docs: OS updates steps 3+4 BUILT (11 §8.2/§8.3, §5.6 kernel facts, §5.8 Docker slow lane design), 00/03/07/08 updated, decisions 84-86 (CC unattended), host undo runbook (proved), register: R-841 R-845 R-846 R-850 closed, R-848 R-849 R-851 opened, R-836 R-812 narrowed (332 -> 333); STATUS; live evidence
gates / gates (push) Successful in 31s

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
This commit is contained in:
2026-10-04 14:47:21 +02:00
parent 0e970ba384
commit 31bdb4b549
36 changed files with 1679 additions and 16 deletions
@@ -3,3 +3,17 @@
11:36:47 container=running/unhealthy hub=running alarm=none
11:37:49 container=running/unhealthy hub=not_running alarm=none
11:38:51 container=running/unhealthy hub=not_running alarm=none
11:39:53 container=running/unhealthy hub=not_running alarm=none
11:40:55 container=running/unhealthy hub=not_running alarm=none
11:41:57 container=running/unhealthy hub=not_running alarm=none
11:42:59 container=running/unhealthy hub=not_running alarm=none
11:44:01 container=running/unhealthy hub=not_running alarm=none
11:45:03 container=running/unhealthy hub=not_running alarm=none
11:46:05 container=running/unhealthy hub=not_running alarm=none
11:47:07 container=running/unhealthy hub=not_running alarm=none
11:48:09 container=running/unhealthy hub=not_running alarm=none
11:49:10 container=running/unhealthy hub=not_running alarm=none
11:50:12 container=running/unhealthy hub=not_running alarm=none
11:51:14 container=running/unhealthy hub=not_running alarm=none
11:52:16 container=running/unhealthy hub=not_running alarm=none
11:53:18 container=running/unhealthy hub=not_running alarm=2026/10/04 13:52:29 [WARN] host demo-hp-bb76ea tunnel: tunnel_down (container running but the tunnel is NOT connected (cloudflared /ready fails))
@@ -3,3 +3,6 @@ Chain DOCKER-USER (1 references)
target prot opt source destination
DROP tcp -- 0.0.0.0/0 0.0.0.0/0 tcp dpt:7844
DROP udp -- 0.0.0.0/0 0.0.0.0/0 udp dpt:7844
unblock at 2026-10-04T11:53:29Z
Chain DOCKER-USER (1 references)
target prot opt source destination
@@ -0,0 +1,14 @@
11:53:39 container=unhealthy hub=not_running
11:54:41 container=healthy hub=not_running
11:55:43 container=healthy hub=not_running
11:56:45 container=healthy hub=not_running
11:57:47 container=healthy hub=not_running
11:58:48 container=healthy hub=not_running
11:59:50 container=healthy hub=not_running
12:00:52 container=healthy hub=not_running
12:01:54 container=healthy hub=not_running
12:02:56 container=healthy hub=not_running
12:03:58 container=healthy hub=not_running
12:05:00 container=healthy hub=not_running
12:06:02 container=healthy hub=not_running
12:07:04 container=healthy hub=not_running
@@ -0,0 +1,5 @@
2026/10/04 13:52:29 [WARN] host demo-hp-bb76ea tunnel: tunnel_down (container running but the tunnel is NOT connected (cloudflared /ready fails))
2026/10/04 13:52:30 [INFO] Operator email sent for demo-hp/tunnel_down
2026/10/04 13:52:29 [WARN] host demo-hp-bb76ea tunnel: tunnel_down (container running but the tunnel is NOT connected (cloudflared /ready fails))
2026/10/04 13:52:30 [INFO] Operator email sent for demo-hp/tunnel_down
2026/10/04 14:07:29 [WARN] host demo-hp-bb76ea tunnel: tunnel_recovered (connected)
@@ -0,0 +1,135 @@
=== felhom-agent 0.141.1 selftest=os-update vmid=9201 ring=0 enabled=true guest-release=false host-release=false appliance=true ===
time=2026-10-04T14:22:52.476+02:00 level=INFO msg="osupdate: START" run=20261004T122252Z layer=guest vmid=9201 ring=0 trigger=debug enabled=true release=ring0-20261004T122252Z
time=2026-10-04T14:23:08.079+02:00 level=INFO msg="osupdate: wrapper" line="os-apply: START release=ring0-20261004T122252Z layer=guest:9201 lane=fast mode=apply select=pending-fast packages=0"
time=2026-10-04T14:23:08.079+02:00 level=INFO msg="osupdate: wrapper" line="os-apply: REPAIR configured=0 fixed=0"
time=2026-10-04T14:23:08.079+02:00 level=INFO msg="osupdate: wrapper" line="os-apply: PLAN upgrade=0 already=0 not-installed=0 from-snapshot=0"
time=2026-10-04T14:23:08.079+02:00 level=INFO msg="osupdate: wrapper" line="os-apply: DONE rc=0 seconds=0 upgraded=0 (nothing to do)"
time=2026-10-04T14:23:08.080+02:00 level=INFO msg="osupdate: DONE" run=20261004T122252Z layer=guest vmid=9201 ring=0 trigger=debug outcome=nothing healthy=true reason="" upgraded=0 pending=6 not_covered=6 restart_needed=0 reboot_needed=false wrapper_seconds=15.5
time=2026-10-04T14:23:08.089+02:00 level=INFO msg="osupdate: START" run=20261004T122252Z layer=host vmid=9201 ring=0 trigger=debug enabled=true release=ring0-20261004T122252Z
time=2026-10-04T14:23:22.788+02:00 level=INFO msg="osupdate: wrapper" line="os-apply: START release=ring0-20261004T122252Z layer=host lane=fast mode=apply select=pending-fast packages=0"
time=2026-10-04T14:23:22.788+02:00 level=INFO msg="osupdate: wrapper" line="os-apply: REPAIR configured=0 fixed=0"
time=2026-10-04T14:23:22.788+02:00 level=INFO msg="osupdate: wrapper" line="os-apply: PLAN upgrade=0 already=0 not-installed=0 from-snapshot=0"
time=2026-10-04T14:23:22.788+02:00 level=INFO msg="osupdate: wrapper" line="os-apply: DONE rc=0 seconds=0 upgraded=0 (nothing to do)"
time=2026-10-04T14:23:23.852+02:00 level=INFO msg="osupdate: DONE" run=20261004T122252Z layer=host vmid=9201 ring=0 trigger=debug outcome=nothing healthy=true reason="" upgraded=0 pending=78 not_covered=78 restart_needed=0 reboot_needed=false wrapper_seconds=14.6
--- os-update report (guest) ---
{
"health_reason": "",
"healthy": true,
"mode": "apply",
"not_covered": [
"docker-ce-cli",
"containerd.io",
"docker-ce",
"docker-buildx-plugin",
"docker-ce-rootless-extras",
"docker-compose-plugin"
],
"outcome": "nothing",
"pending": 6,
"reboot_needed": false,
"refused": null,
"release_id": "ring0-20261004T122252Z",
"restart_needed": null,
"ring": 0,
"run_id": "20261004T122252Z",
"upgraded": [],
"wrapper_seconds": 15.5
}
--- os-update report (host) ---
{
"health_reason": "",
"healthy": true,
"mode": "apply",
"not_covered": [
"frr",
"shim-signed-common",
"proxmox-secure-boot-support",
"shim-unsigned",
"shim-helpers-amd64-signed",
"shim-signed",
"amd64-microcode",
"libradosstriper1",
"librgw2",
"ceph-common",
"librbd1",
"librados2",
"python3-cephfs",
"libcephfs2",
"python3-rgw",
"python3-rados",
"python3-ceph-argparse",
"python3-ceph-common",
"python3-rbd",
"ceph-fuse",
"chrony",
"libcorosync-common4",
"libcfg7",
"libcmap4",
"libcpg4",
"libknet1t64",
"libnozzle1t64",
"libquorum5",
"libvotequorum8",
"corosync",
"frr-pythontools",
