hasNextcloudApp (startos/utils.ts:19) decides an app is present by looking for its directory. A major Nextcloud upgrade is exactly the event that disables an incompatible app while leaving its files on disk, so after one the check returns true for apps that are no longer usable.
Upstream's entrypoint.sh confirms occ upgrade auto-disables incompatible apps — it diffs get_enabled_apps before and after and prints "The following apps have been disabled". Of the 457 apps with a Nextcloud 33 release on apps.nextcloud.com, 63 have no 34 release.
Concrete failure, with Talk and the Coturn relay turned on: after the upgrade spreed is disabled but custom_apps/spreed remains, so hasNextcloudApp(TALK_APP) passes and the talk-turn oneshot proceeds. occ talk:turn:add then exits non-zero because the app is disabled, allOk stays false, and talkTurnConfigured is never recorded. The relay silently stops being applied; the only signal is a console.error in the service log, and the oneshot re-runs on every subsequent chain build. The three App Commands actions have the same shape via requireNextcloudApp.
The retry behaviour is already acknowledged at startos/main.ts:814. What changes is that a major upgrade makes the disabled-but-present state normal rather than rare, for a window that lasts until the user updates each app.
Checking enablement rather than presence — occ app:list --enabled --output=json, which disableUnstableApps.ts already runs — would distinguish the two states.
Found while reviewing #131.
hasNextcloudApp(startos/utils.ts:19) decides an app is present by looking for its directory. A major Nextcloud upgrade is exactly the event that disables an incompatible app while leaving its files on disk, so after one the check returns true for apps that are no longer usable.Upstream's
entrypoint.shconfirmsocc upgradeauto-disables incompatible apps — it diffsget_enabled_appsbefore and after and prints "The following apps have been disabled". Of the 457 apps with a Nextcloud 33 release onapps.nextcloud.com, 63 have no 34 release.Concrete failure, with Talk and the Coturn relay turned on: after the upgrade
spreedis disabled butcustom_apps/spreedremains, sohasNextcloudApp(TALK_APP)passes and thetalk-turnoneshot proceeds.occ talk:turn:addthen exits non-zero because the app is disabled,allOkstays false, andtalkTurnConfiguredis never recorded. The relay silently stops being applied; the only signal is aconsole.errorin the service log, and the oneshot re-runs on every subsequent chain build. The three App Commands actions have the same shape viarequireNextcloudApp.The retry behaviour is already acknowledged at
startos/main.ts:814. What changes is that a major upgrade makes the disabled-but-present state normal rather than rare, for a window that lasts until the user updates each app.Checking enablement rather than presence —
occ app:list --enabled --output=json, whichdisableUnstableApps.tsalready runs — would distinguish the two states.Found while reviewing #131.