Skip to content

fix(start-core): refuse a dependency mount whose volume does not exist - #3961

Merged
dr-bonez merged 1 commit into
masterfrom
fix/pointer-mount-missing-volume
Sep 16, 2026
Merged

dr-bonez merged 1 commit into
masterfrom
fix/pointer-mount-missing-volume

Conversation

@MattDHill

Copy link
Copy Markdown
Member

Summary

  • A read-write mountDependency of a dependency that isn't installed used to succeed: Bind::pre_mount creates a missing source for read-write binds (disk/mount/filesystem/bind.rs), so the pointer-mount effect (service/effects/dependency.rs::mount) created volumes/<dep>/data/<vol> on the host as a plain directory and bound it. The dependent started against an empty folder; the only signal was the dependency warning.
  • Worse, when the dependency was installed afterwards, ensure_volume_root (volume.rs) found the directory present and adopted it as the live root — a plain directory, not a btrfs subvolume — so InstallBackup::snapshot returns false for that package and updates get no rollback point.
  • The effect now checks that the dependency's volume root exists and otherwise fails with a localized NotFound naming the package and volume, which is what a read-only mount already did (no source is created for those, so mount --rbind failed). A missing subpath inside an existing volume is still created for read-write mounts, as before.
  • StartOS changelog entry; the SDK guide's Mounting Dependency Volumes section and the mountDependency doc comment state the failure mode.

Observed

On the dev box with paperless-startos (Start9-Community/paperless-startos#9) pointing its consume folder at FileBrowser Quantum's data volume: uninstall FileBrowser, start Paperless → it starts, and inside the container /mnt/filebrowser is a fresh empty directory on the package-data filesystem (subvol=/, i.e. not a volume subvolume) — volumes/filebrowser/ now exists on the host with no package owning it.

Not built locally (start-core); CI does that.

🤖 Generated with Claude Code

`Bind::pre_mount` creates a missing source for a read-write bind, which is
right for a package's own subpaths but wrong for a pointer mount: with the
dependency not installed, the effect created `volumes/<dep>/data/<vol>` on the
host as a plain directory and bound it, so the dependent started against an
empty folder with only the dependency warning to say so. When the dependency
was installed later, `ensure_volume_root` adopted that orphan as its live root,
leaving it a directory rather than a subvolume — so `InstallBackup::snapshot`
has nothing to snapshot and the package gets no rollback point on update.

The mount now fails with a localized error naming the missing volume when the
dependency's volume root does not exist, matching what a read-only mount
already did. A missing subpath inside an existing volume is still created for
a read-write mount.

Observed with paperless-startos pointing its consume folder at a FileBrowser
Quantum that had been uninstalled.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@dr-bonez
dr-bonez merged commit 4989ed8 into master Sep 16, 2026
32 checks passed
@dr-bonez
dr-bonez deleted the fix/pointer-mount-missing-volume branch September 16, 2026 16:29
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants