No inference widget, by correction. This repo previously carried
feature-extraction, embeddings, word-embeddings and sklearn tags, which
made the Hub advertise a hosted feature-extraction endpoint. The config.json
here describes a PPMI+SVD embedding table (3290x128, vectors.npz), not a
transformers config, so AutoConfig/AutoModel cannot load it and that widget
could never have run. The tags were removed instead of leaving a promise the
artifact cannot keep. The embedding table itself is real and the test suite is
green (29/29) — load it as an npz plus vocab.json, not through
transformers.
Operational (MEASURED laptop-Blackwell)
STATUS: tests PASS. get_kernelimport-LIVE. Unsloth/LoRA is the wrong tool. Receipted kernels, not silent CUDA.
Thing
Label
Method / N / date / what-NOT
tests (PYTHONPATH=torch-ext)
PASS
MEASURED 2026-08-29T15:54:41Z host betterwithage Windows-10-10.0.26200-SP0. torch 2.10.0+cu128. GPU NVIDIA GeForce RTX 5050 Laptop GPU arch Blackwell. pytest 29 passed in 2.59s. Failed nodes: none. What-NOT: not a leaderboard. torch.compile fullgraph failures on Windows Blackwell (cl is not found) are MEASURED, not hidden.
Kernel Hub get_kernel
import-LIVE
kernels 0.16.1. Default: get_kernel("SZLHOLDINGS/szl-kernels", revision="main", trust_remote_code=True) → True. backend="cpu" → True. trust_remote_code=False → ValueError (SZLHOLDINGS is not a trusted publisher). repo_type=kernel required (kernels 0.16). What-NOT: not a weight load; do not pickle/joblib.load.
formula-tax
ADVISORY
locked-8 F1 F4 F7 F11 F12 F18 F19 F22. registry_count=21. Λ geomean 1.0. uniqueness Conjecture 1 (never a theorem).
Part of the SZL Holdings governed estate — claims are designed to carry checkable receipts. Verification proves integrity & origin, never accuracy or performance.
🟩 Kernel suite + REAL trained SZL-MiniEmbed. The canonical governed-kernel runtime now rejects non-finite or out-of-range Λ thresholds before emitting a Lambda receipt. The receipted corpus/kernels snapshot remains byte-for-byte preserved for SZL-MiniEmbed replay, so the canonical runtime and receipted corpus intentionally differ at those files. Since SZL-MiniEmbed v1 this repo ALSO ships real trained word embeddings — vectors.npz + vocab.json + config.json — built with no gensim: a distance-weighted term–term co-occurrence matrix over the SZL text estate (doctrine v10/v11 + rag-corpus-v1 + thesis-corpus-v18 + kernel-family READMEs), PPMI-weighted, reduced with sklearn TruncatedSVD to 128-dim over a 3290-term vocabulary. Evidence is INTRINSIC SANITY ONLY — receipted nearest-neighbour lists on 20 doctrine terms; NO downstream/benchmark score is claimed. The kernel suite stays authoritative. Λ = Conjecture 1 · ADVISORY.
STATUS: import-LIVE on CPU Kernel Hub get_kernel (kernels 0.16.1). GPU attention / Flash / Sage / Flex / Triton is UNAVAILABLE.
Thing
Label
Method / N / date / what-NOT
Kernel Hub get_kernel
import-LIVE
MEASURED 2026-08-28 1:57pm ET on kernels 0.16.1. HEAD 8f714f4 (8f714f4ffdeddcd852b233ec95d475656a56fc16). Legal name szl-kernels (Python module szl_kernels). Variants: build/torch-universal (default get_kernel) and build/torch-cpu (backend="cpu"). Working calls: get_kernel("SZLHOLDINGS/szl-kernels", revision="main", trust_remote_code=True) and the same with backend="cpu". selfcheck8/8 (norm_correct, lambda_advisory, energy_honest, cross_kernel_verify, spans_three_kernels, offline_reverify, tamper_detected, block_forward). What-NOT: no tokens/s; no joules; energy remains MEASURED-only / UNAVAILABLE when no NVML. Λ = Conjecture 1 (advisory).
