Skip to content

fix: a first boot finishes without a journal and without a watcher - #38

Merged
marcos-mendez merged 1 commit into
masterfrom
fix/first-boot-without-journal-or-console
Oct 3, 2026
Merged

marcos-mendez merged 1 commit into
masterfrom
fix/first-boot-without-journal-or-console

Conversation

@marcos-mendez

Copy link
Copy Markdown
Collaborator

Two stalls of the published core 19.0-6 booted headless (BR2, 2026-10-03), the ones CI's boot-published-layer fails on.

1. Hooks that die when journald is down. 15regen-sslcert runs under bash -e and its log() called logger, which fails with "socket /dev/log: Connection refused" when journald is down (in the CI container it dies with status=243/CREDENTIALS: the host's AppArmor profile denies the ramfs mount systemd 257 makes for credentials; Keel-Linux/handbook PR to follow). The first info killed the hook before it made the certificate. Its logger is now logger ... 2>/dev/null || true, the shape run's log() and keel's 10keel-system use. Audit of every hook and lib for -e + logger: 95secupdates was the other one (nine calls, now through one journal() with the same shape); 30turnkey-init-fence and bin/keel-host-keys call logger without -e; no lib calls it.

2. Notices that wedge an unattended boot. run's notice() drew dialog --infobox on tty1 for every hook (keel17); in LXC tty1 is a pty whose master only pct console/lxc-console reads, so with nobody attached the writes filled the buffer and blocked for good after 30turnkey-init-fence. Now: a console with no size (stty size answers 0 0 on an unattended LXC tty; a VT or an attached console answers rows and columns) gets no notice; a notice the console does not take within NOTICE_TIMEOUT (2 s, timeout --foreground so dialog keeps the terminal's process group) is given up with the ones after it. Each case, and output that is not a terminal, is said once in the inithooks log and the journal ("first boot notices not drawn: ..."), so an operator can tell why the screen stayed still. confconsole --usage at the end of the run is unchanged: it is interactive and the boot is over by then.

Tested. tests/test-regen-sslcert.bats (8, new; the hook is measured for the first time, 27/27) with logger exiting 1; three tests in test-secupdates.bats with logger failing; test-run.bats: the terminal tests now run on a sized pty, an unsized pty gets no notice and the log line, and a sized pty whose master is never read (python pty.openpty, dialog a stub writing more than the pty holds) finishes with all hooks run and the timeout said. 322 bats, shell 99.64 (COVERAGE.md).

Two stalls of the published core 19.0-6 booted headless (BR2,
2026-10-03; CI's boot-published-layer fails on them).

15regen-sslcert exited 1 before doing anything: under bash -e its log()
called logger, which fails with "socket /dev/log: Connection refused"
when journald is down (status=243/CREDENTIALS in the CI container, the
host's AppArmor profile denying the ramfs mount systemd 257 makes for
credentials), and the first info line killed the hook. Its logger may
not fail it now, nor may 95secupdates', the one other hook that logs
under -e; the other hooks and libs do not call logger, and run's own
log() was tolerant already.

The first boot stalled after [30turnkey-init-fence] running when nobody
was attached to the container console: run's notice() drew a dialog
infobox on tty1 for every hook, tty1 in LXC is a pty whose master only an
attached console reads, and after about 30 KB the write blocked in
n_tty_write for good. A console with no size (stty answers 0 0 on an
unattended LXC tty; a VT or an attached console answers its rows and
columns) gets no notice, and a notice the console does not take within
NOTICE_TIMEOUT (2 s, timeout --foreground) is given up with the ones
after it, so no boot can wedge on its console. Each is said once in the
inithooks log and the journal.
@marcos-mendez
marcos-mendez force-pushed the fix/first-boot-without-journal-or-console branch from 2d1bbf3 to ae89636 Compare October 3, 2026 04:05
@marcos-mendez
marcos-mendez merged commit 7aedeb5 into master Oct 3, 2026
3 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant