controller v0.268.0: the undo finds volumes by definition; a held app names only a whole copy; one press = one tested step (R-658, R-659, R-660, R-651; 09 §6.4 part 5)
gates / gates (push) Successful in 27s

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
This commit is contained in:
2026-09-24 08:15:27 +02:00
parent 80e6ad8c47
commit 206b0357d1
36 changed files with 2201 additions and 40 deletions
+27
View File
@@ -677,6 +677,33 @@ sentence and its prefix — is stored as a key + args and rendered in the READER
the Hungarian stored text is unchanged. At startup, an app already CURRENT with the catalog gets its
`applied-meta/` record (R-646); a behind app is skipped by name, never guessed.
**One press = one tested step (v0.268.0, `09` §3 decision 14, §6.4 part 5).** The catalog's
`update_ladder:` in `.felhom.yml` lists every tested step; every step but the newest carries its own compose
file at `templates/<app>/steps/<StepKey(to)>.yml` (sha256 of `to` as canonical JSON, 16 hex — the catalog
computes the same). The guarded update finds the NEWEST entry whose `from` is the app's pin and pins exactly
that step's definition (the newest step: the template's `docker-compose.yml`), read straight from the
catalog clone. A step the catalog promises and does not carry refuses before anything moves. A pin that
matches no entry (an app older than the ladder) takes the catalog's current definition, logged by name. The
app page shows „Hátralévő frissítési lépések: N" / "Update steps remaining: N" while steps remain. A failed
step is undone as any update and the next press starts from the same step again. **Limitation:** a step
has no `.felhom.yml` of its own — the health probe and memory check read the catalog's current one (R-664).
**The undo finds the app's volumes by its definition (v0.268.0, R-658).** The undo copies the named volumes
the rendered compose file DECLARES (`<project>_<key>`, or the volume's own `name:`), each checked to exist;
the compose label is a logged cross-check. Until v0.267.0 it selected by the label, and a restore recreated
volumes without it — so after any restore the undo copied nothing. The restore now creates volumes WITH
compose's project/volume/version labels too, and the remove counts unlabelled declared volumes.
**A held app's page names only a way back that works (v0.268.0, R-659, operator ruling 2026-09-24, option
A).** The hold names the newest copy on any tier that brings the app back WHOLE — for an app with declared
drive files (`DeclaredDriveFileLegs`) only the off-site copy, because the unit restore and the second-drive
unit restore both refuse it (R-538) — with what it holds. With none, the sentence is
`hold.update.no_whole_copy` („… Ezen a dobozon nincs olyan másolat … A Felhom ügyfélszolgálatát
értesítettük …"), no Mentések button is shown beside it, and the operator gets `app_hold_no_whole_copy`
(critical, operator-only on hub v0.122.0+, details `{app, from, to, at, copies_seen, undo_state}`). A held
app raises no `app_start_failed` (R-660). A removed app leaves no `applied-compose.yml` / `applied-meta/`
(R-651).
**Start/restart never answer "completed" (v0.263.0, R-642)** — they answer what was requested and the
state the containers are in at that moment; whether the app works is the health probe's to say.