no-mistakes(review): re-sample systemd invocation each pass during token wait
This commit is contained in:
@@ -104,25 +104,16 @@ if [ -e "$PENDING_FILE" ]; then
|
|||||||
fi
|
fi
|
||||||
|
|
||||||
# ── 2. Select the token the RUNNING service actually accepts ────────────────
|
# ── 2. Select the token the RUNNING service actually accepts ────────────────
|
||||||
# Read candidates ONLY from the service's current systemd invocation so a
|
# Re-sample the service's CURRENT systemd invocation on every pass and read
|
||||||
# restarted process's stale token is never considered while its new startup
|
# candidates only from it, so a restart that lands during the wait immediately
|
||||||
# banner is still pending; there is no whole-journal or cross-invocation
|
# switches to the new invocation; there is no whole-journal or cross-invocation
|
||||||
# fallback. Each candidate is then functionally verified against the local
|
# fallback, and an empty/unknown invocation just waits. Each candidate is then
|
||||||
# dsh-web using the public authority, exactly as the /dsh-web-login proxy does,
|
# functionally verified against the local dsh-web using the public authority,
|
||||||
# and the first that answers 303 is the live token. Candidates are re-probed
|
# exactly as the /dsh-web-login proxy does, and the first that answers 303 is
|
||||||
# newest-first on each pass (connection failures stay eligible) until one is
|
# the live token. Candidates are re-probed newest-first on each pass (connection
|
||||||
# accepted or the wait elapses.
|
# failures stay eligible) until one is accepted or the wait elapses.
|
||||||
INVOCATION="$(systemctl show -p InvocationID --value "$JOURNAL_UNIT" 2>/dev/null || true)"
|
journal_tokens() {
|
||||||
JOURNAL_ARGS=(-u "$JOURNAL_UNIT")
|
journalctl -u "$JOURNAL_UNIT" "_SYSTEMD_INVOCATION_ID=$1" --no-pager -o cat 2>/dev/null \
|
||||||
if [ -n "$INVOCATION" ] && [ "$INVOCATION" != "n/a" ]; then
|
|
||||||
JOURNAL_ARGS+=("_SYSTEMD_INVOCATION_ID=$INVOCATION")
|
|
||||||
else
|
|
||||||
log "WARNING: no invocation id for $JOURNAL_UNIT; no token can be selected this run"
|
|
||||||
fi
|
|
||||||
|
|
||||||
collect_tokens() {
|
|
||||||
[ "${#JOURNAL_ARGS[@]}" -ge 3 ] || return 0
|
|
||||||
journalctl "${JOURNAL_ARGS[@]}" --no-pager -o cat 2>/dev/null \
|
|
||||||
| grep -oE 'dsh web: https?://[^[:space:]]+[?&]token=[^[:space:]]+' \
|
| grep -oE 'dsh web: https?://[^[:space:]]+[?&]token=[^[:space:]]+' \
|
||||||
| sed -E 's/.*[?&]token=//' \
|
| sed -E 's/.*[?&]token=//' \
|
||||||
| grep -E '^[A-Za-z0-9._~+/=:@-]+$' \
|
| grep -E '^[A-Za-z0-9._~+/=:@-]+$' \
|
||||||
@@ -131,8 +122,18 @@ collect_tokens() {
|
|||||||
|
|
||||||
TOKEN=""
|
TOKEN=""
|
||||||
DEADLINE=$((SECONDS + TOKEN_WAIT))
|
DEADLINE=$((SECONDS + TOKEN_WAIT))
|
||||||
|
NO_INVOCATION_WARNED=0
|
||||||
while [ -z "$TOKEN" ] && [ "$SECONDS" -lt "$DEADLINE" ]; do
|
while [ -z "$TOKEN" ] && [ "$SECONDS" -lt "$DEADLINE" ]; do
|
||||||
for cand in $(collect_tokens); do
|
INVOCATION="$(systemctl show -p InvocationID --value "$JOURNAL_UNIT" 2>/dev/null || true)"
|
||||||
|
if [ -z "$INVOCATION" ] || [ "$INVOCATION" = "n/a" ]; then
|
||||||
|
if [ "$NO_INVOCATION_WARNED" -eq 0 ]; then
|
||||||
|
log "WARNING: no invocation id for $JOURNAL_UNIT; waiting for a live invocation"
|
||||||
|
NO_INVOCATION_WARNED=1
|
||||||
|
fi
|
||||||
|
sleep 2
|
||||||
|
continue
|
||||||
|
fi
|
||||||
|
for cand in $(journal_tokens "$INVOCATION"); do
|
||||||
code="$(curl -s -o /dev/null --max-time 5 -w '%{http_code}' \
|
code="$(curl -s -o /dev/null --max-time 5 -w '%{http_code}' \
|
||||||
-H "Host: $LOGIN_HOST" "$LOGIN_UPSTREAM/?token=$cand" || true)"
|
-H "Host: $LOGIN_HOST" "$LOGIN_UPSTREAM/?token=$cand" || true)"
|
||||||
if [ "$code" = "303" ]; then
|
if [ "$code" = "303" ]; then
|
||||||
|
|||||||
@@ -294,9 +294,11 @@ proxy_pass http://127.0.0.1:3080/?token=<TOKEN>;
|
|||||||
`/opt/deepseek-harness/capture-dsh-token.sh` (source:
|
`/opt/deepseek-harness/capture-dsh-token.sh` (source:
|
||||||
`scripts/capture-dsh-token.sh`) reads candidate launch tokens from the journal
|
`scripts/capture-dsh-token.sh`) reads candidate launch tokens from the journal
|
||||||
**scoped to the service's current systemd invocation**
|
**scoped to the service's current systemd invocation**
|
||||||
(`systemctl show -p InvocationID` + `_SYSTEMD_INVOCATION_ID=`), so a restarted
|
(`systemctl show -p InvocationID` + `_SYSTEMD_INVOCATION_ID=`), re-sampling the
|
||||||
process's stale token is never considered while its new startup banner is still
|
invocation on every pass so a restart that lands during the wait switches to the
|
||||||
pending; there is no whole-journal or cross-invocation fallback. Each candidate
|
new invocation; a restarted process's stale token is never considered while its
|
||||||
|
new startup banner is still pending and there is no whole-journal or
|
||||||
|
cross-invocation fallback. Each candidate
|
||||||
is then functionally verified against dsh-web with `Host: tankodhs.sysloggh.net`,
|
is then functionally verified against dsh-web with `Host: tankodhs.sysloggh.net`,
|
||||||
using the first the running process accepts with `303`. It waits up to 120s for
|
using the first the running process accepts with `303`. It waits up to 120s for
|
||||||
a restarted process to accept a token and re-probes every current-invocation
|
a restarted process to accept a token and re-probes every current-invocation
|
||||||
|
|||||||
Reference in New Issue
Block a user