verifier / README.md
Michael Stattelman
Add application file
f75eb4e
|
Raw History Blame Contribute Delete
4.47 kB
---
title: Provenance Verifier
emoji: ✔
colorFrom: gray
colorTo: green
sdk: gradio
sdk_version: 5.44.1
app_file: app.py
pinned: false
license: apache-2.0
---
# Provenance Verifier · FALCONS.AI Model Surgeon
A public, no-account verifier where anyone can watch a Model Surgeon package prove
itself. Tap a sample, drop your own `.zip` onto the grid, or point it at a
Hugging Face repo — the verdict comes straight from the unmodified, audited
`verify_attestation.py` from
[Falcons-ai/surgeon-verify](https://github.com/Falcons-ai/surgeon-verify)
(Apache-2.0), invoked as a subprocess.
Product: [surgeon.falcons.ai](https://surgeon.falcons.ai) ·
[/verify](https://surgeon.falcons.ai/verify)
> Signed creation is the product — universal verification is what makes it
> worth anything. Free, no account, forever.
## Transport: Gradio (refactored 2026-09-03 from the FastAPI/Docker Space)
| file | role |
| --- | --- |
| `app.py` | the Gradio page and its three handlers (sample · upload · Hub repo), the cancel control, the five-deep verdict stack with receipts |
| `engine_wrapper.py` | the verification wrapper — **every function byte-identical to the FastAPI original** (`_run_engine_sync`, `_parse_stdout`, `_normalize_container`, `_junk_entry`, `_zip_declared_size`, `_resolve_and_verify_repo_sync`, `_dsse_subject_names`, `_result`) |
| `engine/verify_attestation.py` | the pinned engine, verbatim from Model Surgeon `tools/verify_attestation.py` (V7.13, 2026-09-08: names the legacy predicate id when it meets one) |
| `static/style.css` | the product stylesheet, unchanged; `static/gradio.css` holds the few overrides that hide Gradio's own wrappers |
| `samples/` | SAMPLE_A (genuine) · SAMPLE_B (one byte flipped) |
What changed for the reader: sample cards are tapped rather than dragged (Gradio has no cross-component drag; drop **of your own files** onto the grid still works); the keyid chip is plain selectable text (no copy button); "recomputing digests… / fetching from the Hub…" shows as Gradio's progress text; ✕ cancel aborts the in-flight event exactly as the old AbortController did.
## Guarantees (BUILD SPEC section 1) — how each survives the transport
- The **only** verification engine is the pinned, verbatim copy in `engine/verify_attestation.py`, invoked as a subprocess. No porting, no patching.
- **No model-parsing code** anywhere in this Space.
- **Nothing retained**: per-request temp dirs deleted in `finally`; Gradio's own upload copy is moved into that dir and deleted with it; `delete_cache=(60, 60)` sweeps anything Gradio holds; `analytics_enabled=False`; Gradio launches uvicorn at `log_level="warning"` (no access log); this code never logs user input.
- A missing capability is never reported as tampering.
- Weights are never re-served — the page has no file output component.
## Hardware
The Space runs on the free **ZeroGPU** tier (CPU basic is not selectable for it). ZeroGPU refuses any app without a `@spaces.GPU` function, so `app.py` declares a no-op one that nothing calls; all verification runs on CPU and uses no GPU quota. `requirements.txt` lists `spaces` so the import resolves; locally the import is guarded.
## Configuration
| env | default | meaning |
| --- | --- | --- |
| `MAX_UPLOAD_MB` | `1024` | per-file cap for uploads and repo files (also passed to Gradio as `max_file_size`) |
| `MAX_REPO_MB` | `2048` | total cap for attested-repo subject downloads |
| `HF_TOKEN` | unset | optional, for Hub rate headroom only |
| `PORT` | `7860` | Spaces contract |
## Local run
```
pip install -r requirements.txt
python app.py # http://localhost:7860
```
## Verified before delivery (sandbox, 2026-09-03)
Handlers executed against the real engine and both samples through the Gradio
functions (with the `gradio` import stubbed — the package is not installable in
the build sandbox): SAMPLE_A → ✔ VERIFIED with keyid + receipt · SAMPLE_B →
✘ TAMPERED with the ✖ line and signed/actual digests · a Windows-style
backslash container → repaired, VERIFIED, note shown · a text file → NOT A
SURGEON PACKAGE · over-cap → LIMIT / ERROR · bad repo id → LIMIT / ERROR · at
capacity → the same "at capacity" verdict · stack capped at five · no temp
dirs left behind, Gradio's cached upload deleted. **Not run here:** the Gradio
UI itself (first render is on the Space); fonts still fall back to system
monospace until `static/fonts/` is populated.