Skip to content

fix(optics): remove Gate-era enforcement from Optics - #147

Merged
zacharybalicki merged 8 commits into
mainfrom
cursor/optics-remove-enforcement-c44b
Sep 30, 2026
Merged

zacharybalicki merged 8 commits into
mainfrom
cursor/optics-remove-enforcement-c44b

Conversation

@zacharybalicki

@zacharybalicki zacharybalicki commented Sep 30, 2026 •

Copy link
Copy Markdown
Member

CANDIDATE_ONLY. No npm publish, no PyPI publish, and no install.vantio.ai go-live.

Optics is observational only. This PR removes remaining Gate-era enforcement / dead FREE_MODE arms so Optics records destination, process, size, timing, and status and never blocks, delays, rewrites, or waits on policy.

Kate queue

In Optics batch after #142 and #144. Order: #142 → #144 → #145 → #147 → #146 → #148.

Approve exact head only (kvantio). No admin bypass.

Current head: bfd4dff7acee84b9862895b417cc0d154c95e74c
CI on this tip: 8/8 green (post-rebase onto main after #140/#141).
Independent council: PASS_WITH_NONBLOCKING_NOTES (read-only; not a kvantio APPROVE).

What this does

  • CLI FREE_MODE constant removed; host/size/spend arms that followed if (FREE_MODE) return "observe" removed.
  • In-scope calls are still recorded and still proceed.
  • Python _decide returns only pass or observe.
  • _dispatch_gate and _apply_cli_gate no longer contain block or dry-run arms; spawned CLI argv is left as written.
  • Tests fail if those arms reappear.

Installer pins unchanged (CLI 0.3.24 / Python 3.1.0). Nothing published. No history rewrite.

Do not merge until CI green, independent council PASS or PASS_WITH_NONBLOCKING_NOTES, and exact-head kvantio APPROVE.

Optics records destination, process, size, timing, and status. It does
not fetch policy, block hosts, apply a spend cap, redact requests, or
rewrite curl, wget, httpie, or aria2c. A VANTIO_API_KEY is not sent for
enforcement. If that key is set, Optics says enforcement is provided by
Phantom Engine and the call still proceeds.

The gate-mcp preview no longer names a block. This MCP does not decide
host, size, or spend outcomes.

CANDIDATE_ONLY. Not published.
zacharybalicki and others added 6 commits September 30, 2026 13:52
…nd assumption

The live path already returns before those tails. Spawn tests now check that a present httpie or aria2c binary does not fetch Gate config. The stale-name inventory records that the BLOCKED_HOST sight_loop assertions left with that event.

CANDIDATE_ONLY. Not published.
fetch_policy no longer calls the control plane or sends the API key. redact_pii returns the original text. Both say enforcement is provided by Phantom Engine. The gate-mcp preview tail after the observational return is gone.

CANDIDATE_ONLY. Not published.
httpie and aria2c are stopped within two seconds. tls.connect no longer waits on a socket the plain TCP sink will not close. runAgent kills a child that is still up after eight seconds, so one open handle cannot hold the suite.

CANDIDATE_ONLY. Not published.
Optics stays observe-only. The CLI no longer carries a constant-true
FREE_MODE switch or the host, size, and spend arms behind it. Python
_dispatch_gate and _apply_cli_gate only handle pass and observe.

Co-authored-by: VantioAi <zach@vantio.ai>
VANTIO_SUMMARY stays a runtime read so the env catalog still matches the
CLI. The two sight_loop comments left with the deleted ingest body, so the
interceptor is no longer frozen stale-name debt.

Co-authored-by: VantioAi <zach@vantio.ai>
The observe path no longer carries unused redaction helpers, block/dry-run
ingest labels, or GateBlockedError. Calls are recorded as observations and
are not rewritten.

Co-authored-by: VantioAi <zach@vantio.ai>
@zacharybalicki
zacharybalicki marked this pull request as ready for review September 30, 2026 21:48
@zacharybalicki
zacharybalicki merged commit b1ef128 into main Sep 30, 2026
8 checks passed
@kvantio
kvantio deleted the cursor/optics-remove-enforcement-c44b branch September 30, 2026 23:08
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants