diff --git a/scripts/capture-dsh-token.sh b/scripts/capture-dsh-token.sh index 89c609c..273fe6d 100755 --- a/scripts/capture-dsh-token.sh +++ b/scripts/capture-dsh-token.sh @@ -71,6 +71,21 @@ if [ -e "$LEGACY_8081" ] || [ -L "$LEGACY_8081" ]; then log "removed legacy :8081 endpoint -> $STASHED" fi +# ── 1b. Honor a recorded pending reload regardless of token selection ─────── +# A failed reload leaves PENDING_FILE set so a stashed legacy :8081 file can +# never remain loaded in the running nginx while dsh-web is down or not yet +# answering. Reconcile it before the token wait. +if [ -e "$PENDING_FILE" ]; then + if ! nginx -t >/dev/null 2>&1; then + die "pending nginx reload recorded but 'nginx -t' fails; fix the config and rerun" + fi + if ! nginx -s reload; then + die "pending nginx reload recorded but 'nginx -s reload' failed; will retry next run" + fi + rm -f "$PENDING_FILE" + log "completed pending nginx reload" +fi + # ── 2. Select the token the RUNNING service actually accepts ──────────────── # Functionally verify each journal candidate against the local dsh-web using the # public authority, exactly as the /dsh-web-login proxy does. A token from a @@ -114,6 +129,7 @@ if ! printf '%s\n' "$TOKEN" | cmp -s - "$TOKEN_FILE" 2>/dev/null; then mv "$TOKEN_FILE.tmp" "$TOKEN_FILE" log "recorded live launch token in $TOKEN_FILE" fi +chmod 600 "$TOKEN_FILE" # ── 4. Regenerate the nginx login include (reload only when it changes) ──── NEW_INCLUDE="$(mktemp "$INCLUDE_FILE.XXXXXX")" @@ -126,6 +142,8 @@ chmod 600 "$NEW_INCLUDE" # reload path so the include can never silently diverge from what nginx serves. APPLIED="" [ -f "$STAMP_FILE" ] && APPLIED="$(cat "$STAMP_FILE" 2>/dev/null || true)" +[ -f "$INCLUDE_FILE" ] && chmod 600 "$INCLUDE_FILE" +[ -f "$STAMP_FILE" ] && chmod 600 "$STAMP_FILE" if [ "$APPLIED" = "$TOKEN" ] && [ -f "$INCLUDE_FILE" ] && cmp -s "$NEW_INCLUDE" "$INCLUDE_FILE" \ && [ ! -e "$PENDING_FILE" ]; then @@ -140,6 +158,7 @@ RESTORE="" if [ -f "$INCLUDE_FILE" ]; then RESTORE="$(mktemp "$INCLUDE_FILE.bak.XXXXXX")" cp -p "$INCLUDE_FILE" "$RESTORE" + chmod 600 "$RESTORE" fi mv "$NEW_INCLUDE" "$INCLUDE_FILE" diff --git a/zulip-health.prose.md b/zulip-health.prose.md index e4ee53c..ac31867 100644 --- a/zulip-health.prose.md +++ b/zulip-health.prose.md @@ -305,10 +305,11 @@ reloading nginx only when the on-disk include differs from the generated one or the applied-state stamp does not match the token (`nginx -t` guards the reload, and the stamp is written only after a successful `nginx -s reload`, so a failed or interrupted reload is retried on the next run). Any failed reload records a -pending-reload marker under `/etc/dsh-web/` that forces the next run through the -reload path even when the token is unchanged, so a disabled legacy `:8081` file -can never leave the running nginx unreloaded. Runs are serialized with -`flock` on `/run/capture-dsh-token.lock`. It **never stops or starts `dsh-web`**. +pending-reload marker under `/etc/dsh-web/`; the next run honors it before the +token wait, reloading nginx and clearing the marker regardless of token state, +so a disabled legacy `:8081` file can never leave the running nginx unreloaded. +Runs are serialized with `flock` on `/run/capture-dsh-token.lock`. It **never +stops or starts `dsh-web`**. It is triggered by the `dsh-web.service` drop-in `/etc/systemd/system/dsh-web.service.d/20-token-refresh.conf` (`ExecStartPost=/bin/systemctl --no-block start dsh-web-token.service`) and by @@ -393,11 +394,20 @@ fresh cookie. Both verified live 2026-09-11. ```bash # 5. Cookie survives a dsh-web restart, and the new token mints a new cookie. ssh root@192.168.68.15 "pct exec 112 -- systemctl restart dsh-web" -ssh root@192.168.68.15 "pct exec 112 -- /opt/deepseek-harness/capture-dsh-token.sh" ssh root@192.168.68.15 "pct exec 112 -- curl -s -b /tmp/dsh.jar -o /dev/null \ -w '%{http_code}\n' -H 'Host: tankodhs.sysloggh.net' http://127.0.0.1:3080/" # Expected: 200 — the pre-restart cookie is still accepted. -TOKEN=$(ssh root@192.168.68.15 "pct exec 112 -- cat /etc/dsh-web/launch-token") +# The restart's ExecStartPost (or the 2-minute timer) refreshes the include. A +# manual run may no-op on the flock, so poll until the include carries a token +# the running process accepts (bounded wait) before the mint+reuse check. +for i in $(seq 1 60); do + TOKEN=$(ssh root@192.168.68.15 "pct exec 112 -- sed -n 's/.*token=//p' /etc/dsh-web/nginx-login.conf | tr -d ';\n'") + CODE=$(ssh root@192.168.68.15 "pct exec 112 -- curl -s -o /dev/null -w '%{http_code}' \ + -H 'Host: tankodhs.sysloggh.net' 'http://127.0.0.1:3080/?token=$TOKEN'") + [ "$CODE" = "303" ] && break + sleep 2 +done +# Expected: 303 — the include now holds the token the running process accepts. ssh root@192.168.68.15 "pct exec 112 -- curl -s -c /tmp/dsh-new.jar -o /dev/null \ -H 'Host: tankodhs.sysloggh.net' 'http://127.0.0.1:3080/?token=$TOKEN'" ssh root@192.168.68.15 "pct exec 112 -- curl -s -b /tmp/dsh-new.jar -o /dev/null \