fix(hermes): add shared reachability check helper
Bug: The reachability check used 'ssh ... grep ... || echo unreachable', which conflated grep's 'no matches found' (exit 1) with SSH failure. This caused clean hosts to be reported as unreachable. Fix: Add scripts/hermes-reachability-check.sh with the pattern: out=$(ssh -o BatchMode=yes root@HOST "grep ... 2>/dev/null; true") if [ $? -ne 0 ]; then verdict="unreachable" elif [ -n "$out" ]; then verdict="violation: $out" else verdict="compliant" fi This correctly distinguishes: - SSH failure (connection/auth/route) -> unreachable - SSH success + grep found matches -> violation - SSH success + grep found nothing -> compliant Evidence: 3 of 4 hosts (Tanko, Mumuni, Koonimo) were reported as 'unreachable' when they were actually compliant. Only Koby (.129) has a real finding (plaintext key in state snapshot). Used by: hermes-key-enforcement, hermes-config-template, hermes-agent-baseline contracts.
This commit is contained in:
Executable
+23
@@ -0,0 +1,23 @@
|
||||
#!/bin/bash
|
||||
# Shared helper for Hermes contract reachability checks
|
||||
# Separates SSH exit status from remote command result
|
||||
# Pattern: remote side always succeeds, so ssh status = connection status only
|
||||
|
||||
hermes_check_host() {
|
||||
local host=$1
|
||||
local pattern=$2
|
||||
local path=$3
|
||||
|
||||
# Remote side always succeeds (grep ...; true), so ssh exit code = connection status only
|
||||
local out
|
||||
out=$(ssh -o BatchMode=yes -o ConnectTimeout=3 root@"$host" "grep -RIn '$pattern' '$path' 2>/dev/null; true" 2>/dev/null)
|
||||
local status=$?
|
||||
|
||||
if [ $status -ne 0 ]; then
|
||||
echo "$host: UNREACHABLE (ssh exit $status)"
|
||||
elif [ -n "$out" ]; then
|
||||
echo "$host: VIOLATION: $out"
|
||||
else
|
||||
echo "$host: COMPLIANT (no matches found)"
|
||||
fi
|
||||
}
|
||||
Reference in New Issue
Block a user