feat(nonprod): bind native Agent to signed calls and live capture

This commit is contained in:
2026-10-04 15:08:02 +08:00
parent 5f052c1db0
commit 0e9e6411be
22 changed files with 514 additions and 45 deletions
+8 -1
View File
@@ -88,11 +88,18 @@ for mode in mixed real; do
echo "release accepted unapproved $mode execution" >&2
exit 1
fi
if ! grep -Fq 'Dispatcher accepts only isolated Mock or SIP-only mode' "$WORK/blocked-$mode.log" || test -e "$blocked_db"; then
if ! grep -Fq 'Dispatcher accepts only isolated Mock, SIP-only or explicit nonprod-real mode' "$WORK/blocked-$mode.log" || test -e "$blocked_db"; then
echo "release reached resources before rejecting $mode execution" >&2
exit 1
fi
done
# The explicit nonproduction real path cannot open durable state unless every
# bound deployment input is present; this package test supplies none of them.
if DISPATCHER_SQLITE_PATH="$WORK/unconfigured-real.sqlite" "$WORK/release/sip-go-agent" dispatcher --mode nonprod-real > "$WORK/unconfigured-real.log" 2>&1 ||
test -e "$WORK/unconfigured-real.sqlite"; then
echo 'unconfigured real Dispatcher opened state or started' >&2
exit 1
fi
rm -- "$PACKAGE_RELEASE/sentinel"
rmdir -- "$PACKAGE_RELEASE"
"$ROOT/deploys/build-package.sh" "$PACKAGE_VERSION" > "$WORK/package.log" 2>&1 || {