4 Commits

Author SHA1 Message Date
Kit OC5
0fb2df11a6 compute-guard: windytalk client-side :8788 refs filed as engine-side (Windy Talk's classification)
run-client.sh points at an ssh -L tunnel to the dev engine on Veron; index.html lines are display-only fallbacks;
the shipped desktop client defaults to the public engine on Veron. Same dated owner-approved exemption
(approved_by windy-hub, expires 2026-12-31), NOT local-user-hardware.

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
2026-10-02 18:25:56 -04:00
44a1800eff Merge pull request #5 from sneakyfree/guard-exempt-talk-registry
All checks were successful
check / gate (push) Successful in 12s
compute-guard: dated exemptions (registry dev origin, windytalk engine-side)
2026-10-02 18:25:19 -04:00
Kit OC5
dc1cfbf044 compute-guard: dated exemptions for windy-registry dev CORS origin and windytalk engine-side ports
Hub decision 10-02 (alternative B, rule stays strict): registry tools/r2-provision.sh :8788 is a dev origin in an
R2 CORS rule; windytalk engine/server/systemd/stress ports are Talk's own engines (owner-approved, NOT compute-door,
a real bypass to be put behind Mind). approved_by windy-hub, expires 2026-12-31. Client-side files pending Talk.

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
2026-10-02 18:25:14 -04:00
61776ce021 Merge pull request #4 from sneakyfree/guard-drop-8099
compute-guard: drop :8099 (false positive) + Deepgram template exemption
2026-10-02 18:20:37 -04:00

View File

@@ -92,3 +92,39 @@ allow:
approved_by: windy-hub
approved_on: 2026-10-02
expires: 2026-12-31
- repo: windy-registry
paths: ["tools/r2-provision.sh"]
matches: ['http://localhost:8788']
reason: "Dev origin in an R2 bucket CORS rule, not a call to the Talk engine (Hub 10-02)."
exemption: owner-approved
approved_by: windy-hub
approved_on: 2026-10-02
expires: 2026-12-31
- repo: windytalk
paths: ["engine/*", "scripts/stress/*", "scripts/veron/*"]
matches: [':(8791|8788|8794)']
reason: "Talk's own voice engines (server, systemd unit, stress scripts); to be placed behind Mind per Mind's audit plan. NOT compute-door: a real bypass being fixed (Hub 10-02)."
exemption: owner-approved
approved_by: windy-hub
approved_on: 2026-10-02
expires: 2026-12-31
- repo: windytalk
paths: ["scripts/run-client.sh"]
matches: [':(8791|8788|8794)']
reason: "Dev client launcher: 127.0.0.1:8788 is an ssh -L tunnel to the dev engine ON VERON (not the user's machine), so engine-side; dev-only, not shipped. To be placed behind Mind per Mind's audit plan (Windy Talk, Hub 10-02)."
exemption: owner-approved
approved_by: windy-hub
approved_on: 2026-10-02
expires: 2026-12-31
- repo: windytalk
paths: ["apps/desktop/renderer/index.html"]
matches: [':(8791|8788|8794)']
reason: "Display-only fallback label in the settings panel (cfg.engineUrl || default); connects to nothing. The shipped client defaults to the public engine on Veron, never local inference (Windy Talk, Hub 10-02)."
exemption: owner-approved
approved_by: windy-hub
approved_on: 2026-10-02
expires: 2026-12-31