vision: scope the note, settle the contract, wait for the prune

Saving a description writes recall corpus. writeNote embeds it under
media:image:<id>, a source no enrollment owns, and the method sits at
AuthRead, so any enrolled module could put a small VLM's guess into what
Maven knows and have it come back in a later turn as something she
believes. The describing half stays a read; save_note is now held to the
same source-scope rule WriteFact is, and the stored text carries a
marker saying it came off a picture.

Three doc comments said the method exists only when vision is enabled
and the code says otherwise. The code is right, and storing without
describing is the state this box is in, so the comments were corrected
rather than the behaviour. A request carrying both data and id used to
take the id branch and drop the bytes without a word; it is refused.

A media dir that cannot be created and a vision endpoint that is a typo
were logged at wiring time and the capability just stayed off, which is
the hardest kind of misconfiguration to notice. Both fail at startup.
runPrune was the one loop started with a bare go and not in the daemon's
WaitGroup, so shutdown did not wait for a prune that was deleting files.

Found in review of #72.
This commit is contained in:
kami
2026-08-01 14:21:46 +04:00
parent e926e4e6df
commit 543aefde4b
9 changed files with 266 additions and 24 deletions
+27
View File
@@ -472,3 +472,30 @@ func TestRequirement_Speaker(t *testing.T) {
t.Errorf("voice listing speakers = %v; want allowed", err)
}
}
// Describing an image is a read. Saving the description is a write of recall
// corpus under a source no enrollment owns, so it is held to the same
// source-scope rule WriteFact is. Before this, any AuthRead caller could put a
// small VLM's guess into what Maven knows.
func TestCan_DescribeImage_SaveNoteNeedsScope(t *testing.T) {
poller := Scope{Surface: SurfaceTelegram, Module: "poll", SourceScope: []string{"poll:healthcheck"}}
web := Scope{Surface: SurfaceAuthedPage, Module: "web", SourceScope: []string{"*"}}
plain, err := json.Marshal(ipc.DescribeImageReq{Data: []byte("x")})
if err != nil {
t.Fatal(err)
}
noting, err := json.Marshal(ipc.DescribeImageReq{Data: []byte("x"), SaveNote: true})
if err != nil {
t.Fatal(err)
}
if err := Can(ipc.MethodDescribeImage, poller, plain); err != nil {
t.Errorf("describing without saving must stay a read: %v", err)
}
if err := Can(ipc.MethodDescribeImage, poller, noting); !errors.Is(err, ErrForbidden) {
t.Errorf("save_note out of scope = %v, want ErrForbidden", err)
}
if err := Can(ipc.MethodDescribeImage, web, noting); err != nil {
t.Errorf("a module scoped to everything must still be allowed: %v", err)
}
}
+32
View File
@@ -178,6 +178,18 @@ func Can(m ipc.Method, scope Scope, params json.RawMessage) error {
switch Requirement(m) {
case AuthRead:
// Describing an image is a read. Saving the description as a note is
// not: writeNote embeds it, so it comes back in a later turn as
// something Maven knows, under the source media:image:<id>, which no
// enrollment owns. The rung's own argument was that the method "cannot
// write a fact, set a reminder, or touch the tool allowlist" — it can
// write recall corpus, and that is what AuthWrite exists to scope. So
// the note half is held to the same source-scope rule WriteFact is.
if m == ipc.MethodDescribeImage && wantsNote(params) {
if !SourceAllowed(scope.SourceScope, ImageNoteSource) {
return fmt.Errorf("%w: source %q out of scope", ErrForbidden, ImageNoteSource)
}
}
// Any enrolled module may read. Reads through the surface level the
// Enrollment set (voice-L0 wouldn't be enrolled to write at all).
return nil
@@ -214,6 +226,26 @@ func Can(m ipc.Method, scope Scope, params json.RawMessage) error {
return nil
}
// ImageNoteSource is the source scope a caller needs to turn a described image
// into a note. The note itself is stored under "media:image:<id-prefix>"; the
// scope is checked against this stem, because the id is not known until the
// bytes arrive and no enrollment could name it in advance.
const ImageNoteSource = "media:image"
// wantsNote reports whether a DescribeImage call asked for the description to
// be remembered. Malformed params read as no: dispatch rejects them a moment
// later with a better error.
func wantsNote(raw json.RawMessage) bool {
if len(raw) == 0 {
return false
}
var p ipc.DescribeImageReq
if json.Unmarshal(raw, &p) != nil {
return false
}
return p.SaveNote
}
// SourceAllowed — true iff src is in scope (the wildcard "*" matches all).
// Empty scope ⇒ fail closed. The function is pure; we keep it exported so a
// future enrollment table can call into the same matching logic.
+37
View File
@@ -27,6 +27,7 @@ import (
"github.com/kami/maven/internal/morning"
"github.com/kami/maven/internal/netscan"
"github.com/kami/maven/internal/smarthome"
"github.com/kami/maven/internal/vision"
"github.com/kami/maven/internal/update"
"github.com/robfig/cron/v3"
)
@@ -693,6 +694,12 @@ type MediaConfig struct {
// MaxBytes — per-blob cap. 0 ⇒ media.DefaultMaxBytes (64 MiB).
MaxBytes int64 `json:"max_bytes,omitempty"`
// MaxTotalBytes — whole-store cap. 0 ⇒ media.DefaultMaxTotalBytes (4 GiB).
// The per-blob cap bounds one call; this one bounds the sum of them, which
// is what actually decides whether the disk mavend's database lives on can
// be filled from outside.
MaxTotalBytes int64 `json:"max_total_bytes,omitempty"`
}
// StoreDir reports the configured blob directory, or "" when media is not
@@ -1428,6 +1435,36 @@ func (c *Config) validate() error {
return err
}
}
// A media dir that cannot be created, or a vision endpoint that is a typo,
// used to be logged at wiring time and the capability just stayed off. A
// capability silently not existing is the hardest kind of misconfiguration
// to notice, so both fail here instead.
if c.Media != nil {
if c.Media.StoreDir() == "" {
return errors.New("media.dir is required when a media block is present")
}
if c.Media.MaxBytes < 0 || c.Media.MaxTotalBytes < 0 {
return errors.New("media: max_bytes and max_total_bytes cannot be negative")
}
if c.Media.MaxTotalBytes > 0 && c.Media.MaxBytes > c.Media.MaxTotalBytes {
return fmt.Errorf("media: max_bytes %d is above max_total_bytes %d",
c.Media.MaxBytes, c.Media.MaxTotalBytes)
}
}
if c.Vision != nil && c.Vision.Enabled {
if strings.TrimSpace(c.Vision.Endpoint) == "" {
return errors.New("vision.enabled set but vision.endpoint is empty")
}
if err := vision.ValidateEndpoint(c.Vision.Endpoint); err != nil {
return err
}
if c.Media.StoreDir() == "" {
return errors.New("vision.enabled set but there is no media block to keep the bytes in")
}
}
if c.Capture.Records() && c.Media.StoreDir() == "" {
return errors.New("capture.enabled set but there is no media block to keep the audio in")
}
if len(c.MorningRoutines) > 0 {
if err := morning.Validate(morningRoutinesFromConfig(c.MorningRoutines)); err != nil {
return err
+37
View File
@@ -221,3 +221,40 @@ func TestSpeakerBlockParsesFromJSON(t *testing.T) {
t.Errorf("thresholds = %+v", cfg.Speaker)
}
}
// A typo in the vision endpoint, or a media block with no dir, used to be
// logged once at wiring time and the capability just stayed off. A capability
// that silently does not exist is the hardest misconfiguration to notice, so
// both fail at startup now.
func TestSensesBlocksAreValidatedAtStartup(t *testing.T) {
bad := map[string]string{
"media with no dir": `{"media":{"retention":"48h"}}`,
"negative budget": `{"media":{"dir":"/srv/media","max_total_bytes":-1}}`,
"blob over the budget": `{"media":{"dir":"/srv/media","max_bytes":100,"max_total_bytes":10}}`,
"vision with no media dir": `{"vision":{"enabled":true,"endpoint":"http://127.0.0.1:8081"}}`,
"vision endpoint typo": `{"media":{"dir":"/srv/media"},"vision":{"enabled":true,"endpoint":"127.0.0.1:8081"}}`,
"vision on the wan": `{"media":{"dir":"/srv/media"},"vision":{"enabled":true,"endpoint":"http://8.8.8.8:8081"}}`,
"vision, empty endpoint": `{"media":{"dir":"/srv/media"},"vision":{"enabled":true}}`,
"capture with no store": `{"capture":{"enabled":true}}`,
}
for name, body := range bad {
t.Run(name, func(t *testing.T) {
if _, err := Load(writeConfig(t, body)); err == nil {
t.Fatal("want a startup error")
}
})
}
good := map[string]string{
"media alone": `{"media":{"dir":"/srv/media"}}`,
"media + vision": `{"media":{"dir":"/srv/media"},"vision":{"enabled":true,"endpoint":"http://127.0.0.1:8081"}}`,
"media + capture": `{"media":{"dir":"/srv/media"},"capture":{"enabled":true}}`,
"vision off": `{"vision":{"endpoint":"http://8.8.8.8:8081"}}`,
}
for name, body := range good {
t.Run(name, func(t *testing.T) {
if _, err := Load(writeConfig(t, body)); err != nil {
t.Fatalf("valid config refused: %v", err)
}
})
}
}
+13 -7
View File
@@ -190,14 +190,16 @@ type IngestMailResp struct {
//
// Source is provenance recorded on the stored blob: "telegram", "web:upload".
//
// Exactly one of Data or ID is set. ID re-describes an image core already has —
// a different question, or the first attempt that succeeds after a vision model
// finally lands on disk.
// Exactly one of Data or ID is set, and core refuses a request carrying both:
// it used to take the ID branch and drop the bytes without a word.
//
// The method exists only when core has both a media store and an enabled vision
// block; otherwise it answers ErrUnknownMethod, which is what "off unless
// configured" looks like at the wire. A surface cannot make Maven look at
// pictures by merely sending one.
// The method exists when core has a media store. Vision being off does NOT
// remove it: the bytes are stored and the answer says she cannot read the
// picture yet, which is re-runnable by ID once a vision model is on disk, and
// it is the state this box is in today. So a surface that gets a reply with an
// id and an empty description has not failed, it has stored something. With no
// media block the method answers ErrUnknownMethod, which is what "off unless
// configured" looks like at the wire.
type DescribeImageReq struct {
Data []byte `json:"data,omitempty"`
ID string `json:"id,omitempty"`
@@ -206,6 +208,10 @@ type DescribeImageReq struct {
// SaveNote — also write the description as a note (source
// "media:image:<id-prefix>") so it is recallable later. Default false: a
// glance at a screenshot is not automatically a memory.
//
// Setting it raises what the call needs: an embedded note is recall corpus,
// so the caller's source scope must cover auth.ImageNoteSource. Describing
// without saving stays an ordinary read.
SaveNote bool `json:"save_note,omitempty"`
}
+6 -4
View File
@@ -455,10 +455,12 @@ type Server struct {
SwapModelFn SwapModelFunc
ModelStatusFn ModelStatusFunc
// DescribeImageFn — looks at one image (Vikunja #252). Set by the daemon only
// when a media store is configured AND vision is enabled with a local
// endpoint; nil ⇒ MethodDescribeImage answers ErrUnknownMethod, so a surface
// cannot make Maven accept a photo by merely sending one.
// DescribeImageFn — looks at one image (Vikunja #252). Set by the daemon
// whenever a media store is configured. Vision being off does not clear it:
// the image is stored and the reply says she cannot read it yet, which is
// re-runnable by id later. nil ⇒ no media block ⇒ MethodDescribeImage
// answers ErrUnknownMethod, so a surface cannot make Maven accept a photo
// by merely sending one.
//
// It bypasses CoreAPI for the same reason IngestMailFn does: it needs a blob
// store and a vision server, neither of which is a store operation, and no