hub v0.122.0: app_hold_no_whole_copy — allow-listed, operator-only, per-app cooldown (R-659)
gates / gates (push) Successful in 28s

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
This commit is contained in:
2026-09-24 07:33:04 +02:00
parent 3e58c184f6
commit e4d45a8f72
5 changed files with 42 additions and 2 deletions
+9
View File
@@ -395,6 +395,9 @@ var perAppCooldownEvents = map[string]bool{
// v0.121.0 (R-636): a storm is one app's event with no digest behind it — two apps storming on one
// night are two alarms. (The controller already sends it at most once per container run.)
"app_oom_storm": true,
// v0.122.0 (R-659): a held app with no whole copy on its box is one app's event with no digest —
// two apps stranded on one night are two alarms, and the second must not be swallowed.
"app_hold_no_whole_copy": true,
}
// perAppCustomerCooldownEvents is the CUSTOMER-leg sibling of perAppCooldownEvents (v0.120.0). The
@@ -659,6 +662,12 @@ var operatorOnlyEvents = map[string]bool{
// OOM-killed 20+ times in 30 minutes. Same audience, same reason — raw container names and memory
// figures; the household's side is the dashboard. Registered in the same commit that mints it.
"app_oom_storm": true,
// R-659 (v0.122.0, controller v0.268.0; operator ruling 2026-09-24, `09` §3 decision 25). A held app
// whose box holds no copy that brings it back WHOLE. The household is told by its own
// `app_update_held` mail, in its language, that support is informed; THIS is that information —
// operator-grade (the copies seen, per tier, with dates), and the act it calls for is support's.
// Registered in the same commit that mints it.
"app_hold_no_whole_copy": true,
}
// IsOperatorOnly reports whether an event type is barred from customer dispatch. Exported so the