fix(assistant): 根目錄守門補上目錄存在檢查

人在現場那一條路解出根目錄之後,守門只看「非空、結束碼 0、是絕對路徑」三項,攔不住 JSC_HOME 沒設的情況。

實測:JSC_HOME 沒設時,readlink -f "$JSC_HOME/current" 印出 /current、結束碼 0。三項全部符合,直接通關,而 /current 並不存在。之後每一條由它組出來的字面路徑都指向不存在的地方,錯誤要到第一支腳本才浮出來,而且訊息看不出根因。

守門加上第四項:印出來的路徑必須是存在的目錄,用 [ -d ] 在同一個已核准的步驟裡查。檢查只掛在人在現場那一條,排程那一輪照舊一個指令都不跑——它的根目錄是安裝排程的人寫進條目的,錯了就由第一支腳本呼叫失敗來反映。

行為契約的關鍵步驟與完成條件兩列跟著改。
This commit is contained in:
2026-09-03 10:31:05 +08:00
parent e4a3d3ae12
commit 711eecac2f
2 changed files with 3 additions and 3 deletions
File diff suppressed because one or more lines are too long
+1 -1
View File
@@ -34,7 +34,7 @@ Never work the root out instead. `readlink -f "$JSC_HOME/current"`, `ls -d "$JSC
Take the root once per invocation and reuse that one answer. Never resolve it again per call, never print it as a report line of its own, and never add a tool that prints it. Never test the root with a command either — an unattended round cannot, and the first script call is the test that matters anyway. Take the root once per invocation and reuse that one answer. Never resolve it again per call, never print it as a report line of its own, and never add a tool that prints it. Never test the root with a command either — an unattended round cannot, and the first script call is the test that matters anyway.
An empty token, an empty `readlink` result, or a path that is not absolute means there is no root to work with. Report it, say `jsc-cli:deploy` has to run, take the operation's `aborted` status, and stop. Never fall back to a cache path, and never create the root here. Completion condition: one literal absolute path is in hand and every later command line carries it, or the missing root was reported and the operation stopped. An empty token, an empty `readlink` result, a path that is not absolute, or a resolved path that is not an existing directory means there is no root to work with. **That fourth item is the one the other three wave through.** With `JSC_HOME` unset, `readlink -f "$JSC_HOME/current"` prints `/current` and exits 0 — non-empty, absolute, and past every other item — and each literal path built from it then names a place that is not there. So the attended resolve is only accepted once `[ -d "{the path just printed}" ]` says that directory exists, run in the same approved step as the resolve itself. The unattended round tests nothing, exactly as above: its root was written into the entry by whoever installed the schedule, and its first script call is what fails if that root is wrong. Report it, say `jsc-cli:deploy` has to run, take the operation's `aborted` status, and stop. Never fall back to a cache path, and never create the root here. Completion condition: one literal absolute path is in hand and every later command line carries it, or the missing root was reported and the operation stopped.
## Every script call carries a literal absolute path ## Every script call carries a literal absolute path