LUKS encrypted /var and cycled systems dependencies

A recent update has introduced a regression I think with systemd whereby a LUKS encrypted /var (separate from root) can result in failed boots. This is due to a cyclic dependency between units involving systemd-tpm2-setup.service.

This took me way longer to root cause than I care to admit so sharing here for visibility. It might save others some time in troubleshooting.

How broken was your setup? Were you able to just select the previous bootc-record or did you need some more advanced solution to get your system bootable again?

Both my bootc-records were impacted. Here’s why…

On each boot systemd would detect the cyclic dependency and attempt to resolve the issue by simply picking a random unit to ignore.

So when it first started to occur I noticed that just rebooting would result in a successful boot sometimes. I assumed it was a flakey disk and even reseated the disks. Because I just rebooted until I got lucky again I ended up with both the bootc entries having the bad update.