fix(start-core): refuse a dependency mount whose volume does not exist - #3961
Merged
Merged
Conversation
`Bind::pre_mount` creates a missing source for a read-write bind, which is right for a package's own subpaths but wrong for a pointer mount: with the dependency not installed, the effect created `volumes/<dep>/data/<vol>` on the host as a plain directory and bound it, so the dependent started against an empty folder with only the dependency warning to say so. When the dependency was installed later, `ensure_volume_root` adopted that orphan as its live root, leaving it a directory rather than a subvolume — so `InstallBackup::snapshot` has nothing to snapshot and the package gets no rollback point on update. The mount now fails with a localized error naming the missing volume when the dependency's volume root does not exist, matching what a read-only mount already did. A missing subpath inside an existing volume is still created for a read-write mount. Observed with paperless-startos pointing its consume folder at a FileBrowser Quantum that had been uninstalled. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
dr-bonez
approved these changes
Sep 16, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
mountDependencyof a dependency that isn't installed used to succeed:Bind::pre_mountcreates a missing source for read-write binds (disk/mount/filesystem/bind.rs), so the pointer-mount effect (service/effects/dependency.rs::mount) createdvolumes/<dep>/data/<vol>on the host as a plain directory and bound it. The dependent started against an empty folder; the only signal was the dependency warning.ensure_volume_root(volume.rs) found the directory present and adopted it as the live root — a plain directory, not a btrfs subvolume — soInstallBackup::snapshotreturns false for that package and updates get no rollback point.NotFoundnaming the package and volume, which is what a read-only mount already did (no source is created for those, somount --rbindfailed). A missingsubpathinside an existing volume is still created for read-write mounts, as before.mountDependencydoc comment state the failure mode.Observed
On the dev box with paperless-startos (Start9-Community/paperless-startos#9) pointing its consume folder at FileBrowser Quantum's
datavolume: uninstall FileBrowser, start Paperless → it starts, and inside the container/mnt/filebrowseris a fresh empty directory on the package-data filesystem (subvol=/, i.e. not a volume subvolume) —volumes/filebrowser/now exists on the host with no package owning it.Not built locally (start-core); CI does that.
🤖 Generated with Claude Code