助理巡檢目錄頁改成大標題加條列,巡檢輸出檔改名 contents-entry.md #13

Merged
admin merged 3 commits from feat/contents-list/main into develop 2026-09-02 10:00:32 +00:00
11 changed files with 145 additions and 131 deletions
+1 -1
View File
@@ -1,6 +1,6 @@
{ {
"name": "jsc-assist", "name": "jsc-assist",
"version": "0.1.4", "version": "0.1.5",
"description": "助理:事件收攏、健康巡檢與待辦簿(MONITOR_{HASH} wiki 頁)", "description": "助理:事件收攏、健康巡檢與待辦簿(MONITOR_{HASH} wiki 頁)",
"skills": "./skills", "skills": "./skills",
"author": { "author": {
+1 -1
View File
@@ -1,6 +1,6 @@
{ {
"name": "jsc-assist", "name": "jsc-assist",
"version": "0.1.4", "version": "0.1.5",
"description": "助理:事件收攏、健康巡檢與待辦簿(MONITOR_{HASH} wiki 頁)", "description": "助理:事件收攏、健康巡檢與待辦簿(MONITOR_{HASH} wiki 頁)",
"skills": "./skills", "skills": "./skills",
"jsc": { "jsc": {
+1 -1
View File
@@ -17,7 +17,7 @@
1. 不做任何要問使用者的決策。背景巡檢時靜默套預設值,等於把逐項共識整條做掉。 1. 不做任何要問使用者的決策。背景巡檢時靜默套預設值,等於把逐項共識整條做掉。
2. 不參與閘門判定。閘門必須留在 hook:同步、不連網、毫秒級。助理只負責維持心跳。 2. 不參與閘門判定。閘門必須留在 hook:同步、不連網、毫秒級。助理只負責維持心跳。
3. 不寫程式碼存取庫、不 commit、不 push、不開 PR、不合併。 3. 不寫程式碼存取庫、不 commit、不 push、不開 PR、不合併。
4. 監控頁只照固定三塊寫:最新一輪整塊換掉、摘要表保留近 24 輪、基本資料建頁之後不動;目錄頁只動自己那一列,別台機器的列一個字都不碰。軌跡留在摘要表,一輪一列,看得出是從哪一輪開始壞的;完整內容只留最新一輪,因為頁面要能讀完才有人讀。 4. 監控頁只照固定三塊寫:最新一輪整塊換掉、摘要表保留近 24 輪、基本資料建頁之後不動;目錄頁一台機器一個 H2 區塊,只動自己那一個區塊,別台機器的區塊一個字都不碰。軌跡留在摘要表,一輪一列,看得出是從哪一輪開始壞的;完整內容只留最新一輪,因為頁面要能讀完才有人讀。
5. 不刪除狀態檔、worktree 與 wiki 頁。破壞性操作留給人發動。 5. 不刪除狀態檔、worktree 與 wiki 頁。破壞性操作留給人發動。
6. 不自動執行自己提出的建議。建議與執行是兩件事,自動接下去等於整條流程沒人按過同意就跑完。 6. 不自動執行自己提出的建議。建議與執行是兩件事,自動接下去等於整條流程沒人按過同意就跑完。
+5 -5
View File
@@ -26,7 +26,7 @@ Marketplace 統一為 `jsc`(https://gitea.jsc.idv.tw/plugins/meta.git),安
### `assistant` ### `assistant`
助理主體,四個操作:`start` 啟動、`status` 查現況、`patrol` 跑一輪巡檢、`stop` 停止。心跳的寫入、判定與清除一律交給 `jsc-hooks` 的 `hooks/heartbeat.sh`,判定只有那一份;系統排程一律交給 `tools/schedule.sh`;一輪巡檢的流程交給 `tools/patrol.sh`。工具一律用 `$JSC_HOME/current/{外掛名}` 那一組不帶版本的路徑叫,不用技能提示給的快取基底目錄——權限只放行 current 那一組。**心跳由巡檢寫,而且只由巡檢寫**:一輪跑完、結果寫上監控頁了,才寫那一次心跳,所以心跳新鮮等於「上一輪巡檢真的做完了」。`start` 先跑一輪巡檢,再裝上巡檢那一筆排程;巡檢週期由心跳的過期門檻算出來,兩個數字綁在一起。`patrol` 讀五項來源(使用統計、版本與重啟閘門、SDLC 階段鎖與工作包鎖、心跳自述、執行狀態事件),各項各自獨立,一項掛掉其餘各項照跑、照記,結果寫上 `MONITOR_{HASH}`:那頁固定三塊,基本資料不動、最新一輪整塊換掉、摘要表保留近 24 輪,一輪一列。目錄頁 `MONITOR_CONTENTS` 在另一個存取庫(`JSC_WIKI_REPO_CONTENTS`),只更新自己那一列,交給 `jsc-gitea/tools/wiki-contents.sh upsert` 寫,連結用絕對網址;那個存取庫沒設定時只少一列索引,這一輪照樣算跑完、照樣寫心跳。`status` 全程唯讀,讀心跳、排程與待辦簿,印成三塊;助理沒在跑就印「助理未運行」,不當成錯誤。`stop` 先移除排程再清掉心跳,順序不能反。這支不參與閘門判定、不做決策、巡檢那一路全程不問人。 助理主體,四個操作:`start` 啟動、`status` 查現況、`patrol` 跑一輪巡檢、`stop` 停止。心跳的寫入、判定與清除一律交給 `jsc-hooks` 的 `hooks/heartbeat.sh`,判定只有那一份;系統排程一律交給 `tools/schedule.sh`;一輪巡檢的流程交給 `tools/patrol.sh`。工具一律用 `$JSC_HOME/current/{外掛名}` 那一組不帶版本的路徑叫,不用技能提示給的快取基底目錄——權限只放行 current 那一組。**心跳由巡檢寫,而且只由巡檢寫**:一輪跑完、結果寫上監控頁了,才寫那一次心跳,所以心跳新鮮等於「上一輪巡檢真的做完了」。`start` 先跑一輪巡檢,再裝上巡檢那一筆排程;巡檢週期由心跳的過期門檻算出來,兩個數字綁在一起。`patrol` 讀五項來源(使用統計、版本與重啟閘門、SDLC 階段鎖與工作包鎖、心跳自述、執行狀態事件),各項各自獨立,一項掛掉其餘各項照跑、照記,結果寫上 `MONITOR_{HASH}`:那頁固定三塊,基本資料不動、最新一輪整塊換掉、摘要表保留近 24 輪,一輪一列。目錄頁 `MONITOR_CONTENTS` 在另一個存取庫(`JSC_WIKI_REPO_CONTENTS`),一台機器一個 H2 區塊,只更新自己那一個區塊,交給 `jsc-gitea/tools/wiki-contents.sh upsert` 寫,連結用絕對網址;那個存取庫沒設定時只少一筆索引,這一輪照樣算跑完、照樣寫心跳。`status` 全程唯讀,讀心跳、排程與待辦簿,印成三塊;助理沒在跑就印「助理未運行」,不當成錯誤。`stop` 先移除排程再清掉心跳,順序不能反。這支不參與閘門判定、不做決策、巡檢那一路全程不問人。
<!-- JSC-SKILLS:END --> <!-- JSC-SKILLS:END -->
@@ -35,7 +35,7 @@ Marketplace 統一為 `jsc`(https://gitea.jsc.idv.tw/plugins/meta.git),安
| Plugin | 最低版本 | 用途 | | Plugin | 最低版本 | 用途 |
| --- | --- | --- | | --- | --- | --- |
| `jsc-cli` | `>=0.2.7` | CLI 偵測與委派 | | `jsc-cli` | `>=0.2.7` | CLI 偵測與委派 |
| `jsc-gitea` | `>=0.2.0` | 監控頁的所有 wiki 讀寫,一律經 `tools/gitea.sh`;目錄頁那一列走 `tools/wiki-contents.sh upsert`,頁名雜湊走 `tools/hash-id`,兩頁要放進去的連結一律先過 `tools/link-check.sh` | | `jsc-gitea` | `>=0.2.0` | 監控頁的所有 wiki 讀寫,一律經 `tools/gitea.sh`;目錄頁那一個區塊走 `tools/wiki-contents.sh upsert`,頁名雜湊走 `tools/hash-id`,兩頁要放進去的連結一律先過 `tools/link-check.sh` |
| `jsc-hooks` | `>=0.3.7` | 心跳、閘門與事件來源(`$JSC_HOME` 底下的狀態檔)。心跳的寫入、判定與清除一律走 `hooks/heartbeat.sh`,那支腳本是 `0.3.7` 才有的 | | `jsc-hooks` | `>=0.3.7` | 心跳、閘門與事件來源(`$JSC_HOME` 底下的狀態檔)。心跳的寫入、判定與清除一律走 `hooks/heartbeat.sh`,那支腳本是 `0.3.7` 才有的 |
| `jsc-log` | `>=0.1.4` | 使用統計與工作日誌的資料來源 | | `jsc-log` | `>=0.1.4` | 使用統計與工作日誌的資料來源 |
@@ -44,9 +44,9 @@ Marketplace 統一為 `jsc`(https://gitea.jsc.idv.tw/plugins/meta.git),安
| 檔案 | 用途 | | 檔案 | 用途 |
| --- | --- | | --- | --- |
| `tools/schedule.sh` | 助理系統排程的安裝、移除與查現況。三個子命令 `install`、`remove`、`status`,只裝 `patrol` 這一筆——心跳由巡檢自己寫,`install heartbeat` 一律回 6,舊版遺留的心跳條目由 `install patrol` 順手清掉。巡檢週期由心跳的過期門檻算出來(`2 × 週期 × 60 < 門檻`,再取能整除一小時的分鐘數):門檻 300 秒是每 2 分鐘一輪,門檻 1800 秒是每 12 分鐘一輪。Linux、WSL 與 macOS 走 crontab,Windows 走 schtasks。條目行尾帶固定標記 `# jsc-assist:assistant {工作}`,只動自己那一筆,別人的排程一行都不碰。條目自己把環境帶齊:CLI 用 `command -v` 解成絕對路徑、安裝當下把 `GITEA_HOST`、`GITEA_TOKEN`、`JSC_HOME`、`JSC_ASSISTANT_HEARTBEAT_TTL` 與已設定的 `JSC_WIKI_REPO` 系列快照進條目、自帶 `JSC_GITEA_CONFIRM=yes`。`JSC_WIKI_REPO` 系列含內容頁的 `JSC_WIKI_REPO_MONITOR` 與目錄頁的 `JSC_WIKI_REPO_CONTENTS`:監控頁 `MONITOR_{HASH}` 與目錄頁 `MONITOR_CONTENTS` 分屬不同存取庫,兩支變數都要帶。名單是安裝當下從環境撈出所有已設定的,不寫死,所以新增的頁型變數自動涵蓋,這支不必跟著改——cron 的 PATH 很短、不讀設定檔、也沒有 tty。印出條目時金鑰一律遮掉,條目本身含金鑰快照,crontab 檔案要保持只有本人讀得到,變數改過要重跑一次 install。裝完會檢查排程服務在不在跑,沒跑就回 1——WSL 預設不啟動 cron;也會檢查 `$JSC_HOME/current` 那組連結在不在、印出這一輪要開的 allow 規則,連結不在只警告、不代建。`--dry-run` 只印組出來的條目與寫回後的內容,什麼都不動 | | `tools/schedule.sh` | 助理系統排程的安裝、移除與查現況。三個子命令 `install`、`remove`、`status`,只裝 `patrol` 這一筆——心跳由巡檢自己寫,`install heartbeat` 一律回 6,舊版遺留的心跳條目由 `install patrol` 順手清掉。巡檢週期由心跳的過期門檻算出來(`2 × 週期 × 60 < 門檻`,再取能整除一小時的分鐘數):門檻 300 秒是每 2 分鐘一輪,門檻 1800 秒是每 12 分鐘一輪。Linux、WSL 與 macOS 走 crontab,Windows 走 schtasks。條目行尾帶固定標記 `# jsc-assist:assistant {工作}`,只動自己那一筆,別人的排程一行都不碰。條目自己把環境帶齊:CLI 用 `command -v` 解成絕對路徑、安裝當下把 `GITEA_HOST`、`GITEA_TOKEN`、`JSC_HOME`、`JSC_ASSISTANT_HEARTBEAT_TTL` 與已設定的 `JSC_WIKI_REPO` 系列快照進條目、自帶 `JSC_GITEA_CONFIRM=yes`。`JSC_WIKI_REPO` 系列含內容頁的 `JSC_WIKI_REPO_MONITOR` 與目錄頁的 `JSC_WIKI_REPO_CONTENTS`:監控頁 `MONITOR_{HASH}` 與目錄頁 `MONITOR_CONTENTS` 分屬不同存取庫,兩支變數都要帶。名單是安裝當下從環境撈出所有已設定的,不寫死,所以新增的頁型變數自動涵蓋,這支不必跟著改——cron 的 PATH 很短、不讀設定檔、也沒有 tty。印出條目時金鑰一律遮掉,條目本身含金鑰快照,crontab 檔案要保持只有本人讀得到,變數改過要重跑一次 install。裝完會檢查排程服務在不在跑,沒跑就回 1——WSL 預設不啟動 cron;也會檢查 `$JSC_HOME/current` 那組連結在不在、印出這一輪要開的 allow 規則,連結不在只警告、不代建。`--dry-run` 只印組出來的條目與寫回後的內容,什麼都不動 |
| `tools/patrol.sh` | 一輪巡檢的收攏與收口。三個子命令:`collect` 取鎖、讀五項來源、組出監控頁的「最新一輪」與「近 24 輪摘要」兩塊、本輪的摘要列與目錄頁那一列(那一列的第一欄是連結,網址留佔位,等監控頁寫成之後由呼叫端用 `gitea.sh wiki-url` 的絕對網址換掉;第 2 欄是裸 HASH,upsert 拿那一欄當鍵);`finish` 在監控頁寫成之後才寫心跳、換上用量快照、放掉鎖;`abort` 只放掉鎖,不寫心跳。各項來源各自獨立,一項失敗其餘各項照跑,失敗那一項在頁上寫明是「這一項失敗」而不是沒資料。執行狀態事件那一項由 `collect` 自己叫 `jsc-hooks/tools/report-status.sh` 排空再輪替,把非 ok 的事件與「有 start 沒有配對 end」的技能彙整成頁上那一節;`drain` 是消耗性讀取,所以只由這支跑,且它失敗一律不中止那一輪。整輪拿一把目錄鎖,上一輪還在跑就回 4 讓開;鎖逾時(門檻取心跳門檻)會被下一輪搶回來,並在頁上記一筆。`version-guard.sh report` 回「查詢失敗」時照原字抄,不補查、不美化 | | `tools/patrol.sh` | 一輪巡檢的收攏與收口。三個子命令:`collect` 取鎖、讀五項來源、組出監控頁的「最新一輪」與「近 24 輪摘要」兩塊、本輪的摘要列與目錄頁那一個區塊(區塊的 H2 標題是內容頁頁名 `MONITOR_{HASH}`,upsert 拿標題當鍵;「監控頁」那一條是連結,網址留佔位,等監控頁寫成之後由呼叫端用 `gitea.sh wiki-url` 的絕對網址換掉);`finish` 在監控頁寫成之後才寫心跳、換上用量快照、放掉鎖;`abort` 只放掉鎖,不寫心跳。各項來源各自獨立,一項失敗其餘各項照跑,失敗那一項在頁上寫明是「這一項失敗」而不是沒資料。執行狀態事件那一項由 `collect` 自己叫 `jsc-hooks/tools/report-status.sh` 排空再輪替,把非 ok 的事件與「有 start 沒有配對 end」的技能彙整成頁上那一節;`drain` 是消耗性讀取,所以只由這支跑,且它失敗一律不中止那一輪。整輪拿一把目錄鎖,上一輪還在跑就回 4 讓開;鎖逾時(門檻取心跳門檻)會被下一輪搶回來,並在頁上記一筆。`version-guard.sh report` 回「查詢失敗」時照原字抄,不補查、不美化 |
| `references/behaviors.md` | 本 domain 的技能行為清單:一支技能一節,五列記下觸發時機、關鍵步驟、外部呼叫、完成條件、可驗證跡象,供稽核與驗證比對。格式合約見 `plugins/meta` 的 `references/guidelines.md`「技能行為清單」 | | `references/behaviors.md` | 本 domain 的技能行為清單:一支技能一節,五列記下觸發時機、關鍵步驟、外部呼叫、完成條件、可驗證跡象,供稽核與驗證比對。格式合約見 `plugins/meta` 的 `references/guidelines.md`「技能行為清單」 |
| `templates/monitor-contents.md` | 目錄頁 `MONITOR_CONTENTS` 的範本,這一頁落在 `JSC_WIKI_REPO_CONTENTS` 解出的專用存取庫,和監控頁不同庫。一列代表一台機器,雜湊來源是 `{主機名}/{登入帳號}`,主機名取短的那一段。寫入一律走 `jsc-gitea/tools/wiki-contents.sh upsert`,比對鍵是第 2 欄的裸 HASH:**只更新自己那一列**,別台機器的列原樣保留,禁止整頁覆蓋。第一欄的連結一律寫成 `[{頁名}]({絕對網址})`,網址取 `gitea.sh wiki-url` 印的那一個,寫入前先過 `jsc-gitea/tools/link-check.sh`、結束碼 0 才寫;但那一格含主機位址與網址編碼,會變,所以不當鍵 | | `templates/monitor-contents.md` | 目錄頁 `MONITOR_CONTENTS` 的範本,這一頁落在 `JSC_WIKI_REPO_CONTENTS` 解出的專用存取庫,和監控頁不同庫。版面是 H1、`>` 引言,然後一台機器一個 H2 區塊,欄位在標題底下一行一條 `- {欄位名}:{值}`,頁上不放 markdown 表格。H2 標題就是內容頁頁名 `MONITOR_{HASH}`,雜湊來源是 `{主機名}/{登入帳號}`,主機名取短的那一段。寫入一律走 `jsc-gitea/tools/wiki-contents.sh upsert`,比對鍵是 H2 標題:**只更新自己那一個區塊**,別台機器的區塊原樣保留,禁止整頁覆蓋。「監控頁」那一條的連結一律寫成 `[{頁名}]({絕對網址})`,網址取 `gitea.sh wiki-url` 印的那一個,寫入前先過 `jsc-gitea/tools/link-check.sh`、結束碼 0 才寫;但那一條含主機位址與網址編碼,會變,所以不當鍵 |
| `templates/monitor-page.md` | 內容頁 `MONITOR_{HASH}` 的範本。記的是這台機器的巡檢軌跡。頁面固定三塊:本頁基本資料建頁時寫一次就不動、最新一輪每輪整塊換掉、近 24 輪摘要一輪一列且最新的在最上面。軌跡留在摘要表,完整內容只留最新一輪,頁面才讀得完 | | `templates/monitor-page.md` | 內容頁 `MONITOR_{HASH}` 的範本。記的是這台機器的巡檢軌跡。頁面固定三塊:本頁基本資料建頁時寫一次就不動、最新一輪每輪整塊換掉、近 24 輪摘要一輪一列且最新的在最上面。軌跡留在摘要表,完整內容只留最新一輪,頁面才讀得完 |
## 助理的狀態檔 ## 助理的狀態檔
@@ -59,7 +59,7 @@ Marketplace 統一為 `jsc`(https://gitea.jsc.idv.tw/plugins/meta.git),安
| `tasks/{id}` | 待辦簿,一筆一檔。一筆一檔是為了讓並行寫入不互相覆寫 | | `tasks/{id}` | 待辦簿,一筆一檔。一筆一檔是為了讓並行寫入不互相覆寫 |
| `schedule.log` | 排程條目的輸出。刻意放在存取庫外面:寫進專案會多出未追蹤檔,污染別人的變更盤點 | | `schedule.log` | 排程條目的輸出。刻意放在存取庫外面:寫進專案會多出未追蹤檔,污染別人的變更盤點 |
| `patrol.lock/` | 一輪巡檢的鎖,是目錄——`mkdir` 是原子操作,搶不到就是別人在跑。裡面的 `info` 記 `round`、`pid`、`started` | | `patrol.lock/` | 一輪巡檢的鎖,是目錄——`mkdir` 是原子操作,搶不到就是別人在跑。裡面的 `info` 記 `round`、`pid`、`started` |
| `patrol/` | 本輪巡檢的暫存檔:`latest.md` 是「最新一輪」那一塊,`summary.md` 是摘要那一塊、裡面已經放好本輪這一列,`summary-row.md` 只有那一列,`newpage.md` 是頁不存在時要建的整頁,`contents.tsv` 是目錄頁那一列 | | `patrol/` | 本輪巡檢的暫存檔:`latest.md` 是「最新一輪」那一塊,`summary.md` 是摘要那一塊、裡面已經放好本輪這一列,`summary-row.md` 只有那一列,`newpage.md` 是頁不存在時要建的整頁,`contents-entry.md` 是目錄頁那一個 H2 區塊 |
| `usage-prev.tsv` | 上一輪記下來的累計用量。有了它,下一輪的「本輪次數」才算得出來;沒有它的第一輪一律寫「-」,不拿累計冒充本輪 | | `usage-prev.tsv` | 上一輪記下來的累計用量。有了它,下一輪的「本輪次數」才算得出來;沒有它的第一輪一律寫「-」,不拿累計冒充本輪 |
## 相關 domain ## 相關 domain
+1 -1
View File
@@ -1,6 +1,6 @@
{ {
"name": "jsc-assist", "name": "jsc-assist",
"version": "0.1.4", "version": "0.1.5",
"description": "助理:事件收攏、健康巡檢與待辦簿(MONITOR_{HASH} wiki 頁)", "description": "助理:事件收攏、健康巡檢與待辦簿(MONITOR_{HASH} wiki 頁)",
"skills": "./skills/", "skills": "./skills/",
"jsc": { "jsc": {
File diff suppressed because one or more lines are too long
+22 -20
View File
@@ -1,6 +1,6 @@
--- ---
name: assistant name: assistant
description: 'Start, inspect, patrol or stop the background assistant: jsc-hooks/hooks/heartbeat.sh owns the freshness verdict, tools/schedule.sh the system scheduler, tools/patrol.sh one round. The heartbeat is written by a completed round and by nothing else, so the schedule carries the patrol entry only, its period from the heartbeat TTL; start runs one round then installs that entry - absolute CLI path, environment snapshot, unattended write confirmation, which cron lacks - status prints heartbeat, schedule and task book read-only, stop removes the entry before clearing the heartbeat. One round reads five independent sources - skill and chain usage, version gaps and the restart gate, SDLC stage and work-package locks, the heartbeat''s own report, and the status event stream that jsc-hooks/tools/report-status.sh drains and rotates, whose starts with no matching end are the only evidence an earlier skill run aborted - then rewrites wiki MONITOR_{HASH} through jsc-gitea:wiki as three fixed blocks - basic data untouched, the latest round replaced whole, a 24-row summary table - and upserts its MONITOR_CONTENTS row through jsc-gitea/tools/wiki-contents.sh, which reads the separate CONTENTS wiki repo and links the monitor page by its absolute wiki-url. Every link on either page is written as [text](URL) and is verified by jsc-gitea/tools/link-check.sh before that page is written, so a dead link stops the write instead of landing on the page. A round that cannot record its result writes no heartbeat; one that starts while the previous holds the lock stands down. Use when someone starts, patrols or stops the assistant, or asks whether it runs and what is queued; not for environment health checks (jsc-cli:doctor), not for skill usage counts (jsc-log:stats).' description: 'Start, inspect, patrol or stop the background assistant: jsc-hooks/hooks/heartbeat.sh owns the freshness verdict, tools/schedule.sh the system scheduler, tools/patrol.sh one round. The heartbeat is written by a completed round and by nothing else, so the schedule carries the patrol entry only, its period from the heartbeat TTL; start runs one round then installs that entry - absolute CLI path, environment snapshot, unattended write confirmation, which cron lacks - status prints heartbeat, schedule and task book read-only, stop removes the entry before clearing the heartbeat. One round reads five independent sources - skill and chain usage, version gaps and the restart gate, SDLC stage and work-package locks, the heartbeat''s own report, and the status event stream that jsc-hooks/tools/report-status.sh drains and rotates, whose starts with no matching end are the only evidence an earlier skill run aborted - then rewrites wiki MONITOR_{HASH} through jsc-gitea:wiki as three fixed blocks - basic data untouched, the latest round replaced whole, a 24-row summary table - and upserts its MONITOR_CONTENTS entry through jsc-gitea/tools/wiki-contents.sh, which reads the separate CONTENTS wiki repo and keeps one H2 block per machine - the heading is the monitor page''s own name, the fields are bullets under it, and one of them links that page by its absolute wiki-url. Every link on either page is written as [text](URL) and is verified by jsc-gitea/tools/link-check.sh before that page is written, so a dead link stops the write instead of landing on the page. A round that cannot record its result writes no heartbeat; one that starts while the previous holds the lock stands down. Use when someone starts, patrols or stops the assistant, or asks whether it runs and what is queued; not for environment health checks (jsc-cli:doctor), not for skill usage counts (jsc-log:stats).'
--- ---
# assistant — start, status, patrol, stop # assistant — start, status, patrol, stop
@@ -26,10 +26,10 @@ Every tool below is addressed through `$JSC_HOME/current/{plugin}`, and `$JSC_HO
| the heartbeat | `$JSC_HOME/current/jsc-hooks/hooks/heartbeat.sh` | | the heartbeat | `$JSC_HOME/current/jsc-hooks/hooks/heartbeat.sh` |
| the status event stream | `$JSC_HOME/current/jsc-hooks/tools/report-status.sh` | | the status event stream | `$JSC_HOME/current/jsc-hooks/tools/report-status.sh` |
| the wiki, through `jsc-gitea:wiki` | `$JSC_HOME/current/jsc-gitea/tools/gitea.sh` | | the wiki, through `jsc-gitea:wiki` | `$JSC_HOME/current/jsc-gitea/tools/gitea.sh` |
| the `MONITOR_CONTENTS` row | `$JSC_HOME/current/jsc-gitea/tools/wiki-contents.sh` | | the `MONITOR_CONTENTS` entry | `$JSC_HOME/current/jsc-gitea/tools/wiki-contents.sh` |
| the link check every write depends on | `$JSC_HOME/current/jsc-gitea/tools/link-check.sh` | | the link check every write depends on | `$JSC_HOME/current/jsc-gitea/tools/link-check.sh` |
**A `Skill(...)` rule permits invoking that skill and nothing more.** Every Bash call inside it is still checked on its own, so `jsc-gitea:wiki` reaching the wiki depends on `gitea.sh` carrying its own rule, the directory row depends on `wiki-contents.sh` carrying one too, and both writes depend on `link-check.sh` carrying one — without them the round is refused locally, before any request leaves the machine, and the page never gets written. **A `Skill(...)` rule permits invoking that skill and nothing more.** Every Bash call inside it is still checked on its own, so `jsc-gitea:wiki` reaching the wiki depends on `gitea.sh` carrying its own rule, the directory entry depends on `wiki-contents.sh` carrying one too, and both writes depend on `link-check.sh` carrying one — without them the round is refused locally, before any request leaves the machine, and the page never gets written.
**Never build a tool path out of the base directory the CLI hands you in the skill prompt.** That directory points into the plugin cache and carries a version segment, and the permission gate allows exactly the seven paths above and nothing else. A cache path is therefore refused silently: the round stops on a permission prompt nobody can answer, records nothing, writes no heartbeat, and the refusal looks exactly like a broken tool. Read the paths off this table every time — not off the prompt, not off a previous transcript, not off `crontab -l`. **Never build a tool path out of the base directory the CLI hands you in the skill prompt.** That directory points into the plugin cache and carries a version segment, and the permission gate allows exactly the seven paths above and nothing else. A cache path is therefore refused silently: the round stops on a permission prompt nobody can answer, records nothing, writes no heartbeat, and the refusal looks exactly like a broken tool. Read the paths off this table every time — not off the prompt, not off a previous transcript, not off `crontab -l`.
@@ -39,9 +39,9 @@ Both scripts check this for themselves: run from anywhere outside `$JSC_HOME/cur
## Two rules bind every link this skill writes ## Two rules bind every link this skill writes
Both pages this round writes carry links, and both rules below hold for every one of them — the monitor page and the directory row alike. Both pages this round writes carry links, and both rules below hold for every one of them — the monitor page and the directory entry alike.
**Rule A — a link is always written as `[{text}]({URL})`.** The wiki's own `[[page]]` and `[[text|page]]` forms are not used here at all, and neither is the split between "same repo" and "cross repo" writing. The URL comes from `$JSC_HOME/current/jsc-gitea/tools/gitea.sh wiki-url {repo} {page}`; never assemble a path by hand. `[[...]]` resolves only inside the wiki it sits in: the monitor page and the directory page live in two different repos, so a `[[MONITOR_{HASH}]]` written into the directory row renders as an ordinary-looking link that goes nowhere, and nothing reports it. **Rule A — a link is always written as `[{text}]({URL})`.** The wiki's own `[[page]]` and `[[text|page]]` forms are not used here at all, and neither is the split between "same repo" and "cross repo" writing. The URL comes from `$JSC_HOME/current/jsc-gitea/tools/gitea.sh wiki-url {repo} {page}`; never assemble a path by hand. `[[...]]` resolves only inside the wiki it sits in: the monitor page and the directory page live in two different repos, so a `[[MONITOR_{HASH}]]` written into the directory entry renders as an ordinary-looking link that goes nowhere, and nothing reports it.
**Rule B — a link is verified before it is written, never after.** Collect every link that is about to go into the page, hand the whole set to `$JSC_HOME/current/jsc-gitea/tools/link-check.sh`, and write only on exit 0. The script prints one `{OK|DEAD|SKIP}<TAB>{URL}<TAB>{note}` line per URL and checks Gitea URLs through the API, never through the web status code — a private repo answers 404 to a logged-out web request, so a status-code check condemns live pages. **Rule B — a link is verified before it is written, never after.** Collect every link that is about to go into the page, hand the whole set to `$JSC_HOME/current/jsc-gitea/tools/link-check.sh`, and write only on exit 0. The script prints one `{OK|DEAD|SKIP}<TAB>{URL}<TAB>{note}` line per URL and checks Gitea URLs through the API, never through the web status code — a private repo answers 404 to a logged-out web request, so a status-code check condemns live pages.
@@ -72,7 +72,7 @@ The `start` half is already on record — a hook writes it when this skill loads
| `ok` | the operation reached its own completion condition | | `ok` | the operation reached its own completion condition |
| `blocked` | the round stood down because another round holds the lock, or `install heartbeat` was refused — nothing was done and nothing is wrong | | `blocked` | the round stood down because another round holds the lock, or `install heartbeat` was refused — nothing was done and nothing is wrong |
| `failed` | a step returned a code that stopped the operation: `collect` exit 5 or 6, a monitor-page write that could not be made, `remove` non-zero in `stop` | | `failed` | a step returned a code that stopped the operation: `collect` exit 5 or 6, a monitor-page write that could not be made, `remove` non-zero in `stop` |
| `degraded` | the operation finished with a known gap: the directory row was left unwritten, or the schedule entry was installed but the cron service is stopped | | `degraded` | the operation finished with a known gap: the directory entry was left unwritten, or the schedule entry was installed but the cron service is stopped |
| `aborted` | the operation stopped because a precondition did not hold, such as an empty `hash=` or a missing `current` link | | `aborted` | the operation stopped because a precondition did not hold, such as an empty `hash=` or a missing `current` link |
The call never changes the outcome: it returns 0 even when it cannot write, and a non-zero from it is reported as a defect in the reporting chain, never as a failure of the operation that just succeeded. Completion condition for all four operations: exactly one `skill-end` was written, and its status matches the outcome that was reported. The call never changes the outcome: it returns 0 even when it cannot write, and a non-zero from it is reported as a defect in the reporting chain, never as a failure of the operation that just succeeded. Completion condition for all four operations: exactly one `skill-end` was written, and its status matches the outcome that was reported.
@@ -85,7 +85,7 @@ The call never changes the outcome: it returns 0 even when it cannot write, and
| `$JSC_HOME/assistant/schedule.log` | nobody here — the scheduled entry appends to it | free text; point the operator at it when a scheduled round misbehaves | | `$JSC_HOME/assistant/schedule.log` | nobody here — the scheduled entry appends to it | free text; point the operator at it when a scheduled round misbehaves |
| `$JSC_HOME/assistant/tasks/{id}` | this skill, read-only | `key=value` lines, one task per file: `id`, `kind` (`check` / `todo`), `title`, `action`, `trigger`, `recur`, `repo`, `due`, `state` (`pending` / `done` / `paused`), `last_run`, `next_run`, `fail_count`, `origin` (`user` / `assistant`) | | `$JSC_HOME/assistant/tasks/{id}` | this skill, read-only | `key=value` lines, one task per file: `id`, `kind` (`check` / `todo`), `title`, `action`, `trigger`, `recur`, `repo`, `due`, `state` (`pending` / `done` / `paused`), `last_run`, `next_run`, `fail_count`, `origin` (`user` / `assistant`) |
| `$JSC_HOME/assistant/patrol.lock/` | `patrol.sh` only | the round lock, a directory. `info` holds `round`, `pid`, `started` | | `$JSC_HOME/assistant/patrol.lock/` | `patrol.sh` only | the round lock, a directory. `info` holds `round`, `pid`, `started` |
| `$JSC_HOME/assistant/patrol/` | `patrol.sh` only | one round's scratch files, including `latest.md`, `summary.md`, `summary-row.md`, `newpage.md` and `contents.tsv` | | `$JSC_HOME/assistant/patrol/` | `patrol.sh` only | one round's scratch files, including `latest.md`, `summary.md`, `summary-row.md`, `newpage.md` and `contents-entry.md` |
| `$JSC_HOME/assistant/usage-prev.tsv` | `patrol.sh` only | last recorded round's cumulative usage counts, so the next round can print a real per-round delta | | `$JSC_HOME/assistant/usage-prev.tsv` | `patrol.sh` only | last recorded round's cumulative usage counts, so the next round can print a real per-round delta |
| `$JSC_HOME/usage/events.jsonl` | `report-status.sh` only, never this skill and never `patrol.sh` by hand | one JSON object per line: `ts`, `cli`, `session`, `kind`, `name`, `phase`, `status`, `exit`, optional `ms` and `detail` | | `$JSC_HOME/usage/events.jsonl` | `report-status.sh` only, never this skill and never `patrol.sh` by hand | one JSON object per line: `ts`, `cli`, `session`, `kind`, `name`, `phase`, `status`, `exit`, optional `ms` and `detail` |
| `$JSC_HOME/assistant/events-open.tsv` | `patrol.sh` only | the starts still waiting for a matching end, carried from round to round: `session`, `name`, `kind`, first-seen epoch, the event's own `ts` | | `$JSC_HOME/assistant/events-open.tsv` | `patrol.sh` only | the starts still waiting for a matching end, carried from round to round: `session`, `name`, `kind`, first-seen epoch, the event's own `ts` |
@@ -187,7 +187,7 @@ The six limits in `AGENTS.md`「助理的界線」 hold for all four operations.
- **This skill never judges a gate.** It maintains the heartbeat and prints what the heartbeat says. Whether a stale heartbeat blocks a skill call is decided by a hook, synchronously and offline; nothing in this skill blocks or waves through anything. 界線 2. - **This skill never judges a gate.** It maintains the heartbeat and prints what the heartbeat says. Whether a stale heartbeat blocks a skill call is decided by a hook, synchronously and offline; nothing in this skill blocks or waves through anything. 界線 2.
- **A patrol round asks nothing.** It runs from cron with nobody present, so there is no one to answer and a question hangs the round. Every branch in the patrol steps below resolves without a question: a missing source is recorded as missing, an ambiguous result is recorded verbatim, and a round that cannot proceed aborts and reports. Never call `jsc-ask:ask` from `patrol`. 界線 1. - **A patrol round asks nothing.** It runs from cron with nobody present, so there is no one to answer and a question hangs the round. Every branch in the patrol steps below resolves without a question: a missing source is recorded as missing, an ambiguous result is recorded verbatim, and a round that cannot proceed aborts and reports. Never call `jsc-ask:ask` from `patrol`. 界線 1.
- **A patrol round rewrites the monitor page as three fixed blocks.** Read the old page back first; keep 本頁基本資料 as it stands, replace 最新一輪 whole, put this round's row on top of the summary table and cut it to 24; then put the whole page. The directory page is a separate write in a separate wiki repo, and `wiki-contents.sh` does it: this machine's row is updated and nobody else's. A page that could not be read is a page that does not get written — the summary table only survives if the old one came back. 界線 4. - **A patrol round rewrites the monitor page as three fixed blocks.** Read the old page back first; keep 本頁基本資料 as it stands, replace 最新一輪 whole, put this round's row on top of the summary table and cut it to 24; then put the whole page. The directory page is a separate write in a separate wiki repo, and `wiki-contents.sh` does it: that page keeps one H2 block per machine, and this machine's block is the only one that is updated. A page that could not be read is a page that does not get written — the summary table only survives if the old one came back. 界線 4.
- **A patrol round reports; it never acts on what it found.** The 待人處理 rows name an entry point for a human. The patrol does not run that entry point, does not fix a hook, does not update a plugin and does not touch a repository. 界線 3 and 界線 6. - **A patrol round reports; it never acts on what it found.** The 待人處理 rows name an entry point for a human. The patrol does not run that entry point, does not fix a hook, does not update a plugin and does not touch a repository. 界線 3 and 界線 6.
- **`stop` clearing the heartbeat and removing the schedule is not a breach of 界線 5「不刪除狀態檔」.** That limit protects state that records work — the task book, worktrees, wiki pages — from a background process nobody is watching. The heartbeat records one fact only, "the last patrol round finished", and the schedule entry is what keeps rounds running, so a `stop` that leaves either behind leaves a lie behind. Clearing both is the whole job of `stop`, and they are the only deletions any operation here performs, both of them entries this skill installed itself. `stop` touches nothing under `tasks/`, nobody else's cron entry, no worktree and no wiki page. Do not "restore" this limit later by taking either removal out of `stop`. - **`stop` clearing the heartbeat and removing the schedule is not a breach of 界線 5「不刪除狀態檔」.** That limit protects state that records work — the task book, worktrees, wiki pages — from a background process nobody is watching. The heartbeat records one fact only, "the last patrol round finished", and the schedule entry is what keeps rounds running, so a `stop` that leaves either behind leaves a lie behind. Clearing both is the whole job of `stop`, and they are the only deletions any operation here performs, both of them entries this skill installed itself. `stop` touches nothing under `tasks/`, nobody else's cron entry, no worktree and no wiki page. Do not "restore" this limit later by taking either removal out of `stop`.
@@ -203,7 +203,7 @@ That property holds only while nothing fakes a heartbeat. **`write` is called by
`start` proves the loop works before it schedules it: one patrol round first, then the scheduled entry. It installs no daemon and writes no bare heartbeat. `start` proves the loop works before it schedules it: one patrol round first, then the scheduled entry. It installs no daemon and writes no bare heartbeat.
1. **Run one patrol round.** Follow every step of the `patrol` operation below, start to finish. This is what writes the first heartbeat — there is no shortcut past it, because a heartbeat that no round produced is exactly the lie this design removes. When that round ends without a heartbeat for any reason (`collect` exit 4, 5 or 6, an empty `hash=`, a failed write of the monitor page, a directory-row failure other than exit 3, or `finish` exit 2, 4 or 5), the start has failed: report the round's outcome and the code, do not run step 2, and do not claim a started assistant. A round that completed with failed items (`collect` exit 1 or 3) is still a completed round — carry on to step 2 and name the failures in the closing report. Completion condition: `patrol.sh finish` exited 0, or the failure report naming the step and the code has been printed and no start was claimed. 1. **Run one patrol round.** Follow every step of the `patrol` operation below, start to finish. This is what writes the first heartbeat — there is no shortcut past it, because a heartbeat that no round produced is exactly the lie this design removes. When that round ends without a heartbeat for any reason (`collect` exit 4, 5 or 6, an empty `hash=`, a failed write of the monitor page, a directory-entry failure other than exit 3, or `finish` exit 2, 4 or 5), the start has failed: report the round's outcome and the code, do not run step 2, and do not claim a started assistant. A round that completed with failed items (`collect` exit 1 or 3) is still a completed round — carry on to step 2 and name the failures in the closing report. Completion condition: `patrol.sh finish` exited 0, or the failure report naming the step and the code has been printed and no start was claimed.
2. **Confirm the heartbeat.** Run `$JSC_HOME/current/jsc-hooks/hooks/heartbeat.sh report` and read its `state=`, `ts=`, `ttl=`, `pid=`, `cli=`, `session=` and `file=` fields. `state=fresh` is the expected result. Any other state right after a successful round means something rewrote or removed the file in between: report the state, the path and that the heartbeat did not survive its own write, and do not claim a started assistant. Completion condition: the report line was read and either `state=fresh` was recorded with its seven fields, or the mismatch was reported. 2. **Confirm the heartbeat.** Run `$JSC_HOME/current/jsc-hooks/hooks/heartbeat.sh report` and read its `state=`, `ts=`, `ttl=`, `pid=`, `cli=`, `session=` and `file=` fields. `state=fresh` is the expected result. Any other state right after a successful round means something rewrote or removed the file in between: report the state, the path and that the heartbeat did not survive its own write, and do not claim a started assistant. Completion condition: the report line was read and either `state=fresh` was recorded with its seven fields, or the mismatch was reported.
@@ -243,33 +243,35 @@ One round: read five sources, record the result, then beat. Everything before th
Put the whole page. An old-format page — per-round sections stacked up, no summary table — has no rows to carry over: keep its `本頁基本資料` block, drop the stacked sections, let the table start with this round's row, and say in the report that the page was converted. Only exit 4 from the read permits creating the page instead, and then the body is the whole content of `newpage_file`, which already carries all three blocks. Exit 7 and exit 8 mean the old content is unknown: create nothing, write nothing — rebuilding a page from an unknown original throws the summary table away. On any write failure — including exit 3 with no wiki repo configured for `MONITOR`, which the patrol cannot ask about — run `$JSC_HOME/current/jsc-assist/tools/patrol.sh abort --round {round}`, report the code, and stop. **No record, no heartbeat**, and that verdict belongs to this step alone: the round's result lives on this page, so a repo this step cannot resolve leaves the round with nowhere to be recorded. Step 4 is judged on its own terms. Completion condition: `link-check.sh` exited 0 over the body's links or the body carried none, the put or the create returned success, and the page holds exactly three blocks with the summary table at 24 rows or fewer and this round's row on top, or the abort ran and the round was reported as unrecorded with its exit code. Put the whole page. An old-format page — per-round sections stacked up, no summary table — has no rows to carry over: keep its `本頁基本資料` block, drop the stacked sections, let the table start with this round's row, and say in the report that the page was converted. Only exit 4 from the read permits creating the page instead, and then the body is the whole content of `newpage_file`, which already carries all three blocks. Exit 7 and exit 8 mean the old content is unknown: create nothing, write nothing — rebuilding a page from an unknown original throws the summary table away. On any write failure — including exit 3 with no wiki repo configured for `MONITOR`, which the patrol cannot ask about — run `$JSC_HOME/current/jsc-assist/tools/patrol.sh abort --round {round}`, report the code, and stop. **No record, no heartbeat**, and that verdict belongs to this step alone: the round's result lives on this page, so a repo this step cannot resolve leaves the round with nowhere to be recorded. Step 4 is judged on its own terms. Completion condition: `link-check.sh` exited 0 over the body's links or the body carried none, the put or the create returned success, and the page holds exactly three blocks with the summary table at 24 rows or fewer and this round's row on top, or the abort ran and the round was reported as unrecorded with its exit code.
4. **Update this machine's row in `MONITOR_CONTENTS`, through `jsc-gitea/tools/wiki-contents.sh`.** That page is a directory every machine writes to, and it lives in the repo `gitea.sh wiki-repo CONTENTS` resolves — `JSC_WIKI_REPO_CONTENTS`, then `JSC_WIKI_REPO`, then exit 3, and never a fallback to `JSC_WIKI_REPO_MONITOR`. The script owns the read-match-write of one row, so never read this page and rebuild it by hand, never write it through `jsc-gitea:wiki`, and never rebuild it the way step 3 rebuilds the content page — every other row here belongs to a machine that is not this one, and one careless whole-page write deletes their records. 4. **Update this machine's block in `MONITOR_CONTENTS`, through `jsc-gitea/tools/wiki-contents.sh`.** That page is a directory every machine writes to, and it lives in the repo `gitea.sh wiki-repo CONTENTS` resolves — `JSC_WIKI_REPO_CONTENTS`, then `JSC_WIKI_REPO`, then exit 3, and never a fallback to `JSC_WIKI_REPO_MONITOR`. The page carries no table: it is an H1, a `>` preamble, and then one H2 block per machine — the heading is that machine's monitor page name, and the fields are one `- {name}:{value}` bullet each underneath. The script owns the read-match-write of one block, so never read this page and rebuild it by hand, never write it through `jsc-gitea:wiki`, and never rebuild it the way step 3 rebuilds the content page — every other block here belongs to a machine that is not this one, and one careless whole-page write deletes their records.
**Finish the row first.** The `row=` line in `contents_file` already carries the rule A shape `[{page name}]({URL})` in its first cell, with the placeholder `{監控頁絕對網址}` standing in for the URL, because the absolute URL cannot be known until step 3 has actually put the page. Run `$JSC_HOME/current/jsc-gitea/tools/gitea.sh wiki-url {the MONITOR repo step 3 resolved} MONITOR_{HASH}`, replace the placeholder with what it prints, and write the finished row to a file. Exit 4 there means step 3's write has not landed — go back to step 3 rather than writing a row. Exit 5 means the page carries no `html_url`: report it and never assemble a URL by hand. Exit 7 or 8: report the code and take the abort row below. **Any other non-zero exit takes the same abort row**, a missing argument included — a URL that never arrived would otherwise leave the link cell holding the raw placeholder, and the row would still be written. **Finish the block first.** `contents_file` holds this machine's whole block — `## MONITOR_{HASH}`, a blank line, then the bullets — and its 監控頁 bullet already carries the rule A shape `[{page name}]({URL})` with the placeholder `{監控頁絕對網址}` standing in for the URL, because the absolute URL cannot be known until step 3 has actually put the page. Run `$JSC_HOME/current/jsc-gitea/tools/gitea.sh wiki-url {the MONITOR repo step 3 resolved} MONITOR_{HASH}`, replace the placeholder with what it prints, and write the finished block to a file. Exit 4 there means step 3's write has not landed — go back to step 3 rather than writing a block. Exit 5 means the page carries no `html_url`: report it and never assemble a URL by hand. Exit 7 or 8: report the code and take the abort row below. **Any other non-zero exit takes the same abort row**, a missing argument included — a URL that never arrived would otherwise leave that bullet holding the raw placeholder, and the block would still be written.
**Then verify that URL before the row goes anywhere.** Run `$JSC_HOME/current/jsc-gitea/tools/link-check.sh {the URL just substituted}` and read the exit code by the rule B table above. Exit 0 is the only result that permits the upsert. On exit 1 the directory would gain a row pointing at a page that is not there: report the `DEAD` line verbatim, write no row, and treat the directory row as not updated — the round's own result is already on `MONITOR_{HASH}`, so carry on to step 5 and write the heartbeat, exactly as exit 3 from the upsert does, and put the dead link into the 待人處理 rows. Exits 2, 3 and 7 are reported the same way and the row is left unwritten. Never write the row first and check afterwards: the directory is what other people read to find this machine, and a dead row there sends every one of them to a page that does not exist. **Then verify that URL before the block goes anywhere.** Run `$JSC_HOME/current/jsc-gitea/tools/link-check.sh {the URL just substituted}` and read the exit code by the rule B table above. Exit 0 is the only result that permits the upsert. On exit 1 the directory would gain a block pointing at a page that is not there: report the `DEAD` line verbatim, write no block, and treat the directory entry as not updated — the round's own result is already on `MONITOR_{HASH}`, so carry on to step 5 and write the heartbeat, exactly as exit 3 from the upsert does, and put the dead link into the 待人處理 rows. Exits 2, 3 and 7 are reported the same way and the block is left unwritten. Never write the block first and check afterwards: the directory is what other people read to find this machine, and a dead link there sends every one of them to a page that does not exist.
Then run, with the template as the fifth argument every time: Then run, with the template as the fifth argument every time:
`$JSC_HOME/current/jsc-gitea/tools/wiki-contents.sh upsert MONITOR 2 "{HASH}" {row file} $JSC_HOME/current/jsc-assist/templates/monitor-contents.md` `$JSC_HOME/current/jsc-gitea/tools/wiki-contents.sh upsert MONITOR 1 "MONITOR_{HASH}" {block file} $JSC_HOME/current/jsc-assist/templates/monitor-contents.md`
**The key is column 2, the bare `HASH` cell** — the 40-character string `collect` printed as `hash=`, copied verbatim, with no link, no brackets and no URL around it. The script compares the whole cell text, so column 1 cannot be the key: that cell holds `GITEA_HOST` and the wiki's encoding of the page name, so a changed host, a `JSC_WIKI_REPO_MONITOR` pointed at another repo, or a different URL encoding changes the text and stops it matching. This page is written once every round, so from that moment on every round appends one more row for this same machine and the old row is never updated again. The bare `HASH` depends on `{host}/{user}` alone, which none of those three touch. Column 1's link stays in the row for people to click, and never for matching. A key typed by hand matches nothing either, and appends the same duplicate row. **The key is the H2 heading — the page name `MONITOR_{HASH}`**, taken from `collect`'s `page=` line verbatim, with no link, no brackets and no URL around it. The script compares the heading text, so the 監控頁 bullet cannot be the key: it holds `GITEA_HOST` and the wiki's encoding of the page name, so a changed host, a `JSC_WIKI_REPO_MONITOR` pointed at another repo, or a different URL encoding changes that text and stops it matching. This page is written once every round, so from the moment matching breaks every round appends one more block for this same machine and the old block is never updated again. The page name depends on `{host}/{user}` alone, which none of those three touch. That bullet's link stays in the block for people to click, and never for matching. A key typed by hand matches nothing either, and appends the same duplicate block.
**The `1` is the third argument, `key-col`, and it only matters while an old page is still a table.** A directory page written in the previous format holds a markdown table, and the script converts the whole page to blocks before it upserts; `key-col` tells it which column of that table held the identity, counting from 1. Column 1 of this page's old table was the monitor-page link, whose cell is `[MONITOR_{HASH}]({URL})`, and the conversion takes the text out of it as the H2 heading. Once the page is in the block format the argument is ignored — pass `1` regardless, and never a column number worked out from the current page.
| Exit | Do | | Exit | Do |
| --- | --- | | --- | --- |
| 0 | The row is in place. The script prints `updated` or `added` plus the page it wrote — carry that word into the report, and carry on to step 5 | | 0 | The block is in place. The script prints `updated` or `added` plus the page it wrote — carry that word into the report, and carry on to step 5 |
| 1 | The write failed, or the directory page holds no markdown table. Run `$JSC_HOME/current/jsc-assist/tools/patrol.sh abort --round {round}`, report the code, and stop | | 1 | The page content could not be built, or the write failed. Run `$JSC_HOME/current/jsc-assist/tools/patrol.sh abort --round {round}`, report the code, and stop. A page with no matching block is not this code: an unmatched key is an append |
| 2 | An argument was rejected and nothing was written. A template path that does not exist lands here too, and means the plugin installation is incomplete. Correct the call and run it once more; report a second exit 2 as a defect in this skill, then abort and stop | | 2 | An argument was rejected and nothing was written. A template path that does not exist lands here too, and means the plugin installation is incomplete. Correct the call and run it once more; report a second exit 2 as a defect in this skill, then abort and stop |
| 3 | No `CONTENTS` wiki repo is configured. **This one does not stop the round.** Carry on to step 5 and write the heartbeat: the round's result is already on `MONITOR_{HASH}`, and that is exactly what a heartbeat stands for. Report the directory row as not updated, name `JSC_WIKI_REPO_CONTENTS` and `JSC_WIKI_REPO` as the two variables to set, and add that to the 待人處理 rows. Never abort a recorded round over the directory page — a missing directory row loses one index line, an aborted round loses the whole round, and the patrol cannot ask anybody for the missing setting | | 3 | No `CONTENTS` wiki repo is configured. **This one does not stop the round.** Carry on to step 5 and write the heartbeat: the round's result is already on `MONITOR_{HASH}`, and that is exactly what a heartbeat stands for. Report the directory entry as not updated, name `JSC_WIKI_REPO_CONTENTS` and `JSC_WIKI_REPO` as the two variables to set, and add that to the 待人處理 rows. Never abort a recorded round over the directory page — a missing directory block loses one index entry, an aborted round loses the whole round, and the patrol cannot ask anybody for the missing setting |
| 4 | The page is absent and no template reached the script. The call above always passes the template as its fifth argument, so this code cannot come out of it — getting it means that argument was dropped, so restore it and run the call once more. A template path that does not exist is rejected as exit 2, never as 4 | | 4 | The page is absent and no template reached the script. The call above always passes the template as its fifth argument, so this code cannot come out of it — getting it means that argument was dropped, so restore it and run the call once more. A template path that does not exist is rejected as exit 2, never as 4 |
| 7 | The token is invalid or lacks permission, so the other machines' rows are unknown. The script wrote nothing, which is what keeps those rows alive. Abort, report the key problem, and stop | | 7 | The token is invalid or lacks permission, so the other machines' blocks are unknown. The script wrote nothing, which is what keeps those blocks alive. Abort, report the key problem, and stop |
| 8 | Some other API failure. Abort, report the status, and stop | | 8 | Some other API failure. Abort, report the status, and stop |
Completion condition: `link-check.sh` exited 0 over the row's URL and the script exited 0 with exactly one row carrying this machine's bare `HASH` in column 2 with this round's values, or exit 3 from the upsert or a non-zero `link-check.sh` was reported as an unwritten directory row and the round carried on, or one of the other non-zero codes — `wiki-url`'s included — was reported after the abort ran. Completion condition: `link-check.sh` exited 0 over the block's URL and the script exited 0 with exactly one `## MONITOR_{HASH}` block on the page carrying this round's values, or exit 3 from the upsert or a non-zero `link-check.sh` was reported as an unwritten directory entry and the round carried on, or one of the other non-zero codes — `wiki-url`'s included — was reported after the abort ran.
5. **Write the heartbeat.** Run `$JSC_HOME/current/jsc-assist/tools/patrol.sh finish --round {round}`. This is the last step for a reason: it is the only thing that turns a fresh heartbeat into a true statement. Judge the exit code by the patrol.sh table — 2, 4 and 5 all mean the round is recorded but unproven, and each has its own report line there. Completion condition: `finish` exited 0, or the failure was reported as "recorded but no heartbeat" with its code. 5. **Write the heartbeat.** Run `$JSC_HOME/current/jsc-assist/tools/patrol.sh finish --round {round}`. This is the last step for a reason: it is the only thing that turns a fresh heartbeat into a true statement. Judge the exit code by the patrol.sh table — 2, 4 and 5 all mean the round is recorded but unproven, and each has its own report line there. Completion condition: `finish` exited 0, or the failure was reported as "recorded but no heartbeat" with its code.
6. **Report the round.** Print the round verdict and, when it is `警示`, the `warn_sources=` text that says why — a round can read all five sources and still come out `警示`, and that column is the only place the reason appears; then one line per item with its `status=` and, for a failure, its `note=`; the monitor page name, the link-check verdict for each of the two writes — passed, skipped for a body with no link, or refused with its exit code and its `DEAD` lines — and the directory row as `updated`, `added`, or not written with the exit code and the reason; whether the heartbeat was written; and, when `lock_broken=1`, that the previous round's lock was taken over because it had aged past the TTL. 6. **Report the round.** Print the round verdict and, when it is `警示`, the `warn_sources=` text that says why — a round can read all five sources and still come out `警示`, and that column is the only place the reason appears; then one line per item with its `status=` and, for a failure, its `note=`; the monitor page name, the link-check verdict for each of the two writes — passed, skipped for a body with no link, or refused with its exit code and its `DEAD` lines — and the directory entry as `updated`, `added`, or not written with the exit code and the reason; whether the heartbeat was written; and, when `lock_broken=1`, that the previous round's lock was taken over because it had aged past the TTL.
**The event numbers get their own line, and the unpaired starts get their own list.** Print `events_total=` and `events_bad=` as this round's event count and its non-`ok` count, then every non-`ok` event with its `kind`, `name`, `status`, `exit` and `detail`, then — separately, never folded into the same list — every start with no matching end, by `name` and `session`. A non-zero `events_unpaired=` is the round's most important finding: each row is a skill run that started and never reached its closing step. Say `events_rotated=` too when it is `rotated` or `failed`. When `item=D-11` failed, say the source could not be read rather than reporting zero events — zero read events and zero existing events look identical in a report and mean opposite things. **The event numbers get their own line, and the unpaired starts get their own list.** Print `events_total=` and `events_bad=` as this round's event count and its non-`ok` count, then every non-`ok` event with its `kind`, `name`, `status`, `exit` and `detail`, then — separately, never folded into the same list — every start with no matching end, by `name` and `session`. A non-zero `events_unpaired=` is the round's most important finding: each row is a skill run that started and never reached its closing step. Say `events_rotated=` too when it is `rotated` or `failed`. When `item=D-11` failed, say the source could not be read rather than reporting zero events — zero read events and zero existing events look identical in a report and mean opposite things.
+66 -58
View File
@@ -1,68 +1,76 @@
# 助理巡檢目錄 # 助理巡檢目錄
> 由 `jsc-assist` 維護。這是目錄頁 `MONITOR_CONTENTS`,落在 `JSC_WIKI_REPO_CONTENTS` 解出的專用存取庫,和監控頁不同庫。 > 由 `jsc-assist` 維護。這是目錄頁 `MONITOR_CONTENTS`,落在 `JSC_WIKI_REPO_CONTENTS` 解出的專用存取庫,和監控頁不同庫。
> 一列代表一台機器。雜湊來源是 `{主機名}/{登入帳號}`,主機名取短的那一段,所以一台機器一列、一頁,換一支 CLI 不另開列。 > 一個區塊代表一台機器。雜湊來源是 `{主機名}/{登入帳號}`,主機名取短的那一段,所以一台機器一個區塊、一頁,換一支 CLI 不另開區塊。
> `MONITOR_{HASH}` 的 `{HASH}` 執行 `jsc-gitea/tools/hash-id {主機名}/{登入帳號}` 取得,原樣採用它印出的完整 40 碼大寫十六進位,不截短、不加前綴(共用 wiki hash 規則,演算法見 `jsc-meta` 的 `references/guidelines.md`)。 > `MONITOR_{HASH}` 的 `{HASH}` 執行 `jsc-gitea/tools/hash-id {主機名}/{登入帳號}` 取得,原樣採用它印出的完整 40 碼大寫十六進位,不截短、不加前綴(共用 wiki hash 規則,演算法見 `jsc-meta` 的 `references/guidelines.md`)。
> >
> 版面固定三段:H1 頁名、這一段引言,然後每一台機器一個 H2 區塊。H2 標題就是那一台機器的內容頁頁名 `MONITOR_{HASH}`,標題不放連結、不放網址、不加前後綴、不加日期。欄位一行一條,格式 `- {欄位名}:{值}`,順序照這段引言的「欄位說明」從上到下。H2 與第一條之間空一行,區塊之間空一行。這一頁不放 markdown 表格。
>
> 連結寫法:一律寫成 `[{文字}]({絕對網址})`,網址取 `jsc-gitea/tools/gitea.sh wiki-url` 印出的那一個,不自己組路徑。wiki 自己那種雙中括號寫法只在同一個 wiki 裡解得開,寫錯不會報錯,畫面上看起來像正常文字或死連結。 > 連結寫法:一律寫成 `[{文字}]({絕對網址})`,網址取 `jsc-gitea/tools/gitea.sh wiki-url` 印出的那一個,不自己組路徑。wiki 自己那種雙中括號寫法只在同一個 wiki 裡解得開,寫錯不會報錯,畫面上看起來像正常文字或死連結。
> >
> 寫入前驗證:這一列要放進去的連結,先交給 `jsc-gitea/tools/link-check.sh`,結束碼 0 才寫。有 DEAD 就不寫這一列,把連不到的那幾筆回報出去。驗證走 API,不看網頁狀態碼——私有存取庫的網頁網址對未登入請求一律回 404,拿狀態碼判會把還在的頁判成死連結。 > 寫入前驗證:這一個區塊要放進去的連結,先交給 `jsc-gitea/tools/link-check.sh`,結束碼 0 才寫。有 DEAD 就不寫這一個區塊,把連不到的那幾筆回報出去。驗證走 API,不看網頁狀態碼——私有存取庫的網頁網址對未登入請求一律回 404,拿狀態碼判會把還在的頁判成死連結。
> >
> 比對鍵:第 2 欄的裸 HASH,純文字,不帶連結、不帶網址。連結那一欄是給人看的,不當鍵。 > 比對鍵:H2 標題,也就是內容頁頁名 `MONITOR_{HASH}`,純文字,不帶連結、不帶網址。「監控頁」那一條的連結是給人點的,不當鍵。
>
> 欄位說明:條列的順序就是下面這幾條從上到下的順序,一條都不能少。鍵在 H2 標題出現過,「監控頁」與「HASH」照樣各留一條,資料才不會少。
>
> - **監控頁**:指向 `MONITOR_{HASH}` 的連結,寫成 `[{頁名}]({絕對網址})`,給人點的,不當比對鍵。少了它就要人自己算雜湊才翻得到內容頁;絕對網址在哪一個存取庫都連得過去,寫入前也驗得起來。
> - **HASH**:`hash-id` 印出的完整 40 碼大寫十六進位,純文字,不加連結、不加網址。這一條只跟 `{主機名}/{登入帳號}` 有關,換主機位址、換存取庫、換一種網址編碼都不會變。H2 標題就是 `MONITOR_` 接上這一串,所以這一條也是標題的來源。
> - **主機**:這台機器的短主機名,與雜湊第一段相同。一眼看出這一個區塊是哪一台機器。
> - **帳號**:助理執行時的登入帳號,與雜湊第二段相同。同一台機器換帳號就是另一個巡檢對象,雜湊也會不同。
> - **心跳**:巡檢當下(本輪寫入前)的心跳判定,判準只看 `ts` 距現在有沒有超過門檻,預設 300 秒。一眼看出這台機器上一輪巡檢有沒有跑完,不必逐頁翻。
> - **最後巡檢**:該頁最新一輪的時間戳。心跳由巡檢寫,兩條理當一致;差很多就代表有一輪寫了心跳卻沒寫頁,那是缺陷。
> - **待辦筆數**:待辦簿現有筆數。心跳新鮮而筆數為 0,代表助理空轉,沒有東西可跑。
> - **連續失敗項**:待辦簿裡 `fail_count` 大於 0 的筆數。待辦簿的項目失敗不會自動暫停,每輪都重試,這一條讓壞掉的項目在目錄頁就現形。
>
> 為什麼沒有「本輪非 ok 事件數」這一條:執行狀態事件的筆數只放在監控頁的「執行狀態事件」那一節,這一頁不加條。兩個理由:
>
> - **同一頁上會出現兩種欄位組合。** 每一個區塊由那一台機器自己那一輪寫,別台機器的區塊要到它下一輪才會重寫。新加一條,只有跑到新版的機器寫得出來,其餘機器的區塊還是舊的那幾條,而讀的人分不出「這台機器本輪沒有非 ok 事件」與「這台機器的版本還沒寫這一條」。目錄頁也沒有整頁改寫的路可以走:整頁覆蓋等於刪掉別台機器的紀錄。
> - **這個數字離開監控頁就會被讀錯。** 它算的是「上一次排空之後到這一輪之間」的事件,視窗長度隨巡檢週期與上一輪的成敗變動。放在監控頁上,同一節裡就有事件總數、未配對的 `start` 與明細表可以對照;抽一個數字放到目錄頁,0 會被讀成「這台機器很健康」,但它同樣可能只是那一段時間沒有任何技能跑過。
>
> 要判斷一台機器有沒有問題,這一頁上的「心跳」與「最後巡檢」就夠帶人往下翻;細節一律回監控頁看。
>
> 寫入規則:這一頁是共用目錄,別台機器的區塊一律原樣保留。寫入一律用 `jsc-gitea/tools/wiki-contents.sh upsert`,不手工改頁。
>
> ```mermaid
> flowchart TD
> A[監控頁已經寫成] --> B[gitea.sh wiki-url 取監控頁絕對網址]
> B --> C[組出本機那一個區塊,網址換掉佔位]
> C --> V{link-check.sh 驗這一個區塊的連結}
> V -- 結束碼 0 --> D[wiki-contents.sh upsert MONITOR,H2 標題 MONITOR_HASH 當鍵]
> V -- 有 DEAD 或其他非 0 --> W[不寫這一個區塊,回報連不到的那幾筆]
> D --> E{舊頁讀得回來}
> E -- 是 --> F{找得到同名的 H2 標題}
> F -- 是 --> G[整塊換掉那一個區塊]
> F -- 否 --> H[附加一個區塊到頁尾]
> E -- 頁不存在 --> I[用範本建頁,再附加一個區塊]
> E -- 金鑰失效或 API 失敗 --> J[中止:不建頁、不寫入]
> G --> K[整頁寫回,別台機器的區塊原樣送回]
> H --> K
> I --> K
> ```
>
> - 連結一律 `[{文字}]({絕對網址})`,網址取 `gitea.sh wiki-url`。這一個區塊要放進去的每一個連結,寫入前先過 `link-check.sh`,結束碼 0 才寫;結束碼 1 就不寫這一個區塊,把 DEAD 那幾筆回報出去。結束碼 3 是 `GITEA_HOST` 沒設定,補設定再驗,不准跳過驗證;結束碼 7 是金鑰失效,停下來回報金鑰問題,不要當成死連結——金鑰過期時私有存取庫的回應和「頁不存在」分不出來,混為一談會把還在的頁整批判死。
> - 存取庫走 `gitea.sh wiki-repo CONTENTS`:先 `JSC_WIKI_REPO_CONTENTS`,再 `JSC_WIKI_REPO`,都沒設就結束碼 3,不退回監控頁那一支變數。
> - `upsert` 的位置參數是 `MONITOR`、`{key-col}`、`{key}`、`{區塊檔}`、`{範本}`:
> - `{key-col}` 只在舊頁還是 markdown 表格時才用得到,指舊表格中持有身分的那一欄序號(1 起算)。本頁的舊表格是第 1 欄「監控頁」,那一格是 `[MONITOR_{HASH}](網址)`,轉檔時只取文字當 H2 標題。頁面已經是條列格式時這個參數完全用不到。
> - `{key}` 是這一個區塊的 H2 標題文字,也就是內容頁頁名 `MONITOR_{HASH}`。用來找既有的區塊。
> - `{區塊檔}` 是整個 H2 區塊的 markdown:`## MONITOR_{HASH}` 那一行、空行,然後各條 `- {欄位名}:{值}`。
> - 比對鍵是 H2 標題,原樣比對標題文字(去頭尾空白後完全相等)。鍵取 `collect` 印的 `page=`,自己重打會對不上,結果是同一台機器多出第二個區塊。
> - 「監控頁」那一條的連結不當鍵:那一條含 `GITEA_HOST` 與頁名的網址編碼,主機位址改掉、`JSC_WIKI_REPO_MONITOR` 換了存取庫、或 Gitea 的網址編碼有差,整條文字就變了,鍵跟著對不上。這一頁每 15 分鐘寫一次,對不上的那一刻起每輪多附一個區塊,舊區塊再也不會更新。頁名只由 `{主機名}/{登入帳號}` 決定,那三件事都動不到它。
> - 找得到相同的 H2 標題就換掉那一個區塊,找不到才附加一個區塊。
> - 只動自己那一個區塊,別台機器的區塊一個字都不改。禁止整頁覆蓋——整頁覆蓋等於刪掉別台機器的紀錄。
> - 只有「頁不存在」才准用範本建頁。金鑰失效或 API 失敗一律中止:那兩種情況舊內容是未知的,拿範本蓋上去就是把活著的紀錄整份刪掉。
