v0.228.0 — the off-site check reads the data; the debug page stops lying (R-399 + R-400)
gates / gates (push) Successful in 12s

R-399: monitoring.integrity.read_data_subset defaults to 100%. A pack damaged
without changing its size made plain `restic check` report "no errors were found"
on demo-hp 2026-08-30; every read-data form caught it. Cost on that 134 MB store:
35.0s structure vs 39.2s at 100%. "off" (any case) is the off token; empty means
not-configured, therefore the default; a malformed value falls back to the DEFAULT,
never to structure. A completed check over 5 minutes logs a WARN naming the
duration, the depth and R-401 — operator log only, no hub event, no depth change.
The depth is now recorded with the verdict (LastIntegrityDepth; empty = NOT
RECORDED, never "structure").

R-400: 24 debug-page references, 17 dispatched, 7 dead — three of which fetched on
page LOAD, so those panels were permanently blank. backup/crossdrive implemented;
backup/infra, hub/infra-push, dr/infra-status, storage/watchdog-status and both
storage/simulate-* deleted with their panels and JavaScript.
scripts/debug_route_gate.py fails in both directions and is registered after the
seven were resolved. 18 referenced, 18 dispatched, none orphaned.

Corrections: the dead-field warning in report/types.go said the controller runs no
integrity check and the notifiers are called from nowhere — both false since
v0.227.0. controller.yaml.example gains its missing integrity: block.
integrityCheckTimeout's "ships OFF" comment rewritten.
This commit is contained in:
2026-08-31 10:24:29 +02:00
parent 300d7e87d7
commit 3c49dc8ea4
23 changed files with 1144 additions and 175 deletions
+68
View File
@@ -65,6 +65,11 @@ func (s *Server) handleDebugAPI(w http.ResponseWriter, r *http.Request) {
// Section 3: Backup testing (app-data only; disk-tier moved to host agent)
case subpath == "backup/dbdump" && r.Method == http.MethodPost:
s.debugTriggerDBDump(w, r)
// R-400 — the „Csak cross-drive" button has posted here since it was added and nothing answered.
// The capability was never missing: Manager.RunTier2 is live and the app config page already calls
// it. Only the debug route was absent, so this is IMPLEMENTED rather than deleted.
case subpath == "backup/crossdrive" && r.Method == http.MethodPost:
s.debugRunCrossDrive(w, r)
// R-397 — the button at debug.html:83 has posted here since it was added and NOTHING answered.
// Verified 2026-08-30: this dispatch had no such case, so pressing „Restic integritás" did
// nothing at all. Seventh instance of built-but-never-wired in this project; filed as R-400 in its
@@ -404,6 +409,66 @@ func (s *Server) debugTriggerDBDump(w http.ResponseWriter, r *http.Request) {
writeDebugJSON(w, http.StatusOK, true, "DB dump elindítva", nil)
}
// debugRunCrossDrive runs the Tier-2 (cross-drive) copy for every deployed HDD app (R-400).
//
// ASYNCHRONOUS, following debugTriggerDBDump above rather than the integrity button below: a Tier-2
// sweep across every app copies real data and is bounded by disk speed, not by a timeout, so holding
// the operator's request open for it would time the browser out and teach nothing. The integrity
// button is synchronous because the operator pressed it to learn an ANSWER; this one is pressed to
// make something happen, and the log is where its outcome belongs.
//
// It reports WHICH apps it started for, not just „elindítva". A sweep that quietly matched zero apps
// and a sweep that matched eight are different facts, and a message that cannot tell them apart is
// how a button reads as working while doing nothing — the class this whole row exists to close.
func (s *Server) debugRunCrossDrive(w http.ResponseWriter, r *http.Request) {
if s.backupMgr == nil {
writeDebugJSON(w, http.StatusBadRequest, false, "Backup manager nincs konfigurálva", nil)
return
}
names := crossDriveTargets(s.stackMgr.GetStacks(), func(name string) bool {
return s.backupMgr.Tier2Info(name).IsHDDApp
})
if len(names) == 0 {
writeDebugJSON(w, http.StatusOK, true, "Nincs olyan telepített alkalmazás, amelynek 2. mentése futtatható lenne",
map[string]interface{}{"apps": names, "count": 0})
return
}
go func(apps []string) {
for _, name := range apps {
if err := s.backupMgr.RunTier2(name); err != nil {
s.logger.Printf("[WARN] [web] debug cross-drive run for %s failed: %v", name, err)
continue
}
s.logger.Printf("[INFO] [web] debug cross-drive run for %s completed", name)
}
}(names)
writeDebugJSON(w, http.StatusOK, true,
fmt.Sprintf("Cross-drive mentés elindítva %d alkalmazásra", len(names)),
map[string]interface{}{"apps": names, "count": len(names)})
}
// crossDriveTargets picks the apps a Tier-2 sweep should run for.
//
// A NAMED FUNCTION rather than an inline loop so both of its answers are assertable. The empty answer
// and the non-empty answer are the two outcomes a dead button and a working one are told apart by, and
// building a deployed HDD-backed stack inside a web test is not practical — so the selection is proven
// here and the dispatch is proven at the route.
func crossDriveTargets(all []stacks.Stack, isHDDApp func(name string) bool) []string {
names := make([]string, 0)
for _, st := range all {
if !st.Deployed {
continue
}
// Tier 2 is an off-DRIVE copy: an app with no HDD path has no second drive to copy to, and
// RunTier2 would return "no source drive" for every one of them.
if !isHDDApp(st.Name) {
continue
}
names = append(names, st.Name)
}
return names
}
// debugRunIntegrityCheck runs the off-site integrity check by hand (R-359/R-397).
//
// SYNCHRONOUS on purpose, unlike the DB-dump button beside it: the operator pressed this to learn an
@@ -427,6 +492,9 @@ func (s *Server) debugRunIntegrityCheck(w http.ResponseWriter, r *http.Request)
"unreachable": res.Unreachable,
"duration_ms": res.Duration.Milliseconds(),
"read_data_subset": res.ReadDataSubset,
// R-399: the depth as it is RECORDED, so the JSON says "structure" rather than an empty string
// a reader has to interpret. read_data_subset above stays raw for anyone parsing the argv.
"depth": backup.IntegrityDepthCode(res.ReadDataSubset),
}
switch {
case res.Skipped:
@@ -0,0 +1,147 @@
package web
import (
"encoding/json"
"net/http"
"net/http/httptest"
"os"
"path/filepath"
"strings"
"testing"
"gitea.dooplex.hu/admin/felhom-controller/internal/stacks"
)
// ── R-400 — the debug page stops lying ───────────────────────────────────────────────────────────
//
// Verified 2026-08-31 against the shipped tree: debug.html referenced 24 `/api/debug/...` addresses
// and handleDebugAPI answered 17. Seven controls did nothing. Three of the seven were not buttons —
// `dr/infra-status` and both `storage/watchdog-status` calls fetch on page LOAD, so those panels had
// been permanently empty and nobody had to click anything to be misled. This is the page an operator
// opens when something is already wrong.
//
// The gate in scripts/debug_route_gate.py makes the CLASS impossible. These tests name the individual
// DECISIONS, so that re-adding one of them is deliberate rather than accidental.
// debugTemplateSource reads the shipped template from disk. The served page is rendered from this
// file, so a reference that is gone here is gone from the page — and reading the source is what lets
// a deletion be asserted without a browser (none is available on this host).
func debugTemplateSource(t *testing.T) string {
t.Helper()
b, err := os.ReadFile(filepath.Join("templates", "debug.html"))
if err != nil {
t.Fatalf("read debug.html: %v", err)
}
return string(b)
}
// D2 — every control DELETED in Part 2.1, by name, with its reason.
func TestR400_DeletedControlsAreGoneFromTheTemplate(t *testing.T) {
src := debugTemplateSource(t)
deleted := []struct{ ref, why string }{
{"/api/debug/backup/infra",
"the disk-tier infra backup moved to the host agent (slice 8C); no function in this repo backs it"},
{"/api/debug/hub/infra-push",
"Pusher.PushInfraBackup was removed 2026-06-16 — retired hub-side, and it had pushed plaintext secrets"},
{"/api/debug/dr/infra-status",
"it rendered local infra backups and the hub infra push, both of which are the two retired mechanisms above"},
{"/api/debug/storage/watchdog-status",
"the slice-8C storage watchdog is retired; the drive-gate reconcile replaced it and publishes no such status"},
{"/api/debug/storage/simulate-disconnect",
"no backing capability, and it WRITES storage state — a button that fakes a drive disconnect on a customer's machine is a foot-gun"},
{"/api/debug/storage/simulate-reconnect", "same as simulate-disconnect"},
}
for _, d := range deleted {
if strings.Contains(src, d.ref) {
t.Errorf("%s is still referenced by debug.html — it was deleted because %s", d.ref, d.why)
}
}
// POSITIVE CONTROL. Without it this test passes against a template it failed to read, or one that
// was emptied — the exact shape of an assertion that proves nothing.
