Compare commits

...
Author SHA1 Message Date
abiba-bot 595e67bda6 Merge pull request 'fix(search): expect the seven engines that actually contribute, not the five that don't' (#149) from fix/search-stack-multiprovider-20261003 into master
PR Pipeline — Authorize → Validate → Review → Merge / auth (push) Successful in 18s
PR Pipeline — Authorize → Validate → Review → Merge / validate (push) Successful in 7s
PR Pipeline — Authorize → Validate → Review → Merge / lint (push) Successful in 18s
PR Pipeline — Authorize → Validate → Review → Merge / ai-review (push) Successful in 5s
PR Pipeline — Authorize → Validate → Review → Merge / gate (push) Successful in 2s
2026-10-03 10:13:04 +00:00
root 9c6346e3ff Merge master into fix/search-stack-multiprovider-20261003 (pick up the #150 lint allowlist fix so the PR's lint job can pass)
PR Pipeline — Authorize → Validate → Review → Merge / auth (pull_request) Successful in 9s
PR Pipeline — Authorize → Validate → Review → Merge / validate (pull_request) Successful in 9s
PR Pipeline — Authorize → Validate → Review → Merge / lint (pull_request) Successful in 21s
PR Pipeline — Authorize → Validate → Review → Merge / ai-review (pull_request) Successful in 9s
PR Pipeline — Authorize → Validate → Review → Merge / gate (pull_request) Successful in 2s
2026-10-03 10:08:47 +00:00
abiba-bot 1f02b00aaa Merge pull request 'fix: prose-lint allowlist for synthetic credential example' (#150) from fix/prose-lint-allowlist-20261003 into master
PR Pipeline — Authorize → Validate → Review → Merge / auth (push) Failing after 10m47s
PR Pipeline — Authorize → Validate → Review → Merge / validate (push) Skipped
PR Pipeline — Authorize → Validate → Review → Merge / lint (push) Skipped
PR Pipeline — Authorize → Validate → Review → Merge / ai-review (push) Skipped
PR Pipeline — Authorize → Validate → Review → Merge / gate (push) Skipped
2026-10-03 10:07:31 +00:00
root 3fe5cc3af1 fix: prose-lint allowlist for synthetic credential example
PR Pipeline — Authorize → Validate → Review → Merge / auth (pull_request) Successful in 13s
PR Pipeline — Authorize → Validate → Review → Merge / validate (pull_request) Successful in 5s
PR Pipeline — Authorize → Validate → Review → Merge / lint (pull_request) Successful in 23s
PR Pipeline — Authorize → Validate → Review → Merge / ai-review (pull_request) Successful in 11s
PR Pipeline — Authorize → Validate → Review → Merge / gate (pull_request) Successful in 1s
The synthetic example 'sk-synthetic-litellm-' in hermes-key-enforcement.prose.md:217
was flagged by the secret-assign rule as a credential-shaped assignment. The
existing allowlist entry only covered openai-key, so secret-assign still failed.

Fix: Change the rule from openai-key to * (matches any rule) and update the
reason to explain why (2026-10-03: secret-assign also matches the credential-shaped
assignment).

This restores prose-lint on master, which was RED and blocking every open PR's
lint job (including PR #149's lint job 2160).

Chose option (b) (allowlist) over option (a) (restructure) because:
- The existing entry already documented the synthetic example
- Changing the rule to * is the minimal, honest fix
- Restructuring the command would risk weakening the enforcement check

Correlation: corr=7c202734ec6c452a
2026-10-03 09:36:15 +00:00
root 6608d3162f fix(search): expect the seven engines that actually contribute, not the five that don't
PR Pipeline — Authorize → Validate → Review → Merge / auth (pull_request) Successful in 14s
PR Pipeline — Authorize → Validate → Review → Merge / validate (pull_request) Successful in 6s
PR Pipeline — Authorize → Validate → Review → Merge / lint (pull_request) Failing after 10s
PR Pipeline — Authorize → Validate → Review → Merge / ai-review (pull_request) Successful in 10s
PR Pipeline — Authorize → Validate → Review → Merge / gate (pull_request) Skipped
The visibility contract's expected-engine set was still the 2026-09-25 list
(bing, brave, google cse, yandex, duckduckgo). Three of those five are blocked
upstream today, so the check had gone quiet on the engines that DO carry the
stack and noisy on ones that cannot.

