三层回退恢复机制(L0写前留档/L1恢复梯子/L2离线回滚)+ guard 父守护

- L0: files 插件写受保护系统路径(/etc 等)前自动留档,AbstractBeforeWrite 到 data/file_baseline
- L1: failback 受限 worker 执行恢复梯子 probe→还原DNS/proxy→还原LLM配置+ReloadFromConfig→probe,N轮有界
- L2: tracker changeset 持久化原文 blob,guard 离线 RollbackFromDisk 回滚 agentfs;SystemSnapshot 支撑
- guard 父守护: 心跳 IPC(PING/ACK unix socket, 文件心跳回退)、失败计数、退出码协议(42/43/44)、最后手段
- 发行版路径适配: system.protected_paths/network_paths 可注入,默认面向主流 Linux
- Windows 兼容: guard.go/failback.go 加 //go:build linux, guard_windows.go 提供 no-op 桩
- 修复: guard.yaml last_resort 键冲突、changeset Content 不落盘导致离线回滚丢原文

Build 全绿, vet 干净, system/recovery/ipc/tracker 单元测试全过
This commit is contained in:
root
2026-08-05 16:00:08 +08:00
parent fc614477ed
commit d08ed3312e
28 changed files with 3675 additions and 167 deletions

View File

@ -184,7 +184,7 @@ func TestRegisterAgentMultiple(t *testing.T) {
d := New(cfg)
for i := 0; i < 5; i++ {
d.RegisterAgent(types.AgentID(string(rune('a'+i))))
d.RegisterAgent(types.AgentID(string(rune('a' + i))))
}
agents := d.ListAgents()
@ -207,3 +207,64 @@ func TestConcurrentAccess(t *testing.T) {
go d.RegisterAgent(types.AgentID(string(rune('a' + i))))
}
}
func TestCheckAgentHeartbeatSource(t *testing.T) {
cfg := &types.Config{
Daemon: types.DaemonConfig{CheckInterval: time.Minute, HeartbeatInterval: 30 * time.Second},
}
cfg.Defaults.RollbackPolicy.MaxRetries = 3
d := New(cfg)
d.RegisterAgent("main")
a := d.agents["main"]
d.SetHeartbeatSource(func(id types.AgentID) (time.Time, types.HealthStatus, error) {
return time.Now(), types.HealthHealthy, nil
})
regHB := a.lastHB
if regHB.IsZero() {
t.Fatal("lastHB should be set at register")
}
d.checkAgent("main", a)
if a.lastHB.Before(regHB) {
t.Fatal("lastHB should update after a successful heartbeat poll")
}
if a.health != types.HealthHealthy {
t.Fatalf("expected healthy, got %v", a.health)
}
// 健康源丢失:lastHB 不应再更新,状态置 Down
lastHB := a.lastHB
time.Sleep(2 * time.Millisecond)
d.SetHeartbeatSource(func(id types.AgentID) (time.Time, types.HealthStatus, error) {
return time.Time{}, types.HealthDown, nil
})
d.checkAgent("main", a)
if a.health != types.HealthDown {
t.Fatalf("expected down, got %v", a.health)
}
if !a.lastHB.Equal(lastHB) {
t.Fatal("lastHB must NOT update when the agent does not respond")
}
}
func TestRestartHandlerInvoked(t *testing.T) {
cfg := &types.Config{
Daemon: types.DaemonConfig{CheckInterval: time.Minute, HeartbeatInterval: 30 * time.Second},
}
cfg.Defaults.RollbackPolicy.MaxRetries = 3
d := New(cfg)
d.RegisterAgent("main")
a := d.agents["main"]
called := false
d.SetRestartHandler(func(id types.AgentID) { called = true })
d.restartAgent("main", a)
if !called {
t.Fatal("restart handler should be invoked")
}
if a.failCount != 0 {
t.Fatalf("failCount should reset, got %d", a.failCount)
}
}