From 5e046e3d31ff0f6b054faf3f3ad03236e0a28568 Mon Sep 17 00:00:00 2001 From: "goodolclint-claude[bot]" <323206664+goodolclint-claude[bot]@users.noreply.github.com> Date: Tue, 1 Sep 2026 14:25:50 +0000 Subject: [PATCH] ci: stop half-upgrading the nested nodes MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit `apt-get upgrade` holds back any package whose upgrade needs new dependencies, so it neither pins nor updates — it produces whatever partial set the dependency graph allows that day. On these nodes it upgraded pve-cluster to 9.1.6 while leaving libpve-cluster-api-perl at 9.1.0. Those two ship the halves of the join: cfs_backup_database() in PVE/Cluster.pm (pve-cluster) and finish_join() in PVE/Cluster/Setup.pm (libpve-cluster-api-perl). Upstream removed `return $dbfile` from the former and stopped relying on it in the latter, both at 9.1.1 — 9.1.6's finish_join calls cfs_unlink_db_unsafe() instead. The 9.1.0 caller against the 9.1.6 callee unlinks an empty string, so the standalone config.db survives the join, pmxcfs restarts in local mode, and the node reports online=0 forever while corosync forms a healthy 2-node membership. That is the "2 nodes online" failure, and it is not reachable on any coherent install. The ISO is the pin, so drop the upgrade and install only what the harness needs. Upgrades belong in a separate currency lane that records the package set it tested. Co-Authored-By: Claude Opus 5 (1M context) --- tests/infrastructure/scripts/first-boot.sh | 8 ++++++-- 1 file changed, 6 insertions(+), 2 deletions(-) diff --git a/tests/infrastructure/scripts/first-boot.sh b/tests/infrastructure/scripts/first-boot.sh index 020d970..df7fccc 100755 --- a/tests/infrastructure/scripts/first-boot.sh +++ b/tests/infrastructure/scripts/first-boot.sh @@ -18,8 +18,12 @@ if [ -z "$SUITE" ]; then fi echo "deb http://download.proxmox.com/debian/pve ${SUITE} pve-no-subscription" > /etc/apt/sources.list.d/pve-no-subscription.list +# No upgrade here on purpose. `apt-get upgrade` holds back packages that need +# new dependencies, which produced pve-cluster 9.1.6 against +# libpve-cluster-api-perl 9.1.0 — a combination no real install ever has, and +# one whose cluster join silently leaves the node unclustered. The ISO is the +# pin; the currency lane is where upgrades get exercised. apt-get update -qq -apt-get upgrade -y -qq -apt-get install -y -qq qemu-guest-agent open-iscsi +apt-get install -y -qq --no-install-recommends qemu-guest-agent open-iscsi systemctl start qemu-guest-agent systemctl enable open-iscsi