Skip to content

feat: Add start utilities - #9

Merged
nfebe merged 1 commit into
mainfrom
agent-autostart
Sep 28, 2026
Merged

nfebe merged 1 commit into
mainfrom
agent-autostart

Conversation

@nfebe

@nfebe nfebe commented Sep 28, 2026

Copy link
Copy Markdown
Contributor

Any command that needs the agent starts one, on the next free port when something else holds the usual one, and writes that address down so later commands and the view agree on it. Setup starts what it installed. Status and stop start nothing.

sourceant update replaces this command, the agent and the core, or the parts named. Nothing is written until its checksum matches the release it came from, and a replacement is renamed over the old file, so an interrupted update leaves a working install. A machine already on a prerelease follows prereleases, which is what the beta releases need.

A command that reads from the agent starts one where nothing answers, on the
next free port when something else holds the usual one, and writes the address
it got down so later commands and the view agree on it. Setup starts what it
installed. Asking whether it runs, and stopping it, start nothing.

sourceant update replaces this command, the agent and the core, or the parts
named, from the releases each is published in. Nothing is written until its
checksum matches the release it came from, and a replacement is renamed over
the old file, so an interrupted update leaves a working install. A machine
already on a prerelease follows prereleases.

@sourceant sourceant Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

[error] internal/command/lifecycle.go:96 (semgrep dangerous-exec-command): Detected non-static command inside Command. Audit the input to 'exec.Command'. If unverified user data can reach this call site, this is a code injection vulnerability. A malicious actor can inject a malicious script to execute arbitrary code.

@sourceant

sourceant Bot commented Sep 28, 2026

Copy link
Copy Markdown

Code Review Summary

Commands needing the agent now start one themselves, falling back to the next free port and persisting that address to ~/.sourceant/config.json; setup starts what it installed, while status and stop start nothing. A new update command replaces the CLI, agent and core, verifying each checksum and renaming replacements over the old files, and follows prereleases on prerelease installs. Tests cover internal/update.

🚀 Key Improvements

  • Any command needing the agent starts it, retrying on the next free port and persisting the address.
  • sourceant update [cli|agent|core] verifies checksums and renames replacements atomically, keeping a working install.
  • Tests confirm mismatched or missing checksums refuse the update; stable releases are preferred over prereleases.

📉 Regressions

  • Auto-start is bounded by the HTTP client timeout, so a first run that builds a core can time out early.

🚨 Critical Issues

  • [error] internal/command/lifecycle.go:96 (semgrep dangerous-exec-command): Detected non-static command inside Command. Audit the input to 'exec.Command'. If unverified user data can reach this call site, this is a code injection vulnerability. A malicious actor can inject a malicious script to execute arbitrary code.

@nfebe
nfebe merged commit a8386ea into main Sep 28, 2026
3 checks passed
@nfebe
nfebe deleted the agent-autostart branch September 28, 2026 11:39
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant