#!/usr/bin/env python3 """Read-only verification that the existing private Space serves this application.""" from datetime import datetime, timezone import hashlib import json from pathlib import Path import httpx from huggingface_hub import HfApi, get_token ROOT = Path(__file__).resolve().parents[1] state = json.loads((ROOT / 'deployment.json').read_text()) token = get_token() if not token: raise SystemExit('Existing authentication required') info = HfApi(token=token).space_info(state['repo_id']) assert info.private and info.runtime.stage == 'RUNNING' assert str(info.runtime.hardware) == 'zero-a10g' assert info.sha == state['hub_commit'] == info.runtime.raw['sha'] assert info.card_data['title'] == 'Qwen 2.1 Image' domains = [row['domain'] for row in info.runtime.raw['domains'] if row['stage'] == 'READY'] preferred = state['repo_id'].lower().replace('/', '-') + '.hf.space' url = 'https://' + (preferred if preferred in domains else domains[0]) headers = {'Authorization': 'Bearer ' + token} health = httpx.get(url + '/health', headers=headers, timeout=30).json() names = ['app.py', 'settings.py', 'requirements.txt', 'frontend/index.html', 'frontend/style.css', 'frontend/app.js', 'frontend/vendor/gradio-client.js', 'frontend/examples/glass-pear.png', 'frontend/examples/typography.png', 'frontend/examples/architecture.png', 'frontend/examples/cutout.png'] fingerprint = hashlib.sha256(b''.join(n.encode()+b'\0'+(ROOT/n).read_bytes()+b'\0' for n in names)).hexdigest() assert health['source_sha256'] == fingerprint assert health['frontend'] == 'gr.Server' and health['queue_capacity'] == 8 assets = {} for name, endpoint in [('frontend/index.html', '/'), ('frontend/style.css', '/assets/style.css'), ('frontend/app.js', '/assets/app.js'), ('frontend/vendor/gradio-client.js', '/assets/vendor/gradio-client.js'), *[(name, '/assets/' + name.removeprefix('frontend/')) for name in names if name.startswith('frontend/examples/')]]: response = httpx.get(url + endpoint, headers=headers, timeout=30) assert response.status_code == 200 and response.content == (ROOT / name).read_bytes(), name assets[name] = hashlib.sha256(response.content).hexdigest() anonymous_status = httpx.get(url + '/', timeout=30, follow_redirects=False).status_code assert anonymous_status in {401, 403, 404} record = {'at': datetime.now(timezone.utc).isoformat(), 'space': state['repo_id'], 'url': url, 'hub_commit': info.sha, 'source_commit': state['latest_source_commit'], 'private': info.private, 'runtime': info.runtime.stage, 'hardware': str(info.runtime.hardware), 'title': info.card_data['title'], 'health': health, 'served_assets_sha256': assets, 'anonymous_status': anonymous_status, 'credentials_persisted': False} out = ROOT / 'artifacts' / 'release' out.mkdir(exist_ok=True) path = out / (datetime.now(timezone.utc).strftime('%Y%m%dT%H%M%S') + '.json') path.write_text(json.dumps(record, indent=2)+'\n') print(json.dumps(record, indent=2)) print(path)