From 0fb2df11a62e1d624952da16b9b9b125d3e9f83f Mon Sep 17 00:00:00 2001 From: Kit OC5 Date: Fri, 2 Oct 2026 18:25:56 -0400 Subject: [PATCH] compute-guard: windytalk client-side :8788 refs filed as engine-side (Windy Talk's classification) run-client.sh points at an ssh -L tunnel to the dev engine on Veron; index.html lines are display-only fallbacks; the shipped desktop client defaults to the public engine on Veron. Same dated owner-approved exemption (approved_by windy-hub, expires 2026-12-31), NOT local-user-hardware. Co-Authored-By: Claude Sonnet 5.5 --- ci/compute-guard-allow.yml | 18 ++++++++++++++++++ 1 file changed, 18 insertions(+) diff --git a/ci/compute-guard-allow.yml b/ci/compute-guard-allow.yml index 5ac6007..81dc42c 100644 --- a/ci/compute-guard-allow.yml +++ b/ci/compute-guard-allow.yml @@ -110,3 +110,21 @@ allow: approved_by: windy-hub approved_on: 2026-10-02 expires: 2026-12-31 + + - repo: windytalk + paths: ["scripts/run-client.sh"] + matches: [':(8791|8788|8794)'] + reason: "Dev client launcher: 127.0.0.1:8788 is an ssh -L tunnel to the dev engine ON VERON (not the user's machine), so engine-side; dev-only, not shipped. To be placed behind Mind per Mind's audit plan (Windy Talk, Hub 10-02)." + exemption: owner-approved + approved_by: windy-hub + approved_on: 2026-10-02 + expires: 2026-12-31 + + - repo: windytalk + paths: ["apps/desktop/renderer/index.html"] + matches: [':(8791|8788|8794)'] + reason: "Display-only fallback label in the settings panel (cfg.engineUrl || default); connects to nothing. The shipped client defaults to the public engine on Veron, never local inference (Windy Talk, Hub 10-02)." + exemption: owner-approved + approved_by: windy-hub + approved_on: 2026-10-02 + expires: 2026-12-31