Skip to content

fix(cli): keepiq ssh-agent stays in the foreground under systemd - #1144

Merged
rubenvdlinde merged 1 commit into
developmentfrom
fix/ssh-agent-systemd-foreground
Oct 4, 2026
Merged

rubenvdlinde merged 1 commit into
developmentfrom
fix/ssh-agent-systemd-foreground

Conversation

@rubenvdlinde

Copy link
Copy Markdown
Contributor

The systemd user unit in cli/README.md never kept the agent running. Under systemd, stdout is the journal rather than a terminal, so keepiq ssh-agent took the eval path from #1022: it started a background copy and its own process exited 0. systemd then stopped the unit and killed that copy along with the rest of its cgroup. launchd was not affected, because it gives the agent /dev/null, which counts as a terminal for this check. Lane K found this while building the macOS job (#1142).

  • New option: --foreground keeps the agent in the process the service manager started. The README unit now uses it, and the option is documented.
  • Test: the detach decision is now shouldDetach(), pinned by TestTheAgentDetachesOnlyForEvalNotUnderAServiceManager, which did not build before the fix. go vet and go test ./... pass in cli/ (golang:1.25) and gofmt is clean.
  • Reproduced in golang:1.25 as a non-root user, with stdout sent to a file as under systemd:
    • Without --foreground, the main process exited 0 and the agent detached.
    • With it, the main process kept serving and its socket was 0600.
  • CHANGELOG: a Fixed entry.

Not run under a real systemd.

Under systemd the agent's stdout is the journal, not a terminal, so it took
the eval path (#1022): it started a background copy and its main process
exited 0. systemd then stopped the unit and killed the copy with the cgroup,
so the README's service never kept running. Found by the macOS CI lane (#1142).

--foreground keeps the agent in the process systemd started; the README unit
uses it. The detach decision is now shouldDetach(), pinned by a test.
@rubenvdlinde
rubenvdlinde merged commit add76d4 into development Oct 4, 2026
13 of 14 checks passed
@github-actions

github-actions Bot commented Oct 4, 2026

Copy link
Copy Markdown
Contributor

Quality Report — ConductionNL/keepiq @ ffb2dc3

Check PHP Vue Security License Tests
lint ✅
phpcs ✅
phpmd ✅
psalm ✅
phpstan ✅
phpmetrics ✅
eslint ✅
stylelint ✅
build ✅
check-manifest ✅
test-l10n ✅
format ✅
check-l10n-js ✅
check-schema-l10n ✅
composer ✅ ✅ 114/114
npm ✅ ✅ 660/660
app:check-code ⏭️
info.xml ✅
REUSE ✅
lockfile sync ✅
PHPUnit ⏭️ not run for this diff — no file in this diff matches the code globs, and none carries a source extension — the heavy tier has nothing to decide about it.
Newman ❌
Playwright ⏭️ deferred: E2E runs locally and on the promotion path only. This pull request targets development, so the suite is asked once per promotion into beta and main rather than once per push per open pull request. Run it locally with npx playwright test, or from the Actions tab on a branch with no open pull request into development.
Hydra gates ✅

Quality workflow — 2026-10-04 14:42 UTC

Download the full PDF report from the workflow artifacts.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant