
|
| 148 |
+
padding:.9rem 1.1rem;font-size:12px;color:var(--paragraph);line-height:1.6;}
|
| 149 |
+
.honest-box b{color:var(--teal);}
|
| 150 |
+
.footer{border-top:1px solid var(--gold-line);padding:2rem 1.5rem;text-align:center;margin-top:1rem;}
|
| 151 |
+
.footer .note{font-family:var(--mono);font-size:10px;letter-spacing:.1em;text-transform:uppercase;color:var(--dim);}
|
| 152 |
+
@media (prefers-reduced-motion:reduce){*,*::before,*::after{animation-duration:.01ms !important;animation-iteration-count:1 !important;}}
|
| 153 |
+
</style>
|
| 154 |
+
</head>
|
| 155 |
+
<body>
|
| 156 |
+
|
| 157 |
+
<div class="ribbon">
|
| 158 |
+
<span>SZL HOLDINGS</span><span class="sep">/</span>
|
| 159 |
+
<span class="teal">A11OY</span><span class="sep">/</span>
|
| 160 |
+
<span>AI OBSERVABILITY</span><span class="sep">/</span>
|
| 161 |
+
<span>MELT · SIGNED TRACES</span><span class="sep">/</span>
|
| 162 |
+
<span class="live"><span class="live-dot"></span>LIVE · RT</span>
|
| 163 |
+
<a href="/warhacker">Warhacker →</a>
|
| 164 |
+
</div>
|
| 165 |
+
|
| 166 |
+
<section class="hero">
|
| 167 |
+
<div class="grid-bg" aria-hidden="true"></div>
|
| 168 |
+
<div class="hero-inner">
|
| 169 |
+
<div class="eyebrow">
|
| 170 |
+
<span class="eyebrow-dot"></span>
|
| 171 |
+
<span class="eyebrow-text">· a11oy orchestrates · every span is a signed receipt</span>
|
| 172 |
+
</div>
|
| 173 |
+
<h1 class="headline">Observability, but <span class="accent">cryptographically true.</span></h1>
|
| 174 |
+
<p class="support">New-Relic-style <b>MELT</b> (metrics · events · logs · traces) and distributed tracing —
|
| 175 |
+
except every span is a <b>DSSE-signed, replayable receipt</b> on the Khipu DAG. a11oy collects spans across
|
| 176 |
+
the mesh, then does the thing dashboards can't: it <b>traces an agent's reasoning and flags where it drifts
|
| 177 |
+
from the Λ-gate</b>. The drift verdict is a real geometric computation plus a signed receipt — not an LLM opinion.</p>
|
| 178 |
+
<button class="runall" id="b-refresh" onclick="refreshAll()">⟳ Refresh live MELT + spans</button>
|
| 179 |
+
<div class="stats">
|
| 180 |
+
<div class="stat"><div class="k">DAG depth</div><div class="v" id="st-depth">—</div></div>
|
| 181 |
+
<div class="stat"><div class="k">Signed spans</div><div class="v teal" id="st-spans">—</div></div>
|
| 182 |
+
<div class="stat"><div class="k">Organs reachable</div><div class="v" id="st-reach">—</div></div>
|
| 183 |
+
<div class="stat"><div class="k">Chain verified</div><div class="v teal" id="st-chain">—</div></div>
|
| 184 |
+
</div>
|
| 185 |
+
</div>
|
| 186 |
+
</section>
|
| 187 |
+
|
| 188 |
+
<div class="wrap">
|
| 189 |
+
|
| 190 |
+
<!-- ===================== MELT SUMMARY ===================== -->
|
| 191 |
+
<section class="section">
|
| 192 |
+
<div class="section-head"><h2>MELT rollup</h2><span class="tag">live DAG + health probes</span></div>
|
| 193 |
+
<p class="section-sub">Metrics & traces are read from the live in-process Khipu DAG; mesh reach is probed
|
| 194 |
+
against each organ's <code class="mono">/api/health</code>. An unreachable organ is shown honestly — never faked green.</p>
|
| 195 |
+
<div class="panel">
|
| 196 |
+
<div class="controls">
|
| 197 |
+
<button class="r-btn r-btn-primary" id="b-summary" onclick="loadSummary()">▶ Pull MELT summary</button>
|
| 198 |
+
</div>
|
| 199 |
+
<span class="verdict" id="v-summary"></span>
|
| 200 |
+
<div class="metrics" id="m-summary"></div>
|
| 201 |
+
<div class="reach" id="reach-summary"></div>
|
| 202 |
+
<div class="out"><div class="out-label"><span>OBSERVABILITY / SUMMARY (raw)</span>
|
| 203 |
+
<span class="out-status"><span class="status-dot" id="d-summary"></span><span id="s-summary">idle</span></span></div>
|
| 204 |
+
<pre class="out-pre" id="o-summary"></pre></div>
|
| 205 |
+
</div>
|
| 206 |
+
</section>
|
| 207 |
+
|
| 208 |
+
<!-- ===================== SIGNED SPANS ===================== -->
|
| 209 |
+
<section class="section">
|
| 210 |
+
<div class="section-head"><h2>Signed spans</h2><span class="tag">Khipu DAG tail</span></div>
|
| 211 |
+
<p class="section-sub">Each span is an append-only, hash-chained receipt. The signature is real <b>DSSE (cosign)</b>
|
| 212 |
+
when a key is wired; otherwise it is honestly labelled <b>UNSIGNED — no key present</b>. <code class="mono">chain_verified</code> proves integrity regardless.</p>
|
| 213 |
+
<div class="panel">
|
| 214 |
+
<div class="controls">
|
| 215 |
+
<button class="r-btn r-btn-primary" id="b-spans" onclick="loadSpans()">▶ Read recent signed spans</button>
|
| 216 |
+
</div>
|
| 217 |
+
<span class="verdict" id="v-spans"></span>
|
| 218 |
+
<div class="spans" id="span-list"></div>
|
| 219 |
+
<div class="out"><div class="out-label"><span>OBSERVABILITY / SPANS (raw)</span>
|
| 220 |
+
<span class="out-status"><span class="status-dot" id="d-spans"></span><span id="s-spans">idle</span></span></div>
|
| 221 |
+
<pre class="out-pre" id="o-spans"></pre></div>
|
| 222 |
+
</div>
|
| 223 |
+
</section>
|
| 224 |
+
|
| 225 |
+
<!-- ===================== DISTRIBUTED TRACE ===================== -->
|
| 226 |
+
<section class="section">
|
| 227 |
+
<div class="section-head"><h2>Distributed trace</h2><span class="tag">cross-organ fan-out</span></div>
|
| 228 |
+
<p class="section-sub">a11oy (the root span) fans out to every organ and collects span-bearing receipts. Each
|
| 229 |
+
organ span carries <code class="mono">fabricated:false</code>; unreachable organs are reported, not invented.</p>
|
| 230 |
+
<div class="panel">
|
| 231 |
+
<div class="controls">
|
| 232 |
+
<button class="r-btn r-btn-primary" id="b-trace" onclick="loadTrace()">▶ Run distributed trace</button>
|
| 233 |
+
</div>
|
| 234 |
+
<span class="verdict" id="v-trace"></span>
|
| 235 |
+
<div class="reach" id="reach-trace"></div>
|
| 236 |
+
<div class="out"><div class="out-label"><span>OBSERVABILITY / TRACE (raw)</span>
|
| 237 |
+
<span class="out-status"><span class="status-dot" id="d-trace"></span><span id="s-trace">idle</span></span></div>
|
| 238 |
+
<pre class="out-pre" id="o-trace"></pre></div>
|
| 239 |
+
</div>
|
| 240 |
+
</section>
|
| 241 |
+
|
| 242 |
+
<!-- ===================== Λ-DRIFT (KILLER FEATURE) ===================== -->
|
| 243 |
+
<section class="section">
|
| 244 |
+
<div class="section-head"><h2>Λ-drift detector</h2><span class="tag">the killer feature</span></div>
|
| 245 |
+
<p class="section-sub">Score an agent's reasoning on the 9 canonical axes. a11oy computes the <b>real</b> geometric
|
| 246 |
+
Λ = ∏ xᵢ<sup>wᵢ</sup>. If Λ falls below the floor (0.90), the reasoning has <b>drifted</b> → <b>DENY</b>, and the weak
|
| 247 |
+
axes are cited as the cause. Zero-pinning: any zero positive-weight axis forces Λ=0. The verdict is emitted as a signed receipt.</p>
|
| 248 |
+
<div class="panel">
|
| 249 |
+
<div class="preset-row">
|
| 250 |
+
<button class="r-btn" onclick="preset('clean')">Preset · clean reasoning</button>
|
| 251 |
+
<button class="r-btn" onclick="preset('thin')">Preset · thin provenance (drift)</button>
|
| 252 |
+
<button class="r-btn" onclick="preset('zero')">Preset · zero consent (pinned)</button>
|
| 253 |
+
</div>
|
| 254 |
+
<div class="axes" id="axes"></div>
|
| 255 |
+
<div class="lam-readout">local preview Λ ≈ <b id="lam-preview">—</b>
|
| 256 |
+
<span style="color:var(--muted)">(server computes the authoritative value)</span></div>
|
| 257 |
+
<div class="controls">
|
| 258 |
+
<button class="r-btn r-btn-primary" id="b-drift" onclick="scoreDrift()">▶ Score reasoning vs Λ-gate</button>
|
| 259 |
+
</div>
|
| 260 |
+
<span class="verdict" id="v-drift"></span>
|
| 261 |
+
<div class="receipt" id="rc-drift"></div>
|
| 262 |
+
<div class="out"><div class="out-label"><span>OBSERVABILITY / DRIFT (raw)</span>
|
| 263 |
+
<span class="out-status"><span class="status-dot" id="d-drift"></span><span id="s-drift">idle</span></span></div>
|
| 264 |
+
<pre class="out-pre" id="o-drift"></pre></div>
|
| 265 |
+
</div>
|
| 266 |
+
</section>
|
| 267 |
+
|
| 268 |
+
<div class="honest">
|
| 269 |
+
<div class="honest-box">
|
| 270 |
+
<b>Honesty.</b> Every metric, span, and trace on this page is read from the <b>live in-process Khipu DAG</b>
|
| 271 |
+
and <b>live organ health probes</b> — no synthetic data. A span's signature reads <b>DSSE (cosign)</b> only when
|
| 272 |
+
a key is present; otherwise it is labelled <b>UNSIGNED — no key present</b>. The Λ-drift verdict is a real
|
| 273 |
+
geometric computation, not an LLM judgement. Λ uniqueness is <b>Conjecture 1</b>, not a theorem; proved-formula
|
| 274 |
+
count is <b>5</b>. SLSA <b>L2</b> build-provenance verifies on the 5 organ images (cosign <code>.att</code>), not
|
| 275 |
+
the bundle. No L3 / FedRAMP / Iron Bank / CMMC claims. <b>telemetry</b> (an unauthenticated claim) is distinct
|
| 276 |
+
from a <b>receipt</b> (an attested record).
|
| 277 |
+
</div>
|
| 278 |
+
</div>
|
| 279 |
+
|
| 280 |
+
</div>
|
| 281 |
+
|
| 282 |
+
<footer class="footer">
|
| 283 |
+
<span class="note">a11oy · the orchestrating brain · MELT + signed traces · by SZL Holdings · Counsel-governed</span>
|
| 284 |
+
</footer>
|
| 285 |
+
|
| 286 |
+
<script>
|
| 287 |
+
const API = '/api/a11oy/v1';
|
| 288 |
+
const CANON = ["soundness","calibration","robustness","provenance","consent","reversibility","auditability","linearity","scope_compliance"];
|
| 289 |
+
const FLOOR = 0.90;
|
| 290 |
+
|
| 291 |
+
function fmt(o){return JSON.stringify(o,null,2);}
|
| 292 |
+
function setS(key,state,text){const d=document.getElementById('d-'+key),s=document.getElementById('s-'+key);if(d)d.className='status-dot '+(state||'');if(s)s.textContent=text||state||'idle';}
|
| 293 |
+
function setO(key,text){const o=document.getElementById('o-'+key);if(o)o.textContent=text;}
|
| 294 |
+
function setV(key,cls,text){const v=document.getElementById('v-'+key);if(v){v.className='verdict show '+cls;v.textContent=text;}}
|
| 295 |
+
function setRC(key,text){const r=document.getElementById('rc-'+key);if(r){r.className='receipt show';r.textContent=text;}}
|
| 296 |
+
|
| 297 |
+
function reachHTML(arr){
|
| 298 |
+
return (arr||[]).map(o=>{
|
| 299 |
+
const ok=o.status==='ok';
|
| 300 |
+
const cls=ok?'ok':'bad';
|
| 301 |
+
const lat=(o.latency_ms!=null)?(' · '+o.latency_ms+'ms'):'';
|
| 302 |
+
return `<span class="organ ${cls}"><span class="dot"></span>${o.organ} · ${o.status||'?'}${lat}</span>`;
|
| 303 |
+
}).join('');
|
| 304 |
+
}
|
| 305 |
+
|
| 306 |
+
async function loadSummary(){
|
| 307 |
+
const btn=document.getElementById('b-summary'); if(btn)btn.disabled=true;
|
| 308 |
+
setS('summary','loading','reading DAG + probing organs…'); setO('summary','');
|
| 309 |
+
try{
|
| 310 |
+
const res=await fetch(API+'/observability/summary');
|
| 311 |
+
const j=await res.json();
|
| 312 |
+
const m=j.melt||{}; const met=m.metrics||{}; const ev=m.events||{}; const tr=m.traces||{};
|
| 313 |
+
document.getElementById('m-summary').innerHTML=`
|
| 314 |
+
<div class="metric"><div class="mk">DAG depth</div><div class="mv">${met.dag_depth??'—'}</div></div>
|
| 315 |
+
<div class="metric"><div class="mk">Signed spans</div><div class="mv teal">${ev.signed_spans??'—'}</div></div>
|
| 316 |
+
<div class="metric"><div class="mk">Organs reachable</div><div class="mv">${met.organs_reachable??'—'} / ${met.organs_total??'—'}</div></div>
|
| 317 |
+
<div class="metric"><div class="mk">Chain verified</div><div class="mv teal">${tr.chain_verified===true?'YES':(tr.chain_verified===false?'NO':'—')}</div></div>`;
|
| 318 |
+
document.getElementById('reach-summary').innerHTML=reachHTML(j.mesh_reach);
|
| 319 |
+
// hero stats
|
| 320 |
+
document.getElementById('st-depth').textContent=met.dag_depth??'—';
|
| 321 |
+
document.getElementById('st-spans').textContent=ev.signed_spans??'—';
|
| 322 |
+
document.getElementById('st-reach').textContent=(met.organs_reachable??'—')+' / '+(met.organs_total??'—');
|
| 323 |
+
document.getElementById('st-chain').textContent=tr.chain_verified===true?'YES':(tr.chain_verified===false?'NO':'—');
|
| 324 |
+
setV('summary','ok','MELT live · '+(met.organs_reachable??0)+'/'+(met.organs_total??0)+' organs reachable · DAG depth '+(met.dag_depth??0));
|
| 325 |
+
setS('summary','ok','live ✓');
|
| 326 |
+
setO('summary',fmt(j));
|
| 327 |
+
}catch(e){ setS('summary','err','error'); setV('summary','err','ERROR'); setO('summary',String(e)); }
|
| 328 |
+
finally{ if(btn)btn.disabled=false; }
|
| 329 |
+
}
|
| 330 |
+
|
| 331 |
+
async function loadSpans(){
|
| 332 |
+
const btn=document.getElementById('b-spans'); if(btn)btn.disabled=true;
|
| 333 |
+
setS('spans','loading','reading DAG tail…'); setO('spans','');
|
| 334 |
+
try{
|
| 335 |
+
const res=await fetch(API+'/observability/spans?limit=25');
|
| 336 |
+
const j=await res.json();
|
| 337 |
+
const spans=j.spans||[];
|
| 338 |
+
if(!j.available){
|
| 339 |
+
setV('spans','warn','DAG unavailable — '+(j.reason||'honest empty'));
|
| 340 |
+
document.getElementById('span-list').innerHTML='';
|
| 341 |
+
}else if(spans.length===0){
|
| 342 |
+
setV('spans','warn','0 spans yet — DAG present, depth '+(j.depth??0)+' (honest, not faked)');
|
| 343 |
+
document.getElementById('span-list').innerHTML='';
|
| 344 |
+
}else{
|
| 345 |
+
setV('spans','ok',spans.length+' signed span(s) · depth '+(j.depth??'?')+' · chain '+(j.chain&&j.chain.ok?'verified ✓':'?'));
|
| 346 |
+
document.getElementById('span-list').innerHTML=spans.map(s=>{
|
| 347 |
+
const signed=!!s.signed;
|
| 348 |
+
const sig=signed?'<span class="sig signed">DSSE signed</span>':'<span class="sig unsigned">unsigned · no key</span>';
|
| 349 |
+
const dg=(s.digest||s.span_id||'').slice(0,16);
|
| 350 |
+
return `<div class="span">${sig}<span class="sname">${s.name||'receipt'}</span>
|
| 351 |
+
<span class="sdigest">${dg}…</span><span class="sts">${s.ts||''}</span></div>`;
|
| 352 |
+
}).join('');
|
| 353 |
+
}
|
| 354 |
+
setS('spans','ok','live ✓ · backend: '+(j.backend||'?'));
|
| 355 |
+
setO('spans',fmt(j));
|
| 356 |
+
}catch(e){ setS('spans','err','error'); setV('spans','err','ERROR'); setO('spans',String(e)); }
|
| 357 |
+
finally{ if(btn)btn.disabled=false; }
|
| 358 |
+
}
|
| 359 |
+
|
| 360 |
+
async function loadTrace(){
|
| 361 |
+
const btn=document.getElementById('b-trace'); if(btn)btn.disabled=true;
|
| 362 |
+
setS('trace','loading','fanning out to mesh…'); setO('trace','');
|
| 363 |
+
try{
|
| 364 |
+
const res=await fetch(API+'/observability/trace');
|
| 365 |
+
const j=await res.json();
|
| 366 |
+
const spans=j.organ_spans||[];
|
| 367 |
+
const reachable=spans.filter(s=>s.status==='ok').length;
|
| 368 |
+
document.getElementById('reach-trace').innerHTML=reachHTML(spans);
|
| 369 |
+
setV('trace','ok','trace '+(j.trace_id||'')+' · '+reachable+'/'+spans.length+' organs · '+(j.total_latency_ms??'?')+'ms');
|
| 370 |
+
setS('trace','ok','live ✓');
|
| 371 |
+
setO('trace',fmt(j));
|
| 372 |
+
}catch(e){ setS('trace','err','error'); setV('trace','err','ERROR'); setO('trace',String(e)); }
|
| 373 |
+
finally{ if(btn)btn.disabled=false; }
|
| 374 |
+
}
|
| 375 |
+
|
| 376 |
+
// ---- Λ-drift form ----
|
| 377 |
+
function buildAxes(){
|
| 378 |
+
const root=document.getElementById('axes'); root.innerHTML='';
|
| 379 |
+
CANON.forEach(a=>{
|
| 380 |
+
const div=document.createElement('div'); div.className='axis'; div.id='ax-'+a;
|
| 381 |
+
div.innerHTML=`<label>${a.replace(/_/g,' ')}<span class="av" id="av-${a}">1.00</span></label>
|
| 382 |
+
<input type="range" min="0" max="1" step="0.01" value="1" id="in-${a}" oninput="onAxis()">`;
|
| 383 |
+
root.appendChild(div);
|
| 384 |
+
});
|
| 385 |
+
onAxis();
|
| 386 |
+
}
|
| 387 |
+
function axesValues(){
|
| 388 |
+
const o={}; CANON.forEach(a=>{o[a]=parseFloat(document.getElementById('in-'+a).value);}); return o;
|
| 389 |
+
}
|
| 390 |
+
function localLambda(ax){
|
| 391 |
+
// mirror of server geometric mean (preview only — server is authoritative)
|
| 392 |
+
const wi=1/CANON.length; let logsum=0, zero=false;
|
| 393 |
+
CANON.forEach(a=>{const xi=Math.max(0,Math.min(1,ax[a]??0)); if(xi<=0){zero=true;logsum=-Infinity;} else if(xi<1){logsum+=wi*Math.log(xi);}});
|
| 394 |
+
return zero?0:(logsum>-Infinity?Math.exp(logsum):0);
|
| 395 |
+
}
|
| 396 |
+
function onAxis(){
|
| 397 |
+
const ax=axesValues();
|
| 398 |
+
CANON.forEach(a=>{
|
| 399 |
+
document.getElementById('av-'+a).textContent=ax[a].toFixed(2);
|
| 400 |
+
document.getElementById('ax-'+a).classList.toggle('weak',ax[a]<FLOOR);
|
| 401 |
+
});
|
| 402 |
+
const lam=localLambda(ax);
|
| 403 |
+
const el=document.getElementById('lam-preview');
|
| 404 |
+
el.textContent=lam.toFixed(4);
|
| 405 |
+
el.style.color=(lam<FLOOR)?'var(--err)':'var(--gold)';
|
| 406 |
+
}
|
| 407 |
+
function preset(kind){
|
| 408 |
+
const set=(o)=>{CANON.forEach(a=>{document.getElementById('in-'+a).value=(a in o)?o[a]:1;}); onAxis();};
|
| 409 |
+
if(kind==='clean') set({});
|
| 410 |
+
if(kind==='thin') set({provenance:0.2,auditability:0.55});
|
| 411 |
+
if(kind==='zero') set({consent:0});
|
| 412 |
+
}
|
| 413 |
+
async function scoreDrift(){
|
| 414 |
+
const btn=document.getElementById('b-drift'); if(btn)btn.disabled=true;
|
| 415 |
+
setS('drift','loading','computing Λ + signing receipt…'); setO('drift','');
|
| 416 |
+
const ax=axesValues();
|
| 417 |
+
const claim={clean:'agent reasoning across all axes',thin:'agent asserted X with thin provenance',zero:'action without consent'};
|
| 418 |
+
try{
|
| 419 |
+
const res=await fetch(API+'/observability/drift',{method:'POST',headers:{'Content-Type':'application/json'},
|
| 420 |
+
body:JSON.stringify({axes:ax,lambda_floor:FLOOR,claim:'observability page drift check'})});
|
| 421 |
+
const j=await res.json();
|
| 422 |
+
if(j.drift_detected){
|
| 423 |
+
const cause=(j.drift_cause||[]).map(c=>c.axis+'='+c.score).join(', ');
|
| 424 |
+
setV('drift','err','Λ='+j.lambda+' < '+j.lambda_floor+' · DRIFT → DENY · cause: '+(cause||'zero-pinned'));
|
| 425 |
+
}else{
|
| 426 |
+
setV('drift','ok','Λ='+j.lambda+' ≥ '+j.lambda_floor+' · within gate → ALLOW');
|
| 427 |
+
}
|
| 428 |
+
const rc=j.a11oy_receipt||{};
|
| 429 |
+
if(rc.digest) setRC('drift','a11oy receipt '+String(rc.digest).slice(0,16)+'… · '+(rc.signed?'SIGNED':'UNSIGNED (no key)'));
|
| 430 |
+
setS('drift','ok','live ✓ · real geometric Λ');
|
| 431 |
+
setO('drift',fmt(j));
|
| 432 |
+
}catch(e){ setS('drift','err','error'); setV('drift','err','ERROR'); setO('drift',String(e)); }
|
| 433 |
+
finally{ if(btn)btn.disabled=false; }
|
| 434 |
+
}
|
| 435 |
+
|
| 436 |
+
async function refreshAll(){
|
| 437 |
+
const b=document.getElementById('b-refresh'); b.disabled=true;
|
| 438 |
+
await loadSummary();
|
| 439 |
+
await loadSpans();
|
| 440 |
+
b.disabled=false;
|
| 441 |
+
}
|
| 442 |
+
|
| 443 |
+
// init: build the Λ form and pull the live MELT summary once.
