v0.228.0 — the off-site check reads the data; the debug page stops lying (R-399 + R-400)
gates / gates (push) Successful in 12s

R-399: monitoring.integrity.read_data_subset defaults to 100%. A pack damaged
without changing its size made plain `restic check` report "no errors were found"
on demo-hp 2026-08-30; every read-data form caught it. Cost on that 134 MB store:
35.0s structure vs 39.2s at 100%. "off" (any case) is the off token; empty means
not-configured, therefore the default; a malformed value falls back to the DEFAULT,
never to structure. A completed check over 5 minutes logs a WARN naming the
duration, the depth and R-401 — operator log only, no hub event, no depth change.
The depth is now recorded with the verdict (LastIntegrityDepth; empty = NOT
RECORDED, never "structure").

R-400: 24 debug-page references, 17 dispatched, 7 dead — three of which fetched on
page LOAD, so those panels were permanently blank. backup/crossdrive implemented;
backup/infra, hub/infra-push, dr/infra-status, storage/watchdog-status and both
storage/simulate-* deleted with their panels and JavaScript.
scripts/debug_route_gate.py fails in both directions and is registered after the
seven were resolved. 18 referenced, 18 dispatched, none orphaned.

Corrections: the dead-field warning in report/types.go said the controller runs no
integrity check and the notifiers are called from nowhere — both false since
v0.227.0. controller.yaml.example gains its missing integrity: block.
integrityCheckTimeout's "ships OFF" comment rewritten.
This commit is contained in:
2026-08-31 10:24:29 +02:00
parent 300d7e87d7
commit 3c49dc8ea4
23 changed files with 1144 additions and 175 deletions
+9
View File
@@ -304,6 +304,15 @@ type OffboxTarget struct {
// a dated check that is quietly missed and never catches up.
LastIntegrityCheck string `json:"last_integrity_check,omitempty"` // RFC3339
LastIntegrityOK bool `json:"last_integrity_ok,omitempty"`
// LastIntegrityDepth (R-399) records HOW DEEP that verdict looked: "structure" for the
// structure-and-index check, or the subset spec that was re-read ("100%", "10%", "1/7", ...).
//
// It is a third field rather than a flag for the same reason there are two above: "checked, OK"
// means two different things at structure depth and at 100%, and a verdict that cannot say which
// cannot be judged afterwards. EMPTY means NOT RECORDED — a verdict written by a controller older
// than v0.228.0 — and never "structure"; absence means the box cannot answer, exactly as StatsKnown
// below establishes for the counts.
LastIntegrityDepth string `json:"last_integrity_depth,omitempty"`
LastError string `json:"last_error,omitempty"`
LastDuration string `json:"last_duration,omitempty"`
RepoSizeHuman string `json:"repo_size_human,omitempty"`