|
From: Tim T. <t....@co...> - 2004-05-27 02:58:10
|
Heiko Zuerker wrote: > Friedrich Lobenstock wrote: > >> Tim Tait wrote on 27.05.2004 00:38 MET: >> >>> Since the new config has not been saved yet, no permanent harm done. >>> Now the user can ssh in and review them. If they are not to their >>> exact liking then they can run upgrade-config again with the right >>> input, and make a new-etc tree. Save that as etc.tar.bz2 (do the >>> paths need to be munged?) over the old one, and reboot. Voila! Trick >>> is to try to garantee the 1st boot has a high likelyhood of success. >> >> >> >> Hmmmm.....maybe in case of autoupdate we should start a process in >> the background that does nothing than the following: >> sleep 10min >> <restore prev. version of DL and remove disable new one> >> reboot -n -f >> >> This way you'd at least end up with the not updated system back to >> live if everything else fails. Of course we'd then need to add some >> kind of warning to the admins login to not forget to kill this >> process ;-) > > > This is a very good idea ! > I agree a fail-safe restore to old version mechanism would be nice... but I still say you have to force an auto-update or you run a high risk of not being to update remotely in the future, in which case why even bother supporting it. When major versions are released, just how far can one expect a boot to go on an old config? Did dl 1.0 work with an unmodified dl 0.5 config? Will 1.2 work woth an unmodified 1.06 config? Will we always require it to going forward? This fail-safe would also by default restore the old config, because nobody would have run a save-config yet. The watchdog script could wait for an event to terminate - like the etc.tar.bz2 file being updated or something. > >> Anyway those files that could not be upgrade by an auto-upgrade, eg. >> because they where changed manually, need to be updated manually anyway. >> > > True And they still can be, but only if the user can ssh in at which point he can check the upgrade results, which aren't saved yet so not harmful. Running the upgrade-config script itself later is harmless because all changes are made to a copy, you have to pu it into /etc to apply it. > > Heiko Tim |