no-mistakes(review): re-sample systemd invocation each pass during token wait

This commit is contained in:
2026-09-11 17:34:53 +00:00
parent 55f1208eb8
commit e97145c88f
2 changed files with 26 additions and 23 deletions
+21 -20
View File
@@ -104,25 +104,16 @@ if [ -e "$PENDING_FILE" ]; then
fi fi
# ── 2. Select the token the RUNNING service actually accepts ──────────────── # ── 2. Select the token the RUNNING service actually accepts ────────────────
# Read candidates ONLY from the service's current systemd invocation so a # Re-sample the service's CURRENT systemd invocation on every pass and read
# restarted process's stale token is never considered while its new startup # candidates only from it, so a restart that lands during the wait immediately
# banner is still pending; there is no whole-journal or cross-invocation # switches to the new invocation; there is no whole-journal or cross-invocation
# fallback. Each candidate is then functionally verified against the local # fallback, and an empty/unknown invocation just waits. Each candidate is then
# dsh-web using the public authority, exactly as the /dsh-web-login proxy does, # functionally verified against the local dsh-web using the public authority,
# and the first that answers 303 is the live token. Candidates are re-probed # exactly as the /dsh-web-login proxy does, and the first that answers 303 is
# newest-first on each pass (connection failures stay eligible) until one is # the live token. Candidates are re-probed newest-first on each pass (connection
# accepted or the wait elapses. # failures stay eligible) until one is accepted or the wait elapses.
INVOCATION="$(systemctl show -p InvocationID --value "$JOURNAL_UNIT" 2>/dev/null || true)" journal_tokens() {
JOURNAL_ARGS=(-u "$JOURNAL_UNIT") journalctl -u "$JOURNAL_UNIT" "_SYSTEMD_INVOCATION_ID=$1" --no-pager -o cat 2>/dev/null \
if [ -n "$INVOCATION" ] && [ "$INVOCATION" != "n/a" ]; then
JOURNAL_ARGS+=("_SYSTEMD_INVOCATION_ID=$INVOCATION")
else
log "WARNING: no invocation id for $JOURNAL_UNIT; no token can be selected this run"
fi
collect_tokens() {
[ "${#JOURNAL_ARGS[@]}" -ge 3 ] || return 0
journalctl "${JOURNAL_ARGS[@]}" --no-pager -o cat 2>/dev/null \
| grep -oE 'dsh web: https?://[^[:space:]]+[?&]token=[^[:space:]]+' \ | grep -oE 'dsh web: https?://[^[:space:]]+[?&]token=[^[:space:]]+' \
| sed -E 's/.*[?&]token=//' \ | sed -E 's/.*[?&]token=//' \
| grep -E '^[A-Za-z0-9._~+/=:@-]+$' \ | grep -E '^[A-Za-z0-9._~+/=:@-]+$' \
@@ -131,8 +122,18 @@ collect_tokens() {
TOKEN="" TOKEN=""
DEADLINE=$((SECONDS + TOKEN_WAIT)) DEADLINE=$((SECONDS + TOKEN_WAIT))
NO_INVOCATION_WARNED=0
while [ -z "$TOKEN" ] && [ "$SECONDS" -lt "$DEADLINE" ]; do while [ -z "$TOKEN" ] && [ "$SECONDS" -lt "$DEADLINE" ]; do
for cand in $(collect_tokens); do INVOCATION="$(systemctl show -p InvocationID --value "$JOURNAL_UNIT" 2>/dev/null || true)"
if [ -z "$INVOCATION" ] || [ "$INVOCATION" = "n/a" ]; then
if [ "$NO_INVOCATION_WARNED" -eq 0 ]; then
log "WARNING: no invocation id for $JOURNAL_UNIT; waiting for a live invocation"
NO_INVOCATION_WARNED=1
fi
sleep 2
continue
fi
for cand in $(journal_tokens "$INVOCATION"); do
code="$(curl -s -o /dev/null --max-time 5 -w '%{http_code}' \ code="$(curl -s -o /dev/null --max-time 5 -w '%{http_code}' \
-H "Host: $LOGIN_HOST" "$LOGIN_UPSTREAM/?token=$cand" || true)" -H "Host: $LOGIN_HOST" "$LOGIN_UPSTREAM/?token=$cand" || true)"
if [ "$code" = "303" ]; then if [ "$code" = "303" ]; then
+5 -3
View File
@@ -294,9 +294,11 @@ proxy_pass http://127.0.0.1:3080/?token=<TOKEN>;
`/opt/deepseek-harness/capture-dsh-token.sh` (source: `/opt/deepseek-harness/capture-dsh-token.sh` (source:
`scripts/capture-dsh-token.sh`) reads candidate launch tokens from the journal `scripts/capture-dsh-token.sh`) reads candidate launch tokens from the journal
**scoped to the service's current systemd invocation** **scoped to the service's current systemd invocation**
(`systemctl show -p InvocationID` + `_SYSTEMD_INVOCATION_ID=`), so a restarted (`systemctl show -p InvocationID` + `_SYSTEMD_INVOCATION_ID=`), re-sampling the
process's stale token is never considered while its new startup banner is still invocation on every pass so a restart that lands during the wait switches to the
pending; there is no whole-journal or cross-invocation fallback. Each candidate new invocation; a restarted process's stale token is never considered while its
new startup banner is still pending and there is no whole-journal or
cross-invocation fallback. Each candidate
is then functionally verified against dsh-web with `Host: tankodhs.sysloggh.net`, is then functionally verified against dsh-web with `Host: tankodhs.sysloggh.net`,
using the first the running process accepts with `303`. It waits up to 120s for using the first the running process accepts with `303`. It waits up to 120s for
a restarted process to accept a token and re-probes every current-invocation a restarted process to accept a token and re-probes every current-invocation