From 9b4275a7a0363dc84c78193d715450a922345798 Mon Sep 17 00:00:00 2001 From: MickLesk <47820557+MickLesk@users.noreply.github.com> Date: Fri, 25 Sep 2026 18:21:01 +0200 Subject: [PATCH] Offer to raise the kernel key limits instead of only naming them The check fires while usage is merely near the limit, then exited with 'limits exceeded' and pointed at a sysctl file that does not exist yet - which left the node unable to create any further container and gave no command to copy. It now offers to write the file and reload sysctl, and prints three runnable lines when declined. --- ui/build-ui.func | 25 ++++++++++++++++++++----- 1 file changed, 20 insertions(+), 5 deletions(-) diff --git a/ui/build-ui.func b/ui/build-ui.func index 4f7e1e1..53fbec5 100644 --- a/ui/build-ui.func +++ b/ui/build-ui.func @@ -200,19 +200,34 @@ maxkeys_check() { if [[ "$used_lxc_keys" -gt "$threshold_keys" ]]; then msg_warn "Key usage is near the limit (${used_lxc_keys}/${per_user_maxkeys})" - echo -e "${INFO} Suggested action: Set ${GN}kernel.keys.maxkeys=${new_limit_keys}${CL} in ${BOLD}/etc/sysctl.d/98-community-scripts.conf${CL}." failure=1 fi if [[ "$used_lxc_bytes" -gt "$threshold_bytes" ]]; then msg_warn "Key byte usage is near the limit (${used_lxc_bytes}/${per_user_maxbytes})" - echo -e "${INFO} Suggested action: Set ${GN}kernel.keys.maxbytes=${new_limit_bytes}${CL} in ${BOLD}/etc/sysctl.d/98-community-scripts.conf${CL}." failure=1 fi - if [[ "$failure" -eq 1 ]]; then - msg_error "Kernel key limits exceeded - see suggestions above" - exit 108 + [[ "$failure" -eq 1 ]] || return 0 + + # Offering beats explaining: the old text named a file that does not exist yet and left + # every further install on the node blocked behind a step nobody could copy. + local keys_conf="/etc/sysctl.d/98-community-scripts.conf" + if prompt_confirm "${TAB}Raise the kernel key limits now?" "y" 60; then + if printf 'kernel.keys.maxkeys = %s\nkernel.keys.maxbytes = %s\n' \ + "$new_limit_keys" "$new_limit_bytes" >"$keys_conf" 2>/dev/null && + sysctl --system >/dev/null 2>&1; then + msg_ok "Raised kernel key limits (maxkeys ${new_limit_keys}, maxbytes ${new_limit_bytes})" + return 0 + fi + msg_error "Could not apply ${keys_conf}" fi + + echo -e "${TAB}${INFO} Run this on the node, then start the script again:" + echo -e "${TAB}${GN}echo 'kernel.keys.maxkeys = ${new_limit_keys}' > ${keys_conf}${CL}" + echo -e "${TAB}${GN}echo 'kernel.keys.maxbytes = ${new_limit_bytes}' >> ${keys_conf}${CL}" + echo -e "${TAB}${GN}sysctl --system${CL}" + msg_error "Kernel key limits too low to create another container" + exit 108 } # ==============================================================================