# REPORT — controller v0.240.0: seven defects from the any-tier proof and the first nightly rotation (2026-09-13) *Overwritten each run. This records the most recent implementation only.* > **Shipped as v0.240.0 and delivered to both demo guests by the managed floor** (declared MinAgent > 0.129.0): demo-hp at +16 s, demo-felhom at +18 s from the save. Every row proven live on demo-hp > with a throwaway adventurelog. Evidence: `felhom.eu/documentation/audits/v0240-2026-09-13/`. ## What changed (`bdcbd50`) | Row | Change | Live proof | |---|---|---| | R-486 (P1) | removal keeps the Tier-2 record unless `remove_backups` | remove-keep → record kept → „Teljes visszaállítás" restored 2 volumes + the DB, data identical | | R-484 | `postgis`/`pgvector`/`timescaledb` are Postgres | `db-dumps/adventurelog-postgres.sql` (8 MB) in the unit and mirror | | R-485 | the backup card sizes the unit + mirror(s) | `244M` + `244M`, `has_backups:true` | | R-480 | a held update's sentence leaves the card with the hold | card clean after a restore | | R-477 | the Tier-3 lookup is one `snapshots` call | unit-tested; the R-408 walk registers the shared reader | | R-478 | a copy older than `deployed_at` does not count | unit-tested (the leftover unit R-474 now removes) | | R-474 | "delete backups" deletes the unit, mirror(s), prefs | 244M + 243.6 MB removed, nothing left, prefs `None` | ## Gates, tests, red-proofs - `go build ./... && go vet ./... && go test ./...` green (28 packages); `controller_gates.py --fast` green. - Red-proofs, all valid (RUN > 0, FAIL > 0, file restored byte-identical): `rp-v240-R486-…`, `R484`, `R485`, `R480` (first attempt inert — the mutation did not compile; rerun with a compiling one), `R478`, `R477`, `R474`. - `internal/backup` takes 5½ minutes on its own (89 tests with real waits) — R-488. ## Observations 1. **Two concurrent `go test` runs of the backup package looked like a hang; the package is slow alone.** FILED: R-488 2. **`volumes_removed: null` still reported over removed volumes.** FILED: R-489 3. **The first R-480 red-proof was inert (a non-compiling mutation, RUN=0).** NOT-A-FINDING: harness discipline, caught by the RUN count rule and rerun; recorded here so the pattern stays visible.