version-travel: session record, evidence B/C/D/R, 09 decision 42, 07 §6.5 decision, register 339 -> 336, STATUS (D4)
gates / gates (push) Successful in 26s

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
This commit is contained in:
2026-09-27 13:02:33 +02:00
parent bff98a81a2
commit 7696836f84
85 changed files with 10970 additions and 48 deletions
+25 -26
View File
@@ -1,38 +1,37 @@
# STATUS — what works, what's broken, what's next
**Updated 2026-09-26 (early morning). Both demo boxes run controller 0.274.0 and host agent 0.134.0. Hub 0.125.0.**
**Updated 2026-09-27. Both demo boxes run controller 0.275.0 and host agent 0.135.0. Hub 0.125.0.**
**Decisions I took on my own** (you may reverse each):
1. **docmost's database goes to PostgreSQL 18, not 17.** Its own makers already use 18. One move instead of two.
2. **The box copies the whole old database before it converts, and stops on any error.** It then puts everything back.
3. **docmost gets 512 MB of memory instead of 384 MB.** Under light load it used 91 % of 384 MB. The move was not allowed without it.
1. **paperless-ngx goes to PostgreSQL 18, tandoor to 17.** Each follows what its own makers ship. paperless's makers use 18. tandoor's use 16, and 17 is the newest its framework supports.
2. **The file browser reads nextcloud's kept folder by joining its group.** Nothing on your disk changes. The folder stays read-only in the view.
**What I did, and it worked.**
- **The box now converts a PostgreSQL database to a new main version.** Only for an app whose step was tested. docmost is the first. On the scratch box: the conversion took 42 seconds in total. The data came back.
- **When it goes wrong, the box puts the old version back.** I tested three failures: a load error, an app that does not start, and a controller killed in the middle. Each time the old version came back with its data.
- **The HP box converted its docmost by itself in the night.** It took 54 seconds. Its users, spaces and pages are all still there.
- **Kept data is never a dead end now.** When an app is installed over old files, the page asks: "Use my kept data" or "Start fresh". A new "Kept data" page shows every leftover folder. The household can look at it (read only), load it, or delete it (they must type the app's name). I tested all of it on the scratch box, in both languages.
- **The hub's customer delete stops promising to clean Cloudflare.** It now lists what you remove by hand.
- **A backup now always says truthfully which version its data belongs to.** Before, the label changed to "new version" minutes after an update, while the data inside stayed old. A restore in that window broke docmost: its database would not start. Now the backup keeps the old version's settings next to the old data. I tested it on the scratch box: docmost came back whole at the old version, and the normal update brought it forward again.
- **The box tested this by itself in the night.** It updated docmost's database at 02:15. Two minutes later the backup kept the matching old settings. The restore the next morning worked.
- **Two more apps move to a new database version: paperless-ngx and tandoor.** Each was tested twice: on a throwaway test machine and on the scratch box through the normal update. Every account came back.
- **adventurelog moves to its new version.** It keeps its world-map download. If that file was cut off, the box sets it aside and downloads it again. Tested both ways.
- **The HP box's restore test now tests real backups only**, not the golden template file.
- **Small fixes:** the file browser no longer re-creates an empty kept folder; the "Kept data" name follows the box's language; after a load, the app page no longer shows a password that does not work.
**What broke, or is not done.**
- **The restore of a removed app was broken for data drives.** It came back without its settings or database. Fixed tonight.
- **The Kept data list named two old folders "Filebrowser".** Found on the scratch box. Fixed before release.
- **The other ten PostgreSQL apps still cannot move.** Each needs its own test.
- **The file browser cannot open nextcloud's kept folder.** The files are there and can be loaded or deleted.
- **The HP box's restore test tries to test the golden template file and fails every 6 hours.** Not fixed (agent side).
- **The memory check always calls docmost "tight".** Its memory grows with its limit. Filed.
- **The box threw away docmost's old database copy too early on the HP box.** It trusted the wrong time for "a backup exists". The data is safe: the check proved every row came across, and tonight's backup is on the new version. Filed.
- **Two quick deletes on the Kept data page can leave an empty folder that keeps coming back.** Seen once on the scratch box; no data involved. Cleared by hand. Filed.
- **adventurelog stays on its old version.** I found how to skip its internet download. The move needs a choice.
- **Found and fixed today: an app installed minutes ago could be updated with no backup of its database.** The update trusted a backup that held only the app's settings. Now it backs up first.
- **"Use my kept data" still cannot load from the off-site copy.** Filed.
- **The file-browser group fix is tested in code only.** No nextcloud kept folder existed on the scratch box.
- **A backup stores the name of each app version, not the app itself.** If a maker deletes an old version, a restore of it cannot start. Today all 42 versions the catalog names still exist. Filed with options; nothing decided.
- **After a restore, the box keeps an old database copy it can no longer release.** Disk only. Filed.
- **Not watched yet:** the HP box converts paperless tonight; the scratch box releases its old paperless copy after tonight's backup.
**Rows.** 8 opened, 3 closed. The list went from 334 to 339.
**Rows.** 3 opened, 6 closed. The list went from 339 to 336.
**Decision for you — D3: may the box ever delete kept data by itself?**
- **A — never; only the household deletes it (I recommend this).** Cost: kept data can fill a drive. The drive-full warning names the kept folders and their sizes, so the household sees what to delete.
- **B — after 90 days, with mails at 30 and 7 days before.** Cost: a small add-on to build; a household that ignores the mails loses the data.
- **If you do nothing:** nothing is ever deleted by itself (A in effect). Nobody is blocked.
**Decision for you — D4: when the only backup holds data of an older app version, what does a restore bring back?**
- **A — the older version with its own data; then the normal update climbs, one tested step at a time (I recommend this, and it is built).** Cost: after the restore the app runs an older version for a night or until someone presses Update. The page says so.
- **B — restore into a temporary copy, update it there, then move the data in.** Cost: a new mechanism on customer data, and double the disk space during the restore. Same end state as A.
- **If you do nothing:** A stays in force. Nobody is blocked.
**What needs you.**
1. **D3** above.
2. **adventurelog:** skip its world-data download on every start (new installs then have no country list), or keep it and test the update with the file present. If you do nothing, it stays on the old version.
3. **From before:** Peti's box in the Claude project text; Cloudflare leftovers of Peti's domain; the old Storage Box `PBS-storage-1`. If you do nothing, they stay as they are.
1. **D4** above.
2. **The weekly golden bake is due** (last one a week ago, 21 controller releases behind). The brief said no golden, so I renewed the waiver for 7 days only (to 4 October). If you do nothing, the checks go red again on 4 October and nothing can be pushed to felhom.eu until a bake or a new waiver.
3. **Vouch agent 0.135.0** for new installs (hub → Configs → Day-0 artifacts). If you do nothing, new boxes install 0.134.0 and get 0.135.0 only by a signed update.
4. **The image-copy question** (a maker deletes an old version): keep as is, or copy installed versions into our registry. If you do nothing, nothing changes.
5. **From before:** Peti's box in the Claude project text; Cloudflare leftovers of Peti's domain; the old Storage Box `PBS-storage-1`. If you do nothing, they stay as they are.