|
| 444 |
+
(function init(){
|
| 445 |
+
buildAxes();
|
| 446 |
+
loadSummary();
|
| 447 |
+
})();
|
| 448 |
+
</script>
|
| 449 |
+
|
| 450 |
+
</body>
|
| 451 |
+
</html>
|
pages/warhacker.html
ADDED
|
@@ -0,0 +1,286 @@
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| 1 |
+
<!DOCTYPE html>
|
| 2 |
+
<html lang="en">
|
| 3 |
+
<head>
|
| 4 |
+
<meta charset="UTF-8"/>
|
| 5 |
+
<meta name="viewport" content="width=device-width, initial-scale=1.0"/>
|
| 6 |
+
<title>a11oy — Warhacker Orchestration · SZL Holdings</title>
|
| 7 |
+
<meta name="description" content="a11oy is the single launch point for the 5 approved Warhacker demos. Each button calls the live organ endpoint and renders the real result + a signed receipt."/>
|
| 8 |
+
<link rel="preconnect" href="https://fonts.googleapis.com"/>
|
| 9 |
+
<link rel="preconnect" href="https://fonts.gstatic.com" crossorigin/>
|
| 10 |
+
<link href="https://fonts.googleapis.com/css2?family=Space+Grotesk:wght@300;400;500;600;700&family=JetBrains+Mono:wght@400;500&display=swap" rel="stylesheet"/>
|
| 11 |
+
<style>
|
| 12 |
+
/* a11oy house style — dark-constellation + gold/teal ribbon (matches /superpowers) */
|
| 13 |
+
:root{
|
| 14 |
+
--ground:#0a0a0a; --panel:#0c0c0c; --panel2:#070707;
|
| 15 |
+
--gold:#c9b787; --gold-bright:#d6c69a;
|
| 16 |
+
--teal:#5fb3a3; --teal-soft:rgba(95,179,163,0.10);
|
| 17 |
+
--cream:#f5f5f5; --paragraph:#9a9a9a; --muted:#888; --dim:#555;
|
| 18 |
+
--gold-line:rgba(201,183,135,0.15); --gold-soft:rgba(201,183,135,0.04);
|
| 19 |
+
--teal-line:rgba(95,179,163,0.22);
|
| 20 |
+
--live:#5a8a6e; --err:#b06a5a;
|
| 21 |
+
--mono:'JetBrains Mono',ui-monospace,SFMono-Regular,monospace;
|
| 22 |
+
--display:'Space Grotesk',Georgia,serif;
|
| 23 |
+
}
|
| 24 |
+
*{box-sizing:border-box;}
|
| 25 |
+
html,body{margin:0;padding:0;background:var(--ground);color:var(--cream);
|
| 26 |
+
font-family:var(--display);-webkit-font-smoothing:antialiased;text-rendering:optimizeLegibility;}
|
| 27 |
+
.mono{font-family:var(--mono);}
|
| 28 |
+
a{color:inherit;}
|
| 29 |
+
:focus-visible{outline:2px solid var(--gold);outline-offset:3px;border-radius:3px;}
|
| 30 |
+
.ribbon{position:sticky;top:0;z-index:50;display:flex;align-items:center;gap:1.25rem;
|
| 31 |
+
flex-wrap:wrap;padding:0.5rem 1.25rem;font-family:var(--mono);font-size:10px;
|
| 32 |
+
letter-spacing:0.12em;text-transform:uppercase;color:var(--gold);
|
| 33 |
+
background:rgba(10,10,10,0.85);backdrop-filter:blur(10px);
|
| 34 |
+
border-bottom:1px solid var(--gold-line);}
|
| 35 |
+
.ribbon .sep{color:var(--dim);}
|
| 36 |
+
.ribbon .teal{color:var(--teal);}
|
| 37 |
+
.ribbon .live{display:inline-flex;align-items:center;gap:0.4rem;color:var(--cream);}
|
| 38 |
+
.ribbon a{margin-left:auto;color:var(--muted);text-decoration:none;}
|
| 39 |
+
.ribbon a:hover{color:var(--gold);}
|
| 40 |
+
.live-dot{width:6px;height:6px;border-radius:50%;background:var(--live);
|
| 41 |
+
box-shadow:0 0 6px var(--live);animation:pulseDot 2.2s ease-in-out infinite;}
|
| 42 |
+
@keyframes pulseDot{0%,100%{opacity:1;}50%{opacity:.35;}}
|
| 43 |
+
.hero{position:relative;overflow:hidden;padding:3.5rem 1.5rem 2.5rem;text-align:center;}
|
| 44 |
+
.grid-bg{position:absolute;inset:0;pointer-events:none;
|
| 45 |
+
background-image:
|
| 46 |
+
linear-gradient(rgba(255,255,255,.025) 1px,transparent 1px),
|
| 47 |
+
linear-gradient(90deg,rgba(255,255,255,.025) 1px,transparent 1px);
|
| 48 |
+
background-size:56px 56px;
|
| 49 |
+
-webkit-mask-image:radial-gradient(ellipse at center,#000 30%,transparent 75%);
|
| 50 |
+
mask-image:radial-gradient(ellipse at center,#000 30%,transparent 75%);}
|
| 51 |
+
.hero-inner{position:relative;z-index:2;max-width:64rem;margin:0 auto;}
|
| 52 |
+
.eyebrow{display:inline-flex;align-items:center;gap:.5rem;padding:.3rem .85rem;
|
| 53 |
+
border-radius:999px;border:1px solid var(--gold-line);background:var(--gold-soft);margin-bottom:1.75rem;}
|
| 54 |
+
.eyebrow-dot{width:6px;height:6px;border-radius:50%;background:var(--gold);
|
| 55 |
+
animation:pulseDot 2.2s ease-in-out infinite;}
|
| 56 |
+
.eyebrow-text{font-family:var(--mono);font-size:10px;letter-spacing:.2em;text-transform:uppercase;color:var(--gold);}
|
| 57 |
+
.headline{font-size:clamp(2.4rem,5.5vw,4.4rem);font-weight:300;line-height:1.03;
|
| 58 |
+
letter-spacing:-.035em;margin:0 0 1.25rem;color:var(--cream);}
|
| 59 |
+
.headline .accent{background:linear-gradient(120deg,var(--cream) 20%,var(--gold) 90%);
|
| 60 |
+
-webkit-background-clip:text;background-clip:text;-webkit-text-fill-color:transparent;color:transparent;}
