v0.269.1: an installed app keeps the image digest it runs until a guarded Update moves it
gates / gates (push) Successful in 26s

Found live on 9202 (night 2026-09-24 Part B): the sync rendered the ladder's newest
tested digest into a RUNNING app's compose, so the next restart would pull a new image
with no backup and no undo. stacks.CarryDigests keeps the running digest for an
installed app; a fresh install still takes the tested digest. Red-proofed.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
This commit is contained in:
2026-09-24 13:01:31 +02:00
parent 3c6b49b31c
commit 5b1b191ffc
6 changed files with 138 additions and 27 deletions
+3 -1
View File
@@ -713,7 +713,9 @@ a replaced older one beside as `.felhom-<ts>`) and then restores the unit from t
`app_stopped_unhealthy`. Start gives one more try; a repeat within 24 h says support is informed.
**Exact images (v0.269.0, `09` §6.4 part 6).** The compose that runs pins `tag@sha256` from the ladder entry that
tested it; pins stay plain; a floating tag reads Behind only for a newer TESTED digest. An update judges the new
tested it; pins stay plain; a floating tag reads Behind only for a newer TESTED digest. A fresh install takes the
tested digest; an INSTALLED app keeps the digest it runs until a guarded update moves it — the sync carries it
over and never renders a newer one (v0.269.1, `CarryDigests`). An update judges the new
version by its own `.felhom.yml` (the step's, or the catalog's). A stranded app's Remove keeps the data.
**Start/restart never answer "completed" (v0.263.0, R-642)** — they answer what was requested and the