From fb09a01c8846ed0583047f5fcef3adf57f0ec37b Mon Sep 17 00:00:00 2001 From: Bastian de Byl Date: Fri, 28 Aug 2026 11:40:07 -0400 Subject: [PATCH] fix(podman): stop restorecon walking the TrueNAS CIFS mounts restorecon -Frv over the podman volumes tree descends into two SMB shares mounted inside it -- volumes/photos/immich and volumes/photos/storage, both from truenas -- so it was relabelling the entire remote photo library over the network, on a filesystem that cannot store SELinux xattrs at all. On 2026-08-28 that pinned CPU#0 at 100% system time and the kernel logged six escalating soft lockups: watchdog: BUG: soft lockup - CPU#0 stuck for 1423s! [restorecon:132780] New process creation starved, so sshd accepted connections and then hung during session setup, and the host needed a hard reboot. An earlier run the same day had already been SIGKILLed at 49s, which was the same bug surfacing quietly. -x keeps it on the local filesystem. Measured: 1,279,231 local files walked and relabelled in 29.2s, against never finishing before. The mounts are also x-systemd.automount, so merely walking into them triggers a mount -- there was never anything there to relabel. Co-Authored-By: Claude Opus 5 --- ansible/roles/podman/handlers/main.yml | 14 +++++++++++++- 1 file changed, 13 insertions(+), 1 deletion(-) diff --git a/ansible/roles/podman/handlers/main.yml b/ansible/roles/podman/handlers/main.yml index 80b532c..8e94f6f 100644 --- a/ansible/roles/podman/handlers/main.yml +++ b/ansible/roles/podman/handlers/main.yml @@ -1,8 +1,20 @@ --- +# -x keeps this on the local filesystem. Two TrueNAS CIFS shares are mounted +# INSIDE this tree -- volumes/photos/immich and volumes/photos/storage -- and +# without -x restorecon walked the entire remote photo library over SMB, +# relabelling a filesystem that cannot even store SELinux xattrs. On 2026-08-28 +# that pinned CPU#0 at 100% system time and the kernel logged escalating soft +# lockups ("BUG: soft lockup - CPU#0 stuck for 1423s! [restorecon]") until the +# host could no longer create login sessions and needed a hard reboot. An +# earlier run the same day had already been SIGKILLed at 49s, which was the +# same problem surfacing quietly. +# +# The mounts are also x-systemd.automount, so merely walking into them triggers +# a mount -- there is nothing to relabel there and never was. - name: restorecon podman become: true ansible.builtin.command: | - restorecon -Frv {{ podman_home }}/.local/share/volumes + restorecon -Frxv {{ podman_home }}/.local/share/volumes tags: - podman - selinux