kept data: the choice at reinstall, the list, the read-only view, the load (09 decision 36); R-690 fixed
gates / gates (push) Successful in 26s

An install over an app's kept drive folder (appdata/<app> non-empty) asks the household:
"use my kept data" (a load from the newest copy of THIS drive's install, own unit or
second-drive mirror, then the template's after_load) or "start fresh" (the folder is
renamed into <drive>/kept/<app>/<date>/ with the removed app's unit; nothing deleted).
The install API answers 409 kept_data_choice until one is chosen; DeployStack refuses
too. New page Megorzott adatok / Kept data (/kept-data): Load / Look / Delete (typed
confirmation, the only deletion of kept data). FileBrowser gets a read-only source.
The drive-full warning names the kept folders. <drive>/kept is protected and outside
every backup leg.

R-690: the removed-app restore (R-487) never found a unit on a DATA drive — it asked
GetStackComposePath (true for every catalog app) and restored nextcloud with no env.
Now isStackDeployed; pinned with a production-shaped provider.

Red-proofs: audits/night-2026-09-26/E/redproofs/.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
This commit is contained in:
2026-09-25 13:32:30 +02:00
parent 5a731b45b9
commit 43e99d160c
44 changed files with 3311 additions and 37 deletions
@@ -0,0 +1,78 @@
package api
import (
"encoding/json"
"io"
"log"
"net/http"
"net/http/httptest"
"os"
"path/filepath"
"testing"
"gitea.dooplex.hu/admin/felhom-controller/internal/config"
"gitea.dooplex.hu/admin/felhom-controller/internal/stacks"
)
// `09` §3 decision 36 — the install API answers an install over old data with the CHOICE (409,
// code kept_data_choice, both sentences, "use" OFF when no database copy exists) and installs nothing;
// "use" without a copy is refused; "fresh" is left to DeployStack. Nothing here reaches Docker.
// COMPANION RED-PROOF: make keptDataAtInstall return false at once → the no-choice case writes nothing
// and the first assertion fails (the install would go on to DeployStack).
func TestKept_InstallAPIAsksAndInstallsNothing(t *testing.T) {
dir := t.TempDir()
drive := filepath.Join(dir, "drive")
cfg := &config.Config{}
cfg.Paths.StacksDir = filepath.Join(dir, "stacks")
cfg.Stacks.ComposeCommand = "docker compose"
app := filepath.Join(cfg.Paths.StacksDir, "cloudapp")
for _, d := range []string{app, filepath.Join(drive, "appdata/cloudapp")} {
if err := os.MkdirAll(d, 0o755); err != nil {
t.Fatal(err)
}
}
_ = os.WriteFile(filepath.Join(app, "docker-compose.yml"), []byte("services:\n cloudapp:\n image: busybox\n volumes:\n - ${HDD_PATH}/appdata/cloudapp:/data\n"), 0o644)
_ = os.WriteFile(filepath.Join(app, ".felhom.yml"), []byte("display_name: Cloud App\n"), 0o644)
_ = os.WriteFile(filepath.Join(drive, "appdata/cloudapp/old.txt"), []byte("old"), 0o644)
m, err := stacks.NewManager(cfg, log.New(io.Discard, "", 0))
if err != nil {
t.Fatal(err)
}
if err := m.ScanStacks(); err != nil {
t.Fatal(err)
}
r := &Router{stackMgr: m, logger: log.New(io.Discard, "", 0)}
call := func(choice string) (bool, int, map[string]interface{}) {
w := httptest.NewRecorder()
req := httptest.NewRequest(http.MethodPost, "/api/stacks/cloudapp/deploy?lang=en", nil)
handled := r.keptDataAtInstall(w, req, "cloudapp", drive, choice)
var body map[string]interface{}
_ = json.Unmarshal(w.Body.Bytes(), &body)
return handled, w.Code, body
}
handled, code, body := call("")
data, _ := body["data"].(map[string]interface{})
if !handled || code != http.StatusConflict || data["code"] != "kept_data_choice" {
t.Fatalf("no choice: handled=%v code=%d body=%v", handled, code, body)
}
if data["title"] != "This app's old data is still here" || data["use_offered"] != false ||
data["use_off"] != "There is no backup of the database, so the app cannot load the old files. You can look at the files under Kept data." ||
data["fresh_label"] != "Start fresh" || data["not_backed_up"] != "This is not backed up." {
t.Fatalf("the choice's sentences: %v", data)
}
if handled, code, _ := call("use"); !handled || code != http.StatusConflict {
t.Fatalf("use with no copy: handled=%v code=%d", handled, code)
}
if handled, _, _ := call("fresh"); handled {
t.Fatal("fresh must be left to DeployStack (which moves the old data aside)")
}
if st, _ := m.GetStack("cloudapp"); st.Deployed || st.Deploying {
t.Fatal("something was installed")
}
// No old data → the API does not interfere.
_ = os.RemoveAll(filepath.Join(drive, "appdata/cloudapp"))
if handled, _, _ := call(""); handled {
t.Fatal("an install with no old data was intercepted")
}
}