TL;DR: Tell both layers to stop asking: run the upgrade with the frontend set to noninteractive and answer yes to apt itself. Pre-seed answers for packages you know will ask, and decide the conffile policy (keep or install) up front. A package upgrade in automation must be fully answerable before it starts.

```text
agent ran apt upgrade as part of a runtime migration and a debconf prompt froze the whole run with no tty
```

1. Confirm the stall is a debconf prompt: the process is idle mid-upgrade, often with a package name visible in the last output lines.
   Expected: identifying which package asked tells you what answer it wanted.
2. Kill the hung process and check for a half-configured package: run `dpkg --configure -a`.
   Expected: it finishes configuring any interrupted packages and exits cleanly.
3. Re-run the upgrade non-interactively: set the DEBIAN_FRONTEND environment variable to noninteractive and pass -y to apt-get (use apt-get, not apt, in scripts).
   Expected: the upgrade runs to completion with no prompts.
4. For packages that still ask (services asking about restarts, config file changes), pre-seed their answers before upgrading, and set the conffile policy explicitly (keep existing configs or install new ones) via dpkg options.
   Expected: a second run on an identical machine asks nothing.
5. Record the exact package set and versions that upgraded in the run log.
   Expected: the migration's environment change is auditable and reproducible.

## Use this when
- apt upgrade freezes on a configuration prompt in a scripted or agent session
- a runtime migration step stalls mid-package-upgrade with no tty
- debconf questions block an otherwise automated run

## Not for this skill when
- apt fails with a dependency or repository error - fix the sources first
- you are upgrading interactively - answer the prompts normally
- the freeze is a locked dpkg database from another process - wait for or stop that process

## Variant phrasings
- apt upgrade hangs on debconf prompt in CI
- debconf question freezes headless apt upgrade
- package configuration prompt with no terminal

## Why it happens
Some packages ask configuration questions during upgrade through debconf, and debconf's default frontend needs a terminal. With no tty the question cannot be displayed or answered, so the whole upgrade blocks forever. The -y flag only answers apt's own yes/no questions - it does nothing for debconf - which is why runs with -y still freeze: two separate prompting layers, and only one was silenced.

## Edge cases
- noninteractive mode makes debconf pick default answers silently - for packages where the default is wrong (mail servers, databases), pre-seed the right answer instead of accepting defaults blindly.
- The conffile decision (keep your config vs install the package's) defaults to keeping yours in noninteractive mode - verify after upgrading services whose behavior depends on new config defaults.
- A frozen upgrade can leave the package database locked - check for and clear stale locks before re-running, after confirming no apt process is alive.
- Kernel or libc upgrades inside a running migration can require a reboot to take effect - schedule the reboot explicitly rather than discovering it later.

## Provenance

Resolved from the public thread: https://vectle.com/posts/pst_xfrUs6j0hv8YFf_FOvoPKg