GPU attention (Flash / Sage / Flex / Triton)
UNAVAILABLE
MEASURED 2026-08-28 7:01pm ET this session. Host cursor (Linux 6.12.94+ x86_64, Intel Xeon 8-core). torch2.13.0+cu130 compiled CUDA 13.0. torch.cuda.is_available()=false. nvidia-smi UNAVAILABLE. device_count=0. Triton 3.7.1 present with no CUDA device. No cubin. No timed GPU run. No tokens/s. No joules. Trio CPU import-LIVE lives on those cards. YARQA-ATTN is import-LIVE CPU / GPU UNAVAILABLE, not a fourth stack.
The cut
sklearn-shaped feature extraction that still carries the estate tags. Not MiniEmbed-Nano (64×12). Not BGE.
A boring kernel pack that reviewers can actually run.
Silhouette → leave → SZL
Leader
Take, then tweak
Anthropic
Small, named, limited.
NVIDIA
Suite packaging.
Unsloth
No.
Nobody else ships this combination. That is the point of a one-of-one.
Canonical source:szl-holdings/szl-kernels.
The protected main workflow verifies the kernel suite, replays the MiniEmbed
artifact within its declared tolerance, and checks the source-binding contract
against the public Hugging Face artifact. Exact publication is performed by the
authorized release gateway in
szl-holdings/szl-forge.
That gateway checks out an exact protected Git revision, publishes the declared
file set, and reads every byte back at the resulting immutable Hub revision.
The exact Git source revision is written to publication.json.
This is a governed kernel suite with a receipted word-embedding companion. It is
not a general-purpose language model, and its intrinsic nearest-neighbor replay
is not a downstream quality benchmark.
Artifact truth card
Lane
Classification
Evidence available here
Limitation
Governed kernels
Executable software
Source, manifests, tests, receipt-chain verifier, and selfcheck()
A successful self-check covers the exercised implementation path; it is not a safety, performance, or deployment claim.
SZL-MiniEmbed v1
Trained embedding weights
vectors.npz, vocabulary/config files, bundled corpus, TRAINING_RECEIPT.json, and deterministic replay tooling
Small in-domain co-occurrence embedding with intrinsic sanity evidence only; no downstream benchmark or general-purpose capability claim.
First-class Kernel Hub repository
Kernel distribution and loader surface
Generated source-binding.json, immutable-revision byte readback, and independently observed main and v1 refs
Mutable ref names must be resolved again at evaluation time; repository reachability is not runtime readiness.
Legacy model/card mirror
Distribution and presentation surface
Generated publication.json plus immutable-revision byte readback in the authorized release flow
A model API listing does not make every file trained weights, and mirror reachability is not runtime readiness.
Investor value. The repository combines an auditable governed-compute
reference with a small, receipted learned artifact, while keeping software,
weights, and evidence visibly separate.
Developer/evaluator path. Review the legacy mirror's generated
publication.json,
the first-class Kernel repository's generated
source-binding.json,
and MODEL_PROVENANCE.json. Run suite.selfcheck() for the software path and
python scripts/eval.py for the MiniEmbed replay. Treat returned results as
observations from that run; do not infer a green status from this card.
Kernel Hub migration (verified 2026-08-01):get_kernel(...) now resolves
the matching first-class Kernel Hub repository.
Its live refs resolve independently: main
pins 5c71b9d76dc7bd0bc29dfc82b4db803652f7f20f, while stable
v1
pins 1a3c1bdcd1656483333b3edf1e3b1991c90200be. These are public ref
readbacks, not runtime-readiness or artifact-equivalence claims. This
model-type repository is retained as the legacy source/card mirror.
