Skip to content

mount: ownership options are checked state; drift remounts without a lazy detach (fixes #642) - #643

Merged
noahgift merged 5 commits into
mainfrom
fix/642-mount-options
Sep 27, 2026
Merged

noahgift merged 5 commits into
mainfrom
fix/642-mount-options

Conversation

@noahgift

Copy link
Copy Markdown
Contributor

Fixes #642.

Defect: the mount check compared only the findmnt SOURCE. A share mounted from the right source with the wrong uid/gid/file_mode/dir_mode/mode reported converged, and apply never remounted it. This is a tool reporting what it did not measure. Found on lambda-labs: the NAS gid must change so the course user can write the share (paiml/infra#1208), and 1.32.0 would have reported converged with the old gid still live.

Fix (src/resources/mount.rs):

  • The check reads each declared ownership key back from findmnt -o OPTIONS.
    • Modes compare as numbers, so 0755 equals 755.
    • A user or group NAME resolves to its id with id -u or getent group.
    • A key the kernel omits (e.g. tmpfs uid=0) counts as the default.
  • On drift, apply remounts with a plain umount and no umount -l fallback. A busy mount fails loudly and names the path, instead of being detached under live jobs.

Tests (src/resources/tests_mount_options.rs): the generated scripts run against a fake findmnt/umount/mount, so the tests measure what the host is told, not the script text. There are 8 tests; all 41 resources::tests_mount* pass and clippy -D warnings is clean.

Discriminates: with options_condition neutralised, 5 of the 8 go RED: the wrong gid, the wrong mode, the group name, the remount on drift, and the refusal when busy. The 3 converged cases stay green, as they must.

🤖 Generated with Claude Code

…t a lazy detach (fixes #642)

check_script compared only the mounted SOURCE, so a share mounted with the
right source and the wrong uid/gid/file_mode/dir_mode/mode reported
converged, and apply never remounted it. Measured on lambda-labs: the NAS
declared gid changed and forjar would have said converged while the kernel
still showed gid=1000.

The check now reads the declared ownership keys back from findmnt OPTIONS:
modes compare as numbers (0755 == 755), a user or group name resolves to its
id, and a key the kernel omits counts as the default. On drift, apply
remounts with a plain umount and NO `umount -l` fallback: a busy mount fails
loudly naming the path instead of being detached under live jobs.

tests_mount_options runs the generated scripts against a fake
findmnt/umount/mount. Neutralising options_condition turns 5 of its 8 tests
RED (the three converged cases stay green, as they must).

Refs #642

Pmat-Ticket: PMAT-642
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@noahgift

Copy link
Copy Markdown
Contributor Author

quorum-review (AD-04): NOT agreed (auto_merge: checked=true was_armed=false disarmed=false)

{
 "ticket": "PMAT-642",
 "head": "6c1cabf22bf4f324990b6258b4166bfc30f06be9",
 "width": 3,
 "executor": "agy",
 "agreed": false,
 "auto_merge": {
  "checked": true,
  "was_armed": false,
  "disarmed": false,
  "note": "auto-merge not armed"
 },
 "lanes": [
  {
   "lane": 1,
   "verdict": "FAIL",
   "findings": 1
  },
  {
   "lane": 2,
   "verdict": "FAIL",
   "findings": 1
  },
  {
   "lane": 3,
   "verdict": "PASS",
   "findings": 0
  }
 ]
}

…quorum R1)

Round 1 lanes 1 and 2 refuted the first head. `[ -z "$_fj_v" ] || ...` let a
key the kernel leaves out match ANY declared value, so a declared uid=1000 over
a tmpfs that omits uid (= 0) read converged. That is the same false green #642
exists to remove. An omitted key is now compared as its kernel default: uid and
gid are 0, and mode is 1777. file_mode and dir_mode have no default, because
cifs always echoes both, so a missing one never matches.

fj642_an_omitted_key_is_its_default_not_a_wildcard goes RED with the old
wildcard restored and GREEN with this fix.

Refs #642

Pmat-Ticket: PMAT-642
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@noahgift

Copy link
Copy Markdown
Contributor Author

quorum-review (AD-04): three PASS — agreed (auto_merge: checked=true was_armed=false disarmed=false)

{
 "ticket": "PMAT-642",
 "head": "0b5882e06de1bdf2197de0b09ad7ac953cc465cf",
 "width": 3,
 "executor": "agy",
 "agreed": true,
 "auto_merge": {
  "checked": true,
  "was_armed": false,
  "disarmed": false,
  "note": "auto-merge not armed"
 },
 "lanes": [
  {
   "lane": 1,
   "verdict": "PASS",
   "findings": 4
  },
  {
   "lane": 2,
   "verdict": "PASS",
   "findings": 0
  },
  {
   "lane": 3,
   "verdict": "PASS",
   "findings": 0
  }
 ]
}

noahgift and others added 3 commits September 27, 2026 08:11
Refs #642

Pmat-Ticket: PMAT-642
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
An integration target the quorum gate can run (`cargo test --test`). It
executes the generated check/apply scripts against a fake findmnt, umount
and mount; with src/resources/mount.rs reverted to the base, 4 of 5 fail.

Refs #642

Pmat-Ticket: PMAT-642
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…d-key wildcard; fixed and re-reviewed)

Refs #642

Pmat-Ticket: PMAT-642
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@noahgift

Copy link
Copy Markdown
Contributor Author

Quorum 3/3 PASS at 0b5882e (R1 refuted the omitted-key wildcard, fixed and re-reviewed). After review, 184876b adds only tests/falsification_642_mount_ownership_is_state.rs, an integration target so the gate can run cargo test --test. It reuses the reviewed lib cases, and with mount.rs at base, 4 of 5 are red. 3a487e2 is the receipt; scripts/quorum-gate.sh passes.

@noahgift
noahgift enabled auto-merge (squash) September 27, 2026 06:27
@noahgift
noahgift merged commit c04b6b2 into main Sep 27, 2026
31 of 32 checks passed
@noahgift
noahgift deleted the fix/642-mount-options branch September 27, 2026 07:59
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

mount resource ignores options: a changed uid/gid/mode is never applied, and apply reports converged (#280 sibling)

1 participant