Skip to content
This repository was archived by the owner on Aug 25, 2026. It is now read-only.

fix(cognee): load allowlisted env files safely - #22

Merged
JTInventory merged 1 commit into
mainfrom
fm/cognee-safe-env-loader-0629
Jun 29, 2026
Merged

JTInventory merged 1 commit into
mainfrom
fm/cognee-safe-env-loader-0629

Conversation

@JTInventory

Copy link
Copy Markdown
Owner

Summary

Cognee live lookup can now load its required environment from FM_COGNEE_ENV_FILE without sourcing or evaluating that file. The loader accepts only the Cognee names the wrapper needs, keeps existing exported environment behavior, ignores unrelated names, and fails closed with secret-safe reasons for unreadable or malformed dotenv input.

The lookup path still calls only POST /api/v1/search in live mode, treats Cognee output as hint_only, requires local source verification, and never authorizes external actions.

Testing

  • tests/fm-cognee-lookup.test.sh
  • tests/fm-cognee-telemetry.test.sh
  • bash tests/fm-cognee-lookup-gate.test.sh
  • bash tests/fm-cognee-source-verify.test.sh
  • bash -n bin/fm-cognee-lookup.sh bin/fm-cognee-telemetry-lib.sh tests/fm-cognee-lookup.test.sh && git diff --check

Also attempted for t in tests/*.test.sh; do bash "$t"; done; it reached the Firstmate primary-checkout tangle guard and failed because this isolated ship worktree is intentionally on fm/cognee-safe-env-loader-0629, not main.

Post-Deploy Monitoring & Validation

No additional production monitoring is required by default because this is disabled unless an operator sets FM_COGNEE_ENV_FILE for the lookup process.

When enabled for a manual Cognee lookup, validate for one lookup window:

  • Logs/search terms: reason=env_file_unreadable, reason=env_file_malformed, reason=missing_required_env, external_action_authorized=false.
  • Healthy signal: env-file lookup reaches mode=live, returns cognee_answer_status=hint_only, and source verification reports verified_local_source or a clear fail-closed reason.
  • Failure signal: malformed/unreadable env-file blocks before any HTTP request, or missing required names are reported by name only.
  • Rollback: unset FM_COGNEE_ENV_FILE and rely on already-exported environment variables, or leave Cognee lookup disabled.
  • Owner/window: Firstmate operator during the manual lookup session.

Compound Engineering
Codex

@JTInventory
JTInventory merged commit e3e9642 into main Jun 29, 2026
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant