Skip to content

search/verify now respect hellgraph's declared not-yet-wired status - #19

Merged
mdheller merged 1 commit into
mainfrom
fix/search-respects-not-wired-status
Aug 2, 2026
Merged

mdheller merged 1 commit into
mainfrom
fix/search-respects-not-wired-status

Conversation

@mdheller

@mdheller mdheller commented Aug 2, 2026

Copy link
Copy Markdown
Member

Summary

Fixes #18 — validate CI has been red on main since 2026-07-19 (commit 4dfd418).

Root cause (confirmed by re-running the actual validate CI job's logs, and reproduced directly in a real golang:1.23-bookworm Linux container matching the ubuntu-latest runner): Makefile:39's bin/holmes search "truth and evidence" step makes a genuine HTTP call to http://127.0.0.1:8090/api/graph/ground (hellgraph-service). Nothing listens there in CI, so it's a guaranteed connection refused, exit 1, failing the whole validate target.

The actual inconsistency: holmes doctor already declares hellgraph-backed components (sherlock-search, deduction-engine) as "not-yet-wired" / wired: [] — but that declaration was 100% hardcoded and consulted by nothing. search attempted the live call regardless, contradicting the tool's own stated maturity status.

What changed (cmd/holmes/main.go)

  • Added hellgraphWired(): the single source of truth for "is a hellgraph backend actually configured" — true iff HOLMES_HELLGRAPH is explicitly set. An unset env var now honestly means "not configured", instead of silently defaulting to 127.0.0.1:8090 and finding out the hard way.
  • runDoctor(): wired/pending are now derived from hellgraphWired() instead of a static list. Behavior is byte-for-byte identical to before when unwired (verified).
  • runSearch(): when not wired, returns an honest "status": "not-yet-wired" JSON response and exits 0 (this is documented/expected behavior, not a command failure) instead of attempting a call that can only fail.
  • serve's /search and /verify HTTP handlers: same consistency fix, since they hit the identical searchGraph/verifyClaim path. When wired, behavior is unchanged (still hits hellgraph for real).
  • No changes to analyze, emit-evidence, graph, or govern — checked, and they're already fully self-contained (no network calls).

Verification

All in a real golang:1.23-bookworm container (podman run --rm -v <repo>:/work:Z -w /work golang:1.23-bookworm), nothing listening on port 8090:

  • Before fix (matches actual CI logs from run 29667029446): doctor/self-test/emit-evidence/analyze pass, then search step fails → make: *** [Makefile:39: validate] Error 1.
  • After fix: make validate → exit 0. /tmp/holmes-search.json contains {"status":"not-yet-wired", "message":"hellgraph backend is not configured (set HOLMES_HELLGRAPH to a live endpoint to enable search); see \holmes doctor`.", ...}`.
  • make release-dry-run → exit 0.
  • go build ./..., go vet ./... clean. No existing Go tests in the repo (go test ./... → [no test files]).
  • Regression check — with HOLMES_HELLGRAPH pointed at a stub HTTP server, doctor correctly reports "status": "partially-wired" / "wired": ["sherlock-search","deduction-engine"], and search performs a real live call and returns real grounding data, exactly as before this change.

Test plan

  • CI (validate workflow) goes green on this PR

…clares

Fixes CI: `make validate`'s `bin/holmes search "truth and evidence"` step
makes a real HTTP call to hellgraph-service (127.0.0.1:8090) regardless of
whether a backend is actually configured. With nothing listening there (the
real CI environment, and any dev box without hellgraph-service running),
this is a guaranteed connection-refused, exit 1, failing the whole target.
This is why `validate` has been red on main since 2026-07-19.

Meanwhile `holmes doctor` already declares hellgraph-backed components
("sherlock-search", "deduction-engine") as "not-yet-wired" with
`wired: []` — but that declaration was fully hardcoded and never consulted
by anything, so `search` happily attempted the live call anyway,
contradicting the tool's own stated maturity status.

Fix: add hellgraphWired(), the single source of truth for "is a hellgraph
backend actually configured" (true iff HOLMES_HELLGRAPH is explicitly set —
an unset env var is honestly "not configured", not "assume localhost and
find out the hard way" via the previous silent 127.0.0.1:8090 default).
`doctor`, `search`, and serve's `/search` and `/verify` handlers all consult
it now:
  - unwired: search/verify return an honest "not-yet-wired" JSON response
    (exit 0 for the CLI — this is documented, expected behavior, not an
    error) instead of attempting a call that can only fail; doctor's
    wired/pending lists are now real, derived from the same signal, rather
    than a static list disconnected from what search actually does.
  - wired (HOLMES_HELLGRAPH set): behavior is unchanged — a real live call
    is made, exactly as before.

Verified in a real `golang:1.23-bookworm` Linux container (matching the
ubuntu-latest CI runner) with nothing listening on port 8090:
`make validate` and `make release-dry-run` now both exit 0. Also verified
the wired path still works end-to-end against a stub HTTP backend.

Fixes #18
Copilot AI review requested due to automatic review settings August 2, 2026 14:56
@mdheller
mdheller merged commit 4875e08 into main Aug 2, 2026
7 checks passed
@mdheller
mdheller deleted the fix/search-respects-not-wired-status branch August 2, 2026 14:57

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR aligns holmes search/verify behavior with holmes doctor’s declared HellGraph wiring status, preventing unwired environments (like CI) from making guaranteed-failing localhost HTTP calls.

Changes:

  • Introduces hellgraphWired() as the gate for HellGraph-backed functionality (wired only when HOLMES_HELLGRAPH is explicitly set).
  • Updates doctor to derive wired/pending (and status) from the wiring state rather than a hardcoded list.
  • Makes search and the HTTP /search + /verify handlers return an explicit "not-yet-wired" JSON response without attempting network calls when unwired.

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Comment thread cmd/holmes/main.go

// hellgraphWired reports whether a HellGraph backend has been explicitly configured via
// HOLMES_HELLGRAPH. This is the single source of truth for hellgraph-backed integrations'
// wiring status: `doctor` reports it, and `search`/`verify` consult it before attempting a
Comment thread cmd/holmes/main.go
Comment on lines +333 to +336
if !hellgraphWired() {
json.NewEncoder(w).Encode(map[string]any{"status": "not-yet-wired", "query": q, "engine": "sherlock-search→hellgraph",
"message": "hellgraph backend is not configured (set HOLMES_HELLGRAPH); see /healthz or `holmes doctor`."})
return
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

search command ignores its own 'not-yet-wired' status and makes a live HTTP call, breaking CI with no backend present

2 participants