diff --git a/CONTEXT.md b/CONTEXT.md index 49609c0..a85fa39 100644 --- a/CONTEXT.md +++ b/CONTEXT.md @@ -7,7 +7,17 @@ > > Ask Claude Code: "Please update CONTEXT.md with what we did today" -Last updated: 2026-09-25 night (v0.271.0 — automatic app updates, `09` §6.4 part 7; R-680, R-678; floor 0.271.0) +Last updated: 2026-09-27 (v0.275.0 — a backup's data and its version travel together; floor 0.275.0) + +> **2026-09-27 — v0.275.0, floor 0.275.0 (MinAgent 0.131.0).** `backup/data_versions.go`: `stampDataFile` (called by the +> DB leg, the volume leg and `RunAppBackupNow` — a new writer of a unit data file MUST call it), `foldUnitData`, +> `RecoveryManifest.Data`; `captureRecoveryUnit(stack, dataRun)` keeps `compose/` when the pins moved since the data +> (frozen); `unitVersionCheck`/`ErrUnitVersionMismatch` in the unit restore and the off-site reconstitute (which now +> writes the snapshot's definition when versions differ); `unitDataTime` = THE unit data time (+ proven flag, R-699); +> Tier 2 `DataDate`/`DataUnproven`; Tier 3 `offsiteDataTime`; `stacks.DumpStampSource` (optional guards interface) + +> `ConversionCopy.Service`; `stacks.RestoredVersionPosition` + the restore pages' first sentence; R-695 single-flight +> FB sync; R-691 `keptReadGroups`/`group_add` (CC-unattended decision, `07` §6.5); R-694 `restored_logins`. +> D4 (open) option A is the built behaviour — `07` §6.6. > **2026-09-25 midday — v0.272.0, floor 0.272.0.** `web.noSpaceLine` (agent prefix `skipped: not enough space: `, > key `backup.tier.no_space`); `backup.SetUndoCopyRemover` → `stacks.RemoveUndoCopies` from `clearUpdateHoldAfterRestore` diff --git a/REPORT.md b/REPORT.md index af39130..f63a647 100644 --- a/REPORT.md +++ b/REPORT.md @@ -1,31 +1,26 @@ -# REPORT — controller v0.273.0 + v0.274.0 (2026-09-25) +# REPORT — v0.275.0: a backup's data and its version travel together (2026-09-26/27) -Two releases in one session, as the brief allowed: **v0.273.0** (`5a731b4`) — the PostgreSQL major conversion -(`09` §3 decisions 35, 37, 38; §6.4 part 10) + R-687's two small items; **v0.274.0** (`64cbefe`) — kept data (decision -36) + R-690 + R-692. Floor 0.273.0 then 0.274.0, MinAgent 0.131.0 declared both times, read back from the hub; both -demo boxes arrived healthy within ~25 s each time. CI: `5a731b4` job 1002 success. +Brief: version-travel (Parts A, D2–D4). Architecture: `07-backup-architecture.md` §6 (+ new §6.6), `09` §3, §5.3, §6.4. +Session record: `felhom.eu/documentation/audits/DRILL-version-travel-2026-09-26.md`. -**The conversion** (`internal/stacks/pgconvert.go`): only on a ladder step marked `engine_conversion`; a PostgreSQL -major move without the mark is refused by the preflight and the job. Phase `converting` after the undo copy: old -engine alone → check (owners, encodings, roles, extensions, per-table row counts) → `pg_dumpall` with its completion -line → the volume emptied only after the copy's marker is validated again → new engine alone → entrypoint databases -dropped, existing roles' `CREATE ROLE` skipped → load with `ON_ERROR_STOP` → check equal + `PG_VERSION`. Any failure, -and a restart during `converting`, runs the existing undo. The old datadir's copy stays until a backup is proven -after the conversion (hourly `conversion-copy-release`). **Live on 9202** (`0.273.0-rc1`, drill catalog): docmost -16 → 18 done in 42 s (9.9 s of engine work, 48 tables / 71 rows