R-699: a unit that holds no data is never an update-precondition copy (found live on 9202)
gates / gates (push) Successful in 25s

A just-installed app's unit, captured by the status refresh before any backup, satisfied
the precondition on its manifest time; tandoor's PostgreSQL was converted with no backup
of its database. Listed still; never a copy on Tier 1 or Tier 2. Red-proof RP6.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
This commit is contained in:
2026-09-27 12:04:03 +02:00
parent b6810f14ff
commit 7fcda8f1a4
8 changed files with 89 additions and 11 deletions
+15 -4
View File
@@ -77,22 +77,33 @@ func (m *Manager) driveLabelForRoot(root string) string {
// copies `pre-restore-*` excluded — an update's own safety dump is not a backup); the manifest's time
// only for a unit that holds no data file at all, whose whole content is its definition.
func unitNewestArtifact(unitDir string) (time.Time, bool) {
t, _, ok := unitDataTime(unitDir)
return t, ok
}
// unitDataTime is unitNewestArtifact plus WHETHER THE TIME IS A PROVEN DATA TIME (R-699, v0.275.0): true
// when a data run confirmed the unit (`data` block) or it holds data files; false when the unit is only a
// captured definition — a just-installed app's unit, written by the status refresh before any backup
// ran. Such a unit is still LISTED (it can be restored: it is the app's definition), but it is never a
// copy the update's precondition may lean on — measured on 9202 2026-09-27: tandoor's two-minute-old,
// dump-less unit satisfied it and PostgreSQL was converted with no backup of the database.
func unitDataTime(unitDir string) (time.Time, bool, bool) {
fi, err := os.Stat(UnitManifestFile(unitDir))
if err != nil {
return time.Time{}, false
return time.Time{}, false, false
}
if man := readManifest(UnitManifestFile(unitDir)); man != nil {
if t, ok := man.Data.DataTime(); ok {
return t, true
return t, true, true
}
}
var newest time.Time
newest = newestDataFile(UnitDBDumpDir(unitDir), ".sql", newest)
newest = newestDataFile(UnitVolumeDumpDir(unitDir), ".tar", newest)
if newest.IsZero() {
return fi.ModTime(), true
return fi.ModTime(), false, true
}
return newest, true
return newest, true, true
}
// ListRemovedAppUnits walks backups/primary/ on every connected registered drive and returns the