v0.291.0: decision 78 (R-726) — a returning household's first night sets the orphaned copy aside; R-838 — traefik v3.7.13, cloudflared 2026.9.3, filebrowser 1.5.6-stable, a release now moves a running file browser, check-infra-pins.py
gates / gates (push) Successful in 31s

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
This commit is contained in:
2026-10-04 10:56:19 +02:00
parent 99a1497560
commit fc796dd95e
8 changed files with 258 additions and 18 deletions
+15 -5
View File
@@ -875,14 +875,24 @@ func (m *Manager) ensureOffboxRepo(ctx context.Context, base, env []string) erro
return nil
case "orphaned":
// The repo EXISTS but is keyed under a passphrase we no longer have (the reinstall shape). An
// UNCLAIMED (as-delivered) box auto-resets (Scenario B); a CLAIMED box surfaces the orphan card
// and skips until the customer confirms a reset (Scenario C). Move-aside, never delete.
if !m.settings.GetClaimed() {
m.logger.Printf("[INFO] [offbox] orphaned repo on an UNCLAIMED box — auto-resetting (move-aside + re-init)")
// UNCLAIMED (as-delivered) box auto-resets (Scenario B). So does a CLAIMED box that has NEVER made
// an off-site copy itself (LastSuccess empty) — a returning household's new box on its first night
// (`09` §3 decision 78, R-726): without this it would make no off-site copy until someone pressed
// the reset button. A claimed box that HAS made copies surfaces the orphan card and skips until the
// customer confirms (Scenario C) — its key changing is a real fault, not a new box. Move-aside, never
// delete; the old copy can be put back. Pinned by TestOffbox_OrphanDetection_* and TestR726_*.
t0 := m.settings.GetOffboxTarget()
firstNight := t0 != nil && t0.LastSuccess == ""
if !m.settings.GetClaimed() || firstNight {
reason := "auto (unclaimed)"
if m.settings.GetClaimed() {
reason = "auto (returning household — this box never made an off-site copy; decision 78)"
}
m.logger.Printf("[INFO] [offbox] orphaned repo, %s — setting the old copy aside (move-aside + re-init, nothing deleted)", reason)
if m.offboxOrphanEvent != nil {
m.offboxOrphanEvent("offbox_repo_orphaned", "")
}
if rerr := m.resetOrphanedRepo(ctx, base, env, "auto (unclaimed)"); rerr != nil {
if rerr := m.resetOrphanedRepo(ctx, base, env, reason); rerr != nil {
m.markOrphaned() // auto-reset failed → fall back to the orphan card so it isn't silent
return ErrOffboxOrphaned
}
@@ -5,6 +5,8 @@ import (
"fmt"
"strings"
"testing"
"gitea.dooplex.hu/admin/felhom-controller/internal/settings"
)
// classifyResticProbe maps the exact restic stderr to a repo class (the 2026-07-17 diagnosis
@@ -59,7 +61,10 @@ func wrongPwRunner(seen *[]string) offboxRunner {
// no state → these assertions FAIL.
func TestOffbox_OrphanDetection_Claimed(t *testing.T) {
m, sett := newOffboxManager(t)
if err := sett.SetClaimed(); err != nil { // claimed → orphan card, NEVER auto-reset
if err := sett.SetClaimed(); err != nil { // claimed AND has made copies before → orphan card, NEVER auto-reset
t.Fatal(err)
}
if err := sett.UpdateOffboxStatus(func(o *settings.OffboxTarget) { o.LastSuccess = "2026-10-01T02:00:00Z" }); err != nil {
t.Fatal(err)
}
var events []string
@@ -170,3 +175,71 @@ func TestOffbox_ConfirmedReset(t *testing.T) {
t.Fatal("state not cleared after confirmed reset")
}
}
// R-726, decision 78: a CLAIMED box that has NEVER made an off-site copy (a returning household's new box, night
// one) sets the old copy aside by itself and makes its first copy — as an unclaimed box does. The old copy is
// moved, never deleted, and recorded so it can be put back. Red-proof: drop `|| firstNight` and this fails while
// TestOffbox_OrphanDetection_Claimed still passes.
func TestR726_ReturningHouseholdFirstNightSetsAside(t *testing.T) {
m, sett := newOffboxManager(t)
if err := sett.SetClaimed(); err != nil {
t.Fatal(err)
}
var events []string
m.SetOffboxOrphanEvent(func(evt, _ string) { events = append(events, evt) })
var sshCmds []string
m.SetOffboxSSH(func(_ context.Context, _, _ string, _ int, _, _, remoteCmd string) ([]byte, error) {
sshCmds = append(sshCmds, remoteCmd)
if strings.HasPrefix(remoteCmd, "test -e") {
return nil, fmt.Errorf("exit status 1")
}
return nil, nil
})
var seen []string
m.SetOffboxRunner(wrongPwRunner(&seen))
if err := m.RunOffboxBackup(context.Background()); err != nil {
t.Fatalf("the first night must make a copy, got %v", err)
}
if m.OffboxOrphaned() {
t.Fatal("the returning household's box stayed orphaned")
}
got := sett.GetOffboxTarget()
if !strings.Contains(got.OrphanedRenamedTo, ".orphaned-") {
t.Fatalf("the old copy's new place is not recorded (it must be listable and restorable): %q", got.OrphanedRenamedTo)
}
for _, c := range sshCmds {
if strings.HasPrefix(c, "rm ") || strings.Contains(c, "rm -") {
t.Fatalf("something was deleted: %q", c)
}
}
backedUp := false
for _, s := range seen {
backedUp = backedUp || s == "init"
}
if !backedUp {
t.Fatalf("no fresh repository was started: %v", seen)
}
if len(events) != 2 || events[0] != "offbox_repo_orphaned" || events[1] != "offbox_repo_reset" {
t.Fatalf("events = %v, want [orphaned reset]", events)
}
}
// A box whose repository is NOT orphaned changes nothing (no move, no reset event).
func TestR726_NotOrphanedChangesNothing(t *testing.T) {
m, sett := newOffboxManager(t)
_ = sett.SetClaimed()
var events []string
m.SetOffboxOrphanEvent(func(evt, _ string) { events = append(events, evt) })
var sshCmds []string
m.SetOffboxSSH(func(_ context.Context, _, _ string, _ int, _, _, remoteCmd string) ([]byte, error) {
sshCmds = append(sshCmds, remoteCmd)
return nil, nil
})
m.SetOffboxRunner(func(_ context.Context, _ []string, args ...string) ([]byte, error) { return nil, nil })
if err := m.RunOffboxBackup(context.Background()); err != nil {
t.Fatalf("run: %v", err)
}
if len(events) != 0 || len(sshCmds) != 0 || sett.GetOffboxTarget().OrphanedRenamedTo != "" {
t.Fatalf("a healthy repository was touched: events=%v ssh=%v", events, sshCmds)
}
}