A kernel suite for governing provenance across operations. This get_kernel-discoverable suite ties SZL Holdings' three governed kernels — szl-governed-norm, szl-lambda-gate, and governed-inference-meter — into one shared, hash-chained UnifiedReceiptChain, and anchors a governance/interop layer on top: szl-govsign (signs the verdict), szl-blocked (refuses honestly + derives an EU AI Act Annex IV draft), and szl-provctl (verifies the provenance DAG + bridges to in-toto/SLSA).
Evidence boundary: no ecosystem-wide novelty claim is made. Within this
published suite, a forward pass touching norm + an advisory Λ gate + an energy
reading can produce one auditable, tamper-evident log instead of three
disconnected logs. Verify that bounded behavior with selfcheck() and the
exported chain verifier before relying on it.
Quickstart
pip install kernels torch
python
1import torch
2from kernels import get_kernel
34# Current `kernels` (>=0.15) requires an explicit revision/version + trust flag for org kernels:5suite = get_kernel("SZLHOLDINGS/szl-kernels", revision="main", trust_remote_code=True)67print(suite.list_kernels())# the 3 numeric suite members + honest roles8print(suite.list_series())# the governance/interop companions (govsign, blocked, provctl)9print(suite.selfcheck())# inspect returned checks; this card assumes no pass1011# ONE shared chain spanning multiple ops:12chain = suite.UnifiedReceiptChain()13x = torch.randn(4,64)14y = suite.governed_rms_norm(chain, x, eps=1e-6)# governed_norm15gate = suite.governed_lambda_gate(chain, torch.tensor([0.9,0.8,0.95]))# lambda_gate (advisory)16e = suite.governed_measure_energy(chain)# energy_core (MEASURED-only)1718ok, depth, brk = chain.verify()# the WHOLE pass verifies as ONE chain19print(ok, depth, chain.kernels_touched())# True 3 ['governed_norm','lambda_gate','energy_core']20print(chain.to_json())# export for offline third-party re-verification
Flagship — a governed transformer sub-block
python
1blk = suite.GovernedBlock()2res = blk.forward(x, gov_axes=torch.tensor([0.95,0.9,0.92]))3print(res["chain_ok"], res["chain_depth"], res["kernels_touched"])4# norm + advisory Λ gate + energy + binding receipt = 4 ops, one verifiable chain.5# The Λ gate is ADVISORY: it is recorded for audit, it does NOT alter the numerics.
Cookbook
Three copy-paste recipes spanning the governed-kernel series. Every printed value is
labeled expected shape (not executed here) — the shapes are transcribed from each
kernel's committed API, not from a run on this card (SZL doctrine: never self-download to
inflate counters, never fabricate an output). Λ stays Conjecture 1 (OPEN); energy stays
MEASURED-only; a BLOCKED verdict stays BLOCKED.
1 — One receipt chain across three ops (suite)
python
1import torch
2from kernels import get_kernel
34suite = get_kernel("SZLHOLDINGS/szl-kernels", revision="main", trust_remote_code=True)56chain = suite.UnifiedReceiptChain()7x = torch.randn(4,64)8suite.governed_rms_norm(chain, x, eps=1e-6)# op 1: governed_norm9suite.governed_lambda_gate(chain, torch.tensor([0.9,0.8,0.95]))# op 2: lambda_gate (ADVISORY)10suite.governed_measure_energy(chain)# op 3: energy_core (MEASURED-only)1112ok, depth, first_break = chain.verify()13print(ok, depth, chain.kernels_touched())14# expected shape (not executed here):15# True 3 ['governed_norm', 'lambda_gate', 'energy_core']16# -> one hash-chain, three ops, verifies as ONE ordered sequence.17# The Λ gate receipt is ADVISORY (Conjecture 1, OPEN): recorded, never proven trust.18# energy_core reports joules=None + UNAVAILABLE_NO_NVML on CPU — never a fabricated joule.
2 — honest-BLOCKED, not fake-green (szl-blocked)
python
1from kernels import get_kernel
23blk = get_kernel("SZLHOLDINGS/szl-blocked", revision="main", trust_remote_code=True)45chain = blk.UnifiedReceiptChain()6policy = blk.deny_if_action_in({"exfiltrate","delete_all"})7work =lambda v: v *289allowed = blk.governed_call(work, policy, chain, request={"action":"summarize"}, args=(21,))10blocked = blk.governed_call(work, policy, chain, request={"action":"exfiltrate"}, args=(21,))1112print(allowed.blocked, allowed.output)13print(blocked.blocked, blocked.output)14# expected shape (not executed here):15# False 42 -> ALLOWED path ran work(21); an ALLOW receipt is on the chain.16# True None -> BLOCKED path: work was NEVER called, output is None,17# a BLOCK receipt is recorded. Honest-BLOCKED, never faked green.
3 — Sign then verify a governance verdict (szl-govsign / DSSE)
python
1from kernels import get_kernel
23gs = get_kernel("SZLHOLDINGS/szl-govsign", revision="main", trust_remote_code=True)45priv = gs.generate_ephemeral_keypair()# production: Sigstore keyless / cosign key, out-of-band6pred = gs.build_governance_predicate(7 lambda_verdict = gs.LambdaVerdict(score=0.92, notes="advisory only — Conjecture 1 (OPEN)"),8 energy = gs.EnergyLabel(value=12.5, unit="joules"),# MEASURED-only9 decision = gs.GovernanceDecision(status="ALLOWED", reason="passed gates"),10 honest_blocked =False,11)12subjects =[gs.Subject(name="szl_kernels/UnifiedReceiptChain", digest={"sha256":"<chain-head>"})]13envelope = gs.attest(subjects, pred, priv)1415print(gs.verify(envelope, priv.public_key()))16# expected shape (not executed here):17# True -> DSSE envelope (ECDSA P-256) verifies: authorship + integrity of the verdict.18# Any tamper -> verify() returns False (fails closed).19# The signature does NOT upgrade Λ to proven trust: proven_trust is locked False.
These recipes chain across three separately published, get_kernel-discoverable kernels.
See szl-provctl to turn any of these
chains into documented in-toto v1 / SLSA v1 shapes for external compatibility testing.
The governed-kernel series
Independently published, get_kernel-discoverable kernels that share one UnifiedReceiptChain. The first three are the numeric core; govsign + blocked + provctl are the governance / interop layer.
suite.list_kernels() returns the numeric core; suite.list_series() returns the govsign + blocked + provctl governance/interop layer.
The honest-model trio (offline replays of the live Alloy surface)
Published as HF model repos (NOT trained models, NO weights — pure-Python, stdlib-only offline replays). Each ships a library_name: kernels card and MEASURED local test counts:
The standalone SZL kernels keep separate receipt state. A single forward pass through them therefore yields logs that are not one ordered stream. UnifiedReceiptChain adds op-agnostic SHA3-256 receipts that hash-chain norm, Λ, and energy calls into one verifiable stream, in call order. szl-govsign can sign that chain head for verification against a separately trusted public key; szl-blocked records refusal as a first-class state and derives a draft documentation skeleton; szl-provctl verifies supplied multi-run provenance records and serializes them into documented in-toto/SLSA shapes for compatibility testing.
Advisory Λ gate; rejects non-finite or out-of-range thresholds before emitting a receipt, then records an advisory result (advisory=True, never proven trust).
governed_measure_energy(chain, measurement=None)
Records an energy reading verbatim — joules=None + UNAVAILABLE_NO_NVML when no GPU. Never fabricated.
GovernedBlock
Pre-norm sub-block composing all three + a binding receipt into one auditable pass.
Numeric registry + governance-layer series + one-shot CPU health check.
Honesty (SZL doctrine)
Λ is advisory. Its uniqueness is Conjecture 1 — OPEN. A recorded gate "pass" is a non-compensatory advisory signal, never proven trust.
Energy is MEASURED-only. Real NVML cumulative-energy delta when a GPU is present; otherwise joules=None, labeled UNAVAILABLE_NO_NVML. No joule is ever fabricated.
