set -euo pipefail release=/home/ps/token-usage-20260917 cd "$release" mkdir -m 700 payload tar -xzf payload.tar.gz -C payload python3 - <<'PY' from pathlib import Path import json,hashlib root=Path('/home/ps/token-usage-20260917') manifest=json.loads((root/'manifest.json').read_text()) for row in manifest: p=(root/'payload'/row['path']).resolve() assert root/'payload' in p.parents data=p.read_bytes() assert len(data)==row['bytes'] and hashlib.sha256(data).hexdigest()==row['sha256'],row['path'] print('Release files verified:',len(manifest),flush=True) PY docker exec -i im-admin-api-1 python -u - <<'PY' | tee "$release/backup-verification.json" from pathlib import Path import sqlite3,shutil,json,os,time folder=Path('/data/backups/token-usage-20260917');folder.mkdir(mode=0o700) started=time.monotonic() source=sqlite3.connect('/data/backend.db',timeout=30) backup=sqlite3.connect(folder/'backend.db') try: source.execute('BEGIN');source.execute('SELECT COUNT(*) FROM sqlite_master').fetchone() source.backup(backup,pages=4096,sleep=0.05) finally: backup.close();source.close() with sqlite3.connect(f'file:{folder}/backend.db?mode=ro',uri=True) as c: check=c.execute('PRAGMA quick_check').fetchone()[0];assert check=='ok',check os.chmod(folder/'backend.db',0o600) keys=[] for key in Path('/data').glob('*.key'): shutil.copy2(key,folder/key.name);os.chmod(folder/key.name,0o600);keys.append(key.name) assert keys print(json.dumps({'backup':str(folder),'bytes':(folder/'backend.db').stat().st_size,'quick_check':check,'key_files':keys,'seconds':round(time.monotonic()-started,1)}),flush=True) PY docker build --network=none -f Dockerfile.overlay -t zyt/wecom-admin:token-usage-20260917 . 2>&1 | tee build.log docker run --rm --network=none --read-only --tmpfs /tmp:size=256m,mode=1777 zyt/wecom-admin:token-usage-20260917 python -X utf8 -B -m unittest test_model_usage_collection test_model_usage_recovery test_model_usage_ledger test_model_gateway test_gateway_guard_audit test_gateway_media_audit test_gateway_failure_audit test_knowledge_model_output test_knowledge_tasks test_knowledge test_admin_api test_ark_chat_config -q 2>&1 | tee candidate-tests.log