Host report keeps the last backup across a restart; Secure Boot meta-package leaves the Proxmox lane
gates / gates (push) Successful in 1m7s
gates / gates (push) Successful in 1m7s
Found in the 2026-10-09 kernel-night read-back: - demo-felhom: the kernel step restarted the host 4 minutes after the night backup; the in-memory backup list was empty after the restart, so the hub alarmed "host tier: newest backup is 48h old". The report now adds R-894's saved newest success per tier (one shared instance). - demo-hp: proxmox-secure-boot-support pulled shim-signed-common into the ring-0 Proxmox plan; the step was refused R6 and the kernel step skipped. It joins HOST_SLOW_RE with shim and GRUB. Red-proved: TestCollectBackups_SavedSuccessSurvivesARestart, TestR894_LastKnownBackupsIsWiredIntoTheDaemon, test_ring0_pending_pve_leaves_the_secure_boot_meta_out. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
This commit is contained in:
@@ -103,6 +103,29 @@ func (s *BackupSuccessState) LastKnownSuccess(target string, vmid int) (time.Tim
|
||||
return e.at, ok
|
||||
}
|
||||
|
||||
// KnownBackupSuccesses returns every saved success as a host-report record (the collector's
|
||||
// KnownBackupReporter, so the hub keeps its evidence across a restart). Only the tier, guest and start
|
||||
// time are known; the archive name is not saved and stays empty. Sorted for a stable report.
|
||||
func (s *BackupSuccessState) KnownBackupSuccesses() []hub.Backup {
|
||||
if s == nil {
|
||||
return nil
|
||||
}
|
||||
s.mu.Lock()
|
||||
defer s.mu.Unlock()
|
||||
out := make([]hub.Backup, 0, len(s.last))
|
||||
for _, e := range s.last {
|
||||
out = append(out, hub.Backup{TargetID: e.target, VMID: e.vmid, Success: true, CrashConsistent: true,
|
||||
StartedAt: e.at.Format(time.RFC3339), UncoveredVolumes: []string{}})
|
||||
}
|
||||
sort.Slice(out, func(i, j int) bool {
|
||||
if out[i].TargetID != out[j].TargetID {
|
||||
return out[i].TargetID < out[j].TargetID
|
||||
}
|
||||
return out[i].VMID < out[j].VMID
|
||||
})
|
||||
return out
|
||||
}
|
||||
|
||||
func (s *BackupSuccessState) saveLocked() error {
|
||||
entries := make([]backupSuccessJSON, 0, len(s.last))
|
||||
for _, e := range s.last {
|
||||
|
||||
@@ -57,3 +57,20 @@ func TestBackupSuccessState_CorruptFileIsEmpty(t *testing.T) {
|
||||
t.Fatal("a corrupt file must read as nothing known")
|
||||
}
|
||||
}
|
||||
|
||||
// The saved successes come back as host-report records: success, tier, guest, start time (R-894 → the
|
||||
// host report, 2026-10-09). A new state read from the same file gives the same records (the restart case).
|
||||
func TestBackupSuccessState_KnownBackupSuccessesSurviveAReopen(t *testing.T) {
|
||||
path := filepath.Join(t.TempDir(), "backup-success-state.json")
|
||||
s := NewBackupSuccessState(path)
|
||||
if err := s.RecordBackupSuccess("felhom-backup", hub.Backup{VMID: 9201, Success: true, StartedAt: "2026-10-09T02:40:16Z"}); err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
got := NewBackupSuccessState(path).KnownBackupSuccesses()
|
||||
if len(got) != 1 || !got[0].Success || got[0].TargetID != "felhom-backup" || got[0].VMID != 9201 || got[0].StartedAt != "2026-10-09T02:40:16Z" {
|
||||
t.Fatalf("got %+v", got)
|
||||
}
|
||||
if got[0].UncoveredVolumes == nil {
|
||||
t.Fatal("uncovered_volumes must marshal as [], not null")
|
||||
}
|
||||
}
|
||||
|
||||
+49
-5
@@ -66,6 +66,13 @@ type ProvenRestoreTestReporter interface {
|
||||
ProvenRestoreTests(ctx context.Context) []RestoreTest
|
||||
}
|
||||
|
||||
// KnownBackupReporter is the newest SUCCESSFUL backup per tier and guest kept on disk (R-894's
|
||||
// backup-success-state.json). collectBackups folds it into the report so a restart does not erase the
|
||||
// hub's evidence of a backup that ran minutes before it (the kernel-night shape, 2026-10-09).
