docs: 07 kept data; register (R-657, R-690, R-692 closed; R-450/463/687/688/691 narrowed; R-693, R-694 opened); night-2026-09-26 evidence (part0, C, D, E, F)
gates / gates (push) Successful in 27s

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
This commit is contained in:
2026-09-25 14:35:15 +02:00
parent f12f8609fc
commit 302f24e47c
70 changed files with 5572 additions and 6 deletions
@@ -557,6 +557,34 @@ successes only. After an agent restart the success is read back from the tier's
anything is stopped, logged, and reported once as `backup_tier_skipped`; `unknown` is never skipped.
**Still open:** quiescing per tier, so a slow second tier does not keep every app down.
### 6.5 Kept data — what a removed app leaves on the drive (controller v0.274.0, `09` §3 decision 36)
**What it is.** "Remove the app, keep my data" leaves the app's drive folder (`<drive>/appdata/<app>`, or the folder
its definition binds through `${HDD_PATH}`) in place. A reinstall over it no longer runs silently into the old files
(R-657): the install asks „A megőrzött adataimat használom" / "Use my kept data" (the database from the newest copy of
THIS drive's install — the app's own unit or the second-drive mirror — loaded under the kept files, then the
template's `after_load:`, e.g. nextcloud's `occ files:scan --all`) or „Tiszta lappal kezdem" / "Start fresh".
**Where it lives.** "Start fresh" RENAMES the folder — same drive, never a copy, never across drives — to
`<drive>/kept/<app>/<YYYY-MM-DD_HHMMSS>/`, together with the removed app's unit when one sits on that drive (so a later
Load has its database). `<drive>/kept` is in `ProtectedHDDPaths`, never under `userdata/`, never bound by a live app.
The page „Megőrzött adatok" / "Kept data" lists every dated folder and every `appdata/<x>` no installed app binds.
**It is NOT backed up.** No tier captures `<drive>/kept` or a leftover `appdata/<x>` of a removed app; the page says
so („Erről nem készül mentés." / "This is not backed up."). What brings it back into an app is the unit it carries
(or the app's own unit on the drive), listed per row as „Visszatölthető innen" / "Can be loaded from".
**Who deletes it.** Only the household, by Delete on that page with the app's name typed (a wrong name, or a path that
is not a listed item, is refused — proven live 2026-09-25). **The box never deletes kept data by itself** — whether it
ever should (e.g. after 90 days with warnings) is operator decision **D3, open** (`STATUS.md`). Until then kept data
can fill a drive; the drive-full warning names the kept folders and their sizes as space the household can free.
**Read-only view.** The file browser shows each kept item under „Megőrzött adatok", one `:ro` bind per item, and
follows the list at the next sync (a write is refused: `Read-only file system`, proven live). Not yet readable there:
a folder its app owns with mode 0770 (nextcloud, `www-data`) — R-691.
Evidence: `audits/night-2026-09-26/E/` (E1 spike, E5 live proof).
## 7. The recovery chain (D3) — the reason this document exists
**[DESIGN] 3-2-1 describes copies. It does not describe recovery.**