* Run OVA build and tests for Renovate OS bumps
Add a workflow that calls build.yaml to build the OVA image and run the
tests for same-repo PRs labeled run-ova-test. Renovate adds the label to
kernel, OS Agent and tempio bumps.
Pass build.yaml inputs to scripts through environment variables so a
caller's input can't inject code into the scripts. Fail on an unknown
release channel.
* Don't inherit secrets for PR build
This will generate a self-signed RAUC bundle, which is not an issue as
it's not used in the tests.
Change default titles of Renovate bumps to "Update tempio to ..." for
tempio and "Tests: update <dep> to ..." for dependencies in tests, so it
matches patterns we used previously.
Set rebaseWhen to never for the mainline kernel group. Renovate then
leaves an open kernel PR at its version and does not move it to a
newer release. The next PR opens once the open one is merged.
The kernel.org datasource lists only the latest release of each
series. When a PR from 6.18.53 to 6.18.54 is moved to 6.18.55, the
notes can link only the 6.18.55 changelog, and the 6.18.54 one is
lost. A single release per bump also makes it easier to bisect
regressions.
Renovate shortens the version to the major number for major updates.
A bump of tempio to 2026.07.0 got the title "Update dependency
home-assistant/tempio to v2026". Use Renovate's default
commitMessageExtra without its isMajor branch so the commit subject
and PR title always name the full version.
* Add release note links to Renovate commit messages
Put the kernel ChangeLog link and the OS Agent release links in the
commit body, as in the manual updates. For OS Agent, list every
release included in the bump.
* List release notes also for tempio and labgrid
* Move dependency updates from Dependabot to Renovate
* Keep GitHub Actions pinned to commit SHAs
* Track tempio and the XenServer guest utilities
* Apply batched suggestions from code review
Co-authored-by: Jan Čermák <sairon@users.noreply.github.com>
---------
Co-authored-by: Stefan Agner <stefan@agner.ch>
Co-authored-by: Jan Čermák <sairon@users.noreply.github.com>
* Refill boot tries before slot selection in U-Boot scripts
When no slot had tries left, the boot scripts reset both counters to 3,
stored the env and rebooted right away. On USB disks the write can sit
in the drive's cache. U-Boot never flushes it and the RPi bootloader
cuts USB power on reboot. The write is lost and the board loops
forever.
Refill the counters before the slot loop instead, so the board boots in
the same pass. The branch after the loop now only stores the
decremented counters and resets. This replaces the ODROID-N2 approach
from #4832, which kept the store and reset.
Fixes#4886
* Re-add slots dropped from BOOT_ORDER when refilling tries
RAUC removes a slot from BOOT_ORDER when it marks it bad. If the
remaining slot then used up all its tries, the refill only retried that
slot and never the other one. Append any missing slot to BOOT_ORDER when
refilling, keeping the current order so the preferred slot is still
tried first.
Global data deduplication in mkfs.erofs is hit by an upstream bug [1].
Drop BR2_TARGET_ROOTFS_EROFS_DEDUPE from all defconfigs until it is
fixed. Rootfs images may get slightly larger, but we should have enough
headroom now.
[1] https://github.com/erofs/erofs-utils/issues/57
The USB/SATA bridge in the Argon ONE M.2 case is reported to hang in UAS
mode under heavier writes, freezing the system. Forcing it to use
usb-storage instead resolves the issue.
Fixes#5049
Since 6.18.53, btrtl driver is used for binding RTL8761CU, requiring the
firmware as well. Add it to BR2_PACKAGE_LINUX_FIRMWARE_RTL_87XX_BT
symbol.
* buildroot d2b75e0548...8c39950771 (1):
> package/linux-firmware: add RTL8761CU Bluetooth firmware
Needs #5046, fixes#5026
This release makes the agent only load AppArmor profiles whose name
matches the profile file name. Profiles are enumerated with
`apparmor_parser --names` before load/unload, and any profile which is
not the file's base name or a child profile/hat of it is rejected. This
prevents an add-on supplied apparmor.txt from redefining unrelated
profiles such as docker-default or hassio-supervisor.
Full changelog:
* https://github.com/home-assistant/os-agent/releases/tag/1.14.0
Co-authored-by: Claude Fable 5.1 <noreply@anthropic.com>
(cherry picked from commit d049a3159b)
This release makes the agent only load AppArmor profiles whose name
matches the profile file name. Profiles are enumerated with
`apparmor_parser --names` before load/unload, and any profile which is
not the file's base name or a child profile/hat of it is rejected. This
prevents an add-on supplied apparmor.txt from redefining unrelated
profiles such as docker-default or hassio-supervisor.
Full changelog:
* https://github.com/home-assistant/os-agent/releases/tag/1.14.0
Co-authored-by: Claude Fable 5.1 <noreply@anthropic.com>
* buildroot 5035249eae...2af73e052f (3):
> package/go: bump to version 1.26.8
> package/go: security bump to version 1.26.6
> package/go: decrease debug level for CGO linking
containerd fsyncs its metadata database when committing a snapshot, but
never syncs the unpacked layer data itself. On an unclean shutdown
within the writeback window after an image pull this leaves layers with
zero-byte files (correct names/modes/mtimes, no data) while the
snapshot stays durably recorded as valid. Because existing snapshots
are never re-verified or re-unpacked, such corruption even survives
deleting and re-pulling the image, and with shared base layers it can
only be recovered by wiping the Docker storage entirely.
This is the failure signature behind a growing number of reports of
broken plugins/add-ons/Core after power loss (e.g. 0-byte coredns in
home-assistant/plugin-dns#207, supervisor#6476/#6835, #4913).
Enable the containerd diff-service sync_fs option (containerd >= 2.0,
containerd/containerd#10284): the daemon then issues one syncfs(2) per
applied layer, making unpacked data as durable as the metadata that
references it. It applies to all clients of the daemon, including
dockerd with the containerd image store.
Verified in QEMU on haos 18.3.dev (Docker 29.6.2, containerd 2.2.6):
* With completely stock settings, a power cut <1s after `docker pull`
of the DNS plugin image corrupts the image 2 out of 2 runs: one run
zeroed /usr/bin/coredns entirely, the other zeroed the s6 scripts
and left coredns truncated (20021248 of 25919650 bytes) - matching
the two damage profiles reported in plugin-dns#207.
* Deterministic A/B with kernel background writeback suppressed, so
survival can only come from the stack syncing explicitly: without
this option 1215 zero-byte files including a 0-byte coredns failing
with "exec format error"; with sync_fs the image survives intact
(152 kB dirty at the power cut vs 76 MB).
* strace on containerd confirms 0 syncfs calls per image load before,
one per layer after - which also confirms dockerd pulls route
through the containerd daemon's diff service where this option
takes effect.
* Cost of loading+unpacking the 2 GB Core image: 41.6s -> 42.2s on a
fast disk, 226s -> 230s (+1.9%) on a 30 MB/s / 250 IOPS throttled
disk. Note QEMU throttling does not model SD-card sync latency, so
the real-world cost on the slowest cards may be somewhat higher, but
it stays bounded at one syncfs per layer.
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
The persistent timesyncd configuration is a single bind-mounted file
over /etc/systemd/timesyncd.conf. The NTP configuration through OS Agent
(home-assistant/os-agent#207) attempted to do atomic updates, but a
temporary file cannot be created next to it in the read-only
/etc/systemd, and replacing the file in the overlay directly changes the
inode, so the bind mount keeps pointing to the old content. Also, a
persisted copy of the whole file means changes to the shipped defaults
never reach existing installations.
Bind-mount the /etc/systemd/timesyncd.conf.d directory from the overlay
instead and keep the shipped timesyncd.conf read-only. Configuration is
layered as drop-ins, from lowest priority to higher:
* 10-ntp.conf (in /run): NTP servers from DHCP
* 20-custom.conf: timesyncd.conf imported from the CONFIG partition
* 50-os-agent.conf: NTP servers set through the OS Agent D-Bus API
On upgrade, settings from the previously persisted timesyncd.conf other
than the shipped defaults are moved to 20-custom.conf. This migration
can be removed later (with #4986). 50-os-agent.conf should be only
managed by OS Agent, so we don't need to care about user's edits.
Finally, if needed, drop-ins with higher priorities can be added for
complex customizations.
Refs home-assistant/supervisor#6278
Supervisor pairs every network mount with a systemd .automount unit,
so the kernel automounter is a hard requirement for network storage.
Today the option is only enabled as a side effect: Buildroot's systemd
package force-enables CONFIG_AUTOFS_FS through its kernel config
fixups. That works — it even overrode the explicit disable the
Raspberry Pi config carried until 11.2 — but nothing in our configs
states the dependency, and the fixup skips symbols already set to =m,
which leaves the Rockchip boards (Green, ODROID-M1/M1S) with autofs as
a module while every other board has it built in.
Set the option in the shared fragment to document the requirement and
build it in everywhere.
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
Corrupted Docker image layers cannot be always fixed by removing and
re-pulling a single image, because layers are shared between images. The
only (easy) way to recover is wiping all of Docker's storage which is
currently cumbersome and requires OS shell access.
Add service triggered by /mnt/data/docker/.wipe-scheduled flag file
which wipes the Docker directory by atomically renaming it and deleting
synchronously. If this is interrupted, docker-prepare script removes the
leftovers before Docker is started on every boot.
It should be noted that docker-prepare also forces the switch to
containerd snapshotter after the wipe.
Refs home-assistant/supervisor#6555