> - 舊頁還是 markdown 表格時,`upsert` 自己先把整頁轉成 H2 區塊再做這一次寫入,資料列的順序原樣保留。這一頁不再留任何 markdown 表格。
> - 內容頁 `MONITOR_{HASH}` 的寫入語意不同:那頁固定三塊,最新一輪整塊換掉,摘要表一輪一列、最新的在最上面、超過 24 列丟最舊的。內容頁維持表格,兩者不要混用。
| 監控頁 | HASH | 主機 | 帳號 | 心跳 | 最後巡檢 | 待辦筆數 | 連續失敗項 | ## MONITOR_{HASH}
| --- | --- | --- | --- | --- | --- | ---: | ---: |
| [MONITOR_{HASH}]({wiki-url 印出的絕對網址}) | {HASH} | {主機名} | {登入帳號} | {新鮮、過期、不存在 三選一} | {yyyy-MM-dd HH:mm} | {n} | {n} |
## 欄位說明 - 監控頁:[MONITOR_{HASH}]({wiki-url 印出的絕對網址})
- HASH:{HASH}
| 欄位 | 內容 | 為什麼留這一欄 | - 主機:{主機名}
| --- | --- | --- | - 帳號:{登入帳號}
| 監控頁 | 指向 `MONITOR_{HASH}` 的連結,寫成 `[{頁名}]({絕對網址})`,給人點的,不當比對鍵 | 少了連結就要人自己算雜湊才翻得到內容頁;絕對網址在哪一個存取庫都連得過去,寫入前也驗得起來 | - 心跳:{新鮮、過期、不存在 三選一}
| HASH | `hash-id` 印出的完整 40 碼大寫十六進位,純文字,不加連結、不加網址,也是 upsert 的比對鍵 | 這一格只跟 `{主機名}/{登入帳號}` 有關,換主機位址、換存取庫、換一種網址編碼都不會變。拿含網址的連結當鍵才會對不上,然後同一台機器每輪多附一列 | - 最後巡檢:{yyyy-MM-dd HH:mm}
| 主機 | 這台機器的短主機名,與雜湊第一段相同 | 一眼看出這一列是哪一台機器 | - 待辦筆數:{n}
| 帳號 | 助理執行時的登入帳號,與雜湊第二段相同 | 同一台機器換帳號就是另一個巡檢對象,雜湊也會不同 | - 連續失敗項:{n}
| 心跳 | 巡檢當下(本輪寫入前)的心跳判定,判準只看 `ts` 距現在有沒有超過門檻,預設 300 秒 | 一眼看出這台機器上一輪巡檢有沒有跑完,不必逐頁翻 |
| 最後巡檢 | 該頁最新一輪的時間戳 | 心跳由巡檢寫,兩欄理當一致;差很多就代表有一輪寫了心跳卻沒寫頁,那是缺陷 |
| 待辦筆數 | 待辦簿現有筆數 | 心跳新鮮而筆數為 0,代表助理空轉,沒有東西可跑 |
| 連續失敗項 | 待辦簿裡 `fail_count` 大於 0 的筆數 | 待辦簿的項目失敗不會自動暫停,每輪都重試。這一欄讓壞掉的項目在目錄頁就現形 |
### 為什麼沒有「本輪非 ok 事件數」這一欄
執行狀態事件的筆數只放在監控頁的「執行狀態事件」那一節,這一頁不加欄。兩個理由:
- **這一頁的欄不是自己一台機器說了算。** 每一列是一台機器,欄位卻是共用的:表頭跟著建頁的那一台走,之後每一台只更新自己那一列。新加一欄,只有跑到新版的機器會寫出多一格的列,其餘機器的列還是舊的格數,表頭也還是舊的——同一張表混著兩種格數,多出來的那一格對不到任何欄名。目錄頁沒有整頁改寫的路可以走:整頁覆蓋等於刪掉別台機器的紀錄。
- **這個數字離開監控頁就會被讀錯。** 它算的是「上一次排空之後到這一輪之間」的事件,視窗長度隨巡檢週期與上一輪的成敗變動。放在監控頁上,同一節裡就有事件總數、未配對的 `start` 與明細表可以對照;抽一個數字放到目錄頁,0 會被讀成「這台機器很健康」,但它同樣可能只是那一段時間沒有任何技能跑過。
要判斷一台機器有沒有問題,這一頁上的「心跳」與「最後巡檢」就夠帶人往下翻;細節一律回監控頁看。
## 寫入規則
這一頁是共用目錄,別台機器的列一律原樣保留。寫入一律用 `jsc-gitea/tools/wiki-contents.sh upsert`,不手工改頁。
```mermaid
flowchart TD
A[監控頁已經寫成] --> B[gitea.sh wiki-url 取監控頁絕對網址]
B --> C[組出本機那一列,網址換掉佔位]
C --> V{link-check.sh 驗這一列的連結}
V -- 結束碼 0 --> D[wiki-contents.sh upsert MONITOR 第 2 欄的裸 HASH 當鍵]
V -- 有 DEAD 或其他非 0 --> W[不寫這一列,回報連不到的那幾筆]
D --> E{舊頁讀得回來}
E -- 是 --> F{HASH 欄對得上}
F -- 是 --> G[取代那一列]
F -- 否 --> H[附加一列]
E -- 頁不存在 --> I[用範本建頁,再附加一列]
E -- 金鑰失效或 API 失敗 --> J[中止:不建頁、不寫入]
G --> K[整頁寫回,別台機器的列原樣送回]
H --> K
I --> K
```
- 連結一律 `[{文字}]({絕對網址})`,網址取 `gitea.sh wiki-url`。這一列要放進去的每一個連結,寫入前先過 `link-check.sh`,結束碼 0 才寫;結束碼 1 就不寫這一列,把 DEAD 那幾筆回報出去。結束碼 3 是 `GITEA_HOST` 沒設定,補設定再驗,不准跳過驗證;結束碼 7 是金鑰失效,停下來回報金鑰問題,不要當成死連結——金鑰過期時私有存取庫的回應和「頁不存在」分不出來,混為一談會把還在的頁整批判死。
- 存取庫走 `gitea.sh wiki-repo CONTENTS`:先 `JSC_WIKI_REPO_CONTENTS`,再 `JSC_WIKI_REPO`,都沒設就結束碼 3,不退回監控頁那一支變數。
- 比對鍵是第 2 欄的裸 HASH,原樣比對整格文字。鍵取 `collect` 印的 `hash=`,自己重打會對不上,結果是同一台機器多出第二列。
- 第一欄的連結不當鍵:那一格含 `GITEA_HOST` 與頁名的網址編碼,主機位址改掉、`JSC_WIKI_REPO_MONITOR` 換了存取庫、或 Gitea 的網址編碼有差,整格文字就變了,鍵跟著對不上。這一頁每 15 分鐘寫一次,對不上的那一刻起每輪多附一列,舊列再也不會更新。
- 找得到相同的 HASH 就更新那一列,找不到才附加一列。
- 只動自己那一列,別台機器的列一個字都不改。禁止整頁覆蓋——整頁覆蓋等於刪掉別台機器的紀錄。
- 只有「頁不存在」才准用範本建頁。金鑰失效或 API 失敗一律中止:那兩種情況舊內容是未知的,拿範本蓋上去就是把活著的紀錄整份刪掉。
- 內容頁 `MONITOR_{HASH}` 的寫入語意不同:那頁固定三塊,最新一輪整塊換掉,摘要表一輪一列、最新的在最上面、超過 24 列丟最舊的。兩者不要混用。
+4 -4
View File
@@ -4,7 +4,7 @@
> 這頁固定三塊:本頁基本資料、最新一輪、近 24 輪摘要。 > 這頁固定三塊:本頁基本資料、最新一輪、近 24 輪摘要。
> 最新一輪每輪整塊換掉;摘要表一輪一列往上疊,只留 24 列;基本資料建頁時寫一次就不動。 > 最新一輪每輪整塊換掉;摘要表一輪一列往上疊,只留 24 列;基本資料建頁時寫一次就不動。
> 完整內容只留最新一輪,頁面才讀得完;軌跡留在摘要表,看得出是從哪一輪開始壞的。 > 完整內容只留最新一輪,頁面才讀得完;軌跡留在摘要表,看得出是從哪一輪開始壞的。
> 目錄頁 `MONITOR_CONTENTS` 在 `JSC_WIKI_REPO_CONTENTS` 解出的專用存取庫,和這頁不同庫;那一頁只更新自己那一列,別台機器的列一個字都不動。 > 目錄頁 `MONITOR_CONTENTS` 在 `JSC_WIKI_REPO_CONTENTS` 解出的專用存取庫,和這頁不同庫;那一頁一台機器一個 H2 區塊,只更新自己那一個區塊,別台機器的區塊一個字都不動。
```mermaid ```mermaid
flowchart LR flowchart LR
@@ -14,7 +14,7 @@ flowchart LR
D --> E[本輪摘要列插到表格最上面,截到 24 列] D --> E[本輪摘要列插到表格最上面,截到 24 列]
E --> V[link-check.sh 驗這一頁要放的連結] E --> V[link-check.sh 驗這一頁要放的連結]
V --> F[結束碼 0 才整頁寫回] V --> F[結束碼 0 才整頁寫回]
F --> G[wiki-contents.sh upsert 更新目錄頁自己那一列] F --> G[wiki-contents.sh upsert 更新目錄頁自己那一個區塊]
G --> H[最後才寫心跳] G --> H[最後才寫心跳]
``` ```
@@ -174,7 +174,7 @@ flowchart LR
- 舊格式的頁(一輪一節疊起來的那種)第一次重組時,基本資料留著,那些節收掉,摘要表從本輪這一列開始,並在回報裡說明。 - 舊格式的頁(一輪一節疊起來的那種)第一次重組時,基本資料留著,那些節收掉,摘要表從本輪這一列開始,並在回報裡說明。
- 連結一律寫成 `[{文字}]({絕對網址})`,網址取 `jsc-gitea/tools/gitea.sh wiki-url` 印出的那一個,不自己組路徑。wiki 自己那種雙中括號寫法只在同一個 wiki 裡解得開,寫錯不會報錯,畫面上看不出壞掉。 - 連結一律寫成 `[{文字}]({絕對網址})`,網址取 `jsc-gitea/tools/gitea.sh wiki-url` 印出的那一個,不自己組路徑。wiki 自己那種雙中括號寫法只在同一個 wiki 裡解得開,寫錯不會報錯,畫面上看不出壞掉。
- 這一頁要放進去的每一個連結,寫入前先交給 `jsc-gitea/tools/link-check.sh`,結束碼 0 才整頁寫回。有 DEAD 就不寫,把連不到的那幾筆回報給呼叫端;結束碼 3 是 `GITEA_HOST` 沒設定,補設定再驗,不准跳過;結束碼 7 是金鑰失效,停下來回報金鑰問題,不要當成死連結。驗證一律走 API,不看網頁狀態碼——私有存取庫的網頁網址對未登入請求一律回 404。 - 這一頁要放進去的每一個連結,寫入前先交給 `jsc-gitea/tools/link-check.sh`,結束碼 0 才整頁寫回。有 DEAD 就不寫,把連不到的那幾筆回報給呼叫端;結束碼 3 是 `GITEA_HOST` 沒設定,補設定再驗,不准跳過;結束碼 7 是金鑰失效,停下來回報金鑰問題,不要當成死連結。驗證一律走 API,不看網頁狀態碼——私有存取庫的網頁網址對未登入請求一律回 404。
- 整頁寫成之後,才回頭更新目錄頁自己那一列,寫入交給 `jsc-gitea/tools/wiki-contents.sh upsert`,別台機器的列一個字都不動。目錄頁那一欄的連結同樣先驗過才寫。 - 整頁寫成之後,才回頭更新目錄頁自己那一個區塊,寫入交給 `jsc-gitea/tools/wiki-contents.sh upsert`,別台機器的區塊一個字都不動。目錄頁那一個區塊的連結同樣先驗過才寫。
- 這一頁沒寫成就不寫心跳,讓它過期。心跳代表的是「這一輪的結果記在這一頁上了」。 - 這一頁沒寫成就不寫心跳,讓它過期。心跳代表的是「這一輪的結果記在這一頁上了」。
- 目錄頁只是索引。目錄頁的存取庫沒設定(結束碼 3)時照樣寫心跳,並把那一筆列進待人處理;其餘寫入失敗才不寫心跳。 - 目錄頁只是索引。目錄頁的存取庫沒設定(結束碼 3)時照樣寫心跳,並把那一筆列進待人處理;其餘寫入失敗才不寫心跳。目錄頁少一個區塊只少一筆索引,這一輪的結果已經在這一頁上。
- 執行狀態事件那一節的內容由 `tools/patrol.sh collect` 排空、彙整好,寫頁的人原樣採用,不自己再跑一次 `drain`。`drain` 是消耗性讀取:它一讀完就把位移往前推,同一批事件不會再出現第二次,第二次跑只會拿到 3,或者把下一輪的事件提前吃掉。 - 執行狀態事件那一節的內容由 `tools/patrol.sh collect` 排空、彙整好,寫頁的人原樣採用,不自己再跑一次 `drain`。`drain` 是消耗性讀取:它一讀完就把位移往前推,同一批事件不會再出現第二次,第二次跑只會拿到 3,或者把下一輪的事件提前吃掉。
+39 -35
View File
@@ -84,24 +84,25 @@
# gitea.sh wiki-url 印的那一個,不自己組路徑;wiki 自己那種雙中括號寫法只在同一個 wiki 裡 # gitea.sh wiki-url 印的那一個,不自己組路徑;wiki 自己那種雙中括號寫法只在同一個 wiki 裡
# 解得開,寫錯不會報錯,畫面上看起來像正常文字或死連結,巡不到也修不了。 # 解得開,寫錯不會報錯,畫面上看起來像正常文字或死連結,巡不到也修不了。
# 絕對網址要等內容頁真的寫進去才查得到(gitea.sh wiki-url 讀的是 API 回的 html_url), # 絕對網址要等內容頁真的寫進去才查得到(gitea.sh wiki-url 讀的是 API 回的 html_url),
# 而 collect 跑在寫入之前,這裡查不到。所以這支只把列組好、網址留佔位,換字交給呼叫端。 # 而 collect 跑在寫入之前,這裡查不到。所以這支只把區塊組好、網址留佔位,換字交給呼叫端。
# #
# --- 連結先驗證連得到,才可以寫進頁面 --- # --- 連結先驗證連得到,才可以寫進頁面 ---
# #
# 這支腳本一頁都不寫:它只組出檔案,兩次 wiki 寫入都在呼叫端。所以驗證的時機也在呼叫端—— # 這支腳本一頁都不寫:它只組出檔案,兩次 wiki 寫入都在呼叫端。所以驗證的時機也在呼叫端——
# 換掉佔位、拿到真網址之後,寫入之前,把要放進頁面的每一個連結交給 jsc-gitea 的 # 換掉佔位、拿到真網址之後,寫入之前,把要放進頁面的每一個連結交給 jsc-gitea 的
# tools/link-check.sh,結束碼 0 才寫。有 DEAD 就不寫那一頁或那一列,把連不到的清單回報出去。 # tools/link-check.sh,結束碼 0 才寫。有 DEAD 就不寫那一頁或那一個區塊,把連不到的清單回報出去。
# 驗證一律走 API,不看網頁狀態碼:私有存取庫的網頁網址對未登入請求一律回 404,拿狀態碼判會 # 驗證一律走 API,不看網頁狀態碼:私有存取庫的網頁網址對未登入請求一律回 404,拿狀態碼判會
# 把好連結判成壞的。金鑰失效(結束碼 7)要與「連不到」(結束碼 1)分開看,兩者混用,一次金鑰 # 把好連結判成壞的。金鑰失效(結束碼 7)要與「連不到」(結束碼 1)分開看,兩者混用,一次金鑰
# 過期就會把整批還在的頁判成死連結。 # 過期就會把整批還在的頁判成死連結。
# #
# --- 目錄頁的比對鍵是裸 HASH,不是那個連結 --- # --- 目錄頁的比對鍵是 H2 標題,不是那個連結 ---
# #
# 目錄頁那一列另外留一欄裸 HASH(純文字、不帶連結),upsert 就拿那一欄當鍵。wiki-contents.sh # 目錄頁一台機器一個 H2 區塊,標題寫成內容頁頁名 MONITOR_{HASH},upsert 就拿那個標題當鍵。
# 比對的是整格文字,拿含網址的連結當鍵太脆:GITEA_HOST 換掉、JSC_WIKI_REPO_MONITOR 換過存取 # wiki-contents.sh 比對的是標題文字,拿含網址的連結當鍵太脆:GITEA_HOST 換掉、
# 庫、Gitea 對頁名的網址編碼有差,整格文字就變了,鍵對不上就走附加那一支,同一台機器多出第二 # JSC_WIKI_REPO_MONITOR 換過存取庫、Gitea 對頁名的網址編碼有差,那一條文字就變了,鍵對不上就走
# 列,舊列從此不再更新。這一頁每 15 分鐘寫一次,重複列累積得很快。裸 HASH 只由 # 附加那一支,同一台機器多出第二個區塊,舊區塊從此不再更新。這一頁每 15 分鐘寫一次,重複區塊
# {主機名}/{登入帳號} 決定,上面三件事都動不到它。 # 累積得很快。頁名只由 {主機名}/{登入帳號} 決定,上面三件事都動不到它。
# 裸 HASH 照樣在區塊裡留一條:標題是 MONITOR_ 加上它,那一條讓人不必從標題切字串就抄得到。
# #
# --- 執行狀態事件為什麼由這支排空 --- # --- 執行狀態事件為什麼由這支排空 ---
# #
@@ -142,7 +143,7 @@
# failed_sources= 讀不到的來源路徑,以「、」分隔;全部讀得到就是「無」 # failed_sources= 讀不到的來源路徑,以「、」分隔;全部讀得到就是「無」
# warn_sources= 本輪的警示來源,以「、」分隔;沒有警示就是「無」。各項全過卻判成警示 # warn_sources= 本輪的警示來源,以「、」分隔;沒有警示就是「無」。各項全過卻判成警示
# 時,原因只寫在這裡 # 時,原因只寫在這裡
# tasks_total= tasks_failing= 待辦簿筆數與連續失敗筆數,只供目錄頁那一列用 # tasks_total= tasks_failing= 待辦簿筆數與連續失敗筆數,只供目錄頁那一個區塊用
# pending= 本輪待人處理的筆數 # pending= 本輪待人處理的筆數
# events_total= 本輪排空到的事件筆數 # events_total= 本輪排空到的事件筆數
# events_bad= 其中 status 不是 ok 的筆數 # events_bad= 其中 status 不是 ok 的筆數
@@ -155,10 +156,10 @@
# summary_file= 「近 24 輪摘要」那一塊,表格裡先放本輪這一列,舊頁的資料列接在下面 # summary_file= 「近 24 輪摘要」那一塊,表格裡先放本輪這一列,舊頁的資料列接在下面
# summary_row_file= 只有本輪那一列,方便直接插到既有表格最上面 # summary_row_file= 只有本輪那一列,方便直接插到既有表格最上面
# newpage_file= MONITOR_{HASH} 不存在時要建的整頁內容,三塊都已經排好 # newpage_file= MONITOR_{HASH} 不存在時要建的整頁內容,三塊都已經排好
# contents_file= MONITOR_CONTENTS 那一列的欄位值。row= 就是整列 markdown,第一欄是 # contents_file= 目錄頁上本機那一個 H2 區塊,整塊 markdown:`## {頁名}` 那一行、
# [{頁名}]({絕對網址}) 這種連結,網址的位置留 {監控頁絕對網址} 佔位,由呼叫端 # 空行,然後各條 `- {欄位名}:{值}`。「監控頁」那一條是 [{頁名}]({絕對網址})
# 換掉、驗過再寫,理由見下一段;第二欄是裸 HASH,upsert 拿那一欄當鍵,理由見 # 這種連結,網址的位置留 {監控頁絕對網址} 佔位,由呼叫端換掉、驗過再寫,理由見
# 再下一段 # 下一段。upsert 拿 H2 標題當鍵,理由見再下一段
# #
# 環境變數: # 環境變數:
# JSC_HOME 助理狀態檔的根目錄,預設 ~/.jsc # JSC_HOME 助理狀態檔的根目錄,預設 ~/.jsc
@@ -270,6 +271,10 @@ mtime_of() { # $1=檔案;印出修改時間,取不到印「-」
# markdown 表格欄位裡的 `|` 會把欄切開,一律跳脫;換行壓成空白。 # markdown 表格欄位裡的 `|` 會把欄切開,一律跳脫;換行壓成空白。
cell() { printf '%s' "$1" | tr '\n' ' ' | sed 's/|/\\|/g'; } cell() { printf '%s' "$1" | tr '\n' ' ' | sed 's/|/\\|/g'; }
# 條列一條的值。換行一律壓成空白:一條 bullet 裡的換行會被讀成另一條,或者讓區塊提早結束。
# `|` 在條列裡沒有特殊意義,所以不跳脫——跳脫過的 `\|` 反而會原樣顯示在頁面上。
oneline() { printf '%s' "$1" | tr '\n' ' '; }
# 記一個讀不到的來源。同一輪多項失敗就串起來,供監控頁「讀不到的來源」那一列用。 # 記一個讀不到的來源。同一輪多項失敗就串起來,供監控頁「讀不到的來源」那一列用。
add_failed_source() { # $1=路徑或來源名稱 add_failed_source() { # $1=路徑或來源名稱
if [ -z "$FAILED_SOURCES" ]; then FAILED_SOURCES="$1"; else FAILED_SOURCES="$FAILED_SOURCES、$1"; fi if [ -z "$FAILED_SOURCES" ]; then FAILED_SOURCES="$1"; else FAILED_SOURCES="$FAILED_SOURCES、$1"; fi
@@ -851,7 +856,7 @@ d11() {
return 0 return 0
} }
# --- 待辦簿筆數(只供目錄頁那一列用)--- # --- 待辦簿筆數(只供目錄頁那一個區塊用)---
count_tasks() { count_tasks() {
TASKS_TOTAL=0; TASKS_FAILING=0 TASKS_TOTAL=0; TASKS_FAILING=0
@@ -946,14 +951,14 @@ compose() {
printf '> 最新一輪每輪整塊換掉;摘要表一輪一列往上疊,只留 24 列;基本資料建頁時寫一次就不動。\n' printf '> 最新一輪每輪整塊換掉;摘要表一輪一列往上疊,只留 24 列;基本資料建頁時寫一次就不動。\n'
printf '> 完整內容只留最新一輪,頁面才讀得完;軌跡留在摘要表,看得出是從哪一輪開始壞的。\n' printf '> 完整內容只留最新一輪,頁面才讀得完;軌跡留在摘要表,看得出是從哪一輪開始壞的。\n'
printf '> 目錄頁 `MONITOR_CONTENTS` 在 `JSC_WIKI_REPO_CONTENTS` 解出的專用存取庫,和這頁不同庫。\n' printf '> 目錄頁 `MONITOR_CONTENTS` 在 `JSC_WIKI_REPO_CONTENTS` 解出的專用存取庫,和這頁不同庫。\n'
printf '> 那一頁只更新自己那一列,別台機器的列一個字都不動,寫入交給 `jsc-gitea/tools/wiki-contents.sh upsert`。\n\n' printf '> 那一頁一台機器一個 H2 區塊,只更新自己那一個區塊,別台機器的區塊一個字都不動,寫入交給 `jsc-gitea/tools/wiki-contents.sh upsert`。\n\n'
printf '```mermaid\nflowchart LR\n' printf '```mermaid\nflowchart LR\n'
printf ' A[巡檢一輪] --> B[收攏各項結果]\n' printf ' A[巡檢一輪] --> B[收攏各項結果]\n'
printf ' B --> C[讀回舊頁]\n' printf ' B --> C[讀回舊頁]\n'
printf ' C --> D[換掉最新一輪那一塊]\n' printf ' C --> D[換掉最新一輪那一塊]\n'
printf ' D --> E[本輪摘要列插到表格最上面,截到 24 列]\n' printf ' D --> E[本輪摘要列插到表格最上面,截到 24 列]\n'
printf ' E --> F[整頁寫回]\n' printf ' E --> F[整頁寫回]\n'
printf ' F --> G[wiki-contents.sh upsert 更新目錄頁自己那一列]\n' printf ' F --> G[wiki-contents.sh upsert 更新目錄頁自己那一個區塊]\n'
printf ' G --> H[最後才寫心跳]\n' printf ' G --> H[最後才寫心跳]\n'
printf '```\n\n' printf '```\n\n'
printf '## 本頁基本資料\n\n' printf '## 本頁基本資料\n\n'
@@ -968,25 +973,24 @@ compose() {
cat "$RD/summary.md" cat "$RD/summary.md"
} >"$RD/newpage.md" } >"$RD/newpage.md"
{ # 目錄頁那一個 H2 區塊。標題就是內容頁頁名,欄位一行一條,順序照範本從上到下。
printf 'page=%s\n' "$PAGE" # 「監控頁」那一條是 [{頁名}]({絕對網址}) 這種連結,網址留佔位由呼叫端換掉、過完 link-check.sh
printf 'host=%s\n' "$HOST" # 才寫,理由見檔頭「目錄頁與內容頁分屬兩個存取庫」與「連結先驗證連得到」。
printf 'user=%s\n' "$USER_NAME"
printf 'heartbeat=%s\n' "$HEARTBEAT_STATE"
printf 'last_patrol=%s\n' "$AT"
printf 'tasks_total=%s\n' "$TASKS_TOTAL"
printf 'tasks_failing=%s\n' "$TASKS_FAILING"
printf 'hash=%s\n' "$HASH"
# 第一欄是 [{頁名}]({絕對網址}) 這種連結,網址留佔位由呼叫端換掉、過完 link-check.sh 才寫,
# 理由見檔頭「目錄頁與內容頁分屬兩個存取庫」與「連結先驗證連得到」。
# 連結文字先寫死成頁名:頁名這裡就知道,只有網址要等內容頁寫成才查得到。 # 連結文字先寫死成頁名:頁名這裡就知道,只有網址要等內容頁寫成才查得到。
# 第二欄是裸 HASH,upsert 拿它當鍵。鍵不能用第一欄那個連結:那一格含 GITEA_HOST 與頁名的 # upsert 拿 H2 標題當鍵,不拿那條連結:連結含 GITEA_HOST 與頁名的網址編碼,主機位址、存取庫或
# 網址編碼,主機位址、存取庫或編碼一變,整格文字就變了,鍵對不上就每輪多附一列。裸 HASH # 編碼一變,那一條文字就變了,鍵對不上就每輪多附一個區塊。頁名只跟 {主機名}/{登入帳號} 有關,
# 只跟 {主機名}/{登入帳號} 有關,那三件事都動不到它。 # 那三件事都動不到它。裸 HASH 照樣留一條,讓人不必從標題切字串就抄得到。
printf 'row=| [%s](%s) | %s | %s | %s | %s | %s | %s | %s |\n' \ {
"$PAGE" '{監控頁絕對網址}' "$HASH" "$HOST" "$USER_NAME" "$HEARTBEAT_STATE" "$AT" \ printf '## %s\n\n' "$PAGE"
"$TASKS_TOTAL" "$TASKS_FAILING" printf -- '- 監控頁:[%s](%s)\n' "$PAGE" '{監控頁絕對網址}'
} >"$RD/contents.tsv" printf -- '- HASH:%s\n' "$HASH"
printf -- '- 主機:%s\n' "$(oneline "$HOST")"
printf -- '- 帳號:%s\n' "$(oneline "$USER_NAME")"
printf -- '- 心跳:%s\n' "$(oneline "$HEARTBEAT_STATE")"
printf -- '- 最後巡檢:%s\n' "$(oneline "$AT")"
printf -- '- 待辦筆數:%s\n' "$TASKS_TOTAL"
printf -- '- 連續失敗項:%s\n' "$TASKS_FAILING"
} >"$RD/contents-entry.md"
return 0 return 0
} }
@@ -1076,7 +1080,7 @@ case "$CMD" in
printf 'summary_file=%s\n' "$RD/summary.md" printf 'summary_file=%s\n' "$RD/summary.md"
printf 'summary_row_file=%s\n' "$RD/summary-row.md" printf 'summary_row_file=%s\n' "$RD/summary-row.md"
printf 'newpage_file=%s\n' "$RD/newpage.md" printf 'newpage_file=%s\n' "$RD/newpage.md"
printf 'contents_file=%s\n' "$RD/contents.tsv" printf 'contents_file=%s\n' "$RD/contents-entry.md"
[ "$OK_COUNT" -eq 0 ] && exit 3 [ "$OK_COUNT" -eq 0 ] && exit 3
[ "$FAIL_COUNT" -gt 0 ] && exit 1 [ "$FAIL_COUNT" -gt 0 ] && exit 1
+1 -1
View File
@@ -436,7 +436,7 @@ print_allow_rules() {
# gitea.sh 一定要有自己這一條。`Skill(jsc-gitea:wiki)` 只放行「叫用那支技能」,技能裡的 # gitea.sh 一定要有自己這一條。`Skill(jsc-gitea:wiki)` 只放行「叫用那支技能」,技能裡的
# 每一個 Bash 呼叫仍然各自受檢,少了這一條,那一輪會在寫監控頁時靜靜被擋——頁寫不成就 # 每一個 Bash 呼叫仍然各自受檢,少了這一條,那一輪會在寫監控頁時靜靜被擋——頁寫不成就
# 不寫心跳,外面只看得到心跳過期,看不出是權限擋的。 # 不寫心跳,外面只看得到心跳過期,看不出是權限擋的。
# 目錄頁那一列改由 wiki-contents.sh 寫,所以它也要有自己這一條:巡檢那一輪會直接叫它, # 目錄頁那一個區塊改由 wiki-contents.sh 寫,所以它也要有自己這一條:巡檢那一輪會直接叫它,
# 少了規則就會停在權限詢問,而那一輪沒有人可以按同意。 # 少了規則就會停在權限詢問,而那一輪沒有人可以按同意。
# link-check.sh 同理:兩次寫入前都要先驗連結,少了這一條,驗證那一步就停在權限詢問,那一輪 # link-check.sh 同理:兩次寫入前都要先驗連結,少了這一條,驗證那一步就停在權限詢問,那一輪
# 什麼都寫不成。它排在寫入之前,所以擋住它等於整輪報廢。 # 什麼都寫不成。它排在寫入之前,所以擋住它等於整輪報廢。