Modules/Impermanence: Update impermanence-btrfs-cleanup service
- Run after "systemd-cryptsetup@crypted.service" instead of "dev-mapper-crypted.device" - Delete old backups after recreating home and root subvols in case of failure - Remove possible immutable attributes from backups, so the service doesn't fail because it's not able to clear old backups
This commit is contained in:
@ -74,10 +74,10 @@ in {
|
||||
|
||||
users.${username} = {
|
||||
files = [
|
||||
# NOTE: Don't put files generated/linked by HM here
|
||||
# as HM can't overwrite file mounts...
|
||||
# NOTE: Don't put files generated/linked by HM here (they're already managed)
|
||||
(mkUFile ".config/.tidal-dl.json" m755)
|
||||
(mkUFile ".config/.tidal-dl.token.json" m755)
|
||||
(mkUFile ".config/QtProject.conf" m755) # KeePassXC
|
||||
];
|
||||
|
||||
directories = [
|
||||
@ -202,34 +202,52 @@ in {
|
||||
in {
|
||||
description = "Clean impermanent btrfs subvolumes";
|
||||
wantedBy = ["initrd.target"];
|
||||
after = ["dev-mapper-crypted.device"];
|
||||
# after = ["dev-mapper-crypted.device"];
|
||||
after = ["systemd-cryptsetup@crypted.service"];
|
||||
before = ["sysroot.mount"];
|
||||
unitConfig.DefaultDependencies = "no";
|
||||
serviceConfig.Type = "oneshot";
|
||||
# path = ["/bin" config.system.build.extraUtils pkgs.coreutils-full];
|
||||
|
||||
# NOTE: If any single line of this script fails, the entire system might be bricked
|
||||
# NixOS automatically sets "-e", so if unlucky, the subvolumes will be missing
|
||||
script = ''
|
||||
# This dir will be created in the initrd ramdisk
|
||||
mkdir -p ${mountDir}
|
||||
|
||||
# We mount the root subvolume. Because we're using a flat btrfs layout,
|
||||
# "/" contains the subfolders (-volumes) home, log, nix, persist, root, swap, ...
|
||||
mount -o subvol=/ /dev/mapper/crypted ${mountDir}
|
||||
|
||||
# Backup old root subvolume
|
||||
# Move root subvolume to backup location
|
||||
if [[ -e ${mountDir}/root ]]; then
|
||||
mkdir -p ${persistDir}/old_roots
|
||||
timestamp=$(date --date="@$(stat -c %Y ${mountDir}/root)" "+%Y-%m-%-d_%H:%M:%S")
|
||||
mv ${mountDir}/root "${persistDir}/old_roots/$timestamp"
|
||||
|
||||
# Make the backup mutable (in case it is not, e.g. /var/empty)
|
||||
chattr -R -i -f "${persistDir}/old_roots/$timestamp"
|
||||
|
||||
echo "Backed up previous root subvolume to ${persistDir}/old_roots/$timestamp"
|
||||
fi
|
||||
|
||||
# Backup old home subvolume
|
||||
# Move home subvolume to backup location
|
||||
if [[ -e ${mountDir}/home ]]; then
|
||||
mkdir -p ${persistDir}/old_homes
|
||||
timestamp=$(date --date="@$(stat -c %Y ${mountDir}/home)" "+%Y-%m-%-d_%H:%M:%S")
|
||||
mv ${mountDir}/home "${persistDir}/old_homes/$timestamp"
|
||||
|
||||
# Make the backup mutable (in case it is not)
|
||||
chattr -R -i -f "${persistDir}/old_homes/$timestamp"
|
||||
|
||||
echo "Backed up previous home subvolume to ${persistDir}/old_homes/$timestamp"
|
||||
fi
|
||||
|
||||
# Create new root + home subvolumes
|
||||
btrfs subvolume create ${mountDir}/root
|
||||
btrfs subvolume create ${mountDir}/home
|
||||
echo "Created new subvolumes ${mountDir}/root and ${mountDir}/home"
|
||||
|
||||
# Delete a backed up subvolume
|
||||
delete_subvolume_recursively() {
|
||||
IFS=$'\n'
|
||||
@ -242,38 +260,23 @@ in {
|
||||
if [ $(stat -c %i "$1") -ne 256 ]; then return; fi
|
||||
|
||||
for subvol in $(btrfs subvolume list -o "$1" | cut -f 9- -d ' '); do
|
||||
delete_subvolume_recursively "${persistDir}/$subvol"
|
||||
delete_subvolume_recursively "${persistDir}/$subvol"
|
||||
done
|
||||
|
||||
btrfs subvolume delete "$1"
|
||||
echo "Deleted old subvolume $1"
|
||||
}
|
||||
|
||||
# Delete old roots
|
||||
# Delete old root backups
|
||||
for old_root in $(find ${persistDir}/old_roots/ -maxdepth 1 -mtime +${backupDuration}); do
|
||||
delete_subvolume_recursively "$old_root"
|
||||
done
|
||||
|
||||
# Delete old homes
|
||||
# Delete old home backups
|
||||
for old_home in $(find ${persistDir}/old_homes/ -maxdepth 1 -mtime +${backupDuration}); do
|
||||
delete_subvolume_recursively "$old_home"
|
||||
done
|
||||
|
||||
# Create new root + home subvolumes
|
||||
btrfs subvolume create ${mountDir}/root
|
||||
btrfs subvolume create ${mountDir}/home
|
||||
echo "Created new subvolumes ${mountDir}/root and ${mountDir}/home"
|
||||
|
||||
if [[ -d ${mountDir}/home/${username} ]]; then
|
||||
chown -R ${homeUser}:${homeGroup} ${mountDir}/home/${username}
|
||||
echo "Set permissions for ${mountDir}/home/${username} to ${homeUser}:${homeGroup}"
|
||||
fi
|
||||
|
||||
if [[ -d ${persistDir}/home/${username} ]]; then
|
||||
chown -R ${homeUser}:${homeGroup} ${persistDir}/home/${username}
|
||||
echo "Set permissions for ${persistDir}/home/${username} to ${homeUser}:${homeGroup}"
|
||||
fi
|
||||
|
||||
umount ${mountDir}
|
||||
rmdir ${mountDir}
|
||||
'';
|
||||
|
Reference in New Issue
Block a user