fix(update): identity-pending fleet row no longer claims 'restarted by this update'

The settle poll marks a row identity-pending when it is an unknown pid with no
sha that was not in the pre-restart pid set. That is negative evidence: the poll
never observed the restart, and collect_fleet_versions can emit the same shape
for a fail-open foreign-writer row it explicitly refuses to trust. Word the row
as 'new pid since the update, code identity not published yet' so the matrix
states what was seen and not a restart it did not witness. Requiring positive
successor evidence before stalling the poll is left as a known residual.
This commit is contained in:
teknium1
2026-09-16 12:40:23 -07:00
committed by Teknium
parent f079458401
commit fe52c4a78b

View File

@@ -365,10 +365,12 @@ _FLEET_ROW_LINES = {
"down": " ✗ {profile} — DOWN (gateway was running before the update; pid {pid} is gone and nothing replaced it)",
}
_FLEET_ROW_UNKNOWN = " ? {profile} (pid {pid}) — version unknown (gateway predates version stamping; restart to enable)"
# A gateway this update relaunched that had not published its code identity when the settle window
# closed (#112634): it was just restarted on the new code, so "restart to enable" would be wrong.
# A gateway pid the pre-update snapshot did not know that had not published its code identity when
# the settle window closed (#112634): most likely the successor this update relaunched, still
# booting, so "restart to enable" would be wrong — but the poll never observed the restart itself,
# so the copy does not claim one.
_FLEET_ROW_IDENTITY_PENDING = (
" ? {profile} (pid {pid}) — restarted by this update, code identity not published yet"
" ? {profile} (pid {pid}) — new pid since the update, code identity not published yet"
" — re-check with `hermes gateway status`"
)