v0.263.0: a failed update puts the app back by itself (09 decision 15, R-637)
gates / gates (push) Successful in 26s

The guarded update gains a folder copy of the app's named volumes, taken
after the pull where the app stops anyway (decision 19, chosen by the
2026-09-23 bake-off). On a failed health check the box undoes: every copy
validated by its finished-marker first, volumes refilled, definition and pin
from the job's own pre-update copies, the old version checked with the OLD
.felhom.yml probe. It holds only if the undo fails, and the hold sentence
says so and what state the data is in. Bind-mounted folders are never
touched.

- R-637 built; R-638/R-640/R-641 do not arise with a folder copy; R-639
  (pre-update copies incl. .felhom.yml kept until the undo is over).
- journal phases copying/undoing with power-cut recovery.
- app.yaml last_update_undone + one line on the app page (hu/en).
- R-642: start/restart never answer "completed".
- Removal deletes kept undo copies.

MinAgent unchanged (0.131.0). Nine red-proofs in REPORT.md.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
This commit is contained in:
2026-09-23 11:12:49 +02:00
parent b9deec1907
commit 8fc2b4a1a9
26 changed files with 1326 additions and 69 deletions
+23 -3
View File
@@ -577,7 +577,7 @@ job, and answers **202**. The page polls `GET /api/stacks/{name}`.
| field | meaning |
|---|---|
| `updating` | a guarded update is in progress |
| `update_phase` / `update_phase_label` | `checking`, `backing-up`, `safety-dump`, `pinning`, `pulling`, `starting`, `verifying`, `done`, `failed` — and the Hungarian label for each |
| `update_phase` / `update_phase_label` | `checking`, `backing-up`, `safety-dump`, `pinning`, `pulling`, `copying` (v0.263.0), `starting`, `verifying`, `done`, `undoing` / `undone` (v0.263.0), `failed` — and the Hungarian label for each |
| `update_error` | the customer sentence when the update did not complete |
| `hold_reason` | the hold's sentence while the app is held (failed update OR failed restore) |
@@ -630,8 +630,28 @@ reloads when the update ends. An updating card offers no lifecycle button; a hel
sentence with a `Mentések` link and nothing that would start it; a failed update that held nothing
shows its sentence. These checks run BEFORE `isOperational`, which counts `restarting` as operational.
**Not done, deliberately:** the old version is never put back automatically — whether that works is
per-app and was measured unpredictable. Reasoning: `felhom.eu/documentation/architecture/09-update-architecture.md` §6.
**The undo (v0.263.0, `09` §3 decision 15).** A failed health check no longer holds the app straight
away: the box puts the previous version back ITSELF, with its data exactly as it was seconds before
the update, and holds only if that undo fails too. The copy is a **folder copy** (decision 19, chosen
by a bake-off): after the pull and just before `up` — where the app stops anyway to be recreated —
every **named volume** the app owns is copied with `cp -a` into a sibling volume
`<volume>.pre-update-<stamp>` (label `felhom.undo-copy-of=<app>`) by an `alpine` helper, which writes a
finished-marker last. **Bind-mounted folders (photos, documents, the drive) are never copied and never
touched.** On failure: every copy is validated (marker present) before anything is put back; the
volumes are emptied and refilled from the copies; the previous compose, applied definition and pin
come from the job's own pre-update copies (never the recovery unit); the old version is checked with
the OLD `.felhom.yml` probe (kept in `pre-update-meta/`). Success → phase `undone`, the copies go, and
`app.yaml` records `last_update_undone: {to, at, why}` — the page shows one line under the badge until
the next successful update. Failure → the hold, whose sentence now opens with *„A frissítés nem
sikerült, és az automatikus visszaállítás sem."* and what state the data is in (`untouched`, `half`,
`not_started`); the copies are kept and deleted when the app is removed. The update refuses before
anything moves when the copy would leave less than the 2 GB floor free. A power cut while copying puts
the old version back; a power cut while undoing resumes the undo. Reasoning and measurements:
`felhom.eu/documentation/architecture/09-update-architecture.md` §6.1a,
`felhom.eu/documentation/audits/undo-bakeoff-2026-09-23/`.
**Start/restart never answer "completed" (v0.263.0, R-642)** — they answer what was requested and the
state the containers are in at that moment; whether the app works is the health probe's to say.
#### App Info Pages