v0.277.0: kept data loads from the off-site copy too (R-691 (2))
gates / gates (push) Successful in 25s
gates / gates (push) Successful in 25s
Use my kept data / Load consider the off-site snapshot when it is newer than every local copy or the only one; the unit is downloaded alone, judged (drive, data, recorded data version) and only then restored. The page names the copy and its date. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
This commit is contained in:
@@ -1,3 +1,25 @@
|
||||
## v0.277.0 — „Use my kept data" and Load also bring the database back from the off-site copy (R-691 (2)) (2026-09-28)
|
||||
|
||||
**MinAgent: 0.131.0** (unchanged). Needs hub v0.123.0 (unchanged). New strings: `kept.backup.offsite`,
|
||||
`kept.choice.use.desc_from`, `err.kept.offsite_version_unknown`, `err.kept.offsite_not_usable` (hu + en). Evidence:
|
||||
`felhom.eu/documentation/audits/kept-offsite-2026-09-28/`.
|
||||
|
||||
- **The choice looks off-site too.** `backup.KeptBestCopy` = the newest usable local copy (own unit, second drive) or
|
||||
the off-site copy when it is NEWER or the only one (a tie goes local — no download). The off-site copy is asked with
|
||||
ONE `snapshots --json` (bounded 20 s; the kept list asks once per page) and offered only when its newest snapshot
|
||||
holds the app's recovery unit. Dated by its data time (`07` §6.6 A4).
|
||||
- **The page names the copy and its date.** The install choice now says „Az adatbázist innen töltjük vissza: távoli
|
||||
mentés, 2026-09-28 04:15. …"; the kept list says „távoli mentés, …" in its copy column (shared `backup.KeptCopyKey`).
|
||||
- **The load (`LoadKeptOffsite`)** downloads the unit ALONE (the nightly proof's unit-only restore, into the proof
|
||||
scratch), judges it — holds data, taken of THIS drive, and its data version is RECORDED (`07` §6.6: a unit with no
|
||||
`data` block is refused, never loaded blind; mixed or mismatched is refused by `unitVersionCheck`) — and only then
|
||||
moves a dated folder's files back and runs the one unit restore (`RestoreFromRecoveryUnitAt`). The downloaded copy is
|
||||
removed on every path BEFORE the outcome is reported. A failed download or a refusal leaves the kept files as they were.
|
||||
- Tests: `TestR691_OffsiteCopyIsOfferedWhenItIsTheOnlyOrNewest`, `TestR691_OffsiteLoadDownloadsJudgesThenRestores`,
|
||||
`TestR691_OffsiteLoadRefusalsLeaveTheKeptFilesAlone` (4 refusals), `TestR691_InstallChoiceNamesTheOffsiteCopy`
|
||||
(hu + en). Red-proofs RP1 (0.276.0's local-only choice), RP2 (no version refusal), RP3 (the copy removed after the
|
||||
outcome — seen in the first draft), each seen failing.
|
||||
|
||||
## v0.276.0 — a restore and a drive move keep the app's records (R-697, R-700) (2026-09-27)
|
||||
|
||||
**MinAgent: 0.131.0** (unchanged). Needs hub v0.123.0 (unchanged). New strings: none. Evidence:
|
||||
|
||||
Reference in New Issue
Block a user