no-mistakes(review): re-sample systemd invocation each pass during token wait
This commit is contained in:
@@ -104,25 +104,16 @@ if [ -e "$PENDING_FILE" ]; then
|
||||
fi
|
||||
|
||||
# ── 2. Select the token the RUNNING service actually accepts ────────────────
|
||||
# Read candidates ONLY from the service's current systemd invocation so a
|
||||
# restarted process's stale token is never considered while its new startup
|
||||
# banner is still pending; there is no whole-journal or cross-invocation
|
||||
# fallback. Each candidate is then functionally verified against the local
|
||||
# dsh-web using the public authority, exactly as the /dsh-web-login proxy does,
|
||||
# and the first that answers 303 is the live token. Candidates are re-probed
|
||||
# newest-first on each pass (connection failures stay eligible) until one is
|
||||
# accepted or the wait elapses.
|
||||
INVOCATION="$(systemctl show -p InvocationID --value "$JOURNAL_UNIT" 2>/dev/null || true)"
|
||||
JOURNAL_ARGS=(-u "$JOURNAL_UNIT")
|
||||
if [ -n "$INVOCATION" ] && [ "$INVOCATION" != "n/a" ]; then
|
||||
JOURNAL_ARGS+=("_SYSTEMD_INVOCATION_ID=$INVOCATION")
|
||||
else
|
||||
log "WARNING: no invocation id for $JOURNAL_UNIT; no token can be selected this run"
|
||||
fi
|
||||
|
||||
collect_tokens() {
|
||||
[ "${#JOURNAL_ARGS[@]}" -ge 3 ] || return 0
|
||||
journalctl "${JOURNAL_ARGS[@]}" --no-pager -o cat 2>/dev/null \
|
||||
# Re-sample the service's CURRENT systemd invocation on every pass and read
|
||||
# candidates only from it, so a restart that lands during the wait immediately
|
||||
# switches to the new invocation; there is no whole-journal or cross-invocation
|
||||
# fallback, and an empty/unknown invocation just waits. Each candidate is then
|
||||
# functionally verified against the local dsh-web using the public authority,
|
||||
# exactly as the /dsh-web-login proxy does, and the first that answers 303 is
|
||||
# the live token. Candidates are re-probed newest-first on each pass (connection
|
||||
# failures stay eligible) until one is accepted or the wait elapses.
|
||||
journal_tokens() {
|
||||
journalctl -u "$JOURNAL_UNIT" "_SYSTEMD_INVOCATION_ID=$1" --no-pager -o cat 2>/dev/null \
|
||||
| grep -oE 'dsh web: https?://[^[:space:]]+[?&]token=[^[:space:]]+' \
|
||||
| sed -E 's/.*[?&]token=//' \
|
||||
| grep -E '^[A-Za-z0-9._~+/=:@-]+$' \
|
||||
@@ -131,8 +122,18 @@ collect_tokens() {
|
||||
|
||||
TOKEN=""
|
||||
DEADLINE=$((SECONDS + TOKEN_WAIT))
|
||||
NO_INVOCATION_WARNED=0
|
||||
while [ -z "$TOKEN" ] && [ "$SECONDS" -lt "$DEADLINE" ]; do
|
||||
for cand in $(collect_tokens); do
|
||||
INVOCATION="$(systemctl show -p InvocationID --value "$JOURNAL_UNIT" 2>/dev/null || true)"
|
||||
if [ -z "$INVOCATION" ] || [ "$INVOCATION" = "n/a" ]; then
|
||||
if [ "$NO_INVOCATION_WARNED" -eq 0 ]; then
|
||||
log "WARNING: no invocation id for $JOURNAL_UNIT; waiting for a live invocation"
|
||||
NO_INVOCATION_WARNED=1
|
||||
fi
|
||||
sleep 2
|
||||
continue
|
||||
fi
|
||||
for cand in $(journal_tokens "$INVOCATION"); do
|
||||
code="$(curl -s -o /dev/null --max-time 5 -w '%{http_code}' \
|
||||
-H "Host: $LOGIN_HOST" "$LOGIN_UPSTREAM/?token=$cand" || true)"
|
||||
if [ "$code" = "303" ]; then
|
||||
|
||||
@@ -294,9 +294,11 @@ proxy_pass http://127.0.0.1:3080/?token=<TOKEN>;
|
||||
`/opt/deepseek-harness/capture-dsh-token.sh` (source:
|
||||
`scripts/capture-dsh-token.sh`) reads candidate launch tokens from the journal
|
||||
**scoped to the service's current systemd invocation**
|
||||
(`systemctl show -p InvocationID` + `_SYSTEMD_INVOCATION_ID=`), so a restarted
|
||||
process's stale token is never considered while its new startup banner is still
|
||||
pending; there is no whole-journal or cross-invocation fallback. Each candidate
|
||||
(`systemctl show -p InvocationID` + `_SYSTEMD_INVOCATION_ID=`), re-sampling the
|
||||
invocation on every pass so a restart that lands during the wait switches to the
|
||||
new invocation; a restarted process's stale token is never considered while its
|
||||
new startup banner is still pending and there is no whole-journal or
|
||||
cross-invocation fallback. Each candidate
|
||||
is then functionally verified against dsh-web with `Host: tankodhs.sysloggh.net`,
|
||||
using the first the running process accepts with `303`. It waits up to 120s for
|
||||
a restarted process to accept a token and re-probes every current-invocation
|
||||
|
||||
Reference in New Issue
Block a user