R-553: four decisions stop reading their own Hungarian words (sites 1-4)

Every Hungarian sentence is byte-identical; each decision now reads a signal set where the message is
made. util.KindErrorf builds the same bytes fmt.Errorf did while carrying a sentinel for errors.Is.

- Deploy status (api/router.go): deployStatusFor() by kind — stacks.ErrAlreadyDeployed (409),
  ErrRequiredField / ErrPathMissing / ErrNotEnoughMemory (400). The „kötelező" / „memória" /
  "does not exist" / "already deployed" text chain is gone.
- Off-site failure class (backup/offbox.go): ErrOffsiteQuota replaces the „tárhelykeretet" match. The
  restic/ssh signatures stay text matches on purpose — that output is not ours and is not translated.
- Alert placement (web/alerts.go): monitor.HealthReport carries WarningKinds parallel to Warnings;
  the "not on a separate drive" warning is inline by KIND. The hub report is untouched (builder.go
  copies Status/Issues/Warnings only) — pinned by a wire test.
- Stale off-site note (web/handlers.go): settings LastWarningKind + backup.OffboxWarnNoAppsSelected.
  The text test survives ONLY for kind == "" (a box whose last run predates 0.251.0) and is removed
  when R-570 closes; slice 2 must not translate that producer before then.

