Skip to main content

awdit

Docs · Source · pip install awdit · The Aither World

The Aither World is an operating system for agents — a Linux you can hand to one, the runtimes it works in, and the tools it works with. awnix is the Linux underneath it; awdit is one of its 33 bricks — each installs on its own, runs offline, and needs no account.

Start here: Write one sensitive action to it and then try to remove the record.

An append-only audit trail whose gaps are detectable.

pip install awdit
from awdit import append, verify

append("audit.log", "deploy", service="veil", by="david")

r = verify("audit.log")
if not r:
    for problem in r.problems:
        print(problem)
awdit append audit.log deploy --field service=veil
awdit verify audit.log        # 0 verified · 1 a real problem · 2 could not judge
awdit tail   audit.log -n 20

What it actually proves

Records are hash-chained: each one binds the digest of the one before it, so altering or reordering history breaks the chain at the point of the edit and verify names the record. That much is ordinary.

The part usually got wrong is truncation. A hash chain proves the records you are holding follow one another. It says nothing about records that used to be on the end and are not there now — and cutting the tail off a chained log leaves a perfectly valid shorter chain. That is exactly the edit someone who has just done something wants to make, and exactly the one a naive "tamper-evident log" permits in silence.

So the anchor is part of the format, not an add-on. append() maintains a sidecar holding the head digest and the record count, and verify compares against it:

TRUNCATED: anchor records 3 entries, log holds 2 — 1 removed from the end

Three failures, reported as three different things, because during an incident they call for different responses:

verdict meaning
ALTERED a record's content no longer matches its own hash
REORDERED a record's prev does not match the previous record's hash
TRUNCATED the chain is internally perfect but shorter than the anchor

What it does not prove — stated, not papered over

If the anchor is on the same disk as the log, an attacker with write access edits both. The anchor turns truncation from undetectable into detectable by anyone who has a copy of the head. To get a real guarantee, put the head somewhere the writer cannot reach: another host, a signed artifact (awseal), a transparency log, a sentence in a chat channel.

A security property whose limits nobody can state is not one you can rely on, so: this detects tampering, it does not prevent it, and its truncation detection is exactly as strong as the independence of the anchor.

verify also reports NO ANCHOR as a warning that is not a pass — a chain with no anchor is self-consistent and truncatable, and reporting "ok" there would convert a missing record into a positive assurance.

Design notes

  • No dependencies. An audit log that needs an install before it can be read is one nobody reads during an incident; hashlib and json are the whole requirement.
  • The record lands before the anchor moves. If the process dies between the two, verification reports an anchor behind the log — recoverable and obvious. The other order loses a record while claiming completeness.
  • Digests are taken over canonical JSON (sorted keys, no whitespace), so a log rewritten by a different writer does not read as tampered. An alarm that fires on formatting is an alarm nobody keeps.
  • An unparseable line is reported as itself, not skipped — a silently dropped line becomes a chain gap blamed on the next record.

Tests

Every claim has a mutation that breaks it, including one asserting that a truncated chain with the anchor removed verifies clean — the proof that the anchor is load-bearing rather than decoration.

pip install -e ".[dev]" && pytest

Part of the aw family: awgit · awgraph · awseal · awdk · awnode

Apache-2.0.

The aw family

Standalone tools that share one idea: replace something you would otherwise have to trust with something you can check.

Each installs on its own, works offline, and needs no account.

instead of trusting you check
awdk a framework's idea of how your agents should run one loop you can read, pointed at a backend you already pay for
awskills that an agent knows your procedure the procedure written down, versioned, and loadable by any agent
awm that memory stayed in its lane tenant:user:project scopes, so a write cannot cross a boundary
awnode a vendor's cloud with every prompt a local gateway routing to backends you chose
awgraph that grep found everything an AST + tree-sitter call graph an agent can traverse
awgit that no one else is editing this file a lease, refused at commit time if you do not hold it
awseal that the artifact came from who you think an Ed25519 seal — the key that verifies is not the key that forges
awshare that the download is intact content-addressed bundles, verified on fetch
awnest that there is a person on the other end a verdict with evidence, where "we could not tell" is not "yes"
awnboard a share link anyone who sees it can use an invitation addressed to one person, for one gate, revocable
awnix that the box is what you left it as an immutable image you built, with atomic rollback
awrecover that the restore worked a restore that fully lands or does not land at all
awrelay a SaaS in the middle of your agents findings, alerts and coordination over your own transport
awmail a mailbox somebody else can read mail your agents send and receive over your own server
awfind one vendor's idea of the web results from whichever providers you configured
awbrowse that the page said what you were told the render, the DOM and the requests it made
aitherkvcache a vendor's quantisation defaults sub-byte KV cache kernels you can benchmark yourself
AitherZero a pile of scripts nobody has numbered numbered, discoverable automation with declarative playbooks
AitherConnect what a page tells your browser to do a federated search and desktop bridge you host
awreason a confident paragraph the phases it went through, and every tool call it made to get there
awrecurse that everything you pasted in was actually read which slices it opened, and what it concluded from each
awprism the first explanation that fits the ranked alternatives, and the observation that separates them
awrepl what the agent believes the value is the value, printed from the live session
awresearch a summary of pages nobody opened every claim against the source it came from
awpredict a model because it trained without erroring its prediction against a self-updating lookup, on the rows that are actually novel
awkno that the docs site is up, or that you remember the family the whole ecosystem in your terminal, with no network at all

awnix is the ground floor — A Linux you can hand to an agent — immutable base, capabilities included.

The Aitherium ecosystem

Every repository here is public. Each publishes an aither-manifest.json beside its page, so any surface can read every sibling's — the network is browsable from any node in it.

repo what it is pages
awdk Build AI agent fleets — 3 lines, any backend, local or cloud docs
awskills Portable agent skills — self-contained procedures an agent loads on demand docs
awm A portable, scoped agent memory docs
awnode A lightweight local gateway — bridges your apps to the AI backends you chose docs
awrun A priority-aware queue and dispatcher for agentic runs and ad-hoc CI builds docs
awgraph A semantic code graph for agents — AST + tree-sitter, call graphs docs
awgit Semantic version control on top of git — edit-ops and leases docs
awseal Sign an artifact so a stranger can verify it docs
awshare Publish an artifact and fetch it back verified docs
awdit (you are here) An append-only audit trail whose gaps are DETECTABLE docs
awbac Role-based access control that fails closed and explains itself docs
awiam Who is this caller? A directory and session store that fails honestly docs
awtunnel Reach a service that has no public address docs
awnest Prove there is a human before you let them into the nest docs
awnboard A front gate you can put in front of anything, and hand someone the key to docs
awnix A Linux you can hand to an agent — immutable base, capabilities included docs
awrecover Labelled snapshots with an all-or-nothing restore docs
awrelay Portable agent messaging — findings, alerts, coordination docs
awmail Give an agent an email address — send, and actually receive docs
awnet The agentic web — agents host a mesh, and agents join one docs
awfind A portable search client — query, results, ranking docs
awbrowse A portable browser client — navigate, console, network, DOM, screenshot docs
awknowledge How to run a coding agent so the result survives — the laws, with evidence docs
aitherkvcache Near-optimal KV cache quantization for LLM inference — sub-byte compression docs
AitherZero PowerShell 7+ automation framework — numbered, self-describing scripts docs
AitherConnect Browser extension — federated AI search, page context, and the Living OS overlay docs
awreason A portable reasoning client — sessions, phases, thoughts, and the chain that produced the answer docs
awrecurse Answer a question over a context far larger than the window — recursively, with the trace kept docs
awprism Turn a failure into ranked hypotheses — and say what would confirm each one docs
awrepl A REPL an agent can actually use — state that survives between turns docs
awresearch Ask a research question, get a cited report you can check docs
awpredict Predict what your environment does next, and how surprised you were docs
awkno The man page for the Aither World — every brick, stack and law, offline docs
<script src="aither-constellation.js"></script>

Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

awdit-0.1.0.tar.gz (22.6 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

awdit-0.1.0-py3-none-any.whl (18.9 kB view details)

Uploaded Python 3

File details

Details for the file awdit-0.1.0.tar.gz.

File metadata

  • Download URL: awdit-0.1.0.tar.gz
  • Upload date:
  • Size: 22.6 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/7.0.0 CPython/3.12.3

File hashes

Hashes for awdit-0.1.0.tar.gz
Algorithm Hash digest
SHA256 53ae099ed8365d4e05a2b61e87847f52c00ca1ce2d8ffe1d85c87ef469d9cbe0
MD5 325adf755a3717c7abfb2aaefe9c3ff0
BLAKE2b-256 7c508ae4634ac5dcc30ea0b6e054ea8d06cd81c5ea6cebc2f5b90a4b2d22f7bf

See more details on using hashes here.

File details

Details for the file awdit-0.1.0-py3-none-any.whl.

File metadata

  • Download URL: awdit-0.1.0-py3-none-any.whl
  • Upload date:
  • Size: 18.9 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/7.0.0 CPython/3.12.3

File hashes

Hashes for awdit-0.1.0-py3-none-any.whl
Algorithm Hash digest
SHA256 896d23f20592bc7027d2ca2c6bae4e058a7b33e02865d510394fb792f0b7403d
MD5 7137554cf1ddd66ee1440f7970f9692a
BLAKE2b-256 2d86a2fda7a4190764d7583ae23e34067a9cdf6fe1efd666f5fcbc8b6a433604

See more details on using hashes here.

Release history Release notifications | RSS feed

This release

0.1.0 This release

2 files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page