Skip to content

fix: reconcile headless managed settings without prompting - #1008

Merged
tt-le merged 2 commits into
mainfrom
tt-le/ug-headless-reconciliation-stacked
Oct 8, 2026
Merged

tt-le merged 2 commits into
mainfrom
tt-le/ug-headless-reconciliation-stacked

Conversation

@tt-le

@tt-le tt-le commented Oct 6, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

Headless Claude/Codex launches fail when an existing OS-managed file overrides UG's gateway settings. Allow those conflicting files to be repaired using one-shot sudo -n with stdin disconnected. Authorization failures still block launch; there is no password-prompt fallback.

Reuse the existing backup, policy-preserving composition, atomic write, and verification. Leave absent/compatible files unchanged. Headless creation, revert, and managed MCP writes remain out of scope.

This PR targets main; the separate stdout/JSON fix (#1007) is already merged. Preventing Isaac from replacing UG's apiKeyHelper and propagating harness exit codes remain separate Isaac work.

Validation

  • Reproduced end-to-end against a local Isaac build pinned to this branch: opened Isaac Omni (interactive) to establish the OS-managed-settings state, then ran headless Isaac with JSON output (isaac -p ... --output-format json). The headless launch — which fails on main — succeeded and returned JSON, confirming the fix.
  • 610 managed-file, Claude, Codex, managed-model lifecycle, and managed-resolve component tests passed.
  • Ruff check/format, type checking, and git diff --check passed.
  • The automated suite mocks the privileged write, so no live inference, real sudo, or /etc writes run there; those paths were exercised by the local Isaac repro above.

This pull request description was written with AI assistance.

@tt-le
tt-le force-pushed the tt-le/ug-headless-reconciliation-stacked branch from 93803fd to 3f45f81 Compare October 6, 2026 20:22
Base automatically changed from tt-le/ug-headless-stdout-only to main October 6, 2026 20:44
sunishsheth2009 pushed a commit to sunishsheth2009/ucode that referenced this pull request Oct 6, 2026
## Stack

1. **This PR:** keep headless Claude/Codex stdout clean; targets `main`,
merges independently.
2. Follow-up: databricks#1008 — non-prompting managed-settings reconciliation.

## Problem

`isaac --claude -p --output-format json … > out.json` produces invalid
JSON because UG prints status lines to stdout before the agent's output.
Reported with Isaac `2.0.0-20261005192727-d3c9edb` / UG `0.1.0+0857d42`
([Slack](https://databricks.slack.com/archives/C0AH87SNGNT/p1790166359916159)).

The thread also contains a second, separate failure: when the OS-managed
settings differ on a UG-owned key (e.g. Isaac's `jq …
model-serving-token.json` `apiKeyHelper`), headless launches stop with
`cannot be applied non-interactively`. That is databricks#1008, not this PR.

## Changes

- For Claude `-p`/`--print` and Codex `exec`/`e`/`app-server`, send UG
status and bootstrap/install output to stderr. The agent's own stdout is
untouched.
- Detect headless mode by argument membership before the agent's `--`
(no Codex option parser). Matching an option value only moves UG
diagnostics to stderr.
- Unit/component regressions for streams, errors, forwarding, and
bootstrap subprocesses; live headless journeys now parse raw JSON/JSONL.

## Validation

- Unit/component suites, Ruff, ty pass; CI green.
- confirmed with local isaac build that `--p --output-format json` and
`exec --json` produce valid jsons.
| Case | `main` @ `4c1b866` | this PR @ `39f2d12` |
|---|---|---|
| `ug claude -- -p --output-format json` | ❌ | ✅ |
| `ug claude -- --print --output-format json` | ❌ | ✅ |
| `ug claude -- -p --output-format stream-json --verbose` | ❌ | ✅ |
| `ug claude -- -p` (text) | ❌ | ✅ |
| `ug claude -- --output-format json --model sonnet -p` | ❌ | ✅ |
| `ug claude -- -p … \| python3 -m json.tool` | ❌ | ✅ |
| `ug codex exec --json` | ❌ | ✅ |
| `ug codex e --json` | ❌ | ✅ |
| `ug codex -c … exec --json` | ❌ | ✅ |
| `ug codex exec` (text) | ❌ | ✅ |
| `ug codex exec --output-schema …` (stdout) | ❌ | ✅ |
| `ug codex exec --output-schema … -o file` (file) | ✅ | ✅ |

## Scope

No managed-settings, sudo, or Isaac changes (e.g. Isaac exit-code
propagation, Isaac replacing `apiKeyHelper`).

This pull request and its description were written by Isaac.
@tt-le
tt-le force-pushed the tt-le/ug-headless-reconciliation-stacked branch from 3f45f81 to be771e4 Compare October 7, 2026 13:20
@tt-le
tt-le force-pushed the tt-le/ug-headless-reconciliation-stacked branch from be771e4 to 1520d3f Compare October 7, 2026 13:40
`managed_writes_allowed()` was doing double duty: with `repair_existing` it is the write-authorization gate, but its no-arg form was borrowed as an "is a terminal attached?" check at the sudo-mode sites, so `non_interactive = not managed_writes_allowed()` read backwards. Extract `_sudo_may_prompt()` for the TTY/prompt-mode check and build `managed_writes_allowed()` on top of it; the three prompt-mode sites now call `_sudo_may_prompt()` while the authorization-gate sites keep `managed_writes_allowed`. Behavior is unchanged (`_sudo_may_prompt()` equals the former no-arg form).

Co-authored-by: Isaac <no-reply@databricks.com>
@tt-le
tt-le requested a review from david-siqi-liu October 7, 2026 16:38
@david-siqi-liu david-siqi-liu added the ug-review Run the automated UG review label Oct 8, 2026
@github-actions

github-actions Bot commented Oct 8, 2026

Copy link
Copy Markdown

UG review

Reviewed headless Claude/Codex managed-file reconciliation and the shared privileged writer, focusing on non-prompting sudo, configuration ownership, backup preservation, and interactive compatibility.

No actionable findings.

Automated advisory review of eef3ebb74b2d using Lilly's UG review rubric. It does not approve or block this PR.

@tt-le
tt-le added this pull request to the merge queue Oct 8, 2026
Merged via the queue into main with commit c90633d Oct 8, 2026
29 checks passed
@tt-le
tt-le deleted the tt-le/ug-headless-reconciliation-stacked branch October 8, 2026 18:46
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

ug-review Run the automated UG review

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants