feat(agent): verify native ARI identity before real execution

This commit is contained in:
2026-10-04 13:16:46 +08:00
parent 34f8dd91fa
commit 8f029bcf7a
4 changed files with 119 additions and 0 deletions
@@ -35,6 +35,10 @@ The test host's address and raw logs are omitted from committed evidence.
- After read-only confirmation of **zero active calls and channels**, the committed and locally tested `configure-asterisk-user-ari.sh` (`1d12007`) created only the `rogee` user's private `ari.conf`, `http.conf` and `ari-secret`, all mode `0600`; no existing file was overwritten and no credential was printed or committed. HTTP binds only `127.0.0.1:8088`. The user-level Asterisk service was then explicitly restarted and reported **enabled+active** with a live CLI; anonymous ARI status returned **401**, and a read-only authenticated ARI information request returned **200**. No outbound call, registration or media capture was performed.
- Very short independent SSH probes had observed the service active before its control socket appeared. In a sustained SSH session, its PID stayed stable and the socket and CLI became available after startup; this was a session/startup observation, not evidence of a broken Asterisk binary. Lingering is **still disabled**: availability after logout or reboot remains unverified. Real Agent ARI use, signed task/provider snapshots, carrier requirements and capture-first host validation have **not** been accepted.
## Native Agent ARI SDK readback — 2026-10-04
- On the same pinned test host, an explicitly opt-in, CGO-disabled Go test read the owner-only `ari-secret` **in memory** (no value logged) and used the existing `github.com/CyCoreSystems/ari/v5/client/native` client against the loopback ARI endpoint. `native.Connect` and the authenticated read-only Asterisk status request both passed. The test binary was temporary and removed after the check; no channel was created, no call originated, no RTP/audio was captured and no OSS or AI request was issued. `internal/asterisk/ari.go` fails closed for missing, non-regular, non-`0600`, malformed or mismatched credentials. SDK readback does **not** establish real Agent execution, Stasis/media handling, recording or carrier acceptance.
## Still required before a real call or production acceptance
1. Verify the effect of endpoint updates **during an active authorized call** separately; SIP-only does not enable business dialing. Unsupported authentication/REGISTER and transport changes must continue to fail closed, and provider-side authentication, registration, routing and capacity remain unverified.