The live stack now runs ten engines enabled: seven that returned real results
from this network (bing, yandex, yep, mwmbl, naver, seznam, yahoo) plus the
three best-effort canaries kept for recovery visibility (brave, duckduckgo,
google cse). The expected set is updated to match, so a silent zero is reported
for every engine the stack actually runs.

Live proof after the engine expansion (CT 100, 2026-10-03):
  'proxmox backup server'   -> 7 contributing engines
  'python asyncio tutorial' -> 6 contributing engines
  VERDICT: PASS
Before the change both queries contributed from bing alone, one engine above
the two-engine floor.

Verified broken cases still fail and name the cause: a single-engine floor
exits 1 naming the sole contributor, a broken extraction exits 1, and an
unreachable SearXNG exits 2.

Contract text and version updated to the 2026-10-03 state.
2026-10-03 09:28:09 +00:00
abiba-bot 8dac151063 Merge pull request 'fix: hermes-key-enforcement probe timeout - bounded scan, honest failure kinds' (#148) from fix/hermes-key-enforcement-probe-timeout-20261002 into master
PR Pipeline — Authorize → Validate → Review → Merge / auth (push) Successful in 5s
PR Pipeline — Authorize → Validate → Review → Merge / validate (push) Successful in 8s
PR Pipeline — Authorize → Validate → Review → Merge / lint (push) Failing after 16s
PR Pipeline — Authorize → Validate → Review → Merge / ai-review (push) Successful in 5s
PR Pipeline — Authorize → Validate → Review → Merge / gate (push) Skipped
2026-10-02 12:19:25 +00:00
3 changed files with 32 additions and 14 deletions
+14 -2
View File
@@ -61,11 +61,23 @@ EXTRACT_URL = os.environ.get(
# engines (images, videos, translate, currency, arxiv, npm, ...) are excluded on # engines (images, videos, translate, currency, arxiv, npm, ...) are excluded on
# purpose -- contributing nothing to a general query is correct for them. # purpose -- contributing nothing to a general query is correct for them.
DEFAULT_EXPECTED_ENGINES = [ DEFAULT_EXPECTED_ENGINES = [
# Multi-engine expansion 2026-10-03. The stack had fallen to Bing-only:
# brave and google cse are suspended upstream, duckduckgo CAPTCHAs both
# egresses and yandex flaps. The seven below all returned real results
# from this network and are the engines a general query must draw on.
"bing", "bing",
"brave",
"google cse",
"yandex", "yandex",
"yep",
"mwmbl",
"naver",
"seznam",
"yahoo",
# Best-effort canaries: intentionally left enabled so a recovery shows up
# as a contribution and a failure stays visible in unresponsive_engines.
# All three are blocked upstream today.
"brave",
"duckduckgo", "duckduckgo",
"google cse",
] ]
EXPECTED_ENGINES = [ EXPECTED_ENGINES = [
e.strip() e.strip()
+1 -1
View File
@@ -35,7 +35,7 @@ bearer-token agent-zero-fix-summary.md «vault: agents/production OPENROUTER_API
# example is always an explicit exception, never a pattern-level exemption. # example is always an explicit exception, never a pattern-level exemption.
* hermes-key-enforcement.prose.md sk-synthetic-external-example Rule 15 illustration of a hardcoded external key that is tolerated; fabricated, never a live key. * hermes-key-enforcement.prose.md sk-synthetic-external-example Rule 15 illustration of a hardcoded external key that is tolerated; fabricated, never a live key.
* hermes-key-enforcement.prose.md sk-synthetic-example-12345 Rule 15 illustration of a forbidden hardcoded key; fabricated, never a live key. * hermes-key-enforcement.prose.md sk-synthetic-example-12345 Rule 15 illustration of a forbidden hardcoded key; fabricated, never a live key.
openai-key hermes-key-enforcement.prose.md sk-synthetic-litellm- Fabricated key name inside a `grep 'LITELLM_API_KEY=...'` example; not a live key. * hermes-key-enforcement.prose.md sk-synthetic-litellm- Fabricated key name inside a `grep 'LITELLM_API_KEY=...'` example; not a live key. (2026-10-03: changed rule from openai-key to * because secret-assign also matches the credential-shaped assignment)
secret-assign hermes-key-enforcement.prose.md sk-NEW_KEY Placeholder standing for the rotated key in an `infisical secrets set` command; not a literal key. secret-assign hermes-key-enforcement.prose.md sk-NEW_KEY Placeholder standing for the rotated key in an `infisical secrets set` command; not a literal key.
openrouter-key agent-zero-openrouter-key.prose.md sk-or-v1-synthetic Synthetic key prefix in the contract's example response; the real key is read from the vault. openrouter-key agent-zero-openrouter-key.prose.md sk-or-v1-synthetic Synthetic key prefix in the contract's example response; the real key is read from the vault.
openai-key litellm-api-keys.prose.md sk-synthetic-tanko-example Fabricated key name in migration history prose; not a live key. openai-key litellm-api-keys.prose.md sk-synthetic-tanko-example Fabricated key name in migration history prose; not a live key.
Can't render this file because it contains an unexpected character in line 23 and column 25.
+17 -11
View File
@@ -17,11 +17,16 @@ description: >
* reports every silent-zero engine explicitly (enabled, not in * reports every silent-zero engine explicitly (enabled, not in
unresponsive_engines, contributed no results). unresponsive_engines, contributed no results).
Multi-engine state (2026-09-25): bing, google cse, brave and yandex Multi-engine state (2026-10-03): the stack had fallen to Bing-only -- brave
contribute on every query. duckduckgo is NOT working: the house egress IP and google cse are suspended upstream, duckduckgo CAPTCHAs both egresses and
and the VPS fallback egress are both flagged by DuckDuckGo and it reports yandex flaps. Every no-credential free general engine this build ships was
CAPTCHA. It is left enabled as best-effort coverage so that a recovery shows enabled and probed. Seven now contribute real results on a general query:
up as a contribution. bing, yandex, yep, mwmbl, naver, seznam and yahoo. brave, duckduckgo and
google cse are left enabled as best-effort canaries so a recovery shows up as
a contribution and their failure stays visible in unresponsive_engines.
mojeek, startpage and dogpile are `inactive: true` in the build (proof-of-work
CAPTCHA), marginalia needs an API key, and qwant and fireball were tested and
dropped (CAPTCHA and access-denied).
google cse is a third party's public search-engine id hardcoded in the google cse is a third party's public search-engine id hardcoded in the
SearXNG build. Quota and availability are outside our control. SearXNG build. Quota and availability are outside our control.
@@ -29,7 +34,7 @@ description: >
SCHEDULED: /etc/cron.d/contract-runner on CT 100 (abiba), hourly at :15, SCHEDULED: /etc/cron.d/contract-runner on CT 100 (abiba), hourly at :15,
via scripts/contract-run.sh search-stack-visibility. Logs land in via scripts/contract-run.sh search-stack-visibility. Logs land in
/var/log/contract-runs/. A failure also raises a firstmate inbox note. /var/log/contract-runs/. A failure also raises a firstmate inbox note.
version: 1.1.0 version: 1.2.0
--- ---
## Purpose ## Purpose
@@ -54,11 +59,12 @@ firstmate inbox note through `bin/fm-inbox.sh`.
``` ```
$ bash scripts/contract-run.sh search-stack-visibility $ bash scripts/contract-run.sh search-stack-visibility
Expected engines, enabled (5): ['bing', 'brave', 'duckduckgo', 'google cse', 'yandex'] Expected engines, enabled (10): ['bing', 'brave', 'duckduckgo', 'google cse',
queries: 'proxmox backup server' -> contributing: bing, brave, google cse, yandex 'mwmbl', 'naver', 'seznam', 'yahoo', 'yandex', 'yep']
unresponsive: duckduckgo=CAPTCHA queries: 'proxmox backup server' -> contributing: bing, mwmbl, naver, seznam, yahoo, yandex, yep
'python asyncio tutorial' -> contributing: bing, brave, google cse, yandex unresponsive: brave, duckduckgo, google cse
EXTRACTION: 71016 chars of markdown returned 'python asyncio tutorial' -> contributing: bing, mwmbl, naver, seznam, yandex, yep
EXTRACTION: 71532 chars of markdown returned
VERDICT: PASS -- multiple engines contributing, extraction healthy VERDICT: PASS -- multiple engines contributing, extraction healthy
``` ```