no-mistakes(review): Gate wrapper checks on executed infisical; scope liveness guide

This commit is contained in:
2026-09-10 01:46:06 +00:00
parent c59c9fb174
commit 1974959cc9
4 changed files with 35 additions and 11 deletions
+14 -5
View File
@@ -222,14 +222,23 @@ optional. The 2026-09-09 probe-drift rounds cost three false `DEGRADED` reports
because a stale consumer probed the wrong port and nothing in the report said
where it ran.
Pair it with the **any-HTTP-response liveness rule**: a probe is ALIVE on ANY
HTTP status — including `301` redirects and `401`/`403` auth challenges. A bare
`200` is not required and must never be a pass condition for an auth-gated
endpoint. **DOWN = connection refused (`000`) or timeout only.**
Pair it with the **scoped any-HTTP-response liveness rule**: for unauthenticated
or auth-gated endpoints — where any HTTP answer proves a listener is up (the
PVE API's `401`, LiteLLM health's `301` redirect) — a probe is ALIVE on ANY HTTP
status, including `301` redirects and `401`/`403` auth challenges. **DOWN =
connection refused (`000`) or timeout only.**
Probes whose success condition is specifically a bare `200` are NOT covered by
the any-HTTP rule. On those — authenticated probes such as the Zulip message
POST and the router `/health` — an unexpected status (`401`/`403` from a bad or
missing credential, `5xx`, or anything other than the expected `200`) is an
**ALERT**, not "alive".
```markdown
**Report format**: Begin every report with the absolute execution path
(`pwd -P` / script path). Alive = ANY HTTP status; DOWN = `000`/timeout only.
(`pwd -P` / script path). On auth-gated endpoints, alive = ANY HTTP status and
DOWN = `000`/timeout only; on probes whose expected result is `200`, any other
status is an alert.
```
The lint pipeline enforces the provenance clause: any contract with a
+1 -1
View File
@@ -240,7 +240,7 @@ The health script prints `📍 executed from: script=… cwd=…` and includes
$ pwd -P
/root/.treehouse/prose-contracts-9ce5f3/3/prose-contracts
$ python3 -m pytest -q
22 passed
23 passed
$ shellcheck scripts/prose-lint.sh
(clean)
```
+6 -5
View File
@@ -546,13 +546,14 @@ def check_wrapper_integrity():
# /usr/bin/infisical, just past line 20 — false-failed as "path may be
# wrong". Read the full body, accept a no-infisical wrapper, and verify
# the absolute infisical path(s) the wrapper actually invokes. Only
# executed invocation lines count: a comment or dead prose mentioning a
# removed path (litellm-api-keys.prose.md documents
# `rm -f /usr/local/bin/infisical`) must not false-fail a wrapper whose
# real invocation works.
# executed (non-comment) lines count: a comment or dead prose mentioning
# a removed path (litellm-api-keys.prose.md documents
# `rm -f /usr/local/bin/infisical`) must neither produce a dangling path
# nor trigger the PATH check — it is not an invocation.
wrapper_body = ssh(host, "cat /root/.local/bin/hermes 2>/dev/null", user=user) or ""
wrapper_code = "\n".join(line.split("#", 1)[0] for line in wrapper_body.splitlines())
invoked_paths = _infisical_invocation_paths(wrapper_body)
if "infisical" in wrapper_body:
if "infisical" in wrapper_code:
if invoked_paths:
missing = []
for _p in invoked_paths:
+14
View File
@@ -231,6 +231,20 @@ def test_comment_mentioning_removed_infisical_path_is_not_failed(ahc, monkeypatc
assert "wrapper infisical path OK" in out
def test_comment_only_infisical_mention_does_not_reach_path_check(ahc, monkeypatch, capsys):
# A comment-only mention of a removed infisical path on a healthy .env-based
# wrapper is not an invocation: it must not fall through to the `command -v`
# PATH check and false-FAIL `wrapper-no-infisical`.
_stub_wrapper_ssh(ahc, monkeypatch,
"#!/bin/bash\n# migrated from /usr/local/bin/infisical\n"
"source ~/.hermes/.env\nexec hermes-real \"$@\"\n",
test_x_result="MISS", command_v=None)
ahc.check_wrapper_integrity()
out = capsys.readouterr().out
assert ahc.FAIL == []
assert "wrapper resolves creds without infisical" in out
# ── item 4: prose-lint enforces report provenance (real consumer) ─────
GOOD_CONTRACT = textwrap.dedent("""\