diff --git a/ansible/roles/podman/handlers/main.yml b/ansible/roles/podman/handlers/main.yml index 80b532c..8e94f6f 100644 --- a/ansible/roles/podman/handlers/main.yml +++ b/ansible/roles/podman/handlers/main.yml @@ -1,8 +1,20 @@ --- +# -x keeps this on the local filesystem. Two TrueNAS CIFS shares are mounted +# INSIDE this tree -- volumes/photos/immich and volumes/photos/storage -- and +# without -x restorecon walked the entire remote photo library over SMB, +# relabelling a filesystem that cannot even store SELinux xattrs. On 2026-08-28 +# that pinned CPU#0 at 100% system time and the kernel logged escalating soft +# lockups ("BUG: soft lockup - CPU#0 stuck for 1423s! [restorecon]") until the +# host could no longer create login sessions and needed a hard reboot. An +# earlier run the same day had already been SIGKILLed at 49s, which was the +# same problem surfacing quietly. +# +# The mounts are also x-systemd.automount, so merely walking into them triggers +# a mount -- there is nothing to relabel there and never was. - name: restorecon podman become: true ansible.builtin.command: | - restorecon -Frv {{ podman_home }}/.local/share/volumes + restorecon -Frxv {{ podman_home }}/.local/share/volumes tags: - podman - selinux