6 Commits

Author SHA1 Message Date
Kit OC5
0fb2df11a6 compute-guard: windytalk client-side :8788 refs filed as engine-side (Windy Talk's classification)
run-client.sh points at an ssh -L tunnel to the dev engine on Veron; index.html lines are display-only fallbacks;
the shipped desktop client defaults to the public engine on Veron. Same dated owner-approved exemption
(approved_by windy-hub, expires 2026-12-31), NOT local-user-hardware.

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
2026-10-02 18:25:56 -04:00
44a1800eff Merge pull request #5 from sneakyfree/guard-exempt-talk-registry
All checks were successful
check / gate (push) Successful in 12s
compute-guard: dated exemptions (registry dev origin, windytalk engine-side)
2026-10-02 18:25:19 -04:00
Kit OC5
dc1cfbf044 compute-guard: dated exemptions for windy-registry dev CORS origin and windytalk engine-side ports
Hub decision 10-02 (alternative B, rule stays strict): registry tools/r2-provision.sh :8788 is a dev origin in an
R2 CORS rule; windytalk engine/server/systemd/stress ports are Talk's own engines (owner-approved, NOT compute-door,
a real bypass to be put behind Mind). approved_by windy-hub, expires 2026-12-31. Client-side files pending Talk.

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
2026-10-02 18:25:14 -04:00
61776ce021 Merge pull request #4 from sneakyfree/guard-drop-8099
compute-guard: drop :8099 (false positive) + Deepgram template exemption
2026-10-02 18:20:37 -04:00
Kit OC5
5c42b0e760 compute-guard: drop :8099 from the Talk-engine ports (false positive); Deepgram template line under the BYOK exemption
Hub classification 10-02: :8099 in windy-pro is the OLD translate-api / cloud-storage service, not Windy Talk
(verified: windytalk has no :8099, only lockfile hash fragments). DEEPGRAM_API_KEY in windy-pro .env.example is
a template line for the user-own-key Deepgram feature: owner-approved, approved_by windy-hub, expires 2026-12-31.

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
2026-10-02 18:20:28 -04:00
74ca5ac19b Merge pull request #3 from sneakyfree/compute-guard-gatekeeper
All checks were successful
check / gate (push) Successful in 20s
canary / probe (push) Successful in 5s
compute-guard: gatekeeper rules + expiring exemptions (Windy Mind 10-02)
2026-10-02 18:13:26 -04:00
3 changed files with 53 additions and 6 deletions

View File

@@ -133,7 +133,7 @@ def test_shipped_allow_file_is_valid_today():
('u = f"https://api.cloudflare.com/client/v4/accounts/{a}/ai/run/@cf/m"', "cloudflare workers ai"), ('u = f"https://api.cloudflare.com/client/v4/accounts/{a}/ai/run/@cf/m"', "cloudflare workers ai"),
('ENGINE = "http://10.0.0.5:8791/v1"', "talk engine port"), ('ENGINE = "http://10.0.0.5:8791/v1"', "talk engine port"),
('ENGINE = "http://h:8788/ws"', "talk engine port"), ('ENGINE = "http://h:8788/ws"', "talk engine port"),
('x = "http://h:8099/health"', "talk engine port"), ('x = "http://h:8794/health"', "talk engine port"),
]) ])
def test_gatekeeper_rules_fire(text, kind): def test_gatekeeper_rules_fire(text, kind):
assert kind in [k for k, _ in cg.scan_line("app/x.py", text)] assert kind in [k for k, _ in cg.scan_line("app/x.py", text)]
@@ -365,6 +365,8 @@ def test_findings_carry_kind_and_name_never_the_value_and_ports_skip_contracts()
hits = cg.scan_line("app/x.py", line) hits = cg.scan_line("app/x.py", line)
assert [k for k, _ in hits] == [kind] assert [k for k, _ in hits] == [kind]
assert all("SUPERSECRET" not in m and "VALUE" not in m for _, m in hits) assert all("SUPERSECRET" not in m and "VALUE" not in m for _, m in hits)
assert cg.scan_line("engine/contracts/ops.mcp.v1.json", '"url": "http://h:8099/x"') == [] assert cg.scan_line("engine/contracts/ops.mcp.v1.json", '"url": "http://h:8791/x"') == []
assert cg.scan_line("services/api/openapi/spec.json", '"url": "http://h:8099/x"') == [] assert cg.scan_line("services/api/openapi/spec.json", '"url": "http://h:8791/x"') == []
assert [k for k, _ in cg.scan_line("deploy/docker-compose.yml", " - 8099:8099 # :8099")] == ["talk engine port"] assert [k for k, _ in cg.scan_line("deploy/docker-compose.yml", " - 8791:8791 # :8791")] == ["talk engine port"]
# :8099 is windy-pro's OLD translate-api / cloud-storage service, NOT the Talk engine (Hub 10-02): not flagged
assert cg.scan_line("deploy/docker-compose.yml", " - 8099:8099 # translate-api:8099") == []

