Skip to content

Flip defaults of unattendended software updates feature - #1675

Merged
troglobit merged 13 commits into
mainfrom
unattended-default
Oct 1, 2026
Merged

troglobit merged 13 commits into
mainfrom
unattended-default

Conversation

@troglobit

@troglobit troglobit commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

Description

  • Flip default of enabled nodes to true
  • Add operational support for check and upgrade
  • Revise schedule + upgrade docs
  • Add CLI status of unattended updates in 'show software'
  • Add web status card for unattended updates
  • Fix slot-check race condition causing rauc service to crash
  • Fix hostapd crash on older WiFi boards without 802.11ax support

Checklist

Tick relevant boxes, this PR is-a or has-a:

  • Bugfix
    • Regression tests
    • ChangeLog updates (for next release)
  • Feature
    • YANG model change => revision updated?
    • Regression tests added?
    • ChangeLog updates (for next release)
    • Documentation added?
  • Test changes
    • Checked in changed Readme.adoc (make test-spec)
    • Added new test to group Readme.adoc and yaml file
  • Code style update (formatting, renaming)
  • Refactoring (please detail in commit messages)
  • Build related changes
  • Documentation content changes
    • ChangeLog updated (for major changes)
  • Other (please describe):

The rauc service crashed in a loop at boot on some units, with
"Failed to obtain name de.pengutronix.rauc on system bus".

Finit raises service/rauc/running when it forks the service, before
RAUC has asked for its bus name.  The slot-check task fires on that
condition and runs 'rauc status', dbus-daemon finds no owner and starts
a second instance through the activation helper, and whichever instance
asks last loses the name.  When that is the supervised one, every
restart meets the same stray and finit gives up.

Patch RAUC to send READY=1 on NOTIFY_SOCKET once the name is acquired,
declare the service notify:systemd, and let slot-check wait for
service/rauc/ready.  Drop the D-Bus activation file and its helper from
the image as well: a client calling while the supervised service is
restarting must get "no owner", not a stray instance.

The RAUC patches are regenerated from the kkit-1.13 branch.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
The docs and ChangeLog mixed "upgrades" and "updates" for the same
feature.  The CLI keeps its legacy 'upgrade' command, everything else
is software updates, matching the update-url and check-update settings.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
The note from issue #1637 ran to a long single line in the login banner,
'show software' and the WebUI, and the banner had no blank line after it
so the login prompt sat right below the text.

Say "the primary partition is out of date (v26.08.0)" and put the
'upgrade' hint on its own line, with a blank line after the banner.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
hostapd refused to start on a BPi-R64, whose MT7622 radio is 802.11n
only, because the generated config set ieee80211ax=1 for every band,
and ieee80211ac=1 on 5 GHz, without asking the hardware.

The PHY probe already reads the HT and VHT bitmasks, extend it to say
whether the radio supports HE, and write the 802.11ac and 802.11ax
lines, and the vht_* and he_* settings that go with them, only when it
does.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Enabling unattended updates took two steps: set enabled, then reference
a schedule.  The enabled leaf on check-update and unattended-update
defaulted to false, while scheduled-reboot had no such leaf, so the
three features that run on a schedule had two different shapes.

Move the enabled and schedule leaves into a scheduled-feature grouping
in infix-schedule, with enabled defaulting to true like every other
enabled leaf in our models.  A feature is now active as soon as it
references a schedule, and enabled only pauses it, keeping the reference
and the feature's other settings.  The scheduler's consumer table no
longer needs per-row leaf names.

A check-update that referenced a schedule but never set enabled starts
checking after this upgrade.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Neither check-update nor unattended-update left any trace beyond the
log and a login notice, so after enabling them the only way to see
that they took effect was crontab -l from the shell.

The update scripts now record the outcome of each run in a state file
that yanger folds into /system-state/software/update: when the feed
was last queried, the newest release it offered and whether that is
newer than what boots next, and the time and version of the last
unattended install.  Whether an installed image awaits a reboot is
derived from the RAUC slot data, so it also covers manual upgrades.

'show software' prints the configured triggers next to this outcome,
and the WebUI software page gets a Software Updates card.  The slot
table on that page now uses the same date format as the card.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Enabling a scheduled feature meant first creating a schedule, so the
"connect it to a schedule" step the model promises was really three or
four commands of recurrence setup.

Ship two schedules with the factory config, nightly at 03:00 and weekly
on Sunday nights at 03:00.  An unreferenced schedule generates nothing,
so they are inert until a feature points at one.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
'show software' described the factory weekly schedule as "weekly on sun
at 03:00", repeating the frequency.  When a schedule pins weekdays and
has no interval, the days alone say it: "sunday at 03:00".

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
A development version like v26.09.0-rc1-7-g444b9c575 is longer than the
fixed column width, so the date ran straight into it.

Widen the column to the longest version shown, keeping the old width as
the minimum.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
An unbalanced action in a page template only showed up when the daemon
started, as a "server setup" error in the log, since the handler tests
render minimal stand-in templates.

Parse every page with the layouts and fragments the way server.New does,
so the build catches it.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
The YANG tree editor showed the description text of a module from the
previous image after an upgrade.  The cache under /var/cache/webui/yang
only checks that name@revision.yang exists, /var persists across
upgrades, and a module's revision does not change every time its text
does, least of all between release candidates.

Stamp the cache with VERSION_ID from /etc/os-release and empty it when
the running image is another one.  The YANG files ship with the image,
so that is the key that tracks them.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Following a "Configure" link from a status page into the tree editor
left the sidebar with every section collapsed.  The URL sync after an
htmx navigation closes the other sections but refused to open Configure,
to keep its enter request off the URL sync path.

That request is guarded to fire once per page lifecycle, and a page in
the Configure section needs the candidate it initialises, so open the
section like any other.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
A user setting this up had to read about the update source and how to
host a feed before reaching the example that enables the feature, and
that example first created a schedule by hand.

Lead with enabling, using the factory schedules and the 'configure
system' context, then status, then the update source, and keep the
feed hosting howto last.  The scheduling page uses the factory nightly
schedule in its example and creates a schedule under another name.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
@troglobit
troglobit merged commit c13d184 into main Oct 1, 2026
11 checks passed
@troglobit
troglobit deleted the unattended-default branch October 1, 2026 11:59
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants