fix(host): make libvirt stack enablement mutually exclusive so one stack cannot silently kill the other's sockets (#3126) - #3177
Merged
Conversation
…ack cannot silently kill the other's sockets (#3126) Monolithic libvirtd and modular virt*d stacks both bind /run/libvirt/libvirt-sock(-ro) with Conflicts= between their units. When both stacks get enabled, starting one instantly closes the other's sockets — sockets have no Restart=, so recovery needs manual re-enablement. Reproduced live on the host installer. step_libvirt_install now disables the opposite stack's units before enabling its own: monolithic arm disables virtproxyd.socket/-ro before enabling libvirtd; modular arm disables libvirtd.* before enabling the virt*d sockets. Closes #3126
Strix Security ReviewNo security issues found. Updated for Reviewed by Strix |
Dependency Review✅ No vulnerabilities or license issues or OpenSSF Scorecard issues found.Scanned FilesNone |
There was a problem hiding this comment.
Reviewed the single changed file, scripts/install-homeserver.sh. The change adjusts step_libvirt_install() to disable the opposite libvirt stack's systemd units before enabling its own, preventing the Conflicts= socket-kill hazard described in #3126. All systemctl arguments are hardcoded unit-name literals with no user-controlled input or dynamic expansion, so no injection or other security issue is introduced. No findings.
Reviewed by Strix
Configure security review settings
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Monolithic libvirtd and modular virt*d stacks both bind
/run/libvirt/libvirt-sock(-ro) with Conflicts= between their units. When
both stacks are enabled at once, starting one instantly closes the
other's sockets — socket units carry no Restart=, so recovery needs
manual re-enablement. Reproduced live on the host installer.
step_libvirt_install now disables the opposite stack's units before
enabling its own: the monolithic arm disables virtproxyd.socket/-ro
before enabling libvirtd; the modular arm disables libvirtd.* before
enabling the virt*d sockets.
Times in this description: Europe/Berlin.
Closes #3126