for _, kept := range []string{"/api/debug/backup/integrity", "/api/debug/dr/trigger-setup"} {
if !strings.Contains(src, kept) {
t.Fatalf("positive control failed: %s is missing too, so the assertions above prove nothing "+
"about what was deliberately deleted", kept)
}
}
}
// D2b — the panels and the JavaScript went with the controls. A panel left behind renders nothing
// forever, which is how this whole class hides.
func TestR400_DeletedControlsLeftNoPanelOrScript(t *testing.T) {
src := debugTemplateSource(t)
// ASCII-only fragments (R-364): accented Hungarian through a template read is not the hazard here,
// but the rule is uniform and these identifiers are ASCII anyway.
for _, orphan := range []string{
"watchdog-status", // the panel div and its two loaders
"renderWatchdogStatus",
"loadWatchdogStatus",
"simulateDisconnect",
"simulateReconnect",
"loadDRStatus",
"dr-status",
"btn-infra-backup",
"btn-hub-infra",
"section-storage",
} {
if strings.Contains(src, orphan) {
t.Errorf("%q survived the deletion — an orphaned panel or handler renders nothing forever "+
"and reads as a working page", orphan)
}
}
// POSITIVE CONTROL: the neighbours that must stay.
for _, kept := range []string{"btn-dr-trigger", "triggerDR", "section-dr", "btn-crossdrive"} {
if !strings.Contains(src, kept) {
t.Fatalf("positive control failed: %q is gone too — the deletion took a neighbour with it", kept)
}
}
}
// D1 — the one control IMPLEMENTED in Part 2.1 dispatches and answers with its JSON shape.
func TestR400_CrossDriveRouteDispatches(t *testing.T) {
// backupMgr nil is the fixture on purpose: it reaches the handler's own guard, which proves the
// route was DISPATCHED. A 404 here is the defect — that is precisely what the button got before.
s := newDebugServer(t, nil)
req := httptest.NewRequest(http.MethodPost, "/api/debug/backup/crossdrive", nil)
w := httptest.NewRecorder()
s.handleDebugAPI(w, req)
if w.Code == http.StatusNotFound {
t.Fatal("POST /api/debug/backup/crossdrive returned 404 — the button still posts to nothing")
}
var env map[string]interface{}
if err := json.Unmarshal(w.Body.Bytes(), &env); err != nil {
t.Fatalf("the route answered with something that is not the debug JSON envelope: %q", w.Body.String())
}
if _, has := env["ok"]; !has {
t.Errorf("no `ok` in the envelope: %v", env)
}
}
// D1b — and it answers with the app list when a manager IS present. The empty sweep and the non-empty
// sweep are different facts, and „elindítva" alone cannot tell them apart.
func TestR400_CrossDriveReportsWhichAppsItStarted(t *testing.T) {
// The selection itself, both answers, through the same function the handler calls.
all := []stacks.Stack{
{Name: "immich", Deployed: true},
{Name: "vaultwarden", Deployed: true},
{Name: "not-deployed", Deployed: false},
}
hdd := func(name string) bool { return name == "immich" }
got := crossDriveTargets(all, hdd)
if len(got) != 1 || got[0] != "immich" {
t.Fatalf("the sweep picked %v — it must take deployed HDD-backed apps only: an app with no "+
"second drive has nowhere to copy to, and an undeployed app has nothing to copy", got)
}
if none := crossDriveTargets(all, func(string) bool { return false }); len(none) != 0 {
t.Errorf("with no HDD app the sweep must be EMPTY, not a silent all-apps run: %v", none)
}
// NON-nil empty slice: it marshals as [] rather than null, so the JSON says "zero apps" instead of
// "no answer".
if none := crossDriveTargets(nil, hdd); none == nil {
t.Error("the empty answer is nil — it would marshal as `null`, which reads as 'unknown' rather " +
"than 'none', the same conflation R-331 cost a whole operator card")
}
}
@@ -82,24 +82,10 @@
<button class="btn btn-secondary btn-sm" id="btn-integrity" data-label="Restic integritás" onclick="triggerAction('btn-integrity','/api/debug/backup/integrity','POST')">Restic integritás</button>
<span class="debug-result" id="btn-integrity-result"></span>
<button class="btn btn-secondary btn-sm" id="btn-infra-backup" data-label="Infra mentés" onclick="triggerAction('btn-infra-backup','/api/debug/backup/infra','POST')">Infra mentés</button>
<span class="debug-result" id="btn-infra-backup-result"></span>
</div>
</div>
</div>
<!-- Section 4: Storage Testing -->
<div class="card debug-section" id="section-storage">
<div class="card-header debug-section-header" onclick="toggleSection('storage')">
<h3>Tárhely teszt</h3>
<span class="section-toggle">▶</span>
</div>
<div class="card-body debug-section-body" style="display:none">
<div id="watchdog-status"><span class="text-muted">Betöltés...</span></div>
</div>
</div>
<!-- Section 5: Hub & Connectivity -->
<div class="card debug-section" id="section-hub">
<div class="card-header debug-section-header" onclick="toggleSection('hub')">
@@ -112,9 +98,6 @@
<button class="btn btn-primary btn-sm" id="btn-hub-push" data-label="Hub jelentés küldése" onclick="triggerAction('btn-hub-push','/api/debug/hub/push','POST')">Hub jelentés küldése</button>
<span class="debug-result" id="btn-hub-push-result"></span>
<button class="btn btn-secondary btn-sm" id="btn-hub-infra" data-label="Infra backup küldése" onclick="triggerAction('btn-hub-infra','/api/debug/hub/infra-push','POST')">Infra backup küldése</button>
<span class="debug-result" id="btn-hub-infra-result"></span>
<button class="btn btn-secondary btn-sm" id="btn-hub-conn" data-label="Hub elérhetőség" onclick="triggerAction('btn-hub-conn','/api/debug/hub/test-connectivity','POST')">Hub elérhetőség</button>
<span class="debug-result" id="btn-hub-conn-result"></span>
@@ -168,7 +151,6 @@
<span class="section-toggle">▶</span>
</div>
<div class="card-body debug-section-body" style="display:none">
<div id="dr-status"><span class="text-muted">Betöltés...</span></div>
<div class="debug-actions" style="margin-top:1rem">
<div class="debug-dr-danger">
<p style="color:var(--crit);font-weight:600">Vészhelyzet szimuláció</p>
@@ -305,11 +287,9 @@ function loadSectionData(id) {
case 'diagnostic': loadDiagnostic(); break;
case 'events': loadEventHistory(); break;
case 'backup': loadBackupStatus(); break;
case 'storage': loadWatchdogStatus(); break;
case 'hub': loadHubStatus(); break;
case 'telemetry': break; // no auto-load, user triggers manually
case 'selfupdate': loadSelfUpdateStatus(); break;
case 'dr': loadDRStatus(); break;
case 'appexport': loadAppExportStatus(); break;
case 'logs': initLogViewer(); break;
}
@@ -432,65 +412,6 @@ function loadBackupStatus() {
});
}
// ── Section 4: Storage ──
function loadWatchdogStatus() {
fetch('/api/debug/storage/watchdog-status', {headers: csrfHeaders()}).then(function(r){return r.json()}).then(function(data) {
if (!data.ok) { document.getElementById('watchdog-status').innerHTML = '<span class="text-muted">Nem elérhető</span>'; return; }
renderWatchdogStatus(data.data);
}).catch(function() {
document.getElementById('watchdog-status').innerHTML = '<span class="text-muted">Nem elérhető</span>';
});
startPolling('storage', 5000, function() {
fetch('/api/debug/storage/watchdog-status', {headers: csrfHeaders()}).then(function(r){return r.json()}).then(function(data) {
if (data.ok) renderWatchdogStatus(data.data);
}).catch(function(){});
});
}
function renderWatchdogStatus(paths) {
if (!paths || paths.length === 0) {
document.getElementById('watchdog-status').innerHTML = '<span class="text-muted">Nincs tárhely</span>';
return;
}
var html = '<table class="info-table debug-table"><tr><th>Útvonal</th><th>Cimke</th><th>Állapot</th><th>Probe</th><th>Debounce</th><th>Latency</th><th>Művelet</th></tr>';
paths.forEach(function(p) {
var dot = p.status === 'connected' ? '<span class="status-dot green"></span>' : '<span class="status-dot red"></span>';
var simBadge = p.simulated ? ' <span class="badge-warn">SIM</span>' : '';
var action = '';
if (p.status === 'connected' && !p.simulated) {
action = '<button class="btn btn-xs btn-secondary" onclick="simulateDisconnect(this,\'' + p.path + '\')">Leválasztás</button>';
} else if (p.simulated) {
action = '<button class="btn btn-xs btn-primary" onclick="simulateReconnect(\'' + p.path + '\')">Visszacsatl.</button>';
}
html += '<tr><td class="mono">' + p.path + '</td><td>' + (p.label||'-') + '</td><td>' + dot + ' ' + p.status + simBadge + '</td>';
html += '<td>' + (p.probe_ok_count||0) + '/' + (p.probe_count||0) + '</td><td>' + (p.debounce_count||0) + '/' + (p.debounce_max||3) + '</td>';
html += '<td>' + (p.avg_latency_ms ? p.avg_latency_ms.toFixed(1) + 'ms' : '-') + '</td><td>' + action + '</td></tr>';
});
html += '</table>';
document.getElementById('watchdog-status').innerHTML = html;
}
function simulateDisconnect(btn, path) {
felhomConfirm(btn, 'Biztosan szimulálja a leválasztást? Ez leállítja az érintett alkalmazásokat.', function () {
fetch('/api/debug/storage/simulate-disconnect', {
method: 'POST',
headers: Object.assign({'Content-Type':'application/json'}, csrfHeaders()),
body: JSON.stringify({path: path})
}).then(function(r){return r.json()}).then(function(data) {
if (!data.ok) showAlert('Hiba: ' + (data.error || 'ismeretlen'));
loadWatchdogStatus();
}).catch(function(e) { showAlert('Hiba: ' + e.message); });
});
}
function simulateReconnect(path) {
fetch('/api/debug/storage/simulate-reconnect', {
method: 'POST',
headers: Object.assign({'Content-Type':'application/json'}, csrfHeaders()),
body: JSON.stringify({path: path})
}).then(function(r){return r.json()}).then(function(data) {
if (!data.ok) showAlert('Hiba: ' + (data.error || 'ismeretlen'));
loadWatchdogStatus();
}).catch(function(e) { showAlert('Hiba: ' + e.message); });
}
// ── Section 5: Hub ──
function loadHubStatus() {
fetch('/api/debug/dump', {headers: csrfHeaders()}).then(function(r){return r.json()}).then(function(data) {
@@ -527,32 +448,6 @@ function loadSelfUpdateStatus() {
}
// ── Section 7: DR ──
function loadDRStatus() {
fetch('/api/debug/dr/infra-status', {headers: csrfHeaders()}).then(function(r){return r.json()}).then(function(data) {
if (!data.ok) { document.getElementById('dr-status').innerHTML = '<span class="text-muted">Nem elérhető</span>'; return; }
var d = data.data || {};
var html = '<h4>Helyi infra backup</h4>';
if (d.drives && d.drives.length > 0) {
html += '<table class="info-table debug-table"><tr><th>Meghajtó</th><th>Cimke</th><th>Állapot</th><th>Utolsó módosítás</th><th>Fájlok</th></tr>';
d.drives.forEach(function(dr) {
var files = (dr.files || []).join(', ') || '-';
html += '<tr><td class="mono">' + dr.path + '</td><td>' + (dr.label||'-') + '</td><td>' + (dr.has_backup ? 'Van' : '<span class="state-text-warn">Nincs</span>') + '</td><td>' + (dr.last_modified ? fmtTime(dr.last_modified) : '-') + '</td><td class="text-muted" style="font-size:.75rem">' + files + '</td></tr>';
});
html += '</table>';
} else {
html += '<span class="text-muted">Nincs csatlakoztatott meghajtó</span>';
}
if (d.hub_infra_push) {
html += '<h4>Hub infra backup</h4><div class="debug-kv-grid">';
html += '<span>Utolsó push:</span><span>' + (d.hub_infra_push.last_success ? fmtTime(d.hub_infra_push.last_success) : '-') + '</span>';
if (d.hub_infra_push.last_error) html += '<span>Utolsó hiba:</span><span class="debug-result-error">' + d.hub_infra_push.last_error + '</span>';
html += '</div>';
}
document.getElementById('dr-status').innerHTML = html;
}).catch(function() {
document.getElementById('dr-status').innerHTML = '<span class="text-muted">Nem elérhető</span>';
});
}
function triggerDR() {
var input = document.getElementById('dr-confirm-input');
if (input.value !== 'RESET') {