"libjs-extjs",
"libnvpair3linux",
"libproxmox-acme-plugins",
"libproxmox-backup-qemu0",
"pve-qemu-kvm",
"libpve-notify-perl",
"libpve-cluster-api-perl",
"libpve-cluster-perl",
"pve-cluster",
"libpve-access-control",
"libpve-apiclient-perl",
"librados2-perl",
"proxmox-backup-client",
"proxmox-backup-file-restore",
"pve-manager",
"libproxmox-acme-perl",
"libpve-common-perl",
"libpve-guest-common-perl",
"qemu-server",
"libpve-storage-perl",
"pve-edk2-firmware-legacy",
"pve-edk2-firmware-ovmf",
"libpve-network-api-perl",
"libpve-network-perl",
"proxmox-firewall-data",
"pve-firewall",
"pve-container",
"pve-ha-manager",
"novnc-pve",
"proxmox-enterprise-support-keyring",
"proxmox-mini-journalreader",
"proxmox-widget-toolkit",
"pve-docs",
"pve-i18n",
"pve-xtermjs",
"pve-yew-mobile-i18n",
"pve-yew-mobile-gui",
"libuutil3linux",
"libzfs7linux",
"libzpool7linux",
"proxmox-kernel-helper",
"pve-edk2-firmware-aarch64",
"pve-edk2-firmware",
"pve-firmware",
"zfs-initramfs",
"zfsutils-linux",
"zfs-zed"
],
"outcome": "nothing",
"pending": 78,
"reboot_needed": false,
"refused": null,
"release_id": "ring0-20261004T122252Z",
"restart_needed": [],
"ring": 0,
"run_id": "20261004T122252Z",
"upgraded": [],
"wrapper_seconds": 14.6
}
pass took 31.4s
WALL_SECONDS=31.520457543
@@ -0,0 +1,2 @@
{"ok":true}
200
@@ -0,0 +1,43 @@
+ PKG=tzdata
++ grep -oE 'tzdata:amd64 \([^,]+' /var/log/apt/history.log
++ tail -1
++ sed 's/.*(//'
+ OLD=2026b-0+deb13u1
++ dpkg-query -W '-f=${Version}' tzdata
+ NEW=2026c-0+deb13u1
+ echo OLD=2026b-0+deb13u1 NEW=2026c-0+deb13u1
OLD=2026b-0+deb13u1 NEW=2026c-0+deb13u1
++ curl -s 'https://snapshot.debian.org/mr/binary/tzdata/2026c-0+deb13u1/binfiles?fileinfo=1'
++ python3 -c '
import json,sys; d=json.load(sys.stdin)
print(sorted(f["first_seen"] for v in d["fileinfo"].values() for f in v)[0])'
+ TS=20260831T204404Z
+ . /etc/os-release
++ PRETTY_NAME='Debian GNU/Linux 13 (trixie)'
++ NAME='Debian GNU/Linux'
++ VERSION_ID=13
++ VERSION='13 (trixie)'
++ VERSION_CODENAME=trixie
++ DEBIAN_VERSION_FULL=13.7
++ ID=debian
++ HOME_URL=https://www.debian.org/
++ SUPPORT_URL=https://www.debian.org/support
++ BUG_REPORT_URL=https://bugs.debian.org/
+ printf 'deb [check-valid-until=no] http://snapshot.debian.org/archive/debian/%s %s main\ndeb [check-valid-until=no] http://snapshot.debian.org/archive/debian-security/%s %s-security main\n' 20260831T204404Z trixie 20260831T204404Z trixie
+ apt-get -q update
+ apt-get -s install --allow-downgrades tzdata=2026b-0+deb13u1
+ grep -E '^(Inst|Remv)|downgraded'
0 upgraded, 0 newly installed, 1 downgraded, 0 to remove and 78 not upgraded.
Inst tzdata [2026c-0+deb13u1] (2026b-0+deb13u1 Debian:13.6/stable [all])
+ DEBIAN_FRONTEND=noninteractive
+ apt-get -y -q install --allow-downgrades tzdata=2026b-0+deb13u1
+ rm -f /etc/apt/sources.list.d/felhom-undo-snapshot.list
+ apt-get -q update
+ dpkg-query -W tzdata
tzdata 2026b-0+deb13u1
+ ls /etc/apt/sources.list.d/
ceph.sources
debian.sources
pve-enterprise.sources
pve-no-subscription.sources
tailscale.list
@@ -0,0 +1,178 @@
=== felhom-agent 0.141.1 selftest=os-update vmid=9201 ring=1 enabled=true guest-release=true host-release=true appliance=true ===
time=2026-10-04T14:40:46.795+02:00 level=INFO msg="osupdate: START" run=20261004T124046Z layer=guest vmid=9201 ring=1 trigger=debug enabled=true release=os-guest-20261004-123933
time=2026-10-04T14:40:56.895+02:00 level=INFO msg="osupdate: wrapper" line="os-apply: START release=os-guest-20261004-123933 layer=guest:9201 lane=fast mode=apply select=listed packages=272"
time=2026-10-04T14:40:56.895+02:00 level=INFO msg="osupdate: wrapper" line="os-apply: REPAIR configured=0 fixed=0"
time=2026-10-04T14:40:56.895+02:00 level=INFO msg="osupdate: wrapper" line="os-apply: PLAN upgrade=0 already=272 not-installed=0 from-snapshot=0"
time=2026-10-04T14:40:56.895+02:00 level=INFO msg="osupdate: wrapper" line="os-apply: DONE rc=0 seconds=0 upgraded=0 (nothing to do)"
time=2026-10-04T14:40:56.896+02:00 level=INFO msg="osupdate: DONE" run=20261004T124046Z layer=guest vmid=9201 ring=1 trigger=debug outcome=nothing healthy=true reason="" upgraded=0 pending=6 not_covered=6 restart_needed=0 reboot_needed=false wrapper_seconds=10.1
time=2026-10-04T14:40:56.907+02:00 level=INFO msg="osupdate: START" run=20261004T124046Z layer=host vmid=9201 ring=1 trigger=debug enabled=true release=os-host-20261004-124034
time=2026-10-04T14:41:10.034+02:00 level=INFO msg="osupdate: wrapper" line="os-apply: START release=os-host-20261004-124034 layer=host lane=fast mode=apply select=listed packages=605"
time=2026-10-04T14:41:10.034+02:00 level=INFO msg="osupdate: wrapper" line="os-apply: REPAIR configured=0 fixed=0"
time=2026-10-04T14:41:10.034+02:00 level=INFO msg="osupdate: wrapper" line="os-apply: PLAN upgrade=1 already=604 not-installed=0 from-snapshot=0"
time=2026-10-04T14:41:10.034+02:00 level=INFO msg="osupdate: wrapper" line="os-apply: DONE rc=0 seconds=1.4 upgraded=1 restart-needed=agetty,blkmapd,chronyd,cron,dbus-daemon,dmeventd,ksmtuned,lxc-monitord,lxc-start,lxcfs,pmxcfs,proxmox-firewal,pve-firewall,pve-ha-crm,pve-ha-lrm,pve-lxc-syscall,pvedaemon,pvedaemon worke,pvefw-logger,pveproxy,pveproxy worker,pvescheduler,pvestatd,qmeventd,rpcbind,rrdcached,smartd,spiceproxy,spiceproxy work,sshd,systemd-logind,systemd-udevd,watchdog-mux,zed reboot-needed=yes"
time=2026-10-04T14:41:10.815+02:00 level=INFO msg="osupdate: DONE" run=20261004T124046Z layer=host vmid=9201 ring=1 trigger=debug outcome=applied healthy=true reason="" upgraded=1 pending=80 not_covered=80 restart_needed=34 reboot_needed=true wrapper_seconds=13.1
--- os-update report (guest) ---
{
"health_reason": "",
"healthy": true,
"mode": "apply",
"not_covered": [
"docker-ce-cli",
"containerd.io",
"docker-ce",
"docker-buildx-plugin",
"docker-ce-rootless-extras",
"docker-compose-plugin"
],
"outcome": "nothing",
"pending": 6,
"reboot_needed": false,
"refused": null,
"release_id": "os-guest-20261004-123933",
"restart_needed": null,
"ring": 1,
"run_id": "20261004T124046Z",
"upgraded": [],
"wrapper_seconds": 10.1
}
--- os-update report (host) ---
{
"health_reason": "",
"healthy": true,
"mode": "apply",
"not_covered": [
"frr",
"shim-signed-common",
"shim-unsigned",
"shim-helpers-amd64-signed",
"shim-signed",
"libradosstriper1",
"librgw2",
"ceph-common",
"librbd1",
"librados2",
"python3-cephfs",
"libcephfs2",
"python3-rgw",
"python3-rados",
"python3-ceph-argparse",
"python3-ceph-common",
"python3-rbd",
"ceph-fuse",
"chrony",
"libcorosync-common4",
"libcfg7",
"libcmap4",
"libcpg4",
"libknet1t64",
"libnozzle1t64",
"libquorum5",
"libvotequorum8",
"corosync",
"frr-pythontools",
"libjs-extjs",
"libnvpair3linux",
"libproxmox-acme-plugins",
"libproxmox-backup-qemu0",
"pve-qemu-kvm",
"libpve-notify-perl",
"libpve-cluster-api-perl",
"libpve-cluster-perl",
"pve-cluster",
"libpve-access-control",
"libpve-apiclient-perl",
"librados2-perl",
"proxmox-backup-client",
"proxmox-backup-file-restore",
"pve-manager",
"libproxmox-acme-perl",
"libpve-common-perl",
"libpve-guest-common-perl",
"qemu-server",
"libpve-storage-perl",
"pve-edk2-firmware-legacy",
"pve-edk2-firmware-ovmf",
"libpve-network-api-perl",
"libpve-network-perl",
"proxmox-firewall-data",
"pve-firewall",
"pve-container",
"pve-ha-manager",
"novnc-pve",
"proxmox-enterprise-support-keyring",
"proxmox-mini-journalreader",
"proxmox-widget-toolkit",
"pve-docs",
"pve-i18n",
"pve-xtermjs",
"pve-yew-mobile-i18n",
"pve-yew-mobile-gui",
"libuutil3linux",
"libzfs7linux",
"libzpool7linux",
"proxmox-first-boot",
"pve-firmware",
"proxmox-kernel-7.0.14-20-pve-signed",
"proxmox-kernel-7.0",
"proxmox-kernel-helper",
"pve-edk2-firmware-aarch64",
"pve-edk2-firmware",
"zfs-initramfs",
"zfsutils-linux",
"zfs-zed",
"tailscale"
],
"outcome": "applied",
"pending": 80,
"reboot_needed": true,
"refused": null,
"release_id": "os-host-20261004-124034",
"restart_needed": [
"agetty",
"blkmapd",
"chronyd",
"cron",
"dbus-daemon",
"dmeventd",
"ksmtuned",
"lxc-monitord",
"lxc-start",
"lxcfs",
"pmxcfs",
"proxmox-firewal",
"pve-firewall",
"pve-ha-crm",
"pve-ha-lrm",
"pve-lxc-syscall",
"pvedaemon",
"pvedaemon worke",
"pvefw-logger",
"pveproxy",
"pveproxy worker",
"pvescheduler",
"pvestatd",
"qmeventd",
"rpcbind",
"rrdcached",
"smartd",
"spiceproxy",
"spiceproxy work",
"sshd",
"systemd-logind",
"systemd-udevd",
"watchdog-mux",
"zed"
],
"ring": 1,
"run_id": "20261004T124046Z",
"upgraded": [
{
"name": "tzdata",
"version": "2026c-0+deb13u1",
"origin": ""
}
],
"wrapper_seconds": 13.1
}
pass took 24.1s
tzdata 2026c-0+deb13u1
@@ -0,0 +1,11 @@
+ PKG=eject
+ OLD=2.41-5
+ dpkg -s eject
+ grep -E '^(Status|Version)'
Status: install ok installed
Version: 2.41.5-0+deb13u1
+ curl -s 'https://snapshot.debian.org/mr/binary/eject/2.41-5/binfiles?fileinfo=1'
+ python3 -c '
import json,sys; d=json.load(sys.stdin)
print(sorted(f["first_seen"] for v in d["fileinfo"].values() for f in v)[0])'
20250510T015204Z
@@ -0,0 +1,28 @@
+ PKG=eject
+ OLD=2.41-5
+ TS=20250510T015204Z
+ . /etc/os-release
++ PRETTY_NAME='Debian GNU/Linux 13 (trixie)'
++ NAME='Debian GNU/Linux'
++ VERSION_ID=13
++ VERSION='13 (trixie)'
++ VERSION_CODENAME=trixie
++ DEBIAN_VERSION_FULL=13.7
++ ID=debian
++ HOME_URL=https://www.debian.org/
++ SUPPORT_URL=https://www.debian.org/support
++ BUG_REPORT_URL=https://bugs.debian.org/
+ cat
++ date +%s
+ S=1791116624
+ apt-get -q update
+ tail -3
Get:7 http://snapshot.debian.org/archive/debian/20250510T015204Z trixie/main amd64 Packages [9681 kB]
Fetched 9904 kB in 5s (2165 kB/s)
Reading package lists...
++ date +%s
update_seconds=6
+ echo update_seconds=6
+ apt-get -s install --allow-downgrades eject=2.41-5
+ grep -E '^(Inst|Remv|Conf)|downgraded|newly|Err|E:'
E: Version '2.41-5' for 'eject' was not found
@@ -0,0 +1,35 @@
+ PKG=eject
+ OLD=2.41-5
++ dpkg-query -W '-f=${Version}' eject
+ NEW=2.41.5-0+deb13u1
++ curl -s 'https://snapshot.debian.org/mr/binary/eject/2.41.5-0+deb13u1/binfiles?fileinfo=1'
++ python3 -c '
import json,sys; d=json.load(sys.stdin)
print(sorted(f["first_seen"] for v in d["fileinfo"].values() for f in v)[0])'
TS=20260814T165831Z
+ TS=20260814T165831Z
+ echo TS=20260814T165831Z
+ . /etc/os-release
++ PRETTY_NAME='Debian GNU/Linux 13 (trixie)'
++ NAME='Debian GNU/Linux'
++ VERSION_ID=13
++ VERSION='13 (trixie)'
++ VERSION_CODENAME=trixie
++ DEBIAN_VERSION_FULL=13.7
++ ID=debian
++ HOME_URL=https://www.debian.org/
++ SUPPORT_URL=https://www.debian.org/support
++ BUG_REPORT_URL=https://bugs.debian.org/
+ cat
+ apt-get -q update
+ tail -1
Reading package lists...
+ apt-cache madison eject
eject | 2.41.5-0+deb13u1 | http://deb.debian.org/debian trixie/main amd64 Packages
eject | 2.41.5-0+deb13u1 | http://security.debian.org/debian-security trixie-security/main amd64 Packages
eject | 2.41.5-0+deb13u1 | http://snapshot.debian.org/archive/debian-security/20260814T165831Z trixie-security/main amd64 Packages
eject | 2.41-5 | http://snapshot.debian.org/archive/debian/20260814T165831Z trixie/main amd64 Packages
+ apt-get -s install --allow-downgrades eject=2.41-5
+ grep -E '^(Inst|Remv|Conf)|downgraded|newly|Err|E:'
E: Unable to correct problems, you have held broken packages.
E: The following information from --solver 3.0 may provide additional context:
@@ -0,0 +1,37 @@
+ rm -f /etc/apt/sources.list.d/felhom-undo-snapshot.list
+ PKG=tzdata
+ OLD=2026b-0+deb13u1
++ dpkg-query -W '-f=${Version}' tzdata
+ NEW=2026c-0+deb13u1
+ echo NEW=2026c-0+deb13u1
NEW=2026c-0+deb13u1
++ curl -s 'https://snapshot.debian.org/mr/binary/tzdata/2026c-0+deb13u1/binfiles?fileinfo=1'
++ python3 -c '
import json,sys; d=json.load(sys.stdin)
print(sorted(f["first_seen"] for v in d["fileinfo"].values() for f in v)[0])'
TS=20260831T204404Z
+ TS=20260831T204404Z
+ echo TS=20260831T204404Z
+ . /etc/os-release
++ PRETTY_NAME='Debian GNU/Linux 13 (trixie)'
++ NAME='Debian GNU/Linux'
++ VERSION_ID=13
++ VERSION='13 (trixie)'
++ VERSION_CODENAME=trixie
++ DEBIAN_VERSION_FULL=13.7
++ ID=debian
++ HOME_URL=https://www.debian.org/
++ SUPPORT_URL=https://www.debian.org/support
++ BUG_REPORT_URL=https://bugs.debian.org/
+ cat
+ apt-get -q update
+ tail -1
Reading package lists...
+ apt-cache madison tzdata
tzdata | 2026c-0+deb13u1 | http://deb.debian.org/debian trixie/main amd64 Packages
tzdata | 2026b-0+deb13u1 | http://snapshot.debian.org/archive/debian/20260831T204404Z trixie/main amd64 Packages
+ apt-get -s install --allow-downgrades tzdata=2026b-0+deb13u1
+ grep -E '^(Inst|Remv|Conf)|downgraded|newly|Err|E:'
0 upgraded, 0 newly installed, 1 downgraded, 0 to remove and 77 not upgraded.
Inst tzdata [2026c-0+deb13u1] (2026b-0+deb13u1 Debian:13.6/stable [all])
Conf tzdata (2026b-0+deb13u1 Debian:13.6/stable [all])
@@ -0,0 +1,38 @@
+ PKG=tzdata
+ OLD=2026b-0+deb13u1
++ date +%s
+ S=1791116670
+ DEBIAN_FRONTEND=noninteractive
+ apt-get -y -q install --allow-downgrades tzdata=2026b-0+deb13u1
+ grep -E '^(Unpacking|Setting up)|downgraded'
0 upgraded, 0 newly installed, 1 downgraded, 0 to remove and 77 not upgraded.
Unpacking tzdata (2026b-0+deb13u1) over (2026c-0+deb13u1) ...
Setting up tzdata (2026b-0+deb13u1) ...
+ apt-mark hold tzdata
tzdata set on hold.
+ rm -f /etc/apt/sources.list.d/felhom-undo-snapshot.list
+ apt-get -q update
+ tail -1
Reading package lists...
++ date +%s
undo_seconds=4
+ echo undo_seconds=4
+ dpkg -s tzdata
+ grep -E '^(Status|Version)'
Status: hold ok installed
Version: 2026b-0+deb13u1
+ apt-mark showhold
tzdata
+ systemctl is-active pveproxy pvedaemon pvestatd pve-cluster felhom-agent
active
active
active
active
active
+ pct status 9201
status: running
+ ls /etc/apt/sources.list.d/
ceph.sources
debian.sources
pve-enterprise.sources
pve-no-subscription.sources
@@ -0,0 +1,135 @@
=== felhom-agent 0.141.1 selftest=os-update vmid=9201 ring=0 enabled=true guest-release=false host-release=false appliance=true ===
time=2026-10-04T14:24:41.910+02:00 level=INFO msg="osupdate: START" run=20261004T122441Z layer=guest vmid=9201 ring=0 trigger=debug enabled=true release=ring0-20261004T122441Z
time=2026-10-04T14:24:57.242+02:00 level=INFO msg="osupdate: wrapper" line="os-apply: START release=ring0-20261004T122441Z layer=guest:9201 lane=fast mode=apply select=pending-fast packages=0"
time=2026-10-04T14:24:57.242+02:00 level=INFO msg="osupdate: wrapper" line="os-apply: REPAIR configured=0 fixed=0"
time=2026-10-04T14:24:57.242+02:00 level=INFO msg="osupdate: wrapper" line="os-apply: PLAN upgrade=0 already=0 not-installed=0 from-snapshot=0"
time=2026-10-04T14:24:57.242+02:00 level=INFO msg="osupdate: wrapper" line="os-apply: DONE rc=0 seconds=0 upgraded=0 (nothing to do)"
time=2026-10-04T14:24:57.243+02:00 level=INFO msg="osupdate: DONE" run=20261004T122441Z layer=guest vmid=9201 ring=0 trigger=debug outcome=nothing healthy=true reason="" upgraded=0 pending=6 not_covered=6 restart_needed=0 reboot_needed=false wrapper_seconds=15.3
time=2026-10-04T14:24:57.251+02:00 level=INFO msg="osupdate: START" run=20261004T122441Z layer=host vmid=9201 ring=0 trigger=debug enabled=true release=ring0-20261004T122441Z
time=2026-10-04T14:25:12.127+02:00 level=INFO msg="osupdate: wrapper" line="os-apply: START release=ring0-20261004T122441Z layer=host lane=fast mode=apply select=pending-fast packages=0"
time=2026-10-04T14:25:12.127+02:00 level=INFO msg="osupdate: wrapper" line="os-apply: REPAIR configured=0 fixed=0"
time=2026-10-04T14:25:12.127+02:00 level=INFO msg="osupdate: wrapper" line="os-apply: PLAN upgrade=0 already=0 not-installed=0 from-snapshot=0"
time=2026-10-04T14:25:12.127+02:00 level=INFO msg="osupdate: wrapper" line="os-apply: DONE rc=0 seconds=0 upgraded=0 (nothing to do)"
time=2026-10-04T14:25:13.136+02:00 level=INFO msg="osupdate: DONE" run=20261004T122441Z layer=host vmid=9201 ring=0 trigger=debug outcome=nothing healthy=true reason="" upgraded=0 pending=78 not_covered=78 restart_needed=0 reboot_needed=false wrapper_seconds=14.8
--- os-update report (guest) ---
{
"health_reason": "",
"healthy": true,
"mode": "apply",
"not_covered": [
"docker-ce-cli",
"containerd.io",
"docker-ce",
"docker-buildx-plugin",
"docker-ce-rootless-extras",
"docker-compose-plugin"
],
"outcome": "nothing",
"pending": 6,
"reboot_needed": false,
"refused": null,
"release_id": "ring0-20261004T122441Z",
"restart_needed": null,
"ring": 0,
"run_id": "20261004T122441Z",
"upgraded": [],
"wrapper_seconds": 15.3
}
--- os-update report (host) ---
{
"health_reason": "",
"healthy": true,
"mode": "apply",
"not_covered": [
"frr",
"shim-signed-common",
"proxmox-secure-boot-support",
"shim-unsigned",
"shim-helpers-amd64-signed",
"shim-signed",
"amd64-microcode",
"libradosstriper1",
"librgw2",
"ceph-common",
"librbd1",
"librados2",
"python3-cephfs",
"libcephfs2",
"python3-rgw",
"python3-rados",
"python3-ceph-argparse",
"python3-ceph-common",
"python3-rbd",
"ceph-fuse",
"chrony",
"libcorosync-common4",
"libcfg7",
"libcmap4",
"libcpg4",
"libknet1t64",
"libnozzle1t64",
"libquorum5",
"libvotequorum8",
"corosync",
"frr-pythontools",
"libjs-extjs",
"libnvpair3linux",
"libproxmox-acme-plugins",
"libproxmox-backup-qemu0",
"pve-qemu-kvm",
"libpve-notify-perl",
"libpve-cluster-api-perl",
"libpve-cluster-perl",
"pve-cluster",
"libpve-access-control",
"libpve-apiclient-perl",
"librados2-perl",
"proxmox-backup-client",
"proxmox-backup-file-restore",
"pve-manager",
"libproxmox-acme-perl",
"libpve-common-perl",
"libpve-guest-common-perl",
"qemu-server",
"libpve-storage-perl",
"pve-edk2-firmware-legacy",
"pve-edk2-firmware-ovmf",
"libpve-network-api-perl",
"libpve-network-perl",
"proxmox-firewall-data",
"pve-firewall",
"pve-container",
"pve-ha-manager",
"novnc-pve",
"proxmox-enterprise-support-keyring",
"proxmox-mini-journalreader",
"proxmox-widget-toolkit",
"pve-docs",
"pve-i18n",
"pve-xtermjs",
"pve-yew-mobile-i18n",
"pve-yew-mobile-gui",
"libuutil3linux",
"libzfs7linux",
"libzpool7linux",
"proxmox-kernel-helper",
"pve-edk2-firmware-aarch64",
"pve-edk2-firmware",
"pve-firmware",
"zfs-initramfs",
"zfsutils-linux",
"zfs-zed"
],
"outcome": "nothing",
"pending": 78,
"reboot_needed": false,
"refused": null,
"release_id": "ring0-20261004T122441Z",
"restart_needed": [],
"ring": 0,
"run_id": "20261004T122441Z",
"upgraded": [],
"wrapper_seconds": 14.8
}
pass took 31.2s
tzdata 2026b-0+deb13u1
@@ -0,0 +1,143 @@
Canceled hold on tzdata.
