feat(booth): kept boards can be deleted from the UI; document the TTL-reset trap
Kept boards had no delete path in the UI at all. The kept lane deliberately omits the wipe control -- a one-click wipe next to the durable stuff is a footgun -- but "deliberate" had been implemented as "impossible": the only routes out were ssh or a hand-written API call. Now it is two deliberate acts. A `release` control on kept cards drops the sentinel, the board moves to the ephemeral lane, and the existing x wipes it from there. Release is reversible -- POST /b/<name>/keep pins it again. POST /b/<name>/unkeep release the pin POST /b/<name>/keep pin it (round-trip, so release is not a one-way door) FOUND WHILE TESTING, and it invalidates the previously-documented workaround: removing the sentinel BUMPS the booth directory's mtime, and booth age is the newest mtime in the tree -- so a released board's clock RESETS from 10,000s to 0s and it survives another full TTL. The old comment said "remove the sentinel first (it rejoins the sweep)", which is true but means the board lives another 24h, not that it gets reaped. Unkeep-and-wait is a delay, not a delete. test_releasing_a_board_RESETS_its_ttl_clock pins that behaviour deliberately so nobody re-derives the workaround. Release is what unlocks the x; the x is what deletes. CLI: `booth rm` already worked on kept boards but said nothing about it. It now announces "(was KEPT -- durable board)" so wiping something durable can never look identical to wiping run output. Not a block -- a CLI user naming a booth is being explicit. 5 new tests (67 pass). Verified live on nh3-dev: release renders on all four kept boards, the ephemeral lane keeps its x, and the links board is untouched with its sentinel intact.
This commit is contained in:
@@ -679,6 +679,31 @@ def create_app(
|
||||
|
||||
return RedirectResponse(url=f"/b/{quote(booth_id, safe='')}/", status_code=303)
|
||||
|
||||
# Releasing a kept board. The kept lane has no wipe control on purpose —
|
||||
# destroying a durable board should not be one misclick — but "deliberate"
|
||||
# had been built as "impossible from the UI": the only ways out were ssh or
|
||||
# a hand-written API call. These two routes make the release step reachable
|
||||
# while keeping deletion two deliberate acts (release, then wipe).
|
||||
#
|
||||
# NOTE ON THE TTL, which is not intuitive: removing the sentinel BUMPS the
|
||||
# booth directory's mtime, and booth_age_seconds reads the newest mtime in
|
||||
# the tree — so a released board's clock resets to zero and it survives
|
||||
# another full TTL. "Unkeep and let the sweeper take it" therefore does NOT
|
||||
# delete promptly. Release is the step that makes the × available; the ×
|
||||
# is what deletes. Anything relying on release-then-sweep is relying on a
|
||||
# 24h delay it probably did not intend.
|
||||
|
||||
@app.post("/b/{name}/keep")
|
||||
def booth_keep(name: str):
|
||||
(resolve_booth(name) / KEEP_MARKER).touch()
|
||||
return RedirectResponse(url="/", status_code=303)
|
||||
|
||||
@app.post("/b/{name}/unkeep")
|
||||
def booth_unkeep(name: str):
|
||||
# missing_ok: releasing an already-released board is a no-op, not a 500.
|
||||
(resolve_booth(name) / KEEP_MARKER).unlink(missing_ok=True)
|
||||
return RedirectResponse(url="/", status_code=303)
|
||||
|
||||
@app.post("/b/{name}/delete")
|
||||
def booth_delete_form(name: str):
|
||||
shutil.rmtree(resolve_booth(name))
|
||||
|
||||
Reference in New Issue
Block a user