v0.244.0: the backup page stops promising what it does not hold (R-537/R-538/R-536)
gates / gates (push) Successful in 17s
gates / gates (push) Successful in 17s
R-537 — the contents label is now PER TIER. One string computed from the app's shape was rendered on all three tier rows; a Tier-1 unit has no file-copy step, so for the four class-A apps it was claiming „Adatok" for files it does not hold. R-538 — a unit restore REFUSES before anything is touched when the unit cannot return the app's drive-side files, and names the route that can. It runs before the stack is stopped because the measured harm included the app's own wastebasket going unreachable, which still held every byte. R-536 — „Alkalmazás telepítve" moved from the deploy's acceptance to its completion, with app_deploy_started and app_deploy_failed as the honest pair. Each fix red-proofed: seen failing with its own sentence, passing when restored. Requires hub v0.116.0 for the two new event types. MinAgent unchanged (0.131.0). Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
This commit is contained in:
@@ -1,3 +1,43 @@
|
||||
## v0.244.0 — the backup page stops promising what it does not hold, and a restore refuses to lie (2026-09-16, R-537 / R-538 / R-536)
|
||||
|
||||
**MinAgent: 0.131.0** (unchanged — nothing here needs a newer agent)
|
||||
|
||||
- **R-537 — the app-backup page labelled a Tier-1 unit „DB + Konfig + Adatok" and printed the app's
|
||||
data-drive size beside it, over a unit that holds no copy of those files.** The label was computed
|
||||
from the APP's shape (`HasHDDData || HasVolumeData`) and rendered on all three tier rows, so one
|
||||
string stood for three tiers that capture different things. It is now computed per tier from what
|
||||
the tier actually carries: Tier 1 says „Adatok" only when the app's data really is inside the
|
||||
volumes the unit captured, and a class-A app gets one sentence saying where its files ARE
|
||||
protected. **The design is unchanged** (07-backup-architecture §6.1/§6.2: a Tier-1 unit has no
|
||||
file-copy step; the file legs of calibre-web, immich, nextcloud and paperless-ngx are carried by
|
||||
Tier 2 and Tier 3) — what changed is that the page now says so. Measured on a fresh box
|
||||
2026-09-16: five photos in Nextcloud, in no backup, with the page saying they were.
|
||||
Red-proof: restore the old app-shaped label → `TestAppBackupRows_Tier1LabelDoesNotClaimFilesItCannotHold`
|
||||
fails at „the Tier-1 label claims it holds the app's data".
|
||||
- **R-538 — a unit restore replayed a database over files it did not have, reported success, and
|
||||
destroyed the app's own wastebasket on the way.** `RestoreFromRecoveryUnitAt` now REFUSES before
|
||||
anything is touched when the app's files live on the data drive, names the route that can return
|
||||
them (the off-site wizard's „Teljes visszaállítás (fájlok + adatbázis)", or the second drive's
|
||||
„Fájlok visszaállítása"), and says plainly when there is no copy at all. The explicit
|
||||
database-and-settings-only path is a separately-worded second step
|
||||
(`UnitRestoreOptions{AcceptMissingFiles}`), never a sibling control. The refusal runs before the
|
||||
stack is stopped, because the measured harm included the trash going unreachable.
|
||||
Red-proof: disable the guard → `TestUnitRestore_RefusesWhenTheUnitCannotHoldTheFiles` fails at
|
||||
„a restore that cannot return the files must refuse".
|
||||
- **R-536 — the hub was told „Alkalmazás telepítve" when the deploy was merely ACCEPTED.** The API
|
||||
now emits `app_deploy_started` beside its 202, and `app_deployed` is emitted from the async path's
|
||||
own end (`stacks.SetDeployDoneHook`), with `app_deploy_failed` (warning) when it ends badly —
|
||||
which used to be silence. Measured 2026-09-16: mealie was recorded as installed in the same second
|
||||
its deploy was accepted, then killed 5 s in, and ended `not_deployed` with nothing correcting the
|
||||
event. The accept-time `app.yaml` is deliberately NOT deleted on failure: it is the crash-safe
|
||||
record written with `Deployed:false` and it carries the settings the customer typed.
|
||||
Red-proofs: put the old call back → `TestDeployAcceptance_DoesNotClaimTheAppIsInstalled` fails;
|
||||
remove the success-path hook → `TestDeployDoneHook_FiresAtTheEndAndSaysWhichEndItWas` fails at
|
||||
„the deploy ended and nothing was told about it".
|
||||
- Requires hub **v0.116.0**, which registers `app_deploy_started` / `app_deploy_failed` in both
|
||||
`allowedEventTypes` and `customerMessages`; against an older hub those two POSTs 400 and the
|
||||
events are simply absent (`app_deployed` keeps working).
|
||||
|
||||
## Unreleased — after v0.243.0 (2026-09-15)
|
||||
|
||||
- **R-517 follow-up — the whole-system tile printed „0 B" for a backup whose size is unknown.**
|
||||
|
||||
Reference in New Issue
Block a user