equal); the load failing (`adminpack`, gone in 17+) → -undone in 43.6 s; the app unhealthy on 18 → undone in 148 s; SIGKILL one second after the volume was emptied → the -restart undid it in 40 s; each ending on 16 with the seed read back. Found live and fixed: the recovery line said -UNDOING for a restart during `converting`. **Red-proofs:** 9 (conversion) + 2 (R-687) + 1 (R-692) here; the Part E -build carries 10 more (`felhom.eu/documentation/audits/night-2026-09-26/E/redproofs/`). +**Baseline:** `main` `fb2bcdd5d619`, v0.274.0, floor 0.274.0. **Commits:** `b6810f1` (Part A, R-695, R-691 (1), R-694), +`7fcda8f` (R-699, found live). **Released:** image `0.275.0` (rc `0.275.0-rc1` for the live proofs); floor 0.275.0 with +MinAgent 0.131.0 — both demo boxes on 0.275.0 within 15 s (`audits/version-travel-2026-09-26/R/`); 9202 by hand (scratch). -**Kept data** (`internal/stacks/kept.go`, `internal/web/kept_handlers.go`, `internal/api/kept_install.go`): built by a -parallel helper session in its own worktree, reviewed and proven here. The install over a non-empty drive folder answers -409 `kept_data_choice` until „use my kept data" / „start fresh" is chosen; the „Megőrzött adatok" / "Kept data" page -lists, loads, deletes (typed); a read-only file-browser source; `/kept` protected and never backed up; the -drive-full warning names kept folders. **R-692 found live** (the list named leftovers „Filebrowser") and fixed before -the release. **Live on 9202** (endpoint level, both languages): the whole E5 walk passed — see -`felhom.eu/documentation/audits/night-2026-09-26/E/E5-*`. +**Tests:** full suite green (`go build/vet/test ./...` rc=0) after the last change; controller gates all OK. New tests: +`internal/backup/a_version_travel_test.go` (15), `internal/stacks` `TestA5_TheReleaseRefusesAPreConversionDump`, +`TestA4_AnOldRecordWithoutAServiceChecksEveryPostgresImage`, `TestA3_RestoredVersionPosition`, `TestR695_*`, `TestR694_*`, +`internal/web` `TestA3_RestoredVersionSentence`, `TestR695_*`, `TestR691_*` (2), `TestR694_*`; new parity fixture +`deploy_deployed_restored_login`. Two AST fixture names updated (`TestAdmission_IsWiredIntoEveryProductionWriteLeg`). -**Not done:** R-691 (a 0770 folder is not readable in the view; "use" does not look off-site); R-694 (what the page -shows after a load regenerates a withheld login secret) — measure first. Full session record: -`felhom.eu/documentation/audits/DRILL-night-2026-09-26.md`. +**Red-proofs (each seen failing, tree restored)** — `felhom.eu/documentation/audits/version-travel-2026-09-26/`: +RP1 Tier 1 time = manifest ("the refresh 1s made a two-hour-old dump read as new"); RP2/RP2b the refresh rewrites +`compose/` (the restore started 16 data with `postgres:18`); RP3 no version check (mismatch/mixed restored); RP4 the +release on a pre-conversion dump ("released [nextcloud]; copies=0"); RP5 off-site uses the live definition; RP6 R-699 (a +dump-less unit accepted); D2 R-695 ×2; D3 R-691 ×2; D4 R-694. + +**Live (endpoint level, 9202):** `A5-live/README.md` — both shapes restore the old version whole and climb again; the box's +own night showed the frozen definition and the data-time restore point. + +**NOT yet live-validated:** the off-site restore's definition write; the conversion-copy release on a real 18 dump (due +after 9202's next nightly backup); R-691 (1) with a real 0770 folder; the English restore sentence.