controller v0.178.0 — R-88 Part 2: only a positive 'never' fires the valve

MinAgent: 0.105.0. scheduledRunAllowed fired on any nil age; it now requires a
licence from valveLicensed, which grants it for AgeStateAbsent and for a LEGACY
agent, and refuses it for AgeStateUnknown. An unreadable storage no longer
masquerades as a first-ever backup and no longer quiesces apps outside the window.

A missing wire field means legacy, not unknown — deliberately. Treating it as
unknown would stop the valve firing on un-upgraded boxes and starve genuinely new
ones. Degrade logged once; unrecognised future values also map to legacy.

Caught in passing: TieredBackend is satisfied by a RUNTIME assertion, so the
signature change compiled and vetted clean while quiesceBackend silently stopped
satisfying it — which would have degraded every box to the single-tier path with
no error. Added a compile-time witness.

Also corrects the notifier comment that claimed operator-only came from a missing
customerMessages entry; enforcement is hub-side operatorOnlyEvents (hub 0.79.0).
This commit is contained in:
2026-07-27 18:08:56 +02:00
parent ba8bf9cd75
commit 86ea482fc1
12 changed files with 390 additions and 43 deletions
@@ -40,7 +40,7 @@ func TestScheduledRunAllowed(t *testing.T) {
{"unparseable window fails open", atBudapest(12, 0), "nonsense", h(20), true},
}
for _, c := range cases {
if got := scheduledRunAllowed(c.now, c.window, c.age, cadence24); got != c.want {
if got := scheduledRunAllowed(c.now, c.window, c.age, true, cadence24); got != c.want {
t.Errorf("%s: scheduledRunAllowed(%s, %q, age, cadence) = %v, want %v",
c.name, c.now.Format("15:04"), c.window, got, c.want)
}