# STATUS — what works, what's broken, what's next **Updated 2026-09-22 (late) — I fixed the six faults the two drill nights found in the update, delete and hold machinery, and shipped the six app versions you approved. One thing needs your word: whether the fleet moves to the new controller.** **Decisions I took on my own: none.** **The one that mattered most is fixed and proven.** An app with no health check used to be **shut down by a successful update** — the machine waited five minutes for a check that could never arrive, then stopped a working app. Paperless-ngx, same app, same button: **before, it failed after 5 minutes and the app went dark. Now it finishes in 53 seconds and keeps running.** **Five more, all proven on the test machine.** - **Deleting an app while it is being backed up or restored is now refused**, with a plain sentence telling you to wait — instead of quietly tearing it down and leaving a ghost behind. - **A delete now checks its own work.** The machine watches for 25 seconds afterwards and removes anything that comes back, and says whether it verified. - **An app the machine has lost track of can now be deleted.** Before, if its record went wrong, no button worked and only a command line could clear it. - **A failed update now keeps the app's own log** before shutting it down. Twice we lost the only evidence of why. - **Deleting an app clears its old update status**, so a fresh install of the same app no longer shows a stale "Updated". **The six versions you approved are live on the catalogue** — Emby, Ghost, Immich, Radarr, Sonarr, Termix. **None of them is installed on either demo machine**, so nothing updated; they simply show as available. **What I did not do, and it is on purpose.** Two items from the plan are untouched and named rather than half-finished: finding out *why* an app's record goes wrong in the first place (I fixed the consequence, not the cause), and making a held app stop offering an Update button it will refuse. **What went wrong on my side.** I lost **44 minutes** to my own progress-watchers: they waited for a build that had already succeeded, because each was watching for a name its own command contained. The same bug cost me a pile of stuck watchers earlier in the day. It is now written down as a rule so it does not happen a third time. I also nearly recorded one test as passing when it had proved nothing — the refusal I saw came from an older rule, not the new one. I caught it and re-ran it properly. **Rows opened and closed.** Four closed, one narrowed to what is still unknown. The list stands at 325. **The fleet is on the new controller — you said yes and it is done.** I raised the floor to **0.262.1** with the required agent version declared alongside it. **Both demo machines picked it up in under twenty seconds** and are running healthy. The drill machine is switched off and is **held back on purpose**: its helper software is older than the new controller needs, so the machine refuses to give it a version it cannot run. That is the guard working, not a failure. Peti's machine is parked and would take it only if it ever comes back online. **What needs you: nothing.** **Nothing on your own machine or the off-site box was touched. The demo machines were not touched — they only see the six new version badges.**