Skip to content

supervisor: real daemon address for apps; pick up same-version rebuilds - #42

Merged
TeoSlayer merged 3 commits into
mainfrom
fix/supervisor-daemon-address
Oct 1, 2026
Merged

TeoSlayer merged 3 commits into
mainfrom
fix/supervisor-daemon-address

Conversation

@Alexgodoroja

@Alexgodoroja Alexgodoroja commented Sep 25, 2026 •

Copy link
Copy Markdown
Collaborator

Two supervisor bugs found during the app-store audit. Both reproduce on real nodes (macOS plus linux amd64/arm64 VMs).

1. Every app gets the sentinel address

On a real node, wallet.address returns 0:0001.0000.0000, the supervisor's non-routable sentinel.

daemonAddrFromDeps asserts deps.Identity to interface{ Address() string }, but coreapi.Identity.Address() returns protocol.Addr (a struct with String()). The assertion never matches in the daemon, so every supervised app, and every wallet on the network, starts with --addr 0:0001.0000.0000.

Fix: look Address up by name via reflection (the module still doesn't import coreapi), and use the result if it is a string or a fmt.Stringer. Anything else falls back to the sentinel.

  • TestDaemonAddrFromDeps_CoreapiIdentityAddress mirrors protocol.Addr's shape and formatting (fails before, passes after).
  • TestDaemonAddrFromDeps_UnusableAddressMethodFallsBack checks there's no panic on an odd Address method.

2. A rebuilt bundle at the same version gets the app suspended

pilotctl appstore upgrade reinstalls a rebuilt bundle at the same version ("rebuilt (same version, new bundle)"). rescanForNew skipped any manifest whose app_version matched, so the supervisor kept verifying the new binary against the old pin until it hit sha256 mismatch … >=10 consecutive verify failures and suspended the app. appstore restart reused the same stale manifest, so only a daemon restart recovered. Seen on the audit VMs with rebuilt cosift 0.1.3 / wallet 0.3.4 bundles.

Fix: a same-version manifest with a different binary.sha256 is swapped in like an upgrade. The old supervise goroutine is cancelled, the crash record and .suspended marker are cleared, and a rebuild-applied audit event is written.

  • TestRescanAppliesSameVersionRebuild fails before, passes after.

Tests

go test ./... is green except TestReapStaleKillsEveryInstance. That test is flaky on untouched main too (fails with -count=5 on main, 5/5 passes on this branch) and is unrelated.

Rollout

Ships to nodes through a pilotprotocol daemon release that bumps github.com/pilot-protocol/app-store.

🤖 Generated with Claude Code

daemonAddrFromDeps asserted Identity to an Address() string method, but
coreapi.Identity.Address() returns protocol.Addr. The assertion never
matched the real daemon, so every supervised app, including every wallet on
the network, started with the sentinel --addr 0:0001.0000.0000. The method is
now looked up by name and its result used when it is a string or a
fmt.Stringer; anything else still falls back to the sentinel.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@codecov

codecov Bot commented Sep 25, 2026 •

Copy link
Copy Markdown

Codecov Report

❌ Patch coverage is 90.90909% with 3 lines in your changes missing coverage. Please review.

Files with missing lines Patch % Lines
plugin/appstore/supervisor.go 90.90% 2 Missing and 1 partial ⚠️

📢 Thoughts on this report? Let us know!

rescanForNew skipped any on-disk manifest whose app_version matched the
running one. When a rebuilt bundle is reinstalled at the same version
(pilotctl appstore upgrade: "rebuilt (same version, new bundle)"), the new
binary and manifest land on disk but the supervisor keeps verifying against
the old binary pin, fails ten times and suspends the app; appstore restart
reuses the same stale manifest, so only a daemon restart recovered it.

A same-version manifest with a different binary.sha256 is now swapped in like
an upgrade: the old supervise goroutine is canceled, the crash record and
.suspended marker are cleared, and a rebuild-applied audit event is written.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@Alexgodoroja Alexgodoroja changed the title supervisor: pass apps the daemon's real pilot address supervisor: real daemon address for apps; pick up same-version rebuilds Sep 25, 2026
@TeoSlayer
TeoSlayer merged commit bb502a8 into main Oct 1, 2026
4 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants