v0.84.0: ReassertNetworkMounts — NAS automount survives guest reboots (RCA fix 1)
Storage §8 decision table (stop + enable --now on idle triggers; active mounts untouched), daemon leg at startup with per-running-guest visibility verify, guest-hook post-start leg (root, direct systemctl, non-fatal). Red-proofs: always-rearm table FAIL; unwired hook FAIL. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01PSK5g6qYLknKj8u3QAFEr6
This commit is contained in:
@@ -0,0 +1,81 @@
|
||||
package guesthook
|
||||
|
||||
import (
|
||||
"context"
|
||||
"fmt"
|
||||
"log/slog"
|
||||
"os"
|
||||
"strings"
|
||||
|
||||
"gitea.dooplex.hu/admin/felhom-agent/internal/proxmox"
|
||||
"gitea.dooplex.hu/admin/felhom-agent/internal/storage"
|
||||
)
|
||||
|
||||
// post-start network-storage reassert (RCA AUDIT-nas-cwa-rca-2026-07-11 fix 1, hook leg).
|
||||
//
|
||||
// A freshly started guest's namespace does NOT inherit an idle NAS autofs trigger (only real
|
||||
// mounts), so its /mnt/felhom-drives/<share> path is a silent local stub until the trigger is
|
||||
// re-created host-side. PVE runs the hookscript as root in the start task, so this leg calls
|
||||
// systemctl DIRECTLY (no sudo) — the daemon leg (localapi.ReassertNetworkMounts) is the sudo path.
|
||||
// Like the pre-start heal, this must NEVER fail the hook: all errors go to stderr (the PVE task
|
||||
// log) and the guest start proceeds regardless.
|
||||
|
||||
// netReasserter is the reassert capability (satisfied by *storage.SudoHostOps; faked in tests).
|
||||
type netReasserter interface {
|
||||
ReassertNetworkAutomounts(ctx context.Context) []storage.NetReassertResult
|
||||
}
|
||||
|
||||
// PostStartNetworkReassert re-arms idle NAS automount triggers after vmid started, then verifies
|
||||
// the (now running) guest actually sees each share path. Best-effort throughout.
|
||||
func PostStartNetworkReassert(ctx context.Context, vmid string) {
|
||||
runner := &proxmox.ExecRunner{Mode: proxmox.RunnerDirect}
|
||||
ops := storage.NewSudoHostOps(storage.SudoHostOpsConfig{
|
||||
Runner: runner,
|
||||
Logger: slog.New(slog.NewTextHandler(os.Stderr, &slog.HandlerOptions{Level: slog.LevelInfo})),
|
||||
})
|
||||
postStartNetworkReassert(ctx, vmid, ops, func(ctx context.Context, vmid, path string) bool {
|
||||
return GuestSeesPath(ctx, runner, vmid, path)
|
||||
})
|
||||
}
|
||||
|
||||
// postStartNetworkReassert is the seam-injected core (unit-tested; the wrapper above binds the
|
||||
// real host surface).
|
||||
func postStartNetworkReassert(ctx context.Context, vmid string, ops netReasserter, sees func(ctx context.Context, vmid, path string) bool) {
|
||||
for _, res := range ops.ReassertNetworkAutomounts(ctx) {
|
||||
if res.Err != nil || res.Action == storage.NetReassertSkipNone {
|
||||
continue // already reported by the ops logger / nothing expected in the guest
|
||||
}
|
||||
if sees(ctx, vmid, res.Where) {
|
||||
fmt.Fprintf(os.Stderr, "felhom-agent guest-hook: vmid %s post-start — network share %s visible in guest (%s)\n",
|
||||
vmid, res.Name, res.Action)
|
||||
} else {
|
||||
fmt.Fprintf(os.Stderr, "felhom-agent guest-hook: vmid %s post-start — WARNING: network share %s NOT visible in guest after reassert (%s)\n",
|
||||
vmid, res.Name, res.Action)
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
// GuestSeesPath reports whether vmid's guest has `path` as a mount target in its own namespace —
|
||||
// the hook-process mirror of localapi's GuestBinder.GuestSeesMount (which is method-bound to the
|
||||
// daemon's binder and unavailable here). Resolution/read errors → false.
|
||||
func GuestSeesPath(ctx context.Context, runner proxmox.Runner, vmid, path string) bool {
|
||||
out, _, err := runner.Run(ctx, "lxc-info", "-n", vmid, "-p", "-H")
|
||||
if err != nil {
|
||||
return false
|
||||
}
|
||||
pid := strings.TrimSpace(string(out))
|
||||
if pid == "" {
|
||||
return false
|
||||
}
|
||||
data, err := os.ReadFile("/proc/" + pid + "/mountinfo")
|
||||
if err != nil {
|
||||
return false
|
||||
}
|
||||
for _, line := range strings.Split(string(data), "\n") {
|
||||
f := strings.Fields(line)
|
||||
if len(f) >= 5 && f[4] == path {
|
||||
return true
|
||||
}
|
||||
}
|
||||
return false
|
||||
}
|
||||
Reference in New Issue
Block a user