controller v0.240.0: seven defects from the any-tier proof and the first nightly rotation
gates / gates (push) Successful in 13s

R-486 (P1): removing an app with its backups KEPT keeps its Tier-2 record,
so the second-drive restore is no longer refused over an intact mirror.
R-484: postgis/pgvector/timescaledb images are Postgres (logical dumps).
R-485: the backup card sizes the recovery unit and the mirror(s).
R-480: a held update's sentence leaves the card once the hold is lifted.
R-477: the update's off-site lookup is one snapshots call, no stats.
R-478: a copy older than this install's deploy does not count.
R-474: "delete backups" deletes the unit, the mirror(s) and the prefs.

Tests and red-proofs per row; evidence in felhom.eu
documentation/audits/v0240-2026-09-13/ and nightly-2026-09-13-adventurelog/.
This commit is contained in:
2026-09-13 19:26:50 +02:00
parent 0e3d831030
commit bdcbd50b42
20 changed files with 673 additions and 82 deletions
+41
View File
@@ -1,3 +1,44 @@
## v0.240.0 — seven defects the any-tier proof and the first nightly rotation found (2026-09-13, R-486 / R-484 / R-485 / R-480 / R-477 / R-478 / R-474)
**MinAgent: 0.129.0** (unchanged)
Four were found live proving v0.239.0 in the afternoon; three more the same evening by the first
"be a customer for the night" walk on demo-hp (`adventurelog`, `felhom.eu` `audits/nightly-2026-09-13-adventurelog/`).
Each is fixed, tested and red-proofed.
- **R-486 (P1) — removing an app with its backups KEPT no longer forgets its second-drive copy.**
`removeStack` cleared the cross-drive record on every removal, so the „Teljes visszaállítás" the
customer kept the backups for was refused with „nincs másodlagos fájlmásolat" over an intact 236 MB
mirror. The record — with the rest of the app's backup preferences — now goes only with
`remove_backups`.
- **R-484 (P2) — PostGIS, pgvector and TimescaleDB images are Postgres.** `dbTypeForImage` matched the
substring `postgres` only, so `postgis/postgis:16-3.5-alpine` was "not a database": no nightly
dump, no pre-update safety dump, no DB-only replay window for the app.
- **R-485 — the backup card (`GET /api/stacks/{name}/backup-data`) sizes the recovery unit and the
Tier-2 mirror(s)**, not a `db-dumps` directory and a pre-v2 `secondary/<app>/rsync` path. It
answered `has_backups:false` over 484 MB.
- **R-480 — the card no longer tells a customer a running app is stopped.** After a held update, the
hold's sentence stayed as `update_error` after a successful restore cleared the hold, and after
removal. The stack remembers that its last update ended held; `fillHoldReason` hides that outcome
once the hold is gone or the app is not deployed. A pull failure keeps its (still true) sentence.
- **R-477 — the update's off-site lookup is one `snapshots` call.** It went through
`OffsiteInventoryList`, which also runs one `stats` per app; on demo-hp that spent the whole 15 s
bound and killed a size call for an unrelated app. New `OffsiteSnapshotTimes`; both share
`offsiteNewestPerTag`.
- **R-478 — a copy older than this install's deploy does not count.** A reinstalled app leaned on a
unit left by its removed predecessor. `usableRestorePoint` = the age rule plus "not older than
`deployed_at`"; the update after a restore backs up first.
- **R-474 — "delete backups" deletes the backups.** The whole recovery unit, the app's Tier-2
mirror on any registered drive (`Tier2MirrorDirsForApp` / `RemoveTier2Mirrors`, exact-path
checked, never another app's or the shares mirror) and the app's backup preferences. Off-site
snapshots are not touched. `volumes_removed` still reads `null` over removed volumes — that half of
R-474 stays open.
**TESTS.** `internal/stacks/r480_r478_test.go`, `internal/stacks/r485_backup_card_test.go`,
`internal/backup/r477_r474_test.go`, `internal/api/r474_remove_wiring_test.go` (R-474 + R-486),
`internal/appbackup/dbservices_test.go` (R-484 cases). **Red-proofs** in the felhom.eu audit dir
`audits/v0240-2026-09-13/`: each fix removed in turn fails its test.
## v0.239.0 — any backup tier lets an app update (2026-09-13, R-475)
**MinAgent: 0.129.0** (unchanged)