telegram: keep the bot token out of the log, and correct two design claims
net/http wraps every transport failure in *url.Error, whose Error() prints the request URL. Telegram accepts the bot token nowhere but the URL path, so a send failure wrote the live token into the daemon log. On 2026-08-01 homesrv could not reach api.telegram.org and did that once a minute for as long as the network stayed down. The token lives in deploy/telegram.env to stay out of the repo; putting it in `docker compose logs` undoes that. Both error sites now go through redact. The structural branch rewrites url.Error.URL and keeps the type, so errors.As still matches; anything else falls back to scrubbing the rendered message. No minimum-token-length guard: a one-character token would shred the message, but that beats leaking it. DESIGN.md still said the classifier cascade was the path that runs today with llmrouter wired nil, and gave the resident checkpoint as Qwen3.5-0.8B. Both stopped being true on 2026-07-31. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01TrVSBKe3RFDF4fGYKWYQnX
This commit is contained in:
@@ -757,9 +757,11 @@ Kept for provenance. **None of this is the current or intended design.**
|
||||
examples per intent, and misroutes appended as new centroid examples.
|
||||
*Replaced by* LLM-as-router (`REARCH.md`): one resident model emits
|
||||
GBNF-constrained JSON and also phrases replies; the embedder is demoted to
|
||||
a RAG hint. The classifier cascade is still the code path that runs today
|
||||
(`llmrouter` is wired nil) but it is an interim stopgap, and it is the known
|
||||
cause of weak RU query handling — not a design to extend.
|
||||
a RAG hint. *Landed 2026-07-31:* the LLM router is on by default and set
|
||||
`true` in `deploy/mavend.json`. The classifier cascade stays as the failure
|
||||
floor — it runs when there is no llama-server to talk to and on any per-turn
|
||||
LLM error — but routing by seed similarity is the known cause of weak RU
|
||||
query handling and is not a design to extend.
|
||||
- **Named STT/TTS model picks.** `maven.md` picked faster-whisper small/int8
|
||||
as primary STT with vosk RU for a low-latency command grammar, and silero
|
||||
(license unverified) as TTS with piper RU as the floor, all on
|
||||
@@ -769,8 +771,11 @@ Kept for provenance. **None of this is the current or intended design.**
|
||||
- **Small-model phrasing claim.** `maven.md` specified "lfm2.5 / sub-1b for
|
||||
phrasing — prompted, not trained," and `SPEC.md` named a specific resident
|
||||
size. Both are superseded by the RU-CPT + joint persona/router SFT plan.
|
||||
*Resolved 2026-07-30 (#318):* the resident checkpoint is **Qwen3.5-0.8B**
|
||||
now, with the CPT'd **Qwen3-1.7B** as the target (#122). Note the resident
|
||||
*Resolved 2026-07-30 (#318), revised 2026-07-31:* the resident checkpoint is
|
||||
stock **Qwen3-1.7B** (`UD-Q4_K_XL`, `n_ctx` 4096), which replaced
|
||||
Qwen3.5-0.8B after measuring better on both fixtures
|
||||
(`MODEL-BAKEOFF-31-07-2026.md`). The CPT'd **Qwen3-1.7B** remains the target
|
||||
(#122); what stock gets wrong is the persona, not the Russian. Note the resident
|
||||
model is no longer described as untrained — the target is trained
|
||||
end-to-end, which is the substantive change from the old claim.
|
||||
- **sqlcipher at rest.** `maven.md` specified sqlcipher with the key read at
|
||||
|
||||
Reference in New Issue
Block a user