v0.236.0: "delete my data too" deletes the data, or says that it could not (R-442)
gates / gates (push) Successful in 13s

Removal resolves the drive from the app's own app.yaml HDD_PATH (the 07 ~L437
rule), never the global cfg.Paths.HDDPath which no box sets. A data removal
that cannot be resolved, or whose drive is absent, is refused with a typed
RemoveRefusedError -> 409 + exact Hungarian sentence, before compose down, and
the app is kept. SSD app -> hdd_paths_removed: [] never null; missing folders
stated; backup-path refusals reach the response.

15 tests, two red-proofs run (pre-fix fallback -> C fails with err=nil and the
handler 200s; "no drive refuses" -> D fails).

Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
This commit is contained in:
2026-09-13 08:52:25 +02:00
parent bab82c471e
commit 42a73e667a
9 changed files with 763 additions and 21 deletions
+167 -16
View File
@@ -18,20 +18,139 @@ import (
const felhomDataDir = "felhom-data"
// DeleteResponse holds the result of a stack deletion (orphan delete).
//
// R-442 (v0.236.0): HDDPathsRemoved / HDDPathsPreserved are ALWAYS non-nil — an empty list is `[]`,
// never `null`, because `null` was what a silently inert removal looked like for months and the two
// must be distinguishable. HDDPathsMissing lists folders the app recorded that were already gone from
// the drive (a fact, not a refusal). HDDNote is one customer-facing sentence about what was NOT
// found — empty when nothing needs saying.
type DeleteResponse struct {
Deleted string `json:"deleted"`
VolumesRemoved []string `json:"volumes_removed"`
HDDPathsRemoved []string `json:"hdd_paths_removed"`
HDDPathsPreserved []string `json:"hdd_paths_preserved"`
HDDPathsMissing []string `json:"hdd_paths_missing,omitempty"`
HDDNote string `json:"hdd_note,omitempty"`
}
// RemoveResponse holds the result of removing a deployed (non-orphaned) stack.
// RemoveResponse holds the result of removing a deployed (non-orphaned) stack. Same R-442 shape as
// DeleteResponse, plus the backup half: BackupPathsRefused carries every backup path the removal
// declined to touch and why — until v0.236.0 that refusal existed only as a WARN log line.
type RemoveResponse struct {
Removed string `json:"removed"`
VolumesRemoved []string `json:"volumes_removed"`
HDDPathsRemoved []string `json:"hdd_paths_removed"`
HDDPathsPreserved []string `json:"hdd_paths_preserved"`
HDDPathsMissing []string `json:"hdd_paths_missing,omitempty"`
HDDNote string `json:"hdd_note,omitempty"`
BackupPathsRemoved []string `json:"backup_paths_removed,omitempty"`
BackupPathsRefused []string `json:"backup_paths_refused,omitempty"`
}
// RemoveRefusedError is a removal REFUSED before anything was touched: the customer asked for the
// app's data to go with it and the box cannot honour that. It is a typed error so the API handler can
// map it to a non-2xx status and show Message verbatim (R-442). The app is NOT removed either — an app
// gone with its data left behind is unrecoverable from the UI (the customer cannot even re-run the
// removal). Same class as R-443: success is never reported over inaction.
type RemoveRefusedError struct {
Reason string // RefuseHDDUnresolved | RefuseDriveAbsent — for logs and tests
Message string // Hungarian, customer-facing, exact
}
func (e *RemoveRefusedError) Error() string { return e.Message }
// RemoveRefusedError reasons.
const (
RefuseHDDUnresolved = "hdd_unresolved" // data removal requested; compose binds a drive; app.yaml records none
RefuseDriveAbsent = "drive_absent" // data removal requested; the recorded drive is not mounted right now
)
// Customer-facing copy for the R-442 shapes. Exact strings — the live validation greps ASCII
// fragments of them (`llap` for the first, `nem el` for the second).
const (
msgHDDUnresolved = "Az alkalmazás adatainak helye nem állapítható meg, ezért semmit nem töröltünk. Az alkalmazás nem lett eltávolítva."
msgDriveAbsentFmt = "A(z) %s tárhely jelenleg nem elérhető — az alkalmazás nem távolítható el, amíg a meghajtó vissza nem csatlakozik."
noteNoDriveData = "Az alkalmazás nem tárolt saját adatot külső meghajtón, így ott nem volt mit törölni."
noteMissingFmt = "A következő adatmappa már nem volt a meghajtón: %s"
backupRefusedFmt = "%s — a mentés helye a várt mappán kívül esik, ezért nem töröltük"
)
// appHDDPath returns the data drive the named app RECORDED for itself at deploy time — app.yaml's
// HDD_PATH — and whether it recorded one at all.
//
// It implements, for the removal path, the rule 07-backup-architecture.md states under "[DESIGN]
// 2026-08-22 — the restore destination is resolved by the same rule as the capture destination"
// (~L437): "the drive if the app declares one (HDD_PATH), the system data path otherwise". Deploy
// (withPathVars), the start gate (api.startGatedByMissingDrive) and the backup destination
// (backup.GetAppDrivePath) all read the app's own record. Until v0.236.0 removal alone read the
// GLOBAL cfg.Paths.HDDPath — set on no box — so "delete my data" resolved zero mounts and reported
// success over 128 MB left on the drive (R-442, measured on demo-hp 2026-09-01).
//
// DELIBERATELY NO FALLBACK to m.cfg.Paths.HDDPath when the per-app value is empty. A single global
// drive is the assumption the storage arc removed (a customer can have several), and an empty answer
// must reach the caller as "not declared" so it can tell an SSD-only app (nothing to remove — a fact)
// from a removal it cannot honour (a refusal). A silent fallback is the exact path R-442 closes.
func (m *Manager) appHDDPath(name string) (string, bool) {
cfg := m.LoadAppConfigByName(name)
if cfg == nil {
return "", false
}
hdd := strings.TrimSpace(cfg.Env["HDD_PATH"])
if hdd == "" {
return "", false
}
return filepath.Clean(hdd), true
}
// composeBindsDrive reports whether the app's compose file binds anything under ${HDD_PATH} or
// ${USERDATA_PATH} — whether the app keeps data on a drive AT ALL. This is R-442's deduplication
// rule: "declares no drive" is a fact (an SSD-resident app — nothing to remove, empty list), while
// "binds a drive it cannot resolve" is a failure (refuse). Read through the ONE authoritative bind
// scanner; ParseComposeHDDMounts is unchanged.
func composeBindsDrive(composePath string) bool {
for _, b := range ParseComposeClassifiableBinds(composePath) {
if b.Root == appbackup.RootHDD || b.Root == appbackup.RootUserdata {
return true
}
}
return false
}
// hddPathForRemoval resolves the drive a removal acts on, or refuses — BEFORE anything is touched.
// Returns (path, declared, nil) to proceed; a *RemoveRefusedError to stop. Every refusal is logged at
// ERROR here AND returned to the caller, never one without the other. A removal that does not ask
// for the data is never refused on HDD grounds.
func (m *Manager) hddPathForRemoval(op, name, composePath string, removeHDDData bool) (string, bool, error) {
hddPath, declared := m.appHDDPath(name)
if !removeHDDData {
return hddPath, declared, nil
}
if !declared {
if composeBindsDrive(composePath) {
m.logger.Printf("[ERROR] [stacks] %s %s refused: data removal requested, the compose binds a drive path, but app.yaml records no HDD_PATH — nothing removed, app kept (R-442)", op, name)
return "", false, &RemoveRefusedError{Reason: RefuseHDDUnresolved, Message: msgHDDUnresolved}
}
return "", false, nil // SSD-resident: there is no drive data, and that is a fact
}
if !m.DriveLive(hddPath) {
m.logger.Printf("[ERROR] [stacks] %s %s refused: data removal requested but the drive recorded in HDD_PATH is not mounted — nothing removed, app kept (R-442)", op, name)
return hddPath, true, &RemoveRefusedError{Reason: RefuseDriveAbsent, Message: fmt.Sprintf(msgDriveAbsentFmt, hddPath)}
}
return hddPath, true, nil
}
// hddNoteFor composes the one-sentence HDDNote (see DeleteResponse). Only when the data was asked
// for: a kept-data removal has nothing to explain about what was not found.
func hddNoteFor(removeHDDData bool, mounts, missing []string) string {
switch {
case !removeHDDData:
return ""
case len(mounts) == 0:
return noteNoDriveData
case len(missing) > 0:
return fmt.Sprintf(noteMissingFmt, strings.Join(missing, ", "))
}
return ""
}
// BackupDataResponse holds information about backup data associated with a stack.
@@ -117,13 +236,20 @@ func (m *Manager) DeleteStack(name string, removeHDDData bool) (*DeleteResponse,
}
stackDir := filepath.Dir(stack.ComposePath)
hddPath := m.cfg.Paths.HDDPath
// R-442: the app's OWN recorded drive, never the global config — and a refusal here happens
// before compose down, so a refused removal has touched nothing.
hddPath, hddDeclared, err := m.hddPathForRemoval("DeleteStack", name, stack.ComposePath, removeHDDData)
if err != nil {
return nil, err
}
m.logger.Printf("[INFO] Deleting orphaned stack: %s (removeHDDData=%v)", name, removeHDDData)
m.logger.Printf("[INFO] Deleting orphaned stack: %s (removeHDDData=%v, hddDeclared=%v)", name, removeHDDData, hddDeclared)
start := time.Now()
resp := &DeleteResponse{
Deleted: name,
Deleted: name,
HDDPathsRemoved: []string{},
HDDPathsPreserved: []string{},
}
// Step 1: Parse compose file for HDD bind mounts
@@ -169,7 +295,8 @@ func (m *Manager) DeleteStack(name string, removeHDDData bool) (*DeleteResponse,
if m.isDebug() {
m.logger.Printf("[DEBUG] [stacks] DeleteStack %s: HDD path does not exist, skipping: %s", name, cleanPath)
}
continue // path doesn't exist, nothing to do
resp.HDDPathsMissing = append(resp.HDDPathsMissing, cleanPath) // R-442: stated, not a refusal
continue // path doesn't exist, nothing to do
}
if removeHDDData {
@@ -192,6 +319,7 @@ func (m *Manager) DeleteStack(name string, removeHDDData bool) (*DeleteResponse,
resp.HDDPathsPreserved = append(resp.HDDPathsPreserved, fmt.Sprintf("%s (%s)", cleanPath, sizeHuman))
}
}
resp.HDDNote = hddNoteFor(removeHDDData, hddMounts, resp.HDDPathsMissing)
// Step 5: Remove stack directory
if m.isDebug() {
@@ -223,14 +351,15 @@ func (m *Manager) GetStackHDDData(name string) (*HDDDataResponse, error) {
return nil, fmt.Errorf("stack %q not found", name)
}
hddPath := m.cfg.Paths.HDDPath
// R-442: the app's own recorded HDD_PATH, not the global config (which no box sets).
hddPath, declared := m.appHDDPath(name)
resp := &HDDDataResponse{
Stack: name,
}
if hddPath == "" {
if !declared {
if m.isDebug() {
m.logger.Printf("[DEBUG] [stacks] GetStackHDDData %s: no HDD path configured, returning empty", name)
m.logger.Printf("[DEBUG] [stacks] GetStackHDDData %s: app.yaml records no HDD_PATH, returning empty", name)
}
return resp, nil
}
@@ -322,13 +451,20 @@ func (m *Manager) RemoveStack(name string, removeHDDData bool, backupPathsToRemo
}
stackDir := filepath.Dir(stack.ComposePath)
hddPath := m.cfg.Paths.HDDPath
// R-442: the app's OWN recorded drive, never the global config — and a refusal here happens
// before compose down, so a refused removal has touched nothing.
hddPath, hddDeclared, err := m.hddPathForRemoval("RemoveStack", name, stack.ComposePath, removeHDDData)
if err != nil {
return nil, err
}
m.logger.Printf("[INFO] Removing deployed stack: %s (removeHDDData=%v, backupPaths=%d)", name, removeHDDData, len(backupPathsToRemove))
m.logger.Printf("[INFO] Removing deployed stack: %s (removeHDDData=%v, hddDeclared=%v, backupPaths=%d)", name, removeHDDData, hddDeclared, len(backupPathsToRemove))
start := time.Now()
resp := &RemoveResponse{
Removed: name,
Removed: name,
HDDPathsRemoved: []string{},
HDDPathsPreserved: []string{},
}
// Step 1: Parse compose file for HDD bind mounts
@@ -372,6 +508,7 @@ func (m *Manager) RemoveStack(name string, removeHDDData bool, backupPathsToRemo
if m.isDebug() {
m.logger.Printf("[DEBUG] [stacks] RemoveStack %s: HDD path does not exist, skipping: %s", name, cleanPath)
}
resp.HDDPathsMissing = append(resp.HDDPathsMissing, cleanPath) // R-442: stated, not a refusal
continue
}
@@ -395,17 +532,31 @@ func (m *Manager) RemoveStack(name string, removeHDDData bool, backupPathsToRemo
}
}
// Step 5: Handle backup data cleanup. Model A: backups/ sits directly under the namespace-root
// drive mount (no felhom-data segment).