=== felhom-agent 0.141.1 selftest=os-update vmid=9201 ring=0 enabled=true guest-release=false host-release=false appliance=true ===
time=2026-10-04T14:25:22.024+02:00 level=INFO msg="osupdate: START" run=20261004T122522Z layer=guest vmid=9201 ring=0 trigger=debug enabled=true release=ring0-20261004T122522Z
time=2026-10-04T14:25:37.515+02:00 level=INFO msg="osupdate: wrapper" line="os-apply: START release=ring0-20261004T122522Z layer=guest:9201 lane=fast mode=apply select=pending-fast packages=0"
time=2026-10-04T14:25:37.515+02:00 level=INFO msg="osupdate: wrapper" line="os-apply: REPAIR configured=0 fixed=0"
time=2026-10-04T14:25:37.515+02:00 level=INFO msg="osupdate: wrapper" line="os-apply: PLAN upgrade=0 already=0 not-installed=0 from-snapshot=0"
time=2026-10-04T14:25:37.515+02:00 level=INFO msg="osupdate: wrapper" line="os-apply: DONE rc=0 seconds=0 upgraded=0 (nothing to do)"
time=2026-10-04T14:25:37.516+02:00 level=INFO msg="osupdate: DONE" run=20261004T122522Z layer=guest vmid=9201 ring=0 trigger=debug outcome=nothing healthy=true reason="" upgraded=0 pending=6 not_covered=6 restart_needed=0 reboot_needed=false wrapper_seconds=15.4
time=2026-10-04T14:25:37.526+02:00 level=INFO msg="osupdate: START" run=20261004T122522Z layer=host vmid=9201 ring=0 trigger=debug enabled=true release=ring0-20261004T122522Z
time=2026-10-04T14:25:57.778+02:00 level=INFO msg="osupdate: wrapper" line="os-apply: START release=ring0-20261004T122522Z layer=host lane=fast mode=apply select=pending-fast packages=0"
time=2026-10-04T14:25:57.778+02:00 level=INFO msg="osupdate: wrapper" line="os-apply: REPAIR configured=0 fixed=0"
time=2026-10-04T14:25:57.778+02:00 level=INFO msg="osupdate: wrapper" line="os-apply: PLAN upgrade=1 already=0 not-installed=0 from-snapshot=0"
time=2026-10-04T14:25:57.778+02:00 level=INFO msg="osupdate: wrapper" line="os-apply: DONE rc=0 seconds=2.0 upgraded=1 restart-needed=- reboot-needed=no"
time=2026-10-04T14:25:58.809+02:00 level=INFO msg="osupdate: DONE" run=20261004T122522Z layer=host vmid=9201 ring=0 trigger=debug outcome=applied healthy=true reason="" upgraded=1 pending=78 not_covered=78 restart_needed=0 reboot_needed=false wrapper_seconds=20.2
--- os-update report (guest) ---
{
"health_reason": "",
"healthy": true,
"mode": "apply",
"not_covered": [
"docker-ce-cli",
"containerd.io",
"docker-ce",
"docker-buildx-plugin",
"docker-ce-rootless-extras",
"docker-compose-plugin"
],
"outcome": "nothing",
"pending": 6,
"reboot_needed": false,
"refused": null,
"release_id": "ring0-20261004T122522Z",
"restart_needed": null,
"ring": 0,
"run_id": "20261004T122522Z",
"upgraded": [],
"wrapper_seconds": 15.4
}
--- os-update report (host) ---
{
"health_reason": "",
"healthy": true,
"mode": "apply",
"not_covered": [
"frr",
"shim-signed-common",
"proxmox-secure-boot-support",
"shim-unsigned",
"shim-helpers-amd64-signed",
"shim-signed",
"amd64-microcode",
"libradosstriper1",
"librgw2",
"ceph-common",
"librbd1",
"librados2",
"python3-cephfs",
"libcephfs2",
"python3-rgw",
"python3-rados",
"python3-ceph-argparse",
"python3-ceph-common",
"python3-rbd",
"ceph-fuse",
"chrony",
"libcorosync-common4",
"libcfg7",
"libcmap4",
"libcpg4",
"libknet1t64",
"libnozzle1t64",
"libquorum5",
"libvotequorum8",
"corosync",
"frr-pythontools",
"libjs-extjs",
"libnvpair3linux",
"libproxmox-acme-plugins",
"libproxmox-backup-qemu0",
"pve-qemu-kvm",
"libpve-notify-perl",
"libpve-cluster-api-perl",
"libpve-cluster-perl",
"pve-cluster",
"libpve-access-control",
"libpve-apiclient-perl",
"librados2-perl",
"proxmox-backup-client",
"proxmox-backup-file-restore",
"pve-manager",
"libproxmox-acme-perl",
"libpve-common-perl",
"libpve-guest-common-perl",
"qemu-server",
"libpve-storage-perl",
"pve-edk2-firmware-legacy",
"pve-edk2-firmware-ovmf",
"libpve-network-api-perl",
"libpve-network-perl",
"proxmox-firewall-data",
"pve-firewall",
"pve-container",
"pve-ha-manager",
"novnc-pve",
"proxmox-enterprise-support-keyring",
"proxmox-mini-journalreader",
"proxmox-widget-toolkit",
"pve-docs",
"pve-i18n",
"pve-xtermjs",
"pve-yew-mobile-i18n",
"pve-yew-mobile-gui",
"libuutil3linux",
"libzfs7linux",
"libzpool7linux",
"proxmox-kernel-helper",
"pve-edk2-firmware-aarch64",
"pve-edk2-firmware",
"pve-firmware",
"zfs-initramfs",
"zfsutils-linux",
"zfs-zed"
],
"outcome": "applied",
"pending": 78,
"reboot_needed": false,
"refused": null,
"release_id": "ring0-20261004T122522Z",
"restart_needed": [],
"ring": 0,
"run_id": "20261004T122522Z",
"upgraded": [
{
"name": "tzdata",
"version": "2026c-0+deb13u1",
"origin": ""
}
],
"wrapper_seconds": 20.2
}
pass took 36.9s
tzdata 2026c-0+deb13u1
0
@@ -0,0 +1,104 @@
{
"boxes": [
{
"HostID": "demo-felhom-8363b5",
"Ring": 1,
"Enabled": true,
"Tunnel": "running",
"Guest": {
"ReleaseID": "os-guest-20261004-123933",
"LastOutcome": "nothing",
"LastAt": "2026-10-04T12:40:56Z",
"LastSuccessfulLeg": "2026-10-04T12:40:56Z",
"Pending": 6,
"NotCovered": 6,
"NotCoveredFast": 0,
"RestartNeeded": 0,
"RebootNeededSince": "2026-10-04T09:20:04Z",
"WrapperPassSeconds": 10.1
},
"Host": {
"ReleaseID": "os-host-20261004-124034",
"LastOutcome": "applied",
"LastAt": "2026-10-04T12:41:10Z",
"LastSuccessfulLeg": "2026-10-04T12:41:10Z",
"Pending": 80,
"NotCovered": 80,
"NotCoveredFast": 0,
"RestartNeeded": 34,
"RebootNeededSince": "2026-10-04T11:53:20Z",
"WrapperPassSeconds": 13.1
}
},
{
"HostID": "demo-hp-bb76ea",
"Ring": 0,
"Enabled": true,
"Tunnel": "unknown",
"Guest": {
"ReleaseID": "ring0-20261004T122522Z",
"LastOutcome": "nothing",
"LastAt": "2026-10-04T12:25:37Z",
"LastSuccessfulLeg": "2026-10-04T12:25:37Z",
"Pending": 6,
"NotCovered": 6,
"NotCoveredFast": 0,
"RestartNeeded": 0,
"RebootNeededSince": "2026-10-04T09:21:28Z",
"WrapperPassSeconds": 15.4
},
"Host": {
"ReleaseID": "ring0-20261004T122522Z",
"LastOutcome": "applied",
"LastAt": "2026-10-04T12:25:58Z",
"LastSuccessfulLeg": "2026-10-04T12:25:58Z",
"Pending": 78,
"NotCovered": 78,
"NotCoveredFast": 0,
"RestartNeeded": 0,
"RebootNeededSince": "0001-01-01T00:00:00Z",
"WrapperPassSeconds": 20.2
}
},
{
"HostID": "drill-r50-0a4f9a",
"Ring": 1,
"Enabled": true,
"Tunnel": "inactive",
"Guest": {
"ReleaseID": "",
"LastOutcome": "",
"LastAt": "0001-01-01T00:00:00Z",
"LastSuccessfulLeg": "0001-01-01T00:00:00Z",
"Pending": 0,
"NotCovered": 0,
"NotCoveredFast": 0,
"RestartNeeded": 0,