|
||||
type KnownBackupReporter interface {
|
||||
KnownBackupSuccesses() []Backup
|
||||
}
|
||||
|
||||
// PBSReporter is the slice-6-Phase-B seam the pbs verify loop plugs into (same pattern).
|
||||
// Returns the agent's latest-known PBS snapshot inventory + verify-state. nil → empty.
|
||||
type PBSReporter interface {
|
||||
@@ -105,6 +112,7 @@ type Collector struct {
|
||||
backups BackupReporter
|
||||
restoreTests RestoreTestReporter
|
||||
provenTests ProvenRestoreTestReporter
|
||||
knownBackups KnownBackupReporter // R-894 file → host report after a restart (nil → in-memory only)
|
||||
pbs PBSReporter
|
||||
temp TempReader // slice 9: host CPU/chassis temp (nil-safe → nil temp)
|
||||
capProbe func(ctx context.Context) []capability.Status // v0.44.0: privileged-capability self-check (nil → empty)
|
||||
@@ -576,14 +584,50 @@ func (c *Collector) collectStorage(ctx context.Context) []StorageTarget {
|
||||
// collectBackups / collectRestoreTests read the agent's latest backup + restore-test state
|
||||
// via the seams. Best-effort: a nil reporter or nil slice degrades to an empty (non-nil)
|
||||
// list so the collection always marshals as [].
|
||||
//
|
||||
// The saved successes (SetKnownBackupReporter) are added for each tier and guest the in-memory list has
|
||||
// no success for at or after the saved time. Why: the in-memory list is empty after an agent restart,
|
||||
// and the hub's backup-freshness check reads only what the reports carried. Measured 2026-10-09 on
|
||||
// demo-felhom: the night backup landed 02:40 UTC, the kernel step restarted the host at 02:44, no report
|
||||
// fell in between, so two kernel nights in a row left no trace and the hub alarmed „newest backup is 48h
|
||||
// old" at 03:00. Only SUCCESSES are saved, so a failure is never hidden and never invented.
|
||||
// Pinned by TestCollectBackups_SavedSuccessSurvivesARestart.
|
||||
func (c *Collector) collectBackups(ctx context.Context) []Backup {
|
||||
if c.backups == nil {
|
||||
return []Backup{}
|
||||
out := []Backup{}
|
||||
if c.backups != nil {
|
||||
if b := c.backups.Backups(ctx); b != nil {
|
||||
out = append(out, b...)
|
||||
}
|
||||
}
|
||||
if b := c.backups.Backups(ctx); b != nil {
|
||||
return b
|
||||
if c.knownBackups == nil {
|
||||
return out
|
||||
}
|
||||
return []Backup{}
|
||||
for _, k := range c.knownBackups.KnownBackupSuccesses() {
|
||||
kt, err := time.Parse(time.RFC3339, k.StartedAt)
|
||||
if err != nil {
|
||||
continue
|
||||
}
|
||||
covered := false
|
||||
for _, b := range out {
|
||||
if !b.Success || b.TargetID != k.TargetID || b.VMID != k.VMID {
|
||||
continue
|
||||
}
|
||||
if bt, err := time.Parse(time.RFC3339, b.StartedAt); err == nil && !bt.Before(kt) {
|
||||
covered = true
|
||||
break
|
||||
}
|
||||
}
|
||||
if !covered {
|
||||
out = append(out, k)
|
||||
}
|
||||
}
|
||||
return out
|
||||
}
|
||||
|
||||
// SetKnownBackupReporter wires the R-894 saved successes into the host report (nil-safe → in-memory only).
|
||||
func (c *Collector) SetKnownBackupReporter(r KnownBackupReporter) *Collector {
|
||||
c.knownBackups = r
|
||||
return c
|
||||
}
|
||||
|
||||
// collectRestoreTests merges the in-memory result with the PERSISTED per-tier proofs (R-189).
