8118408796 fix(runner): prevent ghost sessions from orphaned spawn webhooks (#440)
* fix(runner): prevent ghost sessions from orphaned spawn webhooks

spawnSession() registers a tracked session entry before the child's
"Session started" webhook arrives. When the 15s webhook timeout fires,
only pidToAwaiter / pidToErrorAwaiter are cleared; the
pidToTrackedSession entry is left in place and the detached child
keeps running. If the child eventually starts and reports its webhook,
onHappySessionWebhook() still finds the stale tracking entry and
promotes the orphan into a normal runner-managed session, surfacing
a message-less "ghost session" in the web UI.

This is easy to reproduce on opus[1m] --resume: observed real-world
case where four rapid "resume" clicks produced four orphan children
that all reported their webhooks ~60 minutes later, creating four
ghost sessions on the dashboard.

Three-part fix:

1. Make the webhook timeout configurable via
   HAPI_RUNNER_WEBHOOK_TIMEOUT_MS (default unchanged at 15_000). Users
   on slow models / large resumes can raise the ceiling so the
   timeout never fires in the first place.

2. On timeout, also delete the pidToTrackedSession entry and SIGTERM
   the child, so a late webhook cannot promote the orphan.

3. Defence in depth: if onHappySessionWebhook() receives a webhook
   from a PID that is not tracked but whose payload claims
   startedBy: 'runner', ignore it and SIGTERM the child. Genuine
   terminal-launched children correctly report
   startedBy: 'terminal', so this branch cannot false-positive on
   them.

* fix(runner): use tree-kill on timeout and clean up worktree for orphans

Address review feedback on the kill path and worktree cleanup:

1. Timeout handler: replace bare `happyProcess.kill('SIGTERM')` with
   `killProcessByChildProcess(happyProcess)` so the entire process tree
   (wrapper + detached agent grandchildren) is reaped, matching the
   existing `stopSession()` behaviour.

2. Orphan webhook handler: replace bare `process.kill(pid, 'SIGTERM')`
   with `killProcess(pid)` for proper SIGTERM → SIGKILL escalation.
   A ChildProcess reference is unavailable here (tracking entry already
   removed), so tree-kill is not possible — but the timeout handler
   should have already tree-killed the group; this is defence-in-depth.

3. Worktree leak: when a worktree session times out, register a
   one-shot `exit` listener on the child process to run
   `cleanupWorktree()` after the child actually exits.  Previously
   `maybeCleanupWorktree('spawn-error')` would skip cleanup because
   the child was still alive at that point, and `onChildExited()` had
   no worktree awareness after the tracking entry was deleted — so the
   worktree leaked permanently.

---------

Co-authored-by: fengtian <fengtian@users.noreply.github.com>
2026-04-25 10:55:59 +08:00
2026-03-08 11:13:56 +08:00
2026-04-25 10:48:12 +08:00
2026-04-25 10:48:12 +08:00
2026-04-25 10:48:12 +08:00
2026-04-25 10:54:49 +08:00
2026-03-06 20:26:18 +08:00
2026-01-04 20:45:15 +08:00
2026-03-20 12:15:24 +08:00
2026-03-29 09:47:17 +08:00
2025-12-16 15:03:50 +08:00

HAPI

Run official Claude Code / Codex / Gemini / OpenCode sessions locally and control them remotely through a Web / PWA / Telegram Mini App.

Why HAPI? HAPI is a local-first alternative to Happy. See Why Not Happy? for the key differences.

Features

  • Seamless Handoff - Work locally, switch to remote when needed, switch back anytime. No context loss, no session restart.
  • Native First - HAPI wraps your AI agent instead of replacing it. Same terminal, same experience, same muscle memory.
  • AFK Without Stopping - Step away from your desk? Approve AI requests from your phone with one tap.
  • Your AI, Your Choice - Claude Code, Codex, Cursor Agent, Gemini, OpenCode—different models, one unified workflow.
  • Terminal Anywhere - Run commands from your phone or browser, directly connected to the working machine.
  • Voice Control - Talk to your AI agent hands-free using the built-in voice assistant.

Demo

https://github.com/user-attachments/assets/38230353-94c6-4dbe-9c29-b2a2cc457546

Getting Started

npx @twsxtd/hapi hub --relay     # start hub with E2E encrypted relay
npx @twsxtd/hapi                 # run claude code

hapi server remains supported as an alias.

The terminal will display a URL and QR code. Scan the QR code with your phone or open the URL to access.

The relay uses WireGuard + TLS for end-to-end encryption. Your data is encrypted from your device to your machine.

For self-hosted options (Cloudflare Tunnel, Tailscale), see Installation

Docs

Build from source

bun install
bun run build:single-exe

Credits

HAPI means "哈皮" a Chinese transliteration of Happy. Great credit to the original project.

S
Description
GitHub 镜像: wu736139669/hapi(每日自动同步)
Readme AGPL-3.0
103 MiB
Languages
TypeScript 99.5%
CSS 0.2%
JavaScript 0.2%
HTML 0.1%