# REPORT — controller v0.273.0 + v0.274.0 (2026-09-25) Two releases in one session, as the brief allowed: **v0.273.0** (`5a731b4`) — the PostgreSQL major conversion (`09` §3 decisions 35, 37, 38; §6.4 part 10) + R-687's two small items; **v0.274.0** (`64cbefe`) — kept data (decision 36) + R-690 + R-692. Floor 0.273.0 then 0.274.0, MinAgent 0.131.0 declared both times, read back from the hub; both demo boxes arrived healthy within ~25 s each time. CI: `5a731b4` job 1002 success. **The conversion** (`internal/stacks/pgconvert.go`): only on a ladder step marked `engine_conversion`; a PostgreSQL major move without the mark is refused by the preflight and the job. Phase `converting` after the undo copy: old engine alone → check (owners, encodings, roles, extensions, per-table row counts) → `pg_dumpall` with its completion line → the volume emptied only after the copy's marker is validated again → new engine alone → entrypoint databases dropped, existing roles' `CREATE ROLE` skipped → load with `ON_ERROR_STOP` → check equal + `PG_VERSION`. Any failure, and a restart during `converting`, runs the existing undo. The old datadir's copy stays until a backup is proven after the conversion (hourly `conversion-copy-release`). **Live on 9202** (`0.273.0-rc1`, drill catalog): docmost 16 → 18 done in 42 s (9.9 s of engine work, 48 tables / 71 rows equal); the load failing (`adminpack`, gone in 17+) → undone in 43.6 s; the app unhealthy on 18 → undone in 148 s; SIGKILL one second after the volume was emptied → the restart undid it in 40 s; each ending on 16 with the seed read back. Found live and fixed: the recovery line said UNDOING for a restart during `converting`. **Red-proofs:** 9 (conversion) + 2 (R-687) + 1 (R-692) here; the Part E build carries 10 more (`felhom.eu/documentation/audits/night-2026-09-26/E/redproofs/`). **Kept data** (`internal/stacks/kept.go`, `internal/web/kept_handlers.go`, `internal/api/kept_install.go`): built by a parallel helper session in its own worktree, reviewed and proven here. The install over a non-empty drive folder answers 409 `kept_data_choice` until „use my kept data" / „start fresh" is chosen; the „Megőrzött adatok" / "Kept data" page lists, loads, deletes (typed); a read-only file-browser source; `/kept` protected and never backed up; the drive-full warning names kept folders. **R-692 found live** (the list named leftovers „Filebrowser") and fixed before the release. **Live on 9202** (endpoint level, both languages): the whole E5 walk passed — see `felhom.eu/documentation/audits/night-2026-09-26/E/E5-*`. **Not done:** R-691 (a 0770 folder is not readable in the view; "use" does not look off-site); R-694 (what the page shows after a load regenerates a withheld login secret) — measure first. Full session record: `felhom.eu/documentation/audits/DRILL-night-2026-09-26.md`.