get_available_updates reports no updates when it could not read them #4

Closed
opened 2026-10-08 09:50:55 +00:00 by christianmanivong · 0 comments
Owner

get_available_updates() returns [] when it could not read, but the contract netOrk relies on says a reader raises when it cannot read and never returns [] for "don't know". netOrk's poll then records a failed read and leaves every pending update alone; an empty list instead closes every patch-compliance clock on the host (netOrk docs/ARCHITECTURE.md, "A failed read changes nothing").

Where it happens:

  • FreeBSD: pkg upgrade -n and pkg audit run as root. Without root (no sudo password, sudo -n refused) stdout is empty, so no updates.
  • FreeBSD classic base: freebsd-update updatesready exiting 1 (an error) is treated like 2 (nothing ready).
  • OpenBSD: pkg_add -u -n -v and syspatch -c run as root; refused, they print nothing, so no updates and no base-system entry.

Fix: check the exit status (and that root was granted) and raise RuntimeError with the tool's message when the read did not happen.

Found while wiring netOrk's apply side (NetOrk/netork#799).

`get_available_updates()` returns `[]` when it could not read, but the contract netOrk relies on says a reader **raises** when it cannot read and never returns `[]` for "don't know". netOrk's poll then records a failed read and leaves every pending update alone; an empty list instead closes every patch-compliance clock on the host (netOrk `docs/ARCHITECTURE.md`, "A failed read changes nothing"). Where it happens: - FreeBSD: `pkg upgrade -n` and `pkg audit` run as root. Without root (no sudo password, `sudo -n` refused) stdout is empty, so no updates. - FreeBSD classic base: `freebsd-update updatesready` exiting 1 (an error) is treated like 2 (nothing ready). - OpenBSD: `pkg_add -u -n -v` and `syspatch -c` run as root; refused, they print nothing, so no updates and no `base-system` entry. Fix: check the exit status (and that root was granted) and raise `RuntimeError` with the tool's message when the read did not happen. Found while wiring netOrk's apply side (NetOrk/netork#799).
Sign in to join this conversation.
No labels
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: NAPALM/napalm-bsd#4