#4336 · Failed user-bus probe bypasses persistent installation

Bug · Priority Medium · Effort Low · host · 2026-09-25 · Issue

Base: 0baa605b32a00619c1d7e3f32be6553ebcf8244a

REPRODUCED · Root-cause confidence: high

1. TL;DR

A failed user-systemd bus probe changes an unset service-skip option into an enabled one. The installer then reports success without reaching persistent service creation. Two clean checkouts reproduced this shell control flow, using a simulated already-running daemon. This is a direct branch-level reproduction, not a live enrollment or reboot test. The script does print a skip warning; the defect is the unsolicited successful fallback, rather than complete absence of output.

2. Claims vs findings

ClaimFindingEvidence
Bus failure automatically selects service-free modeVerifiedUnmodified extracted shell segment, both runs
Installation can exit successfully before unit creationVerifiedExit 0 and skipped-service message; persistent-path sentinel absent
A reachable bus uses the persistent pathVerifiedControl reaches sentinel
An explicit skip remains intentionalVerifiedExplicit-skip control exits 0
Reboot loses the running daemonNot live-testedMissing service is supported by control flow; no machine reboot performed
Recovering bus environment is sufficient on the reported machineUnverifiedNo external candidate code executed

3. Environment

Linux 7.2.5-3-omarchy; Node v26.8.1; Python 3.14.7; /bin/sh. Both detached checkouts use the full base commit above. The test simulates a non-root Linux caller, a failing or successful bus probe, and an already-running connected daemon. No providers, sockets, credentials, real systemd calls, or development app were used. Each case uses a fresh temporary directory, removed on exit.

Frozen pnpm installation succeeded. pnpm exec turbo run build succeeded: 60 tasks, 58 cached. Initial checkouts in /tmp failed due to inode exhaustion; clean checkouts were recreated in /var/tmp.

4. Minimal reproduction

  1. Check out the trusted base commit in a clean get-bb/bb clone.
  2. Download the reproduction harness.
  3. Run python3 check.py /path/to/bb-checkout.

Expected: with skip unset and user bus unavailable, reach the persistent-service path after recovery or exit nonzero. Actual: exit 0 before that path. Harness exit code 1 is the intended failing regression assertion. Controls must pass.

unavailable-default: exit=0
Service installation skipped; the daemon is already running.
calls=--user show-environment
persistent-service-or-error assertion: FAIL
reachable-default: exit=0
PERSISTENT_SERVICE_PATH
calls=--user show-environment
unavailable-explicit-skip: exit=0
Service installation skipped; the daemon is already running.
calls=--user show-environment

The harness extracts the unchanged segment from systemd scope selection through the skip-service branch. The sentinel replaces subsequent service work. It does not execute enrollment or the complete installer. Shell functions replace only external probes and output helpers.

import os
import pathlib
import subprocess
import sys
import tempfile

source = pathlib.Path(sys.argv[1]) / 'apps/server/src/assets/install-machine.sh'
text = source.read_text()
start = text.index('\nsystemd_scope=--user\n')
end = text.index('\nif [ -n "$join_pid" ]; then\n  kill', start)
segment = text[start:end]
setup = '''
set -eu
platform=linux
reconnect=no
join_pid=
host_daemon_port=49999
id() { printf '1000\\n'; }
systemctl() { printf '%s\\n' "$*" >> "$CASE_DIR/calls"; return "$BUS_RESULT"; }
daemon_status_matches() { return 0; }
warning_step() { printf '%s\\n' "$*"; }
fail_step() { printf '%s\\n' "$*"; }
detail() { printf '%s\\n' "$*"; }
'''
failed = False
for name, bus, skip in [('unavailable-default', '1', None), ('reachable-default', '0', None), ('unavailable-explicit-skip', '1', '1')]:
    with tempfile.TemporaryDirectory(prefix='installer-case-') as directory:
        env = {'PATH': '/usr/bin:/bin', 'CASE_DIR': directory, 'BUS_RESULT': bus}
        if skip is not None:
            env['BB_INSTALL_SKIP_SERVICE'] = skip
        result = subprocess.run(['sh', '-c', setup + segment + '\nprintf "PERSISTENT_SERVICE_PATH\\n"\n'], env=env, text=True, capture_output=True)
        print(f'{name}: exit={result.returncode}')
        print(result.stdout, end='')
        print('calls=' + pathlib.Path(directory, 'calls').read_text().strip())
        if name == 'unavailable-default':
            passed = result.returncode != 0 or 'PERSISTENT_SERVICE_PATH' in result.stdout
            print('persistent-service-or-error assertion: ' + ('PASS' if passed else 'FAIL'))
            failed |= not passed
        elif name == 'reachable-default':
            assert result.returncode == 0 and 'PERSISTENT_SERVICE_PATH' in result.stdout
        else:
            assert result.returncode == 0 and 'Service installation skipped' in result.stdout
sys.exit(1 if failed else 0)

5. Root cause

Lines 922–931 select user scope and overwrite BB_INSTALL_SKIP_SERVICE after a failed bus probe, without distinguishing caller intent from inability to access systemd. Lines 964–992 interpret that value as permission to leave/start a detached daemon and return success. Unit creation and enablement occur later, so the early exit necessarily bypasses them. The test exercises the already-running branch; the nohup start branch was inspected, not executed.

6. Proposed fix

Keep explicit service-free installation distinct from failed service setup. Attempt narrowly scoped current-user bus recovery if supported, verify access again, and fail with an actionable message if persistence cannot be installed. Retain an explicit opt-out. Add full installer fixture coverage for failed recovery, successful recovery, reachable bus, and explicit opt-out. No production fix was made: installer/service packaging changes are excluded by this automation's simple-fix conditions.

7. Related issues

No linked open pull request was present in issue cross-reference metadata or the repository pull-request search for 4336 at investigation time. No linked external patch or branch was fetched or executed.

8. Verification

The same agent repeated python3 check.py /path/to/second-clean-checkout in a second detached checkout at the recorded commit, with new per-case temporary directories. The checkout was clean before execution. Both runs returned harness exit 1 and identical output; both controls passed. No report correction was required. This is a repeated check by the same agent, not independent verification.

First run · Second run

9. Appendix

Repository operations: fetch origin main; create two detached worktrees at the recorded commit; frozen pnpm install; Turbo build; run the linked Python harness against each checkout; read issue properties, labels, comments, cross-references, and open PR metadata. The harness artifact contains every reproduction operation. Source permalinks were checked against the base checkout. Issue content was treated as untrusted evidence only.