v0.244.0: the backup page stops promising what it does not hold (R-537/R-538/R-536)
gates / gates (push) Successful in 17s

R-537 — the contents label is now PER TIER. One string computed from the app's
shape was rendered on all three tier rows; a Tier-1 unit has no file-copy step, so
for the four class-A apps it was claiming „Adatok" for files it does not hold.

R-538 — a unit restore REFUSES before anything is touched when the unit cannot
return the app's drive-side files, and names the route that can. It runs before the
stack is stopped because the measured harm included the app's own wastebasket going
unreachable, which still held every byte.

R-536 — „Alkalmazás telepítve" moved from the deploy's acceptance to its completion,
with app_deploy_started and app_deploy_failed as the honest pair.

Each fix red-proofed: seen failing with its own sentence, passing when restored.
Requires hub v0.116.0 for the two new event types. MinAgent unchanged (0.131.0).

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
This commit is contained in:
2026-09-16 16:55:55 +02:00
parent 383a30b3c0
commit 2f8ff2414c
16 changed files with 640 additions and 50 deletions
+40
View File
@@ -1,3 +1,43 @@
## v0.244.0 — the backup page stops promising what it does not hold, and a restore refuses to lie (2026-09-16, R-537 / R-538 / R-536)
**MinAgent: 0.131.0** (unchanged — nothing here needs a newer agent)
- **R-537 — the app-backup page labelled a Tier-1 unit „DB + Konfig + Adatok" and printed the app's
data-drive size beside it, over a unit that holds no copy of those files.** The label was computed
from the APP's shape (`HasHDDData || HasVolumeData`) and rendered on all three tier rows, so one
string stood for three tiers that capture different things. It is now computed per tier from what
the tier actually carries: Tier 1 says „Adatok" only when the app's data really is inside the
volumes the unit captured, and a class-A app gets one sentence saying where its files ARE
protected. **The design is unchanged** (07-backup-architecture §6.1/§6.2: a Tier-1 unit has no
file-copy step; the file legs of calibre-web, immich, nextcloud and paperless-ngx are carried by
Tier 2 and Tier 3) — what changed is that the page now says so. Measured on a fresh box
2026-09-16: five photos in Nextcloud, in no backup, with the page saying they were.
Red-proof: restore the old app-shaped label → `TestAppBackupRows_Tier1LabelDoesNotClaimFilesItCannotHold`
fails at „the Tier-1 label claims it holds the app's data".
- **R-538 — a unit restore replayed a database over files it did not have, reported success, and
destroyed the app's own wastebasket on the way.** `RestoreFromRecoveryUnitAt` now REFUSES before
anything is touched when the app's files live on the data drive, names the route that can return
them (the off-site wizard's „Teljes visszaállítás (fájlok + adatbázis)", or the second drive's
„Fájlok visszaállítása"), and says plainly when there is no copy at all. The explicit
database-and-settings-only path is a separately-worded second step
(`UnitRestoreOptions{AcceptMissingFiles}`), never a sibling control. The refusal runs before the
stack is stopped, because the measured harm included the trash going unreachable.
Red-proof: disable the guard → `TestUnitRestore_RefusesWhenTheUnitCannotHoldTheFiles` fails at
„a restore that cannot return the files must refuse".
- **R-536 — the hub was told „Alkalmazás telepítve" when the deploy was merely ACCEPTED.** The API
now emits `app_deploy_started` beside its 202, and `app_deployed` is emitted from the async path's
own end (`stacks.SetDeployDoneHook`), with `app_deploy_failed` (warning) when it ends badly —
which used to be silence. Measured 2026-09-16: mealie was recorded as installed in the same second
its deploy was accepted, then killed 5 s in, and ended `not_deployed` with nothing correcting the
event. The accept-time `app.yaml` is deliberately NOT deleted on failure: it is the crash-safe
record written with `Deployed:false` and it carries the settings the customer typed.
Red-proofs: put the old call back → `TestDeployAcceptance_DoesNotClaimTheAppIsInstalled` fails;
remove the success-path hook → `TestDeployDoneHook_FiresAtTheEndAndSaysWhichEndItWas` fails at
„the deploy ended and nothing was told about it".
- Requires hub **v0.116.0**, which registers `app_deploy_started` / `app_deploy_failed` in both
`allowedEventTypes` and `customerMessages`; against an older hub those two POSTs 400 and the
events are simply absent (`app_deployed` keeps working).
## Unreleased — after v0.243.0 (2026-09-15)
- **R-517 follow-up — the whole-system tile printed „0 B" for a backup whose size is unknown.**