From 40a9e05e51ed1f870d70b3a90db43ed34d9d6bd7 Mon Sep 17 00:00:00 2001 From: claude-hdb Date: Mon, 13 Jul 2026 23:05:34 +0000 Subject: [PATCH] fix(drill): stop going silent through host setup MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Run 5 looked stuck for minutes right after the "Host setup" header. The setup stretch is the longest and most failure-prone part of the run, and it was also the only part that printed nothing at all — two ways to block, both invisible: · 'sudo apt-get install -y -qq incus >/dev/null 2>&1' swallows a sudo password prompt, so a stalled sudo is indistinguishable from a hang. Sudo is now pre-authorized up front, out loud. · apt's lock is routinely held by apt-daily / unattended-upgrades on a cloud image, and apt waits for it in complete silence. It now gets DPkg::Lock::Timeout=300 plus an outer timeout, announces that it may be waiting on the lock, and on failure prints the two commands that identify the holder — instead of hanging forever. Also: skip the apt call entirely when incus is already installed (every re-run on the same host), and narrate each setup sub-step, so a stall is locatable rather than a blank terminal. Co-Authored-By: Claude Fable 5 --- drill/drill.sh | 34 ++++++++++++++++++++++++++++++---- 1 file changed, 30 insertions(+), 4 deletions(-) diff --git a/drill/drill.sh b/drill/drill.sh index 5a4554f..5197b46 100755 --- a/drill/drill.sh +++ b/drill/drill.sh @@ -154,20 +154,46 @@ EOF phase "Host setup (Incus, claudenet, ACL, profile, firewall)" # setup-host.sh installs nftables itself when neither nft nor UFW exists - # (fixed in this PR — a stock Debian 13 cloud image ships neither). This - # guard stays as a tripwire: if it fires, that fix regressed. + # (a stock Debian 13 cloud image ships neither). This guard is a tripwire: + # if it fires, that fix regressed. if ! command -v nft >/dev/null 2>&1 && ! command -v ufw >/dev/null 2>&1; then note "neither nft nor ufw present pre-setup — setup-host.sh must install nftables itself (it fixed this once; watch that it still does)" fi - sudo apt-get install -y -qq incus >/dev/null 2>&1 # so the group exists before we sg - ~/.local/share/claudebox/host/setup-host.sh || true # first run may only add the group + + # Sudo, up front and out loud. Later calls run unattended, and a password + # prompt swallowed by a '-qq' redirect looks exactly like a hang. + sudo -v || { echo "drill: need sudo (the host setup installs packages and firewall rules)"; exit 1; } + + # apt's lock is held by apt-daily / unattended-upgrades on a fresh cloud + # image, and 'apt-get -qq >/dev/null' waits for it in COMPLETE SILENCE — + # which is how run 5 looked stuck for minutes right after this header. + # Say what we are waiting for, and give up rather than hang forever. + if ! command -v incus >/dev/null 2>&1; then + inf "installing incus (waiting for the apt lock if a background upgrade holds it)…" + if ! sudo DEBIAN_FRONTEND=noninteractive timeout 600 \ + apt-get -o DPkg::Lock::Timeout=300 install -y incus; then + echo "drill: 'apt-get install incus' failed or timed out." >&2 + echo " a background apt job usually holds the lock. check with:" >&2 + echo " sudo fuser -v /var/lib/dpkg/lock-frontend" >&2 + echo " systemctl status unattended-upgrades apt-daily.service" >&2 + exit 1 + fi + else + inf "incus already installed — skipping apt" + fi + + inf "running setup-host.sh (first pass: may only add you to incus-admin)…" + ~/.local/share/claudebox/host/setup-host.sh || true # The group we were just added to isn't in this shell's credentials yet. + inf "re-entering inside the incus-admin group…" exec sg incus-admin -c "IN_GROUP=1 CLAUDEBOX_REPO='$REPO' CLAUDEBOX_REF='$REF' KEEP=$KEEP bash '$SELF' --in-group" fi export PATH="$HOME/.local/bin:$PATH" KEEP="${KEEP:-0}" +inf "running setup-host.sh (in-group pass: network, ACL, profile, firewall)…" ~/.local/share/claudebox/host/setup-host.sh || { echo "setup-host failed inside the group"; exit 1; } +inf "host setup complete" # Re-runnable: clear anything a previous drill left behind. One name at a # time — 'incus delete -f a b c' aborts at the first MISSING name, which is