hub v0.140.0: a failed operator mail is retried (1, 5, 15 min); a Docker set needs a passing memory-kill check on every ring-0 box (decision 157)
gates / gates (push) Successful in 2m40s

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
This commit is contained in:
2026-10-06 19:14:00 +02:00
parent 2441c86a89
commit eed1dbd80c
8 changed files with 298 additions and 17 deletions
@@ -327,6 +327,13 @@ message, not a wider cooldown.
---
**A failed operator mail is sent again (hub v0.140.0, 2026-10-06).** Until then an operator mail had ONE try with a 10 s
client timeout; a failure was only a `failed` row in the notification log, and because the cooldown is set before the
send, the next mail for the same alarm was silenced too. Measured: of 692 operator mails since 2026-02-16, ONE failed —
demo-hp's `whole_guest_backup_failed` (error) on 2026-10-05 04:27Z (Resend: *context deadline exceeded*), never sent
(`audits/readback-2026-10-07/C/`). Now it is tried again after 1, 5 and 15 minutes; each try is a row (`sent` „after
retry N" or `failed` „retry N: …"); giving up is an ERROR line. Pinned by TestOperatorMailRetry_*.
## 6.3 Box alarms outside the app ladder: the tunnel and OS updates [DESIGN, hub v0.131.0, 2026-10-04]
These are **operator-only** (the household can act on none of them — except `host_restarted_after_crash`, the household's