diff --git a/CONTEXT.md b/CONTEXT.md index f9e8bfb..f7cb47c 100644 --- a/CONTEXT.md +++ b/CONTEXT.md @@ -7,7 +7,18 @@ > > Ask Claude Code: "Please update CONTEXT.md with what we did today" -Last updated: 2026-09-23 (v0.263.2 — a failed update puts the app back by itself) +Last updated: 2026-09-23 (v0.264.0 — the household is told when an update is undone or held) + +> **2026-09-23 (evening) — v0.264.0 (`09` §6.4 parts 2–3; R-606, R-620, R-646).** Two events, +> `app_update_undone` / `app_update_held`, one per app per outcome, via `Manager.SetUpdateEventSink` +> (main.go) → `NotifyAppUpdateUndone` / `NotifyAppUpdateHeld`; on by default and seeded once on existing +> boxes (`app_update_events_seeded`), with two toggles on the notifications page (the page pushes the +> list to the hub on save). Update sentences are stored as key + args (`UpdateErrorKey/Args`, +> `update.error.*`, `update.refusal.*`, `update.phase.*`, `hold.*`) and rendered per reader +> (`updatePhaseText` / `updateErrorText` / `holdText`, `RestoreHoldForLang`, `UpdateErrorIn`); stored +> Hungarian unchanged. Startup `BackfillAppliedMeta` (R-646). Disabled notifier WARNs once per type +> (R-620). Needs hub v0.120.0. Floor 0.264.0. Leftovers: R-647. Evidence: +> `felhom.eu/documentation/audits/undo-fleet-2026-09-23/`. > **2026-09-23 — v0.263.0 → v0.263.2 (R-637, `09` §3 decisions 15 + 19).** A failed health check after > an update is now UNDONE: phase `copying` (after the pull, the app stopped anyway) copies every NAMED diff --git a/REPORT.md b/REPORT.md index b09e182..537318d 100644 --- a/REPORT.md +++ b/REPORT.md @@ -1,38 +1,31 @@ -# REPORT — v0.263.0 → v0.263.2: a failed update puts the app back by itself (R-637) +# REPORT — controller v0.264.0: the household is told when an update is undone or held (2026-09-23) -2026-09-23. Baseline `b9deec19077b` (v0.262.1). Commits: `8fc2b4a` (v0.263.0), `5d38573` (v0.263.1), -`2cd6666` (v0.263.2). **MinAgent 0.131.0, unchanged.** Deployed: **scratch guest 9202 only**; the fleet -floor stays at 0.262.1 (the operator's question). +`09` §6.4 parts 2–3; R-606, R-620, R-646. Commit `bc27894`. MinAgent 0.131.0 (unchanged). Needs hub +v0.120.0 (deployed first). **Floor raised to 0.264.0** after the live proof. Full report, mails and +evidence: `felhom.eu/REPORT.md`, `felhom.eu/documentation/audits/undo-fleet-2026-09-23/`. -## What changed +## Not done, or changed +- R-606 has three leftovers → **R-647**: a reader in the other language than the box sees a HELD sentence + in the box's language; the English mail's raw `Note:` keeps the Hungarian `copy_holds`; two log wordings. +- Added beyond the brief: a one-time box-side seed + two notifications-page toggles (the page pushes its + list to the hub on save, which would undo the hub's migration). +- The undone line ends „nincs teendőd" (the product's „te" voice), not „teendője nincs". -- `internal/stacks/undo.go` (new): the folder copy (`volumeCopier`, docker helper), `tryUndo`, the - applied `.felhom.yml` record, `last_update_undone`. -- `internal/stacks/update.go`: phase `copying` after the pull; `failAndHold` undoes first; journal - phases `copying`/`undoing` with recovery; `restoreDefinition` split from `pinBack`; - `waitUpdateHealthyMeta` (the undo's own probe, which runs on an `unhealthy` app); seam `probeRunFn`. -- `pin.go`, `deploy.go`: every pin writer records the pinned version's `.felhom.yml` (`applied-meta/`). -- `backup/`: `RestoreHold.UndoState`; the hold sentence's undo prefix + state clause (box language). -- `web/`: the undone line on the app page (request language). `api/`: R-642 start answer. -- `delete.go`: a removal deletes the app's kept undo copies. -- i18n: 10 keys born as keys (hu + en). `docker_run_volume_path_gate`: four named-volume mounts allowlisted. +## What shipped +- `app_update_undone` (warning) / `app_update_held` (error), one per app per outcome, via + `Manager.SetUpdateEventSink` (main.go); held mails carry the hold sentence in the household's language. +- Update sentences stored as key + args and rendered per reader on both pages and `GET /api/stacks/`; + stored Hungarian byte-identical. +- `BackfillAppliedMeta` at startup (R-646). Disabled notifier: one WARN per type, then DEBUG (R-620). -## Tests and red-proofs +## Red-proofs (9, each seen failing) +Backfill stores nothing; `dropped()` not called; undone event not emitted; held event not emitted; page +error text not localised; hold sentence ignores the language; `UpdateErrorIn` returns Hungarian; box +seed not run; sink not wired in main (retried with a compiling mutation). Messages in `felhom.eu/REPORT.md` §6. -`go build ./... && go vet ./... && go test ./...` → rc=0 before each commit. Controller gates rc=0. -Twelve red-proofs, each seen failing and restored — table in `felhom.eu/REPORT.md` §3. Two of them -(9, 3b) reproduce the two live-only defects verbatim. +## Live +9202: undone + held, pages hu/en, WARN-then-DEBUG, backfill 3. 9201 (hub on): 4 household + 4 operator +mails in hu and en, `notification_log` 937–946 all sent, backfill 10. Both torn down to their standing +apps and the live catalog; both on 0.264.0. -## Live (endpoint-level, 9202) - -Three apps undone by the product with seeds before/after the backup and seconds before the press read -back; a cut-off copy held honestly (hu and en prefix); a power cut during `undoing` resumed and undone; -a person's press after an undo worked; removal deleted kept copies. Evidence: -`felhom.eu/documentation/audits/undo-live-2026-09-23/README.md`. - -## NOT yet live-validated - -- The household mail / operator event for an undo (not built — `09` §6.4 part 2). -- An app pinned BEFORE v0.263.2 that has not been re-pinned (R-646) — its undo probes with the - current `.felhom.yml`; reasoned, not run live. -- Any box other than 9202. +`go test ./...` rc=0; `controller_gates.py` rc=0.