v0.228.0 — the off-site check reads the data; the debug page stops lying (R-399 + R-400)
gates / gates (push) Successful in 12s
gates / gates (push) Successful in 12s
R-399: monitoring.integrity.read_data_subset defaults to 100%. A pack damaged without changing its size made plain `restic check` report "no errors were found" on demo-hp 2026-08-30; every read-data form caught it. Cost on that 134 MB store: 35.0s structure vs 39.2s at 100%. "off" (any case) is the off token; empty means not-configured, therefore the default; a malformed value falls back to the DEFAULT, never to structure. A completed check over 5 minutes logs a WARN naming the duration, the depth and R-401 — operator log only, no hub event, no depth change. The depth is now recorded with the verdict (LastIntegrityDepth; empty = NOT RECORDED, never "structure"). R-400: 24 debug-page references, 17 dispatched, 7 dead — three of which fetched on page LOAD, so those panels were permanently blank. backup/crossdrive implemented; backup/infra, hub/infra-push, dr/infra-status, storage/watchdog-status and both storage/simulate-* deleted with their panels and JavaScript. scripts/debug_route_gate.py fails in both directions and is registered after the seven were resolved. 18 referenced, 18 dispatched, none orphaned. Corrections: the dead-field warning in report/types.go said the controller runs no integrity check and the notifiers are called from nowhere — both false since v0.227.0. controller.yaml.example gains its missing integrity: block. integrityCheckTimeout's "ships OFF" comment rewritten.
This commit is contained in:
@@ -114,9 +114,17 @@ type BackupReport struct {
|
||||
// protected?".
|
||||
//
|
||||
// **The live numbers are in `Offsite` (backup.OffboxReportStatus) — read that instead**, and
|
||||
// consult its `StatsKnown` before believing a zero. `IntegrityOK` has no source at all: the
|
||||
// controller runs no integrity check, and `NotifyIntegrityOK`/`NotifyIntegrityFailed` exist and
|
||||
// are called from nowhere — so it can only ever be a lie or a permanent "Unknown".
|
||||
// consult its `StatsKnown` before believing a zero. That includes the integrity verdict: it is
|
||||
// published as `Offsite.LastIntegrityCheck` / `LastIntegrityOK` / `LastIntegrityDepth`.
|
||||
//
|
||||
// CORRECTED 2026-08-31 (R-399). The sentence here used to read "`IntegrityOK` has no source at
|
||||
// all: the controller runs no integrity check, and `NotifyIntegrityOK`/`NotifyIntegrityFailed`
|
||||
// exist and are called from nowhere". BOTH HALVES BECAME FALSE IN v0.227.0 — the check runs weekly
|
||||
// and both notifiers are called. The fields below are still dead and still unrendered, but the
|
||||
// reason changed: not "nothing produces it" but "the live verdict lives on OffboxReportStatus, and
|
||||
// these are kept only so historical reports already in the hub's store keep parsing". Giving them
|
||||
// a value now would resurrect the card R-331 removed. A warning block asserting a fact that has
|
||||
// stopped being true is how the next reader concludes the opposite of what it means.
|
||||
//
|
||||
// They are kept rather than deleted so historical reports already in the hub's store keep
|
||||
// parsing; pinned by TestBackupReport_DeadFieldsStayZero.
|
||||
|
||||
Reference in New Issue
Block a user