version-travel: session record, evidence B/C/D/R, 09 decision 42, 07 §6.5 decision, register 339 -> 336, STATUS (D4)
gates / gates (push) Successful in 26s
gates / gates (push) Successful in 26s
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
This commit is contained in:
@@ -580,7 +580,20 @@ is not a listed item, is refused — proven live 2026-09-25). **The box never de
|
||||
|
||||
**Read-only view.** The file browser shows each kept item under „Megőrzött adatok", one `:ro` bind per item, and
|
||||
follows the list at the next sync (a write is refused: `Read-only file system`, proven live). Not yet readable there:
|
||||
a folder its app owns with mode 0770 (nextcloud, `www-data`) — R-691.
|
||||
a folder its app owns with mode 0770 (nextcloud, `www-data`) — R-691 — **until controller v0.275.0.**
|
||||
|
||||
**[DESIGN] How the view reads a folder another user owns** — *decided by CC unattended 2026-09-26 — operator may
|
||||
reverse.* *One sentence:* how does the read-only view open a 0770 kept folder owned by another user without touching
|
||||
the household's files? **Options:** (a) a read-only ACL on the folder; (b) run the file browser as root; (c) a second
|
||||
viewer container running as the owner; (d) the file browser joins the folder's OWNING GROUP (`group_add`).
|
||||
**Costs:** (a) changes the household's files' metadata — nextcloud checks its data folder's mode after a Load, and
|
||||
the brief forbids it; (b) the whole file browser (read-write on the household's userdata) as root; (c) a new container,
|
||||
route and login for one view; (d) the group also applies to the view's other mounts — so root's group (0) and the
|
||||
view's own (1000) are never added, and only a group-READABLE folder's group is. **Why (d):** the kept binds stay
|
||||
`:ro` (a write is refused by the mount), nothing on disk changes, and it is one compose line the sync already writes.
|
||||
Limit: a file inside that is owner-only (0600) stays unreadable. Also: a language switch now re-syncs the file browser
|
||||
so the source's name („Megőrzött adatok" / "Kept data") follows the box's language. Controller v0.275.0,
|
||||
`audits/version-travel-2026-09-26/D3/`.
|
||||
|
||||
Evidence: `audits/night-2026-09-26/E/` (E1 spike, E5 live proof).
|
||||
|
||||
|
||||
@@ -466,6 +466,18 @@ R-636's louder repeated alarm.
|
||||
without world data is a smaller product; the internet dependence is at first start, which the update's own
|
||||
health wait and undo already cover.
|
||||
|
||||
### 2026-09-26/27 — decisions taken by CC unattended (version-travel brief)
|
||||
|
||||
42. **The next PostgreSQL apps: paperless-ngx → 18, tandoor → 17** — *decided by CC unattended 2026-09-27 — operator
|
||||
may reverse.* *One sentence:* which major does each app's conversion target? **Options:** (a) 17 for both — no
|
||||
mount change; (b) 18 for both; (c) per app, from what the app's own upstream runs (decision 37's reasoning).
|
||||
**Costs:** (a) paperless converts twice (its upstream compose ships `postgres:18` at `/var/lib/postgresql`);
|
||||
(b) tandoor would run a major its own upstream compose (`postgres:16-alpine`) and its Django (5.2.16) have not
|
||||
documented; (c) two different targets to remember. **Why (c):** decision 37 said one conversion is better than
|
||||
two WHEN the upstream runs the newer major — paperless's does (18, Django ~5.2.5, psycopg 3); tandoor's does not,
|
||||
and 17 is the newest major its Django documents, with no mount change. Read 2026-09-27 from each upstream's
|
||||
compose and requirements (`audits/version-travel-2026-09-26/B/`). Reversible: the catalog pins the major.
|
||||
|
||||
---
|
||||
|
||||
## 3b. ANSWERED 2026-09-23 — the seven questions Slices 6 and 7 needed
|
||||
|
||||
Reference in New Issue
Block a user