From cd0400c37108e0c46af1e1a121ce9fd07900c0c4 Mon Sep 17 00:00:00 2001 From: Kit OC5 Date: Thu, 1 Oct 2026 03:36:11 -0400 Subject: [PATCH] compute-guard: WARN (never red) on NEW references to Veron Ollama :11434 Grant via Boss 10-01: compute = Windy Mind (endpoint + key); do not call Veron Ollama directly. Judged on lines a PR adds only (not the baseline tree), never blocks even in MODE=block, windy-mind (the compute door) allowed. Co-Authored-By: Claude Sonnet 5.5 --- api/tests/test_compute_guard.py | 21 +++++++++++++++++++++ ci/compute-guard-allow.yml | 5 +++++ scripts/compute_guard.py | 14 +++++++++++++- 3 files changed, 39 insertions(+), 1 deletion(-) diff --git a/api/tests/test_compute_guard.py b/api/tests/test_compute_guard.py index 1995461..df09b5f 100644 --- a/api/tests/test_compute_guard.py +++ b/api/tests/test_compute_guard.py @@ -229,3 +229,24 @@ def test_block_mode_never_blocks_grant_owned(monkeypatch): assert state == "success" and desc.startswith("⚠ WARN (Grant-owned, not blocking): 1") and f is g lane = cg.Finding("a.py", 3, "provider host", "x") assert cg.status_for([lane], whole_tree=True, grant=[g])[0] == "failure" + + +def test_veron_ollama_warns_on_added_lines_and_never_blocks(monkeypatch): + hits = cg.scan_line("app/llm.py", 'OLLAMA = "http://192.168.1.73:11434/api/generate"') + assert [k for k, _ in hits] == ["veron ollama"] + assert cg.scan_line("app/llm.py", 'port = 114345') == [] # not the port + assert cg.scan_line("app/llm.py", "# was http://x:11434 (removed)") == [] # a comment is not a call + f = cg.Finding("app/llm.py", 7, "veron ollama", ":11434") + monkeypatch.setattr(cg, "MODE", "block") + state, desc, _ = cg.status_for([f], whole_tree=False) + assert state == "success" and desc.startswith("⚠ WARN: new Veron Ollama ref app/llm.py:7") + assert "Windy Mind" in desc and len(desc) <= 140 + hard = cg.Finding("app/llm.py", 1, "provider host", "api.openai.com") + assert cg.status_for([f, hard], whole_tree=False)[0] == "failure" # a real violation still blocks + + +def test_ollama_in_added_pr_lines_only(): + diff = ("+++ b/svc/client.py\n@@ -0,0 +1,2 @@\n+import httpx\n" + "+URL = 'http://veron:11434/api/chat'\n") + got = cg.parse_added("some-repo", diff, []) + assert [(f.kind, f.line) for f in got] == [("veron ollama", 2)] diff --git a/ci/compute-guard-allow.yml b/ci/compute-guard-allow.yml index c71832f..29f400a 100644 --- a/ci/compute-guard-allow.yml +++ b/ci/compute-guard-allow.yml @@ -45,3 +45,8 @@ allow: - repo: windy-git paths: ["scripts/compute_guard.py", "ci/compute-guard-allow.yml"] reason: "The guard's own pattern list and this file." + + - repo: windy-mind + paths: ["*"] + matches: [':11434'] + reason: "Windy Mind IS the compute door (endpoint + key); it may call Ollama. Only the Ollama port is allowed here, any provider host/SDK in Mind still flags." diff --git a/scripts/compute_guard.py b/scripts/compute_guard.py index e0b5ce0..5133591 100644 --- a/scripts/compute_guard.py +++ b/scripts/compute_guard.py @@ -63,6 +63,9 @@ JS_SDKS = (r"@anthropic-ai/sdk|openai|groq-sdk|@google/generative-ai|@google/gen RULES: list[tuple[str, re.Pattern]] = [ ("provider host", re.compile("|".join(re.escape(h) for h in HOSTS))), + # Grant via Boss 10-01: compute = Windy Mind. A NEW reference to an Ollama port (Veron's :11434) is a + # direct call around Mind's metering/caps. WARN-only, never red, and only for lines a PR ADDS. + ("veron ollama", re.compile(r"(?::|%3[aA])11434(?![0-9])")), ("provider key", re.compile(r"\b(?:" + "|".join(KEYS) + r")\b")), ("provider SDK", re.compile(rf"^\s*(?:from|import)\s+(?:{PY_SDKS})(?:\s|\.|$|,)")), ("provider SDK", re.compile(rf"""(?:from\s+|require\(\s*|import\(\s*)['"](?:{JS_SDKS})(?:/[^'"]*)?['"]""")), @@ -70,6 +73,9 @@ RULES: list[tuple[str, re.Pattern]] = [ ("provider SDK dep", re.compile(rf'''^\s*"(?:{JS_SDKS})"\s*:''')), ("provider SDK dep", re.compile(rf'''^\s*["']?(?:{PY_SDKS.replace(chr(92) + ".", "-")})(?:\[[^\]]*\])?\s*(?:[<>=~!]=?|["',]|$)''')), ] +# Kinds that never block (even in MODE=block) and are only judged on ADDED lines, never the baseline tree. +WARN_ONLY_KINDS = {"veron ollama"} +OLLAMA_MSG = "compute = Windy Mind (endpoint + key); do not call Veron's Ollama directly" DEP_FILES = re.compile(r"(^|/)(package\.json|requirements[^/]*\.txt|pyproject\.toml|setup\.cfg|Pipfile)$") # Never scanned: tests, docs, lockfiles, vendored/built code, CI config. @@ -253,7 +259,8 @@ def check(repo: str, sha: str, default_branch: str, is_default_head: bool) -> li allow = load_allow() fp = _fingerprint(allow) if is_default_head: - return cached_scan(f"tree:{repo}:{sha}:{fp}", lambda: scan_tree(repo, bare, sha, allow)) + return cached_scan(f"tree:{repo}:{sha}:{fp}", + lambda: [f for f in scan_tree(repo, bare, sha, allow) if f.kind not in WARN_ONLY_KINDS]) return cached_scan( f"pr:{repo}:{sha}:{fp}", lambda: scan_added(repo, bare, f"refs/heads/{default_branch}", sha, allow), @@ -268,6 +275,11 @@ def status_for(findings: list[Finding], whole_tree: bool, Grant-owned code (ci/grant-owned.yml): always WARN, never red (orchestrator 09-23: his desktop work is never blocked by us).""" scope = "in tree" if whole_tree else "added" + soft = [f for f in findings if f.kind in WARN_ONLY_KINDS] + findings = [f for f in findings if f.kind not in WARN_ONLY_KINDS] + if not findings and not grant and soft: + f = soft[0] + return "success", f"⚠ WARN: new Veron Ollama ref {f.path}:{f.line}. {OLLAMA_MSG}"[:140], f if not findings and grant: g, n = grant[0], len(grant) desc = (f"⚠ WARN (Grant-owned, not blocking): {n} direct AI-provider use{'s' if n > 1 else ''} "