compute-guard: gatekeeper rules (Mind 10-02) + allow-list exemptions that expire
New kinds: voice-ai host/key (Deepgram, ElevenLabs, Cartesia, PlayHT, Resemble, HeyGen, Google Vision/Speech/TTS, AWS Transcribe/Polly), cloudflare workers ai (REST /ai/ + wrangler [ai] binding), talk engine port (:8791/:8788/:8794/:8099). Own kinds so they roll out WARN-first via COMPUTE_GUARD_WARN_KINDS. Allow entries now need a named exemption (local-user-hardware | owner-approved | compute-door | guard-self) and an expires date; expired entries stop excusing code and are reported. ci-hygiene keeps its own (non-strict) format. Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
This commit is contained in:
@@ -86,7 +86,7 @@ def test_warn_mode_never_turns_red(monkeypatch):
|
||||
def test_allow_file_is_line_scoped_exceptions_only():
|
||||
"""Every exception is line-scoped (`matches`), so an allowed file can't hide a
|
||||
NEW floating install or docker step. Today: windy-pro's if:false deploy job."""
|
||||
allow = hy.cg.load_allow(hy.ALLOW_FILE)
|
||||
allow = hy.cg.load_allow(hy.ALLOW_FILE, strict=False)
|
||||
assert [(e["repo"], e["paths"]) for e in allow] == [("windy-pro", [".github/workflows/ci.yml"])]
|
||||
assert all(e.get("matches") for e in allow)
|
||||
ok = " run: docker build -f account-server/Dockerfile -t windy-pro:${{ github.sha }} ."
|
||||
|
||||
Reference in New Issue
Block a user