R-699: a unit that holds no data is never an update-precondition copy (found live on 9202)
gates / gates (push) Successful in 25s

A just-installed app's unit, captured by the status refresh before any backup, satisfied
the precondition on its manifest time; tandoor's PostgreSQL was converted with no backup
of its database. Listed still; never a copy on Tier 1 or Tier 2. Red-proof RP6.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
This commit is contained in:
2026-09-27 12:04:03 +02:00
parent b6810f14ff
commit 7fcda8f1a4
8 changed files with 89 additions and 11 deletions
+5 -1
View File
@@ -100,6 +100,9 @@ type Tier2Coverage struct {
// demo-hp a copy holding a dump written at 00:30Z was dated by a manifest from the day before.
// RFC3339 UTC; "" when the unit is not readable.
UnitDataDate string
// UnitDataUnproven (R-699, v0.275.0) — the mirrored unit holds no proven data (no `data` block, no
// data file): restorable as a definition, never a copy the update's precondition may lean on.
UnitDataUnproven bool
}
// CanRestore reports whether the FILE restore has any subtree to read at all.
@@ -148,8 +151,9 @@ func tier2CoverageAt(destBase string) Tier2Coverage {
// R-403: ask the package itself when it was made. Reading the artifact rather than the status
// record is what makes this date impossible to overstate.
c.UnitPackageDate = unitPackageDate(unitDir)
if newest, ok := unitNewestArtifact(unitDir); ok {
if newest, proven, ok := unitDataTime(unitDir); ok {
c.UnitDataDate = newest.UTC().Format(time.RFC3339)
c.UnitDataUnproven = !proven
}
return c
}