v0.284.0 — a box deletes old app images (decision 53, R-736); an after_install app is held until its known login is replaced (R-741)
gates / gates (push) Successful in 27s

Image retention: after a done/undone guarded Update and at remove, an app's images older than its running
and previous one are deleted — never an image any container, installed compose or installed/previous record
names (box-wide keep set read at delete time); exact id, never forced or pruned; paused while any update runs;
a one-time sweep of catalog app images at the first start. Install hold: an after_install app is installed
behind the setup gate's door and opens when after_install succeeds or the household says it changed the login.
Tests TestImageRetention_* and TestInstallHold_* with red-proofs; parity fixture for the held card.

MinAgent: 0.131.0 (unchanged).

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
This commit is contained in:
2026-09-30 22:29:33 +02:00
parent d48da6c7f3
commit 5a3437669f
23 changed files with 1724 additions and 23 deletions
@@ -181,6 +181,9 @@ func (m *Manager) runAfterInstallNow(name string, ai *AfterInstallCommand, cmd [
m.logger.Printf("[INFO] [stacks] after_install %s: %s %v done in %s (try %d) — the app's known first login is replaced by its generated one",
name, ai.Service, ai.Command, time.Since(t0).Round(time.Millisecond), try)
record(true, "")
if err := m.OpenInstallHold(name, InstallHoldByAfterInstall); err != nil {
m.logger.Printf("[ERROR] [stacks] %s: %v — the loop retries", name, err)
}
return nil
}
last = fmt.Sprintf("try %d: err=%v, no %q in the output", try, err, ai.Success)