|
| 61 |
+
.support{font-size:16px;line-height:1.65;color:var(--paragraph);max-width:44rem;margin:0 auto 2rem;}
|
| 62 |
+
.runall{display:inline-flex;align-items:center;gap:.5rem;padding:.7rem 1.5rem;font-size:12.5px;
|
| 63 |
+
font-weight:500;font-family:var(--mono);border-radius:8px;border:1px solid var(--gold);
|
| 64 |
+
background:var(--gold);color:var(--ground);cursor:pointer;letter-spacing:.06em;margin-top:.5rem;}
|
| 65 |
+
.runall:hover{background:var(--gold-bright);}
|
| 66 |
+
.runall:disabled{opacity:.5;cursor:not-allowed;}
|
| 67 |
+
.stats{display:flex;flex-wrap:wrap;justify-content:center;gap:.75rem;max-width:60rem;margin:2rem auto 0;}
|
| 68 |
+
.stat{flex:1 1 150px;min-width:140px;border:1px solid var(--gold-line);border-radius:8px;
|
| 69 |
+
background:var(--panel);padding:.9rem 1rem;text-align:left;}
|
| 70 |
+
.stat .k{font-family:var(--mono);font-size:9px;letter-spacing:.16em;text-transform:uppercase;color:var(--muted);}
|
| 71 |
+
.stat .v{font-size:1.35rem;font-weight:500;color:var(--gold);margin-top:.25rem;}
|
| 72 |
+
.stat .v.teal{color:var(--teal);}
|
| 73 |
+
.grid{max-width:64rem;margin:2.75rem auto 4rem;padding:0 1.25rem;
|
| 74 |
+
display:grid;grid-template-columns:repeat(auto-fit,minmax(320px,1fr));gap:1.25rem;}
|
| 75 |
+
.card{border:1px solid var(--gold-line);border-radius:12px;background:var(--panel);
|
| 76 |
+
padding:1.4rem 1.4rem 1.6rem;display:flex;flex-direction:column;}
|
| 77 |
+
.card-head{display:flex;align-items:baseline;gap:.6rem;margin-bottom:.5rem;flex-wrap:wrap;}
|
| 78 |
+
.card-num{font-family:var(--mono);font-size:11px;color:var(--teal);border:1px solid var(--teal-line);
|
| 79 |
+
border-radius:5px;padding:.1rem .4rem;background:var(--teal-soft);}
|
| 80 |
+
.card-organ{font-family:var(--mono);font-size:10px;color:var(--gold);border:1px solid var(--gold-line);
|
| 81 |
+
border-radius:5px;padding:.1rem .4rem;background:var(--gold-soft);text-transform:uppercase;letter-spacing:.08em;}
|
| 82 |
+
.card-title{font-size:1.1rem;font-weight:500;color:var(--cream);letter-spacing:-.01em;}
|
| 83 |
+
.card-sub{font-size:12.5px;color:var(--paragraph);line-height:1.6;margin:0 0 1rem;}
|
| 84 |
+
.card-endpoint{font-family:var(--mono);font-size:10px;color:var(--muted);margin-bottom:1rem;word-break:break-all;}
|
| 85 |
+
.card-endpoint b{color:var(--gold);font-weight:500;}
|
| 86 |
+
.card-controls{display:flex;flex-wrap:wrap;gap:.5rem;margin-bottom:1rem;}
|
| 87 |
+
.r-btn{display:inline-flex;align-items:center;gap:.4rem;padding:.5rem 1rem;font-size:11.5px;
|
| 88 |
+
font-weight:500;font-family:var(--mono);border-radius:6px;border:1px solid var(--gold-line);
|
| 89 |
+
background:transparent;color:var(--gold);cursor:pointer;letter-spacing:.04em;
|
| 90 |
+
transition:background .18s ease,border-color .18s ease;}
|
| 91 |
+
.r-btn:hover{background:rgba(201,183,135,.08);border-color:rgba(201,183,135,.35);}
|
| 92 |
+
.r-btn:active{opacity:.75;}
|
| 93 |
+
.r-btn:disabled{opacity:.4;cursor:not-allowed;}
|
| 94 |
+
.r-btn-primary{background:var(--gold);color:var(--ground);border-color:var(--gold);}
|
| 95 |
+
.r-btn-primary:hover{background:var(--gold-bright);border-color:var(--gold-bright);}
|
| 96 |
+
.verdict{display:inline-flex;align-items:center;gap:.4rem;font-family:var(--mono);font-size:11px;
|
| 97 |
+
padding:.2rem .6rem;border-radius:5px;margin-bottom:.6rem;visibility:hidden;}
|
| 98 |
+
.verdict.show{visibility:visible;}
|
| 99 |
+
.verdict.ok{color:var(--live);border:1px solid rgba(90,138,110,.4);background:rgba(90,138,110,.08);}
|
| 100 |
+
.verdict.warn{color:var(--gold);border:1px solid var(--gold-line);background:var(--gold-soft);}
|
| 101 |
+
.verdict.err{color:var(--err);border:1px solid rgba(176,106,90,.4);background:rgba(176,106,90,.08);}
|
| 102 |
+
.receipt{font-family:var(--mono);font-size:10px;color:var(--teal);margin:-.2rem 0 .6rem;visibility:hidden;}
|
| 103 |
+
.receipt.show{visibility:visible;}
|
| 104 |
+
.out{position:relative;border:1px solid var(--gold-line);border-radius:8px;background:var(--panel2);
|
| 105 |
+
overflow:hidden;margin-top:auto;}
|
| 106 |
+
.out-label{display:flex;align-items:center;justify-content:space-between;padding:.45rem .85rem;
|
| 107 |
+
border-bottom:1px solid var(--gold-line);font-family:var(--mono);font-size:9px;
|
| 108 |
+
letter-spacing:.1em;text-transform:uppercase;color:var(--muted);}
|
| 109 |
+
.out-status{display:inline-flex;align-items:center;gap:.4rem;}
|
| 110 |
+
.status-dot{width:6px;height:6px;border-radius:50%;background:var(--dim);transition:background .3s;}
|
| 111 |
+
