--- title: Provenance Verifier emoji: ✔ colorFrom: gray colorTo: green sdk: gradio sdk_version: 5.44.1 app_file: app.py pinned: false license: apache-2.0 --- # Provenance Verifier · FALCONS.AI Model Surgeon A public, no-account verifier where anyone can watch a Model Surgeon package prove itself. Tap a sample, drop your own `.zip` onto the grid, or point it at a Hugging Face repo — the verdict comes straight from the unmodified, audited `verify_attestation.py` from [Falcons-ai/surgeon-verify](https://github.com/Falcons-ai/surgeon-verify) (Apache-2.0), invoked as a subprocess. Product: [surgeon.falcons.ai](https://surgeon.falcons.ai) · [/verify](https://surgeon.falcons.ai/verify) > Signed creation is the product — universal verification is what makes it > worth anything. Free, no account, forever. ## Transport: Gradio (refactored 2026-09-03 from the FastAPI/Docker Space) | file | role | | --- | --- | | `app.py` | the Gradio page and its three handlers (sample · upload · Hub repo), the cancel control, the five-deep verdict stack with receipts | | `engine_wrapper.py` | the verification wrapper — **every function byte-identical to the FastAPI original** (`_run_engine_sync`, `_parse_stdout`, `_normalize_container`, `_junk_entry`, `_zip_declared_size`, `_resolve_and_verify_repo_sync`, `_dsse_subject_names`, `_result`) | | `engine/verify_attestation.py` | the pinned engine, verbatim from Model Surgeon `tools/verify_attestation.py` (V7.13, 2026-09-08: names the legacy predicate id when it meets one) | | `static/style.css` | the product stylesheet, unchanged; `static/gradio.css` holds the few overrides that hide Gradio's own wrappers | | `samples/` | SAMPLE_A (genuine) · SAMPLE_B (one byte flipped) | What changed for the reader: sample cards are tapped rather than dragged (Gradio has no cross-component drag; drop **of your own files** onto the grid still works); the keyid chip is plain selectable text (no copy button); "recomputing digests… / fetching from the Hub…" shows as Gradio's progress text; ✕ cancel aborts the in-flight event exactly as the old AbortController did. ## Guarantees (BUILD SPEC section 1) — how each survives the transport - The **only** verification engine is the pinned, verbatim copy in `engine/verify_attestation.py`, invoked as a subprocess. No porting, no patching. - **No model-parsing code** anywhere in this Space. - **Nothing retained**: per-request temp dirs deleted in `finally`; Gradio's own upload copy is moved into that dir and deleted with it; `delete_cache=(60, 60)` sweeps anything Gradio holds; `analytics_enabled=False`; Gradio launches uvicorn at `log_level="warning"` (no access log); this code never logs user input. - A missing capability is never reported as tampering. - Weights are never re-served — the page has no file output component. ## Hardware The Space runs on the free **ZeroGPU** tier (CPU basic is not selectable for it). ZeroGPU refuses any app without a `@spaces.GPU` function, so `app.py` declares a no-op one that nothing calls; all verification runs on CPU and uses no GPU quota. `requirements.txt` lists `spaces` so the import resolves; locally the import is guarded. ## Configuration | env | default | meaning | | --- | --- | --- | | `MAX_UPLOAD_MB` | `1024` | per-file cap for uploads and repo files (also passed to Gradio as `max_file_size`) | | `MAX_REPO_MB` | `2048` | total cap for attested-repo subject downloads | | `HF_TOKEN` | unset | optional, for Hub rate headroom only | | `PORT` | `7860` | Spaces contract | ## Local run ``` pip install -r requirements.txt python app.py # http://localhost:7860 ``` ## Verified before delivery (sandbox, 2026-09-03) Handlers executed against the real engine and both samples through the Gradio functions (with the `gradio` import stubbed — the package is not installable in the build sandbox): SAMPLE_A → ✔ VERIFIED with keyid + receipt · SAMPLE_B → ✘ TAMPERED with the ✖ line and signed/actual digests · a Windows-style backslash container → repaired, VERIFIED, note shown · a text file → NOT A SURGEON PACKAGE · over-cap → LIMIT / ERROR · bad repo id → LIMIT / ERROR · at capacity → the same "at capacity" verdict · stack capped at five · no temp dirs left behind, Gradio's cached upload deleted. **Not run here:** the Gradio UI itself (first render is on the Space); fonts still fall back to system monospace until `static/fonts/` is populated.