Tests (all red-proofed by restoring the pre-fix predicate — see the audit's redproofs.txt):
TestR553_Deploy_DecisionSurvivesWordingChange, TestR553_DeployHandlerUsesTheKind,
TestR553_DeployProducersCarryKindAndKeepTheirWords (through the real DeployStack),
TestR553_OffsiteQuota_{Decision,HeadLine}SurvivesWordingChange, TestR553_OffboxRunRecordsTheKind,
TestR553_StorageWarningsCarryKindsAndKeepTheirWords, TestR553_DiskWarningPlacementSurvivesWordingChange,
TestR553_HubReportWarningsAreUnchangedOnTheWire, TestR553_StaleNote*, TestR553_WarningKindIsPersistedAndCopied.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
This commit is contained in:
2026-09-17 20:58:45 +02:00
parent e236dca486
commit c00fed6db3
19 changed files with 816 additions and 55 deletions
@@ -0,0 +1,137 @@
package stacks
import (
"errors"
"io"
"log"
"os"
"path/filepath"
"strings"
"testing"
"gitea.dooplex.hu/admin/felhom-controller/internal/config"
)
// r553Manager builds a real Manager over a temp stacks dir holding one app fixture, so DeployStack's
// own validation runs — no stub, no modelled predicate.
func r553Manager(t *testing.T, felhomYml string) *Manager {
t.Helper()
dir := t.TempDir()
cfg := &config.Config{}
cfg.Paths.StacksDir = filepath.Join(dir, "stacks")
cfg.Paths.SystemDataPath = filepath.Join(dir, "system")
cfg.Stacks.ComposeCommand = "docker compose" // no detection; nothing is executed in this test
appDir := filepath.Join(cfg.Paths.StacksDir, "r553app")
if err := os.MkdirAll(appDir, 0o755); err != nil {
t.Fatal(err)
}
if err := os.WriteFile(filepath.Join(appDir, "docker-compose.yml"), []byte("services:\n app:\n image: busybox\n"), 0o644); err != nil {
t.Fatal(err)
}
if err := os.WriteFile(filepath.Join(appDir, ".felhom.yml"), []byte(felhomYml), 0o644); err != nil {
t.Fatal(err)
}
m, err := NewManager(cfg, log.New(io.Discard, "", 0))
if err != nil {
t.Fatal(err)
}
if err := m.ScanStacks(); err != nil {
t.Fatal(err)
}
if _, ok := m.GetStack("r553app"); !ok {
t.Fatal("fixture invalid: the app was not scanned, so DeployStack would refuse for the wrong reason")
}
return m
}
// R-553 — the deploy refusals carry their KIND, and their Hungarian sentences are byte-for-byte what
// they were before the kinds existed (a localisation-adjacent change may not move one byte of copy).
//
// RED-PROOF (REPORT): drop the kind from either producer in deploy.go (back to plain fmt.Errorf) and
// the errors.Is assertion fails, while the message assertion still passes — which is exactly the
// silent state this row exists to prevent.
func TestR553_DeployProducersCarryKindAndKeepTheirWords(t *testing.T) {
cases := []struct {
name string
yml string
values map[string]string
kind error
wantMsg string
}{
{
name: "required field left empty",
yml: "display_name: R553\ndeploy_fields:\n - env_var: DATA_DIR\n label: Adatmappa\n type: text\n required: true\n",
values: map[string]string{},
kind: ErrRequiredField,
wantMsg: `a(z) "Adatmappa" (DATA_DIR) mező kitöltése kötelező`,
},
{
name: "password field left empty",
yml: "display_name: R553\ndeploy_fields:\n - env_var: ADMIN_PW\n label: Jelszó\n type: password\n",
values: map[string]string{},
kind: ErrRequiredField,
wantMsg: `a(z) "Jelszó" mező kitöltése kötelező — használja a Generálás gombot vagy írjon be egy jelszót`,
},
{
name: "path field naming something that is not there",
yml: "display_name: R553\ndeploy_fields:\n - env_var: MEDIA\n label: Média\n type: path\n",
values: map[string]string{"MEDIA": "/definitely/not/here/r553"},
kind: ErrPathMissing,
wantMsg: `path "/definitely/not/here/r553" does not exist for field "Média"`,
},
}
for _, c := range cases {
t.Run(c.name, func(t *testing.T) {
m := r553Manager(t, c.yml)
_, err := m.DeployStack(DeployRequest{StackName: "r553app", Values: c.values})
if err == nil {
t.Fatal("deploy was admitted — the fixture no longer exercises the refusal")
}
if !errors.Is(err, c.kind) {
t.Errorf("refusal carries no kind: %v (want errors.Is … %v)", err, c.kind)
}
if err.Error() != c.wantMsg {
t.Errorf("the customer's sentence CHANGED:\n got %q\nwant %q", err.Error(), c.wantMsg)
}
})
}
}
// The already-deployed refusal, on the same Manager: its words are unchanged and it carries its kind
// (the API answers 409 from that kind).
func TestR553_AlreadyDeployedCarriesKindAndKeepsItsWords(t *testing.T) {
m := r553Manager(t, "display_name: R553\n")
m.mu.Lock()
m.stacks["r553app"].Deployed = true
m.mu.Unlock()
_, err := m.DeployStack(DeployRequest{StackName: "r553app"})
if err == nil {
t.Fatal("a deployed stack was admitted for a second deploy")
}
if !errors.Is(err, ErrAlreadyDeployed) {
t.Errorf("refusal carries no kind: %v", err)
}
if want := `stack "r553app" is already deployed; use update instead`; err.Error() != want {
t.Errorf("message CHANGED:\n got %q\nwant %q", err.Error(), want)
}
}
// The memory refusal is a string built by memoryVerdict from the HOST's real memory, so a unit test
// cannot make it fire. Its kind is therefore pinned where it is attached — at the one line that turns
// that string into an error. Source-level on purpose, like TestDeployAcceptance_DoesNotClaimTheAppIsInstalled:
// the defect this guards is a call written the old way, not a wrong value. The status mapping itself
// is covered by TestR553_Deploy_DecisionSurvivesWordingChange with a translated memory message.
func TestR553_MemoryRefusalIsWrappedWithItsKind(t *testing.T) {
src, err := os.ReadFile("deploy.go")
if err != nil {
t.Fatal(err)
}
body := string(src)
if !strings.Contains(body, `util.KindError(ErrNotEnoughMemory, refusal)`) {
t.Error("the memory refusal no longer carries ErrNotEnoughMemory — the API would answer 500 " +
"for a refusal the customer can act on, and translating the sentence would hide it completely")
}
if strings.Contains(body, `errors.New(refusal)`) {
t.Error("the memory refusal is back to a bare errors.New: its kind is gone (R-553)")
}
}