controller v0.271.0: automatic app updates — the update leg after the off-site copy, the backup gate waits, the switch (09 6.4 part 7; R-680, R-678, R-643)
gates / gates (push) Successful in 24s

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
This commit is contained in:
2026-09-24 22:07:24 +02:00
parent 1495ca43fb
commit 9cf13a3add
33 changed files with 1672 additions and 14 deletions
+27
View File
@@ -1,3 +1,30 @@
## v0.271.0 — automatic app updates: the update leg, the failed step remembered, fresh badges (2026-09-25 night, `09` §6.4 part 7, R-680, R-678, R-643)
**MinAgent: 0.131.0** (unchanged). Needs hub v0.123.0 (unchanged; the report's new `update_leg` is additive —
the hub stores the raw report). New strings: yes (hu + en).
- **The update leg** (`09` §3 decisions 11, 12, 14, 15, 20; §6.4.2 point 6 (a)–(d)): chained to the
`offbox-backup` job on every path (`chainUpdateLeg` — nil, error, panic; a box without an off-site target runs it
at W+105m). One app at a time, one tested step per app per night, through the public guarded Update only.
Skipped with a named reason: held, current (not counted), ahead, order unknown, unpinned, no test record,
older than the ladder (logged by name), not `proven`, `needs_person`, `files_may_change` without a fresh whole
copy, the step that failed before on the same ladder, W+5h reached, switched off. Transient refusals retried once.
- **Decision 20:** the full-system backup's gate defers while the leg runs, until W+5h; after it only for a step in
flight, never past W+5h30m. One shared constant (`backupwindow.UpdateLegStopOffsetMin`). The controller's own
self-update also waits for the whole leg.
- **Decision 12 — the switch:** `app_update.unattended` in `settings.json`, absent = ON; a card on the settings page
in both languages (`POST /settings/app-update`). `stacks.update_window` removed (never read).
- **R-680:** an undone or held step is recorded in `app.yaml` (`failed_update_step`, tied to the ladder's print); the
leg never presses it again until the catalog's ladder for that app changes. A person can.
- **R-678:** after `done` (and `undone`) the app's steps-left, badge inputs and pin are re-read before the update
says it finished.
- The household hears nothing new: no mail for a successful automatic step; the app page says „Automatikus
frissítés %s-kor — sikeres." / "Automatic update at %s — done.". The operator: one summary line per night in the
log and the hub report (`update_leg`).
- Decision 28: pinned that the crash-loop stop never fires during an automatic step (verify, undo). **Found:** a
DEPLOY's first start is NOT covered — `Deploying` clears when `compose up -d` returns (R-676 updated).
- Red-proofs: eleven (`felhom.eu/documentation/audits/night-2026-09-25/B/redproofs/`).
## v0.270.0 — no update for a current app; an interrupted install is reported; a restore brings back the right health check (2026-09-24, R-679, R-681, R-669, R-674)
**MinAgent: 0.131.0** (unchanged). Needs hub v0.123.0 (unchanged; R-681 rides the existing `app_deploy_failed`).