Repository navigation
fix: no silent gap between first boot screens; keep a root password set at creation - #35
Merged
Merged
Conversation
added 3 commits
October 2, 2026 13:49
…et at creation
On a Proxmox VE container of the step8 Web image the console stayed on
"Did you save the password?" after <Saved> until the Keel Cloud screen
came. Nothing hung. Measured on LXC: 2 s, 15 s with a quarter of a CPU,
spent in the boot wait (before every hook from 30 on, eleven systemctl
calls and up to 10 s of sleep each while the system is starting) and in
75keel-role's keel inspect, with nothing new on the screen.
run waits for a starting system once per run and stops as soon as it is
up; each first boot hook, and the wait, is named on the terminal in a
box with the first boot backtitle ("Configuring keel-role... please
wait"). Nothing is drawn off a terminal or with REDIRECT_OUTPUT.
The password screen offers Keep first when root can already log in with
a password at first boot (pct create --password, LXC writing
/etc/shadow): passwd -S is the only question, the hash is never read.
No prior password, a preseeded ROOT_PASS, secrets.root_password and
keel-init behave as before.
tests/test-firstboot-pty.bats runs run, 30rootpass, setpass.py and the
real dialog on a pty under script, with a timeout, and fails on a hang
or on a screen drawn into a pipe.
dialog_wrapper logged to /var/log/dialog.log unconditionally, so setpass.py failed for the CI runner's user and every password screen of the pty test was missing. DIALOG_LOG names another file; the test points it into its scratch directory and lets PYTHONPATH carry what the caller set. The Keep assertion reads the recommendation, which a runner outside a container shows too.
2 tasks
Review of #35: passwd -S says P for a password a build with ROOT_PASS left, and for U6aMy0wojraho, which five older WordPress images ship, so Keep was offered as recommended for a password every copy shares. Keep now also needs the image's build date (/etc/keel/build-date, from common's seal-root, which fails a build whose root is not locked) and a last change on or after it, and a shadow field that is neither empty nor a known placeholder. The field is compared, never printed or logged; an image without the date gets no Keep.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What the maintainer saw
Proxmox VE 9.2.11, an LXC container from the step8 Web image, root password set in
pct create. On the console he chose Generate and pressed . The console then stayed on "Did you save the password?" for a while and came back by itself.What runs in that gap
I reproduced it on LXC (freeze-test on the test VM, root password set with chpasswd in the rootfs before first boot, tty1 driven with
lxc-console -t 1in tmux). Nothing hangs and no dialog goes to a pipe:ps -ef --forestat the gap showsrun>80keel-cloud>keelfirstboot.py cloud>dialog, with dialog's fds 0 and 1 on/dev/lxc/tty1. The gap is time in which nothing draws:systemctl is-system-runningeach, up to 10 s of sleep each while the system is stillstarting)keel inspectto find a database engine the Web image does not haveOn a host where the system is still
startingwhen the wizard runs (slow units, DHCP), the boot wait adds 10 s before every hook from 30 on, 30 s before the Keel Cloud screen.Changes
run: waits for a starting system once per run and stops as soon as it is up. Each first boot hook is named on the terminal while it runs, in an infobox with the first boot backtitle ("Configuring keel-role... please wait"), and so is the wait. Nothing is drawn off a terminal or withREDIRECT_OUTPUT; a notice that cannot be drawn is not an error.setpass.py/Dialog.get_password(keep=...): when root can already log in with a password at first boot (passwd -SsaysP), the menu offers Keep first, as the default and recommendation ("Password set when the container was created (recommended)"), with Generate and Manual below. Keep is offered only for a password the image did not ship (review finding):passwd -SsaysP, the image carries/etc/keel/build-date(fix: images ship root locked, or the build fails; stamp the build date common#31, whose seal-root fails any build that does not ship root locked) and the shadow last-change day is on or after it, and the shadow field is neither empty norU6aMy0wojraho. The field is compared, never printed or logged (asserted in every setpass test); an image without the date, such as every image built before common#31, gets no Keep. The same day counts because shadow keeps whole days and a container is often created on its image's build day. No prior password, preseededROOT_PASS,secrets.root_passwordand keel-init are unchanged. The image already ships root as*(checked in the step8 Web tar.zst).30rootpassreadsINITHOOKS_DEFAULTlike the other hooks.With the fix and confconsole's companion PR, at 0.25 CPU the gap from to Keel Cloud is 7.7 s (was 15 s), and the screen reads "Configuring ... please wait" throughout.
Tests (written first, RED on master)
tests/test-firstboot-pty.bats(new):run, the real30rootpass,setpass.pyanddialogon a pty underscript; keys are typed when their screen reaches the pty, with a timeout on the whole run. Generate then Saved, New, Manual, Keep, Generate below Keep and a preseeded password each reach the next hook's screen. It fails on a hang and on a screen drawn into a pipe (both guards have their own test). On master, the Keep test and the notice check fail. CI installsdialog python3-dialogfor it.tests/test-run.bats: the boot wait happens once and ends when the system is up; notices on a terminal only, not for everyboot hooks, not withREDIRECT_OUTPUT, and a failing notice does not stop the run.tests/test_setpass.py,tests/test_dialog_wrapper.py: Keep offered only for statusP, first and the only recommendation, None returned, chpasswd not run, passwd failures mean no Keep, no file read, keel-init and preseed unchanged, text fits the menu.Run: Python 405 passed locally; bats 260 locally (pty file skipped without dialog) and the pty file 8/8 inside the container.
Test plan
pct create --password: Keep is first, Enter goes to Keel Cloud with "please wait" in between