diff --git a/api/tests/test_compute_guard.py b/api/tests/test_compute_guard.py index 8d7de8a..ea1da3e 100644 --- a/api/tests/test_compute_guard.py +++ b/api/tests/test_compute_guard.py @@ -133,7 +133,7 @@ def test_shipped_allow_file_is_valid_today(): ('u = f"https://api.cloudflare.com/client/v4/accounts/{a}/ai/run/@cf/m"', "cloudflare workers ai"), ('ENGINE = "http://10.0.0.5:8791/v1"', "talk engine port"), ('ENGINE = "http://h:8788/ws"', "talk engine port"), - ('x = "http://h:8099/health"', "talk engine port"), + ('x = "http://h:8794/health"', "talk engine port"), ]) def test_gatekeeper_rules_fire(text, kind): assert kind in [k for k, _ in cg.scan_line("app/x.py", text)] @@ -365,6 +365,8 @@ def test_findings_carry_kind_and_name_never_the_value_and_ports_skip_contracts() hits = cg.scan_line("app/x.py", line) assert [k for k, _ in hits] == [kind] assert all("SUPERSECRET" not in m and "VALUE" not in m for _, m in hits) - assert cg.scan_line("engine/contracts/ops.mcp.v1.json", '"url": "http://h:8099/x"') == [] - assert cg.scan_line("services/api/openapi/spec.json", '"url": "http://h:8099/x"') == [] - assert [k for k, _ in cg.scan_line("deploy/docker-compose.yml", " - 8099:8099 # :8099")] == ["talk engine port"] + assert cg.scan_line("engine/contracts/ops.mcp.v1.json", '"url": "http://h:8791/x"') == [] + assert cg.scan_line("services/api/openapi/spec.json", '"url": "http://h:8791/x"') == [] + assert [k for k, _ in cg.scan_line("deploy/docker-compose.yml", " - 8791:8791 # :8791")] == ["talk engine port"] + # :8099 is windy-pro's OLD translate-api / cloud-storage service, NOT the Talk engine (Hub 10-02): not flagged + assert cg.scan_line("deploy/docker-compose.yml", " - 8099:8099 # translate-api:8099") == [] diff --git a/ci/compute-guard-allow.yml b/ci/compute-guard-allow.yml index d71a890..2de83a2 100644 --- a/ci/compute-guard-allow.yml +++ b/ci/compute-guard-allow.yml @@ -83,3 +83,12 @@ allow: reason: "Windy Mind IS the compute door (endpoint + key); it may call Ollama. Only the Ollama port is allowed here, any provider host/SDK in Mind still flags." exemption: compute-door expires: 2027-10-02 + + - repo: windy-pro + paths: [".env.example"] + matches: ['DEEPGRAM_API_KEY'] + reason: "Template line (name only, no value) for the existing user-own-key Deepgram feature in Word's Settings. Mind's migration removes the feature and then this line (Hub classification 10-02)." + exemption: owner-approved + approved_by: windy-hub + approved_on: 2026-10-02 + expires: 2026-12-31 diff --git a/scripts/compute_guard.py b/scripts/compute_guard.py index e01cae6..88d22b7 100644 --- a/scripts/compute_guard.py +++ b/scripts/compute_guard.py @@ -88,7 +88,7 @@ RULES: list[tuple[str, re.Pattern]] = [ ("voice-ai host", re.compile(r"(?:transcribe|polly)\.[a-z0-9-]+\.amazonaws\.com")), ("provider host", re.compile(r"(?:bedrock-runtime|bedrock)\.[a-z0-9-]+\.amazonaws\.com")), ("cloudflare workers ai", re.compile(r"api\.cloudflare\.com/client/v4/accounts/[^\s'\"/]+/ai/")), - ("talk engine port", re.compile(r"(?::|%3[aA])(?:8791|8788|8794|8099)(?![0-9])")), + ("talk engine port", re.compile(r"(?::|%3[aA])(?:8791|8788|8794)(?![0-9])")), ("workers ai binding", WRANGLER_AI), ("provider key", re.compile(r"\b(?:" + "|".join(KEYS) + r")\b")), ("provider SDK", re.compile(rf"^\s*(?:from|import)\s+(?:{PY_SDKS})(?:\s|\.|$|,)")), @@ -225,7 +225,7 @@ def scan_tree(repo: str, bare: Path, sha: str, allow: list[dict], *, line_fn=Non "anthropic", "openai", "groq", "mistral", "generativeai", "genai", "cohere", "together", "cerebras", "litellm", "deepgram", "elevenlabs", "cartesia", "play\\.ht", "resemble", "heygen", "googleapis\\.com", "amazonaws\\.com", "api\\.cloudflare\\.com", ":8791", ":8788", - ":8794", ":8099", "%3[aA]87", "%3[aA]8099", r"^\s*\[ai\]", '"ai"']) + ":8794", "%3[aA]87", r"^\s*\[ai\]", '"ai"']) try: out = _git(bare, "grep", "-nIE", "-e", pre, sha, "--", ".") except subprocess.CalledProcessError as e: