Skip to content

fix: reject overlapping binary upgrades - #278

Draft
cookerpapa wants to merge 1 commit into
boldsoftware:mainfrom
cookerpapa:fix/prevent-concurrent-upgrades
Draft

cookerpapa wants to merge 1 commit into
boldsoftware:mainfrom
cookerpapa:fix/prevent-concurrent-upgrades

Conversation

@cookerpapa

Copy link
Copy Markdown

Fixes #238.

Manual and automatic upgrades call the same VersionChecker.DoUpgrade method, but nothing prevents two calls from downloading and replacing the binary concurrently. Both replacement paths use fixed temporary/backup names.

Add a dedicated upgrade mutex and reject overlapping calls with upgrade already in progress. Hold the guard for the entire attempt, including the permission fallback, and release it on every return so failed attempts can be retried. Keep version-cache locking separate.

Add two deterministic HTTP regression cases that overlap requests during checksum retrieval and binary download. They also verify that cached version checks still work and that an attempt can be retried after failure. Coordination uses channels, with no sleeps.

Validation on Linux / Go 1.27.1:

  • Both new cases fail on unchanged production code and pass with the guard.
  • go test ./server -run '^TestDoUpgrade' passes, as does the same selection with -race.
  • The UI build and go build -o bin/shelley ./cmd/shelley pass.
  • The full go test ./server run stops in terminal initialization because this environment lacks /proc/self/exe. The same failure reproduces with unchanged production code in TestBtwSlashHookRouting; full-suite validation remains pending.

The regression server deliberately fails downloads before binary replacement. No installed binary was upgraded or removed.

@cla-bot

cla-bot Bot commented Sep 11, 2026

Copy link
Copy Markdown

We require contributors to sign our Contributor License Agreement, and we don't have you on file. In order for us to review and merge your code, please contact @crawshaw at david@bold.dev to get yourself added.

@philz

philz commented Sep 17, 2026

Copy link
Copy Markdown
Contributor

Hi!

This seems fine but we need a CLA signed. I think you can now do it online at https://shelley-cla.exe.xyz

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Fix race condition in shelley manual update path causing binary removal

2 participants