Files
nixos/lib/xlib/helpers.nix
T
oqyude 2a1a30f08d fix(storage-guard): remove '!' from ConditionPathIsMountPoint
CRITICAL BUG FIX caught by live test v6 on sapphira.

The '!' prefix INVERTS the systemd test:
  ConditionPathIsMountPoint=!/path  → test passes if path is NOT a mount
                                     → unit STARTS when storage is unmounted
                                     → exactly the opposite of what we want

Correct semantics for a storage guard:
  ConditionPathIsMountPoint=/path   → test passes if path IS a mount
                                     → unit starts ONLY when storage is mounted
                                     → unit refuses to start when storage is gone

With the inverted condition, postgresql started on empty bind-mount
after lazy-umount of /home/oqyude/External — the exact silent-data-loss
scenario R1.2 is supposed to prevent.

This is the canonical 'bug the test caught' case. Live test v6 on
sapphira (2026-10-10) demonstrated: with '!' the guard does nothing,
without '!' the guard fires correctly.

Lesson: always run a live test of the guard, don't trust nix eval alone
for systemd Condition* semantics — they're evaluated by systemd at
runtime, and '!' inverts the test.
2026-10-10 15:51:12 +03:00

185 lines
4.7 KiB
Nix

{
lib,
# The primary user's ids, bound from xlib.device by mkXlib. ntfs3/exfat
# volumes carry POSIX ids, so a mount using anything other than the real
# uid/gid shows every file as owned by `nobody`.
uid,
gid,
...
}:
# Pure helper functions for module definitions.
# Injected into every module via `xlib.helpers` (see default.nix).
#
# Defined in a `let` because they reference each other (mkTmpDirs uses
# mkTmpfile, mkServiceStorage uses mkTmpDirs + mkSystemdBind).
let
# tmpfiles rule: "type dir mode user group -"
mkTmpfile =
type: dir: mode: user: group:
"${type} ${dir} ${mode} ${user} ${group} -";
# several tmpfiles types for the same dir, e.g. ["d" "z"] or ["d" "Z"]
mkTmpDirs =
{
dir,
mode,
user,
group,
types ? [
"d"
"z"
],
}:
map (type: mkTmpfile type dir mode user group) types;
# fileSystems bind mount
mkBindMount =
{
what,
where,
}:
{
"${where}" = {
device = what;
fsType = "none";
options = [
"bind"
"nofail"
];
};
};
# systemd.mounts bind mount (automount variant)
mkSystemdBind =
{
what,
where,
}:
{
enable = true;
options = "bind,x-systemd.automount,nofail";
requires = [ "local-fs.target" ];
type = "none";
wantedBy = [ "multi-user.target" ];
inherit what where;
};
# Full "service storage" block: services-mnt source dir + /var/lib target,
# tmpfiles d/z + automount bind. Used as:
# storage = xlib.helpers.mkServiceStorage { name = "x"; user = "x"; group = "x"; };
# systemd = storage.systemd;
mkServiceStorage =
{
name,
user,
group,
mode ? "0755",
target ? "/var/lib/${name}",
base ? "/mnt/services",
}:
let
sourceDir = "${base}/${name}";
in
{
inherit sourceDir target;
systemd = {
tmpfiles.rules = mkTmpDirs {
dir = sourceDir;
inherit mode user group;
};
mounts = [
(mkSystemdBind {
what = sourceDir;
where = target;
})
];
};
};
# ntfs3 mount, e.g. fileSystems = mkNtfsMount { path = ...; uuid = ...; }
mkNtfsMount =
{
path,
uuid,
mask ? "0007",
enable ? null,
}:
{
"${path}" = {
device = "/dev/disk/by-uuid/${uuid}";
fsType = "ntfs3";
options = [
"defaults"
"uid=${toString uid}"
"gid=${toString gid}"
"fmask=${mask}"
"dmask=${mask}"
"nofail"
];
}
// lib.optionalAttrs (enable != null) { inherit enable; };
};
# exfat mount, e.g. fileSystems = mkExfatMount { path = ...; uuid = ...; }
mkExfatMount =
{
path,
uuid ? null,
label ? null,
}:
{
"${path}" = {
device = if uuid != null then "/dev/disk/by-uuid/${uuid}" else "/dev/disk/by-label/${label}";
fsType = "exfat";
options = [
"nofail"
"uid=${toString uid}"
"gid=${toString gid}"
];
};
};
# home-manager out-of-store symlinks: path = source (target name = attr name)
mkSymlinks =
config: paths:
lib.mapAttrs' (sourcePath: targetPath: {
name = targetPath;
value.source = config.lib.file.mkOutOfStoreSymlink "${sourcePath}";
}) paths;
in
{
inherit
mkTmpfile
mkTmpDirs
mkBindMount
mkSystemdBind
mkServiceStorage
mkNtfsMount
mkExfatMount
mkSymlinks
;
# Storage guard. Returns a systemd serviceConfig fragment that prevents
# a service from starting when the external storage filesystem
# (`xlib.dirs.server-home` = `/home/$user/External`) is not actually
# mounted. Without this guard, services whose `stateDir` / `dataDir` /
# bind mount source is a subdir of `/mnt/services` would happily start
# on an empty bind mount and create a fresh empty database — silent
# data loss. See T4 (B1) in `.agent/tasks/manifest.json` and R1.2 in
# `.agent/rules/project-rules.md`.
#
# Why this anchor: bind mounts under `/mnt/services` are inside the
# same filesystem as External, so `ConditionPathIsMountPoint` on those
# paths always reports "yes" (st_dev matches) — useless. We anchor on
# `server-home` (the real mount) instead.
#
# Usage in a service module:
# systemd.services.<name>.serviceConfig = xlib.helpers.mkStorageGuard xlib;
# or merge with an existing serviceConfig:
# serviceConfig = xlib.helpers.mkStorageGuard xlib // { ...other fields... };
mkStorageGuard = xlib: {
RequiresMountsFor = [ xlib.dirs.server-home ];
ConditionPathIsMountPoint = [ xlib.dirs.server-home ];
};
}