From 1974959cc9ef6ac34e506b8b617983570b501698 Mon Sep 17 00:00:00 2001 From: abiba-bot Date: Thu, 10 Sep 2026 01:46:06 +0000 Subject: [PATCH] no-mistakes(review): Gate wrapper checks on executed infisical; scope liveness guide --- docs/AUTHORING-GUIDE.md | 19 ++++++++++++++----- docs/probe-drift-round2-evidence.md | 2 +- scripts/agent-health-check.py | 11 ++++++----- tests/test_probe_drift.py | 14 ++++++++++++++ 4 files changed, 35 insertions(+), 11 deletions(-) diff --git a/docs/AUTHORING-GUIDE.md b/docs/AUTHORING-GUIDE.md index 6234e3b..f73129e 100644 --- a/docs/AUTHORING-GUIDE.md +++ b/docs/AUTHORING-GUIDE.md @@ -222,14 +222,23 @@ optional. The 2026-09-09 probe-drift rounds cost three false `DEGRADED` reports because a stale consumer probed the wrong port and nothing in the report said where it ran. -Pair it with the **any-HTTP-response liveness rule**: a probe is ALIVE on ANY -HTTP status — including `301` redirects and `401`/`403` auth challenges. A bare -`200` is not required and must never be a pass condition for an auth-gated -endpoint. **DOWN = connection refused (`000`) or timeout only.** +Pair it with the **scoped any-HTTP-response liveness rule**: for unauthenticated +or auth-gated endpoints — where any HTTP answer proves a listener is up (the +PVE API's `401`, LiteLLM health's `301` redirect) — a probe is ALIVE on ANY HTTP +status, including `301` redirects and `401`/`403` auth challenges. **DOWN = +connection refused (`000`) or timeout only.** + +Probes whose success condition is specifically a bare `200` are NOT covered by +the any-HTTP rule. On those — authenticated probes such as the Zulip message +POST and the router `/health` — an unexpected status (`401`/`403` from a bad or +missing credential, `5xx`, or anything other than the expected `200`) is an +**ALERT**, not "alive". ```markdown **Report format**: Begin every report with the absolute execution path -(`pwd -P` / script path). Alive = ANY HTTP status; DOWN = `000`/timeout only. +(`pwd -P` / script path). On auth-gated endpoints, alive = ANY HTTP status and +DOWN = `000`/timeout only; on probes whose expected result is `200`, any other +status is an alert. ``` The lint pipeline enforces the provenance clause: any contract with a diff --git a/docs/probe-drift-round2-evidence.md b/docs/probe-drift-round2-evidence.md index a575230..db44d57 100644 --- a/docs/probe-drift-round2-evidence.md +++ b/docs/probe-drift-round2-evidence.md @@ -240,7 +240,7 @@ The health script prints `📍 executed from: script=… cwd=…` and includes $ pwd -P /root/.treehouse/prose-contracts-9ce5f3/3/prose-contracts $ python3 -m pytest -q -22 passed +23 passed $ shellcheck scripts/prose-lint.sh (clean) ``` diff --git a/scripts/agent-health-check.py b/scripts/agent-health-check.py index 45c3d6a..c0c9b5c 100755 --- a/scripts/agent-health-check.py +++ b/scripts/agent-health-check.py @@ -546,13 +546,14 @@ def check_wrapper_integrity(): # /usr/bin/infisical, just past line 20 — false-failed as "path may be # wrong". Read the full body, accept a no-infisical wrapper, and verify # the absolute infisical path(s) the wrapper actually invokes. Only - # executed invocation lines count: a comment or dead prose mentioning a - # removed path (litellm-api-keys.prose.md documents - # `rm -f /usr/local/bin/infisical`) must not false-fail a wrapper whose - # real invocation works. + # executed (non-comment) lines count: a comment or dead prose mentioning + # a removed path (litellm-api-keys.prose.md documents + # `rm -f /usr/local/bin/infisical`) must neither produce a dangling path + # nor trigger the PATH check — it is not an invocation. wrapper_body = ssh(host, "cat /root/.local/bin/hermes 2>/dev/null", user=user) or "" + wrapper_code = "\n".join(line.split("#", 1)[0] for line in wrapper_body.splitlines()) invoked_paths = _infisical_invocation_paths(wrapper_body) - if "infisical" in wrapper_body: + if "infisical" in wrapper_code: if invoked_paths: missing = [] for _p in invoked_paths: diff --git a/tests/test_probe_drift.py b/tests/test_probe_drift.py index 2c51790..0d9bbec 100644 --- a/tests/test_probe_drift.py +++ b/tests/test_probe_drift.py @@ -231,6 +231,20 @@ def test_comment_mentioning_removed_infisical_path_is_not_failed(ahc, monkeypatc assert "wrapper infisical path OK" in out +def test_comment_only_infisical_mention_does_not_reach_path_check(ahc, monkeypatch, capsys): + # A comment-only mention of a removed infisical path on a healthy .env-based + # wrapper is not an invocation: it must not fall through to the `command -v` + # PATH check and false-FAIL `wrapper-no-infisical`. + _stub_wrapper_ssh(ahc, monkeypatch, + "#!/bin/bash\n# migrated from /usr/local/bin/infisical\n" + "source ~/.hermes/.env\nexec hermes-real \"$@\"\n", + test_x_result="MISS", command_v=None) + ahc.check_wrapper_integrity() + out = capsys.readouterr().out + assert ahc.FAIL == [] + assert "wrapper resolves creds without infisical" in out + + # ── item 4: prose-lint enforces report provenance (real consumer) ───── GOOD_CONTRACT = textwrap.dedent("""\