A volume recreated by a unit restore carries no compose label, so the before/after difference misses it; proven on the scratch guest. Docs only, no release. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
3.7 KiB
REPORT — controller v0.242.0: a removed app is listed with its kept backup, and five small ones (2026-09-13 night)
Overwritten each run. This records the most recent implementation only.
Nightly session under
.claude/rules/unprompted-work.md. Architecture read and named:felhom.eu/documentation/architecture/07-backup-architecture.md(§6.3 restore destination, the R-237 store-keyed list rule) and09-update-architecture.md(holds). Shipped as v0.242.0 (d698ce3), delivered by the managed floor with the declared MinAgent 0.129.0: demo-hp +16 s, demo-felhom +17 s; hand-set on the scratch guest 9202 (the one place that is allowed). Evidence:felhom.eu/documentation/audits/v0242-2026-09-14/.
What changed
- R-487 (P2) —
backup.ListRemovedAppUnitswalksbackups/primary/on the system path and every connected registered drive and returns the units whose app is not deployed. The Mentések page lists them after the deployed rows („Eltávolítva — visszaállítható", one action: Visszaállítás a mentésből =POST /backup/restore), the Visszaállítás picker lists them in their own group,GET /api/backup/snapshotsanswers for them, andRestoreFromRecoveryUnitopens the unit where it sits (primaryUnitDirFor) — a unit kept on a data drive was unreachable before. The claim text is registered with the retrieval-promise gate as conditional on the readable unit. - R-491 (P2) —
removeStackclears an UPDATE hold (Settings.ClearUpdateHold), never an R-379 restore hold. Logged. - R-490 —
/api/system/infomounted exactly ahead of the web layer's/api/system/prefix;systemInforeads the default storage path like every other reader of the empty global. Nil-safe on the syncer. The global's deletion is R-492. - R-489 —
volumes_removedis the before/after difference of the project's volumes,[]when none. Measured limit, row kept open: the listing filters on the compose project label and a volume recreated by a unit restore (docker volume create) carries none — compose removes it, the response says[]. A fresh compose volume is reported. - R-476 —
Tier2Coverage.UnitDataDate: a refreshed leg is dated by its newest dump, a preserved package keeps the manifest date (R-403). - R-456 — the boot-orphan rule pinned by a test; design unchanged.
Proof
- Red-proofs (each a compiling mutation that made its test fail, restored byte-identical):
rp-v242-*.txt— R-487 ×6 (lister inert, picker 404, wrong unit dir, row not built, row not rendered, picker not rendered), R-491, R-490 ×2, R-489, R-476. - Full gate green before the build (
go build/vet/test ./...,controller_gates.py --fast). - Live on 9202 (endpoint-level, the exact endpoints the UI invokes; no browser on DooPlex): an
opengist throwaway —
GET /api/system/info200 with the drive figures; a seeded update hold cleared by the removal (log line + store), the app redeployed by the restore without refusal; the removed app's row, badge, form, picker option and snapshot API all present, „Visszaállítás a mentésből" reinstalled it running in 9.1 s; two captures under one definition dated the Tier-2 confirm by the second capture's dump (22:58 against a manifest from 22:52). First pass was refused 409 (a running app must be stopped first) and repeated; the R-489 cause was then isolated in a third pass (19-R489-cause.txt).
Teardown (three layers)
Machine: the opengist throwaway removed with data and backups, no volume and no unit left; the scratch guest 9202 persists on purpose with filebrowser + traefik + the controller. Host: nothing changed. Hub: floor raised to 0.242.0 (that is the delivery), nothing else touched.