R-893: hold the app after ANY failure once the definition or a volume moved; hold persisted before the stop; run_job done says it ran, not what it found (security review)
gates / gates (push) Successful in 56s

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
This commit is contained in:
2026-10-08 15:13:04 +02:00
parent d3e17e9b2e
commit 3f84f82c3d
9 changed files with 134 additions and 28 deletions
+4 -1
View File
@@ -308,7 +308,10 @@ func (o *OperatorActions) dispatch(a OperatorAction) {
case <-o.ctx.Done():
jerr = o.ctx.Err()
}
msg := "the job " + a.Arg + " ran"
// „done" says the job RAN TO ITS END, never what it found (security review 2026-10-08,
// „presence is not success"): offsite-integrity and offsite-proof return nil whatever their
// verdict — the verdict travels in their own log line, event and alarm.
msg := "the job " + a.Arg + " ran to its end — this does not say what it found; its finding is in its own log line and alarms"
if jerr != nil {
msg = "the job " + a.Arg + ": " + jerr.Error()
}