no-mistakes(review): Gate wrapper checks on executed infisical; scope liveness guide

This commit is contained in:
2026-09-10 01:46:06 +00:00
parent c59c9fb174
commit 1974959cc9
4 changed files with 35 additions and 11 deletions
+6 -5
View File
@@ -546,13 +546,14 @@ def check_wrapper_integrity():
# /usr/bin/infisical, just past line 20 — false-failed as "path may be
# wrong". Read the full body, accept a no-infisical wrapper, and verify
# the absolute infisical path(s) the wrapper actually invokes. Only
# executed invocation lines count: a comment or dead prose mentioning a
# removed path (litellm-api-keys.prose.md documents
# `rm -f /usr/local/bin/infisical`) must not false-fail a wrapper whose
# real invocation works.
# executed (non-comment) lines count: a comment or dead prose mentioning
# a removed path (litellm-api-keys.prose.md documents
# `rm -f /usr/local/bin/infisical`) must neither produce a dangling path
# nor trigger the PATH check — it is not an invocation.
wrapper_body = ssh(host, "cat /root/.local/bin/hermes 2>/dev/null", user=user) or ""
wrapper_code = "\n".join(line.split("#", 1)[0] for line in wrapper_body.splitlines())
invoked_paths = _infisical_invocation_paths(wrapper_body)
if "infisical" in wrapper_body:
if "infisical" in wrapper_code:
if invoked_paths:
missing = []
for _p in invoked_paths: