From 2a1a30f08d53072733fa3c585c6e1a4b166350f6 Mon Sep 17 00:00:00 2001 From: oqyude Date: Sat, 10 Oct 2026 15:51:12 +0300 Subject: [PATCH] fix(storage-guard): remove '!' from ConditionPathIsMountPoint MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit CRITICAL BUG FIX caught by live test v6 on sapphira. The '!' prefix INVERTS the systemd test: ConditionPathIsMountPoint=!/path → test passes if path is NOT a mount → unit STARTS when storage is unmounted → exactly the opposite of what we want Correct semantics for a storage guard: ConditionPathIsMountPoint=/path → test passes if path IS a mount → unit starts ONLY when storage is mounted → unit refuses to start when storage is gone With the inverted condition, postgresql started on empty bind-mount after lazy-umount of /home/oqyude/External — the exact silent-data-loss scenario R1.2 is supposed to prevent. This is the canonical 'bug the test caught' case. Live test v6 on sapphira (2026-10-10) demonstrated: with '!' the guard does nothing, without '!' the guard fires correctly. Lesson: always run a live test of the guard, don't trust nix eval alone for systemd Condition* semantics — they're evaluated by systemd at runtime, and '!' inverts the test. --- lib/xlib/helpers.nix | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/lib/xlib/helpers.nix b/lib/xlib/helpers.nix index 79e9cd2..fc4b11b 100644 --- a/lib/xlib/helpers.nix +++ b/lib/xlib/helpers.nix @@ -179,6 +179,6 @@ in # serviceConfig = xlib.helpers.mkStorageGuard xlib // { ...other fields... }; mkStorageGuard = xlib: { RequiresMountsFor = [ xlib.dirs.server-home ]; - ConditionPathIsMountPoint = [ "!${xlib.dirs.server-home}" ]; + ConditionPathIsMountPoint = [ xlib.dirs.server-home ]; }; }