fix: reject executable pi configuration
This commit is contained in:
@@ -36,6 +36,18 @@ file and verifies the absent/default state. Empty prior files are supported. The
|
||||
the actual host path from `PI_AUTH_FILE`; credentials remain in that protected host file and must
|
||||
never be passed as flags.
|
||||
|
||||
Installation-managed Pi provider/model configuration is declarative only. Any JSON value beginning
|
||||
with `!` is rejected recursively in the complete `models.json` before it can supply management
|
||||
choices, and the exact selected provider/model and credential payload is checked again before the
|
||||
isolated smoke files are written. The API returns only the fixed
|
||||
`Pi provider/model configuration is invalid` message; rejected commands, paths, and secrets are
|
||||
never included. Use `$NAME`/`${NAME}` environment references in `models.json`, or omit `apiKey` and
|
||||
provide the selected credential through the protected `PI_AUTH_FILE`, `THT_MODEL_API_KEY_FILE`, or
|
||||
`THT_SECRETS_FILE` contract. A literal leading exclamation mark uses Pi's `$!` escape. Direct
|
||||
secret-file references are not a `models.json` feature: ThothII converts its managed key source to
|
||||
the provider-native child environment, while `PI_AUTH_FILE` is mounted as Pi's protected credential
|
||||
store.
|
||||
|
||||
## Supported Compose entry points and current image
|
||||
|
||||
Use `thothctl start`, `stop`, `status`, `logs`, and `doctor` for ordinary installation lifecycle
|
||||
|
||||
Reference in New Issue
Block a user