Files
gbrain/test/autopilot-self-upgrade.test.ts
T
a57d98b813 v0.42.12.0 feat: self-upgrading gbrain — invocation-riding update check + opt-in auto-upgrade (#1798)
* feat(self-upgrade): decision/cache/snooze foundation + atomic binary self-update

Pure decideSelfUpgrade (invocation + autopilot channels), atomic untrusted
cache + escalating snooze + shared marker grammar (forged-marker rejection),
semver helpers, and real darwin-arm64/linux-x64 binary self-update
(download -> fsync -> smoke -> atomic rename; failure leaves old binary intact).
Tests incl. real-HTTP-server swap E2E.

* feat(self-upgrade): check-update cache/markers, self-upgrade command, CLI heartbeat hook

check-update gains gstack-style cache/snooze/markers + refreshUpdateCache +
exported fetchLatestRelease. New 'gbrain self-upgrade' command. cli.ts emits the
update marker on every invocation (cache-read-only hot path, detached
single-flight refresh, skip-set + recursion guard + NODE_ENV=test gate).

* feat(self-upgrade): autopilot silent channel, doctor check, runPostUpgrade setup, config + identity marker

autopilot opt-in silent channel (auto+quiet+idle, swap-only+breadcrumb+exit-relaunch)
+ installSystemd Restart=always + migrateSystemdUnitToRestartAlways. doctor
self_upgrade_health. runPostUpgrade applySelfUpgradeSetup (one-time consent +
systemd rewrite). init defaults mode=notify. config self_upgrade plane +
KNOWN_CONFIG_KEYS. get_brain_identity carries update marker.

* docs(self-upgrade): gbrain-upgrade agent skill, RESOLVER/manifest, auto-update doc reversal, HEARTBEAT

New skills/gbrain-upgrade agent flow (mirror gstack-upgrade) wired into RESOLVER +
manifest. upgrades-auto-update.md reversed to document opt-in auto + conservative
gates. HEARTBEAT self-upgrade --check-only line. llms-full regenerated.

* chore: bump version and changelog (v0.42.12.0)

Self-upgrading gbrain: invocation-riding update marker + opt-in autopilot
silent channel + real atomic binary self-update. Mirrors gstack's mechanism.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* fix(self-upgrade): write just-upgraded-from breadcrumb + clear stale cache after upgrade

Codex ship-review P3: the CLI startup hook reads just-upgraded-from to print the
one-time JUST_UPGRADED confirmation, but nothing wrote it — dead path. runUpgrade
now writes the breadcrumb (covers full + --swap-only) and clears the update-check
cache + snooze so a now-applied 'upgrade available' marker stops nudging.

* feat(self-upgrade): surface what's-new in notify + wire agent integration (AGENTS.md, HEARTBEAT) + e2e

- self-upgrade --check-only --json now includes changelog_diff + release_url
  (export fetchChangelog); the gbrain-upgrade skill shows 3-5 what's-new bullets
  before the 4-option prompt instead of just version numbers.
- setup injects a self-upgrade marker protocol into AGENTS.md so interactive
  agents (Claude Code, Codex) act on the UPGRADE_AVAILABLE stderr marker — the
  piece that makes notify actually fire for them.
- HEARTBEAT daily beat routes through the gbrain-upgrade skill (OpenClaw/Hermes
  cron cadence); auto-mode daemons ride the autopilot tick.
- e2e: real subprocess invocation proves the marker fires (notify emits;
  off/snooze/up-to-date silent; JUST_UPGRADED fires+clears; --quiet suppresses).
  Serial test: --check-only surfaces the changelog.

---------

Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-03 06:20:03 -07:00

44 lines
2.1 KiB
TypeScript

import { describe, expect, test } from 'bun:test';
import { readFileSync } from 'node:fs';
import { join } from 'node:path';
import { generateSystemdUnit } from '../src/commands/autopilot.ts';
const AUTOPILOT_SRC = readFileSync(join(import.meta.dir, '../src/commands/autopilot.ts'), 'utf8');
describe('generateSystemdUnit', () => {
const unit = generateSystemdUnit('/home/u/.gbrain/autopilot-run.sh');
test('uses Restart=always (NOT on-failure) so a clean exit-for-relaunch respawns', () => {
expect(unit).toContain('Restart=always');
expect(unit).not.toContain('Restart=on-failure');
});
test('caps a clean-exit respawn storm with StartLimit*', () => {
expect(unit).toContain('StartLimitIntervalSec=');
expect(unit).toContain('StartLimitBurst=');
});
test('runs the given wrapper path', () => {
expect(unit).toContain('ExecStart=/home/u/.gbrain/autopilot-run.sh');
});
});
describe('autopilot self-upgrade static-shape regressions', () => {
test('supervisor-relaunch, NOT in-process re-exec (Bun has no execve) — no exec*-call', () => {
// Match call-shape, not the word (the comments legitimately say "no execve").
expect(AUTOPILOT_SRC).not.toMatch(/execve\s*\(/);
expect(AUTOPILOT_SRC).not.toMatch(/execvp\s*\(/);
});
test('the silent channel does swap-only, never a blocking full post-upgrade in the tick', () => {
expect(AUTOPILOT_SRC).toContain("execSync('gbrain upgrade --swap-only'");
// The tick must not invoke the (up-to-30-min) post-upgrade inline.
expect(AUTOPILOT_SRC).not.toContain("execSync('gbrain post-upgrade'");
});
test('boot reconciles the breadcrumb and the tick attempts the channel', () => {
expect(AUTOPILOT_SRC).toContain('reconcileSelfUpgradeAtBoot()');
expect(AUTOPILOT_SRC).toContain('attemptAutopilotSelfUpgrade(engine, engineType, lockPath)');
});
test('apply path unlinks the lock before exit so the relaunched binary does not self-exit on a stale lock', () => {
// The exit-for-relaunch block unlinks lockPath then process.exit(0).
expect(AUTOPILOT_SRC).toMatch(/unlinkSync\(lockPath\)[\s\S]{0,120}process\.exit\(0\)/);
});
});