v0.236.0: "delete my data too" deletes the data, or says that it could not (R-442)
gates / gates (push) Successful in 13s

Removal resolves the drive from the app's own app.yaml HDD_PATH (the 07 ~L437
rule), never the global cfg.Paths.HDDPath which no box sets. A data removal
that cannot be resolved, or whose drive is absent, is refused with a typed
RemoveRefusedError -> 409 + exact Hungarian sentence, before compose down, and
the app is kept. SSD app -> hdd_paths_removed: [] never null; missing folders
stated; backup-path refusals reach the response.

15 tests, two red-proofs run (pre-fix fallback -> C fails with err=nil and the
handler 200s; "no drive refuses" -> D fails).

Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
This commit is contained in:
2026-09-13 08:52:25 +02:00
parent bab82c471e
commit 42a73e667a
9 changed files with 763 additions and 21 deletions
+167 -16
View File
@@ -18,20 +18,139 @@ import (
const felhomDataDir = "felhom-data"
// DeleteResponse holds the result of a stack deletion (orphan delete).
//
// R-442 (v0.236.0): HDDPathsRemoved / HDDPathsPreserved are ALWAYS non-nil — an empty list is `[]`,
// never `null`, because `null` was what a silently inert removal looked like for months and the two
// must be distinguishable. HDDPathsMissing lists folders the app recorded that were already gone from
// the drive (a fact, not a refusal). HDDNote is one customer-facing sentence about what was NOT
// found — empty when nothing needs saying.
type DeleteResponse struct {
Deleted string `json:"deleted"`
VolumesRemoved []string `json:"volumes_removed"`
HDDPathsRemoved []string `json:"hdd_paths_removed"`
HDDPathsPreserved []string `json:"hdd_paths_preserved"`
HDDPathsMissing []string `json:"hdd_paths_missing,omitempty"`
HDDNote string `json:"hdd_note,omitempty"`
}
// RemoveResponse holds the result of removing a deployed (non-orphaned) stack.
// RemoveResponse holds the result of removing a deployed (non-orphaned) stack. Same R-442 shape as
// DeleteResponse, plus the backup half: BackupPathsRefused carries every backup path the removal
// declined to touch and why — until v0.236.0 that refusal existed only as a WARN log line.
type RemoveResponse struct {
Removed string `json:"removed"`
VolumesRemoved []string `json:"volumes_removed"`
HDDPathsRemoved []string `json:"hdd_paths_removed"`
HDDPathsPreserved []string `json:"hdd_paths_preserved"`
HDDPathsMissing []string `json:"hdd_paths_missing,omitempty"`
HDDNote string `json:"hdd_note,omitempty"`
BackupPathsRemoved []string `json:"backup_paths_removed,omitempty"`
BackupPathsRefused []string `json:"backup_paths_refused,omitempty"`
}
// RemoveRefusedError is a removal REFUSED before anything was touched: the customer asked for the
// app's data to go with it and the box cannot honour that. It is a typed error so the API handler can
// map it to a non-2xx status and show Message verbatim (R-442). The app is NOT removed either — an app
// gone with its data left behind is unrecoverable from the UI (the customer cannot even re-run the
// removal). Same class as R-443: success is never reported over inaction.
type RemoveRefusedError struct {
Reason string // RefuseHDDUnresolved | RefuseDriveAbsent — for logs and tests
Message string // Hungarian, customer-facing, exact
}
func (e *RemoveRefusedError) Error() string { return e.Message }
// RemoveRefusedError reasons.
const (
RefuseHDDUnresolved = "hdd_unresolved" // data removal requested; compose binds a drive; app.yaml records none
RefuseDriveAbsent = "drive_absent" // data removal requested; the recorded drive is not mounted right now
)
// Customer-facing copy for the R-442 shapes. Exact strings — the live validation greps ASCII
// fragments of them (`llap` for the first, `nem el` for the second).
const (
msgHDDUnresolved = "Az alkalmazás adatainak helye nem állapítható meg, ezért semmit nem töröltünk. Az alkalmazás nem lett eltávolítva."
msgDriveAbsentFmt = "A(z) %s tárhely jelenleg nem elérhető — az alkalmazás nem távolítható el, amíg a meghajtó vissza nem csatlakozik."
noteNoDriveData = "Az alkalmazás nem tárolt saját adatot külső meghajtón, így ott nem volt mit törölni."
noteMissingFmt = "A következő adatmappa már nem volt a meghajtón: %s"
backupRefusedFmt = "%s — a mentés helye a várt mappán kívül esik, ezért nem töröltük"
)
// appHDDPath returns the data drive the named app RECORDED for itself at deploy time — app.yaml's
// HDD_PATH — and whether it recorded one at all.
//
// It implements, for the removal path, the rule 07-backup-architecture.md states under "[DESIGN]
// 2026-08-22 — the restore destination is resolved by the same rule as the capture destination"
// (~L437): "the drive if the app declares one (HDD_PATH), the system data path otherwise". Deploy
// (withPathVars), the start gate (api.startGatedByMissingDrive) and the backup destination
// (backup.GetAppDrivePath) all read the app's own record. Until v0.236.0 removal alone read the
// GLOBAL cfg.Paths.HDDPath — set on no box — so "delete my data" resolved zero mounts and reported
// success over 128 MB left on the drive (R-442, measured on demo-hp 2026-09-01).
//
// DELIBERATELY NO FALLBACK to m.cfg.Paths.HDDPath when the per-app value is empty. A single global
// drive is the assumption the storage arc removed (a customer can have several), and an empty answer
// must reach the caller as "not declared" so it can tell an SSD-only app (nothing to remove — a fact)
// from a removal it cannot honour (a refusal). A silent fallback is the exact path R-442 closes.
func (m *Manager) appHDDPath(name string) (string, bool) {
cfg := m.LoadAppConfigByName(name)
if cfg == nil {
return "", false
}
hdd := strings.TrimSpace(cfg.Env["HDD_PATH"])
if hdd == "" {
return "", false
}
return filepath.Clean(hdd), true
}
// composeBindsDrive reports whether the app's compose file binds anything under ${HDD_PATH} or
// ${USERDATA_PATH} — whether the app keeps data on a drive AT ALL. This is R-442's deduplication
// rule: "declares no drive" is a fact (an SSD-resident app — nothing to remove, empty list), while
// "binds a drive it cannot resolve" is a failure (refuse). Read through the ONE authoritative bind
// scanner; ParseComposeHDDMounts is unchanged.
func composeBindsDrive(composePath string) bool {
for _, b := range ParseComposeClassifiableBinds(composePath) {
if b.Root == appbackup.RootHDD || b.Root == appbackup.RootUserdata {
return true
}
}
return false
}
// hddPathForRemoval resolves the drive a removal acts on, or refuses — BEFORE anything is touched.
// Returns (path, declared, nil) to proceed; a *RemoveRefusedError to stop. Every refusal is logged at
// ERROR here AND returned to the caller, never one without the other. A removal that does not ask
// for the data is never refused on HDD grounds.
func (m *Manager) hddPathForRemoval(op, name, composePath string, removeHDDData bool) (string, bool, error) {
hddPath, declared := m.appHDDPath(name)
if !removeHDDData {
return hddPath, declared, nil
}
if !declared {
if composeBindsDrive(composePath) {
m.logger.Printf("[ERROR] [stacks] %s %s refused: data removal requested, the compose binds a drive path, but app.yaml records no HDD_PATH — nothing removed, app kept (R-442)", op, name)
return "", false, &RemoveRefusedError{Reason: RefuseHDDUnresolved, Message: msgHDDUnresolved}
}
return "", false, nil // SSD-resident: there is no drive data, and that is a fact
}
if !m.DriveLive(hddPath) {
m.logger.Printf("[ERROR] [stacks] %s %s refused: data removal requested but the drive recorded in HDD_PATH is not mounted — nothing removed, app kept (R-442)", op, name)
return hddPath, true, &RemoveRefusedError{Reason: RefuseDriveAbsent, Message: fmt.Sprintf(msgDriveAbsentFmt, hddPath)}
}
return hddPath, true, nil
}
// hddNoteFor composes the one-sentence HDDNote (see DeleteResponse). Only when the data was asked
// for: a kept-data removal has nothing to explain about what was not found.
func hddNoteFor(removeHDDData bool, mounts, missing []string) string {
switch {
case !removeHDDData:
return ""
case len(mounts) == 0:
return noteNoDriveData
case len(missing) > 0:
return fmt.Sprintf(noteMissingFmt, strings.Join(missing, ", "))
}
return ""
}
// BackupDataResponse holds information about backup data associated with a stack.
@@ -117,13 +236,20 @@ func (m *Manager) DeleteStack(name string, removeHDDData bool) (*DeleteResponse,
}
stackDir := filepath.Dir(stack.ComposePath)
hddPath := m.cfg.Paths.HDDPath
// R-442: the app's OWN recorded drive, never the global config — and a refusal here happens
// before compose down, so a refused removal has touched nothing.
hddPath, hddDeclared, err := m.hddPathForRemoval("DeleteStack", name, stack.ComposePath, removeHDDData)
if err != nil {
return nil, err
}
m.logger.Printf("[INFO] Deleting orphaned stack: %s (removeHDDData=%v)", name, removeHDDData)
m.logger.Printf("[INFO] Deleting orphaned stack: %s (removeHDDData=%v, hddDeclared=%v)", name, removeHDDData, hddDeclared)
start := time.Now()
resp := &DeleteResponse{
Deleted: name,
Deleted: name,
HDDPathsRemoved: []string{},
HDDPathsPreserved: []string{},
}
// Step 1: Parse compose file for HDD bind mounts
@@ -169,7 +295,8 @@ func (m *Manager) DeleteStack(name string, removeHDDData bool) (*DeleteResponse,
if m.isDebug() {
m.logger.Printf("[DEBUG] [stacks] DeleteStack %s: HDD path does not exist, skipping: %s", name, cleanPath)
}
continue // path doesn't exist, nothing to do
resp.HDDPathsMissing = append(resp.HDDPathsMissing, cleanPath) // R-442: stated, not a refusal
continue // path doesn't exist, nothing to do
}
if removeHDDData {
@@ -192,6 +319,7 @@ func (m *Manager) DeleteStack(name string, removeHDDData bool) (*DeleteResponse,
resp.HDDPathsPreserved = append(resp.HDDPathsPreserved, fmt.Sprintf("%s (%s)", cleanPath, sizeHuman))
}
}
resp.HDDNote = hddNoteFor(removeHDDData, hddMounts, resp.HDDPathsMissing)
// Step 5: Remove stack directory
if m.isDebug() {
@@ -223,14 +351,15 @@ func (m *Manager) GetStackHDDData(name string) (*HDDDataResponse, error) {
return nil, fmt.Errorf("stack %q not found", name)
}
hddPath := m.cfg.Paths.HDDPath
// R-442: the app's own recorded HDD_PATH, not the global config (which no box sets).
hddPath, declared := m.appHDDPath(name)
resp := &HDDDataResponse{
Stack: name,
}
if hddPath == "" {
if !declared {
if m.isDebug() {
m.logger.Printf("[DEBUG] [stacks] GetStackHDDData %s: no HDD path configured, returning empty", name)
m.logger.Printf("[DEBUG] [stacks] GetStackHDDData %s: app.yaml records no HDD_PATH, returning empty", name)
}
return resp, nil
}
@@ -322,13 +451,20 @@ func (m *Manager) RemoveStack(name string, removeHDDData bool, backupPathsToRemo
}
stackDir := filepath.Dir(stack.ComposePath)
hddPath := m.cfg.Paths.HDDPath
// R-442: the app's OWN recorded drive, never the global config — and a refusal here happens
// before compose down, so a refused removal has touched nothing.
hddPath, hddDeclared, err := m.hddPathForRemoval("RemoveStack", name, stack.ComposePath, removeHDDData)
if err != nil {
return nil, err
}
m.logger.Printf("[INFO] Removing deployed stack: %s (removeHDDData=%v, backupPaths=%d)", name, removeHDDData, len(backupPathsToRemove))
m.logger.Printf("[INFO] Removing deployed stack: %s (removeHDDData=%v, hddDeclared=%v, backupPaths=%d)", name, removeHDDData, hddDeclared, len(backupPathsToRemove))
start := time.Now()
resp := &RemoveResponse{
Removed: name,
Removed: name,
HDDPathsRemoved: []string{},
HDDPathsPreserved: []string{},
}
// Step 1: Parse compose file for HDD bind mounts
@@ -372,6 +508,7 @@ func (m *Manager) RemoveStack(name string, removeHDDData bool, backupPathsToRemo
if m.isDebug() {
m.logger.Printf("[DEBUG] [stacks] RemoveStack %s: HDD path does not exist, skipping: %s", name, cleanPath)
}
resp.HDDPathsMissing = append(resp.HDDPathsMissing, cleanPath) // R-442: stated, not a refusal
continue
}
@@ -395,17 +532,31 @@ func (m *Manager) RemoveStack(name string, removeHDDData bool, backupPathsToRemo
}
}
// Step 5: Handle backup data cleanup. Model A: backups/ sits directly under the namespace-root
// drive mount (no felhom-data segment).
backupsBase := filepath.Join(hddPath, "backups")
resp.HDDNote = hddNoteFor(removeHDDData, hddMounts, resp.HDDPathsMissing)
// Step 5: Handle backup data cleanup. Model A: backups/ sits directly under the app's felhom-data
// namespace root. R-442: that root is resolved by the SAME rule as the data half and as the
// router's AppNamespaceRoot that produced these paths — the app's own drive when it records one,
// the system data path otherwise (07-backup-architecture.md ~L437) — instead of the global
// cfg.Paths.HDDPath, under which every backup path was refused on every box. And the refusal now
// reaches the response (BackupPathsRefused), not only the log.
nsDrive := hddPath
if !hddDeclared {
nsDrive = m.sysDataPath
}
backupsBase := ""
if nsDrive != "" {
backupsBase = filepath.Join(appbackup.NamespaceRootFor(nsDrive, m.sysDataPath), "backups")
}
if m.isDebug() {
m.logger.Printf("[DEBUG] [stacks] RemoveStack %s: processing %d backup paths for removal (base=%s)", name, len(backupPathsToRemove), backupsBase)
}
for _, bkPath := range backupPathsToRemove {
cleanPath := filepath.Clean(bkPath)
// Validate path is under the expected backups directory
if hddPath == "" || !strings.HasPrefix(cleanPath, backupsBase+string(filepath.Separator)) {
m.logger.Printf("[WARN] Refusing to remove backup path outside expected directory: %s", cleanPath)
if backupsBase == "" || !strings.HasPrefix(cleanPath, backupsBase+string(filepath.Separator)) {
m.logger.Printf("[WARN] Refusing to remove backup path outside expected directory: %s (expected under %s)", cleanPath, backupsBase)
resp.BackupPathsRefused = append(resp.BackupPathsRefused, fmt.Sprintf(backupRefusedFmt, cleanPath))
continue
}
if _, err := os.Stat(cleanPath); os.IsNotExist(err) {