From e97145c88f3355065cb904517cf3165febceeabe Mon Sep 17 00:00:00 2001 From: abiba-bot Date: Fri, 11 Sep 2026 17:34:53 +0000 Subject: [PATCH] no-mistakes(review): re-sample systemd invocation each pass during token wait --- scripts/capture-dsh-token.sh | 41 ++++++++++++++++++------------------ zulip-health.prose.md | 8 ++++--- 2 files changed, 26 insertions(+), 23 deletions(-) diff --git a/scripts/capture-dsh-token.sh b/scripts/capture-dsh-token.sh index 342275a..4d7fe59 100755 --- a/scripts/capture-dsh-token.sh +++ b/scripts/capture-dsh-token.sh @@ -104,25 +104,16 @@ if [ -e "$PENDING_FILE" ]; then fi # ── 2. Select the token the RUNNING service actually accepts ──────────────── -# Read candidates ONLY from the service's current systemd invocation so a -# restarted process's stale token is never considered while its new startup -# banner is still pending; there is no whole-journal or cross-invocation -# fallback. Each candidate is then functionally verified against the local -# dsh-web using the public authority, exactly as the /dsh-web-login proxy does, -# and the first that answers 303 is the live token. Candidates are re-probed -# newest-first on each pass (connection failures stay eligible) until one is -# accepted or the wait elapses. -INVOCATION="$(systemctl show -p InvocationID --value "$JOURNAL_UNIT" 2>/dev/null || true)" -JOURNAL_ARGS=(-u "$JOURNAL_UNIT") -if [ -n "$INVOCATION" ] && [ "$INVOCATION" != "n/a" ]; then - JOURNAL_ARGS+=("_SYSTEMD_INVOCATION_ID=$INVOCATION") -else - log "WARNING: no invocation id for $JOURNAL_UNIT; no token can be selected this run" -fi - -collect_tokens() { - [ "${#JOURNAL_ARGS[@]}" -ge 3 ] || return 0 - journalctl "${JOURNAL_ARGS[@]}" --no-pager -o cat 2>/dev/null \ +# Re-sample the service's CURRENT systemd invocation on every pass and read +# candidates only from it, so a restart that lands during the wait immediately +# switches to the new invocation; there is no whole-journal or cross-invocation +# fallback, and an empty/unknown invocation just waits. Each candidate is then +# functionally verified against the local dsh-web using the public authority, +# exactly as the /dsh-web-login proxy does, and the first that answers 303 is +# the live token. Candidates are re-probed newest-first on each pass (connection +# failures stay eligible) until one is accepted or the wait elapses. +journal_tokens() { + journalctl -u "$JOURNAL_UNIT" "_SYSTEMD_INVOCATION_ID=$1" --no-pager -o cat 2>/dev/null \ | grep -oE 'dsh web: https?://[^[:space:]]+[?&]token=[^[:space:]]+' \ | sed -E 's/.*[?&]token=//' \ | grep -E '^[A-Za-z0-9._~+/=:@-]+$' \ @@ -131,8 +122,18 @@ collect_tokens() { TOKEN="" DEADLINE=$((SECONDS + TOKEN_WAIT)) +NO_INVOCATION_WARNED=0 while [ -z "$TOKEN" ] && [ "$SECONDS" -lt "$DEADLINE" ]; do - for cand in $(collect_tokens); do + INVOCATION="$(systemctl show -p InvocationID --value "$JOURNAL_UNIT" 2>/dev/null || true)" + if [ -z "$INVOCATION" ] || [ "$INVOCATION" = "n/a" ]; then + if [ "$NO_INVOCATION_WARNED" -eq 0 ]; then + log "WARNING: no invocation id for $JOURNAL_UNIT; waiting for a live invocation" + NO_INVOCATION_WARNED=1 + fi + sleep 2 + continue + fi + for cand in $(journal_tokens "$INVOCATION"); do code="$(curl -s -o /dev/null --max-time 5 -w '%{http_code}' \ -H "Host: $LOGIN_HOST" "$LOGIN_UPSTREAM/?token=$cand" || true)" if [ "$code" = "303" ]; then diff --git a/zulip-health.prose.md b/zulip-health.prose.md index 7b8e0e6..5824a59 100644 --- a/zulip-health.prose.md +++ b/zulip-health.prose.md @@ -294,9 +294,11 @@ proxy_pass http://127.0.0.1:3080/?token=; `/opt/deepseek-harness/capture-dsh-token.sh` (source: `scripts/capture-dsh-token.sh`) reads candidate launch tokens from the journal **scoped to the service's current systemd invocation** -(`systemctl show -p InvocationID` + `_SYSTEMD_INVOCATION_ID=`), so a restarted -process's stale token is never considered while its new startup banner is still -pending; there is no whole-journal or cross-invocation fallback. Each candidate +(`systemctl show -p InvocationID` + `_SYSTEMD_INVOCATION_ID=`), re-sampling the +invocation on every pass so a restart that lands during the wait switches to the +new invocation; a restarted process's stale token is never considered while its +new startup banner is still pending and there is no whole-journal or +cross-invocation fallback. Each candidate is then functionally verified against dsh-web with `Host: tankodhs.sysloggh.net`, using the first the running process accepts with `303`. It waits up to 120s for a restarted process to accept a token and re-probes every current-invocation