Repository navigation
reboot: Propagate a refused reboot as an error - #13
Draft
cgwalters-bot wants to merge 1 commit into
Draft
cgwalters-bot wants to merge 1 commit into
cgwalters-bot wants to merge 1 commit into
Conversation
cgwalters-bot
force-pushed
the
bot/reboot-propagate-error
branch
2 times, most recently
from
September 24, 2026 09:16
3b747f2 to
2dde362
Compare
We run `systemctl reboot` via `systemd-run` so it's outside our mount namespace, but without --wait we only learn whether the transient unit was started, not whether the reboot was accepted. If logind refuses it, bootc then parks forever waiting for a SIGTERM that never comes, and e.g. `bootc upgrade --apply` from bootc-fetch-apply-updates.service would just hang instead of failing. One way to get there is a block mode shutdown inhibitor: since systemd 257, logind rejects reboot requests from root too while one is held, unless the caller explicitly asks to skip inhibitors. On CentOS Stream 10 with such a lock held, `systemd-run -- systemctl reboot` exits 0 while the system stays up, so bootc would wait forever. With --wait and --pipe, the exit status and systemctl's error message come back to us. --collect avoids leaving a failed transient unit behind in that case. There is a small race with --wait: once the reboot is accepted, shutdown can stop the transient unit or kill systemd-run before it reports success, and bootc would then print an error and exit while the system goes down instead of parking until SIGTERM. The window is short since `systemctl reboot` returns as soon as the job is queued, and the reboot happens either way; only the exit status of the bootc process being shut down is affected. Generated-by: AI
cgwalters-bot
force-pushed
the
bot/reboot-propagate-error
branch
from
September 29, 2026 19:58
2dde362 to
b994ba3
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
bootc reboots by running
systemctl rebootthroughsystemd-run, so that it runs outside bootc's mount namespace. Without--wait, bootc only learns that the transient unit started, not whether the reboot was accepted. It then parks and waits for the SIGTERM from shutdown. If logind refuses the reboot, that SIGTERM never comes, andbootc upgrade --apply(and so bootc-fetch-apply-updates.service) hangs instead of failing.systemd 257 and later refuse reboots from root while a
blockmode shutdown inhibitor is held, so this can happen today. This PR adds--wait --pipe --collect, which brings the exit status and systemctl's error message back to bootc.There is a small race. Once the reboot has been accepted, shutdown can stop the transient unit or kill systemd-run before it reports success. bootc would then print an error and exit while the system goes down, instead of being terminated by SIGTERM. The window is short, because
systemctl rebootreturns as soon as the job is queued, and the reboot happens either way.--waitand--pipealso talk to systemd over the D-Bus system bus rather than /run/systemd/private. Where dbus isn't running (e.g. rescue.target),--applynow fails loudly and keeps the staged changes. A code comment notes this.This is split out of the reboot inhibitor PR (bootc#1047), which builds on it.
Testing
systemd-inhibit --what=shutdown --mode=blockheld:systemd-run --quiet -- systemctl reboot, which is bootc's current invocation, exited 0 and the VM stayed up. That's the case where bootc waits forever.systemd-run --quiet --wait --pipe --collect -- systemctl rebootexited 1 and printedOperation inhibited by "probe" ... reason is "testing".just validateandjust unit-tests(443 tests) passed on a 16-core RHEL 10 devspace, rebased on current main (41049cc). The branch was built in its own checkout, with its own cargo target and buildah cache directories, and the built image reportsg2dde3623.Generated-by: https://github.com/cgwalters/#llms
Review draft in cgwalters-forge, not upstream yet. This section is removed when the PR is opened upstream.
bootc-dev/bootc, basemainPVTI_lADOE9oHIs4BlJLczg9kEQcTo review:
/promoteon a line of its own, to open it upstream, ready for review. Either covers only the commits pushed so far.Signed-off-by: Colin Walters <walters@verbum.org>to the commits lacking it (the bot's and yours; anyone else's only if you ask), with you as committer./draftline (in the same comment or before) to open it upstream as a draft (/readyundoes that).