controller v0.265.0: R-634 cause fixed, held apps say so, OOM storm alarm, R-647 leftovers
gates / gates (push) Successful in 27s

R-634: a whole-box backup no longer stops/restarts a DEPLOYING app (the
measured cause of containers running under 'not deployed'); StopStack
and StartStack refuse a deploying stack for every caller.
R-625: held badge 'Stopped - restore needed', no Update button.
R-636: kernel oom_kill counter; 20+ in 30 min -> one app_oom_storm.
R-647: held error per reader, copy_holds key, two log wordings.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
This commit is contained in:
2026-09-23 17:16:57 +02:00
parent 0a3026180a
commit 0054d4bd69
28 changed files with 832 additions and 48 deletions
+24
View File
@@ -724,6 +724,16 @@ func (m *Manager) runVolumeDumps() (summary []string, dumped int, allOK bool) {
continue
}
// R-634 (v0.265.0): an app whose deploy is still running is NOT an installation to back up,
// and stopping it is what broke the deploy. The list is taken once at the start of the run, so
// the question is asked again here, immediately before the stop. A SKIP, not a failure: there
// is nothing of the household's in it yet, and a FAIL would page the operator for a deploy.
if m.stackIsDeploying(stack.Name) {
m.logger.Printf("[INFO] [backup] Skipping volume dump for %s — the app is still being deployed (R-634)", stack.Name)
summary = append(summary, fmt.Sprintf("SKIP %s volumes (deploying)", stack.Name))
continue
}
// R-181: the reserve, ahead of DumpAppVolumesSafe so a refused app is NOT stopped. For an app
// that already has a DB this is a memo lookup taken before its DB dump; for a volume-only app
// this is where its verdict is taken, still before its first byte.
@@ -1398,3 +1408,17 @@ func (m *Manager) note(key string, args ...interface{}) string {
// noteErr renders an error into a saved note in the box's language: its bundle message when it
// carries one (release B), its own text otherwise.
func (m *Manager) noteErr(err error) string { return util.ErrText(m.boxLang(), err) }
// deployingReporter is the OPTIONAL half of the stack provider that can say a deploy is in flight
// (R-634). Optional on purpose: the production adapter implements it, and the many test fakes that
// predate it need not — a provider that cannot answer is read as "not deploying", today's behaviour.
type deployingReporter interface {
IsDeploying(name string) bool
}
func (m *Manager) stackIsDeploying(name string) bool {
if d, ok := m.stackProvider.(deployingReporter); ok {
return d.IsDeploying(name)
}
return false
}