"""Windows gateway lifecycle for ``hermes update``: pause/resume/cold-start the service, sweep venv holders, reap orphaned backends. Split out of ``update_cmd.py``; names are re-imported there so ``hermes_cli.update_cmd.`` still resolves/monkeypatches. Origin helpers are imported lazily per function (no cycle; test patches on the origin stay effective). """ import logging from contextlib import suppress import os import subprocess import sys import time as _time from datetime import datetime from pathlib import Path from hermes_cli.update_cmd_common import _best_effort # Log-record parity with the origin module. logger = logging.getLogger("hermes_cli.update_cmd") def _write_update_planned_stop_marker(profile_path: Path, pid: int) -> bool: """Write a planned-stop marker into a specific profile home.""" try: from datetime import timezone from gateway.status import _get_process_start_time from utils import atomic_json_write record = { "target_pid": pid, "target_start_time": _get_process_start_time(pid), "stopper_pid": os.getpid(), "written_at": datetime.now(timezone.utc).isoformat(), } atomic_json_write( Path(profile_path) / ".gateway-planned-stop.json", record, indent=None, separators=(",", ":"), ) return True except (OSError, PermissionError): return False def _wait_for_windows_update_gateway_exit( pids: list[int], *, timeout: float ) -> set[int]: """Wait for the given gateway PIDs to exit, returning survivors.""" if not pids: return set() from gateway.status import _pid_exists remaining = set(pids) deadline = _time.monotonic() + max(timeout, 0.0) while remaining and _time.monotonic() < deadline: for pid in list(remaining): try: if not _pid_exists(pid): remaining.discard(pid) except Exception: remaining.discard(pid) if remaining: _time.sleep(0.25) survivors: set[int] = set() for pid in remaining: with suppress(Exception): if _pid_exists(pid): survivors.add(pid) return survivors def _self_and_non_gateway_ancestor_pids(psutil) -> set[int]: """PIDs a venv-holder scan must never nominate: this process and its non-gateway ancestry. Do NOT blanket-exclude ancestors: under ``/update`` the updater is a CHILD of the gateway, and hiding it dead-ends the update on ``venv-blocked``. Keep GATEWAY ancestors visible (the pause path stops them gracefully; a detached child survives on Windows); never nominate interactive ancestry as a blocker. """ try: from gateway.status import looks_like_gateway_command_line as _is_gw except Exception: _is_gw = None skip: set[int] = {os.getpid()} with suppress(Exception): for anc in psutil.Process().parents(): try: anc_cmdline = " ".join(anc.cmdline() or []) except Exception: anc_cmdline = "" if _is_gw is not None and anc_cmdline and _is_gw(anc_cmdline): continue skip.add(int(anc.pid)) return skip def _lower_dir_prefix(path: Path) -> str: """``str(path)`` lower-cased with one trailing separator, resolved when possible (prefix matching).""" try: raw = str(path.resolve()) except OSError: raw = str(path) return raw.lower().rstrip(os.sep) + os.sep def _detect_venv_python_processes( *, exclude_pids: set[int] | None = None ) -> list[tuple[int, str, str]]: """Live processes running from the project venv's interpreter as ``(pid, name, cmdline)``; never raises. The hermes.exe shim guard misses the Desktop backend and anything off ``venv\\Scripts\\python(w).exe``; they keep ``.pyd`` files mapped so a mid-update dependency sync dies half-way. Killing is pointless (Desktop respawns its backend) so callers should refuse. Empty off-Windows / without psutil; self+ancestors excluded. """ from hermes_cli.update_cmd import _m if not _m()._is_windows(): return [] try: import psutil except Exception: return [] venv_prefix = _lower_dir_prefix(_m().PROJECT_ROOT / "venv") root_prefix = _lower_dir_prefix(_m().PROJECT_ROOT) skip: set[int] = set(exclude_pids or set()) skip |= _self_and_non_gateway_ancestor_pids(psutil) matches: list[tuple[int, str, str]] = [] try: # cmdline/cwd are expensive per-process on Windows (500+ procs can blow the # Desktop preflight watchdog): fetch them lazily for plausible candidates only. proc_iter = psutil.process_iter(["pid", "exe", "name"]) except Exception: return [] for proc in proc_iter: try: info = proc.info except Exception: continue pid = info.get("pid") exe = info.get("exe") if not exe or pid is None or int(pid) in skip: continue try: exe_norm = str(Path(exe).resolve()).lower() except (OSError, ValueError): exe_norm = str(exe).lower() # Primary match: exe lives under this venv (desktop backend / gateway case). is_holder = exe_norm.startswith(venv_prefix) name = str(info.get("name") or Path(exe).name) name_low = name.lower() if not is_holder and not ( name_low.startswith(("python", "pypy")) or name_low in {"uv.exe", "uvx.exe", "hermes.exe"} ): continue try: cmdline_raw = " ".join(proc.cmdline() or []) except Exception: cmdline_raw = "" cmdline_low = cmdline_raw.lower() # Fallback: uv/base-interpreter trampolines have an exe OUTSIDE the venv yet hold # its .pyd files — match cmdline (venv path, or `-m hermes_cli.main` + root/cwd). if not is_holder and venv_prefix in cmdline_low: is_holder = True if not is_holder and "hermes_cli.main" in cmdline_low: try: cwd_low = str(proc.cwd() or "").lower().rstrip(os.sep) + os.sep except Exception: cwd_low = os.sep if root_prefix in cmdline_low or cwd_low.startswith(root_prefix): is_holder = True if not is_holder: continue name = info.get("name") or Path(exe).name # FULL cmdline: callers parse it (pausable-gateway exemption looks for `gateway run`); # truncating here misreported autostarted gateways as blockers. Truncate at display time. matches.append((int(pid), str(name), cmdline_raw)) return matches _HOLDER_VALUE_FLAGS_FALLBACK = frozenset( { "--profile", "-p", "--config", "--model", "-m", "--provider", "--reasoning", "--toolsets", "-t", "--skills", "-s", "--continue", "-c", "--resume", "-r", "--oneshot", "-z", "--in", "--usage-file", } ) _holder_value_flags_cache: frozenset | None = None def _holder_value_flags() -> frozenset: """Top-level CLI flags that consume a value, introspected from the REAL parser (nargs != 0); cached per process. Derived so the holder classifier can't drift from argparse (a handwritten subset misparsed ``--reasoning high serve``). Pre-argparse profile selectors are added explicitly (stripped before argparse sees argv). Falls back to a static snapshot when the parser can't import — the updater must classify holders even on a broken tree. """ global _holder_value_flags_cache if _holder_value_flags_cache is not None: return _holder_value_flags_cache flags: set[str] = {"--profile", "-p", "--config"} try: from hermes_cli._parser import build_top_level_parser parser = build_top_level_parser()[0] for action in parser._actions: if action.option_strings and action.nargs != 0: flags.update(action.option_strings) _holder_value_flags_cache = frozenset(flags) except Exception: _holder_value_flags_cache = _HOLDER_VALUE_FLAGS_FALLBACK return _holder_value_flags_cache def _hermes_holder_subcommand(cmdline: str) -> str | None: """The actual Hermes SUBCOMMAND a venv-holder argv runs, or None (callers must NOT guess a label). Token-based, never substring (``kanban --preserve-cache`` contains "serve"): find the ``hermes_cli.main`` / ``hermes(.exe)`` entry token, return the first following token that isn't a flag or a flag's value. """ try: import shlex tokens = shlex.split(cmdline, posix=False) except Exception: tokens = cmdline.split() entry_idx: int | None = None for i, token in enumerate(tokens): low = token.lower().strip('"') if low.endswith("hermes_cli.main") and i > 0 and tokens[i - 1] == "-m": entry_idx = i break base = low.rsplit("\\", 1)[-1].rsplit("/", 1)[-1] if base in ("hermes", "hermes.exe"): entry_idx = i break if entry_idx is None: return None value_flags = _holder_value_flags() i = entry_idx + 1 while i < len(tokens): token = tokens[i] if token in value_flags or token.split("=", 1)[0] in value_flags: # --flag value consumes two tokens; --flag=value consumes one. i += 1 if "=" in token else 2 continue if token.startswith("-"): i += 1 continue return token.lower() return None def _format_venv_python_holders_message(matches: list[tuple[int, str, str]]) -> str: """Explain which venv processes block the update and how to clear them. Labels come from the parsed SUBCOMMAND, never substring: a standalone ``hermes dashboard`` must not be called the Desktop backend, ``--preserve-cache`` must not match "serve". Unknown argv gets no hint. """ lines = ["✗ Other Hermes processes are running from this install's venv:"] hint_by_subcommand = { "serve": " ← Hermes backend (if the Desktop app is open, close it)", "dashboard": " ← hermes dashboard (stop it: hermes dashboard stop, or close that terminal)", "gateway": " ← gateway", } for pid, name, cmdline in matches[:6]: sub = _hermes_holder_subcommand(cmdline) hint = hint_by_subcommand.get(sub or "", "") lines.append(f" PID {pid} {name} {cmdline[:120]}{hint}") if len(matches) > 6: lines.append(f" ... and {len(matches) - 6} more") lines.append("") lines.append(" On Windows these keep native extension files (.pyd) locked, so the") lines.append(" dependency update would fail partway and leave a broken install.") lines.append(" Close the Hermes desktop app / other Hermes terminals, then re-run:") lines.append(" hermes update") lines.append(" (or use `hermes update --force-venv` to proceed anyway at your own risk)") return "\n".join(lines) def _venv_launcher_ancestors(pids: list[int]) -> list[int]: """Venv-interpreter parents of *pids* that hold the install open; never raises. A shim-started gateway is a chain: ``venv\\Scripts\\python.exe`` launcher (keeps ``.pyd`` mapped) -> uv CPython worker (writes the PID file). The pause set sees the worker, the venv scan sees the launcher, so a paused gateway still tripped the guard. One hop up only, venv-prefixed only (bounds blast radius). """ from hermes_cli.update_cmd import _m if not _m()._is_windows() or not pids: return [] try: import psutil except Exception: return [] venv_prefix = _lower_dir_prefix(_m().PROJECT_ROOT / "venv") skip = _self_and_non_gateway_ancestor_pids(psutil) found: list[int] = [] for pid in pids: try: parent = psutil.Process(int(pid)).parent() except Exception: continue if parent is None: continue ppid = int(parent.pid) if ppid in skip or ppid in found or ppid in set(pids): continue try: exe = (parent.exe() or "").lower() except Exception: continue if exe.startswith(venv_prefix): found.append(ppid) return found def _leftover_pausable_gateway_pids( matches: list[tuple[int, str, str]], ) -> list[int] | None: """PIDs from *matches* when EVERY remaining venv holder is a pausable gateway, else ``None`` (keep refusing). A gateway respawned inside the pause->guard window (or via an unmapped spawn path) still holds ``.pyd`` files. Uses the Desktop preflight's ``_is_pausable_gateway`` so exemption and tolerance cannot drift; live argv is re-read via psutil when possible since the scan may hold only a cmdline prefix. """ from hermes_cli._scan_venv_blockers import _is_pausable_gateway try: import psutil # type: ignore except Exception: psutil = None pids: list[int] = [] for pid, _name, cmdline in matches: argv = cmdline if psutil is not None: with suppress(Exception): argv = " ".join(psutil.Process(int(pid)).cmdline()) or cmdline if not _is_pausable_gateway(argv): return None pids.append(int(pid)) return pids def _refuse_gateway_ancestor_tree_kill( pids: list[int], *, gateway_mode: bool ) -> bool: """Refuse a plain Windows update that would tree-kill its own ancestry. A chat agent running plain ``hermes update`` is a child of the gateway; ``taskkill /T /F`` on it kills the updater first. ``/update`` (``--gateway``) is exempt (detached, file-based delivery). Refuse only when a nominated gateway is positively an ancestor; unknown ancestry keeps existing recovery. """ if gateway_mode or not pids: return False try: from hermes_cli.gateway import _is_pid_ancestor_of_current_process ancestors = [int(pid) for pid in pids if _is_pid_ancestor_of_current_process(int(pid))] except Exception as exc: logger.debug("Could not inspect gateway ancestry before tree-kill: %s", exc) return False if not ancestors: return False rendered = ", ".join(str(pid) for pid in ancestors) print( "✗ Refusing to stop the gateway process tree because this updater " f"is running inside it (gateway PID(s): {rendered})." ) print(" On Windows, taskkill /T would terminate the updater before the update can run.") print(" From a chat platform, use `/update` instead.") print(" Otherwise, run `hermes update` from a separate terminal.") return True def _ledger_manual_serve_holders( matches: list[tuple[int, str, str]], ) -> list[dict]: """Full ledger entries for venv holders that are MANUAL serve/dashboard backends. Positive identity only: self-registered purpose serve/dashboard, live (pid, create_time), recorded spawner NOT alive (a Desktop-owned backend keeps its live Electron spawner and must keep the refusal — the app would respawn what we kill). Full entries let the relauncher rebuild from host/port/profile, not argv. """ try: from hermes_cli.process_identity import ledger_entries, spawner_is_dead except Exception: return [] holder_pids = {int(pid) for pid, _name, _cmd in matches} out: list[dict] = [] for entry in ledger_entries(): if entry.get("purpose") not in ("serve", "dashboard"): continue pid = entry.get("pid") if not isinstance(pid, int) or pid not in holder_pids: continue if spawner_is_dead(entry) is False: continue # live Desktop supervisor owns it — keep refusing out.append(entry) return out