Client or integration
OpenCodex dashboard
Area
Service lifecycle
Summary
A dashboard update stopped opencodex-proxy.service and killed its own update worker, leaving the proxy offline and the old package installed. The worker uses detached: true, but remains in the service's systemd cgroup. The generated unit's default KillMode=control-group terminates it when the updater stops the service.
Expected: the updater survives proxy shutdown, completes installation, and restarts the service.
Reproduction
- Install via npm and run OpenCodex through its generated systemd user service.
- Start a dashboard update with restart enabled.
- The service stops, the update worker disappears, and
update-job.json remains running with a dead PID. The dashboard origin refuses connections.
Version
2.63.0-preview.20260923, updating to 2.64.0. The affected spawn path is also present in the published 2.64.0 package.
Operating system
Ubuntu 24.04.4 LTS, systemd 255.
Provider and model
Not provider-specific.
Cause and tested workaround
src/update/job.ts, spawnGuiUpdateWorker(): the non-Windows branch spawns the worker detached without isolating it from the service cgroup.
Locally wrapping the Linux service-managed worker with systemd-run --user --scope --quiet --collect -- <runtime> <worker args> fixed the failure while retaining KillMode=control-group. We verified the worker moved to its own scope and survived the service stop. Retrying through /api/update/run then installed 2.64.0, restarted the service automatically, and reported succeeded after its health stability check.
Related: #587 covers stale job recovery; #4173 covers broader update orchestration. This report concerns the worker being killed during service shutdown.
Checks
Client or integration
OpenCodex dashboard
Area
Service lifecycle
Summary
A dashboard update stopped
opencodex-proxy.serviceand killed its own update worker, leaving the proxy offline and the old package installed. The worker usesdetached: true, but remains in the service's systemd cgroup. The generated unit's defaultKillMode=control-groupterminates it when the updater stops the service.Expected: the updater survives proxy shutdown, completes installation, and restarts the service.
Reproduction
update-job.jsonremainsrunningwith a dead PID. The dashboard origin refuses connections.Version
2.63.0-preview.20260923, updating to 2.64.0. The affected spawn path is also present in the published 2.64.0 package.
Operating system
Ubuntu 24.04.4 LTS, systemd 255.
Provider and model
Not provider-specific.
Cause and tested workaround
src/update/job.ts,spawnGuiUpdateWorker(): the non-Windows branch spawns the worker detached without isolating it from the service cgroup.Locally wrapping the Linux service-managed worker with
systemd-run --user --scope --quiet --collect -- <runtime> <worker args>fixed the failure while retainingKillMode=control-group. We verified the worker moved to its own scope and survived the service stop. Retrying through/api/update/runthen installed 2.64.0, restarted the service automatically, and reportedsucceededafter its health stability check.Related: #587 covers stale job recovery; #4173 covers broader update orchestration. This report concerns the worker being killed during service shutdown.
Checks