chore(fleet): sync operator memory, hatch menu dialogs, and watchdog alerts
This commit is contained in:
@@ -5,6 +5,10 @@
|
||||
# branch; deployment needs opm review + sign-off. See
|
||||
# docs/FLEET-ALERT-DUP-POST-GATE.md.
|
||||
#
|
||||
# NOTE (2026-10-06): auto-invoke from fleet-alert-check.sh is disabled by
|
||||
# default (FLEET_BL_RELAY=1 re-enables). The container-side hook pages
|
||||
# #lobby today; do not re-enable without retiring it first.
|
||||
#
|
||||
# The 2026-10-05 11:28Z incident: one RECOVERY record in the outbox became two
|
||||
# identical verified #lobby posts (seq 642/643, 3.35s apart) because the relay
|
||||
# leg had no idempotency: append-only outbox, no consume tracking, no content
|
||||
@@ -68,7 +72,7 @@ transport_post() { # $1 = text
|
||||
local text="$1" ts sig payload resp http
|
||||
ts="$(date +%s)"
|
||||
if ! sig="$(sign_payload "$(printf '%s\n%s\n%s' "$ts" "$CHANNEL" "$text")")"; then
|
||||
echo "UNKNOWN sign-failed"; return 0
|
||||
echo "UNKNOWN sign-failed($KEYFILE)"; return 0
|
||||
fi
|
||||
payload="$(MSG="$text" TS="$ts" SIG="$sig" python3 -c '
|
||||
import json,os
|
||||
@@ -263,12 +267,31 @@ main() {
|
||||
# NOTE: transport_post is invoked via command substitution (subshell), so the
|
||||
# stub counts calls with a file, not a variable.
|
||||
self_test() {
|
||||
local td calls lobby ok=1 n
|
||||
local td calls lobby ok=1 n sk sig_out old_key
|
||||
td="$(mktemp -d)"; export FLEET_ALERT_DIR="$td"
|
||||
ALERT_DIR="$td"; OUTBOX="$td/outbox.jsonl"; POSTED="$td/posted.log"
|
||||
SEEN="$td/seen-hashes.log"; LOCKF="$td/relay.lock"
|
||||
calls="$td/calls.log"; lobby="$td/lobby.log"
|
||||
touch "$calls" "$lobby"
|
||||
# sign_payload must round-trip with a valid key and fail cleanly without
|
||||
# one (2026-10-06: missing ~/.ssh/id_frontdoor broke every #lobby post
|
||||
# with an undiagnosable bare "sign-failed").
|
||||
old_key="$KEYFILE"
|
||||
sk="$td/signkey"
|
||||
ssh-keygen -t ed25519 -f "$sk" -N '' -q >/dev/null 2>&1 \
|
||||
|| { echo "FAIL: cannot generate ephemeral test key"; ok=0; }
|
||||
if KEYFILE="$sk" sig_out="$(sign_payload "self-test")"; then
|
||||
case "$sig_out" in
|
||||
*"BEGIN SSH SIGNATURE"*) : ;;
|
||||
*) echo "FAIL: sign_payload output not armored"; ok=0 ;;
|
||||
esac
|
||||
else
|
||||
echo "FAIL: sign_payload failed with a valid key"; ok=0
|
||||
fi
|
||||
if KEYFILE="$td/no-such-key" sign_payload "self-test" >/dev/null 2>&1; then
|
||||
echo "FAIL: sign_payload succeeded with a missing key"; ok=0
|
||||
fi
|
||||
KEYFILE="$old_key"
|
||||
# Two identical submissions: same text, different record ids (the 11:28Z shape)
|
||||
printf '%s\n' \
|
||||
'{"id":"rec-A","ts":1791199616,"kind":"RECOVERY","condition":"partition:def"}' \
|
||||
|
||||
Reference in New Issue
Block a user