docs: 07 kept data; register (R-657, R-690, R-692 closed; R-450/463/687/688/691 narrowed; R-693, R-694 opened); night-2026-09-26 evidence (part0, C, D, E, F)
gates / gates (push) Successful in 27s
gates / gates (push) Successful in 27s
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
This commit is contained in:
@@ -557,6 +557,34 @@ successes only. After an agent restart the success is read back from the tier's
|
||||
anything is stopped, logged, and reported once as `backup_tier_skipped`; `unknown` is never skipped.
|
||||
**Still open:** quiescing per tier, so a slow second tier does not keep every app down.
|
||||
|
||||
### 6.5 Kept data — what a removed app leaves on the drive (controller v0.274.0, `09` §3 decision 36)
|
||||
|
||||
**What it is.** "Remove the app, keep my data" leaves the app's drive folder (`<drive>/appdata/<app>`, or the folder
|
||||
its definition binds through `${HDD_PATH}`) in place. A reinstall over it no longer runs silently into the old files
|
||||
(R-657): the install asks „A megőrzött adataimat használom" / "Use my kept data" (the database from the newest copy of
|
||||
THIS drive's install — the app's own unit or the second-drive mirror — loaded under the kept files, then the
|
||||
template's `after_load:`, e.g. nextcloud's `occ files:scan --all`) or „Tiszta lappal kezdem" / "Start fresh".
|
||||
|
||||
**Where it lives.** "Start fresh" RENAMES the folder — same drive, never a copy, never across drives — to
|
||||
`<drive>/kept/<app>/<YYYY-MM-DD_HHMMSS>/`, together with the removed app's unit when one sits on that drive (so a later
|
||||
Load has its database). `<drive>/kept` is in `ProtectedHDDPaths`, never under `userdata/`, never bound by a live app.
|
||||
The page „Megőrzött adatok" / "Kept data" lists every dated folder and every `appdata/<x>` no installed app binds.
|
||||
|
||||
**It is NOT backed up.** No tier captures `<drive>/kept` or a leftover `appdata/<x>` of a removed app; the page says
|
||||
so („Erről nem készül mentés." / "This is not backed up."). What brings it back into an app is the unit it carries
|
||||
(or the app's own unit on the drive), listed per row as „Visszatölthető innen" / "Can be loaded from".
|
||||
|
||||
**Who deletes it.** Only the household, by Delete on that page with the app's name typed (a wrong name, or a path that
|
||||
is not a listed item, is refused — proven live 2026-09-25). **The box never deletes kept data by itself** — whether it
|
||||
ever should (e.g. after 90 days with warnings) is operator decision **D3, open** (`STATUS.md`). Until then kept data
|
||||
can fill a drive; the drive-full warning names the kept folders and their sizes as space the household can free.
|
||||
|
||||
**Read-only view.** The file browser shows each kept item under „Megőrzött adatok", one `:ro` bind per item, and
|
||||
follows the list at the next sync (a write is refused: `Read-only file system`, proven live). Not yet readable there:
|
||||
a folder its app owns with mode 0770 (nextcloud, `www-data`) — R-691.
|
||||
|
||||
Evidence: `audits/night-2026-09-26/E/` (E1 spike, E5 live proof).
|
||||
|
||||
## 7. The recovery chain (D3) — the reason this document exists
|
||||
|
||||
**[DESIGN] 3-2-1 describes copies. It does not describe recovery.**
|
||||
|
||||
Reference in New Issue
Block a user