# REPORT — controller v0.242.0: a removed app is listed with its kept backup, and five small ones (2026-09-13 night) *Overwritten each run. This records the most recent implementation only.* > **Nightly session under `.claude/rules/unprompted-work.md`.** Architecture read and named: > `felhom.eu/documentation/architecture/07-backup-architecture.md` (§6.3 restore destination, the > R-237 store-keyed list rule) and `09-update-architecture.md` (holds). Shipped as **v0.242.0** > (`d698ce3`), delivered by the managed floor with the declared MinAgent 0.129.0: demo-hp +16 s, > demo-felhom +17 s; hand-set on the scratch guest 9202 (the one place that is allowed). Evidence: > `felhom.eu/documentation/audits/v0242-2026-09-14/`. ## What changed - **R-487 (P2)** — `backup.ListRemovedAppUnits` walks `backups/primary/` on the system path and every connected registered drive and returns the units whose app is not deployed. The Mentések page lists them after the deployed rows („Eltávolítva — visszaállítható", one action: *Visszaállítás a mentésből* = `POST /backup/restore`), the Visszaállítás picker lists them in their own group, `GET /api/backup/snapshots` answers for them, and `RestoreFromRecoveryUnit` opens the unit where it sits (`primaryUnitDirFor`) — a unit kept on a data drive was unreachable before. The claim text is registered with the retrieval-promise gate as conditional on the readable unit. - **R-491 (P2)** — `removeStack` clears an UPDATE hold (`Settings.ClearUpdateHold`), never an R-379 restore hold. Logged. - **R-490** — `/api/system/info` mounted exactly ahead of the web layer's `/api/system/` prefix; `systemInfo` reads the default storage path like every other reader of the empty global. Nil-safe on the syncer. **The global's deletion is R-492.** - **R-489** — `volumes_removed` is the before/after difference of the project's volumes, `[]` when none. **Measured limit, row kept open:** the listing filters on the compose project label and a volume recreated by a unit restore (`docker volume create`) carries none — compose removes it, the response says `[]`. A fresh compose volume is reported. - **R-476** — `Tier2Coverage.UnitDataDate`: a refreshed leg is dated by its newest dump, a preserved package keeps the manifest date (R-403). - **R-456** — the boot-orphan rule pinned by a test; design unchanged. ## Proof - Red-proofs (each a compiling mutation that made its test fail, restored byte-identical): `rp-v242-*.txt` — R-487 ×6 (lister inert, picker 404, wrong unit dir, row not built, row not rendered, picker not rendered), R-491, R-490 ×2, R-489, R-476. - Full gate green before the build (`go build/vet/test ./...`, `controller_gates.py --fast`). - Live on 9202 (endpoint-level, the exact endpoints the UI invokes; no browser on DooPlex): an opengist throwaway — `GET /api/system/info` 200 with the drive figures; a seeded update hold cleared by the removal (log line + store), the app redeployed by the restore without refusal; the removed app's row, badge, form, picker option and snapshot API all present, „Visszaállítás a mentésből" reinstalled it running in 9.1 s; two captures under one definition dated the Tier-2 confirm by the second capture's dump (22:58 against a manifest from 22:52). First pass was refused 409 (a running app must be stopped first) and repeated; the R-489 cause was then isolated in a third pass (`19-R489-cause.txt`). ## Teardown (three layers) Machine: the opengist throwaway removed with data and backups, no volume and no unit left; the scratch guest 9202 persists on purpose with filebrowser + traefik + the controller. Host: nothing changed. Hub: floor raised to 0.242.0 (that is the delivery), nothing else touched.