kept data: the choice at reinstall, the list, the read-only view, the load (09 decision 36); R-690 fixed
gates / gates (push) Successful in 26s
gates / gates (push) Successful in 26s
An install over an app's kept drive folder (appdata/<app> non-empty) asks the household: "use my kept data" (a load from the newest copy of THIS drive's install, own unit or second-drive mirror, then the template's after_load) or "start fresh" (the folder is renamed into <drive>/kept/<app>/<date>/ with the removed app's unit; nothing deleted). The install API answers 409 kept_data_choice until one is chosen; DeployStack refuses too. New page Megorzott adatok / Kept data (/kept-data): Load / Look / Delete (typed confirmation, the only deletion of kept data). FileBrowser gets a read-only source. The drive-full warning names the kept folders. <drive>/kept is protected and outside every backup leg. R-690: the removed-app restore (R-487) never found a unit on a DATA drive — it asked GetStackComposePath (true for every catalog app) and restored nextcloud with no env. Now isStackDeployed; pinned with a production-shaped provider. Red-proofs: audits/night-2026-09-26/E/redproofs/. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
This commit is contained in:
@@ -192,12 +192,16 @@ func (m *Manager) RestoreFromRecoveryUnit(stackName string) (UnitRestoreResult,
|
||||
// backups/primary/<stack> on its own drive. For a REMOVED app (R-487) the drive is no longer known
|
||||
// — GetAppDrivePath falls back to the system path — so a unit kept on a data drive was unreachable
|
||||
// and the restore silently took the volume-only fallback. It is now found where it sits.
|
||||
//
|
||||
// R-690 (2026-09-25): "removed" is asked with isStackDeployed — the removed-app list's OWN predicate.
|
||||
// It used to be GetStackComposePath's ok, which in production is true for EVERY catalog app (every
|
||||
// template is a stack), so this branch never ran on a box: nextcloud's unit on a data drive was
|
||||
// missed, the restore took the volume-only fallback, and the app came back with no env and no
|
||||
// database. Pinned by TestR690_RemovedUnitFoundWhenTheStackStillExists (production-shaped provider).
|
||||
func (m *Manager) primaryUnitDirFor(stackName string) string {
|
||||
if m.stackProvider != nil {
|
||||
if _, deployed := m.stackProvider.GetStackComposePath(stackName); !deployed {
|
||||
if u, found := m.RemovedAppUnitFor(stackName); found {
|
||||
return u.UnitDir
|
||||
}
|
||||
if m.stackProvider != nil && !m.isStackDeployed(stackName) {
|
||||
if u, found := m.RemovedAppUnitFor(stackName); found {
|
||||
return u.UnitDir
|
||||
}
|
||||
}
|
||||
return RecoveryUnitPath(m.namespaceRoot(m.GetAppDrivePath(stackName)), stackName)
|
||||
|
||||
Reference in New Issue
Block a user