controller v0.242.0: a removed app is listed with its kept backup; five small ones (R-487 R-491 R-490 R-489 R-476 R-456)
gates / gates (push) Successful in 14s

R-487: the local backup lists are keyed on the drives, not on what is
deployed — a removed app whose unit was kept is listed with the restore
that reinstalls it, the picker answers for it, and the restore opens the
unit where it sits. R-491: a removal clears the app's update hold.
R-490: /api/system/info reaches the API router and reads the default
storage path. R-489: volumes_removed is the real before/after difference,
[] when none. R-476: a Tier-2 copy is dated by its data, not its manifest.
R-456: the boot-orphan rule is pinned. Every fix red-proofed.
This commit is contained in:
2026-09-13 22:50:18 +02:00
parent c1f62ddae8
commit d698ce343b
22 changed files with 838 additions and 13 deletions
+38
View File
@@ -1,3 +1,41 @@
## v0.242.0 — a removed app is listed with its kept backup, and five small ones (2026-09-13/14, R-487 / R-491 / R-490 / R-489 / R-476 / R-456)
**MinAgent: 0.129.0** (unchanged)
- **R-487 (P2) — a removed app whose backups were kept is listed, with the restore that brings it
back.** After „Töröld az adataimat is" with the backups kept, the unit sat on the drive and was
restorable through `POST /backup/restore` — and listed on NEITHER backup page (measured on demo-hp
with adventurelog). The local lists are now keyed on the DRIVES the way R-237 keyed the off-site
list on the store: `Manager.ListRemovedAppUnits` walks `backups/primary/` on the system path and
every connected registered drive and lists the units whose app is not deployed. The Mentések page
renders them after the deployed rows („Eltávolítva — visszaállítható", one action: *Visszaállítás
a mentésből*), the Visszaállítás picker lists them in their own group, `GET /api/backup/snapshots`
answers for them instead of 404, and the restore opens the unit WHERE IT SITS
(`primaryUnitDirFor`) — a unit kept on a data drive used to be unreachable, because the drive of a
removed app is unknown and the fallback named the system path.
- **R-476 — a Tier-2 copy is dated by its data, not by its manifest.** The manifest moves only when
the app's definition changes, so a copy holding a dump from 00:30 today was dated the day before.
`Tier2Coverage.UnitDataDate` (newest dump in the mirrored unit) is what a refreshed leg names; a
PRESERVED package keeps the manifest date (R-403).
- **R-491 (P2) — a removal clears the app's update hold.** An app held after a failed update and then
removed kept its hold in the store, so a reinstall under the same name would begin refused with a
sentence about a copy that no longer existed (measured on demo-hp with nextcloud). `removeStack` now
clears an UPDATE hold (`Settings.ClearUpdateHold`); an R-379 restore hold stays operator-cleared.
- **R-490 — the monitoring page's memory-distribution card can render.** `/api/system/info` was eaten
by the web layer's `/api/system/` prefix (404 „ismeretlen végpont"); an exact-path mount on the API
router wins in ServeMux. `systemInfo` also gained the default-storage-path fallback every other
reader of the empty `cfg.Paths.HDDPath` already had (R-465).
- **R-489 — `volumes_removed` reports the volumes a removal removed**, `[]` when none — never `null`:
the project's volumes are listed before and after `down --volumes` and the difference is reported
(compose's progress lines are printed to a TTY it does not have here).
- **R-456 — the boot-orphan rule is pinned:** an absent member does not make a stack degraded, so a
partly-dead stack is not a boot orphan; a present-but-dead member is (`internal/bootrecon/r456_partly_dead_test.go`).
**Tests / red-proofs:** `TestR487_` (lister over two drives, picker, unit dir, row builder, two
render tests with negative controls), `TestR476_` (date rule + coverage reader), `TestR491_` (wiring),
`TestR490_` (mount + behaviour), `TestR489_` (difference, never null, the docker listing), `TestR456_`;
red-proofs in `felhom.eu` `audits/v0242-2026-09-14/`.
## v0.241.0 — a bind-data app leans on off-site before its own unit, and the hold says what the copy holds (2026-09-13, R-479)
**MinAgent: 0.129.0** (unchanged)