no-mistakes(review): Ignore commented infisical paths; normalize probe-model tests

This commit is contained in:
2026-09-10 01:41:27 +00:00
parent 194e256ac5
commit c59c9fb174
3 changed files with 143 additions and 43 deletions
+41 -18
View File
@@ -490,6 +490,26 @@ def check_config_integrity():
# CHECK 6: Wrapper/CLI Integrity (NEW)
# ═══════════════════════════════════════════════════════════════════
def _infisical_invocation_paths(wrapper_body):
"""Absolute infisical paths the wrapper actually invokes.
Only executed (non-comment) lines count, and only a path followed by a real
infisical subcommand (e.g. `/usr/bin/infisical run`) is treated as an
invocation. A note such as `# migrated from /usr/local/bin/infisical` is
prose, not a call, so it must not manufacture a dangling-path false alarm.
"""
paths = []
for line in wrapper_body.splitlines():
code = line.split("#", 1)[0]
for _m in re.finditer(
r"(/[A-Za-z0-9._/-]*infisical)\s+(?:run|export|secrets|login|logout)\b",
code,
):
if _m.group(1) not in paths:
paths.append(_m.group(1))
return paths
def check_wrapper_integrity():
"""Verify the hermes CLI wrapper exists and can reach hermes-real."""
for name, agent in AGENTS.items():
@@ -525,29 +545,32 @@ def check_wrapper_integrity():
# the first 20 lines, so koonimo's wrapper — which DOES reference
# /usr/bin/infisical, just past line 20 — false-failed as "path may be
# wrong". Read the full body, accept a no-infisical wrapper, and verify
# that any absolute infisical path the wrapper hardcodes actually exists
# (PATH resolution alone is not enough — a dangling /usr/bin/infisical is
# a broken wrapper even when a different infisical is on PATH).
# the absolute infisical path(s) the wrapper actually invokes. Only
# executed invocation lines count: a comment or dead prose mentioning a
# removed path (litellm-api-keys.prose.md documents
# `rm -f /usr/local/bin/infisical`) must not false-fail a wrapper whose
# real invocation works.
wrapper_body = ssh(host, "cat /root/.local/bin/hermes 2>/dev/null", user=user) or ""
invoked_paths = _infisical_invocation_paths(wrapper_body)
if "infisical" in wrapper_body:
inf_paths = []
for _m in re.finditer(r"(/[A-Za-z0-9._/-]*infisical)", wrapper_body):
if _m.group(1) not in inf_paths:
inf_paths.append(_m.group(1))
dangling = []
for _p in inf_paths:
_exists = ssh(host, f"test -x {_p} && echo OK || echo MISS", user=user)
if not _exists or _exists.strip().splitlines()[-1] != "OK":
dangling.append(_p)
if inf_paths:
if dangling:
if invoked_paths:
missing = []
for _p in invoked_paths:
_exists = ssh(host, f"test -x {_p} && echo OK || echo MISS", user=user)
if not _exists or _exists.strip().splitlines()[-1] != "OK":
missing.append(_p)
if len(missing) == len(invoked_paths):
inf_actual = ssh(host, "command -v infisical 2>/dev/null", user=user)
suffix = f" (infisical at {inf_actual})" if inf_actual else ""
print(f" ❌ {name}: wrapper hardcodes missing infisical path(s) "
f"{', '.join(dangling)}{suffix}")
print(f" ❌ {name}: wrapper invokes infisical via missing path(s) "
f"{', '.join(missing)}{suffix}")
_fail(f"wrapper-infisical-path:{name}", name)
elif "/usr/bin/infisical" not in wrapper_body:
print(f" ⚠️ {name}: wrapper infisical path differs — informational")
elif missing:
print(f" ⚠️ {name}: wrapper has an unused/missing infisical path "
f"({', '.join(missing)}) but a working invocation — informational")
elif "/usr/bin/infisical" not in invoked_paths:
print(f" ⚠️ {name}: wrapper infisical path differs "
f"({', '.join(invoked_paths)}) — informational")
else:
print(f" ✅ {name}: wrapper infisical path OK")
else: