kept data: the choice at reinstall, the list, the read-only view, the load (09 decision 36); R-690 fixed
gates / gates (push) Successful in 26s

An install over an app's kept drive folder (appdata/<app> non-empty) asks the household:
"use my kept data" (a load from the newest copy of THIS drive's install, own unit or
second-drive mirror, then the template's after_load) or "start fresh" (the folder is
renamed into <drive>/kept/<app>/<date>/ with the removed app's unit; nothing deleted).
The install API answers 409 kept_data_choice until one is chosen; DeployStack refuses
too. New page Megorzott adatok / Kept data (/kept-data): Load / Look / Delete (typed
confirmation, the only deletion of kept data). FileBrowser gets a read-only source.
The drive-full warning names the kept folders. <drive>/kept is protected and outside
every backup leg.

R-690: the removed-app restore (R-487) never found a unit on a DATA drive — it asked
GetStackComposePath (true for every catalog app) and restored nextcloud with no env.
Now isStackDeployed; pinned with a production-shaped provider.

Red-proofs: audits/night-2026-09-26/E/redproofs/.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
This commit is contained in:
2026-09-25 13:32:30 +02:00
parent 5a731b45b9
commit 43e99d160c
44 changed files with 3311 additions and 37 deletions
+36
View File
@@ -1861,6 +1861,42 @@ not just those with HDD data. Non-HDD apps can configure destination, method, an
- Storage overview card (total size across repos, snapshot count, DB dump count/size, encryption key with show/copy)
- Restore section: app dropdown → per-app snapshot dropdown (Tier 1 + Tier 2 grouped) → restore type info → confirmation checkbox → execute → import from `.fab` bundle link
### Kept data — the choice at reinstall, the list, the read-only view (`09` §3 decision 36)
An app removed with „keep my data" leaves its private drive folder (`<drive>/appdata/<app>`). Since this release
that folder is never a dead end, and an install never runs into it silently (R-657).
- **At install.** When the app's `${HDD_PATH}/appdata/…` bind already holds something, `POST /api/stacks/<n>/deploy`
answers **409** with `data.code = "kept_data_choice"` and the sentences (title, body, the two choices, „Erről nem
készül mentés." / "This is not backed up.") in the request's language; nothing is written. The page asks, and
sends again with `kept_data`:
- `use` — **„A megőrzött adataimat használom" / "Use my kept data"**: a LOAD from the newest copy that holds the
app's data and was taken of THIS drive (the app's own unit, Tier 1, or a second-drive mirror, Tier 2 —
`backup.KeptDBCopy`), through the one unit-restore body (`RestoreFromRecoveryUnitAt`); then the template's
`after_load:` once. Refused 409 with the `use_off` sentence when no such copy exists.
- `fresh` — **„Tiszta lappal kezdem" / "Start fresh"**: the old folder is MOVED (a rename on the same drive;
EXDEV or any failure puts back what moved and refuses) to `<drive>/kept/<app>/<YYYY-MM-DD_hhmmss>/` with a
`.felhom-kept.json` marker; the removed app's own unit moves in with it (`kept/.../unit`) so the files keep
their database copy; then the normal install.
- no choice → `DeployStack` refuses too (`ErrKeptDataChoice`), before any write.
- **„Megőrzött adatok" / "Kept data"** — `GET /kept-data` (linked from Tárhely → Meghajtók): every dated kept
folder and every non-empty `appdata/<x>` no installed app binds, on every connected local drive — app, date,
size, which copy can bring it back (or none). **Load** (`POST /kept-data/load`, only with a copy; puts a dated
item's files back first, refuses over an occupied folder), **Look** (the file browser), **Delete**
(`POST /kept-data/delete`, the app's name typed to confirm — the ONLY deletion of kept data; the box never
deletes one by itself, D3 is open).
- **Read-only view.** FileBrowser gets a source „Megőrzött adatok" / "Kept data" (box language) at
`/srv/megorzott/`, one `:ro` bind per listed item, present only when something is kept; the list page re-syncs
it (no recreate when nothing changed). Known limit: an app folder owned by another user with mode 0770
(nextcloud's `www-data`) shows as a folder FileBrowser cannot open.
- **Where it lives.** `<drive>/kept/` is beside `appdata/` and `userdata/`, inside neither: no app bind, FileBrowser
userdata source, Samba share or backup leg reads it. It is in `ProtectedHDDPaths`.
- **The drive-full warning** ends with the kept folders on that drive and their sizes (`fillwatch.SetExtra`).
- **R-690 (fixed here).** The removed-app restore (R-487) never found a unit on a DATA drive — it asked
`GetStackComposePath`, true for every catalog app — and restored with no env. It now asks `isStackDeployed`.
- `.felhom.yml` **`after_load: {service, user, command: [...]}`** — one command run with `docker compose exec -T`
after a load; nextcloud declares `php occ files:scan --all`.
---
### 4. Storage Management