Skip to content

fix(gateway): restart managed external supervisor - #221

Merged
100yenadmin merged 2 commits into
r30/upstream-5fc308a-basefrom
codex/r30.6-managed-restart-20260901
Sep 1, 2026
Merged

100yenadmin merged 2 commits into
r30/upstream-5fc308a-basefrom
codex/r30.6-managed-restart-20260901

Conversation

@100yenadmin

Copy link
Copy Markdown
Member

Outcome

Adds the smallest r30 release-family correction for managed profile gateways supervised by evaOS systemd templates. In managed flat-profile mode, hermes gateway restart now asks the already-running profile-local gateway to drain and exit through its existing SIGUSR1/exit-75 contract, then requires one replacement carrying --external-supervisor.

Scope

  • Branches from the immutable r30.5 release family, not desktop main.
  • Keeps unmanaged Hermes restart behavior unchanged.
  • Fails closed when managed profile authority, PID identity, or supervisor identity is ambiguous.
  • Does not add a root bridge, generic supervisor API, credential path, PCS change, deployment, or fleet mutation.

Deterministic proof

  • tests/hermes_cli/test_gateway_service.py: 95 passed, 1 skipped.
  • Existing restart and managed-scope regressions: 66 passed.
  • Ruff lint: pass.
  • git diff --check: pass.

Proof boundary

This proves source behavior only. Benjamin still requires immutable r30.6 plus PCS 0.1.94 installation and the affected live restart/Telegram/isolation check before the issue can close.

Supports #217 and #201.

@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 1, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-09-01T12:48:11.232594Z 2127a57 New commits
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@coderabbitai

coderabbitai Bot commented Sep 1, 2026 •

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on this repository. Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Team

Run ID: 620b655c-ad10-488b-b189-fd2981fda85e

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Warning

Billing warning: we have not been able to collect payment for this subscription for more than 72 hours. Please update the payment method or pay any pending invoices in Billing to avoid service interruption.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 9214a03b67

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread hermes_cli/gateway.py Outdated
Comment thread hermes_cli/gateway.py Outdated
Comment thread hermes_cli/gateway.py Outdated

@evaos-code-review-bot evaos-code-review-bot Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Walkthrough

PR: #221 - fix(gateway): restart managed external supervisor
Head: 9214a03b67604f9be4755efb4334ecb123bec323 into r30/upstream-5fc308a-base. Review event: COMMENT.
Estimated review effort: 1/5 (~14 min)

Changed Files

File Status Churn Purpose Risk
hermes_cli/gateway.py modified +82/-0 Changed file Moderate: validated P2 finding
tests/hermes_cli/test_gateway_service.py modified +144/-0 Test coverage Low

Review Signal

Validated inline findings: 1 (P0: 0, P1: 0, P2: 1, P3: 0).
Dropped findings before posting: 0. High-severity findings: 0.

Maintainer Analysis

Changed behavior:

  • Plain restart in a managed flat-profile runtime now signals the current externally supervised gateway and waits for a replacement PID instead of using generic service/manual restart logic.
  • The same early return currently also intercepts restart requests carrying --all or --system.

Affected invariants:

  • Explicit restart scope flags must not be silently discarded.
  • A managed handoff must accept only a new profile-local process whose argv contains the external-supervisor marker.
  • Unmanaged runtimes must retain existing restart behavior.

Evidence:

  • hermes_cli/gateway.py:8413 performs the managed early return before reading args.system and without checking args.all.
  • tests/hermes_cli/test_gateway_service.py exercises command routing only with system=False, all=False.
  • The replacement tests mock PID and argv behavior; they do not cover scoped restart flags.

Limitations:

  • Per instructions, no tests, builds, package scripts, app commands, or shell commands were run.
  • Review was limited to the supplied checkout diff and context.

No-finding rationale: The remaining new failure paths and replacement-identity checks are internally consistent with the stated fail-closed managed-supervisor design; no additional concrete current-path defect was validated from the provided evidence.

Risk Taxonomy

  • Runtime correctness: 1

Validation and Proof

No required validation recommendation selected; rely on existing GitHub checks and human review.
Proof status: not_applicable - No required behavior proof selected for this changed surface.

Related Context

Related issues/PRs: #217, #201.

Pre-merge checklist

  • Inline comments target current RIGHT-side diff lines.
  • No secret-like content survived into posted inline comments.
  • REQUEST_CHANGES is only used when eligible P0/P1 findings survive validation.
  • Required behavior proof is present or not applicable.

Comment thread hermes_cli/gateway.py

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 2127a57586

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread hermes_cli/gateway.py
Comment thread hermes_cli/gateway.py
Comment thread hermes_cli/gateway.py

@evaos-code-review-bot evaos-code-review-bot Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Walkthrough

PR: #221 - fix(gateway): restart managed external supervisor
Head: 2127a575867f09df6adba0825e9ef05249f5407a into r30/upstream-5fc308a-base. Review event: COMMENT.
Estimated review effort: 2/5 (~24 min)

Changed Files

File Status Churn Purpose Risk
hermes_cli/gateway.py modified +125/-0 Changed file Moderate: validated P2 finding
tests/hermes_cli/test_gateway_service.py modified +243/-0 Test coverage Elevated: large change

Review Signal

Validated inline findings: 1 (P0: 0, P1: 0, P2: 1, P3: 0).
Dropped findings before posting: 0. High-severity findings: 0.

Maintainer Analysis

Changed behavior:

  • Managed flat-profile gateway restarts now signal the externally supervised process and wait for a profile-local running replacement instead of using generic service or manual restart routing.
  • Replacement acceptance requires strict PID/lock identity, the external-supervisor argv marker, and matching running runtime status.

Affected invariants:

  • A replacement is identified by both PID and process start time.
  • Managed mode must not fall through to credential-incomplete generic restart paths.
  • Startup-failed or ambiguous replacement state must fail closed.

Evidence:

  • hermes_cli/gateway.py:384 compares only replacement[0] with previous_identity[0], despite both values being full identity tuples.
  • The added tests cover a different replacement PID but do not cover PID reuse with a changed start time.

Limitations:

  • Review was limited to the supplied checkout diff; no shell commands, tests, builds, package scripts, app commands, or arbitrary PR code were executed.

No-finding rationale: No additional correctness, security, data-loss, CI, release, or test defect was validated from the supplied diff.

Risk Taxonomy

  • Runtime correctness: 1

Validation and Proof

No required validation recommendation selected; rely on existing GitHub checks and human review.
Proof status: not_applicable - No required behavior proof selected for this changed surface.

Related Context

Related issues/PRs: #217, #201.

Pre-merge checklist

  • Inline comments target current RIGHT-side diff lines.
  • No secret-like content survived into posted inline comments.
  • REQUEST_CHANGES is only used when eligible P0/P1 findings survive validation.
  • Required behavior proof is present or not applicable.

Comment thread hermes_cli/gateway.py
@100yenadmin
100yenadmin merged commit f731611 into r30/upstream-5fc308a-base Sep 1, 2026
80 of 82 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant