Complete managed Gateway upgrades after Node prefix changes while preserving the verified service during preparation and recovering only owned failed activations.
Keep requester/executor and original/candidate ownership through native children; retain uncertain cleanup and original failure outcomes. Source and isolated native component checks are documented in the canonical PR. The wider first-hop installer and other platform journeys remain separate program work.
Closes#107930. Canonical PR history retains the original contributor commits; repository-supported squash preserves explicit contributor credit.
Co-authored-by: Jason (Json) <263060202+fuller-stack-dev@users.noreply.github.com>
Co-authored-by: Peter Steinberger <steipete@gmail.com>
Co-authored-by: Dallin Romney <dallinromney@gmail.com>
* fix(runtime): reuse an available compatible Node at startup
Share startup recovery between the launcher and legacy CLI runtime admission
so older updaters can run target Doctor through dist/index.js under an
already installed compatible Node. Preserve process-contract exclusions,
arguments, environment, standard streams, and exit status.
Refs #140465
* test(runtime): include recovery proof in E2E routing
* fix(runtime): secure Node discovery and decode service scripts
Reject relative candidates and cwd-resolved runtimes before probing, except
for explicit absolute PATH directories. Parse generated Windows command
quoting and recorded code pages without loading application dependencies.
Skip CP850 and CP949 with a diagnostic instead of guessing executable paths.
Use real task-writer fixtures for encoding, quoting, and fallback coverage.
Refs #140465
* fix(runtime): reject cwd-local manager symlinks
* test(runtime): keep recovery home outside launcher cwd
* fix(runtime): isolate recovery from dotenv environment
* fix(runtime): canonicalize discovery paths before use
* fix(runtime): preserve private Node recovery from home
* refactor(runtime): trim Node recovery comments and aliases
Behavior-neutral cleanup of the recovery launcher module: fold the serviceHome and managerHome aliases into homeDir and shorten five comment blocks to the invariant they protect.