fix: repair legacy launcher installs whose service runs from the stable slot - #25
Merged
Merged
Conversation
…le slot A legacy two-layer installation keeps a launcher at the installed path that execs into K's stable slot artifact, so the live product process runs from slots/stable/artifact.bin. Repair asked the running product for its pid and then required that pid's executable to be the installed binary, so it failed every time with "product attestation does not identify a live installed executable" and printed only "current status couldn't be confirmed". Treat the stable and experiment slot artifacts as product executables when attesting a status-reported pid and when enumerating product processes to stop and to prove stopped before quarantine. Post-install proof (live_evidence) still requires the installed binary. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Signed-off-by: archer <archer@mail.build>
This was referenced Sep 30, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Problem
Machines with the legacy two-layer layout cannot be repaired. The installed path (
~/.local/bin/raft-computer) is an old launcher that execs into K's stable slot, so the running service's executable is~/.slock/computer/k/slots/stable/artifact.bin. The installer already classifies these installs as broken ("installed executable differs from the stable slot"), which is right. But repair then asks the running product for its pid and requires that pid's executable to be the installed binary. That check fails every time:detail.diagnostic:product attestation does not identify a live installed executableRaft Computer's current status couldn't be confirmed. Run the same command again to continue.Rerunning cannot help, because the check is deterministic. Seen on artin's machine: 3 live processes, all
/proc/<pid>/exe=slots/stable/artifact.bin; the launcher sha differs from the slot sha. A second machine has the same layout.Fix
host.rs: product executables are the installed binary plus the stable and experiment slot artifacts (both inside the installer-owned K state directory). They are used in:answer(): attesting the status-reported pid (attest_product);installed_product_processes(): the processes repair stops and must see gone before quarantine. Previously, legacy slot processes were invisible here, so the "product is still active before quarantine" proof could not see them.live_evidence(), the post-install proof, still requires the installed binary.Tests
verification/test_legacy_layout.py(native, end-to-end): install 1.0.0, replace the binary with an exec launcher into the slot, start the service, theninstall --version 1.1.0→ outcomerepaired, self-version 1.1.0, service running again.origin/main: exit 3 with exactly the field diagnostic above.host.rsunit tests: a process running from the stable slot is attested and counted as a product process; an unrelated process is not. Mutatingproduct_executablesback to the binary only fails the slot test.python scripts/verify.py: fmt, clippy, lib tests and native contract (87 tests) all pass.The new native test is in its own file because any edit to
test_native.pyis rejected by the Stamp secret scanner (an existing syntheticghp_…fixture).Not in this PR
When this failure happens, the human output does not say where the real cause is.
test_no_installer_wordingforbids naming internal concepts in human output, so that needs a product decision first.🤖 Generated with Claude Code