docs-systemd-verify-silent-defaults
Confirmed empirically: is-enabled returns rc=0 for an installed unit and rc=4 (not-found) for an absent one — exactly the loud-failure guard needed.
Problem (docs-systemd-verify-silent-defaults): The quickstart §3e verify step used systemctl show <unit> -p ProtectProc (asserting it equals default) as its check. That is not an existence check — systemctl show returns the compiled-in default for the property and rc=0 even for a unit that does not exist, so on hosts where the unit is absent the step still printed the expected value and exited 0, giving silent false-PASS.
Diagnosis (verified in this environment, systemd 259):
- systemctl is-enabled <missing> → not-found, rc=4 (correct exists/absent guard, and the guard used).
- systemctl is-enabled <installed> → enabled, rc=0.
- systemctl show's exit code cannot distinguish a real unit from a phantom.
Fix: Gate the flow with systemctl is-enabled "$UNIT", abort with exit 1 and a FATAL message when it fails, and only then inspect runtime properties. Also added an inline single-step form for docs prose.
Deliverable: ~/docs-systemd-verify-silent-defaults.md — self-contained markdown with title, root-cause analysis, exact fix (bash snippets), and a verification section listing concrete commands and acceptance criteria, all empirically verified.
# Evidence - Problem class: docs-systemd-verify-silent-defaults - Model: openrouter/deepseek/deepseek-v4-flash-0731 - Solved: 2026-08-27T00:16:13.351Z - Verification: solution produced by pi in sandbox; see signatures.json
{"description": "systemctl show <nonexistent-unit> -p <prop> prints default property values (ProtectProc=default) with rc=0 \u2014 docs verify steps that rely on it silently pass on hosts where the unit is absent; systemctl is-enabled exits 4 (not-found) and is the correct existence guard. Fixed quickstart 3e verify flow to fail loudly.", "environment": "", "language": "", "model": "openrouter/deepseek/deepseek-v4-flash-0731", "problem_class": "docs-systemd-verify-silent-defaults", "provider": "openrouter", "solved_at": "2026-08-27T00:16:13.352Z", "version": ""}Confirmed empirically: is-enabled returns rc=0 for an installed unit and rc=4 (not-found) for an absent one — exactly the loud-failure guard needed.
Problem (docs-systemd-verify-silent-defaults): The quickstart §3e verify step used systemctl show <unit> -p ProtectProc (asserting it equals default) as its check. That is not an existence check — systemctl show returns the compiled-in default for the property and rc=0 even for a unit that does not exist, so on hosts where the unit is absent the step still printed the expected value and exited 0, giving silent false-PASS.
Diagnosis (verified in this environment, systemd 259):
- systemctl is-enabled <missing> → not-found, rc=4 (correct exists/absent guard, and the guard used).
- systemctl is-enabled <installed> → enabled, rc=0.
- systemctl show's exit code cannot distinguish a real unit from a phantom.
Fix: Gate the flow with systemctl is-enabled "$UNIT", abort with exit 1 and a FATAL message when it fails, and only then inspect runtime properties. Also added an inline single-step form for docs prose.
Deliverable: ~/docs-systemd-verify-silent-defaults.md — self-contained markdown with title, root-cause analysis, exact fix (bash snippets), and a verification section listing concrete commands and acceptance criteria, all empirically verified.
# Evidence - Problem class: docs-systemd-verify-silent-defaults - Model: openrouter/deepseek/deepseek-v4-flash-0731 - Solved: 2026-08-27T00:16:13.351Z - Verification: solution produced by pi in sandbox; see signatures.json
{"description": "systemctl show <nonexistent-unit> -p <prop> prints default property values (ProtectProc=default) with rc=0 \u2014 docs verify steps that rely on it silently pass on hosts where the unit is absent; systemctl is-enabled exits 4 (not-found) and is the correct existence guard. Fixed quickstart 3e verify flow to fail loudly.", "environment": "", "language": "", "model": "openrouter/deepseek/deepseek-v4-flash-0731", "problem_class": "docs-systemd-verify-silent-defaults", "provider": "openrouter", "solved_at": "2026-08-27T00:16:13.352Z", "version": ""}