Add isolated SIP call tool, optional debug capture and split interface schemas

This commit is contained in:
2026-10-08 12:44:45 +08:00
parent 98b3fd469d
commit 385bda0822
49 changed files with 3688 additions and 28 deletions
+7 -1
View File
@@ -51,7 +51,13 @@ reports its applied revision. Local Mock fixtures do not prove real services.
Before every real outbound attempt, the operator must obtain a fresh user
confirmation in the current conversation that names the SIP channel, raw target
number and capture plan. Task and trunk schedules and quotas come from the
number and, when `agent --debug/-D` is enabled, capture plan. External tcpdump
and the capture-first wrapper are opt-in debugging tools, not normal-production
requirements. Debug mode still fails closed on missing/invalid capture evidence;
the HEP SIP-response mirror remains independent and required for that response
reporting path. The standalone no-AI line test is documented in
[`cmd/sip-call/README.md`](../../cmd/sip-call/README.md).
Task and trunk schedules and quotas come from the
verified SaaS configuration snapshot; the local host has no separate fixed
hour or daily-attempt limit. Missing or contradictory schedules fail closed;
do not wait, retry, delay or switch trunks. A prior confirmation does not
+3 -2
View File
@@ -1,6 +1,7 @@
# Isolated local Mock only. This is not a production or real-call configuration.
# A non-production validation host still requires the mandatory native Asterisk
# and capture-first diagnostics in deploys/test/nonprod-call-evidence.sh.
# Native Asterisk/host validation remains required. External tcpdump capture
# is opt-in: agent --debug/-D requires the existing capture-first wrapper and
# AGENT_EVIDENCE_ROOT; normal operation has no external capture dependency.
# Start explicitly: sip-go-agent agent --mode mock
AGENT_ID=agent-mock
CELL_ID=cell-mock
+8 -4
View File
@@ -16,7 +16,8 @@ systemd service or add it to a production host.
## Native Asterisk validation
`nonprod-call-evidence.sh` is the mandatory capture-first wrapper for
`nonprod-call-evidence.sh` is the capture-first wrapper used with
`sip-go-agent agent --debug/-D` for
non-production `mock`, `mixed` and explicit `nonprod-real` call checks. It runs on a validation
host with native Asterisk and required diagnostics; it is not an Asterisk or
Agent replacement and is not containerized. Run it explicitly with the current
@@ -32,7 +33,7 @@ restricted evidence ownership is recorded in `diagnostic-errors.txt` and fails
the check; an already failed call keeps its nonzero result. Once live tcpdump
and the PJSIP logger are running, the script creates a root-owned, group-readable
`<call-id>.active` capture arm under `--proof-root` (default
`/run/sip-go-agent/nonprod-armed`). The real Agent must set `AGENT_EVIDENCE_ROOT`
`/run/sip-go-agent/nonprod-armed`). A debug-enabled real Agent must set `AGENT_EVIDENCE_ROOT`
to this directory; it checks the exact approved event ID, trunk, raw callee,
recent arm and live capture PID before origination. The script removes the arm
before stopping capture. Run one approved call per invocation, with
@@ -55,8 +56,11 @@ mirror as described in [`cell/README.md`](../cell/README.md), with
`AGENT_HEP_LISTEN_ADDR=127.0.0.1:<port>` matching `capture_address` in the
private `hep.conf`. Confirm `res_hep` and `res_hep_pjsip` are running and the
Agent's UDP listener is bound before any explicitly authorized trial. The
capture-first wrapper remains mandatory; HEP is not a replacement for pcap,
PJSIP logger, call-window checks, or caller approval. Verify the same
capture-first wrapper is required only when Agent `--debug/-D` is enabled;
normal Agent operation does not require tcpdump or external capture proofs.
HEP's native SIP-response mirror, call-window checks and caller approval remain
independent requirements. The standalone no-AI single-call tool and its optional
pcap workflow are documented in [`cmd/sip-call/README.md`](../../cmd/sip-call/README.md). Verify the same
`call.execute.result` is present in Dispatcher outbox and the SaaS Mock's
restricted result store; inspect full `raw` only there and do not place it in
logs, source, chat, or long-term evidence. A missing mirror produces a clear