REPORT + CONTEXT: v0.271.0 (automatic app updates), floor 0.271.0, the demo boxes' first real night
gates / gates (push) Successful in 25s

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
This commit is contained in:
2026-09-25 04:55:09 +02:00
parent 9cf13a3add
commit cdfc817d5e
2 changed files with 32 additions and 25 deletions
+14 -1
View File
@@ -7,7 +7,20 @@
> >
> Ask Claude Code: "Please update CONTEXT.md with what we did today" > Ask Claude Code: "Please update CONTEXT.md with what we did today"
Last updated: 2026-09-24 evening (v0.270.0 — R-679, R-681, R-669, R-674; floor 0.270.0) Last updated: 2026-09-25 night (v0.271.0 — automatic app updates, `09` §6.4 part 7; R-680, R-678; floor 0.271.0)
> **2026-09-25 night — v0.271.0, floor 0.271.0 (MinAgent 0.131.0).** `stacks/unattended.go`: `RunUpdateLeg` — one
> app at a time, ONE step per app per night (decision 33), only `proven` entries, never `needs_person`,
> `files_may_change` only with `backup.FreshWholeCopy` (the hold's truth table), never the step in `app.yaml`
> `failed_update_step` while the ladder print is unchanged (R-680), transient refusals retried once, no step at or
> after W+5h (`backupwindow.UpdateLegStopOffsetMin`). Chained by `chainUpdateLeg` inside the `offbox-backup` job
> (every path incl. panic). `quiesce.Options.UpdateLegFn` = decision 20 + 31 (the gate waits until W+5h, then only
> for a step in flight, cap W+5h30m). Self-update waits for the whole leg (decision 32). Switch `settings.json`
> `app_update.unattended`, absent = ON, card on /settings (`POST /settings/app-update`). Page line
> `last_auto_update` („Automatikus frissítés %s-kor — sikeres."), report `update_leg`. R-678: `ScanStacks` before
> `finishUpdate` on done/undone. `stacks.update_window` REMOVED. Decisions 31–33 taken unattended (operator may
> reverse). Open: R-686 (no resume after a restart), R-687 (live-proof gaps), R-685 controller half (the backup
> page line for a space skip). Record: `felhom.eu/documentation/audits/DRILL-night-2026-09-25.md`.
> **2026-09-24 evening — v0.270.0, floor 0.270.0.** `UpdatePreflight` refuses `already_current` (R-679). > **2026-09-24 evening — v0.270.0, floor 0.270.0.** `UpdatePreflight` refuses `already_current` (R-679).
> `stacks/install_interrupted.go`: `.felhom-install-pending` marker + `RecoverInterruptedInstalls` at start (after the > `stacks/install_interrupted.go`: `.felhom-install-pending` marker + `RecoverInterruptedInstalls` at start (after the
+18 -24
View File
@@ -1,28 +1,22 @@
# REPORT — controller v0.270.0 (2026-09-24 evening, Part D of the R-672 brief) # REPORT — controller v0.271.0: automatic app updates (night 2026-09-25)
Full record: `felhom.eu/documentation/audits/r672-2026-09-24/README.md`. Architecture read: `09` §3/§6.4, `07`. **What shipped:** `09` §6.4 part 7 — the automatic update leg (`stacks/unattended.go`), chained after the off-site
leg in the `offbox-backup` job on every path (`chainUpdateLeg`); the full-system gate waits for it until W+5h
(`quiesce.Options.UpdateLegFn`, decisions 20 + 31); the per-box switch `app_update.unattended` (absent = ON) with a
card on /settings; R-680 (`failed_update_step`), R-678 (fresh steps-left at done); the page line `last_auto_update`;
the report's `update_leg`; the self-update waits for the whole leg (decision 32); `stacks.update_window` removed.
Commit `9cf13a3`, image `gitea.dooplex.hu/admin/felhom-controller:0.271.0`, floor 0.271.0 (MinAgent 0.131.0), CI job
974 success.
## Shipped — floor 0.270.0 (MinAgent 0.131.0), both demo boxes arrived in ~12 s **Red-proofs:** 11, each seen failing under its mutation and the tree restored — `felhom.eu/documentation/audits/
- **R-679:** an Update on an app already at the head → `409 already_current` (hu + en) before anything moves. night-2026-09-25/B/redproofs/SUMMARY.txt`.
- **R-681:** an install cut off by a controller restart is finished through the failure path and reported
(`app_deploy_failed`, the apps page sentence, what it started removed, stale pin records cleared).
- **R-669:** the recovery unit keeps the PINNED version's `.felhom.yml`; a restore makes it the applied record.
- **R-674:** the ladder log says "AT THE HEAD" for a pin at the head.
## Red-proofs (each seen failing, then passing; `…/r672-2026-09-24/redproofs/D-*`) **Live:** six simulated nights on 9202 (one step per app, a failing step undone and not re-pressed until re-tested,
D1 R-679 check removed → "an app at the head was allowed to update"; D2 head branch removed → "the head was called `needs_person` skipped, `files_may_change` with a whole copy taken, a kill during a step put back, a power cut
older than the ladder"; D3 restore not resetting applied-meta → "the next undo would judge with the failed step's during a verify resumed and finished, switch off = nothing pressed; data read back after every night). The demo
probe", and the unit capturing the stack dir's file → "the unit carries the failing step's probe"; D4 recovery a boxes' first real night: demo-felhom opengist 1.13 → 1.15 done in 20 s; demo-hp nothing to do; both summaries in the
no-op → "an interrupted install was not reported"; D5 page line removed → "the apps page is silent about an hub. Record: `felhom.eu/documentation/audits/DRILL-night-2026-09-25.md`.
interrupted install". Full suite green; gates OK; one new parity fixture (`stacks_install_interrupted`), no
existing fixture changed.
## Live on 9202 (endpoint level; no browser on DooPlex) **Open:** R-686 (the leg is not resumed after a restart), R-687 (live-proof gaps: W+5h live, a failing off-site leg
R-679: privatebin at the head → 409 in both languages, no backup, no pull. R-681: mealie killed during its pull → live, `files_may_change` without a copy live, the gate's wait live; `"steps": null` for an empty leg), R-685's page
"INTERRUPTED … reporting it", `app_deploy_failed` (dropped — 9202 has no hub), page sentence hu + en, no container half, R-671 / R-670 / R-677 (not started — each needs a release).
left; reinstall cleared it; actualbudget killed after its install finished → left alone. R-669: the unit captured
after the sync wrote a bad probe kept the good one; a second-drive restore turned stack 8999 / applied 3000 into
3000 / 3000. R-674: no product path (R-679 refuses that case first) — unit test only.
## Changed
A test comment called a same-version Update "the repair path"; R-679 removes that path. Restart is the repair path.