kept data: the choice at reinstall, the list, the read-only view, the load (09 decision 36); R-690 fixed
gates / gates (push) Successful in 26s

An install over an app's kept drive folder (appdata/<app> non-empty) asks the household:
"use my kept data" (a load from the newest copy of THIS drive's install, own unit or
second-drive mirror, then the template's after_load) or "start fresh" (the folder is
renamed into <drive>/kept/<app>/<date>/ with the removed app's unit; nothing deleted).
The install API answers 409 kept_data_choice until one is chosen; DeployStack refuses
too. New page Megorzott adatok / Kept data (/kept-data): Load / Look / Delete (typed
confirmation, the only deletion of kept data). FileBrowser gets a read-only source.
The drive-full warning names the kept folders. <drive>/kept is protected and outside
every backup leg.

R-690: the removed-app restore (R-487) never found a unit on a DATA drive — it asked
GetStackComposePath (true for every catalog app) and restored nextcloud with no env.
Now isStackDeployed; pinned with a production-shaped provider.

Red-proofs: audits/night-2026-09-26/E/redproofs/.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
This commit is contained in:
2026-09-25 13:32:30 +02:00
parent 5a731b45b9
commit 43e99d160c
44 changed files with 3311 additions and 37 deletions
+20
View File
@@ -35,6 +35,7 @@ import (
"gitea.dooplex.hu/admin/felhom-controller/internal/config"
"gitea.dooplex.hu/admin/felhom-controller/internal/crypto"
"gitea.dooplex.hu/admin/felhom-controller/internal/fillwatch"
"gitea.dooplex.hu/admin/felhom-controller/internal/i18n"
"gitea.dooplex.hu/admin/felhom-controller/internal/infra"
"gitea.dooplex.hu/admin/felhom-controller/internal/integrations"
"gitea.dooplex.hu/admin/felhom-controller/internal/mailrelay"
@@ -568,6 +569,8 @@ func main() {
// An UNWIRED manager also refuses (fail closed); TestSlice4_UpdateGuardsAreWiredAtStartup walks
// this file for the call, because a seam built and never wired has shipped here seven times.
stackMgr.SetUpdateGuards(&updateGuardsAdapter{b: backupMgr, q: quiesceLoop})
// `09` §3 decision 36: a start-fresh moves the removed app's own unit in with its kept files.
stackMgr.SetKeptUnitFinder(backupMgr.RemovedUnitOnDrive)
// v0.271.0 (`09` §6.4 part 7): the automatic update leg. The switch is read at the leg's start and
// before every press; W is the SAME effective window every nightly leg reads. The files-may-change
// mark asks the backup side's truth table (decisions 25/26), never a second definition of "whole".
@@ -1428,6 +1431,9 @@ func main() {
})
})
}
// `09` §3 decision 36: the warning names the kept folders on the filling drive, with their sizes —
// space the household can free on the kept-data list. Nothing is deleted by the box (D3).
fillWatcher.SetExtra(func(t fillwatch.Target) string { return keptSpaceSentence(stackMgr, t.Path) })
sched.Daily("fill-watch", "03:30", func(ctx context.Context) error { return fillWatcher.Check() })
// AND ONCE SHORTLY AFTER STARTUP. A box that BOOTS with a filesystem already over the line must
@@ -3763,3 +3769,17 @@ func budapestLoc() *time.Location {
})
return budapestLocVal
}
// keptSpaceSentence is the drive-full warning's kept-data sentence for one drive (Hungarian, like the
// warning it extends): each kept folder by app name and size. "" when the drive holds none.
func keptSpaceSentence(sm *stacks.Manager, drive string) string {
items := sm.ListKept([]string{drive})
if len(items) == 0 {
return ""
}
parts := make([]string, 0, len(items))
for _, it := range items {
parts = append(parts, fmt.Sprintf("%s (%s)", it.DisplayName, appbackup.HumanizeBytes(it.SizeBytes)))
}
return util.Text(i18n.Default, "kept.diskwarn", strings.Join(parts, ", "))
}