chore: publish the zec2 and zec2online comment updates to the mirror (#87)
Some checks are pending
tests / test (push) Waiting to run

* chore: publish the zec2 and zec2online comment updates

Mirror drift, not new behaviour: the private copies had their comments
reworded and the public ones had not caught up.

Two things the new wording carries that the old did not:

zec2 now records WHY it grew an ssh of its own. The container-side version
read referenced three variables the script never defined, and because that
read sits inside a try/catch the failure was silent - it fell through to the
HTTP call and reported nothing once that endpoint stopped being public. A
missing variable and an unreachable service looked identical from the
outside, which is the kind of thing worth writing down next to the fix.

Both files now describe the container-side read by what it is - an endpoint
that is not public on every project - rather than by a product's own
wording, which is what keeps this mirror publishable.

Published with zpublish_zscripts; CHECKSUMS.txt refreshed by the same run
and committed with them, as that script requires.

Tests: 286 passed, 1 skipped across the suite; checksums, plain-text twins
and sanitization re-run after the changelog edit - 70 passed.

README.txt was left out deliberately. Regenerating the twins rewrote it with
LF where the repo stores CRLF, and the content is byte-identical - a no-op
that would only have added noise to this diff.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

* fix: rehash zec2 and zec2online against their checked-out form

CI failed the manifest check on both files. The hashes in CHECKSUMS.txt were
computed from the copies zpublish_zscripts had just written, which land with
LF; .gitattributes pins *.ps1 to eol=crlf, so every checkout - CI's included
- materialises them with CRLF and hashes differently.

Local runs passed because the working tree had already been normalised by a
later git operation. Only CI, checking out clean, saw the mismatch. The new
hashes are byte-for-byte the "But was:" values from the failing run.

Nothing about the scripts changed; this is the manifest catching up with the
form the files actually take on disk after checkout.

Worth noting where the sharp edge is: the manifest is generated from the
working tree, so any tool that writes a pinned file and hashes it in the same
breath records a hash the repo will never reproduce. Re-materialising from
git before hashing is what makes the two agree.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
Kelly Michels 2026-09-15 20:47:18 -05:00 committed by GitHub
parent 90f43010c1
commit 86938d0d80
No known key found for this signature in database
GPG Key ID: B5690EEEBB952194
5 changed files with 35 additions and 11 deletions

View File

@ -10,6 +10,16 @@ Notable changes to the Evomedia.net Token Savers.
## Unreleased ## Unreleased
### Changed
- **`zec2` and `zec2online` comments now say what they mean without
naming private detail.** The container-side version read is described
by what it is - an endpoint that is not public on every project - rather
than by a product's own wording, and `zec2` records why it needed its
own ssh: the read referenced three variables the script never defined,
and because it sits inside a try/catch the failure was silent and looked
exactly like a service that could not be reached.
## v1.0.0.0.26 - 2026-09-14 ## v1.0.0.0.26 - 2026-09-14
### Fixed ### Fixed

View File

@ -10,6 +10,17 @@ Notable changes to the Evomedia.net Token Savers.
Unreleased Unreleased
---------- ----------
Changed
-------
- **zec2 and zec2online comments now say what they mean without
naming private detail.** The container-side version read is described
by what it is - an endpoint that is not public on every project - rather
than by a product's own wording, and zec2 records why it needed its
own ssh: the read referenced three variables the script never defined,
and because it sits inside a try/catch the failure was silent and looked
exactly like a service that could not be reached.
v1.0.0.0.26 - 2026-09-14 v1.0.0.0.26 - 2026-09-14
------------------------ ------------------------

