# E2/E3 — demo-hp guest 9201, read 2026-09-30T10:49:40Z
# per app: GET /api/stacks/<app> catalog_images + catalog_digests (the ladder's tested digests) vs app.yaml installed_images (what the containers were created from) and whether the RUNNING compose pins name@sha256
adventurelog | catalog carries tested digests: yes
    adventurelog: ghcr.io/seanmorley15/adventurelog-backend:v0.13.0  catalog=0250d9cb0d74  installed=0250d9cb0d74  equal=True  running-compose-pins-digest=True
    adventurelog-frontend: ghcr.io/seanmorley15/adventurelog-frontend:v0.13.0  catalog=51ee22428b41  installed=51ee22428b41  equal=True  running-compose-pins-digest=True
    adventurelog-postgres: postgis/postgis:16-3.5-alpine  catalog=47e961a569fd  installed=47e961a569fd  equal=True  running-compose-pins-digest=True
bentopdf | catalog carries tested digests: NO (no ladder entry)
    bentopdf: ghcr.io/alam00000/bentopdf:v2.8.6  catalog=-  installed=eaeea1e44720  equal=False  running-compose-pins-digest=False
bookstack | catalog carries tested digests: yes
    bookstack: lscr.io/linuxserver/bookstack:26.05.5  catalog=189c79627346  installed=189c79627346  equal=True  running-compose-pins-digest=False
    bookstack-db: mariadb:12.3  catalog=805c8e104bd5  installed=805c8e104bd5  equal=True  running-compose-pins-digest=False
calibre-web | catalog carries tested digests: NO (no ladder entry)
    calibre-web: crocodilestick/calibre-web-automated:v4.0.6  catalog=-  installed=c31a738b6d5e  equal=False  running-compose-pins-digest=False
docmost | catalog carries tested digests: yes
    docmost: docmost/docmost:0.96.0  catalog=b56947fcfd08  installed=b56947fcfd08  equal=True  running-compose-pins-digest=True
    docmost-postgres: postgres:18-alpine  catalog=77f585114c32  installed=77f585114c32  equal=True  running-compose-pins-digest=True
    docmost-redis: redis:7-alpine  catalog=858f009f9709  installed=858f009f9709  equal=True  running-compose-pins-digest=True
kimai | catalog carries tested digests: yes
    kimai: kimai/kimai2:apache-2.57.0  catalog=efa66c5eadf9  installed=efa66c5eadf9  equal=True  running-compose-pins-digest=False
    kimai-db: mariadb:11.8  catalog=79d59758afc9  installed=79d59758afc9  equal=True  running-compose-pins-digest=False
opengist | catalog carries tested digests: yes
    opengist: ghcr.io/thomiceli/opengist:1.15  catalog=7edc91273ee7  installed=7edc91273ee7  equal=True  running-compose-pins-digest=False
paperless-ngx | catalog carries tested digests: yes
    paperless-postgres: postgres:18-alpine  catalog=77f585114c32  installed=77f585114c32  equal=True  running-compose-pins-digest=True
    paperless-redis: redis:7-alpine  catalog=858f009f9709  installed=858f009f9709  equal=True  running-compose-pins-digest=True
    paperless-webserver: ghcr.io/paperless-ngx/paperless-ngx:2.20.15  catalog=6c86cad80397  installed=6c86cad80397  equal=True  running-compose-pins-digest=True
privatebin | catalog carries tested digests: yes
    privatebin: privatebin/pdo:2.0.6  catalog=4c141b2326f8  installed=4c141b2326f8  equal=True  running-compose-pins-digest=False
romm | catalog carries tested digests: yes
    romm: rommapp/romm:5.3.1  catalog=0d66b4ea152a  installed=0d66b4ea152a  equal=True  running-compose-pins-digest=False
    romm-db: mariadb:11.8  catalog=79d59758afc9  installed=79d59758afc9  equal=True  running-compose-pins-digest=False
    romm-redis: redis:7-alpine  catalog=858f009f9709  installed=858f009f9709  equal=True  running-compose-pins-digest=False
TOTAL {"apps": 10, "ladder": 8, "equal": 18, "svc": 20, "compose_digest": 9}

## Reading (2026-09-30, controller main d48da6c)
- R-446 (the badge blind to a moved floating tag): the badge DOES compare digests now — `stacks/updateorder.go:86` `digestBehind`
  reads the ladder's tested digest (`catalog_digests`) against `app.yaml installed_images[svc].digest` and reads Behind only
  for a newer TESTED digest installed before the test. On demo-hp all 18 services of the 8 ladder apps carry both digests
  and all 18 are EQUAL (so their „Naprakész" is true). STILL BLIND: an app with NO ladder entry — here bentopdf and
  calibre-web: the catalog carries no digest, so `digestBehind` returns false by construction (updateorder.go:96).
- R-440 (a floating pin makes an update / a restore irreproducible): a FRESH install or a guarded Update renders
  `name:tag@sha256` from the ladder (`digest.go` RenderWithLadderDigests) — 9 of 20 services on demo-hp run such a
  definition (adventurelog, docmost, paperless-ngx). The other 11 services (bookstack, kimai, opengist, privatebin, romm,
  bentopdf, calibre-web) run a TAG-ONLY definition: installed before v0.269.0 and never updated since, and `CarryDigests`
  (digest.go:141) keeps only a digest the running definition already has — so they stay tag-only until their next guarded
  Update, and a re-pull (a restore) of those takes whatever the tag serves that day. No-ladder apps are always tag-only.
