Some checks failed
ClawSweeper Dispatch / dispatch (push) Has been cancelled
CodeQL / Security High (actions) (push) Has been cancelled
CodeQL / Security High (channel-runtime-boundary) (push) Has been cancelled
CodeQL / Security High (core-auth-secrets) (push) Has been cancelled
CodeQL / Security High (mcp-process-tool-boundary) (push) Has been cancelled
CodeQL / Security High (network-ssrf-boundary) (push) Has been cancelled
CodeQL / Security High (plugin-trust-boundary) (push) Has been cancelled
CodeQL / Security High (process-exec-boundary) (push) Has been cancelled
Docs Sync Publish Repo / sync-publish-repo (push) Has been cancelled
Docs / docs (push) Has been cancelled
OpenClaw Stable Main Closeout / Resolve stable release closeout inputs (push) Has been cancelled
OpenClaw Stable Main Closeout / Verify stable main closeout (push) Has been cancelled
Workflow Sanity / no-tabs (push) Has been cancelled
Workflow Sanity / actionlint (push) Has been cancelled
Workflow Sanity / generated-doc-baselines (push) Has been cancelled
CI / runner-admission (push) Has been cancelled
CI / preflight (push) Has been cancelled
CI / security-fast (push) Has been cancelled
CI / pnpm-store-warmup (push) Has been cancelled
CI / build-artifacts (push) Has been cancelled
CI / native-i18n (push) Has been cancelled
CI / ${{ matrix.check_name }} (push) Has been cancelled
CI / ${{ matrix.checkName }} (push) Has been cancelled
CI / checks-node-compat-node22 (push) Has been cancelled
CI / check-bundled-channel-config-metadata (push) Has been cancelled
CI / check-dependencies (push) Has been cancelled
CI / check-guards (push) Has been cancelled
CI / check-lint (push) Has been cancelled
CI / check-prod-types (push) Has been cancelled
CI / check-shrinkwrap (push) Has been cancelled
CI / check-test-types (push) Has been cancelled
CI / check-additional-boundaries-a (push) Has been cancelled
CI / check-additional-boundaries-bcd (push) Has been cancelled
CI / check-additional-extension-bundled (push) Has been cancelled
CI / check-additional-extension-channels (push) Has been cancelled
CI / check-additional-extension-package-boundary (push) Has been cancelled
CI / check-additional-runtime-topology-architecture (push) Has been cancelled
CI / check-session-accessor-boundary (push) Has been cancelled
CI / check-session-transcript-reader-boundary (push) Has been cancelled
CI / check-docs (push) Has been cancelled
CI / skills-python (push) Has been cancelled
CI / macos-swift (push) Has been cancelled
CI / ios-build (push) Has been cancelled
CI / ci-timings-summary (push) Has been cancelled
Native App Locale Refresh / Refresh native fa (push) Has been cancelled
Native App Locale Refresh / Refresh native fr (push) Has been cancelled
Native App Locale Refresh / Refresh native hi (push) Has been cancelled
Native App Locale Refresh / Refresh native id (push) Has been cancelled
Native App Locale Refresh / Refresh native it (push) Has been cancelled
Native App Locale Refresh / Refresh native ja-JP (push) Has been cancelled
Control UI Locale Refresh / plan (push) Has been cancelled
Control UI Locale Refresh / Refresh ${{ matrix.locale }} (push) Has been cancelled
Control UI Locale Refresh / Commit control UI locale refresh (push) Has been cancelled
Live Media Runner Image / Build live media runner image (push) Has been cancelled
Native App Locale Refresh / Refresh native ar (push) Has been cancelled
Native App Locale Refresh / Refresh native de (push) Has been cancelled
Native App Locale Refresh / Refresh native es (push) Has been cancelled
Native App Locale Refresh / Refresh native ko (push) Has been cancelled
Native App Locale Refresh / Refresh native nl (push) Has been cancelled
Native App Locale Refresh / Refresh native pl (push) Has been cancelled
Native App Locale Refresh / Refresh native pt-BR (push) Has been cancelled
Native App Locale Refresh / Refresh native ru (push) Has been cancelled
Native App Locale Refresh / Refresh native sv (push) Has been cancelled
Native App Locale Refresh / Refresh native th (push) Has been cancelled
Native App Locale Refresh / Refresh native tr (push) Has been cancelled
Native App Locale Refresh / Refresh native uk (push) Has been cancelled
Native App Locale Refresh / Refresh native vi (push) Has been cancelled
Native App Locale Refresh / Refresh native zh-CN (push) Has been cancelled
Native App Locale Refresh / Refresh native zh-TW (push) Has been cancelled
Native App Locale Refresh / Commit native locale refresh (push) Has been cancelled
Plugin Init Scaffold Validation / Validate provider scaffold (push) Has been cancelled
Plugin NPM Release / preview_plugins_npm (push) Has been cancelled
Plugin NPM Release / Validate release publish approval (push) Has been cancelled
Plugin NPM Release / preview_plugin_pack (push) Has been cancelled
Plugin NPM Release / publish_plugins_npm (push) Has been cancelled
Sandbox Common Smoke / sandbox-common-smoke (push) Has been cancelled
Website Installer Sync / static (push) Has been cancelled
Website Installer Sync / linux-docker (push) Has been cancelled
Website Installer Sync / macos-installer (push) Has been cancelled
Website Installer Sync / windows-installer (push) Has been cancelled
Website Installer Sync / sync-website (push) Has been cancelled
Adolf is a fork/vendored clone of github.com/openclaw/openclaw (v2026.6.11), free to diverge. Tree copied sans upstream .git; upstream remote added for future syncs. Node pinned to 24 (.nvmrc); engines already require >=22.19. Preserves docs/ARCHITECTURE.md. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01LeqyaxJF2nbRXJtae2kNB2
192 lines
4.8 KiB
Bash
Executable File
192 lines
4.8 KiB
Bash
Executable File
#!/usr/bin/env bash
|
|
# Scan for orphaned coding agent processes after a gateway restart.
|
|
#
|
|
# Background coding agents (Claude Code, Codex CLI) spawned by the gateway
|
|
# can outlive the session that started them when the gateway restarts.
|
|
# This script finds them and reports their state.
|
|
#
|
|
# Usage:
|
|
# recover-orphaned-processes.sh
|
|
#
|
|
# Output: JSON object with `orphaned` array and `ts` timestamp.
|
|
set -euo pipefail
|
|
|
|
usage() {
|
|
cat <<'USAGE'
|
|
Usage: recover-orphaned-processes.sh
|
|
|
|
Scans for likely orphaned coding agent processes and prints JSON.
|
|
USAGE
|
|
}
|
|
|
|
if [ "${1:-}" = "--help" ] || [ "${1:-}" = "-h" ]; then
|
|
usage
|
|
exit 0
|
|
fi
|
|
|
|
if [ "$#" -gt 0 ]; then
|
|
usage >&2
|
|
exit 2
|
|
fi
|
|
|
|
if ! command -v node &>/dev/null; then
|
|
_ts="unknown"
|
|
command -v date &>/dev/null && _ts="$(date -u +%Y-%m-%dT%H:%M:%SZ 2>/dev/null)" || true
|
|
[ -z "$_ts" ] && _ts="unknown"
|
|
printf '{"error":"node not found on PATH","orphaned":[],"ts":"%s"}\n' "$_ts"
|
|
exit 0
|
|
fi
|
|
|
|
node <<'NODE'
|
|
const { execFileSync } = require("node:child_process");
|
|
const fs = require("node:fs");
|
|
|
|
let username = process.env.USER || process.env.LOGNAME || "";
|
|
|
|
if (username && !/^[a-zA-Z0-9._-]+$/.test(username)) {
|
|
username = "";
|
|
}
|
|
|
|
function runFile(file, args) {
|
|
try {
|
|
return execFileSync(file, args, {
|
|
encoding: "utf8",
|
|
stdio: ["ignore", "pipe", "ignore"],
|
|
});
|
|
} catch (err) {
|
|
if (err && typeof err.stdout === "string") {
|
|
return err.stdout;
|
|
}
|
|
if (err && err.stdout && Buffer.isBuffer(err.stdout)) {
|
|
return err.stdout.toString("utf8");
|
|
}
|
|
return "";
|
|
}
|
|
}
|
|
|
|
function resolveStarted(pid) {
|
|
const started = runFile("ps", ["-o", "lstart=", "-p", String(pid)]).trim();
|
|
return started.length > 0 ? started : "unknown";
|
|
}
|
|
|
|
function resolveCwd(pid) {
|
|
if (process.platform === "linux") {
|
|
try {
|
|
return fs.readlinkSync(`/proc/${pid}/cwd`);
|
|
} catch {
|
|
return "unknown";
|
|
}
|
|
}
|
|
const lsof = runFile("lsof", ["-a", "-d", "cwd", "-p", String(pid), "-Fn"]);
|
|
const match = lsof.match(/^n(.+)$/m);
|
|
return match ? match[1] : "unknown";
|
|
}
|
|
|
|
function sanitizeCommand(cmd) {
|
|
// Avoid leaking obvious secrets when this diagnostic output is shared.