View File

@@ -83,3 +83,48 @@ allow:
reason: "Windy Mind IS the compute door (endpoint + key); it may call Ollama. Only the Ollama port is allowed here, any provider host/SDK in Mind still flags." reason: "Windy Mind IS the compute door (endpoint + key); it may call Ollama. Only the Ollama port is allowed here, any provider host/SDK in Mind still flags."
exemption: compute-door exemption: compute-door
expires: 2027-10-02 expires: 2027-10-02
- repo: windy-pro
paths: [".env.example"]
matches: ['DEEPGRAM_API_KEY']
reason: "Template line (name only, no value) for the existing user-own-key Deepgram feature in Word's Settings. Mind's migration removes the feature and then this line (Hub classification 10-02)."
exemption: owner-approved
approved_by: windy-hub
approved_on: 2026-10-02
expires: 2026-12-31
- repo: windy-registry
paths: ["tools/r2-provision.sh"]
matches: ['http://localhost:8788']
reason: "Dev origin in an R2 bucket CORS rule, not a call to the Talk engine (Hub 10-02)."
exemption: owner-approved
approved_by: windy-hub
approved_on: 2026-10-02
expires: 2026-12-31
- repo: windytalk
paths: ["engine/*", "scripts/stress/*", "scripts/veron/*"]
matches: [':(8791|8788|8794)']
reason: "Talk's own voice engines (server, systemd unit, stress scripts); to be placed behind Mind per Mind's audit plan. NOT compute-door: a real bypass being fixed (Hub 10-02)."
exemption: owner-approved
approved_by: windy-hub
approved_on: 2026-10-02
expires: 2026-12-31
- repo: windytalk
paths: ["scripts/run-client.sh"]
matches: [':(8791|8788|8794)']
reason: "Dev client launcher: 127.0.0.1:8788 is an ssh -L tunnel to the dev engine ON VERON (not the user's machine), so engine-side; dev-only, not shipped. To be placed behind Mind per Mind's audit plan (Windy Talk, Hub 10-02)."
exemption: owner-approved
approved_by: windy-hub
approved_on: 2026-10-02
expires: 2026-12-31
- repo: windytalk
paths: ["apps/desktop/renderer/index.html"]
matches: [':(8791|8788|8794)']
reason: "Display-only fallback label in the settings panel (cfg.engineUrl || default); connects to nothing. The shipped client defaults to the public engine on Veron, never local inference (Windy Talk, Hub 10-02)."
exemption: owner-approved
approved_by: windy-hub
approved_on: 2026-10-02
expires: 2026-12-31

View File

@@ -88,7 +88,7 @@ RULES: list[tuple[str, re.Pattern]] = [
("voice-ai host", re.compile(r"(?:transcribe|polly)\.[a-z0-9-]+\.amazonaws\.com")), ("voice-ai host", re.compile(r"(?:transcribe|polly)\.[a-z0-9-]+\.amazonaws\.com")),
("provider host", re.compile(r"(?:bedrock-runtime|bedrock)\.[a-z0-9-]+\.amazonaws\.com")), ("provider host", re.compile(r"(?:bedrock-runtime|bedrock)\.[a-z0-9-]+\.amazonaws\.com")),
("cloudflare workers ai", re.compile(r"api\.cloudflare\.com/client/v4/accounts/[^\s'\"/]+/ai/")), ("cloudflare workers ai", re.compile(r"api\.cloudflare\.com/client/v4/accounts/[^\s'\"/]+/ai/")),
("talk engine port", re.compile(r"(?::|%3[aA])(?:8791|8788|8794|8099)(?![0-9])")), ("talk engine port", re.compile(r"(?::|%3[aA])(?:8791|8788|8794)(?![0-9])")),
("workers ai binding", WRANGLER_AI), ("workers ai binding", WRANGLER_AI),
("provider key", re.compile(r"\b(?:" + "|".join(KEYS) + r")\b")), ("provider key", re.compile(r"\b(?:" + "|".join(KEYS) + r")\b")),
("provider SDK", re.compile(rf"^\s*(?:from|import)\s+(?:{PY_SDKS})(?:\s|\.|$|,)")), ("provider SDK", re.compile(rf"^\s*(?:from|import)\s+(?:{PY_SDKS})(?:\s|\.|$|,)")),
@@ -225,7 +225,7 @@ def scan_tree(repo: str, bare: Path, sha: str, allow: list[dict], *, line_fn=Non
"anthropic", "openai", "groq", "mistral", "generativeai", "genai", "cohere", "anthropic", "openai", "groq", "mistral", "generativeai", "genai", "cohere",
"together", "cerebras", "litellm", "deepgram", "elevenlabs", "cartesia", "play\\.ht", "resemble", "together", "cerebras", "litellm", "deepgram", "elevenlabs", "cartesia", "play\\.ht", "resemble",
"heygen", "googleapis\\.com", "amazonaws\\.com", "api\\.cloudflare\\.com", ":8791", ":8788", "heygen", "googleapis\\.com", "amazonaws\\.com", "api\\.cloudflare\\.com", ":8791", ":8788",
":8794", ":8099", "%3[aA]87", "%3[aA]8099", r"^\s*\[ai\]", '"ai"']) ":8794", "%3[aA]87", r"^\s*\[ai\]", '"ai"'])
try: try:
out = _git(bare, "grep", "-nIE", "-e", pre, sha, "--", ".") out = _git(bare, "grep", "-nIE", "-e", pre, sha, "--", ".")
except subprocess.CalledProcessError as e: except subprocess.CalledProcessError as e: