PR Pipeline — Authorize → Validate → Review → Merge / auth (pull_request) Successful in 4s
PR Pipeline — Authorize → Validate → Review → Merge / validate (pull_request) Successful in 5s
PR Pipeline — Authorize → Validate → Review → Merge / lint (pull_request) Successful in 5s
PR Pipeline — Authorize → Validate → Review → Merge / ai-review (pull_request) Successful in 6s
PR Pipeline — Authorize → Validate → Review → Merge / gate (pull_request) Successful in 1s
The helper was correct but dead code - nothing called it. This commit: 1. Makes the helper runnable standalone: scripts/hermes-reachability-check.sh <host> <pattern> <path> 2. Wires all THREE contracts to it: - hermes-key-enforcement.prose.md - hermes-config-template.prose.md - hermes-agent-baseline.prose.md 3. Each contract now explicitly instructs to run the helper and interpret the three outcomes 4. States that the bug this replaces was deriving reachability from the remote grep's exit code Files changed (4): - scripts/hermes-reachability-check.sh (standalone mode added) - hermes-key-enforcement.prose.md (reachability section added) - hermes-config-template.prose.md (reachability section added) - hermes-agent-baseline.prose.md (reachability section added)
33 lines
962 B
Bash
Executable File
33 lines
962 B
Bash
Executable File
#!/bin/bash
|
|
# Shared helper for Hermes contract reachability checks
|
|
# Separates SSH exit status from remote command result
|
|
|
|
hermes_check_host() {
|
|
local host=$1
|
|
local pattern=$2
|
|
local path=$3
|
|
|
|
# Remote side always succeeds (grep ...; true), so ssh exit code = connection status only
|
|
local out
|
|
out=$(ssh -o BatchMode=yes -o ConnectTimeout=3 root@"$host" "grep -RIn '$pattern' '$path' 2>/dev/null; true" 2>/dev/null)
|
|
local status=$?
|
|
|
|
if [ $status -ne 0 ]; then
|
|
echo "$host: UNREACHABLE (ssh exit $status)"
|
|
elif [ -n "$out" ]; then
|
|
echo "$host: VIOLATION: $out"
|
|
else
|
|
echo "$host: COMPLIANT (no matches found)"
|
|
fi
|
|
}
|
|
|
|
# Standalone mode: scripts/hermes-reachability-check.sh <host> <pattern> <path>
|
|
if [ "${BASH_SOURCE[0]}" = "${0}" ]; then
|
|
if [ $# -ne 3 ]; then
|
|
echo "Usage: $0 <host> <pattern> <path>" >&2
|
|
exit 2
|
|
fi
|
|
hermes_check_host "$1" "$2" "$3"
|
|
exit 0
|
|
fi
|