Repository navigation
supervisor: real daemon address for apps; pick up same-version rebuilds - #42
Merged
Merged
Conversation
daemonAddrFromDeps asserted Identity to an Address() string method, but coreapi.Identity.Address() returns protocol.Addr. The assertion never matched the real daemon, so every supervised app, including every wallet on the network, started with the sentinel --addr 0:0001.0000.0000. The method is now looked up by name and its result used when it is a string or a fmt.Stringer; anything else still falls back to the sentinel. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Codecov Report❌ Patch coverage is
📢 Thoughts on this report? Let us know! |
rescanForNew skipped any on-disk manifest whose app_version matched the running one. When a rebuilt bundle is reinstalled at the same version (pilotctl appstore upgrade: "rebuilt (same version, new bundle)"), the new binary and manifest land on disk but the supervisor keeps verifying against the old binary pin, fails ten times and suspends the app; appstore restart reuses the same stale manifest, so only a daemon restart recovered it. A same-version manifest with a different binary.sha256 is now swapped in like an upgrade: the old supervise goroutine is canceled, the crash record and .suspended marker are cleared, and a rebuild-applied audit event is written. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Two supervisor bugs found during the app-store audit. Both reproduce on real nodes (macOS plus linux amd64/arm64 VMs).
1. Every app gets the sentinel address
On a real node,
wallet.addressreturns0:0001.0000.0000, the supervisor's non-routable sentinel.daemonAddrFromDepsassertsdeps.Identitytointerface{ Address() string }, butcoreapi.Identity.Address()returnsprotocol.Addr(a struct withString()). The assertion never matches in the daemon, so every supervised app, and every wallet on the network, starts with--addr 0:0001.0000.0000.Fix: look
Addressup by name via reflection (the module still doesn't importcoreapi), and use the result if it is astringor afmt.Stringer. Anything else falls back to the sentinel.TestDaemonAddrFromDeps_CoreapiIdentityAddressmirrorsprotocol.Addr's shape and formatting (fails before, passes after).TestDaemonAddrFromDeps_UnusableAddressMethodFallsBackchecks there's no panic on an oddAddressmethod.2. A rebuilt bundle at the same version gets the app suspended
pilotctl appstore upgradereinstalls a rebuilt bundle at the same version ("rebuilt (same version, new bundle)").rescanForNewskipped any manifest whoseapp_versionmatched, so the supervisor kept verifying the new binary against the old pin until it hitsha256 mismatch … >=10 consecutive verify failuresand suspended the app.appstore restartreused the same stale manifest, so only a daemon restart recovered. Seen on the audit VMs with rebuilt cosift 0.1.3 / wallet 0.3.4 bundles.Fix: a same-version manifest with a different
binary.sha256is swapped in like an upgrade. The old supervise goroutine is cancelled, the crash record and.suspendedmarker are cleared, and arebuild-appliedaudit event is written.TestRescanAppliesSameVersionRebuildfails before, passes after.Tests
go test ./...is green exceptTestReapStaleKillsEveryInstance. That test is flaky on untouchedmaintoo (fails with-count=5on main, 5/5 passes on this branch) and is unrelated.Rollout
Ships to nodes through a pilotprotocol daemon release that bumps
github.com/pilot-protocol/app-store.🤖 Generated with Claude Code