Fix Home 2.1 sensor shutdown before signal replay - #52
Merged
Merged
Conversation
Pin guest-local hostname and resolver files, verify their archive contents, and preserve bounded internal relay diagnostics. Give launchd and package lifecycle checks sufficient time for ordered sensor cleanup. Record Apple Silicon support, the completed Mini protocol and alert acceptance, reproducible regression fixtures, and the remaining publication gates. Stabilize the closed-peer helper test and keep private evidence outside Git.
chrissyrocket
approved these changes
Oct 2, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Change
Complete sensor runtime cleanup inside Uvicorn's signal-capture scope, before
SIGTERM/SIGINT replay can skip or interrupt teardown. Retain the outer startup
cleanup fallback and idempotent resource teardown.
Real subprocess tests failed for both signals before the fix and pass afterward.
Additional tests cover startup failure, cancellation, cleanup errors, exception
precedence, and one-time cleanup. One existing test now explicitly narrows its
nullable diagnostic reason, resolving its type-check error without runtime changes.
No attacker-visible decoy behavior, PF rules, UID guards, credentials, or network
filter configuration changed. Development instructions, release notes, and the
September 29 verification record are updated.
Verification
deep/strict ad-hoc code-signature verification passed.
Local package SHA-256:
541fc783c41fd2f9a6baba1fe8edae93078a0a24089b8e6d4ede77ba051b7fb1Release boundary
This is not release approval. The mini's earlier SSH/SMB/HTTP acceptance run
still failed despite successful TCP handshakes, and the shared flow stall has
not been attributed to a particular filter or component. The shutdown fix is
separate from that failure. Cleanup is complete and the app remains closed.
The package is unsigned/unnotarized and was not installed. Live protocol tests,
the separately scoped A5 matrix, independent review, green exact-commit CI and
the protected signing/publication workflow remain required. No release tag or
workflow has been dispatched.