View File

@ -10,11 +10,11 @@ a0bf131d0efa75cb3ad468d51a857c272faabc362d793a9401ad5a51db1c7b2e zbackup_ec2.ps
9cd51b0aee0bd96c4ba1820a8bcdc0ad515cf26027113536a8f356a2854a8ff7 zdeploy.cmd 9cd51b0aee0bd96c4ba1820a8bcdc0ad515cf26027113536a8f356a2854a8ff7 zdeploy.cmd
16bcfe8231f52788fc1e91626c1f3ddca2ef231f947dc7d72a0f9cad7bbe3bce zdeploy.ps1 16bcfe8231f52788fc1e91626c1f3ddca2ef231f947dc7d72a0f9cad7bbe3bce zdeploy.ps1
a6891e5f6b9d443e9aa296ccd68f63b76e1d2d17ff5e3764a519287efc006bcd zec2.cmd a6891e5f6b9d443e9aa296ccd68f63b76e1d2d17ff5e3764a519287efc006bcd zec2.cmd
33ea8cd0b332643e7132c441f2cc6e6c1d6104981715bbdfe6e90c4307b8725c zec2.ps1 d327270e135ddccdc1e12fbbf0fac452fd41207b854c7b060dcfb0796723f015 zec2.ps1
1ee7c70216a4db33b3e92726d3ca18c16c4fbcedae378b7e92bbcd67d2ba690a zec2_rotatekeys.cmd 1ee7c70216a4db33b3e92726d3ca18c16c4fbcedae378b7e92bbcd67d2ba690a zec2_rotatekeys.cmd
efc43770e03c1e363f42064a7ee46c04e19a1c40e0f1daadf5b811d159d28967 zec2_rotatekeys.ps1 efc43770e03c1e363f42064a7ee46c04e19a1c40e0f1daadf5b811d159d28967 zec2_rotatekeys.ps1
6215052f8e6fc2f276e7a3dbacc887e4e3e70e4f1f78eecee434991c23d31011 zec2online.cmd 6215052f8e6fc2f276e7a3dbacc887e4e3e70e4f1f78eecee434991c23d31011 zec2online.cmd
163ea78ea6331115426cd00f7d3d818c739afbf6fed85d96e4090762a9528843 zec2online.ps1 df3159022eada0412609cdfb7d8c95516d8665f1d343610374b27d524a1bbfb3 zec2online.ps1
d4bb99f85f591f3e2ee893788bce9e8020ad737dbd7a183eb713e43120a1ecde ZHelpers.ps1 d4bb99f85f591f3e2ee893788bce9e8020ad737dbd7a183eb713e43120a1ecde ZHelpers.ps1
e90f327cb4bdae778ff2c595d938e8292784bc1c7172f9770a569c820cb61f35 zkill.cmd e90f327cb4bdae778ff2c595d938e8292784bc1c7172f9770a569c820cb61f35 zkill.cmd
fc8865ebe5d493c8d560341f013cef1493a4b727439108b70edc839531cebb8a zkill.ps1 fc8865ebe5d493c8d560341f013cef1493a4b727439108b70edc839531cebb8a zkill.ps1

View File

@ -22,9 +22,11 @@ Start-ZTracking
$cfg = Get-ZConfig $cfg = Get-ZConfig
if (-not $HostName) { $HostName = $cfg.ec2.ip } if (-not $HostName) { $HostName = $cfg.ec2.ip }
# Needed by the container-side version read below; same names zec2online.ps1 # Needed by the container-side version read below. zec2 had no ssh of its own
# uses. Without them that read throws inside its try/catch and falls through # before that, so the read referenced three variables this script never
# silently, which looks identical to a service that cannot be reached. # defined -- and because it sits inside a try/catch, the failure was silent:
# it fell through to the HTTP call and reported nothing once that endpoint
# stopped being public. Same names zec2online.ps1 uses.
$PemKey = $cfg.ec2.pemKey $PemKey = $cfg.ec2.pemKey
$SshTarget = Get-Ec2Target $SshTarget = Get-Ec2Target
@ -103,9 +105,9 @@ function Show-Zec2LiveVersion {
$r = Invoke-RestMethod -Uri "http://${HostName}/build-version.json" -Headers $headers -TimeoutSec 10 -ErrorAction Stop $r = Invoke-RestMethod -Uri "http://${HostName}/build-version.json" -Headers $headers -TimeoutSec 10 -ErrorAction Stop
if ($r) { Write-Host " Live build: $(Get-LabelFromBuildJsonObj $r)" -ForegroundColor Gray } if ($r) { Write-Host " Live build: $(Get-LabelFromBuildJsonObj $r)" -ForegroundColor Gray }
} else { } else {
# Container-side first where the project configures it: a build # Container-side first where the project configures it: the
# stamp is not public on every site, and asking the proxy answers # endpoint is not public on every project, and asking the edge
# from whichever vhost matches the Host header. # answers from whichever vhost matches the Host header.
$execCmd = Get-ServerSideVersionCommand -Proj $Proj $execCmd = Get-ServerSideVersionCommand -Proj $Proj
$label = $null $label = $null
if ($execCmd -and (Test-Path $PemKey)) { if ($execCmd -and (Test-Path $PemKey)) {

View File

@ -86,9 +86,10 @@ function Get-RemoteVersionLabel {
param($Proj) param($Proj)
$headers = @{} $headers = @{}
if ($Proj.domain) { $headers['Host'] = $Proj.domain } if ($Proj.domain) { $headers['Host'] = $Proj.domain }
# Container-side first where the project configures it. A build stamp is # Container-side first where the project configures it. The endpoint is
# not public on every site, and the proxy answers from whichever vhost # not public on every project, and the edge answers from whichever vhost
# matches the Host header - which is how a check reads another service. # matches the Host header -- which is how a check reads another
# product's version.
$execCmd = Get-ServerSideVersionCommand -Proj $Proj $execCmd = Get-ServerSideVersionCommand -Proj $Proj
if ($execCmd -and (Test-Path $PemKey)) { if ($execCmd -and (Test-Path $PemKey)) {
try { try {