diff --git a/CONTEXT.md b/CONTEXT.md index a85fa39..ada4d91 100644 --- a/CONTEXT.md +++ b/CONTEXT.md @@ -7,8 +7,10 @@ > > Ask Claude Code: "Please update CONTEXT.md with what we did today" -Last updated: 2026-09-27 (v0.275.0 — a backup's data and its version travel together; floor 0.275.0) +Last updated: 2026-09-27 (v0.276.0 — a restore and a drive move keep the app's records; floor 0.276.0) +> **2026-09-27 — v0.276.0, floor 0.276.0 (MinAgent 0.131.0).** `stacks/life_records.go` `carryLifeRecords` — the restore's fresh `app.yaml` keeps `desired_state`, `conversion_copy`, `earlier_conversion_copies`, `failed_update_step`, `last_update_undone`, `last_auto_update` (NOT the pin, NOT `installed_images`); `recordConversionCopy` moves a superseded copy to `earlier_conversion_copies`; `ReleaseConversionCopies` → `releaseOneConversionCopy` per kept copy. Drive move: `persistDriveFlip` (load-then-save, `HDD_PATH` only) + `upFromAppConfig`; `flipEnv` removed. **A new `app.yaml` writer that is not a new install must load-then-save** (R-697, R-700). Tests `r700_records_carried_test.go`. +> > **2026-09-27 — v0.275.0, floor 0.275.0 (MinAgent 0.131.0).** `backup/data_versions.go`: `stampDataFile` (called by the > DB leg, the volume leg and `RunAppBackupNow` — a new writer of a unit data file MUST call it), `foldUnitData`, > `RecoveryManifest.Data`; `captureRecoveryUnit(stack, dataRun)` keeps `compose/` when the pins moved since the data diff --git a/REPORT.md b/REPORT.md index f63a647..e9bddca 100644 --- a/REPORT.md +++ b/REPORT.md @@ -1,26 +1,23 @@ -# REPORT — v0.275.0: a backup's data and its version travel together (2026-09-26/27) +# REPORT — v0.276.0: a restore and a drive move keep the app's records (2026-09-27) -Brief: version-travel (Parts A, D2–D4). Architecture: `07-backup-architecture.md` §6 (+ new §6.6), `09` §3, §5.3, §6.4. -Session record: `felhom.eu/documentation/audits/DRILL-version-travel-2026-09-26.md`. +Follow-up to the version-travel brief (v0.275.0). Architecture: `07-backup-architecture.md` §6.6. Evidence: +`felhom.eu/documentation/audits/records-carried-2026-09-27/`. -**Baseline:** `main` `fb2bcdd5d619`, v0.274.0, floor 0.274.0. **Commits:** `b6810f1` (Part A, R-695, R-691 (1), R-694), -`7fcda8f` (R-699, found live). **Released:** image `0.275.0` (rc `0.275.0-rc1` for the live proofs); floor 0.275.0 with -MinAgent 0.131.0 — both demo boxes on 0.275.0 within 15 s (`audits/version-travel-2026-09-26/R/`); 9202 by hand (scratch). +**Not done, or changed:** R-691 (2) (Load from the off-site copy) NOT built — a new restore path on household data with no +box CC may prove it on; R-700 NOT proven live (no Tier-0 guest has two drives); R-697's carry not exercised by a real +restore (it would spoil the night's release proof on 9202). -**Tests:** full suite green (`go build/vet/test ./...` rc=0) after the last change; controller gates all OK. New tests: -`internal/backup/a_version_travel_test.go` (15), `internal/stacks` `TestA5_TheReleaseRefusesAPreConversionDump`, -`TestA4_AnOldRecordWithoutAServiceChecksEveryPostgresImage`, `TestA3_RestoredVersionPosition`, `TestR695_*`, `TestR694_*`, -`internal/web` `TestA3_RestoredVersionSentence`, `TestR695_*`, `TestR691_*` (2), `TestR694_*`; new parity fixture -`deploy_deployed_restored_login`. Two AST fixture names updated (`TestAdmission_IsWiredIntoEveryProductionWriteLeg`). +**Baseline:** `main` `54bb4da`, v0.275.0, floor 0.275.0. **Commit:** `820e8ef`. **Released:** image `0.276.0`; floor 0.276.0 +(MinAgent 0.131.0); both demo boxes on 0.276.0 within 10 s; 9202 by hand. -**Red-proofs (each seen failing, tree restored)** — `felhom.eu/documentation/audits/version-travel-2026-09-26/`: -RP1 Tier 1 time = manifest ("the refresh 1s made a two-hour-old dump read as new"); RP2/RP2b the refresh rewrites -`compose/` (the restore started 16 data with `postgres:18`); RP3 no version check (mismatch/mixed restored); RP4 the -release on a pre-conversion dump ("released [nextcloud]; copies=0"); RP5 off-site uses the live definition; RP6 R-699 (a -dump-less unit accepted); D2 R-695 ×2; D3 R-691 ×2; D4 R-694. +- **R-697:** `PersistUnitRedeployConfig` now carries the life records from the `app.yaml` it replaces + (`carryLifeRecords`, `internal/stacks/life_records.go`); `earlier_conversion_copies` keeps a superseded copy's record and + `ReleaseConversionCopies` releases every kept copy by the same rule (`releaseOneConversionCopy`). +- **R-700 (new):** `doFlipRedeploy` persisted through that same fresh write and dropped the pin; now `persistDriveFlip` + (load-then-save, `HDD_PATH` only) + `upFromAppConfig` (the tail shared with `RedeployFromEnv`). -**Live (endpoint level, 9202):** `A5-live/README.md` — both shapes restore the old version whole and climb again; the box's -own night showed the frozen definition and the data-time restore point. +**Tests:** `internal/stacks/r700_records_carried_test.go` (4). Full suite `go build/vet/test ./...` rc=0; controller gates OK. +**Red-proofs** RP1–RP4 (`redproofs/`), each seen failing with the wrong value, tree restored. -**NOT yet live-validated:** the off-site restore's definition write; the conversion-copy release on a real 18 dump (due -after 9202's next nightly backup); R-691 (1) with a real 0770 folder; the English restore sentence. +**Live:** 9202 paperless-ngx keeps its `conversion_copy` record and volume across the upgrade (`R/R3`). The night check +(the release on a real 18 dump, through the rewritten loop) is in `N/`.