v0.238.1: the nightly backup leaves an app alone WHILE it is being updated, not only once it is held (slice 4 follow-up)
gates / gates (push) Successful in 13s
gates / gates (push) Successful in 13s
Found live in v0.238.0 Scenario F on demo-hp: during an update's 5-minute health wait the app is not yet held, and the periodic recovery-unit capture at 10:17:09 wrote the never-started definition (alpine:3.20) into its PRIMARY unit, 53 s before the hold landed. The Tier-2 mirror the hold names survived only because Tier 2 runs daily; a nightly Tier 2 inside a verify window would have mirrored the broken definition over the copy the customer is told to restore from. backup.Manager.isHeld — consulted by the capture sweep, the Tier-2 run and the volume dump — is now also true while a guarded update is moving the app, via SetUpdatingCheck wired in main.go to stacks.Manager.IsUpdating. Test with positive control + red-proof; wiring pinned. Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
This commit is contained in:
@@ -1,3 +1,29 @@
|
||||
## v0.238.1 — the nightly backup leaves an app alone WHILE it is being updated, not only once it is held (2026-09-13, slice 4 follow-up)
|
||||
|
||||
**MinAgent: 0.129.0** (unchanged)
|
||||
|
||||
**Found live, not in review.** v0.238.0 Scenario F on demo-hp: an update to `alpine:3.20` (an image
|
||||
that exits at once) waited its 5-minute health timeout and was held at 10:18:02 — correctly. But the
|
||||
periodic recovery-unit capture ran at **10:17:09**, inside that wait, when the app was updating and
|
||||
not yet held, and wrote the never-started definition into the app's **primary** unit:
|
||||
|
||||
```
|
||||
primary-unit: image: alpine:3.20 manifest "created_at": "2026-09-13T10:17:09Z"
|
||||
tier2-mirror: image: louislam/uptime-kuma:2.4.0 manifest "created_at": "2026-09-13T10:09:51Z"
|
||||
```
|
||||
|
||||
The Tier-2 mirror the hold text names survived only because the Tier-2 run is daily. A nightly Tier-2
|
||||
falling inside a verify window would have mirrored the broken definition over the very copy the
|
||||
customer is told to restore from.
|
||||
|
||||
**Fix.** `backup.Manager.isHeld` — the predicate the capture sweep, the Tier-2 run and the volume dump
|
||||
already consult since v0.237.0 — is also true while a guarded update is moving the app, through a new
|
||||
`SetUpdatingCheck` seam wired in `main.go` to `stacks.Manager.IsUpdating`.
|
||||
|
||||
**Tests.** `TestSlice4_NightlyLegsLeaveAnAppMidUpdateAlone` (all three legs skip the updating app; the
|
||||
other app is still mirrored — positive control), red-proofed by removing the clause (the app is then
|
||||
dumped, captured and mirrored); `TestSlice4_UpdatingCheckIsWiredAtStartup`.
|
||||
|
||||
## v0.238.0 — the page follows the update, and a held app offers no way to start it (2026-09-13, update arc slice 4 Part 4)
|
||||
|
||||
**MinAgent: 0.129.0** (unchanged)
|
||||
|
||||
Reference in New Issue
Block a user