Repository navigation
Make service updates durable and rollback-safe - #165
Merged
Merged
Conversation
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: c7fc853325
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
Closed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
@codori/serverbundles under each registered service metadata directory with bounded npm execution,--no-audit,--no-fund, and no global package mutationactive-bundle.jsonselects an absolute validated entrypointsystemd-rununits so restarting the main service cannot kill the update transaction with its cgroupdownloading,restarting,healthy,failed, androlled-back), active version, failure reason, and structuredupdate.logdiagnosticsnpx, while preserving systemd, launchd, and Windows scope/home/host/port/Tailscale launch behaviorArchitecture rationale
The service manager continues to point at its existing
run-service.shorrun-service.cmd, but that launcher now invokes a small service-owned bootstrap. The bootstrap reads one atomically replaced selection file and launches the selected bundle absolute entrypoint with the recorded Node runtime. The atomic selection file is the single launch source of truth, whileservice.jsonrecords current/previous bundle and status for inspection.Legacy registrations are migrated without taking the listener down. The worker first prepares a rollback copy of the currently running exact package, writes a current-version selection and stable launcher, then switches the selection to the already validated target and restarts. A preparation failure leaves the registered launcher and running process unchanged.
On Linux, the update worker runs in a separate transient systemd unit rather than the main service cgroup. A five-minute durable lease also prevents interrupted
downloadingorrestartingstates from locking updates forever. If a restart was abandoned, the bootstrap restoresprevious-bundle.jsonatomically before launching.Commits
2ccf0b4—fix: make service updates rollback-safec7fc853—test: cover durable service update transactions2d50a0b—fix: supervise durable service update workersValidation
pnpm --filter @codori/server test— 261 passed; Linux smoke skipped on macOSpnpm lint— passedpnpm typecheck— passedpnpm test— client 609, server 261, WebXR 191 passed locallypnpm build— passed for client, WebXR, server, and CLIpnpm --filter @codori/server pack --pack-destination <temp>— passed; tarball containsservice-bundle.js,service-update.js, andservice-update-worker.jsgit diff --check— passed33867922878passed on exact head2d50a0b, including the Linux real-process smokeThe Linux smoke launches a real temporary listener twice through the generated launcher, checks its process tree and exact version endpoint, and uses no
npxpath. No live m5 or chunsik service was modified or restarted.Risks and safeguards
Closes #163