1 Commits

Author SHA1 Message Date
Kit OC5
a2daca61ef ci: mount windy-pro's read-only build inputs into dind; allow exactly that path for jobs
Non-secret inputs git-ignored in windy-pro (models, linux-x64 portable
bundle, enter-monitor build) that build-desktop needs. Mounted :ro into
dind; valid_volumes allows only /ci-inputs/windy-pro; refresh-ci-inputs.sh
copies them from the frozen release clone (read-only on the source).
Invariant I-5 narrowed, not dropped: exactly that one path, read-only in
dind, no other service mounts it, still no docker socket (proven to fail
on :rw). Orchestrator-approved (option a). Applied in an idle window.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2026-09-23 14:56:48 -04:00
16 changed files with 34 additions and 2199 deletions

View File

@@ -51,10 +51,9 @@ jobs:
- name: install
run: |
python3 --version
# From uv.lock, never floating: CI tests exactly what the image ships.
# --locked also FAILS if pyproject.toml changed without re-locking.
python3 -m pip install -q uv==0.12.5
uv sync --locked --extra dev
python3 -m venv .venv
.venv/bin/pip install -q --upgrade pip
.venv/bin/pip install -e ".[dev]"
- name: lint
run: .venv/bin/ruff check api scripts

View File

@@ -10,19 +10,10 @@ WORKDIR /app
RUN apt-get update && apt-get install -y --no-install-recommends git curl \
&& rm -rf /var/lib/apt/lists/*
# Dependencies come from uv.lock, hash-pinned, never "latest at build time".
# Floating installs meant a rebuild could ship different fastapi/starlette/
# pydantic than CI tested (Windy Cloud's OpenAPI drift, 09-23). The lock was
# cut to exactly what prod ran then. uv only exports; pip installs, so the
# image layout (system python, uvicorn on PATH) is unchanged.
COPY --from=ghcr.io/astral-sh/uv:0.12.5 /uv /usr/local/bin/uv
COPY pyproject.toml uv.lock ./
RUN uv export --frozen --no-dev --no-emit-project -o /tmp/requirements.txt \
&& pip install --no-cache-dir --require-hashes -r /tmp/requirements.txt \
&& rm /tmp/requirements.txt
COPY api ./api
RUN pip install --no-cache-dir --no-deps -e .
COPY pyproject.toml ./
RUN pip install --no-cache-dir -e .
COPY api ./api
COPY alembic ./alembic
COPY alembic.ini ./
COPY scripts ./scripts

View File

@@ -1,118 +0,0 @@
"""CI hygiene guard (house rule 6): lockfile-only installs, no host-port services."""
from __future__ import annotations
import importlib.util
import sys
from pathlib import Path
import pytest
ROOT = Path(__file__).resolve().parents[2]
sys.path.insert(0, str(ROOT / "scripts"))
_spec = importlib.util.spec_from_file_location("ci_hygiene", ROOT / "scripts" / "ci_hygiene.py")
hy = importlib.util.module_from_spec(_spec)
sys.modules["ci_hygiene"] = hy
_spec.loader.exec_module(hy)
WF = ".github/workflows/ci.yml"
@pytest.mark.parametrize("path, text", [
(WF, " .venv/bin/pip install -e \".[dev]\""), # windy-git's own, before e64a1b5
("Dockerfile", "RUN pip install --no-cache-dir -e ."), # windy-git image, before e64a1b5
(WF, " - run: uv pip install -e \".[dev]\""), # WindyCloud #109's CI
(WF, " run: pip install fastapi uvicorn"),
(WF, " - run: uv sync --all-extras"), # windy-mind style, not locked
(WF, " - run: npm install"), # windy-drops / windytalk
(WF, " - run: npm install --no-save --no-audit --no-fund jsdom"), # windy-pro reality-check
(WF, " - run: yarn install"),
(WF, " - run: cd web && pnpm install"),
("docker/api.Dockerfile", "RUN apt-get update && pip install requests"),
])
def test_floating_installs_are_flagged(path, text):
assert [k for k, _ in hy.scan_line(path, text)] == ["floating install"]
@pytest.mark.parametrize("path, text", [
(WF, " python3 -m pip install -q uv==0.12.5"), # exact tool pin
(WF, " uv sync --locked --extra dev"),
(WF, " - run: uv sync --frozen"),
(WF, " - run: npm ci"),
(WF, " - run: npm install --no-save jsdom@24.1.0"),
(WF, " - run: pip install -r requirements.lock --require-hashes"),
(WF, " - run: pip install -r requirements.txt"),
("Dockerfile", " && pip install --no-cache-dir --require-hashes -r /tmp/requirements.txt \\\\"),
("Dockerfile", "RUN pip install --no-cache-dir --no-deps -e ."), # project only, deps from the lock
(WF, " .venv/bin/pip install -q --upgrade pip"),
(WF, " - run: yarn install --frozen-lockfile"),
(WF, " # - run: npm install (commented out)"),
(WF, " - run: echo 'pip is great'"),
])
def test_locked_or_pinned_installs_pass(path, text):
assert hy.scan_line(path, text) == []
@pytest.mark.parametrize("text, port", [
(" - 5432:5432", "5432"), # windy-mind / eternitas (collided 09-23)
(" - '15432:5432'", "15432"), # WindyCloud
(' - "6379:6379"', "6379"),
])
def test_services_publishing_a_host_port_are_flagged(text, port):
[(kind, match)] = hy.scan_line(WF, text)
assert kind == "host port" and port in match
def test_host_port_rule_is_for_workflows_only():
assert hy.scan_line("docker-compose.yml", " - 5432:5432") == []
@pytest.mark.parametrize("path, ok", [
(".github/workflows/ci.yml", True), (".gitea/workflows/check.yaml", True),
("Dockerfile", True), ("api/Dockerfile.prod", True), ("docker/web.Dockerfile", True),
("scripts/setup.sh", False), ("README.md", False), ("node_modules/x/Dockerfile", False),
(".github/lint/x.yml", False),
])
def test_scope_is_ci_workflows_and_dockerfiles(path, ok):
assert hy.path_ok(path) is ok
def test_warn_mode_never_turns_red(monkeypatch):
monkeypatch.setattr(hy, "MODE", "warn")
state, desc, f = hy.status_for([hy.cg.Finding(WF, 12, "floating install", "npm install (use npm ci)")], True)
assert state == "success" and desc.startswith("⚠ WARN (not blocking): 1 CI hygiene issue in CI/Dockerfiles")
def test_allow_file_loads_and_is_empty_today():
assert hy.cg.load_allow(hy.ALLOW_FILE) == []
@pytest.mark.parametrize("path, text, want", [
("Dockerfile", "COPY --from=ghcr.io/astral-sh/uv:latest /uv /usr/local/bin/uv", "ghcr.io/astral-sh/uv:latest"), # Mail #147
("Dockerfile", "FROM python:latest", "python:latest"),
("Dockerfile", "FROM --platform=linux/amd64 node:latest AS web", "node:latest"),
(WF, " image: postgres:latest", "postgres:latest"),
(WF, " - uses: docker://ghcr.io/foo/bar:latest", "ghcr.io/foo/bar:latest"),
])
def test_latest_images_are_flagged(path, text, want):
hits = hy.scan_line(path, text)
assert ("floating image", want) in hits
@pytest.mark.parametrize("text", [
"COPY pyproject.toml uv.lock* ./", # Windy Mail #147
"COPY package.json package-lock.json* ./",
])
def test_optional_lock_globs_are_flagged(text):
assert [k for k, _ in hy.scan_line("Dockerfile", text)] == ["optional lock"]
@pytest.mark.parametrize("path, text", [
("Dockerfile", "COPY --from=ghcr.io/astral-sh/uv:0.12.5 /uv /usr/local/bin/uv"),
("Dockerfile", "FROM python:3.12-slim"),
("Dockerfile", "COPY pyproject.toml uv.lock ./"),
("Dockerfile", "COPY src/*.py ./src/"),
("Dockerfile", "RUN echo latest release notes"),
])
def test_pinned_images_and_real_locks_pass(path, text):
assert hy.scan_line(path, text) == []

