R-553: four decisions stop reading their own Hungarian words (sites 1-4)

Every Hungarian sentence is byte-identical; each decision now reads a signal set where the message is
made. util.KindErrorf builds the same bytes fmt.Errorf did while carrying a sentinel for errors.Is.

- Deploy status (api/router.go): deployStatusFor() by kind — stacks.ErrAlreadyDeployed (409),
  ErrRequiredField / ErrPathMissing / ErrNotEnoughMemory (400). The „kötelező" / „memória" /
  "does not exist" / "already deployed" text chain is gone.
- Off-site failure class (backup/offbox.go): ErrOffsiteQuota replaces the „tárhelykeretet" match. The
  restic/ssh signatures stay text matches on purpose — that output is not ours and is not translated.
- Alert placement (web/alerts.go): monitor.HealthReport carries WarningKinds parallel to Warnings;
  the "not on a separate drive" warning is inline by KIND. The hub report is untouched (builder.go
  copies Status/Issues/Warnings only) — pinned by a wire test.
- Stale off-site note (web/handlers.go): settings LastWarningKind + backup.OffboxWarnNoAppsSelected.
  The text test survives ONLY for kind == "" (a box whose last run predates 0.251.0) and is removed
  when R-570 closes; slice 2 must not translate that producer before then.

Tests (all red-proofed by restoring the pre-fix predicate — see the audit's redproofs.txt):
TestR553_Deploy_DecisionSurvivesWordingChange, TestR553_DeployHandlerUsesTheKind,
TestR553_DeployProducersCarryKindAndKeepTheirWords (through the real DeployStack),
TestR553_OffsiteQuota_{Decision,HeadLine}SurvivesWordingChange, TestR553_OffboxRunRecordsTheKind,
TestR553_StorageWarningsCarryKindsAndKeepTheirWords, TestR553_DiskWarningPlacementSurvivesWordingChange,
TestR553_HubReportWarningsAreUnchangedOnTheWire, TestR553_StaleNote*, TestR553_WarningKindIsPersistedAndCopied.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
This commit is contained in:
2026-09-17 20:58:45 +02:00
parent e236dca486
commit c00fed6db3
19 changed files with 816 additions and 55 deletions
+7 -2
View File
@@ -34,10 +34,10 @@ type Settings struct {
// separate enabled flag — an empty token matches nothing). LauncherSharePasswordHash is an
// OPTIONAL bcrypt hash for a per-share password, ALWAYS SEPARATE from the admin PasswordHash above.
// The token is a secret and must never be logged.
LauncherShareToken string `json:"launcher_share_token,omitempty"`
LauncherShareToken string `json:"launcher_share_token,omitempty"`
// Language (v0.247.0, i18n) — the household's dashboard language: "hu" | "en". Empty means never
// chosen and reads as Hungarian (GetLanguage). Reported to the hub so its e-mails can follow.
Language string `json:"language,omitempty"`
Language string `json:"language,omitempty"`
LauncherSharePasswordHash string `json:"launcher_share_password_hash,omitempty"`
// FileBrowser admin login (R-513, v0.243.0). Every box used to accept admin/admin. The controller
@@ -368,6 +368,11 @@ type OffboxTarget struct {
// LastWarning is a customer-visible notice set on an otherwise-OK run when SOME toggled apps had
// no discoverable recovery unit (partial run). Empty on a fully-successful or failed run.
LastWarning string `json:"last_warning,omitempty"`
// LastWarningKind names WHAT LastWarning is about, so the page can react to it without reading its
// Hungarian words (R-553). Today one kind exists: OffboxWarnNoAppsSelected, the zero-selection
// notice the Távoli mentés page replaces once apps HAVE been selected. Written by the run that
// writes LastWarning, cleared with it.
LastWarningKind string `json:"last_warning_kind,omitempty"`
// EnlargedBlocked (3a) lists the apps whose ENLARGED (mandatory-userdata) offsite push was refused
// by the pre-push quota gate on the last run — their unit-only push still succeeded. Replaced each
// OK run (sorted; empty clears). Drives the per-app "config+DB only" note on /backups/remote and