kept data: the choice at reinstall, the list, the read-only view, the load (09 decision 36); R-690 fixed
gates / gates (push) Successful in 26s

An install over an app's kept drive folder (appdata/<app> non-empty) asks the household:
"use my kept data" (a load from the newest copy of THIS drive's install, own unit or
second-drive mirror, then the template's after_load) or "start fresh" (the folder is
renamed into <drive>/kept/<app>/<date>/ with the removed app's unit; nothing deleted).
The install API answers 409 kept_data_choice until one is chosen; DeployStack refuses
too. New page Megorzott adatok / Kept data (/kept-data): Load / Look / Delete (typed
confirmation, the only deletion of kept data). FileBrowser gets a read-only source.
The drive-full warning names the kept folders. <drive>/kept is protected and outside
every backup leg.

R-690: the removed-app restore (R-487) never found a unit on a DATA drive — it asked
GetStackComposePath (true for every catalog app) and restored nextcloud with no env.
Now isStackDeployed; pinned with a production-shaped provider.

Red-proofs: audits/night-2026-09-26/E/redproofs/.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
This commit is contained in:
2026-09-25 13:32:30 +02:00
parent 5a731b45b9
commit 43e99d160c
44 changed files with 3311 additions and 37 deletions
@@ -142,6 +142,9 @@ type Watcher struct {
usage func(path string) *Usage
// notify pushes the customer event. Nil-safe.
notify func(Event)
// extra appends a sentence to the warning for one target — the kept folders on it the household
// can delete (`09` §3 decision 36). Nil-safe; "" appends nothing.
extra func(Target) string
mu sync.Mutex
bands map[string]Band
@@ -164,6 +167,9 @@ func New(statePath string, logger *log.Logger, targets func() []Target, usage fu
// SetNotify wires the customer event push. INIT-ONLY — call once at startup.
func (w *Watcher) SetNotify(fn func(Event)) { w.notify = fn }
// SetExtra wires the kept-data sentence (main.go). INIT-ONLY.
func (w *Watcher) SetExtra(fn func(Target) string) { w.extra = fn }
// classify decides the band from a reading AND the previous band, which is what makes the hysteresis
// work: between the clear and warn thresholds the previous band is HELD rather than recomputed.
//
@@ -231,6 +237,11 @@ func (w *Watcher) Check() error {
}
msg := Message(t, *u, next)
if w.extra != nil {
if x := w.extra(t); x != "" {
msg += " " + x
}
}
w.logger.Printf("[WARN] [fillwatch] %s (%q): %s → %s — %.0f%% used, %.1f GB free of %.1f GB; notifying the customer",
t.Path, t.Label, prev, next, u.UsedPercent, u.AvailGB, u.TotalGB)
emitted++
@@ -0,0 +1,30 @@
package fillwatch
import (
"io"
"log"
"path/filepath"
"strings"
"testing"
)
// `09` §3 decision 36 — the drive-full warning names the kept folders on that drive (and only there).
func TestFillwatch_ExtraSentenceRidesTheWarning(t *testing.T) {
var got []Event
w := New(filepath.Join(t.TempDir(), "s.json"), log.New(io.Discard, "", 0),
func() []Target { return []Target{{Path: "/mnt/d", Label: "HDD"}} },
func(string) *Usage { return &Usage{UsedPercent: 97, AvailGB: 3, UsedGB: 97, TotalGB: 100} })
w.SetNotify(func(e Event) { got = append(got, e) })
w.SetExtra(func(tg Target) string {
if tg.Path == "/mnt/d" {
return "KEPT: Nextcloud (126.0 MB)."
}
return ""
})
if err := w.Check(); err != nil {
t.Fatal(err)
}
if len(got) != 1 || !strings.HasSuffix(got[0].Message, " KEPT: Nextcloud (126.0 MB).") {
t.Fatalf("events = %+v", got)
}
}