semescalate

package
v0.8.0 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Sep 24, 2026 License: AGPL-3.0, AGPL-3.0-or-later Imports: 13 Imported by: 0

Documentation

Overview

Package semescalate is the experimental deterministic core of the Semantic Escalation Gate (docs/specs/semantic-escalation-gate-v0.md). It routes one named semantic gap to at most one bounded provider call and admits proposals only through an independently registered verifier. It registers no provider and no verifier, makes no network or process call, and is not wired into any serving, ranking, or default command path.

Index

Constants

View Source
const (
	ChoiceDecisionSchema = "corvint-semantic-choice-decision/0"
	ChoiceAbstain        = "none"
	ProbabilityScalePPM  = uint32(1_000_000)
)
View Source
const (
	RouteSchema          = "corvint-semantic-route/0"
	CallSchema           = "corvint-semantic-call/0"
	RequestSchema        = "corvint-semantic-request/0"
	ProposalSchema       = "corvint-semantic-proposals/0"
	ChoiceRequestSchema  = "corvint-semantic-choice-request/0"
	ChoiceResponseSchema = "corvint-semantic-choice/0"

	Call   = "CALL"
	NoCall = "NO_CALL"

	AdmissionPower = "admission"

	FrontierUnknown             = "UNKNOWN"
	FrontierVerifierUnavailable = "UNKNOWN(verifier-unavailable)"
)
View Source
const (
	Completed     = "COMPLETED"
	Timeout       = "TIMEOUT"
	OutputLimit   = "OUTPUT_LIMIT"
	ProviderError = "PROVIDER_ERROR"
)

Termination states of one attempted invocation.

Variables

This section is empty.

Functions

func GapID

func GapID(g Gap) string

GapID is the SEG-002 deterministic identity of a gap.

Types

type Authority

type Authority string

Authority is set by the gate, never the model. INFERRED is the SEG-011 ceiling reached by admission.

const Inferred Authority = "INFERRED"

type Budget

type Budget struct {
	Calls       int
	InputBytes  int
	OutputBytes int
	CostMicros  int64
	WallTime    time.Duration
}

Budget is the hard per-run limit set. A zero field allows nothing. WallTime is one run deadline fixed when the gate is built; every gap's call is bounded by what remains of it.

type CallReceipt

type CallReceipt struct {
	Schema              string
	GapID               string
	InputHandles        []string
	SpanDigests         []string
	PromptDigest        string
	ResponseSchema      string
	ModelRevision       string
	CalibrationDigest   string
	Trigger             Trigger
	Attempt             int
	RequestDigest       string
	ResponseDigest      string
	ParsedDigest        string
	QuestionDigest      string                 `json:",omitempty"`
	Decision            *ChoiceDecisionReceipt `json:",omitempty"`
	ObservedInputBytes  int
	ObservedOutputBytes int
	ObservedCalls       int
	Termination         string
	ProviderReturned    bool // the gate observed Invoke return; false after a timeout it could not observe end
	ProviderReported    Observation
	Rejections          []string
}

CallReceipt is the corvint-semantic-call/0 record of one attempted invocation.

type Candidate

type Candidate struct {
	Proposal
	Authority Authority
}

Candidate is an admitted proposal; the gate, not the model, sets its authority.

type Capabilities

type Capabilities struct {
	ModelRevision     string
	CalibrationDigest string
	ResponseSchema    string
	Remote            bool
}

Capabilities is a provider's describe() result.

type ChoiceDecisionReceipt

type ChoiceDecisionReceipt struct {
	Schema               string              `json:"schema"`
	QuestionID           string              `json:"questionId"`
	Choice               string              `json:"choice"`
	Probabilities        []ChoiceProbability `json:"probabilities"`
	ConfidencePPM        uint32              `json:"confidencePpm"`
	ConfidenceBasis      string              `json:"confidenceBasis"`
	MinimumConfidencePPM uint32              `json:"minimumConfidencePpm"`
	Abstained            bool                `json:"abstained"`
}

ChoiceDecisionReceipt records a validated distribution. ConfidencePPM is the deterministic winner-minus-runner-up margin and is explicitly uncalibrated.

type ChoiceOption

type ChoiceOption struct {
	ID      string `json:"id"`
	Handle  string `json:"handle"`
	Excerpt string `json:"excerpt"`
}

ChoiceOption is a mechanically supplied, already anchored candidate. A provider can select its ID but cannot author its handle or excerpt.

type ChoiceProbability

type ChoiceProbability struct {
	ID    string `json:"id"`
	Value uint32 `json:"value"`
}

ChoiceProbability preserves the canonical question order in a receipt.

type ChoiceQuestion

type ChoiceQuestion struct {
	ID                   string         `json:"id"`
	Instructions         string         `json:"instructions"`
	Options              []ChoiceOption `json:"options"`
	MinimumConfidencePPM uint32         `json:"minimumConfidencePpm"`
}