"RebootNeededSince": "0001-01-01T00:00:00Z",
"WrapperPassSeconds": 0
},
"Host": {
"ReleaseID": "",
"LastOutcome": "",
"LastAt": "0001-01-01T00:00:00Z",
"LastSuccessfulLeg": "0001-01-01T00:00:00Z",
"Pending": 0,
"NotCovered": 0,
"NotCoveredFast": 0,
"RestartNeeded": 0,
"RebootNeededSince": "0001-01-01T00:00:00Z",
"WrapperPassSeconds": 0
}
}
],
"latest_guest_release": {
"approved_at": "2026-10-04T12:39:33Z",
"approved_by": "auto",
"id": "os-guest-20261004-123933"
},
"latest_host_release": {
"approved_at": "2026-10-04T12:40:34Z",
"approved_by": "auto",
"id": "os-host-20261004-124034"
}
}
@@ -0,0 +1,172 @@
=== felhom-agent 0.141.1 selftest=os-update vmid=9201 ring=0 enabled=true guest-release=false host-release=false appliance=true ===
time=2026-10-04T13:52:57.534+02:00 level=INFO msg="osupdate: START" run=20261004T115257Z layer=guest vmid=9201 ring=0 trigger=debug enabled=true release=ring0-20261004T115257Z
time=2026-10-04T13:53:09.479+02:00 level=INFO msg="osupdate: wrapper" line="os-apply: START release=ring0-20261004T115257Z layer=guest:9201 lane=fast mode=apply select=pending-fast packages=0"
time=2026-10-04T13:53:09.479+02:00 level=INFO msg="osupdate: wrapper" line="os-apply: REPAIR configured=0 fixed=0"
time=2026-10-04T13:53:09.479+02:00 level=INFO msg="osupdate: wrapper" line="os-apply: PLAN upgrade=0 already=0 not-installed=0 from-snapshot=0"
time=2026-10-04T13:53:09.479+02:00 level=INFO msg="osupdate: wrapper" line="os-apply: DONE rc=0 seconds=0 upgraded=0 (nothing to do)"
time=2026-10-04T13:53:09.480+02:00 level=INFO msg="osupdate: DONE" run=20261004T115257Z layer=guest vmid=9201 ring=0 trigger=debug outcome=nothing healthy=true reason="" upgraded=0 pending=6 not_covered=6 restart_needed=0 reboot_needed=false wrapper_seconds=11.9
time=2026-10-04T13:53:09.491+02:00 level=INFO msg="osupdate: START" run=20261004T115257Z layer=host vmid=9201 ring=0 trigger=debug enabled=true release=ring0-20261004T115257Z
time=2026-10-04T13:53:19.927+02:00 level=INFO msg="osupdate: wrapper" line="os-apply: START release=ring0-20261004T115257Z layer=host lane=fast mode=apply select=pending-fast packages=0"
time=2026-10-04T13:53:19.927+02:00 level=INFO msg="osupdate: wrapper" line="os-apply: REPAIR configured=0 fixed=0"
time=2026-10-04T13:53:19.927+02:00 level=INFO msg="osupdate: wrapper" line="os-apply: PLAN upgrade=0 already=0 not-installed=0 from-snapshot=0"
time=2026-10-04T13:53:19.927+02:00 level=INFO msg="osupdate: wrapper" line="os-apply: DONE rc=0 seconds=0 upgraded=0 (nothing to do)"
time=2026-10-04T13:53:20.705+02:00 level=INFO msg="osupdate: DONE" run=20261004T115257Z layer=host vmid=9201 ring=0 trigger=debug outcome=nothing healthy=true reason="" upgraded=0 pending=80 not_covered=80 restart_needed=34 reboot_needed=true wrapper_seconds=10.4
--- os-update report (guest) ---
{
"health_reason": "",
"healthy": true,
"mode": "apply",
"not_covered": [
"docker-ce-cli",
"containerd.io",
"docker-ce",
"docker-buildx-plugin",
"docker-ce-rootless-extras",
"docker-compose-plugin"
],
"outcome": "nothing",
"pending": 6,
"reboot_needed": false,
"refused": null,
"release_id": "ring0-20261004T115257Z",
"restart_needed": null,
"ring": 0,
"run_id": "20261004T115257Z",
"upgraded": [],
"wrapper_seconds": 11.9
}
--- os-update report (host) ---
{
"health_reason": "",
"healthy": true,
"mode": "apply",
"not_covered": [
"frr",
"shim-signed-common",
"shim-unsigned",
"shim-helpers-amd64-signed",
"shim-signed",
"libradosstriper1",
"librgw2",
"ceph-common",
"librbd1",
"librados2",
"python3-cephfs",
"libcephfs2",
"python3-rgw",
"python3-rados",
"python3-ceph-argparse",
"python3-ceph-common",
"python3-rbd",
"ceph-fuse",
"chrony",
"libcorosync-common4",
"libcfg7",
"libcmap4",
"libcpg4",
"libknet1t64",
"libnozzle1t64",
"libquorum5",
"libvotequorum8",
"corosync",
"frr-pythontools",
"libjs-extjs",
"libnvpair3linux",
"libproxmox-acme-plugins",
"libproxmox-backup-qemu0",
"pve-qemu-kvm",
"libpve-notify-perl",
"libpve-cluster-api-perl",
"libpve-cluster-perl",
"pve-cluster",
"libpve-access-control",
"libpve-apiclient-perl",
"librados2-perl",
"proxmox-backup-client",
"proxmox-backup-file-restore",
"pve-manager",
"libproxmox-acme-perl",
"libpve-common-perl",
"libpve-guest-common-perl",
"qemu-server",
"libpve-storage-perl",
"pve-edk2-firmware-legacy",
"pve-edk2-firmware-ovmf",
"libpve-network-api-perl",
"libpve-network-perl",
"proxmox-firewall-data",
"pve-firewall",
"pve-container",
"pve-ha-manager",
"novnc-pve",
"proxmox-enterprise-support-keyring",
"proxmox-mini-journalreader",
"proxmox-widget-toolkit",
"pve-docs",
"pve-i18n",
"pve-xtermjs",
"pve-yew-mobile-i18n",
"pve-yew-mobile-gui",
"libuutil3linux",
"libzfs7linux",
"libzpool7linux",
"proxmox-first-boot",
"pve-firmware",
"proxmox-kernel-7.0.14-20-pve-signed",
"proxmox-kernel-7.0",
"proxmox-kernel-helper",
"pve-edk2-firmware-aarch64",
"pve-edk2-firmware",
"zfs-initramfs",
"zfsutils-linux",
"zfs-zed",
"tailscale"
],
"outcome": "nothing",
"pending": 80,
"reboot_needed": true,
"refused": null,
"release_id": "ring0-20261004T115257Z",
"restart_needed": [
"agetty",
"blkmapd",
"chronyd",
"cron",
"dbus-daemon",
"dmeventd",
"ksmtuned",
"lxc-monitord",
"lxc-start",
"lxcfs",
"pmxcfs",
"proxmox-firewal",
"pve-firewall",
"pve-ha-crm",
"pve-ha-lrm",
"pve-lxc-syscall",
"pvedaemon",
"pvedaemon worke",
"pvefw-logger",
"pveproxy",
"pveproxy worker",
"pvescheduler",
"pvestatd",
"qmeventd",
"rpcbind",
"rrdcached",
"smartd",
"spiceproxy",
"spiceproxy work",
"sshd",
"systemd-logind",
"systemd-udevd",
"watchdog-mux",
"zed"
],
"ring": 0,
"run_id": "20261004T115257Z",
"upgraded": [],
"wrapper_seconds": 10.4
}
pass took 23.2s
WALL_SECONDS=23.268350584
@@ -0,0 +1,125 @@
+ uname -r
7.0.2-6-pve
+ mokutil --sb-state
SecureBoot enabled
+ od -An -tx1 /sys/firmware/efi/efivars/SecureBoot-8be4df61-93ca-11d2-aa0d-00e098032b8c
+ head -1
06 00 00 00 01
+ ls /boot/vmlinuz-7.0.14-20-pve /boot/vmlinuz-7.0.2-6-pve
/boot/vmlinuz-7.0.14-20-pve
/boot/vmlinuz-7.0.2-6-pve
+ dpkg -l 'proxmox-kernel-*'
+ grep '^ii'
+ awk '{print $2,$3}'
proxmox-kernel-7.0 7.0.14-20
proxmox-kernel-7.0.14-20-pve-signed 7.0.14-20
proxmox-kernel-7.0.2-6-pve-signed 7.0.2-6
proxmox-kernel-helper 9.1.0+fde2
+ proxmox-boot-tool status
+ tail -5
Re-executing '/usr/sbin/proxmox-boot-tool' in new private mount namespace..
E: /etc/kernel/proxmox-boot-uuids does not exist.
+ grep -E '^GRUB_DEFAULT|^GRUB_TIMEOUT|^GRUB_SAVEDEFAULT' /etc/default/grub
GRUB_DEFAULT=0
GRUB_TIMEOUT=5
+ grub-editenv list
+ '[' -d /sys/firmware/efi ']'
+ efibootmgr
+ head -6
BootCurrent: 0003
Timeout: 0 seconds
BootOrder: 0003,0029,0001,0002,0006,0007,0019,001A,001B,001C,001D,001E,0008,0009,0016,0017,001F,0020,0021,0022,0023,0024,0025,0026,0027,0028,000A,0004,0005,000B
Boot0001* USB Floppy/CD VenMedia(b6fef66f-1495-4584-a836-3492d1984a8d,0500000001)0000424f
Boot0002* USB Hard Drive VenMedia(b6fef66f-1495-4584-a836-3492d1984a8d,0200000001)0000424f
Boot0003* proxmox HD(2,GPT,175383fb-546d-430e-9b4c-73ec2379169d,0x800,0x200000)/File(\EFI\proxmox\shimx64.efi)
+ sysctl kernel.panic kernel.panic_on_oops
kernel.panic = 0
kernel.panic_on_oops = 0
+ lsmod
+ grep -i -E 'sp5100|wdt|watchdog'
+ ls -l /dev/watchdog /dev/watchdog0
crw------- 1 root root 10, 130 Oct 4 09:46 /dev/watchdog
crw------- 1 root root 243, 0 Oct 4 09:46 /dev/watchdog0
+ wdctl
+ head -12
Device: /dev/watchdog0
Identity: Software Watchdog [version 0]
Timeout: 10 seconds
Timeleft: 9 seconds
Pre-timeout: 0 seconds
Pre-timeout governor: noop
Available pre-timeout governors: noop
FLAG DESCRIPTION STATUS BOOT-STATUS
KEEPALIVEPING Keep alive ping reply 1 0
MAGICCLOSE Supports magic close char 0 0
PRETIMEOUT Pretimeout (in seconds) 0 0
SETTIMEOUT Set timeout (in seconds) 0 0
+ dmesg
+ grep -i -E 'sp5100|watchdog'
+ tail -5
[ 0.353227] NMI watchdog: Enabled. Permanently consumes one hw-PMU counter.
+ apt-cache policy proxmox-default-kernel
+ head -4
proxmox-default-kernel:
Installed: 2.1.0
Candidate: 2.1.0
Version table:
+ apt-cache search --names-only '^proxmox-kernel-[0-9.]+-[0-9]+-pve-signed$'
+ sort -V
+ tail -3
proxmox-kernel-7.0.14-18-pve-signed - Proxmox Kernel Image (signed)
proxmox-kernel-7.0.14-19-pve-signed - Proxmox Kernel Image (signed)
proxmox-kernel-7.0.14-20-pve-signed - Proxmox Kernel Image (signed)
+ cat /proc/cmdline
BOOT_IMAGE=/boot/vmlinuz-7.0.2-6-pve root=/dev/mapper/pve-root ro quiet
+ grep -nE '^menuentry|^submenu|^\s+menuentry' /boot/grub/grub.cfg
+ cut -c1-140
+ head -8
26: menuentry_id_option="--id"
28: menuentry_id_option=""
110:menuentry 'Proxmox VE GNU/Linux' --class proxmox --class gnu-linux --class gnu --class os $menuentry_id_option 'gnulinux-simple-529c0c3d
128:submenu 'Advanced options for Proxmox VE GNU/Linux' $menuentry_id_option 'gnulinux-advanced-529c0c3d-b48e-4d01-989d-43fd5d7dbb43' {
129: menuentry 'Proxmox VE GNU/Linux, with Linux 7.0.14-20-pve' --class proxmox --class gnu-linux --class gnu --class os $menuentry_id_optio
147: menuentry 'Proxmox VE GNU/Linux, with Linux 7.0.14-20-pve (recovery mode)' --class proxmox --class gnu-linux --class gnu --class os $me
165: menuentry 'Proxmox VE GNU/Linux, with Linux 7.0.2-6-pve' --class proxmox --class gnu-linux --class gnu --class os $menuentry_id_option
183: menuentry 'Proxmox VE GNU/Linux, with Linux 7.0.2-6-pve (recovery mode)' --class proxmox --class gnu-linux --class gnu --class os $menu
+ ls -l --time-style=+%F_%T /boot/grub/grub.cfg
-rw------- 1 root root 13743 2026-10-04_09:47:05 /boot/grub/grub.cfg
+ uptime -s
2026-10-04 09:46:15
+ last -x reboot
+ head -4
reboot system boot 7.0.2-6-pve Sun Oct 4 09:46 - still running
reboot system boot 7.0.14-20-pve Sun Oct 4 09:44 - 09:45 (00:00)
shutdown system down 7.0.14-20-pve Sun Oct 4 09:45 - 09:46 (00:00)
reboot system boot 7.0.2-6-pve Fri Aug 21 17:44 - 09:43 (43+15:58)
+ ls /boot/efi/EFI/proxmox/
BOOTX64.CSV
fbx64.efi
grub.cfg
grubx64.efi
mmx64.efi
shimx64.efi
+ cat /boot/efi/EFI/proxmox/grub.cfg
+ head -5
search.fs_uuid 529c0c3d-b48e-4d01-989d-43fd5d7dbb43 root lvmid/zVqGDa-V6js-HB26-RyZr-d0ft-fUB3-blL75R/iAs9TN-W8rL-ViG8-jptz-1tcY-3djE-MRqamk
set prefix=($root)'/boot/grub'
configfile $prefix/grub.cfg
+ lspci -nn
+ grep -i -E 'smbus|fch'
00:14.0 SMBus [0c05]: Advanced Micro Devices, Inc. [AMD] FCH SMBus Controller [1022:790b] (rev 61)
00:14.3 ISA bridge [0601]: Advanced Micro Devices, Inc. [AMD] FCH LPC Bridge [1022:790e] (rev 51)
06:00.0 SATA controller [0106]: Advanced Micro Devices, Inc. [AMD] FCH SATA Controller [AHCI mode] [1022:7901] (rev 61)
+ modinfo -F filename sp5100_tco
/lib/modules/7.0.2-6-pve/kernel/drivers/watchdog/sp5100_tco.ko
+ grep -rl sp5100 /lib/modprobe.d /etc/modprobe.d
/lib/modprobe.d/blacklist_proxmox-kernel-7.0.14-20-pve.conf
/lib/modprobe.d/blacklist_proxmox-kernel-7.0.2-6-pve.conf
+ grep -h sp5100 /lib/modprobe.d/aliases.conf /lib/modprobe.d/blacklist_proxmox-kernel-7.0.14-20-pve.conf /lib/modprobe.d/blacklist_proxmox-kernel-7.0.2-6-pve.conf /lib/modprobe.d/fbdev-blacklist.conf /lib/modprobe.d/proxmox_prevent_autoload_proxmox-kernel-7.0.14-20-pve.conf /lib/modprobe.d/proxmox_prevent_autoload_proxmox-kernel-7.0.2-6-pve.conf /lib/modprobe.d/systemd.conf /etc/modprobe.d/amd64-microcode-blacklist.conf /etc/modprobe.d/pve-blacklist.conf /etc/modprobe.d/zfs.conf
+ head -3
blacklist sp5100_tco
blacklist sp5100_tco
+ modprobe -n -v sp5100_tco
insmod /lib/modules/7.0.2-6-pve/kernel/drivers/watchdog/sp5100_tco.ko
+ ls /sys/class/watchdog/
watchdog0
@@ -0,0 +1,20 @@
+ findmnt -no SOURCE,FSTYPE --target /boot
/dev/mapper/pve-root ext4
+ ls -l /boot/grub/grubenv
-rw-r--r-- 1 root root 1024 Oct 4 09:46 /boot/grub/grubenv
+ cp -p /etc/default/grub /root/grub.default.bak-2026-10-04
+ sed -i 's/^GRUB_DEFAULT=0$/GRUB_DEFAULT=saved/' /etc/default/grub
+ grep '^GRUB_DEFAULT' /etc/default/grub
GRUB_DEFAULT=saved
+ update-grub
+ tail -3
Found memtest86+ 32bit image: /boot/memtest86+ia32.bin
Adding boot menu entry for UEFI Firmware Settings ...
