kept data: the choice at reinstall, the list, the read-only view, the load (09 decision 36); R-690 fixed
gates / gates (push) Successful in 26s

An install over an app's kept drive folder (appdata/<app> non-empty) asks the household:
"use my kept data" (a load from the newest copy of THIS drive's install, own unit or
second-drive mirror, then the template's after_load) or "start fresh" (the folder is
renamed into <drive>/kept/<app>/<date>/ with the removed app's unit; nothing deleted).
The install API answers 409 kept_data_choice until one is chosen; DeployStack refuses
too. New page Megorzott adatok / Kept data (/kept-data): Load / Look / Delete (typed
confirmation, the only deletion of kept data). FileBrowser gets a read-only source.
The drive-full warning names the kept folders. <drive>/kept is protected and outside
every backup leg.

R-690: the removed-app restore (R-487) never found a unit on a DATA drive — it asked
GetStackComposePath (true for every catalog app) and restored nextcloud with no env.
Now isStackDeployed; pinned with a production-shaped provider.

Red-proofs: audits/night-2026-09-26/E/redproofs/.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
This commit is contained in:
2026-09-25 13:32:30 +02:00
parent 5a731b45b9
commit 43e99d160c
44 changed files with 3311 additions and 37 deletions
+9 -2
View File
@@ -417,7 +417,7 @@ func (r *Router) getDeployFields(w http.ResponseWriter, req *http.Request, name
// Pinned by TestR553_Deploy_DecisionSurvivesWordingChange.
func deployStatusFor(err error) int {
switch {
case errors.Is(err, stacks.ErrAlreadyDeployed):
case errors.Is(err, stacks.ErrAlreadyDeployed), errors.Is(err, stacks.ErrKeptDataChoice):
return http.StatusConflict
case errors.Is(err, stacks.ErrRequiredField), errors.Is(err, stacks.ErrPathMissing),
errors.Is(err, stacks.ErrNotEnoughMemory):
@@ -432,7 +432,8 @@ func (r *Router) deployStack(w http.ResponseWriter, req *http.Request, name stri
r.dbg("deployStack: name=%s contentLength=%d", name, req.ContentLength)
var body struct {
Values map[string]string `json:"values"`
Values map[string]string `json:"values"`
KeptData string `json:"kept_data"`
}
if err := json.NewDecoder(req.Body).Decode(&body); err != nil {
writeJSON(w, http.StatusBadRequest, apiResponse{OK: false, Error: "invalid request body"})
@@ -490,9 +491,15 @@ func (r *Router) deployStack(w http.ResponseWriter, req *http.Request, name stri
return
}
// `09` §3 decision 36: the app's drive folder already holds its old data → the household chooses.
if handled := r.keptDataAtInstall(w, req, name, body.Values["HDD_PATH"], body.KeptData); handled {
return
}
deployReq := stacks.DeployRequest{
StackName: name,
Values: body.Values,
KeptData: body.KeptData,
}
warning, err := r.stackMgr.DeployStack(deployReq)