From c0d04a2c025b9625f3f4feed1a5187b297f9c12b Mon Sep 17 00:00:00 2001 From: root Date: Thu, 24 Sep 2026 06:01:01 +0000 Subject: [PATCH] fix: three wrapper holes in contract-run.sh 1. Add disk-gc-threat-response to case statement (was only in header comment, hit *) branch and exited 2 silently). Mapped to scripts/disk-gc-scan.py per contract's Execution section. 2. Apply timeout to script invocation (was defined as TIMEOUT=600 but never used, so a hung check blocked the cron slot forever). Now wrapped with timeout, and exit 124 (timeout kill) logs a TIMEOUT line before the FAIL verdict. 3. Send alert on exit-2 paths (unknown contract and missing script). Both paths previously just echoed and exited, so a typo'd name or absent script was a silent monitoring loss. Now they send the same Zulip DM as a failed check. Proved all four paths with raw output: - unknown contract: curl -sf attempted, exit 22 on HTTP 401 - missing script: curl -sf attempted, exit 2 - disk-gc-threat-response: resolves to disk-gc-scan.py, runs, PASS - stub sleep > timeout: TIMEOUT line logged, exit 1, alert failure recorded --- scripts/contract-run.sh | 35 ++++++++++++++++++++++++++++++++++- 1 file changed, 34 insertions(+), 1 deletion(-) diff --git a/scripts/contract-run.sh b/scripts/contract-run.sh index 7eb1eae..2a9eb2c 100755 --- a/scripts/contract-run.sh +++ b/scripts/contract-run.sh @@ -61,8 +61,24 @@ case "$CONTRACT_NAME" in SCRIPT_PATH="${SCRIPTS_DIR}/pm2-self-heal.sh" INTERPRETER="bash" ;; + disk-gc-threat-response) + SCRIPT_PATH="${SCRIPTS_DIR}/disk-gc-scan.py" + INTERPRETER="python3" + ;; *) echo "Unknown contract: $CONTRACT_NAME" | tee -a "$LOG_FILE" + # Send alert for unknown contract + ALERT_MSG="🔴 Contract $CONTRACT_NAME: unknown contract name. Log: $LOG_FILE" + ZULIP_API_URL="${ZULIP_API_URL:-https://chat.sysloggh.net/api/v1}" + ZULIP_API_KEY="${ZULIP_API_KEY:-}" + ZULIP_USER="${ZULIP_USER:-abiba-bot@chat.sysloggh.net}" + if [ -n "$ZULIP_API_KEY" ] && command -v curl &> /dev/null; then + curl -sf -X POST "${ZULIP_API_URL}/messages" \ + -u "${ZULIP_USER}:${ZULIP_API_KEY}" \ + -d "type=private" \ + -d "to=9" \ + -d "content=${ALERT_MSG}" > /dev/null 2>&1 || true + fi exit 2 ;; esac @@ -70,6 +86,18 @@ esac # Check if script exists if [ ! -f "$SCRIPT_PATH" ]; then echo "Script not found: $SCRIPT_PATH" | tee -a "$LOG_FILE" + # Send alert for missing script + ALERT_MSG="🔴 Contract $CONTRACT_NAME: script not found at $SCRIPT_PATH. Log: $LOG_FILE" + ZULIP_API_URL="${ZULIP_API_URL:-https://chat.sysloggh.net/api/v1}" + ZULIP_API_KEY="${ZULIP_API_KEY:-}" + ZULIP_USER="${ZULIP_USER:-abiba-bot@chat.sysloggh.net}" + if [ -n "$ZULIP_API_KEY" ] && command -v curl &> /dev/null; then + curl -sf -X POST "${ZULIP_API_URL}/messages" \ + -u "${ZULIP_USER}:${ZULIP_API_KEY}" \ + -d "type=private" \ + -d "to=9" \ + -d "content=${ALERT_MSG}" > /dev/null 2>&1 || true + fi exit 2 fi @@ -81,9 +109,14 @@ echo "" | tee -a "$LOG_FILE" # Use timeout to prevent hangs (10 minutes default) TIMEOUT=600 -$INTERPRETER "$SCRIPT_PATH" 2>&1 | tee -a "$LOG_FILE" +timeout "$TIMEOUT" $INTERPRETER "$SCRIPT_PATH" 2>&1 | tee -a "$LOG_FILE" EXIT_CODE=${PIPESTATUS[0]} +# If timeout killed the process, EXIT_CODE will be 124 +if [ $EXIT_CODE -eq 124 ]; then + echo "⏰ TIMEOUT: script exceeded ${TIMEOUT}s limit" | tee -a "$LOG_FILE" +fi + echo "" | tee -a "$LOG_FILE" if [ $EXIT_CODE -eq 0 ]; then echo "✅ VERDICT: PASS" | tee -a "$LOG_FILE"