REPORT + CONTEXT: v0.271.0 (automatic app updates), floor 0.271.0, the demo boxes' first real night
gates / gates (push) Successful in 25s

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
This commit is contained in:
2026-09-25 04:55:09 +02:00
parent 9cf13a3add
commit cdfc817d5e
2 changed files with 32 additions and 25 deletions
+18 -24
View File
@@ -1,28 +1,22 @@
# REPORT — controller v0.270.0 (2026-09-24 evening, Part D of the R-672 brief)
# REPORT — controller v0.271.0: automatic app updates (night 2026-09-25)
Full record: `felhom.eu/documentation/audits/r672-2026-09-24/README.md`. Architecture read: `09` §3/§6.4, `07`.
**What shipped:** `09` §6.4 part 7 — the automatic update leg (`stacks/unattended.go`), chained after the off-site
leg in the `offbox-backup` job on every path (`chainUpdateLeg`); the full-system gate waits for it until W+5h
(`quiesce.Options.UpdateLegFn`, decisions 20 + 31); the per-box switch `app_update.unattended` (absent = ON) with a
card on /settings; R-680 (`failed_update_step`), R-678 (fresh steps-left at done); the page line `last_auto_update`;
the report's `update_leg`; the self-update waits for the whole leg (decision 32); `stacks.update_window` removed.
Commit `9cf13a3`, image `gitea.dooplex.hu/admin/felhom-controller:0.271.0`, floor 0.271.0 (MinAgent 0.131.0), CI job
974 success.
## Shipped — floor 0.270.0 (MinAgent 0.131.0), both demo boxes arrived in ~12 s
- **R-679:** an Update on an app already at the head → `409 already_current` (hu + en) before anything moves.
- **R-681:** an install cut off by a controller restart is finished through the failure path and reported
(`app_deploy_failed`, the apps page sentence, what it started removed, stale pin records cleared).
- **R-669:** the recovery unit keeps the PINNED version's `.felhom.yml`; a restore makes it the applied record.
- **R-674:** the ladder log says "AT THE HEAD" for a pin at the head.
**Red-proofs:** 11, each seen failing under its mutation and the tree restored — `felhom.eu/documentation/audits/
night-2026-09-25/B/redproofs/SUMMARY.txt`.
## Red-proofs (each seen failing, then passing; `…/r672-2026-09-24/redproofs/D-*`)
D1 R-679 check removed → "an app at the head was allowed to update"; D2 head branch removed → "the head was called
older than the ladder"; D3 restore not resetting applied-meta → "the next undo would judge with the failed step's
probe", and the unit capturing the stack dir's file → "the unit carries the failing step's probe"; D4 recovery a
no-op → "an interrupted install was not reported"; D5 page line removed → "the apps page is silent about an
interrupted install". Full suite green; gates OK; one new parity fixture (`stacks_install_interrupted`), no
existing fixture changed.
**Live:** six simulated nights on 9202 (one step per app, a failing step undone and not re-pressed until re-tested,
`needs_person` skipped, `files_may_change` with a whole copy taken, a kill during a step put back, a power cut
during a verify resumed and finished, switch off = nothing pressed; data read back after every night). The demo
boxes' first real night: demo-felhom opengist 1.13 → 1.15 done in 20 s; demo-hp nothing to do; both summaries in the
hub. Record: `felhom.eu/documentation/audits/DRILL-night-2026-09-25.md`.
## Live on 9202 (endpoint level; no browser on DooPlex)
R-679: privatebin at the head → 409 in both languages, no backup, no pull. R-681: mealie killed during its pull →
"INTERRUPTED … reporting it", `app_deploy_failed` (dropped — 9202 has no hub), page sentence hu + en, no container
left; reinstall cleared it; actualbudget killed after its install finished → left alone. R-669: the unit captured
after the sync wrote a bad probe kept the good one; a second-drive restore turned stack 8999 / applied 3000 into
3000 / 3000. R-674: no product path (R-679 refuses that case first) — unit test only.
## Changed
A test comment called a same-version Update "the repair path"; R-679 removes that path. Restart is the repair path.
**Open:** R-686 (the leg is not resumed after a restart), R-687 (live-proof gaps: W+5h live, a failing off-site leg
live, `files_may_change` without a copy live, the gate's wait live; `"steps": null` for an empty leg), R-685's page
half, R-671 / R-670 / R-677 (not started — each needs a release).