35 lines
13 KiB
Plaintext
35 lines
13 KiB
Plaintext
CHAT_OUTPUT_BEGIN
|
|
COMMAND_ID=HOMELAB-CLUSTER-KB-V1-READER-V3-EXECUTOR-ARGUMENT-ORIGIN-TRACE-READ-ONLY-20260805T100500Z
|
|
STATUS=OK
|
|
RC=0
|
|
HOST=pve01
|
|
MODE=verify
|
|
COMPONENT=cluster-knowledge-base-error-system
|
|
REFERENCE_REGISTER_CHECK=OK
|
|
REFERENCE_SHA256=5763f2f8edc75fcf6f3951f8c95896d1cc112ceccb6cf5b64a383f540a4deb8e
|
|
ERROR_REGISTER_CHECK=OK
|
|
ERROR_REGISTER_SHA256=24934a2c7fa5c26f6e828583c4aefac7f143b40c0171736ed7571e617d55ab83
|
|
COMMAND_SHA256=05e8e4433883efd21b258bc2f533b298e1e88a1216452b52cede4e3972e5e3dd
|
|
DUPLICATE_FAILED_COMMAND_BLOCKED=false
|
|
EXECUTION_STARTED=true
|
|
CHANGE_DECLARED=false
|
|
RESULT_CONTRACT_VALID=true
|
|
RESULT_CONTRACT_STATUS=NOT_APPLICABLE
|
|
RESULT_CONTRACT_ERROR=NONE
|
|
COMMAND_RC=0
|
|
CHANGES_MADE=false
|
|
ROLLBACK_STARTED=false
|
|
ROLLBACK_RESTORED=null
|
|
MUTATION_OUTCOME=NO_MUTATION
|
|
SANITIZED=yes
|
|
SECRETS_INCLUDED=no
|
|
PRIVATE_ADDRESSES_INCLUDED=no
|
|
RAW_EVIDENCE_SHA256=b457b303ad6344a464f5a9b843525f8abbeb40cb0ad7cf879be3e75e39efef69
|
|
SANITIZED_OUTPUT_SHA256=b457b303ad6344a464f5a9b843525f8abbeb40cb0ad7cf879be3e75e39efef69
|
|
OUTPUT_BEGIN
|
|
HOMELAB_RESULT_CONTRACT={"changes_made":false,"command_id":"HOMELAB-CLUSTER-KB-V1-READER-V3-EXECUTOR-ARGUMENT-ORIGIN-TRACE-READ-ONLY-20260805T100500Z","command_rc":0,"mutation_outcome":"NO_MUTATION","output_truncated_in_json":false,"rc":0,"rollback_restored":null,"rollback_started":false,"status":"OK","version":1}
|
|
{"changes_made":false,"command_id":"HOMELAB-CLUSTER-KB-V1-READER-V3-EXECUTOR-ARGUMENT-ORIGIN-TRACE-READ-ONLY-20260805T100500Z","command_rc":0,"correction_of_previous_logic_gap":{"exact_fix":"trace handler-to-global call edges, statically resolve executor/file arguments, run the exact feed route in two no-I/O sandbox variants, and capture source-file exception events even when the Reader catches them","proven_gap":"the exact feed operation returned HTTP 500 in sandbox with zero recorded executor calls, while health alone was accepted; the previous projection did not capture global helper reachability, argument origins or caught exception events","regression_test":"a global helper using pvesh get must be reachable from feed, classified read-only and produce JSON through the fake executor; an unresolved module binding must produce a redacted caught NameError rather than another unexplained 500"},"error_fingerprint":"5df9f11405f92e576f437d2dc0523af74b62ac27efe7de6a4a8a4f5c1bd8ce05","latest_exact_result_basis":{"capsule_sha256":"67a018293eac4609c92494c56600f92f0b7161717182b1634e91b651960f98fb","changes_made":false,"command_id":"HOMELAB-CLUSTER-KB-V1-READER-V3-SANITIZED-BYTECODE-BRANCH-TRACE-READ-ONLY-20260805T095300Z","command_rc":0,"control_plane_error":null,"error_fingerprint":"f98fa5c6dec20928ee530acb4189a9ee8dceb9eeb1d09ace9b218f6762352eda","mutation_outcome":"NO_MUTATION","next_action":"RUN_ONE_READ_ONLY_READER_V3_EXECUTOR_ARGUMENT_ORIGIN_TRACE","output_complete":true,"output_sha256":"1c4ceb575201d7aa2a512efe92329d7faea09c277cbcc247c5fae4cea9b35780","output_truncated_in_json":false,"rc":0,"rollback_restored":null,"rollback_started":false,"root_cause_classification":"READER_V3_EXACT_OPERATION_ACCEPTED_BUT_READ_ONLY_INVENTORY_SCHEMA_NOT_PROVEN","runner_document_rc":0,"runner_json_sha256":"2386a2a2786a249f45f7331e3b49fa057f9f930908c3844c56669229431cf8bc","runner_rc":0,"runner_text_sha256":"6a15d08e977274340b4880f5fe2d64de803877676967ff4c207b54e878b9621e","runner_wrapper_matches_document":true,"status":"OK"},"mutation_outcome":"NO_MUTATION","next_action":"RUN_ONE_READ_ONLY_READER_V3_SANDBOX_GLOBAL_BINDING_FIX","output_truncated_in_json":false,"owned_listeners":[{"address_class":"private","address_sha256":"fb345731d21c612ed2cb13088c10fd26bac959c79a7634cb55e23ee6bfb428d9","family":"ipv4","inode":"24795","port":18788}],"pre_command_known_error_gate":{"checked":true,"items":[{"id":"candidate-scan-limit-20260805","prevention":"exact files only; bounded AST, simulation, response and output limits"},{"id":"runner-wrapper-mismatch-20260805","prevention":"single compact JSON below 42000 bytes; no raw source, secret or response body"},{"id":"gitea-owner-hardcoded-20260805","prevention":"no repository owner, guest ID or repository URL is assumed"},{"id":"gitea-git-auth-unavailable-20260805","prevention":"no Git or Gitea authentication attempt"},{"id":"pvesh-adapter-context-unreadable-20260805","prevention":"the payload does not call pvesh or any real executor"},{"id":"gitea-process-self-match-20260805","prevention":"Reader identity is bound to exact systemd ControlGroup"},{"id":"sanitize-non-string-attributeerror-20260805","prevention":"sanitize converts Any to str; embedded bool test"},{"id":"reader-path-env-misclassified-as-route-20260805","prevention":"PATH and filesystem-like values are excluded from request candidates"},{"id":"reader-loopback-only-probe-20260805","prevention":"owned listeners are inspected but no network connection is made"},{"id":"reader-capability-not-secret-20260805","prevention":"capability values are redacted before every output projection"},{"id":"reader-systemd-unit-parsed-as-python-20260805","prevention":"only the exact Python server source is parsed or compiled"},{"id":"reader-helper-contract-coverage-gap-20260805","prevention":"all handler methods reachable from do_GET/do_HEAD are traced"},{"id":"reader-capability-root-empty-suffix-404-20260805","prevention":"never infer inventory from capability-only paths; trace the exact post-prefix suffix and response branch with fake executors first"},{"id":"reader-generic-suffix-missed-exact-operation-20260805","prevention":"derive route operations from exact compiled branch constants and intersect them with AST path literals before sandbox execution"},{"id":"reader-feed-500-without-origin-20260805","prevention":"before any live feed request, trace global helper reachability, exact executor/file argument origins and caught sandbox exceptions; health alone never proves inventory safety"}]},"prevention_test":{"must_run_before_future_cluster_or_gitea_commands":true,"name":"reader_v3_executor_argument_origin_preflight","requirements":["verify exact Reader source SHA and systemd identity","trace all handler-to-global helper edges","resolve executor or file argument origins and classify read-only semantics","capture caught source exceptions in a strict fake-import sandbox","require a successful JSON feed with at least one proven read-only data source before any live request","never output capability values, private addresses, raw source, disassembly or response bodies"]},"process_environment":{"capability_name_present":true,"names":["HOME","HOMELAB_READER_CAPABILITY","HOMELAB_READER_PORT","INVOCATION_ID","JOURNAL_STREAM","LANG","LOGNAME","MEMORY_PRESSURE_WATCH","MEMORY_PRESSURE_WRITE","PATH","SHELL","SYSTEMD_EXEC_PID","USER"],"secret_name_count":1},"rc":0,"read_only":true,"ready_for_live_inventory_probe":false,"real_executor_calls_made":false,"real_file_mutations_made":false,"real_network_requests_made":false,"result_projection":{"bytes_before_projection":11641,"compacted":false,"max_bytes":36000},"rollback_restored":null,"rollback_started":false,"root_cause_classification":"READER_V3_FEED_CAUGHT_EXCEPTION_ORIGIN_PROVEN","sandbox_feed_origin_trace":{"caught_exception_types":["NameError"],"live_probe_contract_ready":false,"ready_variant_count":0,"variant_count":2,"variants":[{"all_effects_read_only":false,"body_bytes":13,"body_sha256":"326ce78e3deb6574ce072bbe8379c0e4deb1cb12c160a0f1a8161f8ddc6f4bd7","caught_exception_count":1,"caught_exceptions":[{"line":60,"message":"name 'MANIFEST' is not defined","message_sha256":"7ffaa9a9433abf55defe29684eca6160f703dc251b5b9ab47ccbd33b3dd3411c","symbol":"handle_reader","type":"NameError"}],"content_type":"text/plain; charset=utf-8","data_source_call_count":0,"effect_call_count":0,"effects":[],"handler_error_count":0,"json":null,"live_probe_contract_ready":false,"module_projection":{"excluded_assignment_count":6,"excluded_assignment_names":["CAPABILITY","MANIFEST","PORT","RESULTS","RESULT_RE","ROOT"],"include_safe_assignments":false,"included_assignment_count":0,"included_assignment_names":[]},"response_header_names":["cache-control","content-length","content-type","expires","pragma","surrogate-control","x-robots-tag"],"route_template":"/<capability>/feed","source_call_count":3,"source_calls":[{"line":42,"symbol":"do_GET"},{"line":45,"symbol":"handle_reader"},{"line":23,"symbol":"reply"}],"status":500,"variant":"definitions-plus-resolved-scope"},{"all_effects_read_only":false,"body_bytes":13,"body_sha256":"326ce78e3deb6574ce072bbe8379c0e4deb1cb12c160a0f1a8161f8ddc6f4bd7","caught_exception_count":1,"caught_exceptions":[{"line":60,"message":"name 'MANIFEST' is not defined","message_sha256":"7ffaa9a9433abf55defe29684eca6160f703dc251b5b9ab47ccbd33b3dd3411c","symbol":"handle_reader","type":"NameError"}],"content_type":"text/plain; charset=utf-8","data_source_call_count":0,"effect_call_count":0,"effects":[],"handler_error_count":0,"json":null,"live_probe_contract_ready":false,"module_projection":{"excluded_assignment_count":3,"excluded_assignment_names":["MANIFEST","RESULTS","RESULT_RE"],"include_safe_assignments":true,"included_assignment_count":3,"included_assignment_names":["CAPABILITY","PORT","ROOT"]},"response_header_names":["cache-control","content-length","content-type","expires","pragma","surrogate-control","x-robots-tag"],"route_template":"/<capability>/feed","source_call_count":3,"source_calls":[{"line":42,"symbol":"do_GET"},{"line":45,"symbol":"handle_reader"},{"line":23,"symbol":"reply"}],"status":500,"variant":"safe-assignments"}]},"sanitized_bytecode_branch_trace":{"branch_instruction_count":14,"branch_literal_count":7,"branch_literal_templates":["X-Homelab-Generation","X-Robots-Tag","feed","health","health-v3","include_body","results"],"bytecode_disassembly_emitted":false,"bytecode_literal_count":28,"call_instruction_count":53,"code_object_count":8,"compile_ok":true,"exact_branch_operation_count":2,"exact_compiled_operation_count":2,"operation_suffixes":["feed","health"],"operation_suffixes_sha256":"7b2583665af60a5f63c575c89ecaff1cd688710d29507b6d79238e5d9ca5e58b","raw_source_emitted":false,"source_literal_count":2},"schema":1,"source_files":[{"actual_sha256":"d672b74b390efa787ffd5a090e8c8eea8fdf038075421231a9d9b3053ea926b1","bytes":580,"expected_sha256":"d672b74b390efa787ffd5a090e8c8eea8fdf038075421231a9d9b3053ea926b1","matches_expected":true,"path":"/etc/systemd/system/homelab-reader-v3.service"},{"actual_sha256":"092780e76ff18dfe2920c51f8b97dd09d194fd6cbdb59c3755c9fbf6530f3536","bytes":3539,"expected_sha256":"092780e76ff18dfe2920c51f8b97dd09d194fd6cbdb59c3755c9fbf6530f3536","matches_expected":true,"path":"/usr/local/sbin/homelab-reader-server-v3"}],"source_selection":{"raw_source_emitted":false,"selected_path":"/usr/local/sbin/homelab-reader-server-v3","systemd_unit_excluded":true},"source_state":"MATCH","static_executor_argument_origin_trace":{"all_resolved_origins_read_only":true,"call_edge_count":3,"call_edges":[{"from":"Handler.do_GET","to":"Handler.handle_reader"},{"from":"Handler.do_HEAD","to":"Handler.handle_reader"},{"from":"Handler.handle_reader","to":"Handler.reply"}],"handler_roots":["Handler.do_GET","Handler.do_HEAD"],"raw_source_emitted":false,"reachable_data_origin_count":2,"reachable_data_origins":[{"argument_origin_names":[],"argument_resolved":false,"call":"MANIFEST.read_bytes","evidence_sha256":"3b9f9140c901f027be26f124b8c983ccfddbb3a62b03a416b5e7bfbb19f9fe59","kind":"file","mode":"r","origin_symbol":"Handler.handle_reader","path_class":null,"path_sha256":null,"read_only_basis":"file_read","read_only_proven":true},{"argument_origin_names":[],"argument_resolved":false,"call":"target.read_bytes","evidence_sha256":"aa896c2be567c54cf2da0cf24792da33575188def3c5d95fda4745ed3de4fdaf","kind":"file","mode":"r","origin_symbol":"Handler.handle_reader","path_class":null,"path_sha256":null,"read_only_basis":"file_read","read_only_proven":true}],"reachable_symbol_count":4,"reachable_symbols":["Handler.do_GET","Handler.do_HEAD","Handler.handle_reader","Handler.reply"],"unresolved_origin_count":2},"static_response_trace":{"ast_parse_ok":true,"capability_prefix_count":1,"capability_prefix_templates":["/<capability>/"],"handler_count":1,"reachable_methods":["do_GET","do_HEAD","handle_reader","reply"],"resolved_scope_names":["CAPABILITY","PORT"],"source_suffix_literal_count":2,"source_suffix_literal_templates":["feed","health"]},"status":"OK","systemd_identity":{"identity_valid":true,"pid_count":1,"probe":{"duration_seconds":0.005,"rc":0,"stderr_bytes":0,"stderr_sha256":"e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855","stderr_truncated":false,"stdout_bytes":375,"stdout_sha256":"49094d65d3787c1479e6408e1fefb7af3758d0fa55e1d37bf22907442aab35e9","stdout_truncated":false},"properties":{"ActiveState":"active","ControlGroup":"/system.slice/homelab-reader-v3.service","ExecStart_present":true,"ExecStart_sha256":"2500fde09569176736b4f2f1dd29d6289b6a6ae6a59b52b6a3c31f797f567379","FragmentPath":"/etc/systemd/system/homelab-reader-v3.service","LoadState":"loaded","MainPID":"1282","SubState":"running"}}}
|
|
|
|
OUTPUT_END
|
|
CHAT_OUTPUT_END
|