mirror of
https://github.com/oqyude/nixos.git
synced 2026-10-11 14:27:26 +03:00
fix(storage-guard): remove RequiresMountsFor — was causing auto-remount
CRITICAL BUG #2 in storage guard, caught by live test v8 on sapphira (2026-10-10). RequiresMountsFor=/home/ooyude/External in the unit file told systemd that the service depends on the mount. When the mount was gone and the service was started, systemd's dependency resolver AUTOMATICALLY REMOUNTED the filesystem to satisfy the dependency — THEN checked ConditionPathIsMountPoint. The condition saw the just-remounted filesystem and evaluated to true. Service started on empty external storage. Guard completely bypassed. This is a subtle interaction: - ConditionPathIsMountPoint is a TEST (true/false evaluation) - RequiresMountsFor is a DEPENDENCY (systemd must make it true) A guard should be a TEST, not a dependency that makes the test trivially pass. Remove the dependency. The condition alone is sufficient for both boot-time and runtime checks: - Boot: mount unit starts via local-fs.target, condition is true - Runtime: if mount disappears, condition becomes false on next start attempt. Without RequiresMountsFor, systemd doesn't auto-recover, so the guard fires. Ordering should be expressed via After= in the consumer's systemd.services block (not in the shared helper), e.g.: systemd.services.postgresql.after = [ "home-ooyude-External.mount" ]; Live test v8 sequence (before this fix): 1. umount /home/ooyude/External → OK, gone from /proc/mounts 2. findmnt /home/ooyude/External → exit=1, not in table 3. systemctl start postgresql → STARTED (guard bypassed) 4. journal: no ConditionPath error (service started successfully) This is the second guard bug found by live testing in this session. The first one was the '!' prefix inversion. Both were invisible to nix eval, both only visible at runtime. Lesson reinforced: guards MUST be live-tested, not just statically evaluated. Recovery: v8 test reverted state via emergency_recovery trap (remount + restart all services). System healthy at 10/10.
This commit is contained in:
@@ -178,7 +178,13 @@ in
|
|||||||
# or merge with an existing serviceConfig:
|
# or merge with an existing serviceConfig:
|
||||||
# serviceConfig = xlib.helpers.mkStorageGuard xlib // { ...other fields... };
|
# serviceConfig = xlib.helpers.mkStorageGuard xlib // { ...other fields... };
|
||||||
mkStorageGuard = xlib: {
|
mkStorageGuard = xlib: {
|
||||||
RequiresMountsFor = [ xlib.dirs.server-home ];
|
# Guard via ConditionPathIsMountPoint ONLY. We intentionally do
|
||||||
|
# NOT add RequiresMountsFor: that creates a dependency that causes
|
||||||
|
# systemd to auto-remount the filesystem when starting the unit,
|
||||||
|
# which defeats the guard (tested and confirmed: v8 test on
|
||||||
|
# sapphira, 2026-10-10). Ordering should be expressed via After=
|
||||||
|
# on the .mount unit in the consumer's systemd.services block,
|
||||||
|
# not via a guard-creating dependency here.
|
||||||
ConditionPathIsMountPoint = [ xlib.dirs.server-home ];
|
ConditionPathIsMountPoint = [ xlib.dirs.server-home ];
|
||||||
};
|
};
|
||||||
}
|
}
|
||||||
|
|||||||
Reference in New Issue
Block a user