Found live on 9202: the product pins tag@digest, and such images are stored untagged (repo:<none>); `docker image ls` without -a did not list them, so the retention saw almost no app image. Now `image ls -a`; an anonymous <none>:<none> entry is never a candidate; the one-time marker is v2 so the corrected sweep runs once everywhere. Test TestImageRetention_SeesUntaggedDigestPulledImages, red-proofed. 0.284.0/0.284.1 were never floored. MinAgent: 0.131.0 (unchanged). Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
1.4 KiB
REPORT — v0.284.0 + v0.284.1 + v0.284.2 (2026-09-30 late evening)
-
v0.284.2: the retention lists images with
-a— digest-pulled app images are untagged and were invisible (found live on 9202); markerimage-retention-v2.done. 0.284.0/0.284.1 were never floored. -
v0.284.1: the remove half of decision 53 wired into
RemoveStack(the household's Remove button — v0.284.0 wired onlyDeleteStack, found live on 9202); one summary line per retention pass. v0.284.0 was never floored (9202 only). -
Image retention (
09§3 decision 53, R-736): after a done/undone guarded Update and at remove, an app's older images are deleted; the box-wide keep set (containers, installed composes, installed/previous records) is read at delete time; exact id, never forced/pruned; paused while any update runs; a one-time sweep 3 min after start. -
Install hold (R-741): an
after_installapp is held behind the setup gate's door from its first start until the known login is replaced (after_install, or the household's "I changed it"). -
Tests:
TestImageRetention_*(6),TestInstallHold_*(6), parity fixtureapp_info_install_hold; red-proofs infelhom.eu/documentation/audits/night-rulings-2026-09-30/{B,C}/. Green gate: build, vet, test ./... rc=0. -
Evidence and the live proofs:
felhom.eu/documentation/audits/night-rulings-2026-09-30/.