From cd0efd137ea0f7244e220accc7cb64b379a391f5 Mon Sep 17 00:00:00 2001 From: Teknium <127238744+teknium1@users.noreply.github.com> Date: Wed, 2 Sep 2026 23:53:08 -0700 Subject: [PATCH] refactor(tools): inline SyncClient._url; wire/org top-of-file blank squeeze --- tools/skills_sync_client.py | 1 - tools/skills_sync_client_org.py | 2 -- tools/skills_sync_client_wire.py | 19 ++++++------------- tools/threat_patterns.py | 2 -- tools/tirith_security.py | 2 -- 5 files changed, 6 insertions(+), 20 deletions(-) diff --git a/tools/skills_sync_client.py b/tools/skills_sync_client.py index 429cc11172..a4d605c086 100644 --- a/tools/skills_sync_client.py +++ b/tools/skills_sync_client.py @@ -25,7 +25,6 @@ from tools.skills_sync_client_wire import ( # noqa: F401 (re-exports) read_ref_hash, root_tree_of_commit, skill_trees_of_root, wire_address) logger = logging.getLogger(__name__) - # Gate claim (NAS's wire name; means "Nous admin" / Permissions.ADMIN_ACCESS). The bearer comes # from resolve_nous_runtime_credentials(); its payload is decoded unverified to read this. NOUS_ADMIN_CLAIM = "tool_gateway_admin" diff --git a/tools/skills_sync_client_org.py b/tools/skills_sync_client_org.py index 638864685d..54c4ffcbe7 100644 --- a/tools/skills_sync_client_org.py +++ b/tools/skills_sync_client_org.py @@ -21,9 +21,7 @@ from tools.skills_sync_client_wire import ( checked_capabilities, materialize_tree, read_ref_hash, root_tree_of_commit, skill_trees_of_root) logger = logging.getLogger("tools.skills_sync_client") - ORG_DIR_NAME = "_org" - # Propose re-splices onto a moved org HEAD at most this many times. Small: contention means # other members are actively proposing; unbounded would spin. _ORG_CAS_MAX_ATTEMPTS = 5 diff --git a/tools/skills_sync_client_wire.py b/tools/skills_sync_client_wire.py index c4c7b63561..ce29b13c58 100644 --- a/tools/skills_sync_client_wire.py +++ b/tools/skills_sync_client_wire.py @@ -18,7 +18,6 @@ from pathlib import Path, PurePosixPath from typing import Any, Dict, List, Optional, Tuple logger = logging.getLogger("tools.skills_sync_client") - WIRE_VERSION = "1" DEFAULT_MAX_OBJECT_BYTES = 26214400 # 25 MiB, mirrors capabilities default KIND_BLOB, KIND_TREE, KIND_COMMIT = "blob", "tree", "commit" @@ -37,7 +36,6 @@ SYNC_MANIFEST_VERSION = 1 # Content addressing: the wire uses the FULL 64-hex sha256 -- a different namespace from the # truncated 16-hex local `content_hash` (skills_guard.py). def wire_address(data: bytes) -> str: - """``sha256:<64-hex>`` -- the wire address of ``data``.""" return "sha256:" + hashlib.sha256(data).hexdigest() @@ -116,8 +114,8 @@ def build_tree(dir_path: Path, objects: ObjectSet, *, max_object_bytes: int) -> if child.is_symlink(): logger.debug("skills_sync_client: skipping symlink %s", child) elif child.is_dir(): - sub_hash = build_tree(child, objects, max_object_bytes=max_object_bytes) - entries.append(_entry(child.name, KIND_TREE, sub_hash, MODE_DIR)) + entries.append(_entry(child.name, KIND_TREE, build_tree(child, objects, max_object_bytes=max_object_bytes), + MODE_DIR)) elif child.is_file(): data = child.read_bytes() if len(data) > max_object_bytes: @@ -217,13 +215,10 @@ class SyncClient: self._session = requests.Session() self._session.headers["Authorization"] = f"Bearer {api_key}" - def _url(self, path: str) -> str: - return f"{self.base}/v1/sync/{path.lstrip('/')}" - def _request(self, method: str, path: str, op: str, *, ok=(200,), errors: Optional[Dict[int, Any]] = None, **kw): - """One wire call; SyncError unless the status is in *ok*. *errors* maps a status to a message - (str or ``fn(response)``); anything else gets ``" failed: "``.""" - r = self._session.request(method, self._url(path), timeout=self.timeout, **kw) + """One wire call to ``/v1/sync/``; SyncError unless the status is in *ok*. *errors* maps a + status to a message (str or ``fn(response)``); anything else gets ``" failed: "``.""" + r = self._session.request(method, f"{self.base}/v1/sync/{path.lstrip('/')}", timeout=self.timeout, **kw) if r.status_code in ok: return r msg = (errors or {}).get(r.status_code) @@ -237,9 +232,7 @@ class SyncClient: """GET refs?prefix=... (or org/refs, filtered client-side by *prefix*).""" path, params = ("org/refs", None) if org_scope else ("refs", {"prefix": prefix}) refs = (self._request("GET", path, "get_refs", params=params).json() or {}).get("refs", []) - if org_scope: - refs = [r_ for r_ in refs if str(r_.get("name", "")).startswith(prefix)] - return refs + return [r_ for r_ in refs if str(r_.get("name", "")).startswith(prefix)] if org_scope else refs def get_object(self, obj_hash: str, *, org_scope: bool = False) -> Tuple[str, bytes]: """GET objects/:hash -> ``(kind, bytes)``; kind from the object-type header, blob default.""" diff --git a/tools/threat_patterns.py b/tools/threat_patterns.py index e43649d141..eca17ff887 100644 --- a/tools/threat_patterns.py +++ b/tools/threat_patterns.py @@ -15,14 +15,12 @@ from typing import List, Optional, Tuple # Hard cap on scanned text: scanners are advisory, so bound worst-case runtime. MAX_SCAN_CHARS = 65_536 - # Bounded filler between key attack words (unbounded ``(?:\w+\s+)*`` backtracks badly). _FILLER = r"(?:\w+\s+){0,8}" # Env var reference ending in a secret-ish suffix (see exfil comment below). _SECRET_VAR = r"\$\{?\w*(?:KEY|TOKEN|SECRET|PASSWORD|CREDENTIAL)S?\b" # Verb prefix for "modify agent config" patterns. _MODIFY = r"(update|modify|edit|write|change|append|add\s+to)\s+[^\n]{0,2048}" - # (regex, pattern_id, scope); scope ∈ {"all", "context", "strict"} _PATTERNS: List[Tuple[str, str, str]] = [ # ── Classic prompt injection (applies everywhere) ──────────────── diff --git a/tools/tirith_security.py b/tools/tirith_security.py index 02b2a661d1..63eb900693 100644 --- a/tools/tirith_security.py +++ b/tools/tirith_security.py @@ -24,7 +24,6 @@ from contextlib import suppress from hermes_constants import get_hermes_home logger = logging.getLogger(__name__) - _REPO = "sheeki03/tirith" # Cosign provenance pinned to the release workflow, not the whole repo. _COSIGN_IDENTITY_REGEXP = f"^https://github.com/{_REPO}/\\.github/workflows/release\\.yml@refs/tags/v" @@ -58,7 +57,6 @@ def _load_security_config() -> dict: # --- Module state --- - # Cached path after first resolution. _INSTALL_FAILED means "tried and failed" (distinct # from None = "not yet tried") so a failed install is not retried per command. _resolved_path: str | None | bool = None