Skip to content

fix(installer): preserve configuration and handle failed installs safely - #719

Closed
SaladDay wants to merge 1 commit into
mainfrom
codex/installer-robustness
Closed

SaladDay wants to merge 1 commit into
mainfrom
codex/installer-robustness

Conversation

@SaladDay

Copy link
Copy Markdown
Collaborator

Repeated installer runs could reset saved settings, while interrupted downloads could overwrite the stored Compose file. The installer now preserves existing configuration by default, stages and validates updates before committing them, and verifies actual data mounts before saving newly generated secrets. Explicit installation options continue to override saved settings.

This also adds per-home installation locking, bounded downloads, failure cleanup, safe Core configuration initialization, database-aware readiness checks, and regression coverage. Operator instructions live in README; CONTRIBUTING retains the implementation contract. No product/API/schema changes or legacy runtime migration logic are included.

Validation:

  • make check-installer passes on Bash 3.2 and Compose 2.15.1: existing lifecycle checks plus 17 Python regression cases. Compose parsing is real; Docker lifecycle failures are simulated.
  • bash -n install.sh scripts/check-installer.sh and git diff --check pass.
  • Two independent blind reviews used fresh contexts and only requirements, acceptance criteria, scope, repository location and the baseline. Findings from the first review were fixed and regression-tested; the second found no blocking issues and independently reran the installer checks.
  • make check was attempted, including a reduced-concurrency retry and make -k check to exercise remaining targets. It is not green: the claudecode/claudesdk Go test processes are killed, the Claude SDK exported-runtime check fails, and the native executor does not compile on macOS (OFlags::PATH and device-ID type errors). Those files are unchanged.
  • Docker's engine is unavailable on this host. Real container startup, ownership and interruption behavior are not verified; database migration smoke tests skip. Keep this PR in draft until the full gate and real Docker installation checks pass.

@SaladDay SaladDay closed this Sep 30, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant