Complete managed Gateway upgrades after Node prefix changes while preserving the verified service during preparation and recovering only owned failed activations.
Keep requester/executor and original/candidate ownership through native children; retain uncertain cleanup and original failure outcomes. Source and isolated native component checks are documented in the canonical PR. The wider first-hop installer and other platform journeys remain separate program work.
Closes#107930. Canonical PR history retains the original contributor commits; repository-supported squash preserves explicit contributor credit.
Co-authored-by: Jason (Json) <263060202+fuller-stack-dev@users.noreply.github.com>
Co-authored-by: Peter Steinberger <steipete@gmail.com>
Co-authored-by: Dallin Romney <dallinromney@gmail.com>
* fix(runtime): reuse an available compatible Node at startup
Share startup recovery between the launcher and legacy CLI runtime admission
so older updaters can run target Doctor through dist/index.js under an
already installed compatible Node. Preserve process-contract exclusions,
arguments, environment, standard streams, and exit status.
Refs #140465
* test(runtime): include recovery proof in E2E routing
* fix(runtime): secure Node discovery and decode service scripts
Reject relative candidates and cwd-resolved runtimes before probing, except
for explicit absolute PATH directories. Parse generated Windows command
quoting and recorded code pages without loading application dependencies.
Skip CP850 and CP949 with a diagnostic instead of guessing executable paths.
Use real task-writer fixtures for encoding, quoting, and fallback coverage.
Refs #140465
* fix(runtime): reject cwd-local manager symlinks
* test(runtime): keep recovery home outside launcher cwd
* fix(runtime): isolate recovery from dotenv environment
* fix(runtime): canonicalize discovery paths before use
* fix(runtime): preserve private Node recovery from home
* refactor(runtime): trim Node recovery comments and aliases
Behavior-neutral cleanup of the recovery launcher module: fold the serviceHome and managerHome aliases into homeDir and shorten five comment blocks to the invariant they protect.
* fix(runtime): keep diagnostics and update usable on an unsupported Node
Share CLI admission between the launcher and source guard, retain private-copy
SQLite recovery, and keep live database writers and repair agents refused.
Route plain Doctor to lint and refuse update before its run-ledger admission
when the CLI Node is unsupported. Report CLI/service runtime findings and the
reporting Node version in update-failure reports.
Refs #140672#142742
* docs(install): explain private Node recovery and diagnostic access
* test(runtime): preserve Node recovery coverage with diagnostic admission
* fix(runtime): offer Node recovery once per update invocation
* fix(build): emit Node 22 syntax for recovery diagnostics
* fix(update): check runtime at the state preparation boundary
* fix(doctor): preserve migration order before runtime diagnostics
* fix(runtime): recover before admitting unsupported Node diagnostics
* fix(runtime): preserve capability admission in diagnostic recovery
* test(cli): retain capability checks in startup fixtures
* refactor(runtime): share Node findings across diagnostic commands
* fix(doctor): omit absent repair hints in lint errors
* fix(runtime): gate node:sqlite on a NUL round-trip capability probe
Validate the loaded SQLite library and TEXT, BLOB, and JSON round trips across startup, doctor, Gateway install, update preflight, and installers. Admit capable Node 24+ vendor builds with a support-policy note while retaining the package engines and Node 22 exclusion. Refs #140465#140672.
* fix(runtime): expose capability diagnostics through doctor
Register the runtime check in the ordered Doctor contribution catalog. Keep shared audit types in a leaf module, include the bootstrap probe in duplicate scanning, and update native runtime and compiled-worker fixtures for the capability protocol.
* fix(update): preserve target Node version requirements
* fix(install): remove unused Node major probe state
* feat: offer Node.js updates when the CLI runtime is incompatible
* fix: include Node runtime recovery in duplicate scans
---------
Co-authored-by: Morrow <morrow@bluedot.it.com>