Skip to content

host-integration: the lane requires a live sudo timestamp and fails silently in non-interactive runs #530

Description

@vicondoa

Context

make test-host-integration stages the host-tool bundle with Bazel (cached, fast) and then builds each vmChecks.<system>.<name> derivation as sudo -A -E nix build --option build-users-group "" --option extra-sandbox-paths /dev/vhost-vsock .... The -A asks for the password through SUDO_ASKPASS, which on NixOS is /run/current-system/sw/bin/systemd-ask-password.

Problem

In a non-interactive context - an agent shell, CI, or a session with no ask-password agent - nothing answers that prompt, so every check fails after the 90-second timer with:

Failed to query password: Timer expired
sudo: no password was provided
sudo: a password is required

This happens before any build starts, so it reads as a test failure rather than a missing credential, and a full run burns roughly seventeen minutes producing nothing. Worse, sudo timestamps are global with timestamp_timeout=360, so a run can start fine and then lose authorization mid-flight if one check takes longer than six minutes, turning the later checks into the same confusing failure.

Acceptance

  • A non-interactive invocation reports the credential problem once, immediately, instead of as eleven per-check failures - a preflight sudo -n true with an explicit message is enough.
  • The target documents that it needs a live sudo timestamp, since one authentication covers the serially-run checks while no single check exceeds the timeout.

Environment note (2026-09-21)

A full eleven-check run of make test-host-integration succeeded today from a non-interactive agent context, because this host is configured with passwordless sudo (sudo -n true succeeds). The described failure therefore did not reproduce here: the issue is environment-dependent and is not fixed - on hosts whose sudo requires a password/askpass it remains exactly as reported above. The acceptance criteria stay the target for those hosts.

A sibling lane already implements the preflight-with-skip pattern this target lacks: tests/integration/distro-matrix/ubuntu-2404-tier1.sh defines preflight_or_skip() (lines 81-103) - it checks the costly prerequisite up front and reports skip "..." with the named reason (ok "preflight" on success) instead of letting the lane fail per-check. The host-integration target should mirror that shape: a sudo -n true preflight that reports the missing credential once (or skips the lane with a named reason in contexts that cannot prompt), before any nix build starts.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    backlogBacklog — not tied to a specific release

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions