R-899: a daytime press never cancels the night's whole-guest backup (operator ruling 2026-10-08, option A); press sends trigger=manual
gates / gates (push) Successful in 1m3s
gates / gates (push) Successful in 1m3s
Unreleased; ships with tomorrow's release. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
This commit is contained in:
@@ -1,3 +1,21 @@
|
||||
## Unreleased (2026-10-08) — a daytime press never cancels the night's whole-guest backup (R-899; operator ruling 2026-10-08, option A) — ships with tomorrow's release
|
||||
|
||||
**MinAgent: 0.131.0** (unchanged — the new `trigger=manual` query is ignored by an older agent, which keeps running the
|
||||
OS leg after a press exactly as before; the night itself is fixed by the controller alone).
|
||||
|
||||
- **R-899:** the agent answers `/backup/due` from the newest archive on the tier, and a „Mentés most" press is an archive
|
||||
like any other. So a press at 08:49 made the 24 h tier due at 08:49 the next day — after the gate window
|
||||
[W+2h, W+6h) closed — and that night had no whole-guest backup, no OS leg and no kernel step (demo-hp, 2026-10-07 → 08).
|
||||
Now the quiesce loop keeps a durable ledger beside its marker (`whole-guest-ledger.json`: the last successful press and
|
||||
the last successful scheduled run per tier). A tier the agent calls „not due" is still due on the scheduled path when
|
||||
a press succeeded after its last scheduled success and that success is older than tonight's gate opening. Such an
|
||||
„owed" tier never fires the window gate's safety valve (it waits for the window). A scheduled success inside tonight's
|
||||
window ends it; a failed one does not. `internal/quiesce/nightowed.go`; tests `TestR899_*` (6; red-proved: with the
|
||||
rule off, the 2026-10-07 replay started nothing on night 2 — `started=[local local]`, and two more failed).
|
||||
- The press now reaches the agent as `POST /backup?…trigger=manual` (`agentapi.StartBackupForTrigger`); an agent that
|
||||
knows it runs no OS leg after a press (agent, same day). Test `TestR899_PressCarriesTriggerManual` asserts the query the
|
||||
agent receives for each of the four shapes.
|
||||
|
||||
## v0.303.0 — after a restart, a backup capture waits for the drive (R-897; `09` §3 decision 176) (2026-10-07)
|
||||
|
||||
**MinAgent: 0.131.0** (unchanged — no agent route is read; the signal is the controller's own mount table).
|
||||
|
||||
Reference in New Issue
Block a user