backupsBase := filepath.Join(hddPath, "backups")
resp.HDDNote = hddNoteFor(removeHDDData, hddMounts, resp.HDDPathsMissing)
// Step 5: Handle backup data cleanup. Model A: backups/ sits directly under the app's felhom-data
// namespace root. R-442: that root is resolved by the SAME rule as the data half and as the
// router's AppNamespaceRoot that produced these paths — the app's own drive when it records one,
// the system data path otherwise (07-backup-architecture.md ~L437) — instead of the global
// cfg.Paths.HDDPath, under which every backup path was refused on every box. And the refusal now
// reaches the response (BackupPathsRefused), not only the log.
nsDrive := hddPath
if !hddDeclared {
nsDrive = m.sysDataPath
}
backupsBase := ""
if nsDrive != "" {
backupsBase = filepath.Join(appbackup.NamespaceRootFor(nsDrive, m.sysDataPath), "backups")
}
if m.isDebug() {
m.logger.Printf("[DEBUG] [stacks] RemoveStack %s: processing %d backup paths for removal (base=%s)", name, len(backupPathsToRemove), backupsBase)
}
for _, bkPath := range backupPathsToRemove {
cleanPath := filepath.Clean(bkPath)
// Validate path is under the expected backups directory
if hddPath == "" || !strings.HasPrefix(cleanPath, backupsBase+string(filepath.Separator)) {
m.logger.Printf("[WARN] Refusing to remove backup path outside expected directory: %s", cleanPath)
if backupsBase == "" || !strings.HasPrefix(cleanPath, backupsBase+string(filepath.Separator)) {
m.logger.Printf("[WARN] Refusing to remove backup path outside expected directory: %s (expected under %s)", cleanPath, backupsBase)
resp.BackupPathsRefused = append(resp.BackupPathsRefused, fmt.Sprintf(backupRefusedFmt, cleanPath))
continue
}
if _, err := os.Stat(cleanPath); os.IsNotExist(err) {
@@ -0,0 +1,418 @@
package stacks
import (
"encoding/json"
"errors"
"io"
"log"
"os"
"path/filepath"
"runtime"
"strings"
"testing"
"gitea.dooplex.hu/admin/felhom-controller/internal/config"
)
// R-442 — "delete my data too" must delete the data, or say that it could not.
//
// Every test here asserts the EFFECT on a real t.TempDir() tree (the folder is gone / is still
// there / app.yaml is gone / is still there), never "no error". The compose process boundary is a
// stub script that leaves a marker file, so a refusal can be shown to have run NOTHING.
//
// COMPANION RED-PROOFS (both run, both recorded in REPORT.md):
// 1. Scenario C — model the pre-fix resolver (fall back to the global cfg.Paths.HDDPath, never
// refuse) → TestRemoveStack_R442_RefusesWhenDriveUnresolvable FAILS: err=nil, app.yaml gone,
// hdd_paths_removed empty.
// 2. Scenario D — make "declares no drive" refuse → TestRemoveStack_R442_SSDAppIsNotRefused FAILS.
const r442SysData = "/mnt/sys_drive"
// newR442Manager builds a Manager with ONE deployed, stopped stack from the given compose and
// app.yaml, a marker-leaving stub compose on PATH, and the mountpoint seam answering "live" for
// `liveDrive` only. Returns the manager, the stack dir and the compose marker path.
func newR442Manager(t *testing.T, name, compose, appYAML, liveDrive string) (*Manager, string, string) {
t.Helper()
if runtime.GOOS != "linux" {
t.Skip("the stub compose binary is a shell script")
}
root := t.TempDir()
dir := filepath.Join(root, name)
if err := os.MkdirAll(dir, 0o755); err != nil {
t.Fatal(err)
}
if err := os.WriteFile(filepath.Join(dir, "docker-compose.yml"), []byte(compose), 0o644); err != nil {
t.Fatal(err)
}
if err := os.WriteFile(filepath.Join(dir, "app.yaml"), []byte(appYAML), 0o600); err != nil {
t.Fatal(err)
}
cfg := &config.Config{}
cfg.Paths.StacksDir = root
cfg.Paths.SystemDataPath = r442SysData
m := &Manager{
cfg: cfg,
logger: log.New(io.Discard, "", 0),
encKey: []byte("0123456789abcdef0123456789abcdef"),
sysDataPath: r442SysData,
stacks: map[string]*Stack{},
}
m.stacks[name] = &Stack{Name: name, ComposePath: filepath.Join(dir, "docker-compose.yml"), Deployed: true, State: StateStopped}
m.stacks[name].AppConfig = LoadAppConfig(dir)
// The compose boundary: a script that records it ran. A refusal must leave NO marker.