|
||||
|
||||
@@ -0,0 +1,62 @@
|
||||
package hub
|
||||
|
||||
import (
|
||||
"context"
|
||||
"testing"
|
||||
)
|
||||
|
||||
type fakeMemBackups []Backup
|
||||
|
||||
func (f fakeMemBackups) Backups(context.Context) []Backup { return f }
|
||||
|
||||
type fakeKnownBackups []Backup
|
||||
|
||||
func (f fakeKnownBackups) KnownBackupSuccesses() []Backup { return f }
|
||||
|
||||
// The consequence, not the mechanism: after a restart (empty in-memory list) the host report still carries
|
||||
// the night's backup, so the hub's freshness check sees it. Measured 2026-10-09 on demo-felhom: without this
|
||||
// the report carried backups: [] and the hub alarmed „newest backup is 48h old" an hour after a good backup.
|
||||
// RED-PROOF: return before the saved-success loop in collectBackups → the first case reports nothing → fails.
|
||||
func TestCollectBackups_SavedSuccessSurvivesARestart(t *testing.T) {
|
||||
saved := Backup{TargetID: "felhom-backup", VMID: 9201, Success: true, StartedAt: "2026-10-09T02:40:16Z"}
|
||||
|
||||
t.Run("restart: memory empty, the saved success is reported", func(t *testing.T) {
|
||||
c := &Collector{backups: fakeMemBackups(nil), knownBackups: fakeKnownBackups{saved}}
|
||||
got := c.collectBackups(context.Background())
|
||||
if len(got) != 1 || got[0].StartedAt != saved.StartedAt || !got[0].Success || got[0].TargetID != "felhom-backup" {
|
||||
t.Fatalf("want the saved success, got %+v", got)
|
||||
}
|
||||
})
|
||||
|
||||
t.Run("memory holds the same or a newer success: no second entry", func(t *testing.T) {
|
||||
mem := Backup{TargetID: "felhom-backup", VMID: 9201, Success: true, StartedAt: "2026-10-09T02:40:16Z", Archive: "a"}
|
||||
c := &Collector{backups: fakeMemBackups{mem}, knownBackups: fakeKnownBackups{saved}}
|
||||
if got := c.collectBackups(context.Background()); len(got) != 1 || got[0].Archive != "a" {
|
||||
t.Fatalf("want only the in-memory record, got %+v", got)
|
||||
}
|
||||
})
|
||||
|
||||
t.Run("a newer FAILURE in memory never hides the saved success, and is kept", func(t *testing.T) {
|
||||
fail := Backup{TargetID: "felhom-backup", VMID: 9201, Success: false, StartedAt: "2026-10-10T02:40:00Z", Error: "x"}
|
||||
c := &Collector{backups: fakeMemBackups{fail}, knownBackups: fakeKnownBackups{saved}}
|
||||
got := c.collectBackups(context.Background())
|
||||
if len(got) != 2 || got[0].Success || !got[1].Success {
|
||||
t.Fatalf("want the failure and the saved success, got %+v", got)
|
||||
}
|
||||
})
|
||||
|
||||
t.Run("another tier's success does not cover this tier", func(t *testing.T) {
|
||||
other := Backup{TargetID: "felhom-pbs", VMID: 9201, Success: true, StartedAt: "2026-10-10T00:00:00Z"}
|
||||
c := &Collector{backups: fakeMemBackups{other}, knownBackups: fakeKnownBackups{saved}}
|
||||
if got := c.collectBackups(context.Background()); len(got) != 2 {
|
||||
t.Fatalf("want both tiers, got %+v", got)
|
||||
}
|
||||
})
|
||||
|
||||
t.Run("no saved state wired: the in-memory list as before, never nil", func(t *testing.T) {
|
||||
c := &Collector{}
|
||||
if got := c.collectBackups(context.Background()); got == nil || len(got) != 0 {
|
||||
t.Fatalf("want an empty non-nil list, got %#v", got)
|
||||
}
|
||||
})
|
||||
}
|
||||
Reference in New Issue
Block a user