no-mistakes(review): fix pending-reload path, token modes, restart check
This commit is contained in:
@@ -71,6 +71,21 @@ if [ -e "$LEGACY_8081" ] || [ -L "$LEGACY_8081" ]; then
|
|||||||
log "removed legacy :8081 endpoint -> $STASHED"
|
log "removed legacy :8081 endpoint -> $STASHED"
|
||||||
fi
|
fi
|
||||||
|
|
||||||
|
# ── 1b. Honor a recorded pending reload regardless of token selection ───────
|
||||||
|
# A failed reload leaves PENDING_FILE set so a stashed legacy :8081 file can
|
||||||
|
# never remain loaded in the running nginx while dsh-web is down or not yet
|
||||||
|
# answering. Reconcile it before the token wait.
|
||||||
|
if [ -e "$PENDING_FILE" ]; then
|
||||||
|
if ! nginx -t >/dev/null 2>&1; then
|
||||||
|
die "pending nginx reload recorded but 'nginx -t' fails; fix the config and rerun"
|
||||||
|
fi
|
||||||
|
if ! nginx -s reload; then
|
||||||
|
die "pending nginx reload recorded but 'nginx -s reload' failed; will retry next run"
|
||||||
|
fi
|
||||||
|
rm -f "$PENDING_FILE"
|
||||||
|
log "completed pending nginx reload"
|
||||||
|
fi
|
||||||
|
|
||||||
# ── 2. Select the token the RUNNING service actually accepts ────────────────
|
# ── 2. Select the token the RUNNING service actually accepts ────────────────
|
||||||
# Functionally verify each journal candidate against the local dsh-web using the
|
# Functionally verify each journal candidate against the local dsh-web using the
|
||||||
# public authority, exactly as the /dsh-web-login proxy does. A token from a
|
# public authority, exactly as the /dsh-web-login proxy does. A token from a
|
||||||
@@ -114,6 +129,7 @@ if ! printf '%s\n' "$TOKEN" | cmp -s - "$TOKEN_FILE" 2>/dev/null; then
|
|||||||
mv "$TOKEN_FILE.tmp" "$TOKEN_FILE"
|
mv "$TOKEN_FILE.tmp" "$TOKEN_FILE"
|
||||||
log "recorded live launch token in $TOKEN_FILE"
|
log "recorded live launch token in $TOKEN_FILE"
|
||||||
fi
|
fi
|
||||||
|
chmod 600 "$TOKEN_FILE"
|
||||||
|
|
||||||
# ── 4. Regenerate the nginx login include (reload only when it changes) ────
|
# ── 4. Regenerate the nginx login include (reload only when it changes) ────
|
||||||
NEW_INCLUDE="$(mktemp "$INCLUDE_FILE.XXXXXX")"
|
NEW_INCLUDE="$(mktemp "$INCLUDE_FILE.XXXXXX")"
|
||||||
@@ -126,6 +142,8 @@ chmod 600 "$NEW_INCLUDE"
|
|||||||
# reload path so the include can never silently diverge from what nginx serves.
|
# reload path so the include can never silently diverge from what nginx serves.
|
||||||
APPLIED=""
|
APPLIED=""
|
||||||
[ -f "$STAMP_FILE" ] && APPLIED="$(cat "$STAMP_FILE" 2>/dev/null || true)"
|
[ -f "$STAMP_FILE" ] && APPLIED="$(cat "$STAMP_FILE" 2>/dev/null || true)"
|
||||||
|
[ -f "$INCLUDE_FILE" ] && chmod 600 "$INCLUDE_FILE"
|
||||||
|
[ -f "$STAMP_FILE" ] && chmod 600 "$STAMP_FILE"
|
||||||
|
|
||||||
if [ "$APPLIED" = "$TOKEN" ] && [ -f "$INCLUDE_FILE" ] && cmp -s "$NEW_INCLUDE" "$INCLUDE_FILE" \
|
if [ "$APPLIED" = "$TOKEN" ] && [ -f "$INCLUDE_FILE" ] && cmp -s "$NEW_INCLUDE" "$INCLUDE_FILE" \
|
||||||
&& [ ! -e "$PENDING_FILE" ]; then
|
&& [ ! -e "$PENDING_FILE" ]; then
|
||||||
@@ -140,6 +158,7 @@ RESTORE=""
|
|||||||
if [ -f "$INCLUDE_FILE" ]; then
|
if [ -f "$INCLUDE_FILE" ]; then
|
||||||
RESTORE="$(mktemp "$INCLUDE_FILE.bak.XXXXXX")"
|
RESTORE="$(mktemp "$INCLUDE_FILE.bak.XXXXXX")"
|
||||||
cp -p "$INCLUDE_FILE" "$RESTORE"
|
cp -p "$INCLUDE_FILE" "$RESTORE"
|
||||||
|
chmod 600 "$RESTORE"
|
||||||
fi
|
fi
|
||||||
|
|
||||||
mv "$NEW_INCLUDE" "$INCLUDE_FILE"
|
mv "$NEW_INCLUDE" "$INCLUDE_FILE"
|
||||||
|
|||||||
+16
-6
@@ -305,10 +305,11 @@ reloading nginx only when the on-disk include differs from the generated one or
|
|||||||
the applied-state stamp does not match the token (`nginx -t` guards the reload,
|
the applied-state stamp does not match the token (`nginx -t` guards the reload,
|
||||||
and the stamp is written only after a successful `nginx -s reload`, so a failed
|
and the stamp is written only after a successful `nginx -s reload`, so a failed
|
||||||
or interrupted reload is retried on the next run). Any failed reload records a
|
or interrupted reload is retried on the next run). Any failed reload records a
|
||||||
pending-reload marker under `/etc/dsh-web/` that forces the next run through the
|
pending-reload marker under `/etc/dsh-web/`; the next run honors it before the
|
||||||
reload path even when the token is unchanged, so a disabled legacy `:8081` file
|
token wait, reloading nginx and clearing the marker regardless of token state,
|
||||||
can never leave the running nginx unreloaded. Runs are serialized with
|
so a disabled legacy `:8081` file can never leave the running nginx unreloaded.
