Four silent failures a demo on somebody else's Mac walked straight into
Three reported from a colleague's machine, plus one the fixing uncovered. Every one produced a message that was true and useless. ## behavision-setup chose the Python least likely to work findPython walked 3.14, 3.13, 3.12, 3.11, 3.10 and took the first hit - a floor with NO ceiling, which is exactly backwards. The newest Python on a machine is the one least likely to have binary wheels. It picked 3.14, pip found no numpy wheel for cp314, fell back to building numpy from source and produced "Unknown compiler(s)"; once the operator had installed Xcode's command line tools to get past that, ten minutes of compiling ended in "<arm_neon.h> is intended only for ARM and AArch64 targets". maxMinor refuses in one line before anything is downloaded, and "too new" is a different message from "too old" - telling somebody holding Python 3.14 that no Python was found sends them to install a newer one, which is the direction that just failed. ## numpy<2.0 was the cap; OpenCV was the hazard Widening it needed proof, and the proof found something else. Nine runs of the detector guard per combination, one machine, one sitting: numpy 1.26 / cv2 4.11 9 passed, 0 crashed numpy 2.0 / cv2 4.11 8 passed, 1 crashed numpy 1.26 / cv2 4.14 3 passed, 6 crashed numpy 2.0 / cv2 4.14 2 passed, 7 crashed numpy is not the variable; OpenCV is - the third row is numpy 1.26. The crash was test_a_shared_detector_really_does_race, which races a shared cv2.FaceDetectorYN on purpose. That is undefined behaviour in C++: 4.11 usually turned it into an exception, 4.14 usually turns it into a segfault, and 4.11 crashing once says the hazard was always there. It never reached the product - Engine._build_worker builds a detector per camera. It reached the suite: two runs in three died with no failing assertion in them. The race runs in a subprocess now, and one clean attempt proves nothing, so the premise holds if any of several attempts misbehaves. 226 passed / 2 skipped on numpy 2.0.2, five runs of five. opencv stays capped below 5: everything above was measured on 4.x, and an uncapped >=4.8.1 gives every NEW install a major release this project has never run a real camera through. ## One MQTT client id for a whole shop, so two PCs fought over it behavision-<client>-<site> is the same string on every computer claimed to one site. MQTT requires unique client ids and a broker enforces it by disconnecting the older session, so the colleague's Mac and the shop's own till took turns kicking each other off: broker connected / broker connection lost: EOF / broker connected / EOF ... The damage is not confined to the new machine. The till is the other half of that loop, so signing in on a laptop to look at the product stops a live shop delivering visits - and from each end it reads as an unstable network. MQTTClientID() appends a per-installation id, minted on first load and written back so an existing install gets one without anybody doing anything. The site stays in the name because that is what a broker log is read by. An unwritable config falls back to a per-run id rather than a shared one. ## "no such file or directory" for an engine nobody had installed Pressing Start went straight to the supervisor, which reported what exec reported: a 200-character path ending in "no such file or directory". Every word true, none of it saying "run the setup tool" - the startup path had that sentence, in a log file nobody on a shop counter opens. engineMissing() is the one function the startup path, the Start button and the status panel all consult. It also names App Translocation, which was in that path and is unguessable: macOS runs a downloaded unsigned app from a random read-only copy, so relative paths resolve inside it and an install there would not survive a restart. The product is unsigned, so that is the normal first-run state on every Mac, not an edge case. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01KGcjxF1cNLcuwc3DAPcnfj
This commit is contained in:
@@ -44,6 +44,9 @@ type App struct {
|
||||
broker *agentmqtt.Client
|
||||
stopBridge func()
|
||||
hookURL string
|
||||
// The resolved engine command, so engineMissing() and the supervisor are
|
||||
// never looking at two different paths.
|
||||
engineExe string
|
||||
// Relays camera feeds to the webview so the engine's credential never has
|
||||
// to travel in an <img> src, which a Chromium webview would strip anyway.
|
||||
proxy *streamProxy
|
||||
@@ -109,6 +112,9 @@ func (a *App) startup(ctx context.Context) {
|
||||
if exe != "" && !filepath.IsAbs(exe) {
|
||||
exe = filepath.Join(agentpaths.InstallRoot(), exe)
|
||||
}
|
||||
a.mu.Lock()
|
||||
a.engineExe = exe
|
||||
a.mu.Unlock()
|
||||
logFile, _ := agentengine.LogFile(agentpaths.EngineLog())
|
||||
a.sup = agentengine.New(agentengine.Options{
|
||||
Command: func(c context.Context) *exec.Cmd {
|
||||
@@ -154,13 +160,55 @@ func (a *App) startup(ctx context.Context) {
|
||||
// not run yet, starting the supervisor would loop on a missing executable
|
||||
// with nothing useful to say. The Start button still exists for the one
|
||||
// case where somebody has deliberately stopped it.
|
||||
if _, err := os.Stat(exe); err == nil {
|
||||
if why := a.engineMissing(); why == "" {
|
||||
a.sup.Start()
|
||||
} else {
|
||||
log.Printf("engine not installed yet (%s); run behavision-setup, then Start", exe)
|
||||
log.Printf("%s (looked for %s)", why, exe)
|
||||
}
|
||||
}
|
||||
|
||||
// engineMissing says, in a sentence somebody can act on, why recognition
|
||||
// cannot start here - or "" when it can.
|
||||
//
|
||||
// It exists because the answer was only ever given at startup, to a log file
|
||||
// nobody on a shop counter opens. Pressing Start went straight to the
|
||||
// supervisor, which reported what exec reported:
|
||||
//
|
||||
// engine failed to start: fork/exec /private/var/folders/c2/.../
|
||||
// AppTranslocation/500A5354-.../d/Behavision.app/Contents/MacOS/engine/
|
||||
// behavision: no such file or directory
|
||||
//
|
||||
// Every word of that is true and none of it says "run the setup tool". One
|
||||
// function, consulted by the startup path, the Start button and the status
|
||||
// panel, so the three cannot give three different accounts of one fact.
|
||||
func (a *App) engineMissing() string {
|
||||
a.mu.RLock()
|
||||
exe := a.engineExe
|
||||
a.mu.RUnlock()
|
||||
if exe == "" {
|
||||
return "The recognition engine is not set up on this computer yet."
|
||||
}
|
||||
if _, err := os.Stat(exe); err == nil {
|
||||
return ""
|
||||
}
|
||||
msg := "The recognition engine is not installed on this computer yet. " +
|
||||
"Run behavision-setup from the folder you unzipped, then press Start."
|
||||
// macOS quarantines a downloaded app it cannot verify and runs it from a
|
||||
// randomly named READ-ONLY copy - App Translocation. Every relative path
|
||||
// then resolves inside that copy, which is why the engine folder appears
|
||||
// to be missing from a bundle that plainly contains one, and why an
|
||||
// install into it would not survive a restart. Detectable, unguessable,
|
||||
// and fixed by one drag; saying nothing leaves somebody re-running a
|
||||
// setup tool that cannot win.
|
||||
if strings.Contains(exe, "/AppTranslocation/") {
|
||||
msg = "macOS is running Behavision from a temporary read-only copy, " +
|
||||
"because it was opened straight from Downloads. Move Behavision " +
|
||||
"to your Applications folder and open it from there, then run " +
|
||||
"behavision-setup."
|
||||
}
|
||||
return msg
|
||||
}
|
||||
|
||||
// webhookURL is the loopback address the bridge is listening on, or empty
|
||||
// before it has started.
|
||||
func (a *App) webhookURL() string {
|
||||
@@ -242,7 +290,7 @@ func (a *App) startPipeline(ctx context.Context) {
|
||||
}
|
||||
client, err := agentmqtt.NewClient(agentmqtt.ClientOptions{
|
||||
BrokerURL: a.cfg.BrokerURL,
|
||||
ClientID: "behavision-" + a.cfg.ClientID + "-" + a.cfg.SiteID,
|
||||
ClientID: a.cfg.MQTTClientID(),
|
||||
Username: a.cfg.BrokerUsername, Password: a.cfg.BrokerPassword,
|
||||
CAFile: a.cfg.BrokerCAFile, Log: logger,
|
||||
})
|
||||
@@ -595,6 +643,11 @@ func (a *App) EngineStatus() EngineStatus {
|
||||
if err != nil {
|
||||
out.Error = err.Error()
|
||||
}
|
||||
// The supervisor's own error is an exec failure; this replaces it with
|
||||
// the reason, which is the part that tells somebody what to do.
|
||||
if why := a.engineMissing(); why != "" {
|
||||
out.Error = why
|
||||
}
|
||||
ctx, cancel := context.WithTimeout(a.ctx, 4*time.Second)
|
||||
defer cancel()
|
||||
// A running process is not a working engine: on a memory-starved box the
|
||||
@@ -609,6 +662,13 @@ func (a *App) EngineStatus() EngineStatus {
|
||||
}
|
||||
|
||||
func (a *App) StartEngine() EngineStatus {
|
||||
// Refused rather than attempted. Handing a missing path to the supervisor
|
||||
// produces a retry loop and an exec error for a message.
|
||||
if why := a.engineMissing(); why != "" {
|
||||
st := a.EngineStatus()
|
||||
st.Error = why
|
||||
return st
|
||||
}
|
||||
if a.sup != nil {
|
||||
a.sup.Start()
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user