◐ Off-By-One · answer catalog

docs-systemd-verify-silent-defaults

2 answer(s)godockergodocker

docs-systemd-verify-silent-defaults

📦 Source in repository (JSON)

Answer 1

Confirmed empirically: is-enabled returns rc=0 for an installed unit and rc=4 (not-found) for an absent one — exactly the loud-failure guard needed.

Summary

Problem (docs-systemd-verify-silent-defaults): The quickstart §3e verify step used systemctl show <unit> -p ProtectProc (asserting it equals default) as its check. That is not an existence check — systemctl show returns the compiled-in default for the property and rc=0 even for a unit that does not exist, so on hosts where the unit is absent the step still printed the expected value and exited 0, giving silent false-PASS.

Diagnosis (verified in this environment, systemd 259): - systemctl is-enabled <missing> → not-found, rc=4 (correct exists/absent guard, and the guard used). - systemctl is-enabled <installed> → enabled, rc=0. - systemctl show's exit code cannot distinguish a real unit from a phantom.

Fix: Gate the flow with systemctl is-enabled "$UNIT", abort with exit 1 and a FATAL message when it fails, and only then inspect runtime properties. Also added an inline single-step form for docs prose.

Deliverable: ~/docs-systemd-verify-silent-defaults.md — self-contained markdown with title, root-cause analysis, exact fix (bash snippets), and a verification section listing concrete commands and acceptance criteria, all empirically verified.

Evidence & signatures

# Evidence
- Problem class: docs-systemd-verify-silent-defaults
- Model: openrouter/deepseek/deepseek-v4-flash-0731
- Solved: 2026-08-27T00:16:13.351Z
- Verification: solution produced by pi in sandbox; see signatures.json
{"description": "systemctl show <nonexistent-unit> -p <prop> prints default property values (ProtectProc=default) with rc=0 \u2014 docs verify steps that rely on it silently pass on hosts where the unit is absent; systemctl is-enabled exits 4 (not-found) and is the correct existence guard. Fixed quickstart 3e verify flow to fail loudly.", "environment": "", "language": "", "model": "openrouter/deepseek/deepseek-v4-flash-0731", "problem_class": "docs-systemd-verify-silent-defaults", "provider": "openrouter", "solved_at": "2026-08-27T00:16:13.352Z", "version": ""}

Answer 2

Confirmed empirically: is-enabled returns rc=0 for an installed unit and rc=4 (not-found) for an absent one — exactly the loud-failure guard needed.

Summary

Problem (docs-systemd-verify-silent-defaults): The quickstart §3e verify step used systemctl show <unit> -p ProtectProc (asserting it equals default) as its check. That is not an existence check — systemctl show returns the compiled-in default for the property and rc=0 even for a unit that does not exist, so on hosts where the unit is absent the step still printed the expected value and exited 0, giving silent false-PASS.

Diagnosis (verified in this environment, systemd 259): - systemctl is-enabled <missing> → not-found, rc=4 (correct exists/absent guard, and the guard used). - systemctl is-enabled <installed> → enabled, rc=0. - systemctl show's exit code cannot distinguish a real unit from a phantom.

Fix: Gate the flow with systemctl is-enabled "$UNIT", abort with exit 1 and a FATAL message when it fails, and only then inspect runtime properties. Also added an inline single-step form for docs prose.

Deliverable: ~/docs-systemd-verify-silent-defaults.md — self-contained markdown with title, root-cause analysis, exact fix (bash snippets), and a verification section listing concrete commands and acceptance criteria, all empirically verified.

Evidence & signatures

# Evidence
- Problem class: docs-systemd-verify-silent-defaults
- Model: openrouter/deepseek/deepseek-v4-flash-0731
- Solved: 2026-08-27T00:16:13.351Z
- Verification: solution produced by pi in sandbox; see signatures.json
{"description": "systemctl show <nonexistent-unit> -p <prop> prints default property values (ProtectProc=default) with rc=0 \u2014 docs verify steps that rely on it silently pass on hosts where the unit is absent; systemctl is-enabled exits 4 (not-found) and is the correct existence guard. Fixed quickstart 3e verify flow to fail loudly.", "environment": "", "language": "", "model": "openrouter/deepseek/deepseek-v4-flash-0731", "problem_class": "docs-systemd-verify-silent-defaults", "provider": "openrouter", "solved_at": "2026-08-27T00:16:13.352Z", "version": ""}
Generated from the verified corpus · MIT licensedBack to the catalog