Repository navigation
pilotctl: uninstall keeps the app's state in the backups instead of deleting it - #524
Merged
Merged
Conversation
…eleting it appstore uninstall deleted the app's dir and with it the app's state: the wallet's EVM private key, and the funds at its address, smol's secrets, each metered app's identity. The dir now goes to the app backups like a replaced install (without the binary), as a new "uninstall" kind that retention never removes, and the command prints where. If no backup location takes it, retireAppDir keeps it in the install root with its manifest disabled; if even that fails the command stops with the dir in place. Nothing is deleted. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…findable name Review fixes: - When even the in-place rename fails, retireAppDir hands back the dir itself; uninstall reported success with the app still installed. It now fails with "nothing was deleted". - A dir parked beside the install (no backup location worked) is named <appID>.previous-<stamp>, the name backup listings and the wallet's key restore look for, instead of <appID>-<stamp>. - Processes still running from the app's files are looked for in the backup too: on Linux their executable path follows the move. - The output no longer says any app picks its keys back up; only the wallet, from 0.4.0, does. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Problem
pilotctl appstore uninstall <id> --yesdeleted the app's dir, and with it the app's state:There was no backup and no way back.
Fix
~/.pilot/app-backups/<id>/(or$PILOT_APPSTORE_BACKUP_ROOT), the way upgrades already retire a replaced install, without the binary. The command prints where it went, and--jsoncarriesbackup.uninstall. It is pinned, so retention never removes it.retireAppDirkeeps it in the install root as<id>.previous-<time>with its manifest disabled.The wallet (pilot-protocol/wallet#47) looks in these backups, and in its own copy under
~/.pilot/keys/io.pilot.wallet, before it would create a key. So installing it again brings the old key back.Tests
TestUninstallKeepsTheAppsStateInABackup: the key lands byte for byte in a pinneduninstallbackup underapp-backups/<id>/, and the binary is not kept.TestUninstallNeverDeletesTheKeyWhenBackupsFail: with every backup rename refused, the key still exists afterwards, in<id>.previous-<time>.TestUninstallFailsWhenTheDirCannotBeMoved: with the install root read-only, the command fails, says nothing was deleted, and the key is untouched.All three fail on main.
go test -race ./cmd/pilotctlpasses.🤖 Generated with Claude Code