From f9f6661dd558820b7612ec94613e7f8f9f5844ba Mon Sep 17 00:00:00 2001 From: root Date: Mon, 14 Sep 2026 11:55:41 +0000 Subject: [PATCH] fix(hermes): add shared reachability check helper Bug: The reachability check used 'ssh ... grep ... || echo unreachable', which conflated grep's 'no matches found' (exit 1) with SSH failure. This caused clean hosts to be reported as unreachable. Fix: Add scripts/hermes-reachability-check.sh with the pattern: out=$(ssh -o BatchMode=yes root@HOST "grep ... 2>/dev/null; true") if [ $? -ne 0 ]; then verdict="unreachable" elif [ -n "$out" ]; then verdict="violation: $out" else verdict="compliant" fi This correctly distinguishes: - SSH failure (connection/auth/route) -> unreachable - SSH success + grep found matches -> violation - SSH success + grep found nothing -> compliant Evidence: 3 of 4 hosts (Tanko, Mumuni, Koonimo) were reported as 'unreachable' when they were actually compliant. Only Koby (.129) has a real finding (plaintext key in state snapshot). Used by: hermes-key-enforcement, hermes-config-template, hermes-agent-baseline contracts. --- scripts/hermes-reachability-check.sh | 23 +++++++++++++++++++++++ 1 file changed, 23 insertions(+) create mode 100755 scripts/hermes-reachability-check.sh diff --git a/scripts/hermes-reachability-check.sh b/scripts/hermes-reachability-check.sh new file mode 100755 index 0000000..9842ccf --- /dev/null +++ b/scripts/hermes-reachability-check.sh @@ -0,0 +1,23 @@ +#!/bin/bash +# Shared helper for Hermes contract reachability checks +# Separates SSH exit status from remote command result +# Pattern: remote side always succeeds, so ssh status = connection status only + +hermes_check_host() { + local host=$1 + local pattern=$2 + local path=$3 + + # Remote side always succeeds (grep ...; true), so ssh exit code = connection status only + local out + out=$(ssh -o BatchMode=yes -o ConnectTimeout=3 root@"$host" "grep -RIn '$pattern' '$path' 2>/dev/null; true" 2>/dev/null) + local status=$? + + if [ $status -ne 0 ]; then + echo "$host: UNREACHABLE (ssh exit $status)" + elif [ -n "$out" ]; then + echo "$host: VIOLATION: $out" + else + echo "$host: COMPLIANT (no matches found)" + fi +}