|
||||||
`flock` on `/run/capture-dsh-token.lock`. It **never stops or starts `dsh-web`**.
|
Runs are serialized with `flock` on `/run/capture-dsh-token.lock`. It **never
|
||||||
|
stops or starts `dsh-web`**.
|
||||||
It is triggered by the `dsh-web.service` drop-in
|
It is triggered by the `dsh-web.service` drop-in
|
||||||
`/etc/systemd/system/dsh-web.service.d/20-token-refresh.conf`
|
`/etc/systemd/system/dsh-web.service.d/20-token-refresh.conf`
|
||||||
(`ExecStartPost=/bin/systemctl --no-block start dsh-web-token.service`) and by
|
(`ExecStartPost=/bin/systemctl --no-block start dsh-web-token.service`) and by
|
||||||
@@ -393,11 +394,20 @@ fresh cookie. Both verified live 2026-09-11.
|
|||||||
```bash
|
```bash
|
||||||
# 5. Cookie survives a dsh-web restart, and the new token mints a new cookie.
|
# 5. Cookie survives a dsh-web restart, and the new token mints a new cookie.
|
||||||
ssh root@192.168.68.15 "pct exec 112 -- systemctl restart dsh-web"
|
ssh root@192.168.68.15 "pct exec 112 -- systemctl restart dsh-web"
|
||||||
ssh root@192.168.68.15 "pct exec 112 -- /opt/deepseek-harness/capture-dsh-token.sh"
|
|
||||||
ssh root@192.168.68.15 "pct exec 112 -- curl -s -b /tmp/dsh.jar -o /dev/null \
|
ssh root@192.168.68.15 "pct exec 112 -- curl -s -b /tmp/dsh.jar -o /dev/null \
|
||||||
-w '%{http_code}\n' -H 'Host: tankodhs.sysloggh.net' http://127.0.0.1:3080/"
|
-w '%{http_code}\n' -H 'Host: tankodhs.sysloggh.net' http://127.0.0.1:3080/"
|
||||||
# Expected: 200 — the pre-restart cookie is still accepted.
|
# Expected: 200 — the pre-restart cookie is still accepted.
|
||||||
TOKEN=$(ssh root@192.168.68.15 "pct exec 112 -- cat /etc/dsh-web/launch-token")
|
# The restart's ExecStartPost (or the 2-minute timer) refreshes the include. A
|
||||||
|
# manual run may no-op on the flock, so poll until the include carries a token
|
||||||
|
# the running process accepts (bounded wait) before the mint+reuse check.
|
||||||
|
for i in $(seq 1 60); do
|
||||||
|
TOKEN=$(ssh root@192.168.68.15 "pct exec 112 -- sed -n 's/.*token=//p' /etc/dsh-web/nginx-login.conf | tr -d ';\n'")
|
||||||
|
CODE=$(ssh root@192.168.68.15 "pct exec 112 -- curl -s -o /dev/null -w '%{http_code}' \
|
||||||
|
-H 'Host: tankodhs.sysloggh.net' 'http://127.0.0.1:3080/?token=$TOKEN'")
|
||||||
|
[ "$CODE" = "303" ] && break
|
||||||
|
sleep 2
|
||||||
|
done
|
||||||
|
# Expected: 303 — the include now holds the token the running process accepts.
|
||||||
ssh root@192.168.68.15 "pct exec 112 -- curl -s -c /tmp/dsh-new.jar -o /dev/null \
|
ssh root@192.168.68.15 "pct exec 112 -- curl -s -c /tmp/dsh-new.jar -o /dev/null \
|
||||||
-H 'Host: tankodhs.sysloggh.net' 'http://127.0.0.1:3080/?token=$TOKEN'"
|
-H 'Host: tankodhs.sysloggh.net' 'http://127.0.0.1:3080/?token=$TOKEN'"
|
||||||
ssh root@192.168.68.15 "pct exec 112 -- curl -s -b /tmp/dsh-new.jar -o /dev/null \
|
ssh root@192.168.68.15 "pct exec 112 -- curl -s -b /tmp/dsh-new.jar -o /dev/null \
|
||||||
|
|||||||
Reference in New Issue
Block a user