Skip to content

Report approved command launch failures accurately - #157

Merged
morgaesis merged 9 commits into
mainfrom
fix/command-launch-outcomes
Sep 10, 2026
Merged

morgaesis merged 9 commits into
mainfrom
fix/command-launch-outcomes

Conversation

@morgaesis

@morgaesis morgaesis commented Sep 10, 2026 •

Copy link
Copy Markdown
Owner

Approved commands can fail during launch and still appear as policy denials. This change separates policy decisions from execution outcomes, applies working-directory access under the intended child identity and capabilities, and retains child ownership through runtime registration and cleanup. Typed outcomes preserve unknown start state and execution failures across approval, rollback, audit and session history. Upgrade the daemon and clients together; schema 15 requires a matching pre-upgrade snapshot for rollback. See the upgrade and rollback contract.

Comment thread src/server/tests/exec_policy.rs Fixed

@postil-dev postil-dev Bot left a comment •

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

warn review incomplete · info 1 advisory finding open
1 finding posted inline

info 1 suppressed
  • Release registered ownership when spawn fails at src/server/runtime.rs:780: cites a line the named construct does not sit on; severity warn, confidence 0.94. prepare registers a state whose pending_launch flag remains true until adopt runs. If the subsequent spawn fails, the state is still held by the cleanup worker, cleanup_tick never considers it complete, and any secret_files lease remains retained indefinitely. Make failed launch handling clear the pending state and release the lease, or unregister the state before propagating the spawn error.

Review details

Comment thread src/server/admin.rs
@morgaesis
morgaesis merged commit 7147535 into main Sep 10, 2026
30 of 32 checks passed
@morgaesis
morgaesis deleted the fix/command-launch-outcomes branch September 10, 2026 10:23
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants