v0.244.0: the backup page stops promising what it does not hold (R-537/R-538/R-536)
gates / gates (push) Successful in 17s

R-537 — the contents label is now PER TIER. One string computed from the app's
shape was rendered on all three tier rows; a Tier-1 unit has no file-copy step, so
for the four class-A apps it was claiming „Adatok" for files it does not hold.

R-538 — a unit restore REFUSES before anything is touched when the unit cannot
return the app's drive-side files, and names the route that can. It runs before the
stack is stopped because the measured harm included the app's own wastebasket going
unreachable, which still held every byte.

R-536 — „Alkalmazás telepítve" moved from the deploy's acceptance to its completion,
with app_deploy_started and app_deploy_failed as the honest pair.

Each fix red-proofed: seen failing with its own sentence, passing when restored.
Requires hub v0.116.0 for the two new event types. MinAgent unchanged (0.131.0).

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
This commit is contained in:
2026-09-16 16:55:55 +02:00
parent 383a30b3c0
commit 2f8ff2414c
16 changed files with 640 additions and 50 deletions
@@ -223,11 +223,61 @@ func (m *Manager) primaryUnitDirFor(stackName string) string {
// start → replay → start, R-47), the secret reconciliation with unit-over-guest precedence and the
// fail-closed data-key gate, and the no-unit fallback to RestoreApp with its CountsUnknown handling.
func (m *Manager) RestoreFromRecoveryUnitAt(stackName, unitDir string) (UnitRestoreResult, error) {
return m.RestoreFromRecoveryUnitAtWith(stackName, unitDir, UnitRestoreOptions{})
}
// UnitRestoreOptions carries the caller's EXPLICIT consent for a restore this package would
// otherwise refuse. It exists because of R-538, and it has exactly one member for now.
type UnitRestoreOptions struct {
// AcceptMissingFiles lets a unit restore proceed for an app whose own files live on the data
// drive and are therefore NOT in the unit. The default — zero value, every existing caller — is
// to REFUSE, because the run that produced this option replayed a database over files that were
// never captured, reported „3 adatkötet és az adatbázis visszaállítva", and left Nextcloud
// listing five photos that returned `Sabre\DAV\Exception\NotFound`.
//
// It is a per-call argument and never a field on the Manager: a consent that outlives the act it
// was given for is not consent.
AcceptMissingFiles bool
}
// ErrUnitLacksFileLegs is the refusal R-538 asks for. It names the app and the paths that are NOT in
// the unit, so the caller can build an honest sentence without re-deriving anything.
type ErrUnitLacksFileLegs struct {
Stack string
Paths []string
}
func (e *ErrUnitLacksFileLegs) Error() string {
return fmt.Sprintf("%s: the recovery unit carries no copy of the app's files on the data drive (%s) — refusing to replay the database over them",
e.Stack, strings.Join(e.Paths, ", "))
}
// RestoreFromRecoveryUnitAtWith is RestoreFromRecoveryUnitAt with the caller's explicit consent
// flags. See UnitRestoreOptions.
func (m *Manager) RestoreFromRecoveryUnitAtWith(stackName, unitDir string, opt UnitRestoreOptions) (UnitRestoreResult, error) {
var res UnitRestoreResult
if m.stackProvider == nil {
return res, fmt.Errorf("stack provider not configured")
}
// R-538 — REFUSE BEFORE ANYTHING IS TOUCHED. This runs before the lock, before the stack is
// stopped and before a single volume is replaced, because the measured harm was not only the
// missing files: the replayed database also stopped referencing the app's OWN wastebasket, which
// still held every byte on the drive. A refusal that has already stopped the app has destroyed
// the customer's last route while declining to help them.
//
// The condition is about the UNIT, not the app class: a unit structurally cannot hold these
// paths (`CaptureRecoveryUnit` has no file-copy step, `RecoveryManifest` no field for one), and
// that is true of the Tier-2 mirror of a unit as well — Tier 2's file half is a separate action
// („Fájlok visszaállítása", RestoreTier2Files), which is exactly what the caller should offer.
if !opt.AcceptMissingFiles {
if legs := m.DeclaredDriveFileLegs(stackName); len(legs) > 0 {
m.logger.Printf("[WARN] [backup] unit restore REFUSED for %s: the unit carries no file leg; %d drive path(s) would be left as they are: %s",
stackName, len(legs), strings.Join(legs, ", "))
return res, &ErrUnitLacksFileLegs{Stack: stackName, Paths: legs}
}
}
m.mu.Lock()
if m.running {
m.mu.Unlock()