Skip to content

fix update rollback and archive on installer installs - #3278

Open
kevinjosethomas wants to merge 62 commits into
mainfrom
lane/installer-rollback-archive
Open

kevinjosethomas wants to merge 62 commits into
mainfrom
lane/installer-rollback-archive

Conversation

@kevinjosethomas

@kevinjosethomas kevinjosethomas commented Oct 1, 2026 •

Copy link
Copy Markdown
Member
  • prime-agent update --rollback now brings back the version the last update replaced, and running it again undoes that.
  • prime-agent update --archive now installs a local release file instead of failing with a confusing error.

Note

High Risk
Changes self-update and installer publish/rollback paths (including Windows handoff and bundled script execution), where mistakes can brick installs or leave machines without a working launcher.

Overview
Installer-owned installs can now use prime-agent update --rollback and update --archive <path> without the managed-install flow. When the running binary lives under a marked installer payload, the CLI runs the install-rust.sh copy bundled in the binary against that prefix via new installer_update::run_local, with stricter flag rules (--source, channel flags, and --force are rejected for these local operations). --archive no longer requires --source at parse time; managed installs still require --source when they take the archive path.

install-rust.sh gains --rollback and --archive, a generations record (plus prime-agent.old fallback for legacy install.ps1), archive name vs payload --version checks, synchronous PRIME_AGENT_*_CHECK pre-flights, publish-window interrupt recovery, and Windows parent-wait / trusted tasklist behavior. pa-core adds run_bundled_installer, installer-prefix detection, PS1-era marker encoding handling, and stdin-based installer execution (with a Windows detached handoff when the running exe locks the payload). Help text and install.ps1 marker writes are aligned; e2e tests cover archive/rollback swaps, check modes, and refusals.

Reviewed by Cursor Bugbot for commit c040ac7. Bugbot is set up for automated code reviews on this repo. Configure here.

Note

Fix update --rollback and update --archive for installer-owned installs

  • Adds a local update path that runs the installer script bundled into the binary against the running install prefix, so prime-agent update --rollback and prime-agent update --archive <path> work on installer installs (installer_update.rs, installer.rs)
  • The installer script install-rust.sh now accepts --rollback (restores the newest retained generation) and --archive <path> (installs a local platform archive), validates payloads before publication, and cleans staging on failure
  • --archive no longer requires --source at parse time; the source requirement now applies only to managed installs. Source, channel, and --force flags are rejected for local installer operations (public_command.rs)
  • On Windows, when the running executable is the locked payload, the CLI runs a synchronous preflight, hands publication to a detached installer child, and does not report a version
  • Adds end-to-end tests covering archive install, rollback swaps, check mode, mismatched payload versions, and session preservation (installer_update_e2e.rs)
  • Behavioral Change: update help text and failure wording change (nonzero exit now says the current install was kept); --archive without --source now parses where it previously failed

Changes since #3278 opened

  • Changed probe state file locations and version verification logic in install-rust.sh [c60c173]
  • Wrapped version probe and payload-reported-version validation logic in a conditional guard that executes only when MODE is not 'archive' [1570510]
  • Added exit status validation for payload version probe [a356aab]
  • Modified interrupt signal handler cleanup behavior [a356aab]
  • Relocated stage variable initialization relative to EXIT trap [a356aab]
  • Added ulimit -f 64 file size constraint to the version probe runner subshell in install-rust.sh [6fa03ee]
  • Unset PI_PACKAGE_DIR environment variable in the backgrounded runner subshell before invoking the staged binary with --version [006b39e]
  • Guarded ulimit -f 64 command in probe-runner subshell with stderr redirection and failure tolerance [ecc75fd]
  • Removed conditional compilation gate from test module declaration [68e42ef]
  • Set new process group for child installer process on Windows handoff path [bd00792]
  • Modified install-rust.sh rollback mode to recognize and use an unsuffixed rollback slot at ${PREFIX}/share/prime-agent.old as a fallback source when no recorded generation is available [762fefe]
  • Added update_rollback_reads_the_unsuffixed_installer_slot end-to-end test to verify rollback behavior for Windows-native installer scenarios [762fefe]
  • Added marker_text helper function to normalize marker file encoding and modified rollback logic to parse marker files through this helper, stripping NULs and removing leading BOM for UTF-8 or UTF-16 byte orders before validating the ps1_slot marker and extracting CHANNEL and VERSION values [108740a]
  • Modified marker file write operation to explicitly specify ASCII encoding without BOM [108740a]
  • Added validation guard that rejects resolved PREFIX paths containing newline characters [108740a]
  • Modified PREFIX path resolution to append and remove a sentinel character 'X' during command substitution [8d9db5f]
  • Modified rollback handler to apply marker_text normalization when verifying recorded installation generations [8d9db5f]
  • Fixed installer marker file parsing to handle UTF-16 and BOM-prefixed encodings [597d392]
  • Removed trailing carriage return from version verification in installer script [597d392]
  • Added Windows parent process synchronization to prevent installer execution while parent holds locks [eba95ef]
  • Normalized version string handling in archive mode to accept versions with leading 'v' prefix [eba95ef]
  • Changed carriage return stripping in version probe to use escaped form [eba95ef]
  • Modified install-rust.sh to use trusted tasklist.exe from SystemRoot/System32 or MSYS /c/Windows/System32 for Windows parent-wait and publication lock liveness checks, skipping checks entirely when tasklist.exe cannot be found [a5d4d74]
  • Refactored update.installer module functions run_installer_from, run_bundled_installer, and execute_script to execute installer scripts via stdin using open file handles instead of passing script file paths as arguments [a5d4d74]
  • Modified update.installer.local_mode_preflight Windows function to accept &std::fs::File instead of &Path and execute preflight script via stdin using cloned file handle [a5d4d74]
  • Updated update.installer.fetch_script and update.installer.write_script functions to return both temp file path and open file handle as tuple [a5d4d74]
  • Added std::io::Seek, SeekFrom, and Write trait imports to update.installer module to support handle-based script execution with file position rewinding [a5d4d74]
  • Implemented publish window restoration mechanism to prevent data loss during installer interrupts [c040ac7]
  • Modified Python and uv installation logic to skip setup on Windows in non-channel modes [c040ac7]
  • Added publish window state tracking to enable rollback restoration [c040ac7]

Macroscope summarized 7c5525f.

Comment thread install-rust.sh

@cursor cursor Bot left a comment •

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Stale Bugbot comment from a previous run.

Comment thread install-rust.sh

@cursor cursor Bot left a comment •

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Stale Bugbot comment from a previous run.

Comment thread install-rust.sh

@cursor cursor Bot left a comment •

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Stale Bugbot comment from a previous run.

Comment thread install-rust.sh Outdated
@snimu

snimu commented Oct 1, 2026

Copy link
Copy Markdown
Contributor

The logic matches TS and looks right, but the rebase over #3253 isn't mechanical: channel resolution moved before the Python bootstrap and the PREFIX realpath, so the single if MODE=channel wrapper and the rollback-source read (needs the realpath'd PREFIX) have to be re-derived as two guarded regions.

Also the new argument parser drops main's --force (and run_local never forwards it) — there's a concurrent fix in flight redefining --force semantics, so please coordinate before re-adding.

[written by prime-agent, reviewed by snimu]

@sethkarten
sethkarten self-requested a review October 1, 2026 22:51
sethkarten
sethkarten previously approved these changes Oct 1, 2026
@kevinjosethomas
kevinjosethomas enabled auto-merge (squash) October 2, 2026 00:42
Comment thread crates/pa-core/src/update/installer.rs Outdated
Comment thread install-rust.sh

@cursor cursor Bot left a comment •

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Stale Bugbot comment from a previous run.

Comment thread crates/pa-cli/src/public_command.rs Outdated
Comment thread crates/pa-cli/src/public_command.rs
Comment thread crates/pa-cli/src/installer_update.rs

@cursor cursor Bot left a comment •

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Stale Bugbot comment from a previous run.

Comment thread crates/pa-daemon/src/worker/turn_stream_tests.rs Outdated

@cursor cursor Bot left a comment •

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Stale Bugbot comment from a previous run.

Comment thread crates/pa-core/src/update/installer.rs

@cursor cursor Bot left a comment •

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Stale Bugbot comment from a previous run.

Comment thread install-rust.sh
Comment thread install-rust.sh Outdated
Comment thread install-rust.sh
Comment thread install-rust.sh

@cursor cursor Bot left a comment •

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Stale Bugbot comment from a previous run.

Comment thread install-rust.sh

@cursor cursor Bot left a comment •

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Stale Bugbot comment from a previous run.

Comment thread crates/pa-core/src/update/installer.rs
Comment thread install-rust.sh

@cursor cursor Bot left a comment •

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Stale Bugbot comment from a previous run.

Comment thread install-rust.sh
Comment thread crates/pa-core/src/update/installer.rs
Comment thread crates/pa-core/src/update/installer.rs
Comment thread crates/pa-core/src/update/installer.rs Outdated

@cursor cursor Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes and found 2 potential issues.

Fix All in Cursor

❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.

Reviewed by Cursor Bugbot for commit 7c5525f. Configure here.

Comment thread install-rust.sh
Comment thread install-rust.sh

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants