controller v0.67.0: intermediary-mount — HDD_PATH repoint + drive-absent gate + H1 routes

Drives are visible in-guest only at the STABLE /mnt/felhom-drives/<name>; the
registered path + HDD_PATH + FileBrowser source repoint there while agent calls
map back to raw /mnt/<name> (agentWhere). Enroll binds-under-parent before
register. Drive-absent GATE (planDriveGates + 30s driveGateLoop) stops/blocks
apps when a drive vanishes and auto-restarts on return; start-gate refuses start
when the drive is absent. H1 endpoints (disconnect/reconnect/restart-apps) routed
onto host-side ops. Non-hollow tests + companions.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This commit is contained in:
2026-06-15 16:45:13 +02:00
parent 2687843a83
commit 55c896624f
9 changed files with 467 additions and 17 deletions
+26
View File
@@ -1,5 +1,31 @@
## Changelog
### v0.67.0 — intermediary-mount: HDD_PATH repoint + drive-absent gate + H1 routes (2026-06-15)
Controller half of the intermediary-mount re-architecture (pairs with agent v0.34.0). Drives are now
visible in the guest ONLY at the STABLE path `/mnt/felhom-drives/<name>` (the host swaps the backing
drive underneath it; no per-drive `pct` mp, no guest reboot).
- **Repoint** (`internal/web/intermediary.go`): the registered storage path + every app's HDD_PATH +
FileBrowser source = the stable `/mnt/felhom-drives/<name>` (`stablePathForName`); the AGENT still
operates on the raw `/mnt/<name>` host mount, so controller→agent `where` is mapped back via
`agentWhere()` at the assign/attach/eject/decommission call sites. Enroll now binds-under-the-parent
BEFORE register/skeleton (the controller can only see/write the drive at the stable path post-attach).
`agentapi.DiskInfo` gains `GuestPath` + `BoundUnderParent`. New `settings.RepointStoragePath` for the
migration. FileBrowser + monitoring follow `sp.Path` automatically.
- **Drive-absent GATE**: `ReconcileDriveGates` (pure decision `planDriveGates` + executor) on a 30s loop
(`driveGateLoop`, replacing the retired slice-8C watchdog) — an ABSENT drive's apps are STOPPED +
recorded (`StoppedStacks` = the gate-stopped set, distinct from a user stop); a RETURNED drive is
re-attached under the parent and its gate-stopped apps AUTO-RESTARTED. Start-gate in `actionStack`:
refuses to start an app whose drive is disconnected/decommissioned (clear "tárhely nem elérhető"
message) — so it can't write to the empty fail-closed stable path.
- **H1 endpoints routed** (were 404): `POST /api/storage/{disconnect,reconnect,restart-apps}`
host-side eject/reconnect (stop→agent-detach→fail-close / agent-attach→restart→clear) — no guest
reboot.
Tests (non-hollow + companions): `TestPlanDriveGates` (4 states; trivial impls fail), `TestAgentWhere`
(stable↔raw idempotent mapping), `TestRunStorageInit_Success` (agent gets RAW, registry gets STABLE).
### v0.66.2 — FileBrowser umask 002 (customer folders group-writable) (2026-06-15)
FileBrowser (uid 1000) created folders with umask 022 → mode 2755 (setgid from the parent, but
+8 -1
View File
@@ -251,8 +251,15 @@ type DiskInfo struct {
WipeDurableID string `json:"wipe_durable_id,omitempty"`
// GuestAttached reports whether the drive is actually bound into THIS guest (usable in-guest), as
// opposed to merely present on the host (F9) — the signal whose absence let the HDD look available
// when it wasn't attached.
// when it wasn't attached. LEGACY (per-drive mp model); the intermediary model uses BoundUnderParent.
GuestAttached bool `json:"guest_attached"`
// GuestPath is the drive's STABLE in-guest path in the intermediary-mount model
// (/mnt/felhom-drives/<name>) — what the controller registers + repoints HDD_PATH to. Distinct from
// MountPath (the raw /mnt/<name> host PVE mount the agent ops on). "" for non-user-data drives.
GuestPath string `json:"guest_path,omitempty"`
// BoundUnderParent reports whether the drive's felhom-data is currently bound under the shared parent
// (live + usable in the guest). The controller's drive-absent gate keys on this + State.
BoundUnderParent bool `json:"bound_under_parent"`
}
// FSUUID returns the raw filesystem UUID from a "uuid:<…>" DurableID, or "" if this disk's identity
+33
View File
@@ -414,6 +414,26 @@ func (r *Router) deployStack(w http.ResponseWriter, req *http.Request, name stri
}
}
// startGatedByMissingDrive reports whether starting `name` must be BLOCKED because the drive its
// HDD_PATH points at is currently disconnected or decommissioned. Returns the storage path for the
// message. SSD-resident apps (no HDD_PATH) are never gated.
func (r *Router) startGatedByMissingDrive(name string) (bool, string) {
cfg := r.stackMgr.LoadAppConfigByName(name)
if cfg == nil {
return false, ""
}
hdd := cfg.Env["HDD_PATH"]
if hdd == "" {
return false, ""
}
for _, sp := range r.sett.GetStoragePaths() {
if sp.Path == hdd && (sp.Disconnected || sp.Decommissioned) {
return true, hdd
}
}
return false, ""
}
func (r *Router) actionStack(w http.ResponseWriter, action, name string) {
r.logger.Printf("[INFO] [api] %s requested for stack: %s", action, name)
r.dbg("actionStack: action=%s name=%s", action, name)
@@ -424,6 +444,19 @@ func (r *Router) actionStack(w http.ResponseWriter, action, name string) {
return
}
// Drive-absent gate: refuse to start an app whose data drive is currently disconnected/decommissioned
// (the intermediary-mount gate). Starting it would let it write to the empty fail-closed stable path
// or just crash-loop; block with a clear message until the drive returns (then the gate auto-restarts).
if action == "start" {
if gated, hdd := r.startGatedByMissingDrive(name); gated {
writeJSON(w, http.StatusConflict, apiResponse{
OK: false,
Error: fmt.Sprintf("A(z) %s tárhely jelenleg nem elérhető — az alkalmazás nem indítható, amíg a meghajtó vissza nem csatlakozik.", hdd),
})
return
}
}
// Memory check before starting a stopped app
if action == "start" {
stackMemMB := r.stackMgr.StackMemoryMB(name)
+29
View File
@@ -535,6 +535,35 @@ func (s *Settings) RemoveStoragePath(path string) error {
return s.save()
}
// RepointStoragePath changes a registered path's Path string in place (intermediary-mount migration:
// /mnt/<name> → /mnt/felhom-drives/<name>), preserving all other fields (label, default, schedulable,
// disconnect/decommission state). No-op (nil) if oldPath isn't registered or already equals newPath.
// Errors if newPath collides with a different existing entry.
func (s *Settings) RepointStoragePath(oldPath, newPath string) error {
s.mu.Lock()
defer s.mu.Unlock()
if oldPath == newPath {
return nil
}
idx := -1
for i := range s.StoragePaths {
if s.StoragePaths[i].Path == newPath {
return fmt.Errorf("repoint target %q already registered", newPath)
}
if s.StoragePaths[i].Path == oldPath {
idx = i
}
}
if idx < 0 {
return nil // nothing to repoint
}
s.StoragePaths[idx].Path = newPath
if s.log != nil {
s.log.Printf("[INFO] [settings] Repointed storage path: %s → %s", oldPath, newPath)
}
return s.save()
}
// SetDefaultStoragePath changes which path is the default.
func (s *Settings) SetDefaultStoragePath(path string) error {
s.mu.Lock()
+264
View File
@@ -0,0 +1,264 @@
package web
import (
"context"
"encoding/json"
"net/http"
"path"
"strings"
"time"
"gitea.dooplex.hu/admin/felhom-controller/internal/agentapi"
"gitea.dooplex.hu/admin/felhom-controller/internal/settings"
)
// Intermediary-mount model (controller side). Post-migration a drive is visible in the guest ONLY at its
// STABLE path /mnt/felhom-drives/<name> (the host swaps the backing drive underneath it; see the agent's
// internal/localapi/intermediary.go + SPIKE-intermediary-mount). So:
// - the REGISTERED storage path + every app's HDD_PATH + FileBrowser source = the STABLE path;
// - the AGENT still operates on the RAW /mnt/<name> host PVE mount (assign/attach/eject/decommission),
// so controller→agent `where` is mapped back to raw via agentWhere().
// The drive-absent GATE stops + blocks apps when their drive vanishes and auto-restarts them when it
// returns (host-side, no guest reboot).
// StableParentDir is the permanent in-guest parent the agent binds drives under (mirrors
// localapi.StableParentDir).
const StableParentDir = "/mnt/felhom-drives"
// stablePathForName maps a drive name to its registered stable in-guest path.
func stablePathForName(name string) string { return StableParentDir + "/" + name }
// agentWhere maps a registered storage path — stable /mnt/felhom-drives/<name> OR a legacy raw /mnt/<name>
// — to the RAW /mnt/<name> host mount the agent operates on. Idempotent for an already-raw path
// (path.Base drops the directory either way).
func agentWhere(registeredPath string) string {
name := path.Base(strings.TrimRight(registeredPath, "/"))
if name == "" || name == "." || name == "/" {
return registeredPath
}
return "/mnt/" + name
}
// appsOnStoragePath returns the deployed stack names whose HDD_PATH equals the given (stable) storage
// path — the apps that depend on that drive.
func (s *Server) appsOnStoragePath(storagePath string) []string {
var names []string
for _, st := range s.stackMgr.GetStacks() {
if cfg := s.stackMgr.LoadAppConfigByName(st.Name); cfg != nil && cfg.Env["HDD_PATH"] == storagePath {
names = append(names, st.Name)
}
}
return names
}
// stopAppsOnPath stops every deployed app on the given storage path and returns their names (the
// gate-stopped set — distinct from a user stop, which never enters this set). Best-effort per app.
func (s *Server) stopAppsOnPath(storagePath string) []string {
var stopped []string
for _, name := range s.appsOnStoragePath(storagePath) {
if err := s.stackMgr.StopStack(name); err != nil {
s.logger.Printf("[WARN] [gate] stop %s on absent %s: %v", name, storagePath, err)
continue
}
stopped = append(stopped, name)
}
return stopped
}
// restartStacks starts each named stack (the gate-stopped set on drive return). Best-effort per app.
func (s *Server) restartStacks(names []string) {
for _, name := range names {
if err := s.stackMgr.StartStack(name); err != nil {
s.logger.Printf("[WARN] [gate] restart %s: %v", name, err)
}
}
}
// gateAction is the reconcile's decision for one registered storage path.
type gateAction struct {
Path string
Stop bool // drive ABSENT + not yet marked → stop apps, mark disconnected
Return bool // drive RETURNED (present + currently disconnected) → re-attach, restart, clear
Raw string // raw /mnt/<name> for the re-attach
}
// planDriveGates is the PURE decision core: given the registry + the agent's disk list, decide per path
// whether to gate (stop) or un-gate (return). A drive is "present" iff a disk with a matching GuestPath
// (stable) or MountPath (legacy raw) is State=="attached". Decommissioned paths are skipped (handled by
// the decommission flow, not the transient gate). No side effects → unit-testable.
func planDriveGates(paths []settings.StoragePath, disks []agentapi.DiskInfo) []gateAction {
present := map[string]bool{}
rawByPath := map[string]string{}
for _, d := range disks {
live := d.State == "attached"
if d.GuestPath != "" {
present[d.GuestPath] = present[d.GuestPath] || live
rawByPath[d.GuestPath] = d.MountPath
}
if d.MountPath != "" { // legacy: a raw path registered directly
present[d.MountPath] = present[d.MountPath] || live
rawByPath[d.MountPath] = d.MountPath
}
}
var actions []gateAction
for _, sp := range paths {
if sp.Decommissioned {
continue
}
switch {
case !present[sp.Path] && !sp.Disconnected:
actions = append(actions, gateAction{Path: sp.Path, Stop: true})
case present[sp.Path] && sp.Disconnected:
actions = append(actions, gateAction{Path: sp.Path, Return: true, Raw: rawByPath[sp.Path]})
}
}
return actions
}
// ReconcileDriveGates enforces the drive-absent gate: an ABSENT registered drive gets its apps STOPPED +
// recorded (disconnected); a RETURNED drive gets re-bound under the parent and its gate-stopped apps
// restarted. Best-effort + idempotent — safe to call on a timer and on demand.
func (s *Server) ReconcileDriveGates() {
if s.settings == nil || s.stackMgr == nil {
return
}
agent, err := s.agentClient()
if err != nil {
return
}
ctx, cancel := context.WithTimeout(context.Background(), 15*time.Second)
defer cancel()
resp, err := agent.Disks(ctx)
if err != nil {
return
}
for _, a := range planDriveGates(s.settings.GetStoragePaths(), resp.Disks) {
switch {
case a.Stop:
stopped := s.stopAppsOnPath(a.Path)
if err := s.settings.SetDisconnected(a.Path, true, stopped); err != nil {
s.logger.Printf("[WARN] [gate] mark disconnected %s: %v", a.Path, err)
}
s.logger.Printf("[WARN] [gate] drive ABSENT %s — stopped+blocked %d app(s): %v", a.Path, len(stopped), stopped)
go s.SyncFileBrowserMounts()
case a.Return:
if a.Raw != "" {
if err := agent.GuestAttach(ctx, a.Raw); err != nil {
s.logger.Printf("[WARN] [gate] re-attach %s (raw %s): %v", a.Path, a.Raw, err)
}
}
var stopped []string
for _, sp := range s.settings.GetStoragePaths() {
if sp.Path == a.Path {
stopped = sp.StoppedStacks
}
}
s.restartStacks(stopped)
if err := s.settings.ClearDisconnected(a.Path); err != nil {
s.logger.Printf("[WARN] [gate] clear disconnected %s: %v", a.Path, err)
}
s.logger.Printf("[INFO] [gate] drive RETURNED %s — re-attached + restarted gate-stopped apps", a.Path)
go s.SyncFileBrowserMounts()
}
}
}
// driveGateLoop runs ReconcileDriveGates on a timer (the periodic absent/return detector — the slice-8C
// watchdog was retired). Started as a goroutine at server startup.
func (s *Server) driveGateLoop() {
t := time.NewTicker(30 * time.Second)
defer t.Stop()
for range t.C {
s.ReconcileDriveGates()
}
}
// ---- H1 endpoints (the UI's settings.js calls these; previously 404/unrouted) -----------------
// handleStorageDisconnect EJECTS a drive without restart: stop its apps (gate-stopped), agent-detach the
// felhom-data bind from under the parent (live, fail-closed), and mark it disconnected. The drive is then
// safely removable. POST {where} where = the registered (stable) path.
func (s *Server) handleStorageDisconnect(w http.ResponseWriter, r *http.Request) {
where, ok := s.gateWhere(w, r)
if !ok {
return
}
stopped := s.stopAppsOnPath(where)
agent, err := s.agentClient()
if err == nil {
if _, derr := agent.EjectDisk(r.Context(), agentWhere(where)); derr != nil {
s.logger.Printf("[WARN] [web] disconnect: agent detach %s failed: %v", where, derr)
}
}
if err := s.settings.SetDisconnected(where, true, stopped); err != nil {
writeDiskJSON(w, http.StatusInternalServerError, false, err.Error(), nil)
return
}
go s.SyncFileBrowserMounts()
writeDiskJSON(w, http.StatusOK, true, "", map[string]any{"where": where, "stopped": stopped})
}
// handleStorageReconnect re-attaches a returned drive without restart: agent-attach the felhom-data bind
// under the parent (live), restart the gate-stopped apps, clear the disconnected mark.
func (s *Server) handleStorageReconnect(w http.ResponseWriter, r *http.Request) {
where, ok := s.gateWhere(w, r)
if !ok {
return
}
var stopped []string
for _, sp := range s.settings.GetStoragePaths() {
if sp.Path == where {
stopped = sp.StoppedStacks
}
}
agent, err := s.agentClient()
if err != nil {
writeDiskJSON(w, http.StatusServiceUnavailable, false, err.Error(), nil)
return
}
if aerr := agent.GuestAttach(r.Context(), agentWhere(where)); aerr != nil {
writeDiskJSON(w, http.StatusBadGateway, false, "újracsatolás sikertelen: "+aerr.Error(), nil)
return
}
s.restartStacks(stopped)
if err := s.settings.ClearDisconnected(where); err != nil {
writeDiskJSON(w, http.StatusInternalServerError, false, err.Error(), nil)
return
}
go s.SyncFileBrowserMounts()
writeDiskJSON(w, http.StatusOK, true, "", map[string]any{"where": where, "restarted": stopped})
}
// handleStorageRestartApps restarts the gate-stopped apps on a path (without changing connection state) —
// the manual "restart the apps that were stopped" action.
func (s *Server) handleStorageRestartApps(w http.ResponseWriter, r *http.Request) {
where, ok := s.gateWhere(w, r)
if !ok {
return
}
var stopped []string
for _, sp := range s.settings.GetStoragePaths() {
if sp.Path == where {
stopped = sp.StoppedStacks
}
}
s.restartStacks(stopped)
writeDiskJSON(w, http.StatusOK, true, "", map[string]any{"where": where, "restarted": stopped})
}
// gateWhere decodes + validates the {where} body shared by the H1 endpoints.
func (s *Server) gateWhere(w http.ResponseWriter, r *http.Request) (string, bool) {
var req struct {
Where string `json:"where"`
}
if err := json.NewDecoder(r.Body).Decode(&req); err != nil {
writeDiskJSON(w, http.StatusBadRequest, false, "érvénytelen kérés", nil)
return "", false
}
where := path.Clean(strings.TrimSpace(req.Where))
if where == "" || where == "." || !strings.HasPrefix(where, "/mnt/") {
writeDiskJSON(w, http.StatusBadRequest, false, "érvénytelen csatlakoztatási pont", nil)
return "", false
}
return where, true
}
@@ -0,0 +1,69 @@
package web
import (
"testing"
"gitea.dooplex.hu/admin/felhom-controller/internal/agentapi"
"gitea.dooplex.hu/admin/felhom-controller/internal/settings"
)
func TestAgentWhere(t *testing.T) {
cases := map[string]string{
"/mnt/felhom-drives/felhom-usb": "/mnt/felhom-usb", // stable → raw
"/mnt/felhom-usb": "/mnt/felhom-usb", // legacy raw → raw (idempotent)
"/mnt/felhom-drives/x": "/mnt/x",
}
for in, want := range cases {
if got := agentWhere(in); got != want {
t.Errorf("agentWhere(%q) = %q, want %q", in, got, want)
}
}
}
func TestStablePathForName(t *testing.T) {
if got := stablePathForName("felhom-usb"); got != "/mnt/felhom-drives/felhom-usb" {
t.Errorf("stablePathForName = %q", got)
}
}
// TestPlanDriveGates pins the gate's pure decision across the four meaningful states.
//
// COMPANION GUARD: a trivial impl that gates every absent path regardless of the disconnected flag would
// re-stop an already-disconnected drive (and never return it); one that ignores presence would never
// gate. Both fail here.
func TestPlanDriveGates(t *testing.T) {
paths := []settings.StoragePath{
{Path: "/mnt/felhom-drives/usb"}, // present + connected → no action
{Path: "/mnt/felhom-drives/flash"}, // ABSENT + connected → STOP
{Path: "/mnt/felhom-drives/back", Disconnected: true}, // present + disconnected → RETURN
{Path: "/mnt/felhom-drives/gone", Disconnected: true}, // ABSENT + disconnected → no action (steady)
{Path: "/mnt/felhom-drives/dead", Decommissioned: true}, // decommissioned → never touched
}
disks := []agentapi.DiskInfo{
{MountPath: "/mnt/usb", GuestPath: "/mnt/felhom-drives/usb", State: "attached"},
{MountPath: "/mnt/back", GuestPath: "/mnt/felhom-drives/back", State: "attached"},
// flash + gone + dead report NO present disk
}
actions := map[string]gateAction{}
for _, a := range planDriveGates(paths, disks) {
actions[a.Path] = a
}
if len(actions) != 2 {
t.Fatalf("expected exactly 2 actions (stop flash, return back), got %d: %+v", len(actions), actions)
}
if a, ok := actions["/mnt/felhom-drives/flash"]; !ok || !a.Stop || a.Return {
t.Errorf("flash should STOP (absent+connected): %+v", a)
}
if a, ok := actions["/mnt/felhom-drives/back"]; !ok || !a.Return || a.Stop || a.Raw != "/mnt/back" {
t.Errorf("back should RETURN with raw /mnt/back (present+disconnected): %+v", a)
}
if _, gated := actions["/mnt/felhom-drives/usb"]; gated {
t.Errorf("usb (present+connected) must not be gated")
}
if _, acted := actions["/mnt/felhom-drives/gone"]; acted {
t.Errorf("gone (absent+already-disconnected) is steady — no action")
}
if _, acted := actions["/mnt/felhom-drives/dead"]; acted {
t.Errorf("decommissioned drive must never be gated")
}
}
+4
View File
@@ -104,6 +104,10 @@ func NewServer(cfg *config.Config, stackMgr *stacks.Manager, cpuCollector *syste
s.loadTemplates()
go s.cleanupSessions()
// Drive-absent gate reconcile (intermediary-mount model): the periodic absent/return detector that
// replaced the retired slice-8C watchdog. Stops+blocks apps whose drive vanished, auto-restarts them
// when it returns. No-op when the agent is unreachable.
go s.driveGateLoop()
// Log auth source on startup
if sett != nil && sett.GetPasswordHash() != "" {
+22 -9
View File
@@ -116,15 +116,19 @@ func (s *Server) runStorageInit(ctx context.Context, agent diskAgent, device, fs
if uuid == "" {
return storageInitResult{}, fmt.Errorf("formázás kész, de az új fájlrendszer-azonosító nem feloldható — frissítsen és használja a Csatolás funkciót")
}
// 3. Mount (benign assign) + 4. register.
// 3. Mount (benign assign) at the raw /mnt/<name>. 4. Bind felhom-data under the shared parent FIRST
// (intermediary model) so the drive's STABLE path is live in the guest, THEN register + skeleton there
// (the controller can only see/write the drive at the stable path post-attach). 5. Register the stable
// path — that is what apps' HDD_PATH / FileBrowser / monitoring use.
if err := agent.AssignDisk(ctx, uuid, where, fstype, ""); err != nil {
return storageInitResult{}, fmt.Errorf("csatlakoztatás sikertelen: %w", err)
}
if err := s.registerStoragePath(where, label, setDefault); err != nil {
s.attachIntoGuest(ctx, agent, where)
stable := stablePathForName(path.Base(where))
if err := s.registerStoragePath(stable, label, setDefault); err != nil {
return storageInitResult{}, err
}
s.attachIntoGuest(ctx, agent, where)
return storageInitResult{Registered: true, Where: where}, nil
return storageInitResult{Registered: true, Where: stable}, nil
}
// attachIntoGuest passes an enrolled drive INTO the guest (slice 10 P2) so the controller + apps can
@@ -152,11 +156,12 @@ func (s *Server) runStorageAttach(ctx context.Context, agent diskAgent, device,
if err := agent.AssignDisk(ctx, uuid, where, fstype, ""); err != nil {
return storageInitResult{}, fmt.Errorf("csatlakoztatás sikertelen: %w", err)
}
if err := s.registerStoragePath(where, label, setDefault); err != nil {
s.attachIntoGuest(ctx, agent, where)
stable := stablePathForName(path.Base(where))
if err := s.registerStoragePath(stable, label, setDefault); err != nil {
return storageInitResult{}, err
}
s.attachIntoGuest(ctx, agent, where)
return storageInitResult{Registered: true, Where: where}, nil
return storageInitResult{Registered: true, Where: stable}, nil
}
// pendingActivationDrives returns registered storage paths that are NOT yet live-mounted in this
@@ -288,6 +293,12 @@ func (s *Server) ServeStorageAPI(w http.ResponseWriter, r *http.Request) {
s.handleStorageMigrateStatus(w, r)
case r.URL.Path == "/api/storage/decommission" && r.Method == http.MethodPost:
s.handleStorageDecommission(w, r)
case r.URL.Path == "/api/storage/disconnect" && r.Method == http.MethodPost:
s.handleStorageDisconnect(w, r)
case r.URL.Path == "/api/storage/reconnect" && r.Method == http.MethodPost:
s.handleStorageReconnect(w, r)
case r.URL.Path == "/api/storage/restart-apps" && r.Method == http.MethodPost:
s.handleStorageRestartApps(w, r)
default:
http.NotFound(w, r)
}
@@ -421,7 +432,8 @@ func (s *Server) finalizeDecommissionWith(ctx context.Context, agent diskAgent,
if err := s.settings.SetDecommissioned(where, migratedTo); err != nil {
return fmt.Errorf("nyilvántartás frissítése sikertelen: %w", err)
}
if _, err := agent.Decommission(ctx, where); err != nil {
// Registered path is the STABLE /mnt/felhom-drives/<name>; the agent decommissions the raw mount.
if _, err := agent.Decommission(ctx, agentWhere(where)); err != nil {
return fmt.Errorf("a meghajtó leszerelése sikertelen: %w", err)
}
if s.stackMgr != nil {
@@ -715,7 +727,8 @@ func (s *Server) handleStorageEject(w http.ResponseWriter, r *http.Request) {
writeDiskJSON(w, http.StatusServiceUnavailable, false, err.Error(), nil)
return
}
res, err := agent.EjectDisk(r.Context(), req.Where)
// The registered path is the STABLE /mnt/felhom-drives/<name>; the agent operates on the raw mount.
res, err := agent.EjectDisk(r.Context(), agentWhere(req.Where))
if err != nil {
writeDiskJSON(w, http.StatusBadGateway, false, err.Error(), nil)
return
@@ -168,19 +168,24 @@ func TestRunStorageInit_Success(t *testing.T) {
if err != nil {
t.Fatalf("unexpected error: %v", err)
}
if !res.Registered || res.Where != "/mnt/hdd1" {
t.Fatalf("expected registered at /mnt/hdd1, got %+v", res)
// Intermediary model: the AGENT operates on the RAW /mnt/hdd1 (assign + guest-attach), but the
// REGISTERED path (+ HDD_PATH/FileBrowser) is the STABLE /mnt/felhom-drives/hdd1.
//
// COMPANION GUARD: a pre-fix impl that registered the raw /mnt/hdd1, or that passed the stable path to
// the agent, would fail one of these assertions.
if !res.Registered || res.Where != "/mnt/felhom-drives/hdd1" {
t.Fatalf("expected registered at the STABLE /mnt/felhom-drives/hdd1, got %+v", res)
}
if len(agent.assignCalls) != 1 || agent.assignCalls[0].uuid != "NEW-9999" || agent.assignCalls[0].where != "/mnt/hdd1" {
t.Fatalf("assign must use the resolved fs UUID + mount path: %+v", agent.assignCalls)
t.Fatalf("assign must use the resolved fs UUID + RAW mount path: %+v", agent.assignCalls)
}
paths := s.settings.GetStoragePaths()
if len(paths) != 1 || paths[0].Path != "/mnt/hdd1" || paths[0].Label != "Külső HDD" || !paths[0].IsDefault || !paths[0].Schedulable {
t.Fatalf("StoragePath not registered as expected: %+v", paths)
if len(paths) != 1 || paths[0].Path != "/mnt/felhom-drives/hdd1" || paths[0].Label != "Külső HDD" || !paths[0].IsDefault || !paths[0].Schedulable {
t.Fatalf("StoragePath not registered at the stable path as expected: %+v", paths)
}
// P2C: enroll must pass the drive into the guest.
// Enroll must pass the drive into the guest via the RAW path (the agent maps it under the parent).
if len(agent.guestAttachCalls) != 1 || agent.guestAttachCalls[0] != "/mnt/hdd1" {
t.Fatalf("enroll did not guest-attach the drive: %+v", agent.guestAttachCalls)
t.Fatalf("enroll did not guest-attach the raw drive path: %+v", agent.guestAttachCalls)
}
}