v0.290.0: the clean-up guard skips same-day superseded young snapshots instead of refusing (R-824), refuses above the weekly cap; a due set-aside deletion is handed to the hub's 7-day wait (decision 74, R-823)
gates / gates (push) Successful in 27s

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
This commit is contained in:
2026-10-04 07:27:38 +02:00
parent c4bf730637
commit c1a73b24b3
10 changed files with 309 additions and 68 deletions
+20
View File
@@ -1,3 +1,23 @@
## v0.290.0 — the clean-up guard lets an honest window through (R-824); a due set-aside deletion goes to the hub (decision 74, R-823) (2026-10-04)
**MinAgent: 0.131.0** (unchanged). **Needs hub v0.128.0** (`abandon-request` / `-status` / `-cancel`; the window cap of
half). No new household string — the page keeps its dated deletion text, now with the hub's date.
- **R-824 — the guard no longer refuses every window after a manual run.** A YOUNG (< 8 days) snapshot that a newer
same-day snapshot of its group (`--group-by host,tags`) supersedes is EXCLUDED from the plan — it is removed in a later
window once older — instead of refusing the run. Measured shape: demo-hp window 1 (2026-10-03), the night run's
copies superseded by a manual run. A young removal WITHOUT a same-day successor still REFUSES (the poisoning
signature). Future-dated snapshots and snapshots newer than the hub allows still refuse. A plan larger than the hub's
`max_remove` (one week's retention) now REFUSES (was: take the oldest) — per the 2026-10-04 brief; cost recorded in R-833.
- **R-823 — the household's "delete my earlier off-site backups" works again on the append-only tier.** When the
countdown is due, the box hands the set-aside path to the hub (`HubAbandonClient`), which deletes it after its own
7-day wait; the box follows the hub's status (deleted → the two-phase commit completes as before; cancelled → the
countdown ends). A recovery on the box cancels at the hub. The backups page and the banner keep showing a dated,
cancellable deletion (the hub's date). `offbox_abandon_deferred` (v0.289) is gone.
- Tests: `TestOffsiteGuard_SameDaySupersededYoungExcluded`, `TestOffsiteGuard_AboveWeeklyCapRefused`,
`TestOffsiteGuard_HonestPlanPrunesOldestFirst`, `TestAbandon_PinnedHandsToHubAndFollows` — red-proofs in
`felhom.eu/documentation/audits/offsite-finish-2026-10-04/red-proofs-controller.txt`.
## v0.289.1 — the provider's rclone notice no longer reads as "0 snapshots" (found live on demo-felhom) (2026-10-03)
**MinAgent: 0.131.0** (unchanged). Needs hub v0.127.0 (unchanged).