Skip to content

fix(host): make libvirt stack enablement mutually exclusive so one stack cannot silently kill the other's sockets (#3126) - #3177

Merged
Xore merged 1 commit into
mainfrom
agent/issue-3126-coder
Sep 13, 2026
Merged

Xore merged 1 commit into
mainfrom
agent/issue-3126-coder

Conversation

@Xore

@Xore Xore commented Sep 12, 2026

Copy link
Copy Markdown
Owner

Monolithic libvirtd and modular virt*d stacks both bind
/run/libvirt/libvirt-sock(-ro) with Conflicts= between their units. When
both stacks are enabled at once, starting one instantly closes the
other's sockets — socket units carry no Restart=, so recovery needs
manual re-enablement. Reproduced live on the host installer.

step_libvirt_install now disables the opposite stack's units before
enabling its own: the monolithic arm disables virtproxyd.socket/-ro
before enabling libvirtd; the modular arm disables libvirtd.* before
enabling the virt*d sockets.

Times in this description: Europe/Berlin.

Closes #3126

…ack cannot silently kill the other's sockets (#3126)

Monolithic libvirtd and modular virt*d stacks both bind
/run/libvirt/libvirt-sock(-ro) with Conflicts= between their units. When
both stacks get enabled, starting one instantly closes the other's
sockets — sockets have no Restart=, so recovery needs manual
re-enablement. Reproduced live on the host installer.

step_libvirt_install now disables the opposite stack's units before
enabling its own: monolithic arm disables virtproxyd.socket/-ro before
enabling libvirtd; modular arm disables libvirtd.* before enabling the
virt*d sockets.

Closes #3126
@strix-security

strix-security Bot commented Sep 12, 2026 •

Copy link
Copy Markdown

Strix Security Review

No security issues found.

Updated for 1b29951.


Reviewed by Strix
Re-run review · Configure security review settings

@github-actions

Copy link
Copy Markdown

Dependency Review

✅ No vulnerabilities or license issues or OpenSSF Scorecard issues found.

Scanned Files

None

@strix-security strix-security Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewed the single changed file, scripts/install-homeserver.sh. The change adjusts step_libvirt_install() to disable the opposite libvirt stack's systemd units before enabling its own, preventing the Conflicts= socket-kill hazard described in #3126. All systemctl arguments are hardcoded unit-name literals with no user-controlled input or dynamic expansion, so no injection or other security issue is introduced. No findings.


Reviewed by Strix
Configure security review settings

@Xore
Xore merged commit 1e60f30 into main Sep 13, 2026
110 checks passed
@Xore
Xore deleted the agent/issue-3126-coder branch September 13, 2026 00:38
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

virtproxyd.socket / virtproxyd-ro.socket self-deactivate on homeserver, breaking /var/run/libvirt/libvirt-sock*

1 participant