From 83c646c3fe8dab1dba7d18d15ab624e3d225105d Mon Sep 17 00:00:00 2001 From: MickLesk <47820557+MickLesk@users.noreply.github.com> Date: Wed, 23 Sep 2026 16:34:59 +0200 Subject: [PATCH 1/2] Do not abort on a failed apt update --- core/core.func | 2 +- incus/tools.func | 4 ++-- lib/db.func | 2 +- lib/runtime.func | 2 +- lib/system.func | 2 +- 5 files changed, 6 insertions(+), 6 deletions(-) diff --git a/core/core.func b/core/core.func index 8af1637..c79613d 100644 --- a/core/core.func +++ b/core/core.func @@ -1418,7 +1418,7 @@ ensure_tput() { if grep -qi 'alpine' /etc/os-release; then apk add --no-cache ncurses >/dev/null 2>&1 elif command -v apt-get >/dev/null 2>&1; then - apt-get update -qq >/dev/null + apt-get update -qq >/dev/null 2>&1 || true apt-get install -y -qq ncurses-bin >/dev/null 2>&1 fi fi diff --git a/incus/tools.func b/incus/tools.func index 1da68c4..4696a13 100644 --- a/incus/tools.func +++ b/incus/tools.func @@ -196,7 +196,7 @@ network_check() { update_os() { msg_info "Updating Container OS" - $STD apt update + apt_update_safe $STD apt upgrade -y msg_ok "Updated Container OS" } @@ -260,7 +260,7 @@ _bootstrap() { if [[ "$need_bootstrap" -eq 1 ]]; then msg_info "Installing Base Dependencies" - $STD apt update + apt_update_safe $STD apt install -y "${base_pkgs[@]}" msg_ok "Installed Base Dependencies" fi diff --git a/lib/db.func b/lib/db.func index 5fef663..3011581 100644 --- a/lib/db.func +++ b/lib/db.func @@ -1052,7 +1052,7 @@ EOF if ! install_packages_with_retry "mysql-community-server" "mysql-community-client"; then msg_warn "MySQL 8.4 LTS installation failed – falling back to MariaDB" cleanup_old_repo_files "mysql" - $STD apt update + apt_update_safe install_packages_with_retry "mariadb-server" "mariadb-client" || { msg_error "Failed to install database engine (MySQL/MariaDB fallback)" return 100 diff --git a/lib/runtime.func b/lib/runtime.func index 739e7b0..e1080c1 100644 --- a/lib/runtime.func +++ b/lib/runtime.func @@ -1282,7 +1282,7 @@ setup_nodejs() { # Ensure jq is available for JSON parsing if ! command -v jq &>/dev/null; then - $STD apt update + apt_update_safe $STD apt install -y jq || { msg_error "Failed to install jq" return 100 diff --git a/lib/system.func b/lib/system.func index 261351c..764ccc0 100644 --- a/lib/system.func +++ b/lib/system.func @@ -2481,6 +2481,6 @@ Suites: trixie-security Components: main contrib non-free non-free-firmware EOF fi - $STD apt update + apt_update_safe return 0 } From ab226e17db9d6fdab993be300487e01c404bee1a Mon Sep 17 00:00:00 2001 From: MickLesk <47820557+MickLesk@users.noreply.github.com> Date: Wed, 23 Sep 2026 16:40:13 +0200 Subject: [PATCH 2/2] Stop apt_update_safe from enabling nounset, and retry --- core/core.func | 40 ++++++++++++++++++++++------------------ 1 file changed, 22 insertions(+), 18 deletions(-) diff --git a/core/core.func b/core/core.func index c79613d..d221067 100644 --- a/core/core.func +++ b/core/core.func @@ -2372,32 +2372,36 @@ function get_lxc_ip() { # apt_update_safe() # # - Runs apt-get update without letting a partial failure abort the caller -# - Disarms errexit and the ERR trap for the duration, then restores them -# - Warns on a non-zero exit and hints at the enterprise-repo 401/403 case +# - Retries up to three times; a mirror hiccup is the usual cause +# - Leaves the caller's shell options and ERR trap untouched +# - Warns after the last attempt and hints at the enterprise-repo 401/403 case # ------------------------------------------------------------------------------ apt_update_safe() { - local logfile + local logfile rc=0 attempt from logfile="$(get_active_logfile)" - local _restore_errexit=false - [[ "$-" == *e* ]] && _restore_errexit=true - - set +Eeuo pipefail - trap - ERR - - apt-get update >>"$logfile" 2>&1 - local rc=$? - - if $_restore_errexit; then - set -Eeuo pipefail - trap 'error_handler' ERR - fi + # `|| rc=$?` is exempt from errexit and the ERR trap, so nothing here has to + # touch the caller's shell options. + for attempt in 1 2 3; do + from=$(($(wc -l <"$logfile" 2>/dev/null || echo 0) + 1)) + rc=0 + apt-get update >>"$logfile" 2>&1 || rc=$? + if [[ "${VERBOSE:-no}" == "yes" ]]; then + tail -n "+${from}" "$logfile" 2>/dev/null + fi + if ((rc == 0)); then + return 0 + fi + if ((attempt < 3)); then + sleep $((attempt * 5)) + fi + done if [[ $rc -ne 0 ]]; then - msg_warn "apt-get update exited with code ${rc} — some repositories may have failed." + msg_warn "apt-get update exited with code ${rc} after 3 attempts — some repositories may have failed." # Check log for common 401/403 enterprise repo issues - if grep -qiE '401\s*Unauthorized|403\s*Forbidden|enterprise\.proxmox\.com' "$logfile" 2>/dev/null; then + if tail -n "+${from}" "$logfile" 2>/dev/null | grep -qiE '401\s*Unauthorized|403\s*Forbidden|enterprise\.proxmox\.com'; then echo -e "${TAB}${INFO} ${YWB}Hint: Proxmox enterprise repository returned an auth error.${CL}" echo -e "${TAB} If you don't have a subscription, you can disable the enterprise" echo -e "${TAB} repo and use the no-subscription repo instead."