fix update rollback and archive on installer installs - #3278
kevinjosethomas wants to merge 62 commits into
Conversation
|
The logic matches TS and looks right, but the rebase over #3253 isn't mechanical: channel resolution moved before the Python bootstrap and the PREFIX realpath, so the single Also the new argument parser drops main's [written by prime-agent, reviewed by snimu] |
…efix the record cannot hold
…ecorded marker through the normalizer
… probe report's carriage return
…fore the payload touch
There was a problem hiding this comment.
Cursor Bugbot has reviewed your changes and found 2 potential issues.
❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.
Reviewed by Cursor Bugbot for commit 7c5525f. Configure here.
…s local modes run without python

prime-agent update --rollbacknow brings back the version the last update replaced, and running it again undoes that.prime-agent update --archivenow installs a local release file instead of failing with a confusing error.Note
High Risk
Changes self-update and installer publish/rollback paths (including Windows handoff and bundled script execution), where mistakes can brick installs or leave machines without a working launcher.
Overview
Installer-owned installs can now use
prime-agent update --rollbackandupdate --archive <path>without the managed-install flow. When the running binary lives under a marked installer payload, the CLI runs theinstall-rust.shcopy bundled in the binary against that prefix via newinstaller_update::run_local, with stricter flag rules (--source, channel flags, and--forceare rejected for these local operations).--archiveno longer requires--sourceat parse time; managed installs still require--sourcewhen they take the archive path.install-rust.shgains--rollbackand--archive, a generations record (plusprime-agent.oldfallback for legacy install.ps1), archive name vs payload--versionchecks, synchronousPRIME_AGENT_*_CHECKpre-flights, publish-window interrupt recovery, and Windows parent-wait / trusted tasklist behavior.pa-coreaddsrun_bundled_installer, installer-prefix detection, PS1-era marker encoding handling, and stdin-based installer execution (with a Windows detached handoff when the running exe locks the payload). Help text andinstall.ps1marker writes are aligned; e2e tests cover archive/rollback swaps, check modes, and refusals.Reviewed by Cursor Bugbot for commit c040ac7. Bugbot is set up for automated code reviews on this repo. Configure here.
Note
Fix
update --rollbackandupdate --archivefor installer-owned installsprime-agent update --rollbackandprime-agent update --archive <path>work on installer installs (installer_update.rs, installer.rs)--rollback(restores the newest retained generation) and--archive <path>(installs a local platform archive), validates payloads before publication, and cleans staging on failure--archiveno longer requires--sourceat parse time; the source requirement now applies only to managed installs. Source, channel, and--forceflags are rejected for local installer operations (public_command.rs)updatehelp text and failure wording change (nonzero exit now says the current install was kept);--archivewithout--sourcenow parses where it previously failedChanges since #3278 opened
install-rust.sh[c60c173]ulimit -f 64file size constraint to the version probe runner subshell ininstall-rust.sh[6fa03ee]PI_PACKAGE_DIRenvironment variable in the backgrounded runner subshell before invoking the staged binary with--version[006b39e]ulimit -f 64command in probe-runner subshell with stderr redirection and failure tolerance [ecc75fd]install-rust.shrollback mode to recognize and use an unsuffixed rollback slot at${PREFIX}/share/prime-agent.oldas a fallback source when no recorded generation is available [762fefe]update_rollback_reads_the_unsuffixed_installer_slotend-to-end test to verify rollback behavior for Windows-native installer scenarios [762fefe]marker_texthelper function to normalize marker file encoding and modified rollback logic to parse marker files through this helper, stripping NULs and removing leading BOM for UTF-8 or UTF-16 byte orders before validating the ps1_slot marker and extracting CHANNEL and VERSION values [108740a]marker_textnormalization when verifying recorded installation generations [8d9db5f]install-rust.shto use trustedtasklist.exefromSystemRoot/System32or MSYS/c/Windows/System32for Windows parent-wait and publication lock liveness checks, skipping checks entirely whentasklist.execannot be found [a5d4d74]update.installermodule functionsrun_installer_from,run_bundled_installer, andexecute_scriptto execute installer scripts via stdin using open file handles instead of passing script file paths as arguments [a5d4d74]update.installer.local_mode_preflightWindows function to accept&std::fs::Fileinstead of&Pathand execute preflight script via stdin using cloned file handle [a5d4d74]update.installer.fetch_scriptandupdate.installer.write_scriptfunctions to return both temp file path and open file handle as tuple [a5d4d74]std::io::Seek,SeekFrom, andWritetrait imports toupdate.installermodule to support handle-based script execution with file position rewinding [a5d4d74]Macroscope summarized 7c5525f.