fix: preserve Pi recovery error semantics

This commit is contained in:
2026-08-04 23:59:01 +02:00
parent 935bb1db0e
commit 70dabcc192
2 changed files with 71 additions and 12 deletions
+5 -11
View File
@@ -114,11 +114,7 @@ func updateWithHooks(ctx context.Context, runner Runner, request Request, hooks
}
if clearErr := setMaintenance(context.Background(), runner, false); clearErr != nil {
result = Result{Phase: PhaseFailed, StatePath: request.StatePath}
if retErr == nil {
retErr = errors.New("maintenance admission gate could not be cleared: recovery required")
} else {
retErr = fmt.Errorf("%w; maintenance admission gate could not be cleared: recovery required", retErr)
}
retErr = errors.Join(retErr, fmt.Errorf("maintenance admission gate could not be cleared: %w", clearErr))
}
}()
@@ -297,11 +293,7 @@ func rollbackWithHooks(ctx context.Context, runner Runner, statePath string, con
}
if clearErr := setMaintenance(context.Background(), runner, false); clearErr != nil {
result = Result{Phase: PhaseFailed, StatePath: statePath}
if retErr == nil {
retErr = errors.New("maintenance admission gate could not be cleared: recovery required")
} else {
retErr = fmt.Errorf("%w; maintenance admission gate could not be cleared: recovery required", retErr)
}
retErr = errors.Join(retErr, fmt.Errorf("maintenance admission gate could not be cleared: %w", clearErr))
}
}()
if maintenanceErr == nil {
@@ -481,7 +473,9 @@ func setMaintenance(ctx context.Context, runner Runner, enabled bool) error {
// reading the durable gate state before deciding that operator recovery is required.
observed, statusErr := MaintenanceStatus(ctx, runner)
if statusErr == nil && observed.Active == enabled && observed.Admissions == 0 {
if observed.RecoveryRequired {
// curl exit 22 means the server explicitly rejected the POST. A matching marker after
// that rejection selects the safest state, but cannot prove the failed write was durable.
if observed.RecoveryRequired || result.ExitCode == 22 {
return recoveryRequired("maintenance durability was explicitly not acknowledged", err)
}
return nil