7 KiB
2026-07-16 — GOA container package upgrade (trixie debs)
Why
taler-monitoring.sh versions reported packages behind deb.taler.net trixie:
| Component | Package | Was | Target (trixie index) |
|---|---|---|---|
| bank | libeufin-bank / common | 1.6.6 | 1.6.7 |
| exchange | taler-exchange* / libtalerexchange | 1.6.6 | 1.6.7~dev2 |
| merchant | taler-merchant-webui | 1.6.9 | 1.6.11 |
| merchant | taler-merchant / libtalermerchant | 1.6.9 | still 1.6.9 (no newer in suite for those) |
Host is openSUSE Tumbleweed — irrelevant for these versions. Debs live inside Debian-based podman images.
Containers
| Role | Name |
|---|---|
| bank | taler-hacktivism-bank |
| exchange | taler-hacktivism-exchange-ansible |
| merchant | taler-hacktivism |
No systemd as PID 1 in these containers. Do not rely on systemctl restart after apt (policy-rc.d / no bus). Restart with:
# bank
podman exec -u root taler-hacktivism-bank \
runuser -u libeufin-bank -- /usr/local/bin/start_bank.sh --restart
# merchant
podman exec -u root taler-hacktivism \
runuser -u taler-merchant-httpd -- /usr/local/bin/start_merchant.sh --restart
# exchange: base (root) then start_exchange as httpd user
podman exec -u root taler-hacktivism-exchange-ansible \
bash -c '/root/start_base_services_for_taler_exchange.sh --no-shell 2>/dev/null; \
runuser -u taler-exchange-httpd -- /usr/local/bin/start_exchange.sh --restart'
Procedure (manual)
# as root inside each container (example bank)
export DEBIAN_FRONTEND=noninteractive
apt-get update -qq
apt-get install -y libeufin-bank libeufin-common # bank
# exchange: taler-exchange taler-exchange-database libtalerexchange …
# merchant: taler-merchant-webui (and stack as needed)
Then restart with start_*.sh as above.
Scripted (host): scripts/taler-shared/upgrade-goa-debs.sh
Copy to koopa or run from a checkout: ./upgrade-goa-debs.sh / bank|exchange|merchant.
Lessons from 2026-07-16 run
apt-get installas root works (podman exec -u root); suitetrixie(+ merchant may also havetrixie-testing).taler-exchange-dbinitas root fails (role "root" does not exist) — run astaler-exchange-httpdif needed.- Bank after upgrade: if postgres socket was down, bank dies with pool init error;
pg_ctlcluster 17 main startthenstart_bank.sh --restart. - Merchant
taler-merchant-dbinit/ merchant-0041.sql can noise-fail (psql cluster path); afterstart_merchant.sh --restart, health check can still be green — verifyhttps://127.0.0.1:9010/configand publictaler.hacktivism.ch. - Exchange postinst may warn about missing SPA files under
/usr/share/taler-exchange/{aml,kyc}-spa/; packagestaler-exchange-aml-webui/kyc-webuipull in SPAs — re-check if AML UI is used. - Images are live-writable (not immutable rebuild): upgraded debs are in the running container layers until next image rebuild/snapshot.
Smoke after upgrade
curl -sS -o /dev/null -w "%{http_code}\n" http://127.0.0.1:9012/config
curl -sS -o /dev/null -w "%{http_code}\n" http://127.0.0.1:9011/config
curl -skS -o /dev/null -w "%{http_code}\n" https://127.0.0.1:9010/config
# public
curl -skS -o /dev/null -w "%{http_code}\n" https://bank.hacktivism.ch/config
curl -skS -o /dev/null -w "%{http_code}\n" https://exchange.hacktivism.ch/config
curl -skS -o /dev/null -w "%{http_code}\n" https://taler.hacktivism.ch/config
Laptop: ./scripts/taler-monitoring/taler-monitoring.sh versions (or urls).
Result (this day)
- bank 1.6.7, exchange 1.6.7~dev2, merchant-webui 1.6.11
- public
/config200 for bank / exchange / merchant after restarts taler-monitoring.sh -d hacktivism.ch versions→ behind=0 (all package rows OK)
Specific residual problems (re-checked after upgrade)
Severity: P1 = breaks settlement/ops soon · P2 = noise / tooling · P3 = hygiene.
P1 — none known after restarts
Settlement path: bank/exchange/merchant /config 200; merchant health can pass including wirewatch (see below).
P2 — taler-merchant-dbinit fails when run by hand
WARNING Could not run PSQL on file …/global_procedures.sql: psql exit code was 1
ERROR Failed to initialize tables
- Schema is actually current:
_v.patchesincludesmerchant-0041(applied 2026-07-16, by rolepostgresduring upgrade noise). - Service works:
check_merchant-health.sh→ ALL CRITICAL CHECKS PASSED when helpers are up. - Cause (likely): service-user
psql/ cluster path (Error: Invalid data directory for cluster 17 mainwhen run poorly), not missing migrations. - Action: do not treat hand-run
dbinitexit≠0 as deploy failure; verify_v.patches+/config. Optional follow-up: fixpg_wrapper/.postgresqlrcfortaler-merchant-httpdso dbinit is clean.
P2 — merchant health vs wirewatch (race / detect)
check_merchant-health.shusespgrepfortaler-merchant-wirewatch.- Wirewatch is supervised by
taler-merchant-wirewatch-supervise.sh(restarts on PG NOTIFY exit). - During restart windows the helper can be absent for seconds → false FAIL.
- When wirewatch + supervise are both live, health reports OK.
- Action: re-run health after 5s; ensure supervise is started after package upgrades (start_merchant / ensure_helpers).
P2 — check_exchange-health.sh missing in live exchange container
exec: "/usr/local/bin/check_exchange-health.sh": no such file or directory
- Script exists in admin-log (
scripts/taler-exchange/check_exchange-health.sh) but was not installed intotaler-hacktivism-exchange-ansible. - Action: copy into image/live
/usr/local/bin/on next deploy (same as bank/merchant health scripts).
P3 — zombie processes inside bank + merchant containers
- bank: defunct
java,python3, occasionalpostgres/dpkg-preconfigu. - merchant: many old
taler-merchant-*defunct (pre-restart leftovers). - Cause: no proper init/reaper (not systemd PID 1); supervise/start scripts leave zombies.
- Impact: mostly cosmetic / PID table clutter unless extreme.
- Action: periodic container restart or install a tiny reaper; not urgent.
P3 — package skew (informational)
| Package | Installed | Note |
|---|---|---|
| taler-merchant / libtalermerchant / typst | 1.6.9 | no newer in trixie index at check time |
| taler-merchant-webui | 1.6.11 | intentionally newer SPA |
| exchange aml/kyc webui | 1.6.8~dev3 | pulled with exchange upgrade |
Monitoring does not ERROR on this skew when suite index matches installed.
Resolved during upgrade (do not re-open without evidence)
- Version behind bank/exchange/webui — fixed.
- Exchange postinst “missing aml-spa/forms.json” — paths
/usr/share/taler-exchange/{aml,kyc}-spanow present after webui packages. - Bank down after apt — fixed with postgres socket +
start_bank.sh --restart.