set -euo pipefail release=/home/ps/ark-chat-config-20260917 cd /opt/im-admin/deploy/im-admin test "$(docker image inspect zyt/wecom-admin:current --format '{{.Id}}')" = 'sha256:1d6df0547b32c29ab28c6d96c0a434f5587cb1b62e97c7aaa0a454c4932c1976' python3 - <<'PY' from pathlib import Path import json,hashlib root=Path('/opt/im-admin');release=Path('/home/ps/ark-chat-config-20260917') baseline=json.loads((release/'inventory.json').read_text(encoding='utf-8-sig'))['files'] for name in ['wechat_rpa/admin_backend.py','wechat_rpa/model_protocol.py','wechat_rpa/model_gateway.py']: assert hashlib.sha256((root/name).read_bytes()).hexdigest()==baseline[name],name+' changed during staging' PY rollback_on_error() { rc=$? trap - ERR docker compose logs --no-color --tail=120 > "$release/failed-startup.log" 2>&1 || true bash "$release/rollback.sh" exit "$rc" } trap rollback_on_error ERR python3 - <<'PY' from pathlib import Path import shutil,json,hashlib release=Path('/home/ps/ark-chat-config-20260917');target=Path('/opt/im-admin') for row in json.loads((release/'manifest.json').read_text()): source=release/'payload'/row['path'];destination=(target/row['path']).resolve() assert target in destination.parents assert hashlib.sha256(source.read_bytes()).hexdigest()==row['sha256'] destination.parent.mkdir(parents=True,exist_ok=True) shutil.copyfile(source,destination) print('Model configuration fix source and frontend installed.',flush=True) PY docker compose config --quiet docker tag zyt/wecom-admin:ark-chat-config-20260917 zyt/wecom-admin:current docker compose up -d --no-build --wait --wait-timeout 180 api gateway knowledge-worker curl -fsS http://127.0.0.1:18766/api/v2/health curl -fsS http://127.0.0.1:18770/health docker compose ps bash "$release/04-verify.sh" trap - ERR echo 'Deployment verified successfully.'