After the Zeus uprev, we have a forward seal failure for the same reason as described here: https://github.com/OpenXT/xenclient-oe/pull/1144 When `seal-system /dev/xenclient/root` is called, /dev/xenclient/root is pointing at /dev/dm-6 which is block node 253 6, the same as /dev/mapper/xenclient-root.old. The old binaries are used for foward sealing.
A band-aid could be to change the forward seal to use /dev/mapper/xenclient-root.
A better solution may be to run udev in the initramfs. That creates both /dev/mapper and /dev/xenclient entries as symlinks to ../dm-. A quick test of adding initramfs-module-udev to xenclient-initramfs-image and dropping the xenclient-oe lvm override booted with the dm- symlinks.
If switching to udev in the initramfs, care must be taken to preserve existing behaviour to skip loading of usb controllers and other customization.
OTA and have forward seal work properly - reboot without a re-seal dialog.