docs: R-691 (2) built (07 §6.5), R-701 (a) measured, R-702 claper default admin, R-703 calcom OOM; evidence
gates / gates (push) Successful in 25s

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
This commit is contained in:
2026-09-28 10:37:42 +02:00
parent 03df4c8220
commit a8f790c0c6
39 changed files with 4023 additions and 4 deletions
@@ -562,7 +562,7 @@ anything is stopped, logged, and reported once as `backup_tier_skipped`; `unknow
**What it is.** "Remove the app, keep my data" leaves the app's drive folder (`<drive>/appdata/<app>`, or the folder
its definition binds through `${HDD_PATH}`) in place. A reinstall over it no longer runs silently into the old files
(R-657): the install asks „A megőrzött adataimat használom" / "Use my kept data" (the database from the newest copy of
THIS drive's install — the app's own unit or the second-drive mirror — loaded under the kept files, then the
THIS drive's install — the app's own unit, the second-drive mirror or (since v0.277.0) the off-site copy — loaded under the kept files, then the
template's `after_load:`, e.g. nextcloud's `occ files:scan --all`) or „Tiszta lappal kezdem" / "Start fresh".
**Where it lives.** "Start fresh" RENAMES the folder — same drive, never a copy, never across drives — to
@@ -570,6 +570,15 @@ template's `after_load:`, e.g. nextcloud's `occ files:scan --all`) or „Tiszta
Load has its database). `<drive>/kept` is in `ProtectedHDDPaths`, never under `userdata/`, never bound by a live app.
The page „Megőrzött adatok" / "Kept data" lists every dated folder and every `appdata/<x>` no installed app binds.
**The off-site copy counts too (controller v0.277.0, R-691 (2)).** „Use my kept data" and Load consider the app's
newest OFF-SITE snapshot beside the local copies, and use it when it is NEWER than every local copy or the only one (a tie
goes local). The page names the copy and its date („távoli mentés, 2026-09-28 04:15" / "the off-site copy, …"). The
repository is asked once per page, bounded to 20 s; an unreachable one offers nothing. The load downloads the unit ALONE
(never the files — they are the kept ones), and refuses it before anything moves when it was taken of another drive,
holds no database, or **does not record its data version** (§6.6 — a unit written before v0.275.0 is never loaded blind);
a mixed or mismatched unit is refused by §6.6's own rule. Then a dated folder's files move back and the one unit restore
runs. The downloaded copy is removed on every path. A failed download or a refusal leaves the kept files as they were.
**It is NOT backed up.** No tier captures `<drive>/kept` or a leftover `appdata/<x>` of a removed app; the page says
so („Erről nem készül mentés." / "This is not backed up."). What brings it back into an app is the unit it carries
(or the app's own unit on the drive), listed per row as „Visszatölthető innen" / "Can be loaded from".