fix(cron): widen deleted-profile protection to all cron mkdir sites
Replace #96637's inline active_profile_homes() closure with #96508's module-level _existing_profile_homes() filter (testable in isolation). Widen _ensure_cron_dir from 3 to 12 mkdir sites across cron/ so every directory creation fails closed for deleted named profiles, not just the 3 originally protected. Add _is_named_profile_path() that checks 'profiles' in path parts (works for subdirs like cron/output/<job> and scripts/ that the original parent.name heuristic couldn't reach). Co-authored-by: misterdas <das7514@gmail.com>
This commit is contained in:
+3
-3
@@ -972,7 +972,7 @@ def _record_forced_release(job_id: str, name: str, age_seconds: float, allowance
|
||||
del _forced_releases[:-_FORCED_RELEASE_HISTORY]
|
||||
try:
|
||||
path = _get_hermes_home() / "cron" / "inflight_forced_releases.jsonl"
|
||||
path.parent.mkdir(parents=True, exist_ok=True)
|
||||
_ensure_cron_dir(path.parent)
|
||||
with open(path, "a", encoding="utf-8") as fh:
|
||||
fh.write(json.dumps(entry) + "\n")
|
||||
except Exception as e: # never let telemetry break a tick
|
||||
@@ -1513,7 +1513,7 @@ def _write_usage_audit(record: dict) -> None:
|
||||
"""
|
||||
try:
|
||||
path = _usage_audit_path()
|
||||
path.parent.mkdir(parents=True, exist_ok=True)
|
||||
_ensure_cron_dir(path.parent)
|
||||
line = json.dumps(record, ensure_ascii=False)
|
||||
with open(path, "a", encoding="utf-8") as f:
|
||||
f.write(line + "\n")
|
||||
@@ -4311,7 +4311,7 @@ def _run_job_script(
|
||||
LLM can report the problem to the user.
|
||||
"""
|
||||
scripts_dir = _get_hermes_home() / "scripts"
|
||||
scripts_dir.mkdir(parents=True, exist_ok=True)
|
||||
_ensure_cron_dir(scripts_dir)
|
||||
scripts_dir_resolved = scripts_dir.resolve()
|
||||
|
||||
# Same ingestion contract as cron.lifecycle_guard._expand_candidate_path:
|
||||
|
||||
Reference in New Issue
Block a user