View File

@@ -182,41 +182,3 @@ def test_code_with_a_trailing_comment_still_counts():
def test_windy_pro_desktop_is_byok_but_the_account_server_is_not():
assert cg.allowed("windy-pro", "src/client/desktop/main.js", ALLOW)
assert not cg.allowed("windy-pro", "account-server/src/routes/translations.ts", ALLOW)
def test_a_commit_not_fetched_yet_is_skipped_not_an_error(tmp_path, monkeypatch):
bare, sha = _repo(tmp_path, {"app/llm.py": "import anthropic\n"})
monkeypatch.setattr(cg, "WORK", tmp_path)
monkeypatch.setattr(cg, "CACHE", tmp_path / "cache.json")
(tmp_path / "windy-chat.git").symlink_to(bare)
assert cg.check("windy-chat", "f" * 40, "main", True) is None # pushed after the fetch
assert [f.kind for f in cg.check("windy-chat", sha, "main", True)] == ["provider SDK"]
KEYCHAIN = "src/client/web/src/pages/panels/MindKeychain.jsx"
def test_scoped_allow_admits_only_the_oauth_endpoints():
ok = [
" window.location.href = `https://openrouter.ai/auth?callback_url=${encodeURIComponent(callback)}`",
" const res = await fetch('https://openrouter.ai/api/v1/auth/keys', {",
]
for line in ok:
assert cg.allowed("windy-pro", KEYCHAIN, ALLOW, line)
# an inference call smuggled into the same file still flags
assert not cg.allowed("windy-pro", KEYCHAIN, ALLOW,
" await fetch('https://openrouter.ai/api/v1/chat/completions', {")
# a scoped entry never allows a line it can't see
assert not cg.allowed("windy-pro", KEYCHAIN, ALLOW)
def test_scoped_allow_in_a_real_diff():
diff = f"""--- /dev/null
+++ b/{KEYCHAIN}
@@ -0,0 +1,3 @@
+ window.location.href = `https://openrouter.ai/auth?callback_url=x`
+ const res = await fetch('https://openrouter.ai/api/v1/auth/keys', {{
+ await fetch('https://openrouter.ai/api/v1/chat/completions', {{
"""
fs = cg.parse_added("windy-pro", diff, ALLOW)
assert [(f.line, f.match) for f in fs] == [(3, "openrouter.ai")]

View File

@@ -1,66 +0,0 @@
"""guards_report: job attribution and the Grant-owned split."""
from __future__ import annotations
import importlib.util
import sys
from pathlib import Path
import yaml
ROOT = Path(__file__).resolve().parents[2]
sys.path.insert(0, str(ROOT / "scripts"))
_spec = importlib.util.spec_from_file_location("guards_report", ROOT / "scripts" / "guards_report.py")
gr = importlib.util.module_from_spec(_spec)
sys.modules["guards_report"] = gr
_spec.loader.exec_module(gr)
OWNED = yaml.safe_load((ROOT / "ci" / "grant-owned.yml").read_text())["grant_owned"]
WF = """name: CI
on:
push:
jobs:
reality-check:
runs-on: x
steps:
- run: npm install jsdom
test-backend:
runs-on: x
steps:
- run: pip install pytest
"""
def test_job_of_attributes_lines_to_their_job():
assert gr.job_of(WF, 3) is None # `on:` block, not a job
assert gr.job_of(WF, 8) == "reality-check"
assert gr.job_of(WF, 12) == "test-backend"
def test_windy_pro_desktop_jobs_and_paths_are_grant_owned():
ci = ".github/workflows/ci.yml"
assert gr.grant_owned("windy-pro", ci, "reality-check", OWNED)
assert gr.grant_owned("windy-pro", ci, "build-electron", OWNED)
assert not gr.grant_owned("windy-pro", ci, "test-backend", OWNED) # server side: 8c
assert gr.grant_owned("windy-pro", ".github/workflows/release-mac.yml", None, OWNED)
assert gr.grant_owned("windy-pro", "src/client/desktop/main.js", None, OWNED)
assert not gr.grant_owned("windy-pro", "services/account-server/Dockerfile", None, OWNED)
assert not gr.grant_owned("windy-chat", "src/client/desktop/main.js", None, OWNED)
def test_render_splits_lane_and_grant_counts():
F = gr.cg.Finding
res = {"windy-pro": {"sha": "a" * 40, "compute": [],
"hygiene": [(F("ci.yml", 8, "floating install", "npm install"), "reality-check", True),
(F("ci.yml", 12, "floating install", "pip x"), "test-backend", False)]},
"windy-git": {"sha": "b" * 40, "compute": [], "hygiene": []}}
md = gr.render(res)
assert "| ci-hygiene (house rule 6) | 1 | 1 | ❌ not yet |" in md
assert "| compute-guard (Mind is the only door) | 0 | 0 | ✅ YES |" in md
assert "| windy-git | bbbbbbb | 0 | 0 | clean ✅ |" in md
assert "(job reality-check)" in md
def test_windy_pro_root_env_example_is_grant_owned_but_not_the_account_servers():
assert gr.grant_owned("windy-pro", ".env.example", None, OWNED)
assert not gr.grant_owned("windy-pro", "account-server/.env.example", None, OWNED)

View File

@@ -382,32 +382,3 @@ def test_guard_that_cannot_run_posts_nothing(fake, monkeypatch):
monkeypatch.setitem(sys.modules, "compute_guard", _Guard(None))
bridge.post_compute_guard("windy-chat", SHA, "main", True)
assert f.posted == []
def test_ci_hygiene_posts_under_its_own_context(fake, monkeypatch):
f = fake(statuses=[{"context": "windy-git/compute-guard", "state": "success", "description": "WARN 1"}])
monkeypatch.setitem(sys.modules, "ci_hygiene", _Guard([_F()]))
bridge.post_ci_hygiene("windy-chat", SHA, "main", True)
# the compute-guard status with the same description must not suppress it
assert [(p["context"], p["description"]) for p in f.posted] == [("windy-git/ci-hygiene", "WARN 1")]
def test_retargeted_pr_gets_a_fresh_mirror_on_the_new_base(fake):
# eternitas #167: stacked on fix/one-hallway, retargeted to main on GitHub.
gh = [{"number": 167, "title": "feat", "html_url": "u",
"head": {"ref": "feat/x", "sha": SHA, "repo": {"full_name": f"{bridge.GH_OWNER}/eternitas"}},
"base": {"ref": "main"}}]
wg = [{"number": 9, "title": "[GH#167] feat", "base": {"ref": "fix/one-hallway"}}]
f = fake(gh_prs=gh, wg_prs=wg)
assert bridge.sync_prs("eternitas") == [SHA]
assert f.closed == [f"/repos/{bridge.WG_OWNER}/eternitas/pulls/9"]
assert [(o["base"], o["head"]) for o in f.opened] == [("main", "feat/x")]
def test_unchanged_base_leaves_the_mirror_alone(fake):
gh = [{"number": 5, "title": "t", "html_url": "u",
"head": {"ref": "b", "sha": SHA, "repo": {"full_name": f"{bridge.GH_OWNER}/windy-chat"}},
"base": {"ref": "main"}}]
f = fake(gh_prs=gh, wg_prs=[{"number": 3, "title": "[GH#5] t", "base": {"ref": "main"}}])
bridge.sync_prs("windy-chat")
assert f.closed == [] and f.opened == []

View File

@@ -1,5 +0,0 @@
# CI hygiene allow-list: installs that may float, or services that may publish
# a host port. House rule 6 (09-23): installs come from a lockfile. Every entry
# is an exception and MUST say why. Paths are fnmatch globs from the repo root.
# Owner: Windy Git lane (13); changes go through the orchestrator.
allow: []

View File

@@ -35,13 +35,6 @@ allow:
paths: ["src/client/web/src/pages/panels/MindPanel.jsx"]
reason: "Validates the USER's own OpenRouter key for BYOK (audit #10); spends no house money."
- repo: windy-pro
paths: ["src/client/web/src/pages/panels/MindKeychain.jsx"]
# ONLY these two endpoints: any other openrouter.ai call in this file (e.g.
# /api/v1/chat, i.e. inference) still flags. Orchestrator-approved 09-23.
matches: ['openrouter\.ai/auth\?', 'openrouter\.ai/api/v1/auth/keys']
reason: "BYOK key acquisition via OpenRouter OAuth PKCE; no inference; successor of MindPanel allow (ADR-064)."
- repo: windy-git
paths: ["scripts/compute_guard.py", "ci/compute-guard-allow.yml"]
reason: "The guard's own pattern list and this file."

View File

@@ -1,19 +0,0 @@
# Code Grant owns directly (orchestrator, 09-23): guard findings here are listed
# SEPARATELY in the guards status page and never hold up "block". Changes to
# these files are proposals for Grant / Windy Word 44, not a lane's fix.
grant_owned:
- repo: windy-pro
reason: "Windy Word desktop (Electron) + its release/installer builds: Grant's, built from the Mac mini."
paths:
- "src/client/desktop/*"
# ROOT .env.example only (exact path): documents the desktop app's BYOK dev
# fallback keys; the hub reads neither (8c, 09-23). account-server/.env.example
# is NOT matched and stays the hub lane's.
- ".env.example"
- "installer-v2/*"
- ".github/workflows/build-windows.yml"
- ".github/workflows/release-mac.yml"
- ".github/workflows/build-installer.yml"
- ".github/workflows/build-offline-installers.yml"
jobs:
".github/workflows/ci.yml": [reality-check, build-desktop, test-installer, build-electron]

View File

@@ -7,7 +7,6 @@
<div class="wg-cta">
{{if not .IsSigned}}
<a class="ui primary button" href="{{AppSubUrl}}/user/login">Sign in with Windy</a>
<p class="wg-note" style="margin-top:.9rem;font-size:.95rem;opacity:.75">Invite only at launch: new accounts are not open yet.</p>
{{else}}
<a class="ui primary button" href="{{AppSubUrl}}/{{.SignedUser.Name}}?tab=repositories">Your repositories</a>
{{end}}
@@ -19,8 +18,8 @@
<p>Git and LFS over Windy Cloud storage. Source, weights and adapters live side by side.</p></div>
<div class="wg-card"><h3>Agents are first-class</h3>
<p>An agent signs in with its own Eternitas passport — not a human's borrowed token — and its work is attributable to it.</p></div>
<div class="wg-card"><h3>Invite only, for now</h3>
<p>Windy Git accounts are by invitation while we launch. If you've been invited, you sign in with your Windy account, with no second password.</p></div>
<div class="wg-card"><h3>Your account, no second password</h3>
<p>Sign in with the Windy account you already have. Nothing new to remember.</p></div>
<div class="wg-card"><h3>Kept, and kept elsewhere</h3>
<p>Every repository is bundled nightly to off-site storage, and the restore is rehearsed rather than assumed.</p></div>
</div>

View File

@@ -1,196 +0,0 @@
#!/usr/bin/env python3
"""CI hygiene guard: installs come from a lockfile, never "latest" (house rule 6).
A floating install lets CI test different versions than prod ships, and a
rebuild silently changes prod. Windy Cloud's OpenAPI test failed on exactly
that (fastapi 0.141.1 in CI vs 0.136.0 on the dev box) and all three Cloud
cells floated in prod. Also flags services that publish a HOST port: every
CI job shares one dind daemon, so two jobs publishing 5432 collide ("port is
already allocated", Windy Mind runs 147/176).
WARN-ONLY (`windy-git/ci-hygiene`, green + "⚠ WARN"); CI_HYGIENE_MODE=block
turns it red once the lanes report clean. Scans CI workflow files and
Dockerfiles only. PR heads: lines the PR adds. Default branch: every line.
OK (not flagged):
pip / uv pip install -r FILE (with or without --require-hashes), --no-deps,
exact pins (tool==1.2.3), pip/setuptools/wheel upgrades
uv sync --locked | --frozen npm ci
npm install pkg@1.2.3 (every package exact-pinned)
yarn install --frozen-lockfile / --immutable pnpm install --frozen-lockfile
Also flagged: `:latest` images (FROM / COPY --from / image: / docker://) and
`COPY uv.lock* ...`-style globs that build without the lock (Windy Mail #147).
Exceptions: ci/ci-hygiene-allow.yml, one reason per entry.
python3 scripts/ci_hygiene.py report [repo ...]
"""
from __future__ import annotations
import hashlib
import os
import re
import shlex
import sys
from pathlib import Path
sys.path.insert(0, str(Path(__file__).resolve().parent))
import compute_guard as cg # noqa: E402 (shared walker, cache and allow-list loader)
ROOT = Path(__file__).resolve().parents[1]
ALLOW_FILE = Path(os.environ.get("CI_HYGIENE_ALLOW", ROOT / "ci" / "ci-hygiene-allow.yml"))
MODE = os.environ.get("CI_HYGIENE_MODE", "warn")
# CI workflow files and Dockerfiles; never vendored copies.
INCLUDE = re.compile(r"(^|/)\.(github|gitea)/workflows/[^/]+\.ya?ml$|(^|/)(Dockerfile[^/]*|[^/]+\.Dockerfile)$")
NEVER = re.compile(r"(^|/)(node_modules|vendor|third_party)/")
PREFILTER = (r"pip3? install|pip install|uv sync|npm (install|i )|yarn install|pnpm install"
r"|^\s*-\s*['\"]?[0-9]+:[0-9]+|:latest|lock[^ ]*\*")
TOOLING = {"pip", "setuptools", "wheel"}
DOCKER_FILE = re.compile(r"(^|/)(Dockerfile[^/]*|[^/]+\.Dockerfile)$")
LATEST = re.compile(r"(?:^\s*FROM\s+(?:--platform=\S+\s+)?|--from=|image:\s*['\"]?|docker://)([\w./-]+):latest\b", re.I)
LOCKNAME = re.compile(r"(uv\.lock|poetry\.lock|package-lock\.json|pnpm-lock\.yaml|yarn\.lock|requirements[^ ]*\.(txt|lock))", re.I)
EXACT_PY = re.compile(r"^[A-Za-z0-9._-]+(\[[^\]]*\])?==[A-Za-z0-9.+!-]+$")
EXACT_NPM = re.compile(r"^(@[^/@]+/)?[^/@]+@\d+\.\d+\.\d+([-+][0-9A-Za-z.-]+)?$")
HOST_PORT = re.compile(r"^\s*-\s*['\"]?(\d{2,5}):(\d{2,5})['\"]?\s*(#.*)?$")
PIP_VALUE_FLAGS = {"-c", "--constraint", "-i", "--index-url", "--extra-index-url", "-f",
"--find-links", "--target", "-t", "--python", "--prefix", "--root", "--platform",
"--python-version", "--implementation", "--abi", "--only-binary", "--no-binary"}
def path_ok(path: str) -> bool:
return bool(INCLUDE.search(path)) and not NEVER.search(path)
def _commands(text: str) -> list[list[str]]:
"""Split a shell line into simple commands (&&, ||, ;, |), tokenized."""
out = []
for part in re.split(r"&&|\|\||;|\|", text):
try:
toks = shlex.split(part, comments=True)
except ValueError:
toks = part.split()
# Dockerfile RUN prefix / sudo / env-prefixed assignments
while toks and (toks[0] in ("RUN", "sudo", "exec", "-", "run:", "command:")
or re.match(r"^[A-Z_][A-Z0-9_]*=", toks[0])):
toks = toks[1:]
if toks:
out.append(toks)
return out
def _pip_problem(args: list[str]) -> str | None:
if "-r" in args or "--requirement" in args or any(a.startswith("--requirement=") for a in args):
return None
if "--no-deps" in args:
return None
pkgs, skip = [], False
for a in args:
if skip:
skip = False
continue
if a in PIP_VALUE_FLAGS:
skip = True
continue
if a.startswith("-") and a not in ("-e", "--editable"):
continue
if a in ("-e", "--editable"):
continue
pkgs.append(a)
loose = [p for p in pkgs if not EXACT_PY.match(p) and p.split("[")[0].lower() not in TOOLING]
if loose:
return f"floating pip install: {' '.join(loose)[:40]}"
return None
def scan_line(path: str, text: str) -> list[tuple[str, str]]:
if cg.COMMENT.match(text):
return []
hits = []
if "/workflows/" in path and HOST_PORT.match(text):
hits.append(("host port", f"service publishes host port {HOST_PORT.match(text).group(1)} (shared dind)"))
return hits
# Windy Mail #147: a `:latest` build/tool image floats exactly like an
# unpinned package, and `COPY uv.lock* ./` builds WITHOUT the lock when it
# is missing instead of failing.
m = LATEST.search(text)
if m:
hits.append(("floating image", f"{m.group(1)}:latest"))
if DOCKER_FILE.search(path) and re.match(r"^\s*COPY\b", text, re.I):
globbed = [t for t in text.split() if "*" in t and LOCKNAME.search(t)]
if globbed:
hits.append(("optional lock", f"COPY {globbed[0]} (must fail if the lock is missing)"))
for toks in _commands(text):
low = [t.lower() for t in toks]
# pip install / python -m pip install / uv pip install
for i in range(len(low) - 1):
if os.path.basename(low[i]) in ("pip", "pip3") and low[i + 1] == "install":
prob = _pip_problem(toks[i + 2:])
if prob:
hits.append(("floating install", prob))
break
if low[:2] == ["uv", "sync"] and not ({"--locked", "--frozen"} & set(low)):
hits.append(("floating install", "uv sync without --locked/--frozen"))
if low[:1] == ["npm"] and len(low) > 1 and low[1] in ("install", "i", "add"):
pkgs = [t for t in toks[2:] if not t.startswith("-")]
if not pkgs or not all(EXACT_NPM.match(p) for p in pkgs):
hits.append(("floating install", f"npm {low[1]} {' '.join(pkgs)[:30]}".strip() + " (use npm ci)"))
if low[:2] == ["yarn", "install"] and not ({"--frozen-lockfile", "--immutable"} & set(low)):
hits.append(("floating install", "yarn install without --frozen-lockfile"))
if low[:2] == ["pnpm", "install"] and "--frozen-lockfile" not in low:
hits.append(("floating install", "pnpm install without --frozen-lockfile"))
return hits
def check(repo: str, sha: str, default_branch: str, is_default_head: bool):
bare = cg.WORK / f"{repo}.git"
if not bare.is_dir() or not cg.fetched(bare, sha): # pushed after the fetch: next cycle
return None
allow = cg.load_allow(ALLOW_FILE)
rules = hashlib.sha256((PREFILTER + INCLUDE.pattern + EXACT_PY.pattern + EXACT_NPM.pattern).encode()).hexdigest()[:8]
fp = cg._fingerprint(allow) + ":" + rules # hashlib, not hash(): hash() is per-process random
kw = dict(line_fn=scan_line, path_ok=path_ok)
if is_default_head:
return cg.cached_scan(f"hyg-tree:{repo}:{sha}:{fp}",
lambda: cg.scan_tree(repo, bare, sha, allow, prefilter=PREFILTER, **kw))
return cg.cached_scan(f"hyg-pr:{repo}:{sha}:{fp}",
lambda: cg.scan_added(repo, bare, f"refs/heads/{default_branch}", sha, allow, **kw))
def status_for(findings, whole_tree: bool):
scope = "in CI/Dockerfiles" if whole_tree else "added"
if not findings:
return "success", f"OK: no floating install or host-port service {scope}", None
f = findings[0]
n = len(findings)
state = "failure" if MODE == "block" else "success"
lead = "BLOCKED" if MODE == "block" else "⚠ WARN (not blocking)"
return state, f"{lead}: {n} CI hygiene issue{'s' if n > 1 else ''} {scope}, e.g. {f.path}:{f.line} {f.match}"[:140], f
def report(repos: list[str]) -> int:
allow = cg.load_allow(ALLOW_FILE)
total = 0
for repo in repos:
bare = cg.WORK / f"{repo}.git"
if not bare.is_dir():
print(f"## {repo}: no sync clone, skipped")
continue
head = cg._git(bare, "symbolic-ref", "--short", "HEAD").strip()
sha = cg._git(bare, "rev-parse", head).strip()
fs = cg.scan_tree(repo, bare, sha, allow, line_fn=scan_line, path_ok=path_ok, prefilter=PREFILTER)
total += len(fs)
print(f"## {repo} ({head} {sha[:7]}): {len(fs)} issue(s)")
for f in fs:
print(f" {f.path}:{f.line} [{f.kind}] {f.match}")
print(f"TOTAL {total}")
return 0
if __name__ == "__main__":
if len(sys.argv) >= 2 and sys.argv[1] == "report":
default = os.environ.get("BRIDGE_REPOS", "").split() or sorted(
p.name.removesuffix(".git") for p in cg.WORK.glob("*.git"))
sys.exit(report(sys.argv[2:] or default))
sys.exit(__doc__)

View File

@@ -98,18 +98,9 @@ def load_allow(path: Path = ALLOW_FILE) -> list[dict]:
return entries
def allowed(repo: str, path: str, allow: list[dict], text: str | None = None) -> bool:
"""An entry may carry `matches:` (regexes): then only lines matching one of
them are allowed, so an allowed file can't smuggle in a NEW call (e.g. an
OAuth sign-in endpoint is allowed, an inference endpoint in the same file
still flags). Entries without `matches` cover the whole path."""
def allowed(repo: str, path: str, allow: list[dict]) -> bool:
for e in allow:
if e["repo"] != repo or not any(fnmatch.fnmatch(path, g) for g in e["paths"]):
continue
pats = e.get("matches")
if not pats:
return True
if text is not None and any(re.search(rx, text) for rx in pats):
if e["repo"] == repo and any(fnmatch.fnmatch(path, g) for g in e["paths"]):
return True
return False
@@ -139,20 +130,11 @@ def _git(bare: Path, *args: str) -> str:
).stdout
def _default_path_ok(path: str) -> bool:
return not SKIP.search(path)
def scan_tree(repo: str, bare: Path, sha: str, allow: list[dict], *, line_fn=None,
path_ok=None, prefilter: str | None = None) -> list[Finding]:
def scan_tree(repo: str, bare: Path, sha: str, allow: list[dict]) -> list[Finding]:
"""Every line in the tree at `sha` (default branch: the baseline)."""
# A cheap prefilter by git, then the real rules in Python.
# Other guards (ci_hygiene) reuse this walker with their own line rules.
line_fn = line_fn or scan_line
path_ok = path_ok or _default_path_ok
pre = prefilter or "|".join([re.escape(h) for h in HOSTS] + KEYS + [
"anthropic", "openai", "groq", "mistral", "generativeai", "genai", "cohere",
"together", "cerebras", "litellm"])
pre = "|".join([re.escape(h) for h in HOSTS] + KEYS + ["anthropic", "openai", "groq", "mistral",
"generativeai", "genai", "cohere", "together", "cerebras", "litellm"])
try:
out = _git(bare, "grep", "-nIE", "-e", pre, sha, "--", ".")
except subprocess.CalledProcessError as e:
@@ -166,26 +148,24 @@ def scan_tree(repo: str, bare: Path, sha: str, allow: list[dict], *, line_fn=Non
_, path, line, text = raw.split(":", 3)
except ValueError:
continue
if not path_ok(path) or allowed(repo, path, allow, text):
if SKIP.search(path) or allowed(repo, path, allow):
continue
for kind, match in line_fn(path, text):
for kind, match in scan_line(path, text):
found.append(Finding(path, int(line), kind, match))
return found
def scan_added(repo: str, bare: Path, base_ref: str, sha: str, allow: list[dict], **kw) -> list[Finding]:
def scan_added(repo: str, bare: Path, base_ref: str, sha: str, allow: list[dict]) -> list[Finding]:
"""Only the lines a PR adds, vs its merge-base with the default branch."""
mb = _git(bare, "merge-base", base_ref, sha).strip()
diff = _git(bare, "diff", "-U0", "--no-color", "--no-ext-diff", mb, sha)
return parse_added(repo, diff, allow, **kw)
return parse_added(repo, diff, allow)
HUNK = re.compile(r"^@@ -\d+(?:,\d+)? \+(\d+)(?:,\d+)? @@")
def parse_added(repo: str, diff: str, allow: list[dict], *, line_fn=None, path_ok=None) -> list[Finding]:
line_fn = line_fn or scan_line
path_ok = path_ok or _default_path_ok
def parse_added(repo: str, diff: str, allow: list[dict]) -> list[Finding]:
found, path, line = [], None, 0
for raw in diff.splitlines():
if raw.startswith("+++ "):
@@ -199,8 +179,8 @@ def parse_added(repo: str, diff: str, allow: list[dict], *, line_fn=None, path_o
if path is None or raw.startswith("--- "):
continue
if raw.startswith("+"):
if path_ok(path) and not allowed(repo, path, allow, raw[1:]):
for kind, match in line_fn(path, raw[1:]):
if not (SKIP.search(path) or allowed(repo, path, allow)):
for kind, match in scan_line(path, raw[1:]):
found.append(Finding(path, line, kind, match))
line += 1
return found
@@ -234,21 +214,10 @@ def cached_scan(key: str, fn) -> list[Finding]:
return result
def fetched(bare: Path, sha: str) -> bool:
"""Is `sha` in the sync clone yet? The bridge learns PR / default heads from
GitHub's API AFTER the sync fetched, so a push in between is simply not here
until the next 5-min cycle. That is a race, not an error: skip quietly."""
try:
_git(bare, "cat-file", "-e", f"{sha}^{{commit}}")
return True
except subprocess.CalledProcessError:
return False
def check(repo: str, sha: str, default_branch: str, is_default_head: bool) -> list[Finding] | None:
"""Findings for one commit, or None when the guard can't run (never a fake OK)."""
bare = WORK / f"{repo}.git"
if not bare.is_dir() or not fetched(bare, sha):
if not bare.is_dir():
return None
allow = load_allow()
fp = _fingerprint(allow)

View File

@@ -1,137 +0,0 @@
#!/usr/bin/env python3
"""Live status of the repo guards (compute-guard + ci-hygiene) as one markdown page.
Scans every bridged repo's DEFAULT branch with both guards and renders what is
left, per repo and owner lane. Findings in code Grant owns (ci/grant-owned.yml:
windy-pro's desktop app and its build jobs) are listed in their OWN section and
do not count against "ready to block": those are proposals for Grant, not a
lane's fix (orchestrator, 09-23).
sudo python3 scripts/guards_report.py > GUARDS_STATUS.md
"""
from __future__ import annotations
import fnmatch
import os
import re
import sys
import time
from pathlib import Path
import yaml
sys.path.insert(0, str(Path(__file__).resolve().parent))
import ci_hygiene as hy # noqa: E402
import compute_guard as cg # noqa: E402
ROOT = Path(__file__).resolve().parents[1]
OWNED = Path(os.environ.get("GRANT_OWNED", ROOT / "ci" / "grant-owned.yml"))
REPOS = os.environ.get("BRIDGE_REPOS", "").split() or [
"windy-chat", "windy-mail", "windy-calendar", "Windy-Clone", "WindyCloud", "windy-search",
"windy-connect", "windy-drops", "windy-code-web", "windy-code", "windy-traveler",
"windy-registry", "eternitas", "windy-translate", "windytranslate-site", "windytraveler-site",
"windy-hand", "windy-cloud-sites", "windy-cloud-domains", "windy-cloud-vps", "windytalk",
"windy-pro", "windy-mind", "windy-git"]
# Owner lane per repo = the session name to message (orchestrator routing, 09-23 ~22:45Z:
# hub/account-server/dashboard/site -> "Windy Hub"; windy-calendar only -> "Windy Calender";
# windy-admin/telemetry -> "Windy Admin"). windy-pro here = its server/web side; the desktop
# app is Grant-owned and listed in its own section below.
OWNERS = {
"windy-chat": "grantwhitmer-ca", "windy-mail": "Windy Mail", "windy-calendar": "Windy Calender",
"Windy-Clone": "Windy Clone", "WindyCloud": "Windy Cloud", "windy-cloud-sites": "Windy Cloud",
"windy-cloud-domains": "Windy Cloud", "windy-cloud-vps": "Windy Cloud", "windy-search": "Windy Search",
"windy-connect": "Windy Connect", "windy-drops": "Windy Drops", "windy-registry": "Windy Drops",
"windy-code-web": "Windy Code", "windy-code": "Windy Code", "windy-traveler": "Windy Traveler",
"windytraveler-site": "Windy Traveler", "eternitas": "Eternitas", "windy-translate": "Windy Translate",
"windytranslate-site": "Windy Translate", "windy-hand": "Windy Hand", "windytalk": "Windy Talk",
"windy-pro": "Windy Hub", "windy-mind": "WIndy Mind", "windy-git": "Windy Git"}
JOB = re.compile(r"^ ([A-Za-z0-9_-]+):\s*$")
def job_of(text: str, line: int) -> str | None:
"""The workflow job a line belongs to (2-space keys under `jobs:`)."""
in_jobs, job = False, None
for i, raw in enumerate(text.splitlines(), 1):
if raw.startswith("jobs:"):
in_jobs = True
elif in_jobs and JOB.match(raw):
job = JOB.match(raw).group(1)
elif raw and not raw[0].isspace() and not raw.startswith("jobs:"):
in_jobs = False
if i == line:
return job if in_jobs else None
return None
def grant_owned(repo: str, path: str, job: str | None, owned: list[dict]) -> bool:
for e in owned:
if e["repo"] != repo:
continue
if any(fnmatch.fnmatch(path, g) for g in e.get("paths") or []):
return True
if job and job in (e.get("jobs") or {}).get(path, []):
return True
return False
def scan(repo: str, owned: list[dict]):
bare = cg.WORK / f"{repo}.git"
if not bare.is_dir():
return None
head = cg._git(bare, "symbolic-ref", "--short", "HEAD").strip()
sha = cg._git(bare, "rev-parse", head).strip()
out = {"sha": sha, "compute": [], "hygiene": []}
texts: dict[str, str] = {}
for key, fs in (("compute", cg.check(repo, sha, head, True) or []),
("hygiene", hy.check(repo, sha, head, True) or [])):
for f in fs:
job = None
if "/workflows/" in f.path:
if f.path not in texts:
texts[f.path] = cg._git(bare, "show", f"{sha}:{f.path}")
job = job_of(texts[f.path], f.line)
out[key].append((f, job, grant_owned(repo, f.path, job, owned)))
return out
def render(results: dict) -> str:
now = time.strftime("%Y-%m-%d %H:%MZ", time.gmtime())
lane = {k: 0 for k in ("compute", "hygiene")}
grant = {k: 0 for k in ("compute", "hygiene")}
for r in results.values():
for k in lane:
lane[k] += sum(1 for _, _, g in r[k] if not g)
grant[k] += sum(1 for _, _, g in r[k] if g)
L = [f"# Repo guards: live status (generated {now}; windy-git scripts/guards_report.py)",
"_Default branches only. WARN-only today; the orchestrator says \"block\" per guard when its LANE column is 0. "
"Grant-owned code (ci/grant-owned.yml) is listed separately and never holds up a block._", "",
"| Guard | Lane-owned findings | Grant-owned (proposals) | Ready to block? |", "|---|---|---|---|",
f"| compute-guard (Mind is the only door) | {lane['compute']} | {grant['compute']} | {'✅ YES' if lane['compute'] == 0 else '❌ not yet'} |",
f"| ci-hygiene (house rule 6) | {lane['hygiene']} | {grant['hygiene']} | {'✅ YES' if lane['hygiene'] == 0 else '❌ not yet'} |",
"", "## By repo (lane-owned)", "| Repo | owner | head | compute | hygiene | first items |", "|---|---|---|---|---|---|"]
for repo, r in sorted(results.items()):
c = [x for x in r["compute"] if not x[2]]
h = [x for x in r["hygiene"] if not x[2]]
items = "; ".join(f"`{f.path}:{f.line}` {f.match}" for f, _, _ in (c + h)[:3]) or "clean ✅"
L.append(f"| {repo} | {OWNERS.get(repo, '?')} | {r['sha'][:7]} | {len(c)} | {len(h)} | {items} |")
L += ["", "## Grant-owned (windy-pro desktop app + its build jobs): proposals only, not blocking"]
g = [(repo, f, job) for repo, r in sorted(results.items()) for k in ("compute", "hygiene")
for f, job, own in r[k] if own]
L += [f"- {repo} `{f.path}:{f.line}`{f' (job {job})' if job else ''}: {f.match}" for repo, f, job in g] or ["- none"]
return "\n".join(L) + "\n"
def main() -> int:
owned = (yaml.safe_load(OWNED.read_text()) or {}).get("grant_owned") or []
results = {}
for repo in REPOS:
r = scan(repo, owned)
if r is not None:
results[repo] = r
sys.stdout.write(render(results))
return 0
if __name__ == "__main__":
sys.exit(main())

View File

@@ -202,17 +202,7 @@ def sync_prs(repo: str) -> list[str]:
wanted.add(tag)
heads.append(pr["head"]["sha"])
if tag in ours:
cur = (ours[tag].get("base") or {}).get("ref")
if cur is None or cur == pr["base"]["ref"]: # unknown base: never guess, leave it
continue
# Retargeted on GitHub (e.g. a stacked PR moved to main after its
# parent merged). The mirror kept the OLD base, so workflows filtered
# on the base (`pull_request: branches: [main]`) silently stopped
# running: eternitas #167, 09-23. Replace the mirror: an "edited"
# event triggers nothing, a freshly opened PR runs CI at once.
gitea("PATCH", f"/repos/{WG_OWNER}/{repo}/pulls/{ours[tag]['number']}", {"state": "closed"})
print(f" {repo}: GH#{pr['number']} retargeted {cur} -> "
f"{pr['base']['ref']}: replacing its mirror PR")
continue
st, _ = gitea(
"POST",
f"/repos/{WG_OWNER}/{repo}/pulls",
@@ -354,45 +344,34 @@ def post_statuses(repo: str, sha: str) -> None:
GUARD_CTX = "windy-git/compute-guard"
HYGIENE_CTX = "windy-git/ci-hygiene"
def post_compute_guard(repo: str, sha: str, default_branch: str, is_default_head: bool) -> None:
"""Windy Mind is the only door to AI compute: flag direct provider use (warn-only)."""
_post_guard("compute_guard", GUARD_CTX, repo, sha, default_branch, is_default_head)
"""Windy Mind is the only door to AI compute: flag direct provider use (warn-only).
def post_ci_hygiene(repo: str, sha: str, default_branch: str, is_default_head: bool) -> None:
"""House rule 6: lockfile-only installs, pinned images, no host-port services (warn-only)."""
_post_guard("ci_hygiene", HYGIENE_CTX, repo, sha, default_branch, is_default_head)
def _post_guard(modname: str, ctx: str, repo: str, sha: str, default_branch: str,
is_default_head: bool) -> None:
"""One code path for every repo-scanning guard. Non-fatal and never a fake OK:
if the guard can't run, nothing is posted."""
Non-fatal and never a fake OK: if the guard can't run, nothing is posted.
"""
try:
import importlib
import compute_guard as cg # same directory; loaded lazily so the bridge never depends on it
g = importlib.import_module(modname) # same directory; lazy so the bridge never depends on it
findings = g.check(repo, sha, default_branch, is_default_head)
except Exception as e: # noqa: BLE001 — a guard must never break CI signals
print(f" {repo}@{sha[:7]} {ctx} skipped ({type(e).__name__}: {str(e)[:80]})")
findings = cg.check(repo, sha, default_branch, is_default_head)
except Exception as e: # noqa: BLE001 — the guard must never break CI signals
print(f" {repo}@{sha[:7]} compute-guard skipped ({type(e).__name__}: {str(e)[:80]})")
return
if findings is None:
return
state, desc, first = g.status_for(findings, whole_tree=is_default_head)
state, desc, first = cg.status_for(findings, whole_tree=is_default_head)
st, existing = github("GET", f"/repos/{GH_OWNER}/{repo}/commits/{sha}/statuses?per_page=100")
for s in existing or []: # newest first: compare the latest guard status only
if s["context"] == ctx:
if s["context"] == GUARD_CTX:
if (s["state"], s.get("description")) == (state, desc):
return
break
url = (f"{PUBLIC}/{WG_OWNER}/{repo}/src/commit/{sha}/{first.path}#L{first.line}"
if first else f"{PUBLIC}/{WG_OWNER}/{repo}/src/commit/{sha}")
st, _ = github("POST", f"/repos/{GH_OWNER}/{repo}/statuses/{sha}",
{"state": state, "context": ctx, "description": desc, "target_url": url})
print(f" {repo}@{sha[:7]} {ctx} = {state} ({len(findings)} finding(s)) -> {st}")
{"state": state, "context": GUARD_CTX, "description": desc, "target_url": url})
print(f" {repo}@{sha[:7]} {GUARD_CTX} = {state} ({len(findings)} finding(s)) -> {st}")
def main() -> int:
@@ -413,7 +392,6 @@ def main() -> int:
for sha in dict.fromkeys(shas):
post_statuses(repo, sha)
post_compute_guard(repo, sha, default_branch, sha == default_head)
post_ci_hygiene(repo, sha, default_branch, sha == default_head)
except Exception as e: # one repo's failure must not hide the others'
print(f" FAILED {repo}: {e}")
failed = 1

View File

@@ -16,8 +16,7 @@
# itself, so Windy Git is never left behind GitHub.
set -euo pipefail
repo="${1:?repo}"; branch="${2:?branch}"; want="${3:?sha prefix}"
# Gitea stores repositories LOWERCASED on disk (WindyCloud -> windycloud.git).
G="sudo docker exec -u git windy-git-gitea-1 git -C /data/git/repositories/windyadmin/${repo,,}.git"
G="sudo docker exec -u git windy-git-gitea-1 git -C /data/git/repositories/windyadmin/${repo}.git"
head=$($G rev-parse "refs/heads/${branch}")
[[ "$head" == "$want"* ]] || { echo "refusing: ${branch} is at ${head:0:7}, not ${want}"; exit 1; }

1485
uv.lock generated

File diff suppressed because it is too large Load Diff