def _serve_relaunch_commands(entries: list[dict]) -> list[list[str]]: """Rebuild launch commands for stopped serves from ledger host/port/profile — never argv parsing (joined argv cannot round-trip Windows paths with spaces). Entries without a port are skipped. """ from hermes_cli.update_cmd import _m commands: list[list[str]] = [] hermes = None try: scripts_dir = _m()._venv_scripts_dir() if scripts_dir is not None: for name in ("hermes.exe", "hermes"): candidate = scripts_dir / name if candidate.is_file(): hermes = str(candidate) break except Exception: hermes = None if hermes is None: hermes = "hermes" for entry in entries: port = entry.get("port") if not isinstance(port, int) or port <= 0: continue cmd = [hermes] profile = str(entry.get("profile") or "") if profile and profile != "default": cmd += ["--profile", profile] cmd.append(str(entry.get("purpose"))) host = str(entry.get("host") or "") if host: cmd += ["--host", host] cmd += ["--port", str(port)] commands.append(cmd) return commands def _relaunch_stopped_serves(token: dict) -> None: """Idempotent atexit relaunch of manual serves stopped by the venv guard. `pending` flips False on first invocation so explicit call + atexit registration cannot double-spawn. """ from hermes_cli.update_cmd import _m, _record_update_step if not token.get("pending"): return token["pending"] = False entries = token.get("entries") or [] if not entries: return commands = _serve_relaunch_commands(entries) skipped = len(entries) - len(commands) failed: list = [] if commands: print(" ⟲ Relaunching stopped serve/dashboard backend(s)") failed = _m()._respawn_dashboard_processes(commands) if skipped or failed: print( " ⚠ Some stopped backends could not be relaunched automatically; " "restart them manually (hermes serve --host --port )." ) _record_update_step( "serve_relaunch", not failed and not skipped, f"relaunched={len(commands) - len(failed)} failed={len(failed)} skipped={skipped}", ) def _is_backend_argv(argv_low: str) -> bool: """Whether a lower-cased argv is a Desktop backend (``hermes_cli.main`` running ``serve``/``dashboard``).""" return "hermes_cli.main" in argv_low and (" serve" in argv_low or " dashboard" in argv_low) def _live_argv_low(psutil, pid, cmdline: str) -> str | None: """Current lower-cased argv of *pid* (falls back to the scanned *cmdline*); ``None`` if it exited.""" argv = cmdline try: argv = " ".join(psutil.Process(int(pid)).cmdline()) or cmdline except psutil.NoSuchProcess: return None except Exception: pass return argv.lower() def _orphaned_desktop_backend_pids( matches: list[tuple[int, str, str]], ) -> list[tuple[int, int]] | None: """``(pid, start_time)`` roots from *matches* when every remaining holder is an ORPHANED backend, else ``None``. Killing a Desktop-owned ``serve`` is futile (the app respawns it), but after the Desktop exited (GUI hand-off contract: it tree-kills backends, the marker parks relaunch) a straggler whose supervisor is gone would dead-end the update with "Hermes is still running" and zero open windows. Qualifies only if cmdline is a Hermes backend (``hermes_cli.main`` + serve/dashboard) AND the parent is demonstrably gone (PID missing or reused: parent created *after* child). Tree-aware: holders inside an accepted root's tree fold into it; only roots are returned (``taskkill /T`` reaps descendants). Any other live-parent backend, unjustified non-backend, unprovable case, or no psutil -> ``None``. Never raises. """ try: import psutil # type: ignore except Exception: return None # Pass 1: find orphaned backend ROOTS among the holders. roots: list[tuple[int, int]] = [] remaining: list[tuple[int, str]] = [] # (pid, argv_low) still to justify for pid, _name, cmdline in matches: low = _live_argv_low(psutil, pid, cmdline) if low is None: continue # exited between scan and classification — nothing to reap if not _is_backend_argv(low): remaining.append((int(pid), low)) continue try: proc = psutil.Process(int(pid)) # Fingerprint from the SAME psutil handle, centisecond-quantized like # gateway.status.get_process_start_time so pid_is_hermes round-trips at kill time. process_start_time = int(round(proc.create_time() * 100)) except psutil.NoSuchProcess: continue # exited during classification — nothing to reap except Exception: return None try: ppid = proc.ppid() parent = psutil.Process(ppid) if ppid else None if parent is not None and parent.is_running(): # PID-reuse check: a "parent" created after its child is a recycled PID. if parent.create_time() <= proc.create_time(): # Live parent: not a root, maybe an orphan root's descendant (the venv # trampoline re-execs uv python with the SAME argv). Defer to pass 2. remaining.append((int(pid), low)) continue except psutil.NoSuchProcess: pass # parent gone → orphan except Exception: return None roots.append((int(pid), process_start_time)) # Pass 2: every non-backend holder must descend from an accepted orphan root # (dies with the tree reap); anything else keeps the refusal. root_set = {pid for pid, _start_time in roots} for pid, _low in remaining: if not root_set: return None try: ancestors = {int(a.pid) for a in psutil.Process(pid).parents()} except psutil.NoSuchProcess: continue # exited already except Exception: return None if not (ancestors & root_set): return None return roots def _ledger_reapable_backend_pids( matches: list[tuple[int, str, str]], ) -> list[int]: """PIDs the spawn ledger positively identifies as orphaned backends; never raises. Strongest rung (no PPID/cmdline inference): qualifies when ``(pid, create_time)`` matches a live ledger entry (PID reuse can't forge it), purpose is a REAPABLE kind (never interactive), and the recorded SPAWNER is provably dead. Safe in ANY context. Unlisted holders fall to later rungs and never disqualify identified ones. """ try: from hermes_cli.process_identity import ( REAPABLE_PURPOSES, ledger_entries, spawner_is_dead, ) entries = ledger_entries() except Exception: return [] by_pid = {e.get("pid"): e for e in entries if isinstance(e.get("pid"), int)} roots: list[int] = [] for pid, _name, _cmdline in matches: entry = by_pid.get(int(pid)) if not entry: continue if entry.get("purpose") not in REAPABLE_PURPOSES: continue if spawner_is_dead(entry) is True: roots.append(int(pid)) return roots def _handoff_reapable_backend_pids( matches: list[tuple[int, str, str]], ) -> list[int] | None: """Backend PIDs safe to tree-reap during a GUI-updater hand-off, INCLUDING ones with a live parent; never raises. ``_orphaned_desktop_backend_pids`` bails on ANY live parent (mid-teardown Electron, launcher->worker chain), which hung a hand-off for 12 minutes. With the update-incomplete marker + ``--gateway`` + no live ``hermes.exe`` shim, nothing legitimate supervises or respawns a ``serve`` from this venv, so survivors are leaks. Only Hermes backends qualify — any non-backend holder, or no psutil -> ``None``. The CALLER must have confirmed the hand-off gate; outside it the stricter orphan-only path stands. """ try: import psutil # type: ignore except Exception: return None roots: list[int] = [] for pid, _name, cmdline in matches: low = _live_argv_low(psutil, pid, cmdline) if low is None: continue # exited — nothing to reap if not _is_backend_argv(low): return None # unexpected non-backend holder: refuse the whole set roots.append(int(pid)) return roots or None def _stop_process_trees( pids: list[int] | list[tuple[int, int]], ) -> None: """Force-stop each PID with its full child tree (Windows); best effort, never raises. ``taskkill /T /F``: stopping only the parent can leave a ``.hermes-runtime`` child holding the install open. """ from gateway.status import get_process_start_time from hermes_cli._subprocess_compat import pid_is_hermes, windows_hide_flags for entry in pids: if isinstance(entry, tuple): pid, expected_start_time = entry else: pid = int(entry) expected_start_time = get_process_start_time(pid) try: if expected_start_time is None: logger.debug("Skipping taskkill of PID %s: process identity unavailable", pid) continue if not pid_is_hermes( pid, expected_start_time=expected_start_time, ): logger.debug("Skipping taskkill of non-Hermes or changed PID %s", pid) continue subprocess.run( ["taskkill", "/PID", str(pid), "/T", "/F"], check=False, stdout=subprocess.DEVNULL, stderr=subprocess.DEVNULL, stdin=subprocess.DEVNULL, creationflags=windows_hide_flags(), ) except Exception as exc: logger.debug("Could not stop process tree %s: %s", pid, exc) def _looks_like_desktop_control_plane(cmdline: str) -> bool: """True for this-install ``hermes serve`` / ``hermes dashboard`` argv (Desktop control plane). Not the messaging gateway — don't feed into ``looks_like_gateway_command_line``. Token-based via the parser-derived classifier, never substring (``kanban --preserve-cache``, ``-m dashboard chat``). Undeterminable subcommand is NOT a control plane. """ if "hermes_cli.main" not in (cmdline or "").lower(): return False return _hermes_holder_subcommand(cmdline) in ("serve", "dashboard") def _desktop_owns_gateway_lifecycle() -> bool: """True when Desktop currently supervises this install's control plane (updater must not steal gateway start). Not proof messaging is served: serve is the control plane, the gateway a detached sibling. Prefer the spawn ledger; fall back to the venv-holder scan. An orphaned control plane (supervisor gone) does not count. """ from hermes_cli.update_cmd import _m with _best_effort('Desktop-lifecycle ledger probe failed: %s'): from hermes_cli.process_identity import ledger_entries, spawner_is_dead for entry in ledger_entries(): if entry.get("purpose") not in ("serve", "dashboard"): continue if spawner_is_dead(entry) is False: return True try: import psutil except Exception: psutil = None try: holders = _m()._detect_venv_python_processes() except Exception as exc: logger.debug("Desktop-lifecycle holder scan failed: %s", exc) return False for pid, _name, cmdline in holders: if not _looks_like_desktop_control_plane(cmdline): continue if psutil is None: return True # cannot prove orphanhood; a live control plane suffices try: proc = psutil.Process(int(pid)) parent = proc.parent() if parent is None or not parent.is_running(): continue if parent.create_time() > proc.create_time(): continue return True except Exception: continue return False def _stop_windows_gateway_service( name: str, *, expected_processes: tuple[tuple[int, float], ...] = (), expected_service_identity: tuple[int, float] | None = None, expected_gateway_identity: tuple[int, float] | None = None, timeout: float = 30.0, ) -> None: """Stop one verified Windows service and wait until SCM reports it down.""" import psutil # noqa: PLC0415 service = psutil.win_service_get(name) if expected_service_identity is not None: try: current_status = str(service.status()) current_service_pid = int(service.pid() or 0) except Exception as exc: raise RuntimeError( f"Windows service {name} SCM identity is unavailable before stop" ) from exc if current_status != "running": raise RuntimeError( f"Windows service {name} is not stably running before stop: {current_status}" ) if current_service_pid != int(expected_service_identity[0]): raise RuntimeError(f"Windows service {name} SCM process identity changed before stop") for label, identity in ( ("service", expected_service_identity), ("gateway", expected_gateway_identity), ): if identity is None: continue pid, create_time = identity try: current = float(psutil.Process(int(pid)).create_time()) except Exception as exc: raise RuntimeError( f"Windows {label} process identity is unavailable before stop" ) from exc if abs(current - float(create_time)) > 0.001: raise RuntimeError(f"Windows {label} process identity changed before stop") if expected_service_identity is not None and expected_gateway_identity is not None: service_pid = int(expected_service_identity[0]) gateway_pid = int(expected_gateway_identity[0]) try: ancestor_pids = {int(parent.pid) for parent in psutil.Process(gateway_pid).parents()} except Exception as exc: raise RuntimeError( "Windows gateway ancestry is unavailable before service stop" ) from exc if service_pid not in ancestor_pids: raise RuntimeError(f"Windows gateway is no longer owned by service {name}") result = subprocess.run( ["sc.exe", "stop", name], capture_output=True, text=True, encoding="utf-8", errors="replace", timeout=10, check=False, ) if result.returncode != 0 and service.status() != "stopped": detail = (result.stderr or result.stdout).strip() raise RuntimeError(detail or f"sc.exe stop failed with {result.returncode}") def _original_process_is_alive(pid: int, create_time: float) -> bool: try: current = float(psutil.Process(pid).create_time()) except (psutil.NoSuchProcess, psutil.ZombieProcess): return False except Exception: return True # AccessDenied/unknown: fail closed, venv may still be locked return abs(current - create_time) <= 0.001 alive = [ pid for pid, create_time in expected_processes if _original_process_is_alive(pid, create_time) ] deadline = _time.monotonic() + timeout while _time.monotonic() < deadline: service_stopped = service.status() == "stopped" alive = [ pid for pid, create_time in expected_processes if _original_process_is_alive(pid, create_time) ] if service_stopped and not alive: return _time.sleep(0.2) if service.status() == "stopped": # Lingering matching-identity processes make venv mutation unsafe — fail closed. alive_after_stop = [ pid for pid, create_time in expected_processes if _original_process_is_alive(pid, create_time) ] if alive_after_stop: raise RuntimeError( f"Windows service {name} stopped but its process tree is still alive: " f"{alive_after_stop}" ) return raise RuntimeError( f"Windows service {name} did not stop within {timeout:.0f}s; venv mutation unsafe." ) def _start_windows_gateway_service(name: str, *, timeout: float = 30.0) -> None: """Start one previously paused Windows service and verify it is running.""" import psutil # noqa: PLC0415 service = psutil.win_service_get(name) result = subprocess.run( ["sc.exe", "start", name], capture_output=True, text=True, encoding="utf-8", errors="replace", timeout=10, check=False, ) if result.returncode != 0 and service.status() != "running": detail = (result.stderr or result.stdout).strip() raise RuntimeError(detail or f"sc.exe start failed with {result.returncode}") deadline = _time.monotonic() + timeout while _time.monotonic() < deadline: if service.status() == "running": return _time.sleep(0.2) raise RuntimeError(f"Windows service {name} did not start within {timeout:.0f}s") def _restore_windows_gateway_service(name: str, *, timeout: float = 60.0) -> None: """Restore a service after an uncertain stop, including STOP_PENDING.""" from hermes_cli.update_cmd import _start_windows_gateway_service import psutil # noqa: PLC0415 service = psutil.win_service_get(name) deadline = _time.monotonic() + timeout while _time.monotonic() < deadline: status = service.status() if status == "running": return if status == "stopped": _start_windows_gateway_service(name) return _time.sleep(0.2) raise RuntimeError( f"Windows service {name} did not reach a restorable state within {timeout:.0f}s" ) def _windows_cold_start_plan() -> dict | None: """Pause token for the no-running-gateway case: cold-start after update when an autostart entry exists. Desktop-owned lifecycle -> ``None`` (spawning ``gateway run`` beside Desktop races ports/state). """ from hermes_cli.update_cmd import _desktop_owns_gateway_lifecycle # No gateway running, but an installed autostart entry is an explicit "I want a # gateway" signal; a gateway that died between updates would otherwise stay down # until next login (resume only relaunches what was running). Cold-start after update. # Exception: Desktop owns the lifecycle — spawning ``gateway run`` beside it races # ports/state. The skip is ownership, not liveness. with _best_effort('Could not check Desktop gateway-lifecycle ownership before update: %s'): if _desktop_owns_gateway_lifecycle(): logger.debug( "Skipping Windows gateway cold-start plan: " "Desktop owns gateway lifecycle" ) return None with _best_effort('Could not check Windows gateway autostart state before update: %s'): from hermes_cli import gateway_windows if gateway_windows.is_installed(): return { "resume_needed": True, "profiles": {}, "unmapped_pids": [], "unmapped": [], "cold_start_if_installed": True, } return None def _pause_windows_gateway_services(service_gateways, token: dict, profiles: dict, unmapped: list) -> dict: """Stop each SCM gateway service, recording them on *token*; roll everything back on failure. Runs after every fallible ordinary-gateway step so a failure here restores the attempted services AND the already-paused ordinary gateways before re-raising. """ from hermes_cli.update_cmd import _restore_windows_gateway_service, _stop_windows_gateway_service # Stop SCM services only after every fallible ordinary-gateway step; from here any # error restores attempted services and already-paused gateways before aborting. paused_services = [] current_service_name = None try: for service in service_gateways: current_service_name = str(service.name) _stop_windows_gateway_service( current_service_name, expected_processes=tuple( getattr(service, "descendant_identities", ()) ), expected_service_identity=( int(service.service_pid), float(service.service_create_time), ), expected_gateway_identity=( int(service.gateway_pid), float(service.gateway_create_time), ), ) paused_services.append(current_service_name) current_service_name = None if paused_services: token["services"] = paused_services token["expected_services"] = list(paused_services) token["restarted_services"] = [] token["service_profiles"] = { str(service.name): str(service.profile) for service in service_gateways if str(service.name) in paused_services } print(" ✓ Paused Windows gateway service(s): " + ", ".join(paused_services)) return token except Exception as exc: restore_names = [] if current_service_name: restore_names.append(current_service_name) restore_names.extend(reversed(paused_services)) rollback_failures = [] for service_name in dict.fromkeys(restore_names): try: _restore_windows_gateway_service(service_name) except Exception as restore_exc: rollback_failures.append(f"{service_name}: {restore_exc}") if profiles or unmapped: try: _resume_windows_gateways_after_update(token) except Exception as restore_exc: rollback_failures.append(f"ordinary gateways: {restore_exc}") failed_service = current_service_name or "unknown" detail = f"Could not stop Windows gateway service {failed_service}: {exc}" if rollback_failures: detail += "; rollback failures: " + "; ".join(rollback_failures) raise RuntimeError(detail) from exc def _pause_windows_gateways_for_update() -> dict | None: """Stop running Windows gateways before mutating the checkout or venv. Scheduled/startup gateways run via pythonw.exe, invisible to the hermes.exe instance guard, yet keep files locked during ``git``/``uv``. Stop only PIDs the gateway discovery code identifies. """ from hermes_cli.update_cmd import _m if not _m()._is_windows(): return None try: from gateway.status import get_process_start_time, terminate_pid from hermes_cli.gateway import ( _capture_gateway_argv, _get_restart_drain_timeout, find_gateway_pids, find_profile_gateway_processes, find_windows_gateway_services, ) except Exception as exc: raise RuntimeError(f"Could not prepare Windows gateway pause for update: {exc}") from exc try: profile_process_list = find_profile_gateway_processes(strict=True) profile_processes = {proc.pid: proc for proc in profile_process_list} except Exception as exc: raise RuntimeError(f"Could not map Windows gateway PIDs to profiles: {exc}") from exc try: service_gateways = find_windows_gateway_services(profile_processes=profile_process_list) except Exception as exc: raise RuntimeError(f"Could not determine Windows gateway service ownership: {exc}") from exc service_gateway_pids = {int(service.gateway_pid) for service in service_gateways} try: running_pids = list( dict.fromkeys( [ *find_gateway_pids(all_profiles=True), *sorted(profile_processes), *sorted(service_gateway_pids), ] ) ) except Exception as exc: raise RuntimeError(f"Could not discover Windows gateway PIDs before update: {exc}") from exc if not running_pids: return _windows_cold_start_plan() profiles: dict[str, int] = {} mapped_pids = [] socket_acks: list[dict] = [] for pid in running_pids: if pid in service_gateway_pids: continue proc = profile_processes.get(pid) if proc is None: continue profiles[str(proc.profile)] = int(pid) mapped_pids.append(int(pid)) _write_update_planned_stop_marker(Path(proc.path), int(pid)) # Socket-first pause: ask the gateway to drain and exit itself (ACK = its own # graceful path). No answer (older gateway) -> marker poll / force-kill ladder below. try: from gateway.control_socket import pause_gateway_for_update ack = pause_gateway_for_update(Path(proc.path)) if ack and (ack.get("pausing") or ack.get("already_stopping")): socket_acks.append(ack) except Exception as exc: logger.debug("Socket pause unavailable for gateway %s: %s", pid, exc) # Resolve venv-side launchers BEFORE draining: a dead worker's parent cannot be # recovered (NoSuchProcess). The launcher keeps ``.pyd`` mapped and would trip the # venv-holder guard after the gateway stopped; it is killed with the survivors. launcher_pids = _m()._venv_launcher_ancestors(mapped_pids) print("→ Stopping Windows gateway process(es) before updating Hermes...") try: drain_timeout = max(float(_get_restart_drain_timeout()), 1.0) except Exception: drain_timeout = 10.0 if socket_acks: # A socket-paused gateway drains its ACTIVE TURN first; honor its declared # budget (+ teardown grace) so it isn't force-killed mid-turn. with suppress(Exception): declared = max(float(a.get("drain_timeout") or 0.0) for a in socket_acks) drain_timeout = max(drain_timeout, declared + 10.0) print( f" → {len(socket_acks)} gateway(s) ACKed socket pause; " f"waiting up to {int(drain_timeout)}s for graceful exit" ) survivors = _m()._wait_for_windows_update_gateway_exit(mapped_pids, timeout=drain_timeout) unmapped_pids = [ pid for pid in running_pids if pid not in profile_processes and pid not in service_gateway_pids ] # Snapshot unmapped gateways' argv *before* force-killing so resume can replay it. # Unmapped = no profile->PID-file mapping (e.g. Scheduled Task ``pythonw.exe -m ...``). unmapped: list[dict] = [] for pid in unmapped_pids: argv = None try: argv = _capture_gateway_argv(int(pid)) except Exception as exc: logger.debug("Could not capture argv for unmapped gateway %s: %s", pid, exc) unmapped.append({"pid": int(pid), "argv": argv}) # Tree-kill survivors, unmapped gateways, and pre-drain launchers; a launcher # already gone with its worker raises ProcessLookupError and is skipped. force_killed = [] for pid in sorted(set(survivors).union(unmapped_pids).union(launcher_pids)): with suppress(ProcessLookupError, PermissionError, OSError): pid_int = int(pid) terminate_pid(pid_int, force=True, expected_start_time=get_process_start_time(pid_int)) force_killed.append(pid_int) if profiles: print(f" ✓ Paused gateway profile(s): {', '.join(sorted(profiles))}") if force_killed: print(f" → Force-stopped {len(force_killed)} gateway process(es)") if unmapped_pids: respawnable = sum(1 for u in unmapped if u.get("argv")) print(f" → Stopped {len(unmapped_pids)} gateway process(es) without profile mapping") if respawnable < len(unmapped_pids): # No recoverable cmdline (psutil missing, access denied, gone): manual restart. print(" Restart manually after update: hermes gateway run") token = { "resume_needed": True, "profiles": profiles, "unmapped_pids": unmapped_pids, "unmapped": unmapped, } return _pause_windows_gateway_services(service_gateways, token, profiles, unmapped) def _cold_start_windows_gateway_after_update() -> bool: """Direct-spawn a detached gateway after update for the ``cold_start_if_installed`` case (installed but down). Uses ``gateway_windows._spawn_detached`` (same hidden-console + breakaway path as ``hermes gateway start``). Idempotent: re-checks nothing is running so a concurrent autostart can't duplicate. A successful Popen doesn't prove survival (a job object denying breakaway kills it), so success is gated on the liveness poll. """ from hermes_cli.update_cmd import _desktop_owns_gateway_lifecycle, _m if not _m()._is_windows(): return True try: from hermes_cli import gateway_windows from hermes_cli.gateway import find_gateway_pids except Exception as exc: raise RuntimeError(f"Could not load Windows gateway cold-start helpers: {exc}") from exc # Re-check liveness right before spawning: autostart may have brought one up. Don't double-start. try: if list(find_gateway_pids(all_profiles=True)): return True except Exception as exc: raise RuntimeError(f"Could not re-check gateway liveness before cold-start: {exc}") from exc try: if _desktop_owns_gateway_lifecycle(): logger.debug("Skipping Windows gateway cold-start: Desktop owns gateway lifecycle") return True except Exception as exc: raise RuntimeError( "Could not re-check Desktop gateway-lifecycle ownership before cold-start: " f"{exc}" ) from exc try: pid = gateway_windows._spawn_detached() except Exception as exc: raise RuntimeError(f"Could not cold-start Windows gateway after update: {exc}") from exc if not pid: raise RuntimeError("Windows gateway cold-start did not return a process ID") ready_pids = gateway_windows._wait_for_gateway_ready() if not ready_pids: raise RuntimeError(f"Windows gateway cold-start PID {pid} did not become ready") print() print( "✓ Gateway started via cold-start after update " f"(PID: {', '.join(map(str, ready_pids))})" ) # Persist vouched PIDs so a death AFTER updater exit (Job Object teardown) is # reported by the next CLI invocation. Best-effort. with suppress(Exception): gateway_windows._write_start_attestation(ready_pids, "cold-start after update") return True def _refresh_windows_gateway_launchers() -> None: """Regenerate installed Windows gateway launcher scripts after update; best-effort, never fails the update. Launchers are written once at install, so old installs kept launching via ``pythonw.exe`` (conhost flashes, ``sys.stderr is None`` death). The task's /TR points at a stable path, so rewriting in place retargets it without schtasks/UAC. ``_write_task_script`` is idempotent. """ from hermes_cli.update_cmd import _m if not _m()._is_windows(): return with _best_effort('Could not refresh Windows gateway launchers after update: %s'): from hermes_cli import gateway_windows if not gateway_windows.is_installed(): return gateway_windows._write_task_script() print(" ✓ Refreshed Windows gateway launcher scripts") def _refresh_bootstrap_cache_scripts(branch: str = "main") -> None: """Overwrite ``$HERMES_HOME/bootstrap-cache/install-.{ps1,sh}`` for *branch* from the fresh checkout. Old ``hermes-setup.exe`` builds NEVER re-download a cached branch-ref script (and have no self-update), so a stale one runs months-old code forever; refreshing turns that reuse into a feature (newer installers re-download anyway). Guards mirror ``install_script.rs``: only the sanitized *branch* key is rewritten (sibling refs untouched); commit-SHA pins (7-40 hex, incl. abbreviated) are immutable and skipped. The .ps1 copy gets a UTF-8 BOM to match the cache format. Best-effort: never fails the update. """ from hermes_cli.update_cmd import _m with _best_effort('Could not refresh bootstrap-cache scripts after update: %s'): import re as _re cache_dir = Path(_m().get_hermes_home()) / "bootstrap-cache" if not cache_dir.is_dir(): return # Mirror install_script.rs::sanitize_ref(). safe_ref = _re.sub(r"[^A-Za-z0-9._-]", "_", str(branch or "main")) # Mirror install_script.rs::is_valid_commit(): immutable commit pin, never rewrite. if _re.fullmatch(r"[0-9a-fA-F]{7,40}", safe_ref): return refreshed = [] for kind, src_name in (("ps1", "install.ps1"), ("sh", "install.sh")): src = _m().PROJECT_ROOT / "scripts" / src_name if not src.is_file(): continue cached = cache_dir / f"install-{safe_ref}.{kind}" if not cached.is_file(): continue # this ref was never bootstrap-cached — nothing to heal data = src.read_bytes() if kind == "ps1" and not data.startswith(b"\xef\xbb\xbf"): # PowerShell needs the BOM or localized/em-dash text mis-decodes. data = b"\xef\xbb\xbf" + data if cached.read_bytes() == data: continue # already current tmp = cached.with_suffix(cached.suffix + ".tmp") tmp.write_bytes(data) os.replace(tmp, cached) refreshed.append(cached.name) if refreshed: print( " ✓ Refreshed installer bootstrap-cache script(s): " + ", ".join(sorted(refreshed)) ) def _resume_windows_gateways_after_update(token: dict | None) -> None: """Restart Windows profile gateways previously paused for update.""" from hermes_cli.update_cmd import _m, _start_windows_gateway_service if not token or not token.get("resume_needed"): return if not _m()._is_windows(): token["resume_needed"] = False return # Regenerate launcher scripts before respawning so a legacy pythonw-era # autostart entry comes back on the current design at next login too. _m()._refresh_windows_gateway_launchers() services = list(token.get("services") or []) token.setdefault("expected_services", list(services)) verified_restarts = list(token.get("restarted_services") or []) restarted_services = [] failed_services = [] for service_name in services: try: _start_windows_gateway_service(str(service_name)) restarted_services.append(str(service_name)) if str(service_name) not in verified_restarts: verified_restarts.append(str(service_name)) except Exception as exc: logger.warning( "Could not restart Windows gateway service %s after update: %s", service_name, exc, ) print(f" ⚠ Could not restart Windows gateway service: {service_name}") failed_services.append(str(service_name)) if failed_services: token["services"] = failed_services token["restarted_services"] = verified_restarts raise RuntimeError( "Could not restart Windows gateway service(s): " + ", ".join(failed_services) ) token["services"] = [] token["restarted_services"] = verified_restarts if restarted_services: print() print(" ✓ Restarted Windows gateway service(s): " + ", ".join(restarted_services)) profiles = token.get("profiles") or {} unmapped = token.get("unmapped") or [] cold_start = bool(token.get("cold_start_if_installed")) if not profiles and not any(u.get("argv") for u in unmapped): if cold_start: if not _m()._cold_start_windows_gateway_after_update(): raise RuntimeError("Windows gateway cold-start was not verified") token["cold_start_if_installed"] = False token["resume_needed"] = False return try: from hermes_cli.gateway import ( launch_detached_gateway_restart_by_cmdline, launch_detached_profile_gateway_restart, ) except Exception as exc: raise RuntimeError(f"Could not load Windows gateway restart helper: {exc}") from exc relaunched = [] failed_profiles = {} for profile, old_pid in sorted(profiles.items()): try: if launch_detached_profile_gateway_restart(str(profile), int(old_pid)): relaunched.append(str(profile)) else: failed_profiles[str(profile)] = int(old_pid) except Exception as exc: logger.debug( "Could not restart Windows gateway profile %s after update: %s", profile, exc, ) failed_profiles[str(profile)] = int(old_pid) # Feed the plan-vs-execution reconciliation (else a relaunched gateway is reported # "unaccounted", exit 1). Failed relaunches are deliberately left off so they # still surface (Windows has no watcher to recover them). token["relaunched_profiles"] = relaunched # Respawn unmapped gateways by replaying the argv snapshotted before the kill. unmapped_relaunched = 0 failed_unmapped = [] for entry in unmapped: argv = entry.get("argv") old_pid = entry.get("pid") if not argv or not old_pid: failed_unmapped.append(entry) continue try: if launch_detached_gateway_restart_by_cmdline(int(old_pid), list(argv)): unmapped_relaunched += 1 else: failed_unmapped.append(entry) except Exception as exc: logger.debug( "Could not restart unmapped Windows gateway (pid %s) after update: %s", old_pid, exc, ) failed_unmapped.append(entry) token["profiles"] = failed_profiles token["unmapped"] = failed_unmapped if failed_profiles or failed_unmapped: raise RuntimeError("Could not restart every paused Windows gateway") # A truthy launch only proves the watcher was created; a parent Job Object denying # CREATE_BREAKAWAY_FROM_JOB can kill the gateway on updater teardown. Verify with # the same liveness poll every spawn path uses; all_profiles=True covers the fleet. if relaunched or unmapped_relaunched: try: from hermes_cli import gateway_windows except Exception as exc: raise RuntimeError(f"Could not load Windows gateway liveness helpers: {exc}") from exc ready_pids = gateway_windows._wait_for_gateway_ready(timeout_s=30.0, all_profiles=True) if not ready_pids: token["profiles"] = dict(profiles) token["unmapped"] = list(unmapped) print() print( " ⚠ Windows gateway restart could not be verified — no stable " "gateway process appeared after relaunch." ) print( " (The respawned gateway may have been killed by a parent " "Job Object during updater teardown, #48820.)" ) print(" Recover with: hermes gateway restart") raise RuntimeError("Windows gateway relaunch after update was not verified alive") # Persist vouched PIDs so a death AFTER updater exit is reported by the # next CLI invocation. Best-effort. with suppress(Exception): gateway_windows._write_start_attestation(ready_pids, "post-update relaunch") token["resume_needed"] = False if relaunched: print() print(f" ✓ Restarting Windows gateway profile(s): {', '.join(relaunched)}") if unmapped_relaunched: if not relaunched: print() print(f" ✓ Restarting {unmapped_relaunched} unmapped Windows gateway process(es)") def _resume_windows_gateways_and_merge_outcome(outcome, _windows_gateway_resume, gateway_mode: bool): """Resume gateways paused for a Windows update and fold the token into ``outcome``'s systemd/launchd-style bookkeeping so reconciliation never reports a healthy gateway as unaccounted. Must