G7.6: never let bookkeeping kill the monitor
All checks were successful
check / gate (push) Successful in 18s
canary / probe (push) Successful in 26s

An unwritable state path raised and took the whole canary down. That is the
worst possible trade for a monitoring tool: it reports nothing at all, and
reports it silently. State is an optimisation for transition detection; the
probing is the point.

Found by fat-fingering an env var, which is exactly how it would happen in
production.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
Grant Whitmer
2026-08-12 15:42:58 -04:00
parent a094960da3
commit ef3450d87b
2 changed files with 22 additions and 2 deletions

View File

@@ -601,3 +601,11 @@ def test_g35_did_not_disable_validation_to_register():
one-time ordering problem."""
for f in (ROOT / "scripts").glob("*.py"):
assert "skip_validation" not in f.read_text()
def test_g76_canary_survives_an_unwritable_state_path():
"""A monitoring tool that dies of a config problem reports nothing at all,
and reports it silently. State is an optimisation; probing is the point."""
src = (ROOT / "scripts" / "canary.py").read_text()
save = src[src.index("def save_state") : src.index("def send_alert")]
assert "except OSError" in save