How do I disable the failing service from being started in the preloaded VM? Shouldn’t the service rules from the template be applied to the preload VM?
The correct fix is that trezord do no start so early or after some other unit has started, adjusted with Requires= or After=.
Yes, please share the contents of trezord.service:
systemctl cat trezord.service
Please add this line inside the if statement:
LC_ALL=C TERM=dumb journalctl -xeu trezord.service
# /usr/lib/systemd/system/trezord.service
[Unit]
Description=Trezor Bridge
After=network.target
[Service]
Type=simple
ExecStart=/usr/bin/trezord
User=trezord
[Install]
WantedBy=multi-user.target
# /usr/lib/systemd/system/service.d/10-timeout-abort.conf
# This file is part of the systemd package.
# See https://fedoraproject.org/wiki/Changes/Shorter_Shutdown_Timer.
#
# To facilitate debugging when a service fails to stop cleanly,
# TimeoutStopFailureMode=abort is set to "crash" services that fail to stop in
# the time allotted. This will cause the service to be terminated with SIGABRT
# and a coredump to be generated.
#
# To undo this configuration change, create a mask file:
# sudo mkdir -p /etc/systemd/system/service.d
# sudo ln -sv /dev/null /etc/systemd/system/service.d/10-timeout-abort.conf
[Service]
TimeoutStopFailureMode=abort
Apr 18 04:57:56 dom0 qubesd[243352]: ERROR: vm.disp2151: Start failed: Error on call to 'qubes.WaitForRunningSystem' during preload startup: Command 'qubes.WaitForRunningSystem' returned non-zero exit status 1., stderr="+ set -eu_+ rc=0_+ systemctl --wait is-system-running_degraded_+ rc=1_+ test 1 -gt 0_+ LC_ALL=C_+ TERM=dumb_+ systemctl --failed --legend=no_* trezord.service loaded failed failed Trezor Bridge_+ LC_ALL=C_+ TERM=dumb_+ journalctl -xeu trezord.service_Hint: You are currently not seeing messages from other users and the system._ Users in groups 'adm', 'systemd-journal', 'wheel' can see all messages._ Pass -q to turn off this notice._+ exit 1_", stdout='-- No entries --_'. To debug, disable preloading from 'fedora-dvm' and run the following on a new disposable: systemctl --failed
Doesn’t seem to be a very helpful error message ![]()
Add sudo journalctl …
Apr 18 13:30:39 dom0 qubesd[243352]: ERROR: vm.disp6096: Start failed: Error on call to 'qubes.WaitForRunningSystem' during preload startup: Command 'qubes.WaitForRunningSystem' returned non-zero exit status 1., stderr='+ set -eu_+ rc=0_+ systemctl --wait is-system-running_degraded_+ rc=1_+ test 1 -gt 0_+ LC_ALL=C_+ TERM=dumb_+ systemctl --failed --legend=no_* trezord.service loaded failed failed Trezor Bridge_+ LC_ALL=C_+ TERM=dumb_+ sudo journalctl -xeu trezord.service_+ exit 1_', stdout="Apr 18 13:30:34 disp6096 systemd[1]: Started trezord.service - Trezor Bridge._-- Subject: A start job for unit trezord.service has finished successfully_-- Defined-By: systemd_-- Support: https://lists.freedesktop.org/mailman/listinfo/systemd-devel_-- _-- A start job for unit trezord.service has finished successfully._-- _-- The job identifier is 156._Apr 18 13:30:34 disp6096 trezord[570]: 2026/04/18 13:30:34 trezord v2.0.27 is starting._Apr 18 13:30:34 disp6096 trezord[570]: 2026/04/18 13:30:34 libusb: error when initializing LibUSB._Apr 18 13:30:34 disp6096 trezord[570]: If you run trezord in an environment without USB (for example, docker or travis), use '-u=false'. For example, './trezord-go -e 21324 -u=false'._Apr 18 13:30:34 disp6096 trezord[570]: Original error: LIBUSB_ERROR_OTHER_Apr 18 13:30:34 disp6096 systemd[1]: trezord.service: Main process exited, code=exited, status=1/FAILURE_-- Subject: Unit process exited_-- Defined-By: systemd_-- Support: https://lists.freedesktop.org/mailman/listinfo/systemd-devel_-- _-- An ExecStart= process belonging to unit trezord.service has exited._-- _-- The process' exit code is 'exited' and its exit status is 1._Apr 18 13:30:34 disp6096 systemd[1]: trezord.service: Failed with result 'exit-code'._-- Subject: Unit failed_-- Defined-By: systemd_-- Support: https://lists.freedesktop.org/mailman/listinfo/systemd-devel_-- _-- The unit trezord.service has entered the 'failed' state with result 'exit-code'._". To debug, disable preloading from 'fedora-dvm' and run the following on a new disposable: systemctl --failed
So something about USB is causing the service to fail. That’s fine, the VM is not sys-usb so it doesn’t matter. The problem is that the service is being started at all. The service is never needed in this VM, so it shouldn’t even start.
Modify the trezord.service on the template to have this line in the unit section:
https://github.com/QubesOS/qubes-core-agent-linux/blob/main/vm-systemd/crond.service.d/30_qubes.conf
Modify the path from crond to trezord. Then, for the qube that you need that service to run:
qvm-features QUBE service.trezord 1
And try to preload again and try to use trezord on the qube that you need it.
Great, that fixed it. I didn’t realise complying with VM service settings was totally optional and a missing line from the .service file would cause the service to ignore those settings.