aboutsummaryrefslogtreecommitdiff
path: root/docs/PLAN-dotfiles-separation.org
diff options
context:
space:
mode:
authorCraig Jennings <c@cjennings.net>2026-08-19 12:16:46 -0700
committerCraig Jennings <c@cjennings.net>2026-08-19 12:16:46 -0700
commitbe0a320dd35f4f4a87341bc3f41132a2a83dbcd7 (patch)
treec81b899f465eb9c51563b5064dc807477ddaf066 /docs/PLAN-dotfiles-separation.org
parent41fea69af643fb60cb8f256a60ff84a19a5a5c32 (diff)
downloadarchsetup-be0a320dd35f4f4a87341bc3f41132a2a83dbcd7.tar.gz
archsetup-be0a320dd35f4f4a87341bc3f41132a2a83dbcd7.zip
fix(installer): give NTP an IP source so a wrong clock can't kill DNS
The installer wrote both halves of a deadlock. configure_dns pins DNSOverTLS=yes with DNSSEC=yes, and both validate against the wall clock. The chrony step enables chronyd without writing a config, so the machine runs Arch's stock one, whose only source is a pool hostname. Boot with a wrong clock and DoT validation fails, so nothing resolves. Chrony then can't resolve its pool, so the clock stays wrong. Neither side moves, and recovery takes a second device. Velox hit this on the road and I diagnosed it from a phone. An address needs no DNS and no certificate, so two IP-addressed sources in a drop-in break the cycle whatever caused the skew. Stock chrony.conf reads no drop-in directory, so it gets a confdir line pointing at one. post-rebuild-check grows a sixth check for the same property. It reads sources only from files chrony is told to read. A drop-in beside a chrony.conf that never names its directory is one chrony won't open, so counting it would pass the machine while describing a file nothing reads. The failure taxonomy gains the mode in its DNS layer and a cluster 5 triage line. Its egress-layer clock entry assumed working DNS and offered set-ntp true, which can't recover this. That entry now says so.
Diffstat (limited to 'docs/PLAN-dotfiles-separation.org')
0 files changed, 0 insertions, 0 deletions