.status-dot.ok{background:var(--live);box-shadow:0 0 6px var(--live);}
|
| 112 |
+
.status-dot.err{background:var(--err);box-shadow:0 0 6px var(--err);}
|
| 113 |
+
.status-dot.loading{background:var(--gold);animation:pulseDot 1s ease-in-out infinite;}
|
| 114 |
+
.out-pre{margin:0;padding:.85rem;font-family:var(--mono);font-size:10.5px;line-height:1.6;
|
| 115 |
+
color:var(--paragraph);white-space:pre-wrap;word-break:break-word;max-height:300px;overflow-y:auto;
|
| 116 |
+
scrollbar-width:thin;scrollbar-color:var(--dim) transparent;}
|
| 117 |
+
.out-pre:empty::before{content:"— launch this demo to call the live organ —";color:var(--dim);font-style:italic;}
|
| 118 |
+
.footer{border-top:1px solid var(--gold-line);padding:2rem 1.5rem;text-align:center;}
|
| 119 |
+
.footer .note{font-family:var(--mono);font-size:10px;letter-spacing:.1em;text-transform:uppercase;color:var(--dim);}
|
| 120 |
+
.honest{max-width:64rem;margin:0 auto 2rem;padding:0 1.25rem;}
|
| 121 |
+
.honest-box{border:1px solid var(--teal-line);border-radius:8px;background:var(--teal-soft);
|
| 122 |
+
padding:.9rem 1.1rem;font-size:12px;color:var(--paragraph);line-height:1.6;}
|
| 123 |
+
.honest-box b{color:var(--teal);}
|
| 124 |
+
@media (prefers-reduced-motion:reduce){*,*::before,*::after{animation-duration:.01ms !important;animation-iteration-count:1 !important;}}
|
| 125 |
+
</style>
|
| 126 |
+
</head>
|
| 127 |
+
<body>
|
| 128 |
+
|
| 129 |
+
<div class="ribbon">
|
| 130 |
+
<span>SZL HOLDINGS</span><span class="sep">/</span>
|
| 131 |
+
<span class="teal">A11OY</span><span class="sep">/</span>
|
| 132 |
+
<span>WARHACKER ORCHESTRATION</span><span class="sep">/</span>
|
| 133 |
+
<span>DOCTRINE V11 · LOCKED</span><span class="sep">/</span>
|
| 134 |
+
<span class="live"><span class="live-dot"></span>LIVE · RT</span>
|
| 135 |
+
<a href="/observability">Observability →</a>
|
| 136 |
+
</div>
|
| 137 |
+
|
| 138 |
+
<section class="hero">
|
| 139 |
+
<div class="grid-bg" aria-hidden="true"></div>
|
| 140 |
+
<div class="hero-inner">
|
| 141 |
+
<div class="eyebrow">
|
| 142 |
+
<span class="eyebrow-dot"></span>
|
| 143 |
+
<span class="eyebrow-text">· a11oy orchestrates · five live organ proofs</span>
|
| 144 |
+
</div>
|
| 145 |
+
<h1 class="headline">Five Warhacker problems. One <span class="accent">launch point.</span></h1>
|
| 146 |
+
<p class="support">a11oy is the orchestrating brain. Each launch below calls the <b>live organ endpoint</b>
|
| 147 |
+
server-side — killinchu, sentra, amaru, a11oy — renders the organ's <b>real JSON</b>, and records an
|
| 148 |
+
a11oy Khipu receipt of the orchestration. No mock data; an unreachable organ is shown honestly.</p>
|
| 149 |
+
<button class="runall" id="b-all" onclick="runAll()">▶ Launch all 5 demos</button>
|
| 150 |
+
<div class="stats">
|
| 151 |
+
<div class="stat"><div class="k">Approved problems</div><div class="v">5</div></div>
|
| 152 |
+
<div class="stat"><div class="k">Live organs</div><div class="v">4</div></div>
|
| 153 |
+
<div class="stat"><div class="k">Λ status</div><div class="v teal">Conjecture 1</div></div>
|
| 154 |
+
<div class="stat"><div class="k">SLSA</div><div class="v teal">L2 · organ images</div></div>
|
| 155 |
+
</div>
|
| 156 |
+
</div>
|
| 157 |
+
</section>
|
| 158 |
+
|
| 159 |
+
<div class="grid" id="cards"></div>
|
| 160 |
+
|
| 161 |
+
<div class="honest">
|
| 162 |
+
<div class="honest-box">
|
| 163 |
+
<b>Honesty.</b> Each card's RESULT panel is the <b>live organ's real response</b> — fetched
|
| 164 |
+
server-side by a11oy. <b>telemetry</b> (an unauthenticated claim) is distinct from a <b>receipt</b>
|
| 165 |
+
(an attested record); the a11oy receipt line shows whether the orchestration receipt is signed
|
| 166 |
+
(a key is present) or <b>UNSIGNED</b>. Λ is <b>Conjecture 1</b>, not a theorem; proved-formula count
|
| 167 |
+
is <b>5</b>. SLSA <b>L2</b> build-provenance verifies on the 5 organ images (cosign <code>.att</code>),
|
| 168 |
+
not the bundle. No L3 / FedRAMP / Iron Bank / CMMC claims. Organs unreachable from the browser are
|
| 169 |
+
reported as such — never faked green.
|
| 170 |
+
</div>
|
| 171 |
+
</div>
|
| 172 |
+
|
| 173 |
+
<footer class="footer">
|
| 174 |
+
<span class="note">a11oy · the orchestrating brain · by SZL Holdings · Counsel-governed</span>
|
| 175 |
+
</footer>
|
| 176 |
+
|
| 177 |
+
<script>
|
| 178 |
+
const API = '/api/a11oy/v1';
|
| 179 |
+
|
| 180 |
+
// Static fallback catalog (mirrors the backend WARHACKER_PROBLEMS). The page
|
| 181 |
+
// also fetches /warhacker/index at load and prefers the live catalog.
|
| 182 |
+
const PROBLEMS = [
|
| 183 |
+
{id:'P1',key:'cannonico',title:'Cannonico — AI-drone oversight',organ:'killinchu',
|
| 184 |
+
method:'POST',path:'/api/killinchu/v1/cannonico/mission/begin',
|
| 185 |
+
proves:'Begins a governed oversight mission; killinchu returns a DSSE-signed anchor receipt. Engage decisions are gated; an envelope breach is BREACH-flagged + signed.'},
|
| 186 |
+
{id:'P2',key:'tychee',title:'Tychee — satellite GSW air-gap',organ:'sentra',
|
| 187 |
+
method:'GET',path:'/api/sentra/v1/gates',
|
| 188 |
+
proves:"sentra's deny-by-default immune gates (signature-scan, intrusion, supply-chain). Every action is matched against the gate corpus before it is allowed."},
|
| 189 |
+
{id:'P3',key:'hangar2apps',title:'HANGAR2APPS — readiness screening',organ:'amaru',
|
| 190 |
+
method:'POST',path:'/api/amaru/v1/readiness/assess',
|
| 191 |
+
proves:'amaru returns a cited DEPLOYABLE/NOT_DEPLOYABLE/NEEDS_REVIEW verdict; every PASS cites the exact record. Missing data forces NEEDS_REVIEW — it refuses to fabricate.'},
|
| 192 |
+
{id:'P4',key:'cyber-rts',title:'Cyber RTS — trajectory triage',organ:'amaru',
|
| 193 |
+
method:'POST',path:'/api/amaru/v1/trajectory/triage',
|
| 194 |
+
proves:'amaru contextualizes a track and flags anomalies (NOMINAL/ANOMALOUS); each flag cites its numeric field + the violated envelope. Absent fields force INSUFFICIENT_EVIDENCE.'},
|
| 195 |
+
{id:'P5',key:'raven',title:'Raven Tactical — edge AI mesh',organ:'a11oy',
|
| 196 |
+
method:'GET',path:'/api/a11oy/v1/mesh/state',
|
| 197 |
+
proves:"a11oy's conserved signed mesh (wires D/E/F): the one-signed-organism state tying the edge organs together. Every wire is live in-process; the mesh is conservation-checked."},
|
| 198 |
+
];
|
| 199 |
+
|
| 200 |
+
function el(tag,cls,html){const e=document.createElement(tag);if(cls)e.className=cls;if(html!=null)e.innerHTML=html;return e;}
|
| 201 |
+
function fmt(o){return JSON.stringify(o,null,2);}
|
| 202 |
+
|
| 203 |
+
function buildCards(list){
|
| 204 |
+
const root=document.getElementById('cards'); root.innerHTML='';
|
| 205 |
+
list.forEach(p=>{
|
| 206 |
+
const card=el('div','card');
|
| 207 |
+
card.innerHTML=`
|
| 208 |
+
<div class="card-head">
|
| 209 |
+
<span class="card-num">${p.id}</span>
|
| 210 |
+
<span class="card-organ">${p.organ}</span>
|
| 211 |
+
<span class="card-title">${p.title}</span>
|
| 212 |
+
</div>
|
| 213 |
+
<p class="card-sub">${p.proves}</p>
|
| 214 |
+
<p class="card-endpoint">${p.method} <b>${p.path}</b> · via a11oy <b>/warhacker/launch/${p.key}</b></p>
|
| 215 |
+
<div class="card-controls">
|
| 216 |
+
<button class="r-btn r-btn-primary" id="b-${p.key}">▶ Launch demo</button>
|
| 217 |
+
</div>
|
| 218 |
+
<span class="verdict" id="v-${p.key}"></span>
|
| 219 |
+
<div class="receipt" id="rc-${p.key}"></div>
|
| 220 |
+
<div class="out"><div class="out-label"><span>LIVE ORGAN RESULT</span>
|
| 221 |
+
<span class="out-status"><span class="status-dot" id="d-${p.key}"></span><span id="s-${p.key}">idle</span></span></div>
|
| 222 |
+
<pre class="out-pre" id="o-${p.key}"></pre></div>`;
|
| 223 |
+
root.appendChild(card);
|
| 224 |
+
card.querySelector('#b-'+p.key).addEventListener('click',()=>launch(p.key));
|
| 225 |
+
});
|
| 226 |
+
}
|
| 227 |
+
|
| 228 |
+
function setS(key,state,text){const d=document.getElementById('d-'+key),s=document.getElementById('s-'+key);if(d)d.className='status-dot '+(state||'');if(s)s.textContent=text||state||'idle';}
|
| 229 |
+
function setO(key,text){const o=document.getElementById('o-'+key);if(o)o.textContent=text;}
|
| 230 |
+
function setV(key,cls,text){const v=document.getElementById('v-'+key);if(v){v.className='verdict show '+cls;v.textContent=text;}}
|
| 231 |
+
function setRC(key,text){const r=document.getElementById('rc-'+key);if(r){r.className='receipt show';r.textContent=text;}}
|
| 232 |
+
|
| 233 |
+
function organVerdict(key,j){
|
| 234 |
+
// Pull the human headline out of each organ's real response shape.
|
| 235 |
+
try{
|
| 236 |
+
if(key==='cannonico') return 'mission '+(j.mission_id||'?')+' · anchor receipt signed='+!!(j.anchor_receipt&&j.anchor_receipt.dsse&&j.anchor_receipt.dsse.signatures);
|
| 237 |
+
if(key==='tychee') return (j.total||(j.gates||[]).length)+' immune gates · deny-by-default';
|
| 238 |
+
if(key==='hangar2apps') return 'VERDICT '+((j.assessment||{}).verdict||'?')+' · cited';
|
| 239 |
+
if(key==='cyber-rts') return 'VERDICT '+((j.triage||{}).verdict||'?')+' · '+(((j.triage||{}).flags||[]).length)+' flag(s)';
|
| 240 |
+
if(key==='raven') return Object.keys(j.wires||{}).length+' wires · doctrine '+(j.doctrine||'v11');
|
| 241 |
+
}catch(e){}
|
| 242 |
+
return 'organ responded';
|
| 243 |
+
}
|
| 244 |
+
|
| 245 |
+
async function launch(key){
|
| 246 |
+
const btn=document.getElementById('b-'+key); if(btn)btn.disabled=true;
|
| 247 |
+
setS(key,'loading','calling organ…'); setO(key,'');
|
| 248 |
+
try{
|
| 249 |
+
const res=await fetch(API+'/warhacker/launch/'+key,{method:'POST',headers:{'Content-Type':'application/json'},body:'{}'});
|
| 250 |
+
let data; try{data=await res.json();}catch(e){data={_raw:await res.text()};}
|
| 251 |
+
const org=data.organ_response||{};
|
| 252 |
+
if(org.status==='ok'){
|
| 253 |
+
setV(key,'ok',organVerdict(key,org.json||{}));
|
| 254 |
+
setS(key,'ok','live ✓ ('+org.latency_ms+'ms)');
|
| 255 |
+
}else if(org.status==='unreachable'){
|
| 256 |
+
setV(key,'warn','ORGAN UNREACHABLE — honest, not faked');
|
| 257 |
+
setS(key,'err','unreachable');
|
| 258 |
+
}else{
|
| 259 |
+
setV(key,'err','ORGAN ERROR '+(org.http_code||''));
|
| 260 |
+
setS(key,'err','error');
|
| 261 |
+
}
|
| 262 |
+
const rc=data.a11oy_receipt||{};
|
| 263 |
+
if(rc.digest) setRC(key,'a11oy receipt '+String(rc.digest).slice(0,16)+'… · '+(rc.signed?'SIGNED':'UNSIGNED (no key)'));
|
| 264 |
+
setO(key,fmt(data));
|
| 265 |
+
}catch(e){ setS(key,'err','error'); setV(key,'err','ERROR'); setO(key,String(e)); }
|
| 266 |
+
finally{ if(btn)btn.disabled=false; }
|
| 267 |
+
}
|
| 268 |
+
|
| 269 |
+
async function runAll(){
|
| 270 |
+
const b=document.getElementById('b-all'); b.disabled=true;
|
| 271 |
+
for(const p of PROBLEMS){ await launch(p.key); }
|
| 272 |
+
b.disabled=false;
|
| 273 |
+
}
|
| 274 |
+
|
| 275 |
+
// Prefer the live backend catalog; fall back to the static list.
|
| 276 |
+
(async function init(){
|
| 277 |
+
buildCards(PROBLEMS);
|
| 278 |
+
try{
|
| 279 |
+
const r=await fetch(API+'/warhacker/index');
|
| 280 |
+
if(r.ok){ const j=await r.json(); if(j.problems&&j.problems.length){ buildCards(j.problems); } }
|
| 281 |
+
}catch(e){/* static catalog already rendered */}
|
| 282 |
+
})();
|
| 283 |
+
</script>
|
| 284 |
+
|
| 285 |
+
</body>
|
| 286 |
+
</html>
|
serve.py
CHANGED
|
@@ -2196,6 +2196,30 @@ async def a11oy_version():
|
|
| 2196 |
}
|
| 2197 |
|
| 2198 |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| 2199 |
@app.api_route("/api/a11oy/{path:path}", methods=["GET", "POST", "PUT", "DELETE", "PATCH", "HEAD", "OPTIONS"])
|
| 2200 |
async def api_proxy(request: Request, path: str) -> Response:
|
| 2201 |
return await proxy_to_backend(request, f"/{path}")
|
|
@@ -2307,15 +2331,6 @@ async def wasi_rikuq_page() -> Response:
|
|
| 2307 |
return FileResponse(INDEX_HTML, media_type="text/html")
|
| 2308 |
|
| 2309 |
|
| 2310 |
-
@app.get("/ayni")
|
| 2311 |
-
async def ayni_page() -> Response:
