CB-600: make it safe to install the launchd agent #99

Closed
agent wants to merge 0 commits from worker/cb600-e6b9a9-20 into main
Member

Closes the gate on installing deploy/dev.ltms.bridged.plist as a launchd agent.

  • redeploy-bridged.sh now FAILS (not warns) a supervised restart when its computed log path disagrees with the loaded plist's StandardOutPath. Extracted as a pure, testable check_log_path_matches_plist function; the script gained a source-for-test guard (no-op on normal execution) so this is testable without installing the agent or touching launchd.
  • a failed 'launchctl load' after a successful 'unload' now retries once, and on ultimate failure tells the operator the agent is stopped AND persistently disabled plus the exact recovery command.
  • the plist now documents honestly that launchd's crash-loop retry is unbounded (ThrottleInterval only paces it to one restart per 10s) and states what actually stops it.
  • fixed the requiredSecretEnvVars javadoc: the auth.tokenEnv startup throw is ~370 lines below its call site, not a few lines above, and only fires in auth.mode: token.

Hard limits respected: did not run launchctl load/unload/bootstrap/kickstart, did not install anything to ~/Library/LaunchAgents, did not touch the live bridged daemon.

Tests: mvn -f bridged/pom.xml clean install (unpiped) -> Tests run: 824, Failures: 0, Errors: 0, Skipped: 0 -- BUILD SUCCESS.

Closes the gate on installing deploy/dev.ltms.bridged.plist as a launchd agent. - redeploy-bridged.sh now FAILS (not warns) a supervised restart when its computed log path disagrees with the loaded plist's StandardOutPath. Extracted as a pure, testable check_log_path_matches_plist function; the script gained a source-for-test guard (no-op on normal execution) so this is testable without installing the agent or touching launchd. - a failed 'launchctl load' after a successful 'unload' now retries once, and on ultimate failure tells the operator the agent is stopped AND persistently disabled plus the exact recovery command. - the plist now documents honestly that launchd's crash-loop retry is unbounded (ThrottleInterval only paces it to one restart per 10s) and states what actually stops it. - fixed the requiredSecretEnvVars javadoc: the auth.tokenEnv startup throw is ~370 lines *below* its call site, not a few lines above, and only fires in auth.mode: token. Hard limits respected: did not run launchctl load/unload/bootstrap/kickstart, did not install anything to ~/Library/LaunchAgents, did not touch the live bridged daemon. Tests: mvn -f bridged/pom.xml clean install (unpiped) -> Tests run: 824, Failures: 0, Errors: 0, Skipped: 0 -- BUILD SUCCESS.
agent added 1 commit 2026-08-16 18:09:17 +02:00
CB-600: make it safe to install the launchd agent
CI / build (pull_request) Failing after 1m21s
CI / contract (pull_request) Successful in 1m26s
cec48832be
- redeploy-bridged.sh now refuses (not warns) a supervised restart when
  its computed log path disagrees with the loaded plist's StandardOutPath
  — otherwise every post-restart check reads the wrong file and can
  report a clean restart while the daemon crash-loops. The check is a
  pure, testable function; the script gained a source-for-test guard so
  it can be exercised without installing the agent or touching launchd.
- a failed 'launchctl load' after a successful 'unload' now retries once
  and, on ultimate failure, tells the operator the agent is stopped AND
  disabled plus the exact recovery command, instead of leaving that
  silently worse than the pre-redeploy state.
- the plist documents honestly that the crash loop launchd retries is
  unbounded (ThrottleInterval only paces it), and what actually stops it.
- fixed the requiredSecretEnvVars javadoc: the auth.tokenEnv startup
  throw is ~370 lines below its call site, not a few lines above it, and
  only fires in auth.mode: token.
Owner

Merged locally into main and pushed. Gitea cannot mark a locally merged PR as merged, so I am closing it by hand — merged, not rejected. Verification is written up on the linked issue.

Merged locally into `main` and pushed. Gitea cannot mark a locally merged PR as merged, so I am closing it by hand — **merged, not rejected**. Verification is written up on the linked issue.
ltms closed this pull request 2026-08-16 18:17:56 +02:00
Some checks are pending
CI / build (pull_request) Failing after 1m21s
CI / contract (pull_request) Successful in 1m26s

Pull request closed

Sign in to join this conversation.