diff --git a/hermes-key-enforcement.prose.md b/hermes-key-enforcement.prose.md index d54a37c..a7d5a27 100644 --- a/hermes-key-enforcement.prose.md +++ b/hermes-key-enforcement.prose.md @@ -225,16 +225,19 @@ timeout 15 ssh -o ConnectTimeout=10 -o StrictHostKeyChecking=no root@ \ If any output from step 2 — **critical violation** (master key leaked). Fix immediately. -### Negative control (probe-failed vs unreachable) +### Negative control (probe-failed vs unreachable) — deterministic -To prove the distinction between a scan timeout and a connection failure, run with a deliberately tiny timeout: +To prove the distinction between a scan timeout and a connection failure, run a command that CANNOT finish in time (sleep 5s) with a 1-second timeout: ```bash -# Negative control: 1-second timeout on koby (scan takes 0.9 s, so this will time out) -timeout 1 ssh -o ConnectTimeout=10 -o StrictHostKeyChecking=no root@192.168.68.129 \ - "grep -rn 'api_key: sk-' /root/.hermes/ --exclude-dir=state-snapshots --include='config.yaml'" 2>/dev/null -# Expected: exit status 124 (timeout) → render as "probe-failed: koby 192.168.68.129 (timeout after 1s)" +# Negative control: 1-second timeout on koby — sleep 5s guarantees timeout +timeout 1 ssh -o ConnectTimeout=10 -o StrictHostKeyChecking=no root@192.168.68.129 "sleep 5"; echo "exit=$?" +# Expected: exit=124 (timeout) → render as "probe-failed: koby 192.168.68.129 (timeout after 1s)" # NOT: "unreachable" or "may be down" + +# Run TWICE to prove determinism: +# Run 1: timeout 1 ssh ... "sleep 5"; echo "exit=$?" → exit=124 +# Run 2: timeout 1 ssh ... "sleep 5"; echo "exit=$?" → exit=124 ``` ## Rotation Procedure