ChoiceQuestion defines one bounded typed decision. MinimumConfidencePPM is a caller-owned winner-margin threshold, not a provider calibration claim.

type Config

type Config struct {
	Provider          Provider
	Verifiers         []Verifier
	Budget            Budget
	AllowRemote       bool
	CostMicrosPerCall int64
}

Config configures one gate run.

type Gap

type Gap struct {
	Repository           string
	Revision             string
	TaskProfile          string
	EvidenceHandles      []string
	AccessContext        string
	VerifierProfile      string
	PolicyDigest         string
	Trigger              Trigger
	MechanicallyResolved bool
}

Gap is one residual semantic gap after deterministic work. MechanicallyResolved is the caller's deterministic result; this package does not perform that work.

type Gate

type Gate struct {
	// contains filtered or unexported fields
}

Gate holds registered verifiers, run usage, and the in-memory derivation ledger. Calls are serialized so budget reservation and derivation reuse remain atomic for one run.

func New

func New(cfg Config) *Gate

New builds a gate. Verifiers are keyed by profile ID.

func (*Gate) Escalate

func (g *Gate) Escalate(gap Gap, spans []Span) Outcome

Escalate routes one gap. Every path returns a route receipt; only a CALL carries a call receipt.

func (*Gate) EscalateChoice

func (g *Gate) EscalateChoice(gap Gap, spans []Span, question ChoiceQuestion) Outcome

EscalateChoice routes one gap through an alternate typed-choice schema. It is deliberately separate from Escalate so the existing proposal request and response bytes remain unchanged.

type Limits

type Limits struct {
	MaxOutputBytes int
	WallTime       time.Duration
}

Limits bound one invocation.

type Observation

type Observation struct {
	Tokens     int64
	CostMicros int64
	Model      string
}

Observation is provider-reported and never governs termination.

type Outcome

type Outcome struct {
	Route      RouteReceipt
	Call       *CallReceipt
	Candidates []Candidate
	Frontier   string
}

Outcome is the full result for one gap.

type Proposal

type Proposal struct {
	Handle  string `json:"handle"`
	Excerpt string `json:"excerpt"`
}

Proposal is the only shape a provider response may carry.

type Provider

type Provider interface {
	Describe() Capabilities
	Invoke(ctx context.Context, request []byte, limits Limits) ([]byte, Observation, error)
}

Provider is the SEG-006 adapter boundary: canonical request bytes and limits in, opaque bytes out.

type Reason

type Reason string

Reason is a stable SEG-003 no-call reason.

const (
	MechanicallyResolved Reason = "MECHANICALLY_RESOLVED"
	CachedDerivation     Reason = "CACHED_DERIVATION"
	NoAdmissionVerifier  Reason = "NO_ADMISSION_VERIFIER"
	PolicyDenied         Reason = "POLICY_DENIED"
	UnauthorizedInput    Reason = "UNAUTHORIZED_INPUT"
	SecretRisk           Reason = "SECRET_RISK"
	IncompleteScope      Reason = "INCOMPLETE_SCOPE"
	UnsupportedInput     Reason = "UNSUPPORTED_INPUT"
	BudgetExhausted      Reason = "BUDGET_EXHAUSTED"
	NoCalibratedModel    Reason = "NO_CALIBRATED_MODEL"
)

type RouteReceipt

type RouteReceipt struct {
	Schema            string
	GapID             string
	TaskProfile       string
	AccessContext     string
	PolicyDigest      string
	VerifierProfile   string
	VerifierVersion   string
	VerifierPower     string
	Decision          string
	Reason            string
	ModelRevision     string
	CalibrationDigest string
	Budget            Budget
}

RouteReceipt is the corvint-semantic-route/0 record; it carries no source bodies.

type Span

type Span struct {
	Handle     string
	Body       []byte
	Authorized bool
}

Span is one immutable evidence span offered for a gap. Only spans named by the gap's EvidenceHandles can reach a provider.

type Trigger

type Trigger string

Trigger is a SEG-005 call trigger; any other value leaves the gap unnamed.

const (
	DeterministicCandidateEmpty Trigger = "DETERMINISTIC_CANDIDATE_EMPTY"
	RankerDisagreement          Trigger = "RANKER_DISAGREEMENT"
	AnchorAmbiguity             Trigger = "ANCHOR_AMBIGUITY"
)

type Verifier

type Verifier interface {
	Profile() VerifierProfile
	Admit(span Span, proposal Proposal) (admitted bool, rejection string)
}

Verifier independently decides admission of one proposal against its provided span.

type VerifierProfile

type VerifierProfile struct {
	ID      string
	Version string
}

VerifierProfile names a registered deterministic admission verifier.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL