v0.263.0: a failed update puts the app back by itself (09 decision 15, R-637)
gates / gates (push) Successful in 26s
gates / gates (push) Successful in 26s
The guarded update gains a folder copy of the app's named volumes, taken after the pull where the app stops anyway (decision 19, chosen by the 2026-09-23 bake-off). On a failed health check the box undoes: every copy validated by its finished-marker first, volumes refilled, definition and pin from the job's own pre-update copies, the old version checked with the OLD .felhom.yml probe. It holds only if the undo fails, and the hold sentence says so and what state the data is in. Bind-mounted folders are never touched. - R-637 built; R-638/R-640/R-641 do not arise with a folder copy; R-639 (pre-update copies incl. .felhom.yml kept until the undo is over). - journal phases copying/undoing with power-cut recovery. - app.yaml last_update_undone + one line on the app page (hu/en). - R-642: start/restart never answer "completed". - Removal deletes kept undo copies. MinAgent unchanged (0.131.0). Nine red-proofs in REPORT.md. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
This commit is contained in:
+23
-3
@@ -577,7 +577,7 @@ job, and answers **202**. The page polls `GET /api/stacks/{name}`.
|
||||
| field | meaning |
|
||||
|---|---|
|
||||
| `updating` | a guarded update is in progress |
|
||||
| `update_phase` / `update_phase_label` | `checking`, `backing-up`, `safety-dump`, `pinning`, `pulling`, `starting`, `verifying`, `done`, `failed` — and the Hungarian label for each |
|
||||
| `update_phase` / `update_phase_label` | `checking`, `backing-up`, `safety-dump`, `pinning`, `pulling`, `copying` (v0.263.0), `starting`, `verifying`, `done`, `undoing` / `undone` (v0.263.0), `failed` — and the Hungarian label for each |
|
||||
| `update_error` | the customer sentence when the update did not complete |
|
||||
| `hold_reason` | the hold's sentence while the app is held (failed update OR failed restore) |
|
||||
|
||||
@@ -630,8 +630,28 @@ reloads when the update ends. An updating card offers no lifecycle button; a hel
|
||||
sentence with a `Mentések` link and nothing that would start it; a failed update that held nothing
|
||||
shows its sentence. These checks run BEFORE `isOperational`, which counts `restarting` as operational.
|
||||
|
||||
**Not done, deliberately:** the old version is never put back automatically — whether that works is
|
||||
per-app and was measured unpredictable. Reasoning: `felhom.eu/documentation/architecture/09-update-architecture.md` §6.
|
||||
**The undo (v0.263.0, `09` §3 decision 15).** A failed health check no longer holds the app straight
|
||||
away: the box puts the previous version back ITSELF, with its data exactly as it was seconds before
|
||||
the update, and holds only if that undo fails too. The copy is a **folder copy** (decision 19, chosen
|
||||
by a bake-off): after the pull and just before `up` — where the app stops anyway to be recreated —
|
||||
every **named volume** the app owns is copied with `cp -a` into a sibling volume
|
||||
`<volume>.pre-update-<stamp>` (label `felhom.undo-copy-of=<app>`) by an `alpine` helper, which writes a
|
||||
finished-marker last. **Bind-mounted folders (photos, documents, the drive) are never copied and never
|
||||
touched.** On failure: every copy is validated (marker present) before anything is put back; the
|
||||
volumes are emptied and refilled from the copies; the previous compose, applied definition and pin
|
||||
come from the job's own pre-update copies (never the recovery unit); the old version is checked with
|
||||
the OLD `.felhom.yml` probe (kept in `pre-update-meta/`). Success → phase `undone`, the copies go, and
|
||||
`app.yaml` records `last_update_undone: {to, at, why}` — the page shows one line under the badge until
|
||||
the next successful update. Failure → the hold, whose sentence now opens with *„A frissítés nem
|
||||
sikerült, és az automatikus visszaállítás sem."* and what state the data is in (`untouched`, `half`,
|
||||
`not_started`); the copies are kept and deleted when the app is removed. The update refuses before
|
||||
anything moves when the copy would leave less than the 2 GB floor free. A power cut while copying puts
|
||||
the old version back; a power cut while undoing resumes the undo. Reasoning and measurements:
|
||||
`felhom.eu/documentation/architecture/09-update-architecture.md` §6.1a,
|
||||
`felhom.eu/documentation/audits/undo-bakeoff-2026-09-23/`.
|
||||
|
||||
**Start/restart never answer "completed" (v0.263.0, R-642)** — they answer what was requested and the
|
||||
state the containers are in at that moment; whether the app works is the health probe's to say.
|
||||
|
||||
#### App Info Pages
|
||||
|
||||
|
||||
Reference in New Issue
Block a user