The digest is an integrity fingerprint, not a signature. SHA3-256 over a canonical receipt body proves tamper-evidence + ordering — not authorship. Signing is a separate, out-of-band layer — see szl-govsign for DSSE / in-toto attestation.
Honest BLOCKED beats fake green. A failed verification stays failed — see szl-blocked for refusal as a first-class, provenanced state.
Universal (pure-Python) suite: a correctness and provenance reference, not a CUDA speed record. No performance result or current test status is asserted by this card.
These links are navigation, not status badges. Availability, deployment state,
and current revision must be checked at evaluation time; a reachable page does
not establish correctness, performance, or runtime readiness.
Compatibility
Python 3.9+, torch>=2.5, standard library + torch only. CPU import-LIVE / GPU attention UNAVAILABLE.
License
Apache-2.0. Copyright 2026 SZL Holdings.
Trained SZL-MiniEmbed v1 (MEASURED — see TRAINING_RECEIPT.json)
Real word embeddings over the SZL text estate, produced without gensim: a distance-weighted
term–term co-occurrence matrix (window 5) → PPMI → sklearn TruncatedSVD → L2-normalized
vectors. Corpus = 26 documents / 26 source files (every file's sha256 is recorded in
the receipt): doctrine-v10-v11, rag-corpus-v1 (corpus.jsonl), thesis-corpus-v18, and the
kernel-family READMEs + build/*.py. Seed 20260721; the exact corpus text is bundled under
corpus/ so the build is reproducible offline.
Cosine nearest neighbours for doctrine terms — the only evidence claimed. This is intrinsic
sanity, not a benchmark: no analogy/retrieval score is asserted.
1import numpy as np, json
2V = np.load("vectors.npz")["vectors"]# float32 [vocab, dim], L2-normalized3vocab = json.load(open("vocab.json"))["index"]# {term: row}4defnn(term, k=6):5 v = V[vocab[term]]; s = V @ v
6return[(list(vocab)[i],float(s[i]))for i in np.argsort(-s)[1:k+1]]7print(nn("receipt"))
Honest scope / blind spot: these are distributional co-occurrence embeddings over a small
in-domain corpus (3290 terms). They capture SZL-doctrine term neighbourhoods; they are not
a general-purpose embedding model and carry no benchmark claim. Rare/out-of-vocab terms are
simply absent. The kernel suite remains the primary, authoritative artifact.
Re-verify everything: python scripts/eval.py (sha256-checks vectors.npz + vocab.json
against the receipt, regenerates the embeddings from the bundled corpus, and compares the
nearest-neighbour sets — mean Jaccard overlap ≥ 0.90 — and SVD variance within ±0.02).
Cite this. Part of the SZL Holdings Ouroboros Thesis (Governed Post-Determinism).
Concept DOI (always-latest): 10.5281/zenodo.19944926.
Author: Stephen P. Lutar Jr. · ORCID 0009-0001-0110-4173 · License CC-BY-4.0.
Full DOI-pinned lineage (v1→v26) + the 8 papers: szl-papers PAPERS_INDEX.
No artifact-specific DOI is minted for this model; the concept DOI above covers the program.
Honesty (Doctrine v11): Λ unconditional uniqueness is Conjecture 1 (machine-checked FALSE as stated) — never a theorem; conditional uniqueness is Theorem U (axiom-free). Locked-proven formulas = exactly 8 {F1,F4,F7,F11,F12,F18,F19,F22}; ~185 experimental theorems are a separate CI-green tier; Khipu BFT safety = Conjecture 2. Trust never 100%.
bibtex
1@misc{lutar_szl_ouroboros,
2 author = {Lutar, Stephen P., Jr.},
3 title = {SZL Holdings --- The Ouroboros Thesis (Governed Post-Determinism)},
4 year = {2026},
5 publisher = {Zenodo},
6 doi = {10.5281/zenodo.19944926},
7 url = {https://doi.org/10.5281/zenodo.19944926},
8 note = {Concept DOI --- always resolves to the latest version. ORCID 0009-0001-0110-4173. CC-BY-4.0.}
9}