no-mistakes(review): re-sample systemd invocation each pass during token wait

This commit is contained in:
2026-09-11 17:34:53 +00:00
parent 55f1208eb8
commit e97145c88f
2 changed files with 26 additions and 23 deletions
+21 -20
View File
@@ -104,25 +104,16 @@ if [ -e "$PENDING_FILE" ]; then
fi
# ── 2. Select the token the RUNNING service actually accepts ────────────────
# Read candidates ONLY from the service's current systemd invocation so a
# restarted process's stale token is never considered while its new startup
# banner is still pending; there is no whole-journal or cross-invocation
# fallback. Each candidate is then functionally verified against the local
# dsh-web using the public authority, exactly as the /dsh-web-login proxy does,
# and the first that answers 303 is the live token. Candidates are re-probed
# newest-first on each pass (connection failures stay eligible) until one is
# accepted or the wait elapses.
INVOCATION="$(systemctl show -p InvocationID --value "$JOURNAL_UNIT" 2>/dev/null || true)"
JOURNAL_ARGS=(-u "$JOURNAL_UNIT")
if [ -n "$INVOCATION" ] && [ "$INVOCATION" != "n/a" ]; then
JOURNAL_ARGS+=("_SYSTEMD_INVOCATION_ID=$INVOCATION")
else
log "WARNING: no invocation id for $JOURNAL_UNIT; no token can be selected this run"
fi
collect_tokens() {
[ "${#JOURNAL_ARGS[@]}" -ge 3 ] || return 0
journalctl "${JOURNAL_ARGS[@]}" --no-pager -o cat 2>/dev/null \
# Re-sample the service's CURRENT systemd invocation on every pass and read
# candidates only from it, so a restart that lands during the wait immediately
# switches to the new invocation; there is no whole-journal or cross-invocation
# fallback, and an empty/unknown invocation just waits. Each candidate is then
# functionally verified against the local dsh-web using the public authority,
# exactly as the /dsh-web-login proxy does, and the first that answers 303 is
# the live token. Candidates are re-probed newest-first on each pass (connection
# failures stay eligible) until one is accepted or the wait elapses.
journal_tokens() {
journalctl -u "$JOURNAL_UNIT" "_SYSTEMD_INVOCATION_ID=$1" --no-pager -o cat 2>/dev/null \
| grep -oE 'dsh web: https?://[^[:space:]]+[?&]token=[^[:space:]]+' \
| sed -E 's/.*[?&]token=//' \
| grep -E '^[A-Za-z0-9._~+/=:@-]+$' \
@@ -131,8 +122,18 @@ collect_tokens() {
TOKEN=""
DEADLINE=$((SECONDS + TOKEN_WAIT))
NO_INVOCATION_WARNED=0
while [ -z "$TOKEN" ] && [ "$SECONDS" -lt "$DEADLINE" ]; do
for cand in $(collect_tokens); do
INVOCATION="$(systemctl show -p InvocationID --value "$JOURNAL_UNIT" 2>/dev/null || true)"
if [ -z "$INVOCATION" ] || [ "$INVOCATION" = "n/a" ]; then
if [ "$NO_INVOCATION_WARNED" -eq 0 ]; then
log "WARNING: no invocation id for $JOURNAL_UNIT; waiting for a live invocation"
NO_INVOCATION_WARNED=1
fi
sleep 2
continue
fi
for cand in $(journal_tokens "$INVOCATION"); do
code="$(curl -s -o /dev/null --max-time 5 -w '%{http_code}' \
-H "Host: $LOGIN_HOST" "$LOGIN_UPSTREAM/?token=$cand" || true)"
if [ "$code" = "303" ]; then
+5 -3
View File
@@ -294,9 +294,11 @@ proxy_pass http://127.0.0.1:3080/?token=<TOKEN>;
`/opt/deepseek-harness/capture-dsh-token.sh` (source:
`scripts/capture-dsh-token.sh`) reads candidate launch tokens from the journal
**scoped to the service's current systemd invocation**
(`systemctl show -p InvocationID` + `_SYSTEMD_INVOCATION_ID=`), so a restarted
process's stale token is never considered while its new startup banner is still
pending; there is no whole-journal or cross-invocation fallback. Each candidate
(`systemctl show -p InvocationID` + `_SYSTEMD_INVOCATION_ID=`), re-sampling the
invocation on every pass so a restart that lands during the wait switches to the
new invocation; a restarted process's stale token is never considered while its
new startup banner is still pending and there is no whole-journal or
cross-invocation fallback. Each candidate
is then functionally verified against dsh-web with `Host: tankodhs.sysloggh.net`,
using the first the running process accepts with `303`. It waits up to 120s for
a restarted process to accept a token and re-probes every current-invocation