Repository navigation
fix: first-boot security updates read Debian's security.sources - #34
Merged
Merged
Conversation
3 of 5 tasks
marcos-mendez
pushed a commit
that referenced
this pull request
Oct 2, 2026
Review of #34: - set -o pipefail: dist-upgrade, dpkg --configure and apt-get update are piped into tee, and a failure ended as tee's success. The modules and /boot listing tolerates a missing /boot, which containers have. - Offline the first boot goes on: the InRelease of the security source is fetched with curl (now a dependency) before anything else, and an unreachable archive or a failed apt-get update is logged to syslog and to the hook's log, naming turnkey-install-security-updates, and the hook exits 0. - force is recorded after a successful install, never before it.
added 2 commits
October 2, 2026 17:29
95secupdates passed /etc/apt/sources.list.d/security.sources.sources as the only sourcelist of its dist-upgrade. That file, written by common's bootstrap, held an enabled archive.turnkeylinux.org stanza, so the first boot of a Keel image fetched from the TurnKey archive. common now writes security.sources with Debian's security archive alone, and the hook reads that name (SEC_UPDATES_SOURCES overrides it for the tests). A missing file now fails the hook: apt reads a missing sourcelist as an empty one, so the upgrade used to succeed having installed nothing. secupdates-ask.py checks it can resolve security.debian.org, where the updates come from, instead of archive.turnkeylinux.org.
Review of #34: - set -o pipefail: dist-upgrade, dpkg --configure and apt-get update are piped into tee, and a failure ended as tee's success. The modules and /boot listing tolerates a missing /boot, which containers have. - Offline the first boot goes on: the InRelease of the security source is fetched with curl (now a dependency) before anything else, and an unreachable archive or a failed apt-get update is logged to syslog and to the hook's log, naming turnkey-install-security-updates, and the hook exits 0. - force is recorded after a successful install, never before it.
marcos-mendez
force-pushed
the
fix/secupdates-debian-security
branch
from
October 2, 2026 17:30
6bb5a7b to
9b0a2af
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Dir::Etc::sourcelist=/etc/apt/sources.list.d/security.sources.sources. common's bootstrap wrote that file with an enabled archive.turnkeylinux.org stanza in it, so the first boot of a Keel image fetched from the TurnKey archive. fix: images take packages from Debian and the Keel repository only common#30 now writessecurity.sourceswith Debian's security archive alone, and the hook reads that name.SEC_UPDATES_SOURCESoverrides the path for the tests.security.debian.org, where the updates come from, instead of archive.turnkeylinux.org.archive.turnkeylinux.orgis removed from the branding test's ALLOWED list.Review fixes (second commit)
set -o pipefail.dist-upgrade,dpkg --configureandapt-get updateall pipe intotee, so a failure ended as tee's success. The listing of/lib/modulesand/bootnow tolerates a missing/boot, as in containers, which would otherwise fail under pipefail.curladded to Depends). If that fails, orapt-get updatefails, it logscannot reach ...orapt-get update failedto syslog and to the hook's log, namesturnkey-install-security-updates, and exits 0. Before, an offlineapt-get updatestopped the hook under -e with nothing logged.forceis recorded only after a successful install, on both the preseeded and the screen path. A failed install, or one that never ran because the machine was offline, leaves no record.secupdates-ask.pystill checks DNS for security.debian.org and shows its error dialog, which fails the hook. That is unchanged here and can be aligned in a follow-up if wanted.Verification
On the step8 Web image in an LXC container, with common#30 applied:
turnkey-install-security-updates(SEC_UPDATES=FORCE) read only security.debian.org trixie-security. With libpng16-16t64 rolled back to the trixie version, the hook fetched1.6.48-1+deb13u6from security.debian.org and installed it. Hook exit 0, and/var/lib/inithooks/sec-updatessaysforce.Test plan
bats tests/test-secupdates.bats: 20 pass (11 new, RED first); kcov 98.6 percent of 95secupdatespytest tests/: 383 pass