Skip to content

A channel stage stays until its trial is judged, so the --retry a failed trial's refusal prints names a stage that is there - #319

Merged
DevomB merged 2 commits into
mainfrom
stage-kept-for-retry
Oct 9, 2026
Merged

DevomB merged 2 commits into
mainfrom
stage-kept-for-retry

Conversation

@DevomB

@DevomB DevomB commented Oct 9, 2026 •

Copy link
Copy Markdown
Owner

What was wrong (3a's whole-picture read, LOW 3)

After a failed trial, kryptik-update refuses to arm the slot again and prints the way on: kryptik-update apply DIR --retry (tools/update/kryptik-update:352-353). For a release fetched from the channel, DIR is the stage. But the trial's own net zone polls: update-poll runs forget_if_installed (broker.rs:249, update.rs:746-752). The trial runs the wanted version, so the poll cleared wanted, files and incoming/ before boot-success had judged it.

The case that loses it: a trial that comes up healthy but whose commit fails (boot-success.sh:148-151). The trial record stays for the next boot, and the machine keeps running well past the first poll, about a minute after the zone's loop starts. The next boot finds the trial not committed and records trial.failed. With automatic fetching off, kryptik update apply then says "no release has been asked for", and the printed --retry names a directory that no longer exists. With it on, the whole release is fetched again first.

What changed

  • update.rs: forget_if_installed keeps the stage while the trial record /var/lib/kryptik/boot/trial exists, or trial.failed beside it, through forget_unless_trial(dir, running, trial). boot-success renames the record to trial.failed before its 5 s pause and reboot (boot-success.sh:158, :166-169), and leaves it so for good on the branches that do not reboot (:160-165); the failed version still runs in both, so the record alone left a window (3a's read of the first head). arm_trial removes trial.failed (kryptik-update:411) when a trial is armed again, and want() replaces the stage when a newer release is asked for, so nothing lingers.
    • Once boot-success commits, it removes the record, and the next poll clears the stage as before.
    • A failed trial moves the record to trial.failed and boots the older release. That is below wanted, so the stage stays for --retry.
    • The broker's call is unchanged.
  • update-channel.md says when the stage goes.

How the run proves it

stage_kept_through_trial (update/tests.rs) stages 1.0.3 and arms a trial record, then has a machine running 1.0.3 forget. The stage and wanted must survive, and again once the record is renamed trial.failed. The old forget_if_installed removes both in the first call. With the record removed, as boot-success removes it on commit, the same call must clear all three. The existing forget tests run unchanged (forget_if_installed, with no trial record on the test host). CI's compartment job runs them, and a Distro run follows on this head.

DevomB added 2 commits October 9, 2026 10:13
…led trial's refusal prints names a stage that is there
…l before the fallback's reboot, or without one, keeps it
@DevomB
DevomB marked this pull request as ready for review October 9, 2026 19:56
@DevomB
DevomB merged commit c2d7e74 into main Oct 9, 2026
21 checks passed
@DevomB
DevomB deleted the stage-kept-for-retry branch October 9, 2026 20:01
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant