# Conflicts: # .gitignore # Dockerfile # agent/onboarding.py # apps/desktop/electron/main.ts # apps/desktop/electron/pool-stop.ts # apps/desktop/src/components/model-picker.test.tsx # apps/desktop/src/store/updates.ts # apps/desktop/vite.config.ts # datagen-config-examples/run_browser_tasks.sh # docs/rca-ssl-cacert-post-git-pull.md # gateway/run.py # hermes_cli/backup.py # hermes_cli/credential_lifecycle.py # hermes_cli/dashboard_procs.py # hermes_cli/doctor_state.py # hermes_cli/env_loader.py # hermes_cli/gateway_windows.py # hermes_cli/local_runtime/endpoint.py # hermes_cli/psutil_android.py # hermes_cli/update_cmd.py # hermes_cli/update_cmd_windows.py # hermes_cli/web_routers/local_models.py # hermes_cli/web_server_config.py # hermes_cli/web_server_cron.py # plugins/memory/hindsight/__init__.py # plugins/memory/holographic/__init__.py # plugins/memory/honcho/cli.py # plugins/memory/mem0/__init__.py # plugins/platforms/google_chat/oauth.py # plugins/platforms/photon/adapter.py # scripts/ci/list_os_marked_tests.py # scripts/run_tests.sh # tests/agent/test_compression_stall_fallback.py # tests/agent/test_create_openai_client_ssl_verify.py # tests/gateway/test_google_chat_oauth_dependencies.py # tests/hermes_cli/conftest.py # tests/hermes_cli/test_cli_init.py # tests/hermes_cli/test_gateway_migrate_multiplex.py # tests/hermes_cli/test_psutil_android_extract.py # tests/hermes_cli/test_relaunch.py # tests/hermes_cli/test_update_check.py # tests/hermes_cli/test_update_handoff_desktop_rebuild.py # tests/hermes_cli/test_worktree_gc.py # tests/scripts/desktop_update/test_desktop_update_windows_python_handoff.py # tests/scripts/desktop_update/test_desktop_update_windows_retry_policy.py # tests/scripts/desktop_update/test_desktop_update_windows_timestamp.py # tests/scripts/install/test_install_autostash_conflict_recovery.py # tests/scripts/install/test_install_clone_throttle_fallback.py # tests/scripts/install/test_install_commit_pin_rollback.py # tests/scripts/install/test_install_diverged_update.py # tests/scripts/install/test_install_lockfile_churn.py # tests/scripts/install/test_install_macos_launcher.py # tests/scripts/install/test_install_no_initial_commit.py # tests/scripts/install/test_install_ps1_ascii_only.py # tests/scripts/install/test_install_ps1_browser_install.py # tests/scripts/install/test_install_ps1_managed_node_swap.py # tests/scripts/install/test_install_ps1_native_stderr_eap.py # tests/scripts/install/test_install_ps1_node_path_for_npm.py # tests/scripts/install/test_install_ps1_python_fallback_venv.py # tests/scripts/install/test_install_ps1_resolver_strictmode.py # tests/scripts/install/test_install_ps1_uv_install_fallback.py # tests/scripts/install/test_install_ps1_uv_powershell_host.py # tests/scripts/install/test_install_ps1_venv_process_tree.py # tests/scripts/install/test_install_ps1_venv_recreate_safety.py # tests/scripts/install/test_install_ps1_venv_rename_abort.py # tests/scripts/install/test_install_ps1_venv_transaction_boundary.py # tests/scripts/install/test_install_ps1_web_server_syntax_probe.py # tests/scripts/install/test_install_scripts_computer_use.py # tests/scripts/install/test_install_sh_acp_launcher.py # tests/scripts/install/test_install_sh_bootstrap_marker.py # tests/scripts/install/test_install_sh_browser_install.py # tests/scripts/install/test_install_sh_install_method_stamp.py # tests/scripts/install/test_install_sh_node_deps_failure.py # tests/scripts/install/test_install_sh_node_deps_workspaces.py # tests/scripts/install/test_install_sh_node_global_prefix.py # tests/scripts/install/test_install_sh_node_npm_check.py # tests/scripts/install/test_install_sh_node_prerelease.py # tests/scripts/install/test_install_sh_node_probe.py # tests/scripts/install/test_install_sh_node_tarball_without_xz.py # tests/scripts/install/test_install_sh_pythonpath_sanitization.py # tests/scripts/install/test_install_sh_reuse_supported_python.py # tests/scripts/install/test_install_sh_root_fhs_uv_python_path.py # tests/scripts/install/test_install_sh_setup_wizard_tty_probe.py # tests/scripts/install/test_install_sh_symlink_stomp.py # tests/scripts/install/test_install_sh_termux_network_prereqs.py # tests/scripts/install/test_install_sh_termux_python_bounds.py # tests/scripts/install/test_install_sh_uv_lock_config.py # tests/scripts/install/test_install_unmerged_index.py # tests/scripts/test_run_tests_parallel.py # tests/test_managed_runtime_resolution.py # tests/test_project_metadata.py # tests/tools/test_browser_use_cli.py # tests/tools/test_tts_pythonpath_fallback.py # tests/tui_gateway/test_hosted_room_driver_runtime.py # tests/tui_gateway/test_tui_gateway_server.py # tools/lazy_deps.py # tools/voice_mode.py # uv.lock # website/docs/developer-guide/macos-bundle-updates.md # website/docs/developer-guide/pm-audit-status.md # website/docs/developer-guide/shared-bundle-builds.md # website/docs/developer-guide/source-update-completion.md # website/docs/developer-guide/stable-releases.md
85 lines
5.3 KiB
Markdown
85 lines
5.3 KiB
Markdown
# Source update completion ownership
|
|
|
|
## Phase seam
|
|
|
|
The command process owns admission, the update lock and output lifetime, pre-update
|
|
inventory, all-profile snapshots, gateway pause, Git selection/stash/restore and
|
|
syntax/HEAD guards, and the ZIP download/stage/dirty recheck/release graft/swap.
|
|
It imports the completion transport before swapping code. Once the final tree is
|
|
selected (including upstream merge), Git, already-current retry and ZIP all send
|
|
one versioned JSON request to `update_completion.py` **from that tree**. No cached
|
|
application module is evicted or reloaded in the command process.
|
|
|
|
The request carries canonical source/home, desktop product selection, interactive
|
|
and gateway mode, pre-update version, active and sibling snapshot identifiers,
|
|
serialized runtime plan, open receipt identity/data and paused-Windows token. It
|
|
contains data, never callables or pickles. stdin stays inherited for interactive
|
|
configuration prompts; gateway mode retains its non-interactive behavior. Child
|
|
output stays visible and is mirrored by the parent's update output stream.
|
|
|
|
## New-code owner
|
|
|
|
A stdlib-only entrypoint starts using the available Python with `-I -S`, so no
|
|
old site-packages or executable `.pth` files initialize. A private bytecode-cache
|
|
prefix fences stale cache files before any new-checkout imports. Its explicit
|
|
import path points at the new checkout. It calls the new PM interface to prepare the
|
|
recorded dependency union, then starts the selected Python with the new activation
|
|
environment. That interpreter also starts with site initialization disabled,
|
|
then the runtime owner leases and activates its selected generation before any
|
|
application imports. Only that interpreter imports application completion code. The same
|
|
receipt/correlation identity crosses this preparation boundary (including PM
|
|
results). Selected-Python completion owns launcher publication, builders, cache
|
|
invalidation, all-profile configuration/state/skills maintenance, process scans,
|
|
fleet restart, Windows resume, dashboard deduplication and verification.
|
|
|
|
The existing per-kind restart and abort-recovery algorithms remain; transient
|
|
supervisor/process failures are real even without mixed-generation imports. Only
|
|
the purge/reload workaround and independent retry/ZIP tail compositions disappear.
|
|
Gateway exit status is written before a restart can terminate the updater's cgroup,
|
|
and is demoted on later failure. Verification publishes the final receipt.
|
|
|
|
## Parent lifecycle and failures
|
|
|
|
The parent waits and propagates the child's exact nonzero result (a signal is
|
|
mapped to shell-style 128+signal). A child cannot succeed by merely exiting zero:
|
|
a terminal response with the matching receipt identity is required. The response
|
|
returns the mutated Windows token so the parent's registered emergency resume does
|
|
not repeat completed work. Normal parent completion performs no maintenance.
|
|
|
|
The parent retains its original receipt until acknowledged child finalization;
|
|
missing/failed child output leaves it available to the existing command-boundary
|
|
failure finalizer. The stdlib bootstrap returns correlated PM failure data even
|
|
when application imports are unavailable, and normalizes negative signal exits
|
|
at each process boundary. POSIX completion owns a new session/process group;
|
|
cancellation kills that group before releasing the lock (Windows uses the retained
|
|
child's `taskkill /T` tree). The parent records the pending fleet obligation before
|
|
starting the completion process, including when preparation cannot begin. The parent's emergency Windows resume remains a last-resort
|
|
lifecycle obligation when the child cannot execute or is killed. A failed child
|
|
never clears the pending fleet obligation. No automatic code rollback after
|
|
maintenance has begun (SQLite snapshots remain file-loss recovery, not rollback).
|
|
|
|
## Historical surface
|
|
|
|
All names frozen from the complete reachable shipped updater history stay
|
|
resolvable. Historical dependency hooks retain the stdlib-only takeover bridge:
|
|
the old parent waits, carries receipt/recovery state and never resumes a retired
|
|
installer. Newly retired preparation and module-reload hooks explicitly marked
|
|
incomplete stop nonzero and request `hermes update` again; they cannot manufacture
|
|
a missing completion request. Current Git/current/ZIP callers use only the
|
|
canonical completion transport, not the historical takeover entrypoint.
|
|
Unfrozen branch-only retry compositions are deleted, not shimmed. ACP convenience
|
|
publication uses the launcher owner's `expose_cli`; the historical ACP entry is
|
|
only an adapter, never a second writer. The frozen set is never trimmed or replaced
|
|
with tag-only coverage. New current-path imports are unioned with that history.
|
|
|
|
## Verification
|
|
|
|
Use isolated homes, disposable Git repositories and fake dependency/build/service
|
|
adapters only. Exercise an old process with cached incompatible modules across a
|
|
real Git transition to new code, selected-Python execution, receipt identity and
|
|
snapshot transfer, nonzero/abrupt child exit, lock release and Windows-token
|
|
return. Focused existing tests cover dirty ZIP checks/grafts, snapshots, fleet
|
|
reconciliation, supervisor timing and historical imports. Native service restart
|
|
and Windows/macOS acceptance remain separate required lanes; no live user service
|
|
or user state is touched by this implementation's test runs.
|