feat(update): keep the monitoring agent correct after fly update - #35
Merged
Merged
Conversation
nabil1440
added this pull request to stack #38
September 22, 2026 10:40
nabil1440
force-pushed
the
agent/30-update
branch
from
September 22, 2026 11:03
13fe692 to
cefb95e
Compare
- After fly update replaces the binary, restart fly-agent when the server has the agent. The agent then runs the new binary at once. - When fly is already up to date but the agent still runs a replaced binary (the kernel shows it as "(deleted)"), restart the agent. - Keep the owner of the old binary: sudo fly update no longer gives the agent's binary in ~fly/.fly/bin to root. - Without --yes and without a terminal, stop with an error (exit 1). A script no longer reads "Update cancelled." as success. - Add internal/service for the systemd unit of the agent. Refs #30
…tl errors Fixes from the adversarial review of this layer. - Give the new binary its owner through the open file (fchown), not its path. The folder of the agent's binary belongs to the server user, who could put a link to a root file (for example /etc/shadow) in place of the temporary file, and root would then give that file to the user. - A systemctl failure now shows its message. Before, fly update exited 1 with no message, because the wrapped exit status looked like the error of a child process that had already reported it. - Restart the agent with try-restart: an agent that an administrator stopped stays stopped. - An agent process that ends during the check is not stale. - Wait up to 2 minutes for systemctl, longer than the stop timeout of systemd. - CI runs the tests that need root (the owner and the link attack). Refs #30
nabil1440
force-pushed
the
agent/30-update
branch
from
September 24, 2026 08:09
cefb95e to
f65867c
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Layer 5 of 7 of the monitoring agent (#31 → #37).
Summary
fly updatestays. When the server has the latest release, it does nothing.fly updaterestarts the agent, so the agent uses the new binary at once. If the agent still uses an old binary,fly updaterestarts it.--yesand without a terminal gets an error, not a false success.Change
internal/service: the unit of the agent (try-restart, and a check for a replaced binary).internal/release: the new binary keeps the owner of the old binary.cmd/version.go: the restart after an update, and the terminal check.sudo.Adversarial review
The first version was refuted. These items are fixed in this PR:
systemctlfailure shows its message. Before,fly updateexited 1 with no message.try-restart: an agent that an administrator stopped stays stopped.systemctlis 2 minutes.Tests
systemctl, the error messages through the exit code, and the terminal check.Closes #30