feat(agent): run agent.update and agent.restart one time only - #34
Merged
Merged
Conversation
nabil1440
added this pull request to stack #38
September 22, 2026 10:40
- Poll GET /agent/v1/commands after each report, and run the new commands one at a time, oldest first. Send the results at once. - Keep a list of the commands that ran (ran.json, 48 hours) and skip them: the poll sends each open command again until its result arrives. - agent.restart: record the command, then exit; systemd starts the agent again, and the new process sends command.completed. - agent.update: skip the download when the agent already runs the target (or a newer release). Else download the archive next to the binary, compare its sha256, and put the new binary in place with a rename. A failure sends command.failed and keeps the old binary. After the exit, the new process compares its version with the target and sends the result. - A dev tag (v0.2.0-dev.<sha>) matches only the same tag: dev tags have no order. - Do not run an unknown verb; send command.unknown. - Move the update code of fly update to internal/release, and add Download and Install for the agent. - README: the contract pin line and the monitoring agent section. Refs #29
… safely Fixes from the adversarial review of this layer. - agent.update skips the download only when the agent runs exactly the target version. Before, an older target reported command.completed and installed nothing, so a rollback looked done. The control plane decides the version; after the update, a newer release still completes it. - An update download follows a redirect only to https (or loopback). - At start, remove downloads that a crash left next to the binary, when they are older than one hour. - Make the new binary executable through the open file, not through its path: the directory can belong to an other user. Sync the binary and the directory, so a power loss cannot leave an empty binary. Refs #29
Maintainer decision: when the agent already runs the target version or a
newer one, it does not update.
- The same version sends command.completed, as before.
- An older target sends command.failed with the reason ("the agent runs
v0.2.1, newer than v0.2.0; it does not downgrade"), so the control plane
sees that its version was not installed. A bad release is fixed with a
newer release; an older version needs the install job.
- Versions compare with semver. Two dev tags of one release
(v0.2.0-dev.<sha>) have no order, and a version that is not semver has no
order: then only the exact version skips the update.
- The new process after an update uses the same comparison for its result.
Refs #29
nabil1440
force-pushed
the
agent/29-commands
branch
from
September 24, 2026 08:09
a2858a8 to
925b69b
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Layer 4 of 7 of the monitoring agent (#31 → #37).
Summary
Change
internal/agent/commands.go: the poll, the list of the commands that ran (ran.json, 48 hours),agent.restart,agent.updateandcommand.unknown.internal/release: the update code offly updatemoved here frominternal/utils, withDownload(https, sha256, size limit) andInstall.Adversarial review
The first version was refuted. These items are fixed in this PR:
agent.updatenever downgrades (maintainer decision). The same version sendscommand.completed. An older target sendscommand.failedwith the reason, so the control plane sees that its version was not installed. A bad release is fixed with a newer release.Tests
testing/synctest: a restart runs one time also when the command stays open, no downgrade (release, dev tag), an update from an older or unordered version, a failed update, the result from the new process, an unknown verb, a list that cannot be saved.command.completed.Closes #29