mirror of
https://github.com/jmcorgan/fips.git
synced 2026-10-05 19:18:25 +00:00
On upgrade, postinst started fips.service and then fips-dns.service with blocking systemctl calls. fips-dns.service requires fips.service, so when the new daemon fails on every start its start job is never dispatched and the blocking call never returns. apt, and everything queued behind it, then waited for ever with no message. postinst now queues each start with --no-block and waits for the unit to be active with no job pending, for at most 60 seconds per unit. Active must hold on two consecutive polls, because the daemon is Type=simple and reads active for an instant before a failed exec; a unit that reaches failed stops the wait early. A unit that is masked, or skipped because its condition is not met, is reported and skipped rather than failed, and the units that require a daemon that did not start are not started. A unit that does not come up has its status printed and fails the configure step at the end of the script, so apt exits non-zero and says which unit. The deb-install suite gains an upgrade scenario on Debian 12, whose systemd shows the hang; on Ubuntu 22.04 the blocked start returns with an error. It makes a newer package from the one under test, upgrades an installed host to it, reinstalls it with the daemon masked, requiring apt to succeed and start nothing, and reinstalls it with a daemon that cannot start, requiring apt to fail within two minutes and name the unit. Its image holds no package: the package this run built is copied into each container and its checksum compared there, so a concurrent run retagging a shared image cannot swap it.