R-403 fix, caught by the live run: the stale flag fired for every healthy app
gates / gates (push) Successful in 11s

UnitRestoreDate also compared the package's date against the run's and flagged 'older'. A recovery
unit is ALWAYS captured shortly before the run that mirrors it, so that comparison is true for every
healthy app. Measured on demo-hp: bookstack, kimai, opengist and privatebin all had src and dest
manifests at 12:03:49Z against a run at 12:14:24Z - perfectly healthy, and all four would have been
told their package was stale.

A warning that fires on everything is a warning nobody reads, which costs the same as the comforting
lie it was meant to replace. The second return is now UnitLegPreserved and nothing else.

TestR403_AHealthyAppIsNeverCalledStale pins it; red-proof: reinstate the comparison -> it fails.
This commit is contained in:
2026-08-31 14:22:32 +02:00
parent 2358e561b7
commit 5429d651ee
2 changed files with 51 additions and 5 deletions
+14 -5
View File
@@ -284,18 +284,27 @@ func (c Tier2Coverage) Tier2CopyDate() (date string, proven bool) {
}
// UnitRestoreDate returns the date of the PACKAGE the unit restore would actually open, and whether
// that package is OLDER than the copy's newest run.
// the newest run PRESERVED that package rather than refreshing it.
//
// R-403. `Tier2CopyDate` answers "when was this copy last written to" and is right for the file
// restore, whose legs really were refreshed by that run. It is the WRONG answer for the unit restore
// after a preserved leg, because the package is then older than the run that reports success. This
// after a preserved leg, because the package is then from before the run that reports success. This
// asks the manifest first and falls back to the copy date only when the package cannot say.
func (c Tier2Coverage) UnitRestoreDate() (date string, olderThanTheRun bool) {
copyDate, _ := c.Tier2CopyDate()
//
// THE SECOND RETURN IS `UnitLegPreserved` AND NOTHING ELSE, and the first draft got this wrong in a
// way only the live run caught. It also compared the package's date against the run's and flagged
// "older" — but a unit is ALWAYS captured shortly before the run that mirrors it, so that comparison
// was true for every healthy app on the box and every one of them rendered the warning. Live on
// demo-hp 2026-08-31: bookstack, kimai, opengist and privatebin all had src and dest manifests at
// `12:03:49Z` against a run at `12:14:24Z` — perfectly healthy, and all four would have been told
// their package was stale. A warning that fires on everything is a warning nobody reads, which costs
// the same as the comforting lie it was meant to replace.
func (c Tier2Coverage) UnitRestoreDate() (date string, preserved bool) {
if c.UnitPackageDate == "" {
copyDate, _ := c.Tier2CopyDate()
return copyDate, c.UnitLegPreserved
}
return c.UnitPackageDate, c.UnitLegPreserved || (copyDate != "" && c.UnitPackageDate < copyDate)
return c.UnitPackageDate, c.UnitLegPreserved
}
// tier2RecordedCopyDir resolves the RECORDED Tier-2 copy dir for a stack, applying every