|
|
return cmd
|
|
.replace(
|
|
/(--(?:token|api[-_]?key|password|secret|authorization)\s+)([^\s]+)/gi,
|
|
"$1<redacted>",
|
|
)
|
|
.replace(
|
|
/((?:token|api[-_]?key|password|secret|authorization)=)([^\s]+)/gi,
|
|
"$1<redacted>",
|
|
)
|
|
.replace(/(Bearer\s+)[A-Za-z0-9._~+/=-]+/g, "$1<redacted>");
|
|
}
|
|
|
|
// Pre-filter candidate PIDs using pgrep to avoid scanning all processes.
|
|
// Only falls back to a full ps scan when pgrep is genuinely unavailable
|
|
// (ENOENT), not when it simply finds no matches (exit code 1).
|
|
let pgrepUnavailable = false;
|
|
const pgrepResult = (() => {
|
|
const args =
|
|
username.length > 0
|
|
? ["-u", username, "-f", "codex|claude"]
|
|
: ["-f", "codex|claude"];
|
|
try {
|
|
return execFileSync("pgrep", args, {
|
|
encoding: "utf8",
|
|
stdio: ["ignore", "pipe", "ignore"],
|
|
});
|
|
} catch (err) {
|
|
if (err && err.code === "ENOENT") {
|
|
pgrepUnavailable = true;
|
|
return "";
|
|
}
|
|
// pgrep exit code 1 = no matches — return stdout (empty)
|
|
if (err && typeof err.stdout === "string") return err.stdout;
|
|
return "";
|
|
}
|
|
})();
|
|
|
|
const candidatePids = pgrepResult
|
|
.split("\n")
|
|
.map((s) => s.trim())
|
|
.filter((s) => s.length > 0 && /^\d+$/.test(s));
|
|
|
|
let lines;
|
|
if (candidatePids.length > 0) {
|
|
// Fetch command info only for candidate PIDs.
|
|
lines = runFile("ps", ["-o", "pid=,command=", "-p", candidatePids.join(",")]).split("\n");
|
|
} else if (pgrepUnavailable && username.length > 0) {
|
|
// pgrep not installed — fall back to user-scoped ps scan.
|
|
lines = runFile("ps", ["-U", username, "-o", "pid=,command="]).split("\n");
|
|
} else if (pgrepUnavailable) {
|
|
// pgrep not installed and no username — full scan as last resort.
|
|
lines = runFile("ps", ["-axo", "pid=,command="]).split("\n");
|
|
} else {
|
|
// pgrep ran successfully but found no matches — no orphans.
|
|
lines = [];
|
|
}
|
|
|
|
const includePattern = /codex|claude/i;
|
|
|
|
const excludePatterns = [
|
|
/openclaw-gateway/i,
|
|
/signal-cli/i,
|
|
/node_modules\/\.bin\/openclaw/i,
|
|
/recover-orphaned-processes\.sh/i,
|
|
];
|
|
|
|
const orphaned = [];
|
|
|
|
for (const rawLine of lines) {
|
|
const line = rawLine.trim();
|
|
if (!line) {
|
|
continue;
|
|
}
|
|
const match = line.match(/^(\d+)\s+(.+)$/);
|
|
if (!match) {
|
|
continue;
|
|
}
|
|
|
|
const pid = Number(match[1]);
|
|
const cmd = match[2];
|
|
if (!Number.isInteger(pid) || pid <= 0 || pid === process.pid) {
|
|
continue;
|
|
}
|
|
if (!includePattern.test(cmd)) {
|
|
continue;
|
|
}
|
|
if (excludePatterns.some((pattern) => pattern.test(cmd))) {
|
|
continue;
|
|
}
|
|
|
|
orphaned.push({
|
|
pid,
|
|
cmd: sanitizeCommand(cmd),
|
|
cwd: resolveCwd(pid),
|
|
started: resolveStarted(pid),
|
|
});
|
|
}
|
|
|
|
process.stdout.write(
|
|
JSON.stringify({
|
|
orphaned,
|
|
ts: new Date().toISOString(),
|
|
}) + "\n",
|
|
);
|
|
NODE
|