search-stack-visibility was still expecting the 2026-09-25 engine set
(bing, brave, google cse, yandex, duckduckgo) — three of which are blocked
upstream today. The check had gone quiet on the engines that actually carry the
stack.
The live stack now runs ten engines enabled: seven that returned real results
from this network, plus three best-effort canaries kept for recovery visibility.
Live engine expansion (CT 100, 2026-10-03)
/etc/searxng/settings.yml (docker-vm .7, container searxng) after the change:
engine
status
bing, yandex, yep, mwmbl, naver, seznam, yahoo
working (kept enabled)
brave, duckduckgo, google cse
best-effort canaries (blocked upstream)
qwant, fireball
tested, failed, disabled
mojeek, startpage, dogpile
inactive: true in the build (proof-of-work CAPTCHA)
Before: both queries contributed from bing alone (one engine above the floor).
Broken cases still fail and name the cause: single-engine floor → exit 1 naming
the sole contributor; broken extraction → exit 1; unreachable SearXNG → exit 2.
Note on CI
scripts/secret-scan.sh fails on master already, independent of this PR: hermes-key-enforcement.prose.md:217 is a deliberate synthetic example
(LITELLM_API_KEY=sk-synthetic-litellm-…) that the scanner flags. Not touched
here; flagging so it can be allowlisted deliberately.
## What
`search-stack-visibility` was still expecting the 2026-09-25 engine set
(`bing, brave, google cse, yandex, duckduckgo`) — three of which are blocked
upstream today. The check had gone quiet on the engines that actually carry the
stack.
The live stack now runs **ten** engines enabled: seven that returned real results
from this network, plus three best-effort canaries kept for recovery visibility.
## Live engine expansion (CT 100, 2026-10-03)
`/etc/searxng/settings.yml` (docker-vm `.7`, container `searxng`) after the change:
| engine | status |
| --- | --- |
| bing, yandex, yep, mwmbl, naver, seznam, yahoo | **working** (kept enabled) |
| brave, duckduckgo, google cse | best-effort canaries (blocked upstream) |
| qwant, fireball | tested, failed, disabled |
| mojeek, startpage, dogpile | `inactive: true` in the build (proof-of-work CAPTCHA) |
| marginalia | needs an API key |
## Proof (contract run at the live service)
```
QUERY: 'proxmox backup server'
contributing engines: {yandex: 14, bing: 10, mwmbl: 58, yep: 16, naver: 14, seznam: 6, yahoo: 1}
QUERY: 'python asyncio tutorial'
contributing engines: {bing: 10, yandex: 3, mwmbl: 82, seznam: 5, naver: 14, yep: 17}
EXTRACTION: 71532 chars of markdown returned
VERDICT: PASS
```
Before: both queries contributed from **bing alone** (one engine above the floor).
Broken cases still fail and name the cause: single-engine floor → exit 1 naming
the sole contributor; broken extraction → exit 1; unreachable SearXNG → exit 2.
## Note on CI
`scripts/secret-scan.sh` fails **on master already**, independent of this PR:
`hermes-key-enforcement.prose.md:217` is a deliberate *synthetic* example
(`LITELLM_API_KEY=sk-synthetic-litellm-…`) that the scanner flags. Not touched
here; flagging so it can be allowlisted deliberately.
The visibility contract's expected-engine set was still the 2026-09-25 list
(bing, brave, google cse, yandex, duckduckgo). Three of those five are blocked
upstream today, so the check had gone quiet on the engines that DO carry the
stack and noisy on ones that cannot.
The live stack now runs ten engines enabled: seven that returned real results
from this network (bing, yandex, yep, mwmbl, naver, seznam, yahoo) plus the
three best-effort canaries kept for recovery visibility (brave, duckduckgo,
google cse). The expected set is updated to match, so a silent zero is reported
for every engine the stack actually runs.
Live proof after the engine expansion (CT 100, 2026-10-03):
'proxmox backup server' -> 7 contributing engines
'python asyncio tutorial' -> 6 contributing engines
VERDICT: PASS
Before the change both queries contributed from bing alone, one engine above
the two-engine floor.
Verified broken cases still fail and name the cause: a single-engine floor
exits 1 naming the sole contributor, a broken extraction exits 1, and an
unreachable SearXNG exits 2.
Contract text and version updated to the 2026-10-03 state.
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
What
search-stack-visibilitywas still expecting the 2026-09-25 engine set(
bing, brave, google cse, yandex, duckduckgo) — three of which are blockedupstream today. The check had gone quiet on the engines that actually carry the
stack.
The live stack now runs ten engines enabled: seven that returned real results
from this network, plus three best-effort canaries kept for recovery visibility.
Live engine expansion (CT 100, 2026-10-03)
/etc/searxng/settings.yml(docker-vm.7, containersearxng) after the change:inactive: truein the build (proof-of-work CAPTCHA)Proof (contract run at the live service)
Before: both queries contributed from bing alone (one engine above the floor).
Broken cases still fail and name the cause: single-engine floor → exit 1 naming
the sole contributor; broken extraction → exit 1; unreachable SearXNG → exit 2.
Note on CI
scripts/secret-scan.shfails on master already, independent of this PR:hermes-key-enforcement.prose.md:217is a deliberate synthetic example(
LITELLM_API_KEY=sk-synthetic-litellm-…) that the scanner flags. Not touchedhere; flagging so it can be allowlisted deliberately.