Hub decision 10-02 (alternative B, rule stays strict): registry tools/r2-provision.sh :8788 is a dev origin in an
R2 CORS rule; windytalk engine/server/systemd/stress ports are Talk's own engines (owner-approved, NOT compute-door,
a real bypass to be put behind Mind). approved_by windy-hub, expires 2026-12-31. Client-side files pending Talk.
Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
Hub classification 10-02: :8099 in windy-pro is the OLD translate-api / cloud-storage service, not Windy Talk
(verified: windytalk has no :8099, only lockfile hash fragments). DEEPGRAM_API_KEY in windy-pro .env.example is
a template line for the user-own-key Deepgram feature: owner-approved, approved_by windy-hub, expires 2026-12-31.
Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
- non-structural exemptions need approved_by (windy-hub|windy-mind) and expire within 90 days;
a longer amnesty simply does not apply and is reported (OVER-CAP). compute-door/guard-self: yearly.
- .github/CODEOWNERS on the allow-lists + guard.
- engine-port rule skips contracts/schemas/specs/openapi dirs and *.json (53 baseline hits, was 57).
- tests: findings carry kind+name never the value; shipped allow file obeys its own rules.
Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
New kinds: voice-ai host/key (Deepgram, ElevenLabs, Cartesia, PlayHT, Resemble, HeyGen, Google
Vision/Speech/TTS, AWS Transcribe/Polly), cloudflare workers ai (REST /ai/ + wrangler [ai] binding),
talk engine port (:8791/:8788/:8794/:8099). Own kinds so they roll out WARN-first via
COMPUTE_GUARD_WARN_KINDS. Allow entries now need a named exemption (local-user-hardware |
owner-approved | compute-door | guard-self) and an expires date; expired entries stop excusing
code and are reported. ci-hygiene keeps its own (non-strict) format.
Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
Grant via Boss 10-01: compute = Windy Mind (endpoint + key); do not call Veron Ollama directly.
Judged on lines a PR adds only (not the baseline tree), never blocks even in MODE=block,
windy-mind (the compute door) allowed.
Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
Allow entries may carry matches: (regexes); then only matching lines are
allowed, so an allowed file can't smuggle in a new call. windy-pro #609
MindKeychain.jsx: openrouter.ai/auth? and /api/v1/auth/keys (BYOK key
acquisition via OAuth PKCE, no inference; successor of the MindPanel
allow, ADR-064). An inference call in the same file still flags (tested).
Orchestrator-approved.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Grant's rule (09-23): every model call goes through Windy Mind. The bridge
now posts windy-git/compute-guard on every PR head (lines the PR ADDS vs its
merge-base) and default-branch head (whole tree): provider hosts, provider
SDK imports/deps and raw provider key names. Warn-only: success + "⚠ WARN"
and a link to the first hit; COMPUTE_GUARD_MODE=block turns it red later.
Exceptions live in ci/compute-guard-allow.yml, each with a reason (Mind
itself, user-BYOK windy-agent / windy-code extension / windy-pro desktop +
MindPanel, windy-connect config writers). Tests, docs, comments, lockfiles,
vendored code and CI config are never scanned. Reads the sync's bare clones
(no docker exec); cached per (repo, sha, rules). Non-fatal; never a fake OK.
First cases = COMPUTE_BYPASS_AUDIT.md. Today on default branches: 38
findings in 3 repos (windy-chat audit #2, windy-pro account-server #3/#4,
windytalk reference/), 0 elsewhere.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>