Skip to content

update: Skip bootloader update when no block devices back the root - #1072

Closed
cgwalters wants to merge 2 commits into
coreos:mainfrom
cgwalters:ephemeral-noupdate
Closed

cgwalters wants to merge 2 commits into
coreos:mainfrom
cgwalters:ephemeral-noupdate

Conversation

@cgwalters

Copy link
Copy Markdown
Member

Fix the problem that bcvk ephemeral run quay.io/fedora/fedora-bootc:43 shows a systemd error by default.

@gemini-code-assist gemini-code-assist Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request effectively addresses the issue of bootupctl update failing in environments without block-backed root filesystems, such as ephemeral VMs using virtiofs. The core change to make get_devices() return an Option is well-implemented and propagated correctly to the callers, allowing them to gracefully skip the update. The addition of ci/ephemeral-test.sh is a great way to ensure this new behavior is tested. I have one main concern about the completeness of the fix regarding other components, which I've detailed in a specific comment.

Comment thread src/efi.rs Outdated
Comment thread .github/workflows/ci.yml Outdated
@nikita-dubrovskii

Copy link
Copy Markdown
Contributor

@nikita-dubrovskii

nikita-dubrovskii commented Apr 24, 2026 •

Copy link
Copy Markdown
Contributor

This won't work on Live systems. Here is my branch with fix, mind checking it?

Logs from live-iso:

$ cosa kola qemuexec --workdir none --qemu-iso builds/latest/x86_64/*.iso

core@localhost:~$ journalctl -u bootloader-update.service 
Apr 24 08:44:56 localhost systemd[1]: Starting bootloader-update.service - Update bootloader on boot...
Apr 24 08:44:57 localhost bootupctl[1090]: Detected live filesystem: erofs, skipping bootloader update.
Apr 24 08:44:57 localhost systemd[1]: Finished bootloader-update.service - Update bootloader on boot.

Logs from qemu:

$  cosa kola qemuexec --devshell-console

core@cosa-devsh:~$ journalctl -u bootloader-update.service 
Apr 24 08:46:34 localhost systemd[1]: Starting bootloader-update.service - Update bootloader on boot...
Apr 24 08:46:34 localhost bootupctl[1456]: No update available for any component.
Apr 24 08:46:34 localhost systemd[1]: Finished bootloader-update.service - Update bootloader on boot.

In environments without block-backed boot filesystems (virtiofs in bcvk
ephemeral, NFS root, ISO boot, etc.) there is no on-disk bootloader to
manage. Previously the update path would fail because
list_dev_current_root() bailed when it could not find a block device
from /boot or /sysroot.

Assisted-by: OpenCode (Claude Opus 4)
Signed-off-by: Colin Walters <walters@verbum.org>
On Fedora 43 dnf is dnf5, and the copr subcommand is provided by the
dnf5-plugins package rather than dnf-plugins-core. Without it the
ephemeral CI job fails with:

  Unknown argument "copr" for command "dnf5".

Install dnf5-plugins with a fallback (|| true) so it's a no-op on
CentOS Stream 9 where that package doesn't exist.

Assisted-by: OpenCode (Claude Sonnet 4.5)
Signed-off-by: Colin Walters <walters@verbum.org>
@openshift-ci

openshift-ci Bot commented Sep 8, 2026

Copy link
Copy Markdown

PR needs rebase.

Details

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository.

@cgwalters-bot cgwalters-bot moved this to Todo in Workstream Sep 23, 2026
@cgwalters-bot cgwalters-bot moved this from Todo to In Review in Workstream Sep 23, 2026
cgwalters-bot added a commit to cgwalters-bot/infra that referenced this pull request Sep 23, 2026
The amd64 boot test fails on every run because bootloader-update.service
ends up failed, leaving the system "degraded". Under `bcvk ephemeral`
the root filesystem is virtiofs with no backing block device, so
`bootupctl update` errors out with "Failed to find block device from
/boot or /sysroot". That's an environment artifact of the test, not a
problem with the rechunked image.

With the manifest now gated on every arch building, this failure would
also block publishing the amd64 images entirely, so carry the mask here
rather than depending on a separate fix landing first.

coreos/bootupd#1072 makes bootupd skip the update in this case; until
that ships in all the base images, mask the unit on the kernel command
line, the same way bcvk itself masks systemd-journal-flush.service.
Every other unit is still checked.

Assisted-by: AI
@cgwalters-bot cgwalters-bot moved this from In Review to Needs human in Workstream Sep 23, 2026
cgwalters-bot added a commit to cgwalters-forge/infra that referenced this pull request Sep 24, 2026
The amd64 boot test fails on every run because bootloader-update.service
ends up failed, leaving the system "degraded". Under `bcvk ephemeral`
the root filesystem is virtiofs with no backing block device, so
`bootupctl update` errors out with "Failed to find block device from
/boot or /sysroot". That's an environment artifact of the test, not a
problem with the rechunked image.

So far that only makes the job red, but once the manifest is gated on
every arch building, it would block publishing the amd64 images
entirely. Carry the mask here rather than depending on a separate fix
landing first.

coreos/bootupd#1072 will make bootupd skip the update in this case;
until that ships in all the base images, mask the unit on the kernel
command line, the same way bcvk itself masks
systemd-journal-flush.service. Every other unit is still checked.

Prep for gating the manifest on every arch building.

Generated-by: AI
@cgwalters

Copy link
Copy Markdown
Member Author

@cgwalters-bot take this rebase

@cgwalters-bot

Copy link
Copy Markdown

Rebased onto current main: cgwalters-forge/bootupd:bot/1072-rebase at b017de2.

Conflicts, in .github/workflows/ci.yml and Dockerfile:

  • ci.yml: kept main's new BIOS/UEFI VM boot steps and appended your ephemeral job unchanged. (It still uses bootc-ubuntu-setup@main, while main now pins that action to a SHA.)
  • Dockerfile: I dropped "Dockerfile: install dnf5-plugins for copr support". Main's cdda351 now runs copr enable only on CentOS, so Fedora 43 never reaches the dnf5 copr path and the resolved commit was empty.

Your remaining commit's code is unchanged; only diff context moved.

Tested on a devspace: cargo fmt --check, cargo clippy --all-targets -D warnings and cargo test --all-targets pass. The CI ephemeral job steps also pass: podman build on fedora-bootc:43, then bcvk ephemeral run-ssh ... ephemeral-test.sh, which reports the skip on virtiofs.

To take it:

git fetch https://github.com/cgwalters-forge/bootupd bot/1072-rebase && git push -f <your remote> FETCH_HEAD:ephemeral-noupdate

Generated-by: https://github.com/cgwalters/#llms

@cgwalters

Copy link
Copy Markdown
Member Author

It's fine you can push a new PR closing this one

@cgwalters cgwalters closed this Sep 25, 2026
auto-merge was automatically disabled September 25, 2026 21:33

Pull request was closed

cgwalters-bot added a commit to cgwalters-forge/bcvk that referenced this pull request Sep 25, 2026
bootupd's bootloader-update.service looks for the block device backing
/boot or /sysroot, and in an ephemeral VM the root is virtiofs, so it
fails with "Failed to find block device from /boot or /sysroot". The
system then comes up "degraded", which breaks every test that boots an
image with bcvk and checks systemctl is-system-running, forcing each
consumer (e.g. bootc-dev/infra, bootupd CI) to mask it themselves.

There is never a bootloader to update in an ephemeral VM, so mask it
by default like systemd-journal-flush.service. coreos/bootupd#1072
makes bootupd skip this case itself, but existing images will carry
older bootupd for a long time.

The ephemeral system-command integration test now asserts the VM
reaches "running", so a unit failing in every ephemeral boot is caught
here rather than by bcvk's consumers.

Generated-by: AI
Signed-off-by: Colin Walters <walters@verbum.org>
cgwalters pushed a commit to bootc-dev/bcvk that referenced this pull request Sep 28, 2026
bootupd's bootloader-update.service looks for the block device backing
/boot or /sysroot, and in an ephemeral VM the root is virtiofs, so it
fails with "Failed to find block device from /boot or /sysroot". The
system then comes up "degraded", which breaks every test that boots an
image with bcvk and checks systemctl is-system-running, forcing each
consumer (e.g. bootc-dev/infra, bootupd CI) to mask it themselves.

There is never a bootloader to update in an ephemeral VM, so mask it
by default like systemd-journal-flush.service. coreos/bootupd#1072
makes bootupd skip this case itself, but existing images will carry
older bootupd for a long time.

The ephemeral system-command integration test now asserts the VM
reaches "running", so a unit failing in every ephemeral boot is caught
here rather than by bcvk's consumers.

Generated-by: AI
Signed-off-by: Colin Walters <walters@verbum.org>
@cgwalters-bot cgwalters-bot moved this to Done in Workstream Sep 30, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants