refactor(tools): inline SyncClient._url; wire/org top-of-file blank squeeze

This commit is contained in:
Teknium
2026-09-02 23:53:08 -07:00
parent 6a9e5312e0
commit cd0efd137e
5 changed files with 6 additions and 20 deletions

View File

@@ -25,7 +25,6 @@ from tools.skills_sync_client_wire import ( # noqa: F401 (re-exports)
read_ref_hash, root_tree_of_commit, skill_trees_of_root, wire_address)
logger = logging.getLogger(__name__)
# Gate claim (NAS's wire name; means "Nous admin" / Permissions.ADMIN_ACCESS). The bearer comes
# from resolve_nous_runtime_credentials(); its payload is decoded unverified to read this.
NOUS_ADMIN_CLAIM = "tool_gateway_admin"

View File

@@ -21,9 +21,7 @@ from tools.skills_sync_client_wire import (
checked_capabilities, materialize_tree, read_ref_hash, root_tree_of_commit, skill_trees_of_root)
logger = logging.getLogger("tools.skills_sync_client")
ORG_DIR_NAME = "_org"
# Propose re-splices onto a moved org HEAD at most this many times. Small: contention means
# other members are actively proposing; unbounded would spin.
_ORG_CAS_MAX_ATTEMPTS = 5

View File

@@ -18,7 +18,6 @@ from pathlib import Path, PurePosixPath
from typing import Any, Dict, List, Optional, Tuple
logger = logging.getLogger("tools.skills_sync_client")
WIRE_VERSION = "1"
DEFAULT_MAX_OBJECT_BYTES = 26214400 # 25 MiB, mirrors capabilities default
KIND_BLOB, KIND_TREE, KIND_COMMIT = "blob", "tree", "commit"
@@ -37,7 +36,6 @@ SYNC_MANIFEST_VERSION = 1
# Content addressing: the wire uses the FULL 64-hex sha256 -- a different namespace from the
# truncated 16-hex local `content_hash` (skills_guard.py).
def wire_address(data: bytes) -> str:
"""``sha256:<64-hex>`` -- the wire address of ``data``."""
return "sha256:" + hashlib.sha256(data).hexdigest()
@@ -116,8 +114,8 @@ def build_tree(dir_path: Path, objects: ObjectSet, *, max_object_bytes: int) ->
if child.is_symlink():
logger.debug("skills_sync_client: skipping symlink %s", child)
elif child.is_dir():
sub_hash = build_tree(child, objects, max_object_bytes=max_object_bytes)
entries.append(_entry(child.name, KIND_TREE, sub_hash, MODE_DIR))
entries.append(_entry(child.name, KIND_TREE, build_tree(child, objects, max_object_bytes=max_object_bytes),
MODE_DIR))
elif child.is_file():
data = child.read_bytes()
if len(data) > max_object_bytes:
@@ -217,13 +215,10 @@ class SyncClient:
self._session = requests.Session()
self._session.headers["Authorization"] = f"Bearer {api_key}"
def _url(self, path: str) -> str:
return f"{self.base}/v1/sync/{path.lstrip('/')}"
def _request(self, method: str, path: str, op: str, *, ok=(200,), errors: Optional[Dict[int, Any]] = None, **kw):
"""One wire call; SyncError unless the status is in *ok*. *errors* maps a status to a message
(str or ``fn(response)``); anything else gets ``"<op> failed: <code>"``."""
r = self._session.request(method, self._url(path), timeout=self.timeout, **kw)
"""One wire call to ``/v1/sync/<path>``; SyncError unless the status is in *ok*. *errors* maps a
status to a message (str or ``fn(response)``); anything else gets ``"<op> failed: <code>"``."""
r = self._session.request(method, f"{self.base}/v1/sync/{path.lstrip('/')}", timeout=self.timeout, **kw)
if r.status_code in ok:
return r
msg = (errors or {}).get(r.status_code)
@@ -237,9 +232,7 @@ class SyncClient:
"""GET refs?prefix=... (or org/refs, filtered client-side by *prefix*)."""
path, params = ("org/refs", None) if org_scope else ("refs", {"prefix": prefix})
refs = (self._request("GET", path, "get_refs", params=params).json() or {}).get("refs", [])
if org_scope:
refs = [r_ for r_ in refs if str(r_.get("name", "")).startswith(prefix)]
return refs
return [r_ for r_ in refs if str(r_.get("name", "")).startswith(prefix)] if org_scope else refs
def get_object(self, obj_hash: str, *, org_scope: bool = False) -> Tuple[str, bytes]:
"""GET objects/:hash -> ``(kind, bytes)``; kind from the object-type header, blob default."""

View File

@@ -15,14 +15,12 @@ from typing import List, Optional, Tuple
# Hard cap on scanned text: scanners are advisory, so bound worst-case runtime.
MAX_SCAN_CHARS = 65_536
# Bounded filler between key attack words (unbounded ``(?:\w+\s+)*`` backtracks badly).
_FILLER = r"(?:\w+\s+){0,8}"
# Env var reference ending in a secret-ish suffix (see exfil comment below).
_SECRET_VAR = r"\$\{?\w*(?:KEY|TOKEN|SECRET|PASSWORD|CREDENTIAL)S?\b"
# Verb prefix for "modify agent config" patterns.
_MODIFY = r"(update|modify|edit|write|change|append|add\s+to)\s+[^\n]{0,2048}"
# (regex, pattern_id, scope); scope ∈ {"all", "context", "strict"}
_PATTERNS: List[Tuple[str, str, str]] = [
# ── Classic prompt injection (applies everywhere) ────────────────

View File

@@ -24,7 +24,6 @@ from contextlib import suppress
from hermes_constants import get_hermes_home
logger = logging.getLogger(__name__)
_REPO = "sheeki03/tirith"
# Cosign provenance pinned to the release workflow, not the whole repo.
_COSIGN_IDENTITY_REGEXP = f"^https://github.com/{_REPO}/\\.github/workflows/release\\.yml@refs/tags/v"
@@ -58,7 +57,6 @@ def _load_security_config() -> dict:
# --- Module state ---
# Cached path after first resolution. _INSTALL_FAILED means "tried and failed" (distinct
# from None = "not yet tried") so a failed install is not retried per command.
_resolved_path: str | None | bool = None