Skip to content

Release exp: fail-closed gateway-restart recovery for agent updates (#6054) - #6057

Merged
nesquena-hermes merged 7 commits into
masterfrom
stage/6054
Jul 14, 2026
Merged

nesquena-hermes merged 7 commits into
masterfrom
stage/6054

Conversation

@nesquena-hermes

Copy link
Copy Markdown
Collaborator

Ships #6054 (closes #6045), @franksong2702 — backend reliability on the agent-update path.

An agent update's launchd/gateway restart can briefly exit non-zero during process replacement; that was reported as a whole-update failure. The updater now confirms the outcome by the actual gateway PID for the exact profile being updated (one retry), so a transient handoff reads as success — while every uncertain shape fails closed (never masks a real failure): real restart failure, unknown/ambient PID, wrong-profile confirmation, or a status helper whose signature can't confirm the specific PID.

Codex authoritative gate SAFE after a thorough 6-round hardening: restart + PID-read profile-pinned (root aliases normalized), malformed profiles rejected pre-launch, isolated profiles/default targeted correctly, capability check uses inspect.signature(follow_wrapped=False) so @functools.wraps/**kwargs/*args/builtin/partial wrappers all fail closed, positional-only PID paths bound at declared index (no ambient positional retry). Verified: a real failed restart can no longer be masked as success via any callable shape or fallback; transient recovery, default-vs-sticky isolation, and normal updates all intact. 43 focused tests. Thanks @franksong2702 for the careful iteration.

@greptile-apps

greptile-apps Bot commented Jul 14, 2026

Copy link
Copy Markdown
Contributor

Greptile Summary

This PR adds fail-closed gateway restart recovery for agent updates. The main changes are:

  • Pins gateway restarts and PID checks to the selected profile.
  • Retries one failed restart and confirms process replacement by PID.
  • Rejects malformed profiles and ambiguous status-helper signatures.
  • Adds tests for profile isolation, helper compatibility, and restart outcomes.

Confidence Score: 5/5

This looks safe to merge.

  • No blocking issues found in the changed code.
  • Unknown PID state, incompatible helpers, and ambiguous restart results remain fail-closed.
  • The selected profile is preserved across restart attempts and PID checks.

Important Files Changed

Filename Overview
api/agent_health.py Adds strict, profile-specific gateway PID lookup without falling back to ambient state.
api/gateway_restart.py Adds validated profile targeting and profile-aware gateway restart commands.
api/updates.py Adds one restart retry and PID-based confirmation of transient recovery.
tests/test_health_restart.py Covers explicit profiles, root aliases, isolated defaults, and malformed profile input.
tests/test_issue716_agent_heartbeat.py Covers profile-specific PID paths and unavailable gateway status handling.
tests/test_update_banner_fixes.py Covers retry outcomes, strict helper signatures, PID confirmation, and profile isolation.

Reviews (1): Last reviewed commit: "Release exp: fail-closed gateway-restart..." | Re-trigger Greptile

@nesquena-hermes
nesquena-hermes merged commit 3f3fa9b into master Jul 14, 2026
18 checks passed
@nesquena-hermes
nesquena-hermes deleted the stage/6054 branch July 14, 2026 09:05
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[Bug]: Agent update reports failure after transient macOS launchd gateway restart error

1 participant