Skip to content

fix(host): keep the host's reason and exit code in HOST_COMMAND_FAILED - #17

Merged
xxchan merged 3 commits into
mainfrom
archer/host-command-failed-detail
Sep 29, 2026
Merged

xxchan merged 3 commits into
mainfrom
archer/host-command-failed-detail

Conversation

@xxchan

@xxchan xxchan commented Sep 29, 2026

Copy link
Copy Markdown
Member

What

botiverse/slock#8609: an in-place Computer upgrade rolled back with only experiment probe failed: HOST_COMMAND_FAILED: probe. The installer controller had written its reason to stdout ({"protocolVersion":1,"ok":false,"uncertain":false,"error":"…"}) and exited non-zero, but CommandHost::call threw away both the error text and the exit status.

Now the failure reads HOST_COMMAND_FAILED: probe (exit 3): <reason>:

  • The reason is the host's own text, reduced to one printable line of at most 240 characters with control characters replaced.
  • The reason flows unchanged into K's operation.reason and the receipt.
  • stderr stays null on purpose, because a resident child could hold a piped stderr open and hang the call.

Tests

  • New native_controller_failure_keeps_the_hosts_reason_and_exit_code: the fixture controller fails with an escape sequence and a 600-char tail. The test asserts the exit code and reason are present, no control characters remain, the message is bounded, and the error is still definite (not uncertain).
  • Mutation check (run locally): restoring the old message turns the test RED.
  • cargo test: 46 passed. cargo clippy --all-targets -D warnings and cargo fmt are clean.

Release

This needs a k-carrier 0.3.3 release plus an installer bump to reach users. The installer-side diagnostics (swallowed start error, product stderr tail kept privately) are separate, in slock task #896 (Wug).

🤖 Generated with Claude Code

archer and others added 3 commits September 29, 2026 07:26
slock#8609: an upgrade rolled back with only "experiment probe failed:
HOST_COMMAND_FAILED: probe". The installer had written its reason to stdout
({ok:false,error}), but CommandHost::call dropped it and the exit status.
Now: "HOST_COMMAND_FAILED: probe (exit 3): <reason>", with the reason
reduced to one printable line of at most 240 chars (control characters
removed). stderr stays null (a resident child could hold a pipe open).

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Signed-off-by: archer <archer@mail.build>
The reason in HOST_COMMAND_FAILED reaches the terminal and the receipt.
Replace any line that names a credential or carries URL userinfo, and
the value line after a credential key ending in ':' or '=', before the
240-character cut.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Signed-off-by: archer <archer@mail.build>
… output

A non-zero exit whose stdout is not JSON used to surface only the JSON
parse error. Report HOST_COMMAND_FAILED with the exit code instead, and
cover it plus the credential redaction end to end through the fixture.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Signed-off-by: archer <archer@mail.build>
@xxchan
xxchan merged commit 45902a6 into main Sep 29, 2026
10 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant