v0.283.1: a Stop holds during the volume dump in production and at the crash recovery (R-721, found live on v0.283.0)
gates / gates (push) Successful in 28s

Red-proofs RP43, RP44. MinAgent 0.131.0 (unchanged).

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
This commit is contained in:
2026-09-30 10:52:19 +02:00
parent 6be6c53e29
commit 29d3c533aa
5 changed files with 104 additions and 0 deletions
@@ -279,7 +279,14 @@ func (g *AppStopGuard) Recover() *AppStopRecovery {
m.Reason.humanReason(), m.OpID, len(m.Stacks), m.Stacks)
res := &AppStopRecovery{Reason: m.Reason, OpID: m.OpID, StartedAt: m.StartedAt}
hs, _ := g.starter.(interface{ WantsStopped(string) bool })
for _, name := range m.Stacks {
if hs != nil && hs.WantsStopped(name) {
// R-721 (v0.283.1): the household pressed Stop while the interrupted operation had the app down.
// It is owed nothing; the marker still clears below.
g.logger.Printf("[INFO] [appstop] crash recovery: NOT restarting %s — the household stopped it", name)
continue
}
if err := g.starter.StartStack(name); err != nil {
// R-174: a REFUSAL is not a failure. The starter's gate has said this app must not be
// started (an absent data drive), so the app is left down deliberately and the holder