|
| 2312 |
-
# ADDITIVE (Yachay / AYNI-OS): reciprocity gauges + replay scrubber + Tinkuy meter.
|
| 2313 |
-
f = PAGES_DIR / "ayni.html"
|
| 2314 |
-
if f.is_file():
|
| 2315 |
-
return FileResponse(f, media_type="text/html")
|
| 2316 |
-
return FileResponse(INDEX_HTML, media_type="text/html")
|
| 2317 |
-
|
| 2318 |
-
|
| 2319 |
# /superpowers — Five live, screenshot-provable superpowers (Decision Replay,
|
| 2320 |
# Tamper Theater, Λ-collapse, RS Resurrection, One-Signed-Organism). Without this
|
| 2321 |
# explicit route the path fell through to the SPA catch-all, which served index.html
|
|
@@ -2329,6 +2344,15 @@ async def superpowers_page() -> Response:
|
|
| 2329 |
return FileResponse(INDEX_HTML, media_type="text/html")
|
| 2330 |
|
| 2331 |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| 2332 |
# --- Throne Room (ADDITIVE; Doctrine v12 PURIQ / Yachay CTO) ---
|
| 2333 |
# Unified 3D control surface for the 5 flagship heroes. WebGPU + WebGL2 fallback.
|
| 2334 |
# Real /healthz polling — no fake data. Three.js r171 (MIT). Kanchay tokens.
|
|
@@ -2695,6 +2719,17 @@ async def api_a11oy_v4_fleet() -> JSONResponse:
|
|
| 2695 |
})
|
| 2696 |
|
| 2697 |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| 2698 |
# ---------------------------------------------------------------------------
|
| 2699 |
# ADDITIVE: /version endpoint — Founder Inspection Surface (v1.0.0)
|
| 2700 |
# Returns build provenance: "what build is live, when, what's its provenance."
|
|
|
|
| 2196 |
}
|
| 2197 |
|
| 2198 |
|
| 2199 |
+
# ===========================================================================
|
| 2200 |
+
# WARHACKER ORCHESTRATION + AI OBSERVABILITY (ADDITIVE, 2026-06-05).
|
| 2201 |
+
# a11oy is the orchestrating BRAIN: one launch point for the 5 Warhacker demos
|
| 2202 |
+
# (server-side calls to each LIVE organ + a11oy Khipu receipt), plus the flagship
|
| 2203 |
+
# AI-observability stack (MELT + distributed tracing, every span a DSSE-signed
|
| 2204 |
+
# receipt on the Khipu DAG, Λ-drift detection). CRITICAL ORDERING: registered
|
| 2205 |
+
# BEFORE the generic /api/a11oy/{path:path} Node proxy (just below) so the new
|
| 2206 |
+
# /api/a11oy/v1/{warhacker,observability}/* routes resolve LOCALLY instead of
|
| 2207 |
+
# being shadowed by the proxy (which would 503 when the Node backend is absent).
|
| 2208 |
+
# try/except-guarded: can NEVER take down the host app. Honest by construction —
|
| 2209 |
+
# an unreachable organ is reported 'unreachable', never fabricated.
|
| 2210 |
+
# Λ = Conjecture 1; proved=5; SLSA L2 organ images (not bundle); no L3/FedRAMP.
|
| 2211 |
+
# Signed-off-by: Stephen P. Lutar Jr. <stephenlutar2@gmail.com>
|
| 2212 |
+
# ===========================================================================
|
| 2213 |
+
try:
|
| 2214 |
+
import a11oy_warhacker_obs as _wh_obs
|
| 2215 |
+
_wh_obs_info = _wh_obs.register(app, ns="a11oy")
|
| 2216 |
+
print(f"[a11oy] Warhacker+Observability mounted: {len(_wh_obs_info.get('warhacker', []))} warhacker + "
|
| 2217 |
+
f"{len(_wh_obs_info.get('observability', []))} observability routes, "
|
| 2218 |
+
f"{_wh_obs_info.get('problems')} problems — Doctrine v11", file=sys.stderr)
|
| 2219 |
+
except Exception as _wh_obs_e: # pragma: no cover - additive, defensive
|
| 2220 |
+
print(f"[a11oy] Warhacker+Observability NOT mounted ({_wh_obs_e!r}); existing routes unaffected", file=sys.stderr)
|
| 2221 |
+
|
| 2222 |
+
|
| 2223 |
@app.api_route("/api/a11oy/{path:path}", methods=["GET", "POST", "PUT", "DELETE", "PATCH", "HEAD", "OPTIONS"])
|
| 2224 |
async def api_proxy(request: Request, path: str) -> Response:
|
| 2225 |
return await proxy_to_backend(request, f"/{path}")
|
|
|
|
| 2331 |
return FileResponse(INDEX_HTML, media_type="text/html")
|
| 2332 |
|
| 2333 |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| 2334 |
# /superpowers — Five live, screenshot-provable superpowers (Decision Replay,
|
| 2335 |
# Tamper Theater, Λ-collapse, RS Resurrection, One-Signed-Organism). Without this
|
| 2336 |
# explicit route the path fell through to the SPA catch-all, which served index.html
|
|
|
|
| 2344 |
return FileResponse(INDEX_HTML, media_type="text/html")
|
| 2345 |
|
| 2346 |
|
| 2347 |
+
@app.get("/ayni")
|
| 2348 |
+
async def ayni_page() -> Response:
|
| 2349 |
+
# ADDITIVE (Yachay / AYNI-OS): reciprocity gauges + replay scrubber + Tinkuy meter.
|
| 2350 |
+
f = PAGES_DIR / "ayni.html"
|
| 2351 |
+
if f.is_file():
|
| 2352 |
+
return FileResponse(f, media_type="text/html")
|
| 2353 |
+
return FileResponse(INDEX_HTML, media_type="text/html")
|
| 2354 |
+
|
| 2355 |
+
|
| 2356 |
# --- Throne Room (ADDITIVE; Doctrine v12 PURIQ / Yachay CTO) ---
|
| 2357 |
# Unified 3D control surface for the 5 flagship heroes. WebGPU + WebGL2 fallback.
|
| 2358 |
# Real /healthz polling — no fake data. Three.js r171 (MIT). Kanchay tokens.
|
|
|
|
| 2719 |
})
|
| 2720 |
|
| 2721 |
|
| 2722 |
+
# --- /warhacker page — a11oy orchestration launchpad for the 5 Warhacker demos.
|
| 2723 |
+
# Explicit route wins over the SPA catch-all. Served from pages/ (COPYed wholesale
|
| 2724 |
+
# by the Dockerfile) so no image-layout change. ADDITIVE.
|
| 2725 |
+
@app.get("/warhacker")
|
| 2726 |
+
async def warhacker_page() -> Response:
|
| 2727 |
+
f = PAGES_DIR / "warhacker.html"
|
| 2728 |
+
if f.is_file():
|
| 2729 |
+
return FileResponse(f, media_type="text/html")
|
| 2730 |
+
return FileResponse(INDEX_HTML, media_type="text/html")
|
| 2731 |
+
|
| 2732 |
+
|
| 2733 |
# ---------------------------------------------------------------------------
|
| 2734 |
# ADDITIVE: /version endpoint — Founder Inspection Surface (v1.0.0)
|
| 2735 |
# Returns build provenance: "what build is live, when, what's its provenance."
|