Skip to content

Check every installer port before slow steps; rename --port to --web-port - #267

Merged
SaladDay merged 2 commits into
mainfrom
codex/install-port-preflight
Sep 30, 2026
Merged

SaladDay merged 2 commits into
mainfrom
codex/install-port-preflight

Conversation

@SaladDay

@SaladDay SaladDay commented Sep 30, 2026 •

Copy link
Copy Markdown
Collaborator

Why

A default install on a host whose port 80 was taken ran for minutes (bundle hashing, image loading) and only failed when the managed gateway tried to bind port 80. The installer checked only the Core/Web/database ports, late, and --port vs --core-port did not say which service each port belongs to.

What

  • --port is now --web-port (maps ports.web); --port no longer exists.
  • configuration.listeners(config) derives every host listener from the same addresses the Compose port mappings and native listen addresses use (Web or the managed gateway, Core, native PostgreSQL, 80/443 with managed ingress).
  • A new installation checks every listener in "Checking installation settings", before the bundle is hashed or images load:
    • an explicitly set port (flag or --config) that is taken fails fast, naming the flag/key and how to find the process;
    • an omitted Core/Web port that is taken moves to the first free port above the default (up to 20), is written to config.json and reported in the summary;
    • with managed ingress, a taken 80/443 fails fast, offering to free it or use --ingress external.
  • The probe binds with SO_REUSEADDR (no TIME_WAIT false positives); an unprivileged account that cannot bind below 1024 reads /proc/net/tcp{,6} instead.
  • oac apply checks listeners a config change adds before touching any service.
  • The bundle is hashed once per fresh install instead of twice.
  • --host must be an address of this machine; a loopback public_url port is never moved.
  • Docs: port rule in install-options.md#ports, troubleshooting rows, regenerated flag tables.

Checks

Focused checks only (installer and docs change), on 7a56199 rebased onto main 015d9f9: make check-distribution (242 installer tests, distribution manifest incl. Markdown link check, install-release, config reference) and make check-names pass. check-docs no longer exists after #269. Full make check not run (no Core/Web code touched). Blind review (fresh Claude subagent): no P0/P1; three P2 (host-only apply change unchecked, moved port vs loopback public_url, unassigned host treated as free) and five P3 fixed in 7a56199, verified by tests only.

…port

configuration.listeners derives each host listener (Web, Core, native
PostgreSQL, the managed gateway's 80 and 443) from the same helpers that
render the Compose port mappings and native listen addresses; the gateway's
ports come from ingress_config.published.

A new installation checks every listener in "Checking installation
settings", before the bundle is hashed or images load. A taken port set by
flag or in the --config file fails with the port, its owner and an ss
command. An omitted Core or Web port moves to the first free port up to 20
above its default, never onto another listener, is written to config.json
and named in the summary. Managed ingress never moves 80 or 443 and fails
fast with the --ingress external remedy. The second bundle hash under the
lock is gone.

oac apply checks each listener a change adds before touching a service and
changes nothing on a conflict; ports the installation already holds are
skipped.

The probe binds with SO_REUSEADDR, as Go and Docker listeners do. An
account that may not bind a port below 1024 reads /proc/net/tcp{,6}.
@SaladDay
SaladDay force-pushed the codex/install-port-preflight branch from 7ee32ef to 7a56199 Compare September 30, 2026 08:28
@SaladDay
SaladDay merged commit 35f019a into main Sep 30, 2026
1 check passed
- oac apply tracks the installation's own listeners by address and port. A
  changed host is probed; where the new listener overlaps an own one, the
  kernel's listening sockets decide, ignoring the installation's entries.
- The installer and apply refuse a host that is not an address of this
  machine instead of failing when a service starts.
- A Web or Core port that a loopback public_url names is never moved; a
  taken one fails, naming both settings.
- One applied_view derives the last-applied config for status, the old
  public URL probe and the listener check.
- The apply message says "Nothing was applied." before the ss command.
- The fake host models binds and the listening table, so tests run the real
  probe logic.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant