feat(hybrid-gateway): integrate muse-cli with Cloudflare netns isolation, symmetric sidechat routing, and 646-pip sync unblock
This commit is contained in:
@@ -185,6 +185,60 @@ HEALTHY_AGENTS=""
|
||||
esac
|
||||
done
|
||||
|
||||
# --- Warp partition detection (2026-10-04) ---
|
||||
# A partitioned node has a live browser + CDP but no internet egress: the
|
||||
# chromebox watchdog sees a healthy browser while all automation fails.
|
||||
# Condition id: partition:<node>. The detail names the node, the WireGuard
|
||||
# handshake age, the egress probe result, and the timestamp, and says
|
||||
# PARTITION explicitly so #lobby readers can tell a network partition from
|
||||
# a browser crash at a glance. Anti-spam comes from the shared consecutive-
|
||||
# failure state machine (2 consecutive failures before first page, re-page
|
||||
# at most every 30 min).
|
||||
WARP_PROBE_URL="${WARP_PROBE_URL:-https://1.1.1.1/cdn-cgi/trace}"
|
||||
warp_partition_probe() { # <node> -> prints "<handshake_age_s|unknown> <ok|FAIL>"
|
||||
local node="$1" iface epoch now age_s
|
||||
iface=$(sudo -n ip netns exec "warp-$node" sh -c 'wg show interfaces 2>/dev/null | head -1')
|
||||
now=$(date +%s)
|
||||
epoch=$(sudo -n ip netns exec "warp-$node" wg show "$iface" latest-handshakes 2>/dev/null | awk '{print $2}')
|
||||
case "$epoch" in ''|*[!0-9]*) age_s="unknown" ;; *) age_s=$(( now - epoch )) ;; esac
|
||||
if sudo -n ip netns exec "warp-$node" curl -s -m 8 -o /dev/null "$WARP_PROBE_URL" 2>/dev/null; then
|
||||
echo "$age_s ok"
|
||||
else
|
||||
echo "$age_s FAIL"
|
||||
fi
|
||||
}
|
||||
|
||||
"$BIN/netvm-registry.py" 2>/dev/null | while IFS=: read -r node port; do
|
||||
[ -n "$node" ] && [ -n "$port" ] || continue
|
||||
cond="partition:$node"
|
||||
read -r hs_age probe_res < <(warp_partition_probe "$node")
|
||||
ts=$(date -u +%FT%TZ)
|
||||
if [ "$probe_res" = "ok" ]; then
|
||||
failing=0
|
||||
detail="warp egress restored for $node at $ts (probe $WARP_PROBE_URL ok)"
|
||||
else
|
||||
failing=1
|
||||
detail="PARTITION $node: warp egress down at $ts (handshake ${hs_age}s ago, probe $WARP_PROBE_URL FAILED)"
|
||||
fi
|
||||
if injected "$cond"; then
|
||||
failing=1
|
||||
detail="PARTITION $node: warp egress down at $ts (handshake ${hs_age}s ago, probe $WARP_PROBE_URL FAILED) [INJECTED]"
|
||||
fi
|
||||
read -r action fails < <(state_machine "$cond" "$failing")
|
||||
case "$action" in
|
||||
ALERT_FIRST|ALERT_REALERT)
|
||||
emit_record "ALERT" "$cond" "$detail" "$fails"
|
||||
echo "$cond" >> "$STATE_DIR/.alerts.tmp"
|
||||
;;
|
||||
RECOVERY)
|
||||
emit_record "RECOVERY" "$cond" "$detail" "$fails"
|
||||
;;
|
||||
SUPPRESSED)
|
||||
log "$cond still critical x$fails — re-page suppressed by quiet hours ($QUIET_HOURS)"
|
||||
;;
|
||||
esac
|
||||
done
|
||||
|
||||
# Recompute healthy agents in the main shell (pipeline subshell above can't export).
|
||||
HEALTHY_AGENTS=""
|
||||
"$BIN/netvm-registry.py" 2>/dev/null | while IFS=: read -r node port; do
|
||||
|
||||
Reference in New Issue
Block a user