v0.246.0: an interrupted restore is told; the recovery-code reminder waits until the box can take it
gates / gates (push) Successful in 15s

MinAgent: 0.131.0 (unchanged). Requires hub v0.117.0 for restore_interrupted.

R-550 (operator ruling: fix). A design reversed and recorded: the restore
op-status was in memory by choice. Now restore-status.json in DataDir, written
atomically at both ends of an op. At startup a record still marked running
becomes a failed, interrupted result kept per app until that app's next
restore, shown on /backups/restore and the off-site wizard, and raised once as
restore_interrupted. Cooldowns stay in memory.

R-546. The R-543 reminder bar consults the agent's own preflight ok (every
blocking item, not a copy of pbs_storage_id), cached 60 s, probed only while
paused. /backup/escrow shows a waiting card that polls and reloads instead of
red crosses and English diagnostics. POST /api/escrow/start refuses 409 before
staging or starting - the direct path chaos night used. Unknown readiness keeps
the bar.

Red-proofs (each seen failing): restore record across restart; main() calls
both startup functions; startup helper with loading skipped; restore page card;
bar held back; waiting card; start refusal. go build/vet/test ./... green, 28
packages; controller_gates --fast all OK.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
This commit is contained in:
2026-09-17 10:45:29 +02:00
parent 714d5bce09
commit 0fe315b759
21 changed files with 788 additions and 10 deletions
+33
View File
@@ -1,3 +1,36 @@
## v0.246.0 — an interrupted restore is told, and the recovery-code reminder waits until the box can take it (2026-09-17, R-550 / R-546)
**MinAgent: 0.131.0** (unchanged — the readiness check reads the escrow preflight, served since agent
0.88.0; nothing here needs agent 0.132.0). **Requires hub v0.117.0** for `restore_interrupted` to be
accepted; an older hub 400s that one event and nothing else changes.
- **R-550 (operator ruling "fix", 2026-09-17) — the restore record survives a restart.** A DESIGN
REVERSED: `opstatus.go` was in memory by choice ("same precedent as notification cooldowns"). Chaos
night round 10 measured the cost — a restore accepted, the box hard-reset four seconds later, and
`/api/backup/restore-status` answering the Go zero value; nobody could learn whether it finished.
Now `restore-status.json` in `DataDir`, written atomically at both ends of an op
(`internal/backup/restore_record.go`). At startup a record still marked running becomes a failed,
`Interrupted` result — „A visszaállítás megszakadt (a doboz újraindult) — indítsd el újra." — kept
per app until that app's next restore, shown as a „Megszakadt visszaállítás" card on
`/backups/restore` and in the off-site wizard's outcome card, and raised ONCE as
`restore_interrupted` (warning, for the household). Cooldowns stay in memory.
- **R-546 — the recovery-code reminder waits until the box can run the ceremony.** The R-543 bar now
consults the agent's OWN preflight `ok` (every blocking item — not a copy of `pbs_storage_id`), cached
60 s and probed only while paused; held back while not ready. `/backup/escrow` shows a waiting card
that polls and reloads itself instead of red crosses and the agent's English diagnostics.
`POST /api/escrow/start` refuses 409 with the same sentence BEFORE staging or starting — the direct
path chaos night used, which ran the ceremony and returned the raw `-storage` stderr. Unknown
readiness keeps the bar (fail loud). The transition is logged at INFO.
**Red-proofs, each seen failing then passing:** the restore record across a restart (blank status,
`StartedAt:0001-01-01` — the chaos-night symptom exactly); a finished restore stays finished; the next
restore of that app clears its notice; `main()` calls both startup functions (AST); the startup helper
with loading skipped pushes nothing; the restore page card with the handler line removed; the bar held
back (readiness check removed → bar shown); the waiting card (never set → checklist); the start refusal
(gate removed → 200 and `stage,start` ran). Controls: a ready box shows the bar; unknown readiness shows
the bar; a box with no interruption shows no card. The three existing start-order tests now expect
`preflight` first — their load-bearing assertion (stage BEFORE start) is unchanged.
## v0.245.0 — the household is asked for the recovery code, and the page says „szünetel" until then (2026-09-16, R-543)
**MinAgent: 0.131.0** (unchanged — nothing here needs a newer agent)