Merge CB-600: make installing the launchd agent safe
Three gaps that only bite once the agent is loaded, plus one wrong comment. The script computed its log path from its own location while the plist hard-codes one. Run from a different checkout, every post-restart check would read the wrong file and report a clean restart while the daemon crash-looped. It now compares the two and fails, not warns. A failed 'launchctl load' after a successful 'unload -w' left the agent stopped AND persistently disabled - worse than before the redeploy. It now retries once, then dies naming the exact recovery command. The plist now says plainly that ThrottleInterval paces restarts but does not bound them, and what actually stops the loop. Verified here: ran the script with --check from the merged tree and it behaves exactly as before, so the unsupervised path - my only restart route - is intact. Exercised the log-path check against match, mismatch and missing-plist fixtures using a truncated copy with no mutating code in it: ok/1/1. 829 tests BUILD SUCCESS. Closes #91
This commit is contained in:
@@ -555,7 +555,10 @@ public final class Bridged {
|
||||
* where set (opt-in). Derived from the config, not hard-coded, so a new profile is covered for
|
||||
* free. A var required by more than one profile is one entry naming every profile that needs
|
||||
* it. Deliberately excludes {@code auth.tokenEnv}: that one is already enforced loudly, by a
|
||||
* startup throw, a few lines above this method's call site.
|
||||
* startup throw in {@code main()} — about 370 lines <em>below</em> this method's call site
|
||||
* ({@link #reportRequiredSecrets(BridgedConfig)}), not a few lines above it. That throw only
|
||||
* fires when {@code auth.mode: token} is configured; under the default loopback-trust mode it
|
||||
* never runs, and {@code auth.tokenEnv} is simply not required.
|
||||
*
|
||||
* <p>Package-private and pure (no I/O, no logging) so the derivation is unit-testable without
|
||||
* capturing log output; {@link #reportRequiredSecrets(BridgedConfig)} is the logging caller.
|
||||
|
||||
Reference in New Issue
Block a user