Add isolated SIP call tool, optional debug capture and split interface schemas
This commit is contained in:
@@ -51,7 +51,13 @@ reports its applied revision. Local Mock fixtures do not prove real services.
|
||||
|
||||
Before every real outbound attempt, the operator must obtain a fresh user
|
||||
confirmation in the current conversation that names the SIP channel, raw target
|
||||
number and capture plan. Task and trunk schedules and quotas come from the
|
||||
number and, when `agent --debug/-D` is enabled, capture plan. External tcpdump
|
||||
and the capture-first wrapper are opt-in debugging tools, not normal-production
|
||||
requirements. Debug mode still fails closed on missing/invalid capture evidence;
|
||||
the HEP SIP-response mirror remains independent and required for that response
|
||||
reporting path. The standalone no-AI line test is documented in
|
||||
[`cmd/sip-call/README.md`](../../cmd/sip-call/README.md).
|
||||
Task and trunk schedules and quotas come from the
|
||||
verified SaaS configuration snapshot; the local host has no separate fixed
|
||||
hour or daily-attempt limit. Missing or contradictory schedules fail closed;
|
||||
do not wait, retry, delay or switch trunks. A prior confirmation does not
|
||||
|
||||
Vendored
+3
-2
@@ -1,6 +1,7 @@
|
||||
# Isolated local Mock only. This is not a production or real-call configuration.
|
||||
# A non-production validation host still requires the mandatory native Asterisk
|
||||
# and capture-first diagnostics in deploys/test/nonprod-call-evidence.sh.
|
||||
# Native Asterisk/host validation remains required. External tcpdump capture
|
||||
# is opt-in: agent --debug/-D requires the existing capture-first wrapper and
|
||||
# AGENT_EVIDENCE_ROOT; normal operation has no external capture dependency.
|
||||
# Start explicitly: sip-go-agent agent --mode mock
|
||||
AGENT_ID=agent-mock
|
||||
CELL_ID=cell-mock
|
||||
|
||||
@@ -16,7 +16,8 @@ systemd service or add it to a production host.
|
||||
|
||||
## Native Asterisk validation
|
||||
|
||||
`nonprod-call-evidence.sh` is the mandatory capture-first wrapper for
|
||||
`nonprod-call-evidence.sh` is the capture-first wrapper used with
|
||||
`sip-go-agent agent --debug/-D` for
|
||||
non-production `mock`, `mixed` and explicit `nonprod-real` call checks. It runs on a validation
|
||||
host with native Asterisk and required diagnostics; it is not an Asterisk or
|
||||
Agent replacement and is not containerized. Run it explicitly with the current
|
||||
@@ -32,7 +33,7 @@ restricted evidence ownership is recorded in `diagnostic-errors.txt` and fails
|
||||
the check; an already failed call keeps its nonzero result. Once live tcpdump
|
||||
and the PJSIP logger are running, the script creates a root-owned, group-readable
|
||||
`<call-id>.active` capture arm under `--proof-root` (default
|
||||
`/run/sip-go-agent/nonprod-armed`). The real Agent must set `AGENT_EVIDENCE_ROOT`
|
||||
`/run/sip-go-agent/nonprod-armed`). A debug-enabled real Agent must set `AGENT_EVIDENCE_ROOT`
|
||||
to this directory; it checks the exact approved event ID, trunk, raw callee,
|
||||
recent arm and live capture PID before origination. The script removes the arm
|
||||
before stopping capture. Run one approved call per invocation, with
|
||||
@@ -55,8 +56,11 @@ mirror as described in [`cell/README.md`](../cell/README.md), with
|
||||
`AGENT_HEP_LISTEN_ADDR=127.0.0.1:<port>` matching `capture_address` in the
|
||||
private `hep.conf`. Confirm `res_hep` and `res_hep_pjsip` are running and the
|
||||
Agent's UDP listener is bound before any explicitly authorized trial. The
|
||||
capture-first wrapper remains mandatory; HEP is not a replacement for pcap,
|
||||
PJSIP logger, call-window checks, or caller approval. Verify the same
|
||||
capture-first wrapper is required only when Agent `--debug/-D` is enabled;
|
||||
normal Agent operation does not require tcpdump or external capture proofs.
|
||||
HEP's native SIP-response mirror, call-window checks and caller approval remain
|
||||
independent requirements. The standalone no-AI single-call tool and its optional
|
||||
pcap workflow are documented in [`cmd/sip-call/README.md`](../../cmd/sip-call/README.md). Verify the same
|
||||
`call.execute.result` is present in Dispatcher outbox and the SaaS Mock's
|
||||
restricted result store; inspect full `raw` only there and do not place it in
|
||||
logs, source, chat, or long-term evidence. A missing mirror produces a clear
|
||||
|
||||
Reference in New Issue
Block a user