docs(test): record user Asterisk ARI readback without calling
This commit is contained in:
@@ -30,9 +30,14 @@ The test host's address and raw logs are omitted from committed evidence.
|
||||
- On the same pinned Debian 13 test host, `rogee` now passes noninteractive `sudo -n true`. With explicit user authorization, installed Debian `tcpdump` **4.99.5-2** and `libpcap0.8t64` **1.10.5-2**; tcpdump executable SHA-256 `0d426e2571a22de0d30996fd01bb44c1f267f33065023abea092c88bad16d2d2`.
|
||||
- `sudo -n tcpdump -D` reported **8 interfaces**. This is only a capability check: **no packet capture or call** was started. Asterisk ARI/HTTP config is still absent on this rebuilt host, the business call executable remains Mock-only, and a real provider/task snapshot has not been signed off. At inspection Asia/Shanghai was **08:15**, before the authorized 09:00 opening; installation of tcpdump alone is not dialing permission.
|
||||
|
||||
## Authorized nonproduction ARI/HTTP setup — 2026-10-04
|
||||
|
||||
- After read-only confirmation of **zero active calls and channels**, the committed and locally tested `configure-asterisk-user-ari.sh` (`1d12007`) created only the `rogee` user's private `ari.conf`, `http.conf` and `ari-secret`, all mode `0600`; no existing file was overwritten and no credential was printed or committed. HTTP binds only `127.0.0.1:8088`. The user-level Asterisk service was then explicitly restarted and reported **enabled+active** with a live CLI; anonymous ARI status returned **401**, and a read-only authenticated ARI information request returned **200**. No outbound call, registration or media capture was performed.
|
||||
- Very short independent SSH probes had observed the service active before its control socket appeared. In a sustained SSH session, its PID stayed stable and the socket and CLI became available after startup; this was a session/startup observation, not evidence of a broken Asterisk binary. Lingering is **still disabled**: availability after logout or reboot remains unverified. Real Agent ARI use, signed task/provider snapshots, carrier requirements and capture-first host validation have **not** been accepted.
|
||||
|
||||
## Still required before a real call or production acceptance
|
||||
|
||||
1. Verify the effect of endpoint updates **during an active authorized call** separately; SIP-only does not enable business dialing. Unsupported authentication/REGISTER and transport changes must continue to fail closed, and provider-side authentication, registration, routing and capacity remain unverified.
|
||||
2. Obtain carrier-confirmed authentication, transport and registration requirements for each real line, provide approved real line configuration, and arrange each whitelist trial (trunk, original number, time, attempt count). The fixed Asia/Shanghai 09:00–20:00 gate and per-number daily cap remain mandatory.
|
||||
3. Establish the approved task/provider snapshots, real ASR/TTS/recording chain and nonproduction call-evidence capture. One isolated Bailian LLM request and one unique-object OSS PUT succeeded independently ([evidence](real-ai-oss-one-shot-20261003.md)); neither proves a phone call or SaaS application receipt. tcpdump and passwordless sudo are now present, but `deploys/test/nonprod-call-evidence.sh` still targets a system-level Asterisk service rather than this host's `rogee` user service. Update and verify that diagnostic entry, ARI/HTTP config, PJSIP logger, and pre-dial capture before any call; any unavailable step fails closed.
|
||||
3. Establish the approved task/provider snapshots, real ASR/TTS/recording chain and nonproduction call-evidence capture. One isolated Bailian LLM request and one unique-object OSS PUT succeeded independently ([evidence](real-ai-oss-one-shot-20261003.md)); neither proves a phone call or SaaS application receipt. tcpdump and passwordless sudo are now present, and `deploys/test/nonprod-call-evidence.sh` now has an explicit user-service scope verified with local fail-closed tests; its **host** preflight and actual PJSIP logger/capture are not yet verified. User-level ARI/HTTP is configured as above, but the formal Agent business call route still rejects non-Mock execution. Verify the host diagnostics, real media and signed snapshots before any call; any unavailable step fails closed.
|
||||
4. Enable `rogee` user lingering and verify reboot-persistent `enabled+active` before claiming production readiness. Complete the host/network/dependency diagnostics and external signoffs separately; local `make check` cannot replace them.
|
||||
|
||||
Reference in New Issue
Block a user