Skip to content

Commit 53c1908

Browse files
committed
Report the shpool fingerprint state in doctor
The watchdog already compares the running daemon against a recorded fingerprint, but nothing surfaced whether that comparison is capable of telling you anything. Both ways it can be inert are silent, so doctor now distinguishes them: no fingerprint recorded means the check is skipped entirely, a malformed value means the same, and a recorded value that no longer matches the installed binary means the watchdog is reporting a change on every pass for a rebuild you did on purpose. Reporting these as separate lines matters because the remedies differ. Absent means record it. Mismatched means re-record it, and until you do, the alert it produces is noise that spends the credibility a genuine silent replacement will need. Compares against the binary on PATH rather than the running daemon's executable: the watchdog already covers the running process, and the case this catches is a rebuild that has not been activated or recorded yet.
1 parent 0f2dbb2 commit 53c1908

1 file changed

Lines changed: 47 additions & 1 deletion

File tree

‎lib/sh/session_kit_doctor.sh‎

Lines changed: 47 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -109,14 +109,15 @@ doctor_command() {
109109
local audit_output audit_ok=1 audit_name
110110
local -a audit_names=(
111111
claude-version codex-version codex-themes naming-instructions naming-hook
112-
kill-switches acceptance
112+
kill-switches acceptance shpool-binary
113113
)
114114
declare -A audit_expected=() audit_seen=()
115115
for audit_name in "${audit_names[@]}"; do audit_expected[$audit_name]=1; done
116116
if audit_output=$(python3 - "$HOME" "$config_root" \
117117
"${SESSION_KIT_CODEX_HOME:-${CODEX_HOME:-$HOME/.codex}}" \
118118
"$release_id" "$current_platform" <<'PY'
119119
import datetime
120+
import hashlib
120121
import json
121122
import os
122123
from pathlib import Path
@@ -332,6 +333,51 @@ def safe_directory_chain(path: Path, *, final_owner: bool = False) -> bool:
332333
return False
333334
334335
336+
# The watchdog compares the running shpool daemon against a fingerprint
337+
# recorded in private state. Two states leave that check present but no longer
338+
# protecting anything, and both are silent: an absent fingerprint skips the
339+
# check entirely, and a stale one reports a change on every pass until the
340+
# report stops being read. Report each distinctly rather than as one failure.
341+
state_root = Path(os.environ.get("XDG_STATE_HOME") or (home / ".local/state"))
342+
fingerprint_bytes = secure_regular_bytes(
343+
state_root / "session-kit" / "shpool-binary.sha256", 4096
344+
)
345+
recorded_fingerprint = None
346+
if fingerprint_bytes is not None:
347+
candidate = fingerprint_bytes.decode("utf-8", "replace").strip()
348+
if re.fullmatch(r"[0-9a-f]{64}", candidate):
349+
recorded_fingerprint = candidate
350+
if fingerprint_bytes is None:
351+
emit(
352+
"warn",
353+
"shpool-binary",
354+
"no fingerprint recorded, so the watchdog binary check is inactive",
355+
)
356+
elif recorded_fingerprint is None:
357+
emit(
358+
"warn",
359+
"shpool-binary",
360+
"recorded fingerprint is not a sha256 digest, so the check is inactive",
361+
)
362+
else:
363+
shpool_path = shutil.which("shpool")
364+
if not shpool_path:
365+
emit("warn", "shpool-binary", "shpool is not on PATH, so it cannot be compared")
366+
else:
367+
installed_bytes = secure_regular_bytes(Path(shpool_path), 512 * 1_048_576)
368+
if installed_bytes is None:
369+
emit("warn", "shpool-binary", "installed shpool binary could not be read")
370+
elif hashlib.sha256(installed_bytes).hexdigest() == recorded_fingerprint:
371+
emit("ok", "shpool-binary", "recorded fingerprint matches the installed shpool")
372+
else:
373+
emit(
374+
"warn",
375+
"shpool-binary",
376+
"recorded fingerprint no longer matches "
377+
+ shpool_path
378+
+ "; re-record it after a deliberate rebuild",
379+
)
380+
335381
theme_errors = []
336382
codex_root_safe = safe_directory_chain(codex_home, final_owner=True)
337383
themes_root = codex_home / "themes"

0 commit comments

Comments
 (0)