my_backup: full Utility-Reliability-Standards compliance audit
Section titled “my_backup: full Utility-Reliability-Standards compliance audit”Trigger: Spun off from my_backup-more-critical-issues — Talbot confirmed the remaining Utility-Reliability-Standards.md items are “warranted — need world-class robustness.” my_backup is the reference implementation the standard was derived from, so a shallow pass wasn’t acceptable; every item was verified against real code and real runs, not assumed.
Findings and fixes
Section titled “Findings and fixes”7 real gaps found and fixed; 2 items confirmed already compliant.
-
Structured Logging —
backup.loghadbackup_count: 3(spec = 5, bumped).virus_scan.log/system_image.log/check_backups.logwere rawprint()redirected by cron shell — no timestamps, levels, or rotation, unbounded growth. Converted all 3 toutils.setup_logging(same patternpipeline.pyuses). Verified live: rancheck_backupsandcreate_system_image --dry-run, confirmed[TS] LEVEL msg+RUN STARTED/RESULTformat. -
Alerts on Failure — PASS, no change.
notify_managertiering (email+Telegram on CRITICAL) confirmed working via a livecheck_backupsrun (email delivered). Subject format differs cosmetically from the spec’s literal template but conveys severity correctly — editing the sharednotify_managerdependency for a cosmetic match would ripple into every other utility for no functional gain. -
Weekly Status Report —
send_status_report.pyonly parsedbackup.log. Generalized to loop over all 4 utility logs, roll up worst status into one subject (Calm/Loud/Critical). Verified against real log data: correctly reported mixed per-utility statuses in one summary. -
Independent Verification — already done in the parent task (
check_backups.pyscheduled + job_monitor-registered). -
Dry-Run Mode — most significant finding —
--dry-runsetctx.config['dry_run'] = Trueand logged a warning banner, but no call site intasks.pyever read the flag. Every kopia snapshot/policy/maintenance command, robocopy/rclone mirror, and 7z archive operation ran for real regardless of--dry-run. The flag had existed long enough to be trusted without ever being verified end-to-end. Addedctx.dry_runproperty, gated every mutating call site (pre-hooks, file syncs, kopia policy/snapshot/maintenance, robocopy/rclone mirrors, 7z create/verify/cleanup/upload). Verified with a fulluv run my_backup --dry-runrun — every mutating step logged[DRY RUN] Would..., nothing executed. -
Test Suite —
tests/test_backups.pyhas real 20-check coverage (incl. a restore test) but wasn’t pytest-discoverable —uv run pytest tests/silently collected 0 tests. Deeper cause: pytest was never declared as a project dependency, souv run pytestwas falling through to a global pytest on~/.local/binPATH. Addedpytestviauv add --dev, addedtests/test_pytest_wrapper.py(reflects overBackupTests.test_*, auto-syncs with future checks). Verified: 18 real checks now collected, 10 passed / 8 failed (failures are genuine — this WSL sandbox has no Windows/D: drive to test against, not a bug). -
Config as SSOT —
update_static_zips.pyanddebug_kopia.pyhardcoded Windows paths. Addedstatic_zips:config block; both scripts now load fromconfig.yaml. Verified loaded values match andgrepfor hardcoded paths is clean. -
Graceful Failure — PASS, no change. Confirmed each
tasks.pyfunction catches its own errors intoctx.failures/ctx.warningsindependently; the pipeline’s outer try/except is only a last-resort catch for truly uncaught exceptions. Tri-state SUCCESS/WARNING/FAILED confirmed correct, not accidental. -
Human Escalation Thresholds — nothing existed. Added
escalation_thresholds:toconfig.yaml(snapshot_size_drop_pct: 15,zero_byte_snapshot: true). Extendedcheck_backups.py::check_snapshots()to compare latest vs previous snapshot size (rootEntry.summ.size— already present in the JSON it was querying but discarding) and fire CRITICAL on breach. Verified with monkeypatched kopia output: 50% drop and 0-byte both correctly fired, a 5% drop correctly did not. -
Annual Fire Drill —
manual_reminders.start_of_yearwas a generic yearly checklist with no actual recovery-path test. Added an explicit fire-drill task naming the realkopia snapshot restorecommand plus spot-check and cleanup steps. Verified rendered output viasend_manual_reminders.tasks_to_markdown().
Commit: my_backup 633383b (14 files changed).
Lessons captured
Section titled “Lessons captured”2 lessons added to my_backup/LESSONS.md:
- A CLI flag that sets a config value proves nothing about whether anything reads it — verify the read side, not just the write side.
- A passing
uv run pytestcan mean “0 tests found,” not “tests passed” — check the collected count, and confirm the test runner itself is actually a declared project dependency.