Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
4 changes: 2 additions & 2 deletions Cargo.lock

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

4 changes: 2 additions & 2 deletions package-lock.json

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

2 changes: 1 addition & 1 deletion package.json
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
{
"name": "startos-ui",
"version": "0.4.0.2",
"version": "0.4.0.3",
"author": "Start9 Labs, Inc",
"homepage": "https://start9.com/",
"license": "MIT",
Expand Down
6 changes: 6 additions & 0 deletions projects/start-cli/CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -9,6 +9,12 @@ Because `start-cli` is a thin client over `start-core`, most user-visible CLI ch
in `start-core`; record here anything that changes this crate's entrypoint, features, packaging,
or the CLI's externally observable behavior.

## [2.3.0]

### Added

- **`server restart` and `server shutdown` wait for a running backup to finish by default.** Pass `--force` to interrupt the backup. `server cancel-deferred-power` cancels the pending action. These commands require StartOS 0.4.0.3 or later.

## [2.2.0]

### Security
Expand Down
2 changes: 1 addition & 1 deletion projects/start-cli/Cargo.toml
Original file line number Diff line number Diff line change
Expand Up @@ -3,7 +3,7 @@ edition = "2024"
license = "MIT"
name = "start-cli"
repository = "https://github.com/Start9Labs/start-technologies"
version = "2.2.0" # VERSION_BUMP
version = "2.3.0" # VERSION_BUMP

[[bin]]
name = "start-cli"
Expand Down
13 changes: 13 additions & 0 deletions projects/start-cli/man/start-cli-server-cancel-deferred-power.1
Original file line number Diff line number Diff line change
@@ -0,0 +1,13 @@
.ie \n(.g .ds Aq \(aq
.el .ds Aq '
.TH start-cli-server-cancel-deferred-power 1 "cancel-deferred-power "
.SH NAME
start\-cli\-server\-cancel\-deferred\-power \- Cancel a restart or shutdown that is waiting for a backup to finish
.SH SYNOPSIS
\fBstart\-cli server cancel\-deferred\-power\fR [\fB\-h\fR|\fB\-\-help\fR]
.SH DESCRIPTION
Cancel a restart or shutdown that is waiting for a backup to finish
.SH OPTIONS
.TP
\fB\-h\fR, \fB\-\-help\fR
Print help
5 changes: 4 additions & 1 deletion projects/start-cli/man/start-cli-server-restart.1
Original file line number Diff line number Diff line change
Expand Up @@ -4,13 +4,16 @@
.SH NAME
start\-cli\-server\-restart \- Restart the server
.SH SYNOPSIS
\fBstart\-cli server restart\fR [\fB\-\-nowait\fR] [\fB\-h\fR|\fB\-\-help\fR]
\fBstart\-cli server restart\fR [\fB\-\-nowait\fR] [\fB\-\-force\fR] [\fB\-h\fR|\fB\-\-help\fR]
.SH DESCRIPTION
Restart the server
.SH OPTIONS
.TP
\fB\-\-nowait\fR
Return immediately instead of waiting for graceful shutdown to complete
.TP
\fB\-\-force\fR
Interrupt a running backup instead of waiting for it to finish
.TP
\fB\-h\fR, \fB\-\-help\fR
Print help
5 changes: 4 additions & 1 deletion projects/start-cli/man/start-cli-server-shutdown.1
Original file line number Diff line number Diff line change
Expand Up @@ -4,13 +4,16 @@
.SH NAME
start\-cli\-server\-shutdown \- Shutdown the server
.SH SYNOPSIS
\fBstart\-cli server shutdown\fR [\fB\-\-nowait\fR] [\fB\-h\fR|\fB\-\-help\fR]
\fBstart\-cli server shutdown\fR [\fB\-\-nowait\fR] [\fB\-\-force\fR] [\fB\-h\fR|\fB\-\-help\fR]
.SH DESCRIPTION
Shutdown the server
.SH OPTIONS
.TP
\fB\-\-nowait\fR
Return immediately instead of waiting for graceful shutdown to complete
.TP
\fB\-\-force\fR
Interrupt a running backup instead of waiting for it to finish
.TP
\fB\-h\fR, \fB\-\-help\fR
Print help
3 changes: 3 additions & 0 deletions projects/start-cli/man/start-cli-server.1
Original file line number Diff line number Diff line change
Expand Up @@ -13,6 +13,9 @@ Commands related to the server i.e. restart, update, and shutdown
Print help
.SH SUBCOMMANDS
.TP
start\-cli\-server\-cancel\-deferred\-power(1)
Cancel a restart or shutdown that is waiting for a backup to finish
.TP
start\-cli\-server\-clear\-smtp(1)
Remove system smtp server and credentials
.TP
Expand Down
4 changes: 2 additions & 2 deletions projects/start-cli/man/start-cli.1
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
.ie \n(.g .ds Aq \(aq
.el .ds Aq '
.TH start-cli 1 "start-cli 2.2.0"
.TH start-cli 1 "start-cli 2.3.0"
.SH NAME
start\-cli
.SH SYNOPSIS
Expand Down Expand Up @@ -123,4 +123,4 @@ Command for calculating the blake3 hash of a file
start\-cli\-wifi(1)
Commands related to wifi networks i.e. add, connect, delete
.SH VERSION
v2.2.0
v2.3.0
5 changes: 5 additions & 0 deletions projects/start-cli/release-notes/2.3.0.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,5 @@
**start-cli 2.3.0 lets a running backup finish before restarting or shutting down your server.**