bin := t.TempDir()
marker := filepath.Join(bin, "compose-ran")
script := "#!/bin/sh\ntouch " + marker + "\nexit 0\n"
if err := os.WriteFile(filepath.Join(bin, "docker-compose"), []byte(script), 0o755); err != nil {
t.Fatal(err)
}
t.Setenv("PATH", bin+string(os.PathListSeparator)+os.Getenv("PATH"))
m.composeCmd = "docker-compose"
m.execFn = func(string, ...string) (string, error) { return "", nil }
m.isMountPoint = func(p string) bool { return liveDrive != "" && filepath.Clean(p) == filepath.Clean(liveDrive) }
return m, dir, marker
}
func plantFile(t *testing.T, path string) {
t.Helper()
if err := os.MkdirAll(filepath.Dir(path), 0o755); err != nil {
t.Fatal(err)
}
if err := os.WriteFile(path, []byte("customer bytes\n"), 0o644); err != nil {
t.Fatal(err)
}
}
func exists(path string) bool {
_, err := os.Stat(path)
return err == nil
}
const driveCompose = "services:\n" +
" app:\n" +
" image: nginx:1.27\n" +
" volumes:\n" +
" - ${HDD_PATH}/appdata/app:/data\n" +
" - app_cfg:/config\n" +
"volumes:\n" +
" app_cfg:\n"
const ssdCompose = "services:\n" +
" app:\n" +
" image: nginx:1.27\n" +
" volumes:\n" +
" - app_cfg:/config\n" +
"volumes:\n" +
" app_cfg:\n"
func driveAppYAML(drive string) string {
return "deployed: true\nenv:\n HDD_PATH: " + drive + "\n"
}
// Scenario A — a drive-backed app is removed WITH its data: the folder is gone, listed with its size.
func TestRemoveStack_R442_RemovesDeclaredDriveData(t *testing.T) {
drive := t.TempDir()
m, dir, marker := newR442Manager(t, "app", driveCompose, driveAppYAML(drive), drive)
data := filepath.Join(drive, "appdata", "app")
plantFile(t, filepath.Join(data, "photos", "one.jpg"))
resp, err := m.RemoveStack("app", true, nil)
if err != nil {
t.Fatalf("RemoveStack: %v", err)
}
if exists(data) {
t.Fatalf("data folder %s STILL EXISTS after remove_hdd_data=true — the R-442 defect", data)
}
if len(resp.HDDPathsRemoved) != 1 || !strings.HasPrefix(resp.HDDPathsRemoved[0], data+" (") {
t.Fatalf("hdd_paths_removed = %v, want exactly [%q (size)]", resp.HDDPathsRemoved, data)
}
if exists(filepath.Join(dir, "app.yaml")) {
t.Fatal("app.yaml still present — the app was not removed")
}
if !exists(marker) {
t.Fatal("compose down never ran on the success path")
}
// The drive's protected roots are untouched.
if !exists(filepath.Join(drive, "appdata")) {
t.Fatal("the protected appdata/ root was removed")
}
}
// Scenario B — the same app, data KEPT: folder untouched, listed under preserved, removed is `[]`
// (never null).
func TestRemoveStack_R442_KeepsDataWhenNotAsked(t *testing.T) {
drive := t.TempDir()
m, dir, _ := newR442Manager(t, "app", driveCompose, driveAppYAML(drive), drive)
data := filepath.Join(drive, "appdata", "app")
plantFile(t, filepath.Join(data, "photos", "one.jpg"))
resp, err := m.RemoveStack("app", false, nil)
if err != nil {
t.Fatalf("RemoveStack: %v", err)
}
if !exists(filepath.Join(data, "photos", "one.jpg")) {
t.Fatal("customer file was deleted on a keep-data removal")
}
if len(resp.HDDPathsPreserved) != 1 || !strings.HasPrefix(resp.HDDPathsPreserved[0], data+" (") {
t.Fatalf("hdd_paths_preserved = %v, want [%q (size)]", resp.HDDPathsPreserved, data)
}
raw, _ := json.Marshal(resp)
if !strings.Contains(string(raw), `"hdd_paths_removed":[]`) {
t.Fatalf("hdd_paths_removed must serialise as [] — got %s", raw)
}
if exists(filepath.Join(dir, "app.yaml")) {
t.Fatal("app.yaml still present — the app was not removed")
}
}
// Scenario C — THE R-442 CASE: data removal requested, the compose binds ${HDD_PATH}, app.yaml
// records none → REFUSED, typed, exact Hungarian sentence, and NOTHING was touched: compose never
// ran, app.yaml is still there.
func TestRemoveStack_R442_RefusesWhenDriveUnresolvable(t *testing.T) {
m, dir, marker := newR442Manager(t, "app", driveCompose, "deployed: true\nenv: {}\n", "")
resp, err := m.RemoveStack("app", true, nil)
var refused *RemoveRefusedError
if !errors.As(err, &refused) {
removed := []string(nil)
if resp != nil {
removed = resp.HDDPathsRemoved
}
t.Fatalf("want *RemoveRefusedError, got err=%v resp.hdd_paths_removed=%v app.yaml present=%v — a 200 over inaction",
err, removed, exists(filepath.Join(dir, "app.yaml")))
}
if refused.Reason != RefuseHDDUnresolved {
t.Fatalf("reason = %q, want %q", refused.Reason, RefuseHDDUnresolved)
}
if refused.Message != msgHDDUnresolved {
t.Fatalf("message = %q, want the exact customer sentence", refused.Message)
}
if exists(marker) {
t.Fatal("compose down RAN on a refused removal — the refusal must precede every mutation")
}
if !exists(filepath.Join(dir, "app.yaml")) {
t.Fatal("app.yaml is gone — the app was removed with its data left behind, the worst outcome")
}
}
// Scenario D — an SSD-resident app (never declared HDD_PATH, binds no drive path) is NOT refused:
// hdd_paths_removed is `[]`, the note says there was no drive data, the app is removed.
func TestRemoveStack_R442_SSDAppIsNotRefused(t *testing.T) {
m, dir, marker := newR442Manager(t, "app", ssdCompose, "deployed: true\nenv: {}\n", "")
resp, err := m.RemoveStack("app", true, nil)
if err != nil {
t.Fatalf("an SSD app must not be refused on HDD grounds, got: %v", err)
}
if resp.HDDPathsRemoved == nil || len(resp.HDDPathsRemoved) != 0 {
t.Fatalf("hdd_paths_removed = %#v, want a non-nil empty list", resp.HDDPathsRemoved)
}
raw, _ := json.Marshal(resp)
if !strings.Contains(string(raw), `"hdd_paths_removed":[]`) {
t.Fatalf("hdd_paths_removed must serialise as [] — got %s", raw)
}
if resp.HDDNote != noteNoDriveData {
t.Fatalf("hdd_note = %q, want %q", resp.HDDNote, noteNoDriveData)
}
if exists(filepath.Join(dir, "app.yaml")) || !exists(marker) {
t.Fatalf("SSD app not removed: app.yaml present=%v compose ran=%v", exists(filepath.Join(dir, "app.yaml")), exists(marker))
}
}
// Edge: HDD_PATH recorded but the drive is not mounted right now → refused with the drive-absent
// sentence naming the path; app kept; nothing ran.
func TestRemoveStack_R442_RefusesWhenDriveAbsent(t *testing.T) {
drive := t.TempDir()
m, dir, marker := newR442Manager(t, "app", driveCompose, driveAppYAML(drive), "" /* nothing is live */)
_, err := m.RemoveStack("app", true, nil)
var refused *RemoveRefusedError
if !errors.As(err, &refused) || refused.Reason != RefuseDriveAbsent {
t.Fatalf("want drive-absent refusal, got %v", err)
}
if !strings.Contains(refused.Message, drive) || !strings.Contains(refused.Message, "vissza nem csatlakozik") {
t.Fatalf("message = %q, want the drive-absent sentence naming %s", refused.Message, drive)
}
if exists(marker) || !exists(filepath.Join(dir, "app.yaml")) {
t.Fatal("a drive-absent refusal must run nothing and keep the app")
}
}
// Edge: a keep-data removal is NEVER refused on HDD grounds, even with the drive absent.
func TestRemoveStack_R442_KeepDataNeverRefusedOnHDDGrounds(t *testing.T) {
drive := t.TempDir()
m, dir, _ := newR442Manager(t, "app", driveCompose, driveAppYAML(drive), "")
if _, err := m.RemoveStack("app", false, nil); err != nil {
t.Fatalf("keep-data removal refused: %v", err)
}
if exists(filepath.Join(dir, "app.yaml")) {
t.Fatal("app not removed")
}
}
// Edge: HDD_PATH recorded, folder already absent → not a refusal; listed under hdd_paths_missing,
// stated in the note, app removed.
func TestRemoveStack_R442_MissingFolderIsStatedNotRefused(t *testing.T) {
drive := t.TempDir()
m, dir, _ := newR442Manager(t, "app", driveCompose, driveAppYAML(drive), drive)
want := filepath.Join(drive, "appdata", "app")
resp, err := m.RemoveStack("app", true, nil)
if err != nil {
t.Fatalf("absent folder must not refuse: %v", err)
}
if len(resp.HDDPathsMissing) != 1 || resp.HDDPathsMissing[0] != want {
t.Fatalf("hdd_paths_missing = %v, want [%s]", resp.HDDPathsMissing, want)
}
if !strings.Contains(resp.HDDNote, want) {
t.Fatalf("hdd_note = %q, must name the missing folder", resp.HDDNote)
}
if len(resp.HDDPathsRemoved) != 0 || exists(filepath.Join(dir, "app.yaml")) {
t.Fatal("removed list must be empty and the app gone")
}
}
// Scenario E — the backup half: a path inside the app's backups/ is removed and listed; a path
// outside it is refused AND the refusal reaches the response, not only the log.
func TestRemoveStack_R442_BackupRefusalReachesResponse(t *testing.T) {
drive := t.TempDir()
m, _, _ := newR442Manager(t, "app", driveCompose, driveAppYAML(drive), drive)
inside := filepath.Join(drive, "backups", "primary", "app", "db-dumps")
plantFile(t, filepath.Join(inside, "app.sql"))
outside := filepath.Join(t.TempDir(), "elsewhere", "db-dumps")
plantFile(t, filepath.Join(outside, "x.sql"))
resp, err := m.RemoveStack("app", true, []string{inside, outside})
if err != nil {
t.Fatalf("RemoveStack: %v", err)
}
if exists(inside) {
t.Fatalf("backup path inside the app's backups/ was not removed: %s", inside)
}
if len(resp.BackupPathsRemoved) != 1 || !strings.HasPrefix(resp.BackupPathsRemoved[0], inside+" (") {
t.Fatalf("backup_paths_removed = %v, want [%s (size)]", resp.BackupPathsRemoved, inside)
}
if !exists(filepath.Join(outside, "x.sql")) {
t.Fatal("a path OUTSIDE backups/ was deleted — the guard is gone")
}
if len(resp.BackupPathsRefused) != 1 || !strings.HasPrefix(resp.BackupPathsRefused[0], outside+" ") {
t.Fatalf("backup_paths_refused = %v, want the outside path with its reason", resp.BackupPathsRefused)
}
}
// Scenario E for an SSD app: its DB dumps live under <system data>/felhom-data/backups — the same
// namespace root the router's AppNamespaceRoot resolves — and are removable. Under the old global
// lookup every backup path of every app was refused.
func TestRemoveStack_R442_SSDAppBackupsUnderSystemNamespace(t *testing.T) {
sys := t.TempDir()
m, _, _ := newR442Manager(t, "app", ssdCompose, "deployed: true\nenv: {}\n", "")
m.sysDataPath = sys
m.cfg.Paths.SystemDataPath = sys
inside := filepath.Join(sys, "felhom-data", "backups", "primary", "app", "db-dumps")
plantFile(t, filepath.Join(inside, "app.sql"))
resp, err := m.RemoveStack("app", true, []string{inside})
if err != nil {
t.Fatalf("RemoveStack: %v", err)
}
if exists(inside) || len(resp.BackupPathsRemoved) != 1 || len(resp.BackupPathsRefused) != 0 {
t.Fatalf("SSD-app backup under the system namespace must be removed: exists=%v removed=%v refused=%v",
exists(inside), resp.BackupPathsRemoved, resp.BackupPathsRefused)
}
}
// The ${USERDATA_PATH} convention (delete.go, ExportDataMounts) keeps working from the PER-APP
// path: removal deletes the app's own ${HDD_PATH}/appdata bind and leaves the shared userdata root
// alone, and the export resolver still derives <HDD_PATH>/userdata from the same per-app value.
func TestRemoveStack_R442_UserdataConventionFromPerAppPath(t *testing.T) {
drive := t.TempDir()
compose := "services:\n" +
" app:\n" +
" image: nginx:1.27\n" +
" volumes:\n" +
" - ${HDD_PATH}/appdata/app:/data\n" +
" - ${USERDATA_PATH}/media:/media\n"
m, _, _ := newR442Manager(t, "app", compose, driveAppYAML(drive), drive)
data := filepath.Join(drive, "appdata", "app")
plantFile(t, filepath.Join(data, "one.bin"))
shared := filepath.Join(drive, "userdata", "media", "holiday.jpg")
plantFile(t, shared)
hdd, declared := m.appHDDPath("app")
if !declared || hdd != filepath.Clean(drive) {
t.Fatalf("appHDDPath = (%q,%v), want (%q,true)", hdd, declared, drive)
}
mounts := ExportDataMounts(m.stacks["app"].ComposePath, hdd, hdd)
wantUD := filepath.Join(drive, "userdata")
found := false
for _, mnt := range mounts {
if mnt == wantUD {
found = true
}
}
if !found {
t.Fatalf("ExportDataMounts from the per-app path = %v, want it to include %s", mounts, wantUD)
}
if _, err := m.RemoveStack("app", true, nil); err != nil {
t.Fatalf("RemoveStack: %v", err)
}
if exists(data) {
t.Fatal("app data not removed")
}
if !exists(shared) {
t.Fatal("the shared userdata root was deleted by an app removal")
}
}
// DeleteStack (orphan delete) takes the same refusal: Scenario C shape, nothing touched.
func TestDeleteStack_R442_RefusesWhenDriveUnresolvable(t *testing.T) {
m, dir, marker := newR442Manager(t, "app", driveCompose, "deployed: true\nenv: {}\n", "")
m.stacks["app"].Orphaned = true
_, err := m.DeleteStack("app", true)
var refused *RemoveRefusedError
if !errors.As(err, &refused) || refused.Message != msgHDDUnresolved {
t.Fatalf("want the unresolved refusal, got %v (stack dir present=%v)", err, exists(dir))
}
if exists(marker) || !exists(dir) {
t.Fatal("orphan delete refused but something ran or the stack dir is gone")
}
}
// DeleteStack success path: the app's own drive data goes, listed.
func TestDeleteStack_R442_RemovesDeclaredDriveData(t *testing.T) {
drive := t.TempDir()
m, dir, _ := newR442Manager(t, "app", driveCompose, driveAppYAML(drive), drive)
m.stacks["app"].Orphaned = true
data := filepath.Join(drive, "appdata", "app")
plantFile(t, filepath.Join(data, "one.bin"))
resp, err := m.DeleteStack("app", true)
if err != nil {
t.Fatalf("DeleteStack: %v", err)
}
if exists(data) || len(resp.HDDPathsRemoved) != 1 || exists(dir) {
t.Fatalf("data exists=%v removed=%v stackdir exists=%v", exists(data), resp.HDDPathsRemoved, exists(dir))
}
}
// GetStackHDDData (the modal's source) reads the per-app record too: with HDD_PATH recorded it
// lists the folder; the global config stays empty throughout.
func TestGetStackHDDData_R442_ReadsPerAppRecord(t *testing.T) {
drive := t.TempDir()
m, _, _ := newR442Manager(t, "app", driveCompose, driveAppYAML(drive), drive)
data := filepath.Join(drive, "appdata", "app")
plantFile(t, filepath.Join(data, "one.bin"))
if m.cfg.Paths.HDDPath != "" {
t.Fatal("fixture error: the global must stay empty to prove the per-app read")
}
resp, err := m.GetStackHDDData("app")
if err != nil {
t.Fatal(err)
}
if !resp.HasHDDData || len(resp.HDDPaths) != 1 || resp.HDDPaths[0].Path != data || !resp.HDDPaths[0].Exists {
t.Fatalf("hdd-data = %+v, want one existing entry for %s", resp, data)
}
}