done
+ grub-set-default 'gnulinux-advanced-529c0c3d-b48e-4d01-989d-43fd5d7dbb43>gnulinux-7.0.2-6-pve-advanced-529c0c3d-b48e-4d01-989d-43fd5d7dbb43'
+ grub-editenv list
saved_entry=gnulinux-advanced-529c0c3d-b48e-4d01-989d-43fd5d7dbb43>gnulinux-7.0.2-6-pve-advanced-529c0c3d-b48e-4d01-989d-43fd5d7dbb43
+ grep -n 'set default' /boot/grub/grub.cfg
+ head -4
17: set default="${next_entry}"
22: set default="${saved_entry}"
@@ -0,0 +1,14 @@
+ grub-reboot 'gnulinux-advanced-529c0c3d-b48e-4d01-989d-43fd5d7dbb43>gnulinux-7.0.14-20-pve-advanced-529c0c3d-b48e-4d01-989d-43fd5d7dbb43'
WARNING: Detected GRUB environment block on lvm device
gnulinux-advanced-529c0c3d-b48e-4d01-989d-43fd5d7dbb43>gnulinux-7.0.14-20-pve-advanced-529c0c3d-b48e-4d01-989d-43fd5d7dbb43 will remain the default boot entry until manually cleared with:
grub-editenv /boot/grub/grubenv unset next_entry
+ grub-editenv list
saved_entry=gnulinux-advanced-529c0c3d-b48e-4d01-989d-43fd5d7dbb43>gnulinux-7.0.2-6-pve-advanced-529c0c3d-b48e-4d01-989d-43fd5d7dbb43
next_entry=gnulinux-advanced-529c0c3d-b48e-4d01-989d-43fd5d7dbb43>gnulinux-7.0.14-20-pve-advanced-529c0c3d-b48e-4d01-989d-43fd5d7dbb43
+ uname -r
7.0.2-6-pve
+ date -u +%FT%TZ
2026-10-04T12:26:10Z
reboot1 issued 2026-10-04T12:26:10Z
@@ -0,0 +1,19 @@
+ uname -r
7.0.14-20-pve
+ uptime -s
2026-10-04 14:27:03
+ mokutil --sb-state
SecureBoot enabled
+ grub-editenv list
saved_entry=gnulinux-advanced-529c0c3d-b48e-4d01-989d-43fd5d7dbb43>gnulinux-7.0.2-6-pve-advanced-529c0c3d-b48e-4d01-989d-43fd5d7dbb43
next_entry=gnulinux-advanced-529c0c3d-b48e-4d01-989d-43fd5d7dbb43>gnulinux-7.0.14-20-pve-advanced-529c0c3d-b48e-4d01-989d-43fd5d7dbb43
+ cat /proc/cmdline
BOOT_IMAGE=/boot/vmlinuz-7.0.14-20-pve root=/dev/mapper/pve-root ro quiet
active
active
active
active
active
status: running
starting
starting
@@ -0,0 +1,33 @@
reboot2 issued 2026-10-04T12:35:19Z, no grub command; grubenv as after reboot 1
ssh back after ~40s
System is going down. Unprivileged users are not permitted to log in anymore. For technical details, see pam_nologin(8).
+ uname -r
7.0.14-20-pve
+ uptime -s
2026-10-04 14:27:03
+ grub-editenv list
saved_entry=gnulinux-advanced-529c0c3d-b48e-4d01-989d-43fd5d7dbb43>gnulinux-7.0.2-6-pve-advanced-529c0c3d-b48e-4d01-989d-43fd5d7dbb43
next_entry=gnulinux-advanced-529c0c3d-b48e-4d01-989d-43fd5d7dbb43>gnulinux-7.0.14-20-pve-advanced-529c0c3d-b48e-4d01-989d-43fd5d7dbb43
+ cat /proc/cmdline
BOOT_IMAGE=/boot/vmlinuz-7.0.14-20-pve root=/dev/mapper/pve-root ro quiet
--- after the real restart, 2026-10-04T12:36:27Z
+ uname -r
7.0.14-20-pve
+ uptime -s
2026-10-04 14:36:11
+ mokutil --sb-state
SecureBoot enabled
+ grub-editenv list
saved_entry=gnulinux-advanced-529c0c3d-b48e-4d01-989d-43fd5d7dbb43>gnulinux-7.0.2-6-pve-advanced-529c0c3d-b48e-4d01-989d-43fd5d7dbb43
next_entry=gnulinux-advanced-529c0c3d-b48e-4d01-989d-43fd5d7dbb43>gnulinux-7.0.14-20-pve-advanced-529c0c3d-b48e-4d01-989d-43fd5d7dbb43
+ cat /proc/cmdline
BOOT_IMAGE=/boot/vmlinuz-7.0.14-20-pve root=/dev/mapper/pve-root ro quiet
+ systemctl is-active pveproxy pvedaemon pvestatd pve-cluster felhom-agent
activating
active
active
active
inactive
+ pct status 9201
status: stopped
@@ -0,0 +1,27 @@
+ grub-editenv /boot/grub/grubenv unset next_entry
+ grub-set-default 'gnulinux-advanced-529c0c3d-b48e-4d01-989d-43fd5d7dbb43>gnulinux-7.0.14-20-pve-advanced-529c0c3d-b48e-4d01-989d-43fd5d7dbb43'
+ grub-editenv list
saved_entry=gnulinux-advanced-529c0c3d-b48e-4d01-989d-43fd5d7dbb43>gnulinux-7.0.14-20-pve-advanced-529c0c3d-b48e-4d01-989d-43fd5d7dbb43
+ grep '^GRUB_DEFAULT' /etc/default/grub
GRUB_DEFAULT=saved
+ dpkg -l 'proxmox-kernel-*-pve-signed'
+ awk '{print $2}'
+ grep '^ii'
proxmox-kernel-7.0.14-20-pve-signed
proxmox-kernel-7.0.2-6-pve-signed
+ uname -r
7.0.14-20-pve
+ systemctl is-active pveproxy pvedaemon pvestatd pve-cluster felhom-agent
active
active
active
active
active
+ pct status 9201
status: running
+ sleep 45
+ pct exec 9201 -- docker inspect -f '{{.Name}} {{.State.Health.Status}}' cloudflared felhom-controller
/cloudflared healthy
/felhom-controller healthy
+ sysctl kernel.panic
kernel.panic = 0
@@ -0,0 +1,74 @@
+ modprobe sp5100_tco
rc=0
+ echo rc=0
+ lsmod
+ grep sp5100
sp5100_tco 20480 0
+ dmesg
+ grep -i sp5100
+ tail -5
[ 85.993589] sp5100_tco: SP5100/SB800 TCO WatchDog Timer Driver
[ 85.993780] sp5100-tco sp5100-tco: Using 0xfeb00000 for watchdog MMIO address
[ 85.993918] sp5100-tco sp5100-tco: initialized. heartbeat=60 sec (nowayout=0)
== /sys/class/watchdog/watchdog0
+ for w in /sys/class/watchdog/watchdog*
+ echo '== /sys/class/watchdog/watchdog0'
+ for f in identity state timeout nowayout bootstatus status
++ cat /sys/class/watchdog/watchdog0/identity
identity=Software Watchdog
+ printf '%s=%s\n' identity 'Software Watchdog'
+ for f in identity state timeout nowayout bootstatus status
++ cat /sys/class/watchdog/watchdog0/state
state=active
+ printf '%s=%s\n' state active
+ for f in identity state timeout nowayout bootstatus status
++ cat /sys/class/watchdog/watchdog0/timeout
timeout=10
+ printf '%s=%s\n' timeout 10
+ for f in identity state timeout nowayout bootstatus status
++ cat /sys/class/watchdog/watchdog0/nowayout
nowayout=0
+ printf '%s=%s\n' nowayout 0
+ for f in identity state timeout nowayout bootstatus status
++ cat /sys/class/watchdog/watchdog0/bootstatus
bootstatus=0
+ printf '%s=%s\n' bootstatus 0
+ for f in identity state timeout nowayout bootstatus status
++ cat /sys/class/watchdog/watchdog0/status
status=0x8000
== /sys/class/watchdog/watchdog1
+ printf '%s=%s\n' status 0x8000
+ for w in /sys/class/watchdog/watchdog*
+ echo '== /sys/class/watchdog/watchdog1'
+ for f in identity state timeout nowayout bootstatus status
++ cat /sys/class/watchdog/watchdog1/identity
identity=SP5100 TCO timer
+ printf '%s=%s\n' identity 'SP5100 TCO timer'
+ for f in identity state timeout nowayout bootstatus status
++ cat /sys/class/watchdog/watchdog1/state
state=inactive
+ printf '%s=%s\n' state inactive
+ for f in identity state timeout nowayout bootstatus status
++ cat /sys/class/watchdog/watchdog1/timeout
timeout=60
+ printf '%s=%s\n' timeout 60
+ for f in identity state timeout nowayout bootstatus status
++ cat /sys/class/watchdog/watchdog1/nowayout
nowayout=0
+ printf '%s=%s\n' nowayout 0
+ for f in identity state timeout nowayout bootstatus status
++ cat /sys/class/watchdog/watchdog1/bootstatus
bootstatus=0
+ printf '%s=%s\n' bootstatus 0
+ for f in identity state timeout nowayout bootstatus status
++ cat /sys/class/watchdog/watchdog1/status
status=0x0
+ printf '%s=%s\n' status 0x0
+ rmmod sp5100_tco
rmmod_rc=0
+ echo rmmod_rc=0
+ lsmod
+ grep -c sp5100
0
+ ls /sys/class/watchdog/
watchdog0
@@ -1,2 +1,4 @@
demo-felhom wrapper 4729769ce32e25e6 755 root; sudoers 02df92d751f1780a
demo-hp wrapper 4729769ce32e25e6 755 root; sudoers 02df92d751f1780a
demo-felhom wrapper 51e100ad81945f67
demo-hp wrapper 51e100ad81945f67