stacks: the box converts a PostgreSQL major as a guarded-update step (09 6.4 part 10, decisions 35/37/38)
gates / gates (push) Successful in 25s

A step whose ladder entry carries engine_conversion {service, engine, from, to}
converts the database: the old engine alone, the check (owners, roles,
extensions, per-table row counts), pg_dumpall validated by its completion line,
the volume emptied only after the undo copy's marker is validated again, the new
engine alone, the load with ON_ERROR_STOP, the check again + PG_VERSION. Any
failure goes to the existing undo; a restart during converting is undone.
A PostgreSQL major move without the mark is refused before anything moves.
The old datadir's copy is kept until a backup is proven after the conversion.
17 tests, 9 red-proofs (audits/night-2026-09-26/B/).

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
This commit is contained in:
2026-09-25 12:57:03 +02:00
parent 3d49df1e5a
commit 2caae38a71
13 changed files with 1523 additions and 12 deletions
@@ -0,0 +1,13 @@
package main
import "testing"
// TestConvert_ReleaseIsWiredAtStartup — v0.273.0 (`09` §6.4 part 10, B5): the kept pre-conversion datadir
// copy is released only by ReleaseConversionCopies, so main.go must CALL it (the seam-built-but-never-wired
// class). COMPANION RED-PROOF (REPORT.md): delete the `conversion-copy-release` job — this fails.
func TestConvert_ReleaseIsWiredAtStartup(t *testing.T) {
lines, _, _ := slice4CallLines(t)
if len(lines["ReleaseConversionCopies"]) == 0 {
t.Fatal("ReleaseConversionCopies is never called — a converted app's old datadir copy would stay on disk for ever")
}
}
+8
View File
@@ -1138,6 +1138,14 @@ func main() {
return nil
})
// v0.273.0 (`09` §6.4 part 10, B5): a PostgreSQL conversion keeps the OLD datadir's copy until a
// backup of the converted app is proven; this releases it. Hourly — a copy outliving its backup by
// an hour costs disk, never data. Pinned by TestConvert_ReleaseIsWiredAtStartup.
sched.Every("conversion-copy-release", 1*time.Hour, func(ctx context.Context) error {
stackMgr.ReleaseConversionCopies(ctx)
return nil
})
// Tier 2: off-drive copy of each HDD app's recovery unit + userdata (auto-enabled, auto-target).
// Runs after the DB dump so it copies a fresh unit.
backupMgr.SetTier2Notifier(func(stackName, destLabel string, dur time.Duration, err error) {