## Highlights

- **`server restart` and `server shutdown` wait for a running backup to finish by default.** Pass `--force` to interrupt the backup. Cancel a pending action with `server cancel-deferred-power`. Requires StartOS 0.4.0.3 or later.
15 changes: 13 additions & 2 deletions projects/start-os/ARCHITECTURE.md
Original file line number Diff line number Diff line change
Expand Up @@ -81,8 +81,19 @@ erasure-coded FUSE filesystem used for StartOS backups. It builds to the
this slice at boot.
- `startos-shutdown.service` — graceful teardown on power-off only (ties to
`poweroff.target`/`halt.target`, not reboot); its `ExecStop` calls
`start-cli server shutdown`.
- `startos-restart.service` — restart handling.
`start-cli server shutdown --force` to interrupt any backup while still
waiting for graceful teardown.
- `startos-restart.service` — graceful teardown on reboot/kexec; its `ExecStop`
calls `start-cli server restart --force`. Systemd-driven teardown cannot
defer a power action until a backup finishes.
- The physical power key is systemd-logind's (`HandlePowerKey=poweroff`),
except while a backup is running: `startd` then holds a logind
`handle-power-key` block inhibitor and reads the key itself, turning a press
into a shutdown that waits for the backup rather than one that interrupts it.
It is best-effort — when the inhibitor cannot be taken or no `power-switch`
device can be read, the key stays logind's — so treat it as one defence and
not a guarantee. See `start-core/src/power_key.rs` for why it inhibits
`handle-power-key` rather than `shutdown`.

## OS image packaging

Expand Down
20 changes: 20 additions & 0 deletions projects/start-os/CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -8,6 +8,26 @@ This file tracks notable changes since the move to the monorepo, and is what eac
[GitHub release](https://github.com/Start9Labs/start-technologies/releases) links to
for the detail behind its highlights.

## [0.4.0.3]

### Added

- **Restarting or shutting down during a backup offers to wait for it to
finish.** The prompt defaults to waiting after a countdown. A bar shows the
pending action and lets you cancel it. Pressing the physical power button
during a backup also waits when StartOS can intercept the key. Over the CLI,
`start-cli server restart` and `server shutdown` wait by default; `--force`
interrupts the backup. The command
`start-cli server cancel-deferred-power` cancels the pending action. StartOS
refuses new backups once a restart or shutdown is committed. See
[Creating Backups](https://docs.start9.com/start-os/backup-create.html).

### Fixed

- **Restarting the StartOS daemon clears interrupted backup, update, restart,
and shutdown indicators**, including any pending power action. An interrupted
operation no longer appears to be running after the daemon starts again.

## [0.4.0.2]

### Security
Expand Down
5 changes: 2 additions & 3 deletions projects/start-os/Cargo.toml
Original file line number Diff line number Diff line change
Expand Up @@ -3,9 +3,8 @@ edition = "2024"
license = "MIT"
name = "start-os"
repository = "https://github.com/Start9Labs/start-technologies"
# Label only: SemVer has no 4th segment, so the OS version 0.4.0.2 is spelled 0.4.0-rev.2
# here. Root package.json is the source of truth — see build/env/version.sh.
version = "0.4.0-rev.2" # VERSION_BUMP
# Label only: SemVer has no 4th segment. Root package.json is the source of truth.
version = "0.4.0-rev.3" # VERSION_BUMP

[[bin]]
name = "startbox"
Expand Down
3 changes: 2 additions & 1 deletion projects/start-os/build.mk
Original file line number Diff line number Diff line change
Expand Up @@ -29,9 +29,10 @@ backup-fs-test: $(call ls-files, projects/start-os/backup-fs/src) projects/start
container-runtime-test: projects/start-os/container-runtime/node_modules/.package-lock.json $(call ls-files, projects/start-os/container-runtime/src) projects/start-os/container-runtime/package.json projects/start-os/container-runtime/tsconfig.json
cd projects/start-os/container-runtime && npm test

start-os-scripts-test: projects/start-os/build/lib/scripts/normalize-fstab projects/start-os/build/tests/normalize-fstab-test.sh projects/start-os/build/image-recipe/raspberrypi/img/usr/lib/startos/scripts/init_resize.sh projects/start-os/build/tests/init-resize-test.sh
start-os-scripts-test: projects/start-os/build/lib/scripts/normalize-fstab projects/start-os/build/tests/normalize-fstab-test.sh projects/start-os/build/image-recipe/raspberrypi/img/usr/lib/startos/scripts/init_resize.sh projects/start-os/build/tests/init-resize-test.sh projects/start-os/startos-restart.service projects/start-os/startos-shutdown.service projects/start-os/build/tests/power-units-test.sh
./projects/start-os/build/tests/normalize-fstab-test.sh
./projects/start-os/build/tests/init-resize-test.sh
./projects/start-os/build/tests/power-units-test.sh

projects/start-os/build/lib/migration-images/.done: projects/start-os/build/save-migration-images.sh
ARCH=$(ARCH) ./projects/start-os/build/save-migration-images.sh projects/start-os/build/lib/migration-images
Expand Down
32 changes: 32 additions & 0 deletions projects/start-os/build/tests/power-units-test.sh
Original file line number Diff line number Diff line change
@@ -0,0 +1,32 @@
#!/bin/bash

set -euo pipefail

ROOT=$(realpath "$(dirname "${BASH_SOURCE[0]}")/../../../..")
TMP=$(mktemp -d)
trap 'rm -rf -- "$TMP"' EXIT
UNITS="$TMP/usr/lib/systemd/system"
mkdir -p "$UNITS" "$TMP/usr/bin" "$TMP/bin"

# verify checks executables without running them.
printf '#!/bin/sh\nexit 1\n' > "$TMP/usr/bin/start-cli"
cp "$TMP/usr/bin/start-cli" "$TMP/bin/true"
chmod +x "$TMP/usr/bin/start-cli" "$TMP/bin/true"
printf '[Unit]\nDescription=Test target\nDefaultDependencies=no\n' > "$UNITS/sysinit.target"

for action in restart shutdown; do
unit="startos-$action.service"
cp "$ROOT/projects/start-os/$unit" "$UNITS/$unit"
if ! SYSTEMD_LOG_LEVEL=debug systemd-analyze verify --man=no --root="$TMP" "$unit" > "$TMP/parsed" 2>&1; then
cat "$TMP/parsed" >&2
exit 1
fi
awk '/ExecStop:/ { getline; print }' "$TMP/parsed" |
grep -Eq "^[[:space:]]*Command Line: /usr/bin/start-cli server $action --force$" || {
printf 'FAIL: %s must interrupt backups during systemd teardown\n' "$unit" >&2
cat "$TMP/parsed" >&2
exit 1
}
done

printf 'power unit tests passed\n'
2 changes: 2 additions & 0 deletions projects/start-os/docs/src/backup-create.md
Original file line number Diff line number Diff line change
Expand Up @@ -21,6 +21,8 @@ Back up your server's data to a physical drive or a network folder.

1. To back up a service, StartOS first stops it (if it was running), performs the backup, then restarts it — but only if it was running beforehand. A service that was already stopped stays stopped. Consequently a service cannot be used while it is backing up, though you may continue to use your server and other services in the meantime.

1. Restarting or shutting down mid-backup can corrupt the backup of whichever service is being written at that moment, so StartOS asks first. Choosing `Restart` or `Shutdown` while a backup is running offers to wait for the backup to finish instead, and takes that option for you if you do not choose within 30 seconds — to power down regardless, choose the "now" option in that prompt. Pressing the server's physical power button during a backup waits without asking when StartOS can intercept the key; otherwise the button powers off through the operating system. Either way StartOS performs the restart or shutdown as soon as the backup completes, and until then a bar along the bottom of the screen says what is coming and lets you cancel it. Once a restart or shutdown is under way, StartOS refuses to start a new backup.

1. Upon completion, StartOS issues a backup report, indicating which services were backed up, as well as any errors.

1. Wait for the `Backup Complete` notification before unplugging a backup drive. StartOS writes out the last of the backup and unmounts the drive before raising that notification, so the drive is safe to remove once it appears. The `Backup Progress` card reads `Complete` first, while StartOS is still finishing — the notification is the one to wait for.
Expand Down
14 changes: 12 additions & 2 deletions projects/start-os/docs/src/cli-reference.md
Original file line number Diff line number Diff line change
Expand Up @@ -54,11 +54,21 @@ Restart, shut down, update, and configure the server.

### `start-cli server restart`

Restart the server.
Restart the server, waiting for a running backup to finish first.

- `--force` — Interrupt a running backup and restart now
- `--nowait` — Return immediately instead of waiting for graceful shutdown

### `start-cli server shutdown`

Shut down the server.
Shut down the server, waiting for a running backup to finish first.

- `--force` — Interrupt a running backup and shut down now
- `--nowait` — Return immediately instead of waiting for graceful shutdown

### `start-cli server cancel-deferred-power`

Cancel a restart or shutdown that is waiting for a backup to finish.

### `start-cli server update`

Expand Down
6 changes: 3 additions & 3 deletions projects/start-os/docs/src/installing-startos.md
Original file line number Diff line number Diff line change
Expand Up @@ -8,7 +8,7 @@ This guide is for flashing StartOS to a USB drive, then installing it onto a des

## Download

1. Visit the [Github release page](https://github.com/Start9Labs/start-technologies/releases/tag/start-os/v0.4.0.2) to find the latest version of StartOS.
1. Visit the [Github release page](https://github.com/Start9Labs/start-technologies/releases/tag/start-os/v0.4.0.3) to find the latest version of StartOS.

1. Under "Image Downloads", select the image for your hardware. StartOS is available in x86_64 (AMD64), aarch64 (ARM64), and RISC-V (RVA23). For x86_64 and aarch64, two variants are available:
- **Standard**: Includes proprietary firmware and drivers for broader hardware compatibility, including display and wireless. Recommended for most users.
Expand All @@ -25,7 +25,7 @@ You do not need to understand what any of this means. Follow the three steps and

### 1. Find your file on the release page

On the [release page](https://github.com/Start9Labs/start-technologies/releases/tag/start-os/v0.4.0.2), scroll down to **OS Images Checksums**, then to the block under **SHA-256**. It holds one line per image: a long code, then the filename it belongs to.
On the [release page](https://github.com/Start9Labs/start-technologies/releases/tag/start-os/v0.4.0.3), scroll down to **OS Images Checksums**, then to the block under **SHA-256**. It holds one line per image: a long code, then the filename it belongs to.

```text
37b63c86197150866809d34b5824ae22c5fc705d4f8dc9e9750b8fa23485441a startos-0.4.0.1-fdb27c7_x86_64-nonfree.iso
Expand Down Expand Up @@ -194,7 +194,7 @@ Anything else is a failure. **`BAD signature`** means the file is not what Start

A Raspberry Pi does not use the USB installer above. Instead, you flash the StartOS image directly to the Pi's microSD card. This is also how a Raspberry Pi is updated to a new major version of StartOS — it cannot update over the air. If you are updating an existing 0.3.5.1 server, complete the [preparation steps in the update guide](update-040.md#prepare-your-server) before flashing.

1. Visit the [Github release page](https://github.com/Start9Labs/start-technologies/releases/tag/start-os/v0.4.0.2) and, from the downloads list, download the **Raspberry Pi `.img.gz`** file.
1. Visit the [Github release page](https://github.com/Start9Labs/start-technologies/releases/tag/start-os/v0.4.0.3) and, from the downloads list, download the **Raspberry Pi `.img.gz`** file.

1. Check it against the release page, exactly as in [Verify your download](#verify-your-download). The release lists a checksum for the `.img` inside the archive as well — the line you want is the one ending in `.img.gz`, because that is the file you downloaded.

Expand Down
3 changes: 3 additions & 0 deletions projects/start-os/docs/src/surge-and-ups.md
Original file line number Diff line number Diff line change
Expand Up @@ -47,3 +47,6 @@ There are three common topologies. For a home server, **line-interactive** is th
StartOS does not currently include built-in support for UPS monitoring (USB or network), so it cannot automatically shut down when the battery is low during an extended outage. The server will run until battery exhaustion and then power off uncleanly. This still carries some risk of data corruption, but it is dramatically less risky than facing the original surge, brownout, or sudden outage with no UPS at all.

If your area has frequent or long outages, size your UPS to give yourself time to shut down manually from the StartOS UI before the battery runs out.

> [!NOTE]
> If a backup is running when you do, StartOS offers to wait for the backup to finish and takes that option if you do not choose within 30 seconds — which on battery is rarely what you want. Choose `Shut down now` instead. The server's physical power button waits for the backup when StartOS can intercept the key, so on battery use the web UI rather than the button.
4 changes: 2 additions & 2 deletions projects/start-os/man/start-container.1
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
.ie \n(.g .ds Aq \(aq
.el .ds Aq '
.TH start-container 1 "start-container 0.4.0.2"
.TH start-container 1 "start-container 0.4.0.3"
.SH NAME
start\-container
.SH SYNOPSIS
Expand Down Expand Up @@ -56,4 +56,4 @@ start\-container\-shutdown(1)
.TP
start\-container\-subcontainer(1)
.SH VERSION
v0.4.0.2
v0.4.0.3
7 changes: 7 additions & 0 deletions projects/start-os/release-notes/0.4.0.3.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,7 @@
**0.4.0.3 lets your server finish a backup before restarting or shutting down.**

## Highlights

- **Restart or shut down after a backup finishes.** During a backup, the UI offers to wait and selects that option after a countdown. A bar shows the pending action and lets you cancel it. Pressing the physical power button also waits for the backup when StartOS can intercept the key. StartOS refuses new backups once a restart or shutdown is committed. See [Creating Backups](https://docs.start9.com/start-os/backup-create.html).
- **CLI restart and shutdown wait for a running backup by default.** Use `start-cli server restart` or `start-cli server shutdown`; add `--force` to interrupt the backup. Cancel a pending action with `start-cli server cancel-deferred-power`.
- **Interrupted operations stop appearing active after the StartOS daemon restarts.** Backup, update, restart, and shutdown indicators reset, along with any pending power action.
15 changes: 3 additions & 12 deletions projects/start-os/startos-restart.service
Original file line number Diff line number Diff line change
@@ -1,17 +1,7 @@
[Unit]
Description=StartOS graceful restart
# Reboot/kexec counterpart of startos-shutdown.service (see its comment).
DefaultDependencies=no
# Conflicts= selects reboot (not poweroff). The ExecStop graceful teardown
# (start-cli server restart -> startd shutdown_all -> per-container Exit RPC +
# lxc-stop) must run while startd and the containers are still up, exactly like a
# manual `start-cli server restart`. A unit ordered After=X is stopped *before* X
# on shutdown, so these two hold until the teardown has finished:
# startd.service - startd must be alive to service the RPC
# lxc.service / lxc-monitord.service - lxc.service's ExecStop is `lxc-containers
# stop`; unordered, it kills the container
# before the Exit RPC ("ungracefully dropped")
# Ordering only; Conflicts= stays the sole reboot-vs-poweroff selector.
# Stop before startd and LXC to finish graceful container teardown.
After=startd.service lxc.service lxc-monitord.service
Before=shutdown.target reboot.target kexec.target
Conflicts=reboot.target kexec.target
Expand All @@ -20,7 +10,8 @@ Conflicts=reboot.target kexec.target
Type=oneshot
RemainAfterExit=yes
ExecStart=/bin/true
ExecStop=/usr/bin/start-cli server restart
# A systemd shutdown transaction cannot wait for a backup.
ExecStop=/usr/bin/start-cli server restart --force
TimeoutStopSec=120

[Install]
Expand Down
Loading
Loading