From 7de9f4af83f5e294850e2901f57ea40ef98436f0 Mon Sep 17 00:00:00 2001 From: "prompt.ac/@jeffrey" Date: Thu, 1 Oct 2026 16:17:05 -0700 Subject: [PATCH] Validate machine discovery before deploying Lith --- lith/deploy.fish | 13 +++++++++++++ 1 file changed, 13 insertions(+) diff --git a/lith/deploy.fish b/lith/deploy.fish index 66daaa2be5..b97e649f33 100644 --- a/lith/deploy.fish +++ b/lith/deploy.fish @@ -243,6 +243,19 @@ sh xbox/tools/precompress-live.sh" exit 1 end +# Validate the committed public-host inventory on the deployment checkout. +# This does not read the maintainer's possibly dirty local working tree. +echo -e "$GREEN-> Verifying public machine discovery...$NC" +if not ssh -i $SSH_KEY $LITH_USER@$TARGET_HOST "cd $REMOTE_DIR && node utilities/generate-machine-manifests.mjs --check" + echo -e "$RED x Machine discovery is stale or a public host is unclassified; restoring $PREVIOUS_HEAD.$NC" + ssh -i $SSH_KEY $LITH_USER@$TARGET_HOST "\ +cd $REMOTE_DIR && \ +git reset --hard $PREVIOUS_HEAD --quiet && \ +git rev-parse HEAD > system/public/.commit-ref && \ +sh xbox/tools/precompress-live.sh" + exit 1 +end + # Upload env (only if the vault has one — otherwise keep the remote's existing env) # Note: lith.service reads EnvironmentFile=/opt/ac/system/.env, so the canonical # vault source lives at aesthetic-computer-vault/lith/.env and is uploaded into -- 2.51.2