Skip to content

overlord/fdestate: run post install checks during auto repair - #16627

Merged
valentindavid merged 1 commit into
canonical:masterfrom
valentindavid:valentindavid/post-install-check
Jun 3, 2026
Merged

overlord/fdestate: run post install checks during auto repair#16627
valentindavid merged 1 commit into
canonical:masterfrom
valentindavid:valentindavid/post-install-check

Conversation

@valentindavid

@valentindavid valentindavid commented Feb 18, 2026

Copy link
Copy Markdown
Member

SNAPDENG-36452

@valentindavid valentindavid added the Run nested The PR also runs tests inluded in nested suite label Feb 18, 2026
@github-actions github-actions Bot added the Run only one system Only runs spread tests on one system label Feb 18, 2026
@github-actions

github-actions Bot commented Feb 18, 2026

Copy link
Copy Markdown

Wed Jun 3 09:21:45 UTC 2026
The following results are from: https://github.com/canonical/snapd/actions/runs/26635929802

Failures:

Executing:

  • openstack:opensuse-tumbleweed-64:tests/main/security-logging
  • openstack:opensuse-16.0-64:tests/main/security-logging
  • openstack:opensuse-tumbleweed-selinux-64:tests/main/security-logging
  • garden:ubuntu-core-18-64:tests/core/auto-refresh-backoff-after-reboot:kernel

Skipped tests from snapd-testing-skip

If you wish to have any of the below tests run in your PR, in your PR description, add 'unskip:' followed by a copy-and-pasted list (without variants) of the below tests you wish to run (unskip plus test list must be valid yaml)

  • openstack-arm:ubuntu-24.04-arm-64:tests/main/i18n
  • openstack-arm:ubuntu-24.04-arm-64:tests/main/snapctl-is-ready
  • openstack-arm:ubuntu-24.04-arm-64:tests/main/snapctl-no-wait
  • openstack-arm:ubuntu-core-24-arm-64:tests/main/i18n
  • openstack-arm:ubuntu-core-24-arm-64:tests/main/snapctl-is-ready
  • openstack-arm:ubuntu-core-24-arm-64:tests/main/snapctl-no-wait
  • openstack:amazon-linux-2-64:tests/main/snapctl-no-wait
  • openstack:amazon-linux-2023-64:tests/main/snapctl-no-wait
  • openstack:arch-linux-64:tests/main/snapctl-no-wait
  • openstack:centos-9-64:tests/main/snapctl-no-wait
  • openstack:debian-12-64:tests/main/snapctl-no-wait
  • openstack:debian-sid-64:tests/main/interfaces-network-status-classic
  • openstack:debian-sid-64:tests/main/snapctl-no-wait
  • openstack:fedora-44-64:tests/main/snapctl-is-ready
  • openstack:fedora-44-64:tests/main/snapctl-no-wait
  • openstack:opensuse-16.0-64:tests/main/snapctl-no-wait
  • openstack:opensuse-tumbleweed-64:tests/main/snapctl-no-wait
  • openstack:opensuse-tumbleweed-selinux-64:tests/main/snapctl-no-wait
  • openstack:ubuntu-16.04-64:tests/main/snapctl-is-ready
  • openstack:ubuntu-16.04-64:tests/main/snapctl-no-wait
  • openstack:ubuntu-18.04-64:tests/main/snapctl-is-ready
  • openstack:ubuntu-18.04-64:tests/main/snapctl-no-wait
  • openstack:ubuntu-20.04-64:tests/main/snapctl-is-ready
  • openstack:ubuntu-20.04-64:tests/main/snapctl-no-wait
  • openstack:ubuntu-22.04-64:tests/main/snapctl-is-ready
  • openstack:ubuntu-22.04-64:tests/main/snapctl-no-wait
  • openstack:ubuntu-24.04-64:tests/main/i18n
  • openstack:ubuntu-24.04-64:tests/main/snapctl-is-ready
  • openstack:ubuntu-24.04-64:tests/main/snapctl-no-wait
  • openstack:ubuntu-25.10-64:tests/main/apparmor-prompting-flag-restart
  • openstack:ubuntu-25.10-64:tests/main/apparmor-prompting-prompt-restoration
  • openstack:ubuntu-25.10-64:tests/main/apparmor-prompting-snapd-startup
  • openstack:ubuntu-25.10-64:tests/main/snapctl-is-ready
  • openstack:ubuntu-25.10-64:tests/main/snapctl-no-wait
  • openstack:ubuntu-26.04-64:tests/main/apparmor-prompting-flag-restart
  • openstack:ubuntu-26.04-64:tests/main/apparmor-prompting-integration-tests:audio_record_single
  • openstack:ubuntu-26.04-64:tests/main/apparmor-prompting-integration-tests:audio_record_timespan_allow
  • openstack:ubuntu-26.04-64:tests/main/apparmor-prompting-integration-tests:audio_record_timespan_deny
  • openstack:ubuntu-26.04-64:tests/main/apparmor-prompting-integration-tests:create_multiple_actioned_by_other_pid_always_allow
  • openstack:ubuntu-26.04-64:tests/main/apparmor-prompting-integration-tests:create_multiple_actioned_by_other_pid_always_deny
  • openstack:ubuntu-26.04-64:tests/main/apparmor-prompting-integration-tests:create_multiple_allow
  • openstack:ubuntu-26.04-64:tests/main/apparmor-prompting-integration-tests:create_multiple_deny
  • openstack:ubuntu-26.04-64:tests/main/apparmor-prompting-integration-tests:create_multiple_not_actioned_by_other_pid_single_allow
  • openstack:ubuntu-26.04-64:tests/main/apparmor-prompting-integration-tests:create_multiple_not_actioned_by_other_pid_single_deny
  • openstack:ubuntu-26.04-64:tests/main/apparmor-prompting-integration-tests:create_write_chmod_same_fd_single_allow
  • openstack:ubuntu-26.04-64:tests/main/apparmor-prompting-integration-tests:create_write_chmod_same_path_single_allow
  • openstack:ubuntu-26.04-64:tests/main/apparmor-prompting-integration-tests:create_write_write_same_path_single_deny
  • openstack:ubuntu-26.04-64:tests/main/apparmor-prompting-integration-tests:download_file_conflict
  • openstack:ubuntu-26.04-64:tests/main/apparmor-prompting-integration-tests:download_file_defaults
  • openstack:ubuntu-26.04-64:tests/main/apparmor-prompting-integration-tests:download_file_safer
  • openstack:ubuntu-26.04-64:tests/main/apparmor-prompting-integration-tests:read_single_allow
  • openstack:ubuntu-26.04-64:tests/main/apparmor-prompting-integration-tests:read_single_deny
  • openstack:ubuntu-26.04-64:tests/main/apparmor-prompting-integration-tests:special_characters
  • openstack:ubuntu-26.04-64:tests/main/apparmor-prompting-integration-tests:timespan_allow
  • openstack:ubuntu-26.04-64:tests/main/apparmor-prompting-integration-tests:timespan_deny
  • openstack:ubuntu-26.04-64:tests/main/apparmor-prompting-integration-tests:write_read_multiple_actioned_by_other_pid_allow_deny
  • openstack:ubuntu-26.04-64:tests/main/apparmor-prompting-integration-tests:write_read_multiple_actioned_by_other_pid_deny_allow
  • openstack:ubuntu-26.04-64:tests/main/apparmor-prompting-integration-tests:write_single_allow
  • openstack:ubuntu-26.04-64:tests/main/apparmor-prompting-integration-tests:write_single_deny
  • openstack:ubuntu-26.04-64:tests/main/apparmor-prompting-prompt-restoration
  • openstack:ubuntu-26.04-64:tests/main/apparmor-prompting-smoke:audiorecord_allow_forever
  • openstack:ubuntu-26.04-64:tests/main/apparmor-prompting-smoke:audiorecord_allow_session
  • openstack:ubuntu-26.04-64:tests/main/apparmor-prompting-smoke:audiorecord_allow_single
  • openstack:ubuntu-26.04-64:tests/main/apparmor-prompting-smoke:audiorecord_allow_timespan
  • openstack:ubuntu-26.04-64:tests/main/apparmor-prompting-smoke:audiorecord_deny_forever
  • openstack:ubuntu-26.04-64:tests/main/apparmor-prompting-smoke:audiorecord_deny_session
  • openstack:ubuntu-26.04-64:tests/main/apparmor-prompting-smoke:audiorecord_deny_single
  • openstack:ubuntu-26.04-64:tests/main/apparmor-prompting-smoke:audiorecord_deny_timespan
  • openstack:ubuntu-26.04-64:tests/main/apparmor-prompting-smoke:camera_allow_forever
  • openstack:ubuntu-26.04-64:tests/main/apparmor-prompting-smoke:camera_allow_session
  • openstack:ubuntu-26.04-64:tests/main/apparmor-prompting-smoke:camera_allow_single
  • openstack:ubuntu-26.04-64:tests/main/apparmor-prompting-smoke:camera_allow_timespan
  • openstack:ubuntu-26.04-64:tests/main/apparmor-prompting-smoke:camera_deny_forever
  • openstack:ubuntu-26.04-64:tests/main/apparmor-prompting-smoke:camera_deny_session
  • openstack:ubuntu-26.04-64:tests/main/apparmor-prompting-smoke:camera_deny_single
  • openstack:ubuntu-26.04-64:tests/main/apparmor-prompting-smoke:camera_deny_timespan
  • openstack:ubuntu-26.04-64:tests/main/apparmor-prompting-smoke:home_allow_forever
  • openstack:ubuntu-26.04-64:tests/main/apparmor-prompting-smoke:home_allow_session
  • openstack:ubuntu-26.04-64:tests/main/apparmor-prompting-smoke:home_allow_single
  • openstack:ubuntu-26.04-64:tests/main/apparmor-prompting-smoke:home_allow_timespan
  • openstack:ubuntu-26.04-64:tests/main/apparmor-prompting-smoke:home_deny_forever
  • openstack:ubuntu-26.04-64:tests/main/apparmor-prompting-smoke:home_deny_session
  • openstack:ubuntu-26.04-64:tests/main/apparmor-prompting-smoke:home_deny_single
  • openstack:ubuntu-26.04-64:tests/main/apparmor-prompting-smoke:home_deny_timespan
  • openstack:ubuntu-26.04-64:tests/main/apparmor-prompting-snapd-startup
  • openstack:ubuntu-26.04-64:tests/main/apparmor-prompting-support
  • openstack:ubuntu-26.04-64:tests/main/i18n
  • openstack:ubuntu-26.04-64:tests/main/interfaces-requests-activates-handlers
  • openstack:ubuntu-26.04-64:tests/main/snapctl-is-ready
  • openstack:ubuntu-26.04-64:tests/main/snapctl-no-wait
  • openstack:ubuntu-core-18-64:tests/main/snapctl-is-ready
  • openstack:ubuntu-core-18-64:tests/main/snapctl-no-wait
  • openstack:ubuntu-core-20-64:tests/main/snapctl-is-ready
  • openstack:ubuntu-core-20-64:tests/main/snapctl-no-wait
  • openstack:ubuntu-core-22-64:tests/main/snapctl-is-ready
  • openstack:ubuntu-core-22-64:tests/main/snapctl-no-wait
  • openstack:ubuntu-core-24-64:tests/main/snapctl-is-ready
  • openstack:ubuntu-core-24-64:tests/main/snapctl-no-wait
  • openstack:ubuntu-core-26-64:tests/main/snapctl-is-ready
  • openstack:ubuntu-core-26-64:tests/main/snapctl-no-wait

@valentindavid
valentindavid force-pushed the valentindavid/post-install-check branch 3 times, most recently from e7fa4b5 to 01afcdd Compare February 20, 2026 10:08
@github-actions github-actions Bot added the Needs Documentation -auto- Label automatically added which indicates the change needs documentation label Feb 20, 2026
@valentindavid
valentindavid force-pushed the valentindavid/post-install-check branch from 01afcdd to 70051ef Compare April 10, 2026 07:23
@github-actions github-actions Bot removed the Needs Documentation -auto- Label automatically added which indicates the change needs documentation label Apr 10, 2026
@valentindavid
valentindavid marked this pull request as ready for review April 10, 2026 08:58
@valentindavid valentindavid removed the Run only one system Only runs spread tests on one system label Apr 10, 2026
@valentindavid
valentindavid force-pushed the valentindavid/post-install-check branch 2 times, most recently from c01e2a5 to 4975a6c Compare April 10, 2026 09:36
@valentindavid

Copy link
Copy Markdown
Member Author

This will need a spread test.

@codecov

codecov Bot commented Apr 10, 2026

Copy link
Copy Markdown

Codecov Report

❌ Patch coverage is 58.51852% with 56 lines in your changes missing coverage. Please review.
✅ Project coverage is 79.03%. Comparing base (74eac1a) to head (944d18b).
⚠️ Report is 25 commits behind head on master.

Files with missing lines Patch % Lines
overlord/fdestate/autorepair.go 57.57% 29 Missing and 13 partials ⚠️
secboot/preinstall_sb.go 50.00% 7 Missing and 2 partials ⚠️
overlord/devicestate/devicemgr.go 58.33% 3 Missing and 2 partials ⚠️
Additional details and impacted files
@@            Coverage Diff             @@
##           master   #16627      +/-   ##
==========================================
+ Coverage   79.00%   79.03%   +0.03%     
==========================================
  Files        1376     1367       -9     
  Lines      192016   192041      +25     
  Branches     2464     2464              
==========================================
+ Hits       151693   151786      +93     
+ Misses      31180    31089      -91     
- Partials     9143     9166      +23     
Flag Coverage Δ
unittests 79.03% <58.51%> (+0.03%) ⬆️

Flags with carried forward coverage won't be shown. Click here to find out more.

☔ View full report in Codecov by Sentry.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

@valentindavid
valentindavid force-pushed the valentindavid/post-install-check branch from 4975a6c to ff7d44d Compare April 14, 2026 09:31
@valentindavid

Copy link
Copy Markdown
Member Author

This will need a spread test.

I could not add a spread test. While the spread test do exercise it, they do not do the case where post install check would fail. Unfortunately, most check fails are either disabled on VMs or require interaction with OVMF menu.

Instead I manually tested it by disabling secure boot and making sure the state had the right value.

@valentindavid
valentindavid force-pushed the valentindavid/post-install-check branch from ff7d44d to 70568ab Compare April 14, 2026 09:37
@valentindavid
valentindavid requested a review from ernestl April 14, 2026 09:37

@Meulengracht Meulengracht left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

quick pass

Comment thread overlord/fdestate/autorepair.go Outdated
}

const postInstall = true
if _, details, err := secbootPreinstallCheck(context.Background(), postInstall, images); len(details) > 0 || err != nil {

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Is there a reason we are not logging the error details here?

return nil, err
}

for _, runModeBootChain := range runModeBootChains {

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This loop warrants some comments

@valentindavid

Copy link
Copy Markdown
Member Author

I have to rebase...

@valentindavid
valentindavid force-pushed the valentindavid/post-install-check branch from fcf7faa to db1e994 Compare April 28, 2026 11:24
Comment thread secboot/preinstall_sb.go Outdated
// To support testing, when the system is running in a Virtual Machine, the check
// configuration is modified to permit this to avoid an error.
func PreinstallCheck(ctx context.Context, bootImagePaths []string) (*PreinstallCheckContext, []PreinstallErrorDetails, error) {
func PreinstallCheck(ctx context.Context, postInstall bool, bootImagePaths []bootloader.BootFile) (*PreinstallCheckContext, []PreinstallErrorDetails, error) {

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Might be worth having a separate PostinstallCheck helper, passing a post-install flag to PreinstallCheck is a little confusing even if the underlying secboot calls are like this

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I wonder about the returned "PreinstallCheckContext" "PreinstallErrorDetails". What should they be renamed to?

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

something like "RunChecksContext" "RunChecksErrorDetails"? but I agree that might be a lot to refactor in this PR so maybe a follow up.

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

SNAPDENG-36867

@ZeyadYasser ZeyadYasser left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM, Thank you! small nitpick comments

Comment thread overlord/fdestate/autorepair.go Outdated
return rs.State, nil
}

func getBootChain() ([]bootloader.BootFile, error) {

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

does it make sense to move this under boot/seal.go?

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I think it would be nice to factorize with runModeBootChainsWithTrustedAssets. But it is not that easy. I will open a ticket to remember to do that.

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

SNAPDENG-36866

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

this is the run boot chain? maybe the function name should reflect that?

Comment thread overlord/fdestate/autorepair.go
@valentindavid

Copy link
Copy Markdown
Member Author

I have to rebase again...

@valentindavid
valentindavid force-pushed the valentindavid/post-install-check branch from 95f15bd to c7b0f00 Compare May 5, 2026 12:15
@valentindavid
valentindavid force-pushed the valentindavid/post-install-check branch 2 times, most recently from 89ed402 to 179d439 Compare May 7, 2026 12:21

@ernestl ernestl left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Looks good, few comments

Comment thread overlord/fdestate/autorepair.go Outdated
return AutoRepairNotAttempted, err
}

if _, details, err := secbootPostinstallCheck(context.Background(), images); len(details) > 0 || err != nil {

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

secbootPreinstallCheck where used in install.go uses context timeout. Considering adding.

Comment thread overlord/fdestate/autorepair.go Outdated
return AutoRepairNotAttempted, err
}

if _, details, err := secbootPostinstallCheck(context.Background(), images); len(details) > 0 || err != nil {

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Should the use if secbootPostinstallCheck be limited to classic hybrid systems >= 25.10? (same as secbootPreinstallCheck)

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

That is a very good point.

break
}

// In theory we should only have one hash here. Multiple would be when we are trying

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Perhaps test and warn if somehow this is not the case?

@valentindavid
valentindavid requested a review from ernestl May 20, 2026 10:25
@ndyer ndyer added this to the 2.77 milestone May 21, 2026
@pedronis
pedronis self-requested a review May 21, 2026 11:43

@pedronis pedronis left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

couple small comments

Comment thread secboot/preinstall_sb.go Outdated
// To support testing, when the system is running in a Virtual Machine, the check
// configuration is modified to permit this to avoid an error.
func PreinstallCheck(ctx context.Context, bootImagePaths []string) (*PreinstallCheckContext, []PreinstallErrorDetails, error) {
func preinstallCheck(ctx context.Context, postInstall bool, bootImagePaths []bootloader.BootFile) (*PreinstallCheckContext, []PreinstallErrorDetails, error) {

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

maybe Paths should become Files ? here and in the callers

Comment thread overlord/fdestate/autorepair.go Outdated
return rs.State, nil
}

func getBootChain() ([]bootloader.BootFile, error) {

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

this is the run boot chain? maybe the function name should reflect that?

@valentindavid
valentindavid requested a review from pedronis May 27, 2026 11:38
@valentindavid

Copy link
Copy Markdown
Member Author

I pushed something, but it is not showing up yet...

@pedronis pedronis left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

thank you

@valentindavid
valentindavid force-pushed the valentindavid/post-install-check branch from 4dffada to 944d18b Compare May 29, 2026 11:57
@github-actions github-actions Bot added the Auto rerun spread Auto reruns spread up to 4 times in non-draft PRs w/ >=1 approval and <20 fails in any fund. system label Jun 2, 2026
@valentindavid
valentindavid merged commit 9fd6e10 into canonical:master Jun 3, 2026
478 of 501 checks passed
@valentindavid
valentindavid deleted the valentindavid/post-install-check branch June 3, 2026 11:39
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Auto rerun spread Auto reruns spread up to 4 times in non-draft PRs w/ >=1 approval and <20 fails in any fund. system Run nested The PR also runs tests inluded in nested suite

Projects

None yet

Development

Successfully merging this pull request may close these issues.

6 participants