fix(updater): relaunch survives the handoff unit's cgroup sweep

v0.1.15 update proved the pipeline end-to-end (download, verify, swap OK)
but the app never reopened: the handoff runs in a systemd transient unit
whose default KillMode=control-group sweeps the process tree when the
script exits, killing the backgrounded relaunch before Electron started.
Two fixes: start the unit with KillMode=process, and setsid the relaunch
(nohup fallback) so it detaches from the unit session entirely.
This commit is contained in:
avi 2026-10-05 18:11:24 -05:00
commit aebfa26308
2 changed files with 13 additions and 1 deletions

View file

@ -1354,6 +1354,11 @@ handleIpc("folio:performUpdate", async () => {
execFileSync("systemd-run", [ execFileSync("systemd-run", [
"--user", "--quiet", "--collect", "--user", "--quiet", "--collect",
`--description=Folio updater handoff`, `--description=Folio updater handoff`,
// Default KillMode=control-group means the unit's cgroup is swept
// when the script exits — that killed the backgrounded relaunch
// before Electron got to start (v0.1.15 update: swap OK, app died).
// KillMode=process lets the script exit while its child app lives.
"--property=KillMode=process",
"/bin/sh", script, "/bin/sh", script,
], { timeout: 10_000, stdio: "ignore" }); ], { timeout: 10_000, stdio: "ignore" });
handedOff = true; handedOff = true;

View file

@ -224,7 +224,14 @@ export function buildInstallerScript(spec: InstallerSpec): string {
' rm -rf "$NEW"', ' rm -rf "$NEW"',
"fi", "fi",
'say "relaunching"', 'say "relaunching"',
'"$RELAUNCH" >/dev/null 2>&1 &', // Detach fully: setsid moves the relaunch into its own session so it
// survives this script's exit and any cgroup sweep of the transient
// unit (systemd KillMode). Fallback chain for missing setsid.
'if command -v setsid >/dev/null 2>&1; then',
' setsid "$RELAUNCH" >/dev/null 2>&1 < /dev/null &',
'else',
' nohup "$RELAUNCH" >/dev/null 2>&1 < /dev/null &',
"fi",
"", "",
].join("\n"); ].join("\n");
} }