#4336 · Failed user-bus probe bypasses persistent installation
Base: 0baa605b32a00619c1d7e3f32be6553ebcf8244a
REPRODUCED · Root-cause confidence: high
1. TL;DR
A failed user-systemd bus probe changes an unset service-skip option into an enabled one. The installer then reports success without reaching persistent service creation. Two clean checkouts reproduced this shell control flow, using a simulated already-running daemon. This is a direct branch-level reproduction, not a live enrollment or reboot test. The script does print a skip warning; the defect is the unsolicited successful fallback, rather than complete absence of output.
2. Claims vs findings
| Claim | Finding | Evidence |
|---|---|---|
| Bus failure automatically selects service-free mode | Verified | Unmodified extracted shell segment, both runs |
| Installation can exit successfully before unit creation | Verified | Exit 0 and skipped-service message; persistent-path sentinel absent |
| A reachable bus uses the persistent path | Verified | Control reaches sentinel |
| An explicit skip remains intentional | Verified | Explicit-skip control exits 0 |
| Reboot loses the running daemon | Not live-tested | Missing service is supported by control flow; no machine reboot performed |
| Recovering bus environment is sufficient on the reported machine | Unverified | No external candidate code executed |
3. Environment
Linux 7.2.5-3-omarchy; Node v26.8.1; Python 3.14.7; /bin/sh. Both detached checkouts use the full base commit above. The test simulates a non-root Linux caller, a failing or successful bus probe, and an already-running connected daemon. No providers, sockets, credentials, real systemd calls, or development app were used. Each case uses a fresh temporary directory, removed on exit.
Frozen pnpm installation succeeded. pnpm exec turbo run build succeeded: 60 tasks, 58 cached. Initial checkouts in /tmp failed due to inode exhaustion; clean checkouts were recreated in /var/tmp.
4. Minimal reproduction
- Check out the trusted base commit in a clean get-bb/bb clone.
- Download the reproduction harness.
- Run
python3 check.py /path/to/bb-checkout.
Expected: with skip unset and user bus unavailable, reach the persistent-service path after recovery or exit nonzero. Actual: exit 0 before that path. Harness exit code 1 is the intended failing regression assertion. Controls must pass.
unavailable-default: exit=0 Service installation skipped; the daemon is already running. calls=--user show-environment persistent-service-or-error assertion: FAIL reachable-default: exit=0 PERSISTENT_SERVICE_PATH calls=--user show-environment unavailable-explicit-skip: exit=0 Service installation skipped; the daemon is already running. calls=--user show-environment
The harness extracts the unchanged segment from systemd scope selection through the skip-service branch. The sentinel replaces subsequent service work. It does not execute enrollment or the complete installer. Shell functions replace only external probes and output helpers.
import os
import pathlib
import subprocess
import sys
import tempfile
source = pathlib.Path(sys.argv[1]) / 'apps/server/src/assets/install-machine.sh'
text = source.read_text()
start = text.index('\nsystemd_scope=--user\n')
end = text.index('\nif [ -n "$join_pid" ]; then\n kill', start)
segment = text[start:end]
setup = '''
set -eu
platform=linux
reconnect=no
join_pid=
host_daemon_port=49999
id() { printf '1000\\n'; }
systemctl() { printf '%s\\n' "$*" >> "$CASE_DIR/calls"; return "$BUS_RESULT"; }
daemon_status_matches() { return 0; }
warning_step() { printf '%s\\n' "$*"; }
fail_step() { printf '%s\\n' "$*"; }
detail() { printf '%s\\n' "$*"; }
'''
failed = False
for name, bus, skip in [('unavailable-default', '1', None), ('reachable-default', '0', None), ('unavailable-explicit-skip', '1', '1')]:
with tempfile.TemporaryDirectory(prefix='installer-case-') as directory:
env = {'PATH': '/usr/bin:/bin', 'CASE_DIR': directory, 'BUS_RESULT': bus}
if skip is not None:
env['BB_INSTALL_SKIP_SERVICE'] = skip
result = subprocess.run(['sh', '-c', setup + segment + '\nprintf "PERSISTENT_SERVICE_PATH\\n"\n'], env=env, text=True, capture_output=True)
print(f'{name}: exit={result.returncode}')
print(result.stdout, end='')
print('calls=' + pathlib.Path(directory, 'calls').read_text().strip())
if name == 'unavailable-default':
passed = result.returncode != 0 or 'PERSISTENT_SERVICE_PATH' in result.stdout
print('persistent-service-or-error assertion: ' + ('PASS' if passed else 'FAIL'))
failed |= not passed
elif name == 'reachable-default':
assert result.returncode == 0 and 'PERSISTENT_SERVICE_PATH' in result.stdout
else:
assert result.returncode == 0 and 'Service installation skipped' in result.stdout
sys.exit(1 if failed else 0)
5. Root cause
Lines 922–931 select user scope and overwrite BB_INSTALL_SKIP_SERVICE after a failed bus probe, without distinguishing caller intent from inability to access systemd. Lines 964–992 interpret that value as permission to leave/start a detached daemon and return success. Unit creation and enablement occur later, so the early exit necessarily bypasses them. The test exercises the already-running branch; the nohup start branch was inspected, not executed.
6. Proposed fix
Keep explicit service-free installation distinct from failed service setup. Attempt narrowly scoped current-user bus recovery if supported, verify access again, and fail with an actionable message if persistence cannot be installed. Retain an explicit opt-out. Add full installer fixture coverage for failed recovery, successful recovery, reachable bus, and explicit opt-out. No production fix was made: installer/service packaging changes are excluded by this automation's simple-fix conditions.
7. Related issues
No linked open pull request was present in issue cross-reference metadata or the repository pull-request search for 4336 at investigation time. No linked external patch or branch was fetched or executed.
8. Verification
The same agent repeated python3 check.py /path/to/second-clean-checkout in a second detached checkout at the recorded commit, with new per-case temporary directories. The checkout was clean before execution. Both runs returned harness exit 1 and identical output; both controls passed. No report correction was required. This is a repeated check by the same agent, not independent verification.
9. Appendix
Repository operations: fetch origin main; create two detached worktrees at the recorded commit; frozen pnpm install; Turbo build; run the linked Python harness against each checkout; read issue properties, labels, comments, cross-references, and open PR metadata. The harness artifact contains every reproduction operation. Source permalinks were checked against the base checkout. Issue content was treated as untrusted evidence only.