never abort the update. """ from hermes_cli.update_cmd import _m, _write_gateway_update_exit_code try: _m()._resume_windows_gateways_after_update(_windows_gateway_resume) except Exception as _windows_resume_exc: outcome.incomplete = True outcome.phase_errors.append(str(_windows_resume_exc)) print(f" ⚠ Windows gateway service restart incomplete: {_windows_resume_exc}") if gateway_mode: _write_gateway_update_exit_code(False) if isinstance(_windows_gateway_resume, dict): # Failed relaunches are absent from the token so they still surface. Best-effort. with _best_effort('Could not merge Windows relaunch outcome into fleet reconciliation bookkeeping: %s'): for _win_profile in _windows_gateway_resume.get("relaunched_profiles") or []: if _win_profile not in outcome.relaunched_profiles: outcome.relaunched_profiles.append(_win_profile) windows_restarted = list(_windows_gateway_resume.get("restarted_services") or []) for service_name in windows_restarted: if service_name not in outcome.restarted_services: outcome.restarted_services.append(service_name) service_profiles = _windows_gateway_resume.get("service_profiles") or {} for service_name in windows_restarted: profile_name = service_profiles.get(service_name) if profile_name and profile_name not in outcome.relaunched_profiles: outcome.relaunched_profiles.append(profile_name) pending_services = list(_windows_gateway_resume.get("services") or []) for service_name in pending_services: label = str(service_profiles.get(service_name) or service_name) if label not in outcome.failed_or_stale_units: outcome.failed_or_stale_units.append(label) with suppress(Exception): from hermes_cli.update_receipt import record_gateway_restart record_gateway_restart( restarted_services=outcome.restarted_services, relaunched_profiles=outcome.relaunched_profiles, externally_supervised_profiles=outcome.externally_supervised_profiles, killed_pids=sorted(outcome.killed_pids), failed_units=outcome.failed_or_stale_units, incomplete=( outcome.incomplete or bool(outcome.failed_or_stale_units) ), phase_error="; ".join(outcome.phase_errors) or None, ) def _clear_windows_venv_holders_or_exit(args, gateway_mode: bool, _windows_gateway_resume): """Windows: stop every venv-python holder we can positively identify, else resume paused gateways and exit 2. Rungs in order: leftover pausable gateways -> ledger orphaned backends -> orphaned Desktop backends -> ledger manual serve (relaunched at exit on the same bind) -> GUI hand-off leaks. Remaining holders are refused (the sync would corrupt against a locked .pyd). """ from hermes_cli.update_cmd import _m, _record_update_step, _refuse_gateway_ancestor_tree_kill _venv_holders = _m()._detect_venv_python_processes() if _venv_holders: _gateway_holders = _m()._leftover_pausable_gateway_pids(_venv_holders) if _gateway_holders is not None: if _refuse_gateway_ancestor_tree_kill( _gateway_holders, gateway_mode=gateway_mode ): _m()._resume_windows_gateways_after_update(_windows_gateway_resume) sys.exit(2) # Gateways the pause machinery owns (respawned in the pause->guard window or # unmapped spawn path): stop and re-check; post-update resume brings them back. from gateway.status import get_process_start_time, terminate_pid print( f" ⚠ {len(_gateway_holders)} gateway process(es) still " "hold the venv after the pause; stopping them" ) for _pid in _gateway_holders: try: pid_int = int(_pid) terminate_pid( pid_int, force=True, expected_start_time=get_process_start_time(pid_int), ) except Exception as exc: logger.debug("Could not stop leftover gateway %s: %s", _pid, exc) _time.sleep(1.0) _venv_holders = _m()._detect_venv_python_processes() if _venv_holders: # Positive-identity rung (any context): spawn ledger proves the holder is an # orphaned backend (self-registered, spawner provably dead). No PPID archaeology. _ledger_backends = _m()._ledger_reapable_backend_pids(_venv_holders) if _ledger_backends: print( f" ⚠ {len(_ledger_backends)} ledger-identified orphaned " "Hermes backend process(es) hold the venv; stopping their trees" ) _m()._stop_process_trees(_ledger_backends) _time.sleep(1.0) _venv_holders = _m()._detect_venv_python_processes() if _venv_holders: _orphan_backends = _m()._orphaned_desktop_backend_pids(_venv_holders) if _orphan_backends: # Desktop `serve` backends whose app is GONE: nothing respawns an orphan, so # reap the tree. Live-Desktop backends return None and keep the refusal. print( f" ⚠ {len(_orphan_backends)} orphaned Desktop backend " "process(es) still hold the venv; stopping their trees" ) _m()._stop_process_trees(_orphan_backends) _time.sleep(1.0) _venv_holders = _m()._detect_venv_python_processes() if _venv_holders: # Manual serve/dashboard rung (e.g. `hermes serve --host ` for a REMOTE Desktop): # ledger identity only (spawner dead; Desktop-owned keep the refusal). Stop and # register an idempotent atexit relaunch on the SAME host/port/profile — success or failure. _serve_entries = _m()._ledger_manual_serve_holders(_venv_holders) if _serve_entries: print( f" ⚠ {len(_serve_entries)} manual serve/dashboard " "backend(s) hold the venv; stopping them for the update " "(they will be relaunched on their recorded endpoints)" ) _m()._stop_process_trees([int(e["pid"]) for e in _serve_entries]) _serve_resume_token = {"pending": True, "entries": _serve_entries} _record_update_step("serve_pause", True, f"stopped={len(_serve_entries)}") import atexit as _serve_atexit _serve_atexit.register(_m()._relaunch_stopped_serves, _serve_resume_token) _time.sleep(1.0) _venv_holders = _m()._detect_venv_python_processes() if _venv_holders: # Final rung: in a GUI hand-off (`--gateway` + update-incomplete marker) the Desktop # is contractually gone; surviving `serve` backends are leaks even with a live # parent (which made the orphan-only rung bail and hang) — reap by cmdline. _handoff = False try: _handoff = bool(getattr(args, "gateway", False)) and _m()._update_marker_path().exists() except Exception: _handoff = False # Fail closed: unverifiable shim state is treated as a live shim (keep refusing). _no_live_shim = False try: _scripts_dir = _m()._venv_scripts_dir() if _scripts_dir is not None: _no_live_shim = not _m()._detect_concurrent_hermes_instances(_scripts_dir) except Exception: _no_live_shim = False if _handoff and _no_live_shim: _handoff_backends = _m()._handoff_reapable_backend_pids(_venv_holders) if _handoff_backends: print( f" ⚠ {len(_handoff_backends)} Hermes backend process(es) " "still hold the venv after the Desktop hand-off; " "stopping their trees" ) _m()._stop_process_trees(_handoff_backends) _time.sleep(1.0) _venv_holders = _m()._detect_venv_python_processes() if _venv_holders: print(_format_venv_python_holders_message(_venv_holders)) _m()._resume_windows_gateways_after_update(_windows_gateway_resume) sys.exit(2)