search/verify now respect hellgraph's declared not-yet-wired status - #19
Merged
Merged
Conversation
…clares
Fixes CI: `make validate`'s `bin/holmes search "truth and evidence"` step
makes a real HTTP call to hellgraph-service (127.0.0.1:8090) regardless of
whether a backend is actually configured. With nothing listening there (the
real CI environment, and any dev box without hellgraph-service running),
this is a guaranteed connection-refused, exit 1, failing the whole target.
This is why `validate` has been red on main since 2026-07-19.
Meanwhile `holmes doctor` already declares hellgraph-backed components
("sherlock-search", "deduction-engine") as "not-yet-wired" with
`wired: []` — but that declaration was fully hardcoded and never consulted
by anything, so `search` happily attempted the live call anyway,
contradicting the tool's own stated maturity status.
Fix: add hellgraphWired(), the single source of truth for "is a hellgraph
backend actually configured" (true iff HOLMES_HELLGRAPH is explicitly set —
an unset env var is honestly "not configured", not "assume localhost and
find out the hard way" via the previous silent 127.0.0.1:8090 default).
`doctor`, `search`, and serve's `/search` and `/verify` handlers all consult
it now:
- unwired: search/verify return an honest "not-yet-wired" JSON response
(exit 0 for the CLI — this is documented, expected behavior, not an
error) instead of attempting a call that can only fail; doctor's
wired/pending lists are now real, derived from the same signal, rather
than a static list disconnected from what search actually does.
- wired (HOLMES_HELLGRAPH set): behavior is unchanged — a real live call
is made, exactly as before.
Verified in a real `golang:1.23-bookworm` Linux container (matching the
ubuntu-latest CI runner) with nothing listening on port 8090:
`make validate` and `make release-dry-run` now both exit 0. Also verified
the wired path still works end-to-end against a stub HTTP backend.
Fixes #18
There was a problem hiding this comment.
Pull request overview
This PR aligns holmes search/verify behavior with holmes doctor’s declared HellGraph wiring status, preventing unwired environments (like CI) from making guaranteed-failing localhost HTTP calls.
Changes:
- Introduces
hellgraphWired()as the gate for HellGraph-backed functionality (wired only whenHOLMES_HELLGRAPHis explicitly set). - Updates
doctorto derivewired/pending(and status) from the wiring state rather than a hardcoded list. - Makes
searchand the HTTP/search+/verifyhandlers return an explicit"not-yet-wired"JSON response without attempting network calls when unwired.
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
|
|
||
| // hellgraphWired reports whether a HellGraph backend has been explicitly configured via | ||
| // HOLMES_HELLGRAPH. This is the single source of truth for hellgraph-backed integrations' | ||
| // wiring status: `doctor` reports it, and `search`/`verify` consult it before attempting a |
Comment on lines
+333
to
+336
| if !hellgraphWired() { | ||
| json.NewEncoder(w).Encode(map[string]any{"status": "not-yet-wired", "query": q, "engine": "sherlock-search→hellgraph", | ||
| "message": "hellgraph backend is not configured (set HOLMES_HELLGRAPH); see /healthz or `holmes doctor`."}) | ||
| return |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Fixes #18 —
validateCI has been red onmainsince 2026-07-19 (commit4dfd418).Root cause (confirmed by re-running the actual
validateCI job's logs, and reproduced directly in a realgolang:1.23-bookwormLinux container matching theubuntu-latestrunner):Makefile:39'sbin/holmes search "truth and evidence"step makes a genuine HTTP call tohttp://127.0.0.1:8090/api/graph/ground(hellgraph-service). Nothing listens there in CI, so it's a guaranteedconnection refused, exit 1, failing the wholevalidatetarget.The actual inconsistency:
holmes doctoralready declares hellgraph-backed components (sherlock-search,deduction-engine) as"not-yet-wired"/wired: []— but that declaration was 100% hardcoded and consulted by nothing.searchattempted the live call regardless, contradicting the tool's own stated maturity status.What changed (
cmd/holmes/main.go)hellgraphWired(): the single source of truth for "is a hellgraph backend actually configured" —trueiffHOLMES_HELLGRAPHis explicitly set. An unset env var now honestly means "not configured", instead of silently defaulting to127.0.0.1:8090and finding out the hard way.runDoctor():wired/pendingare now derived fromhellgraphWired()instead of a static list. Behavior is byte-for-byte identical to before when unwired (verified).runSearch(): when not wired, returns an honest"status": "not-yet-wired"JSON response and exits 0 (this is documented/expected behavior, not a command failure) instead of attempting a call that can only fail.serve's/searchand/verifyHTTP handlers: same consistency fix, since they hit the identicalsearchGraph/verifyClaimpath. When wired, behavior is unchanged (still hits hellgraph for real).analyze,emit-evidence,graph, orgovern— checked, and they're already fully self-contained (no network calls).Verification
All in a real
golang:1.23-bookwormcontainer (podman run --rm -v <repo>:/work:Z -w /work golang:1.23-bookworm), nothing listening on port 8090:29667029446):doctor/self-test/emit-evidence/analyzepass, thensearchstep fails →make: *** [Makefile:39: validate] Error 1.make validate→ exit 0./tmp/holmes-search.jsoncontains{"status":"not-yet-wired", "message":"hellgraph backend is not configured (set HOLMES_HELLGRAPH to a live endpoint to enable search); see \holmes doctor`.", ...}`.make release-dry-run→ exit 0.go build ./...,go vet ./...clean. No existing Go tests in the repo (go test ./...→[no test files]).HOLMES_HELLGRAPHpointed at a stub HTTP server,doctorcorrectly reports"status": "partially-wired"/"wired": ["sherlock-search","deduction-engine"], andsearchperforms a real live call and returns real grounding data, exactly as before this change.Test plan
validateworkflow) goes green on this PR