Load a config that has no age recipient (closes #221)
check / check (push) Successful in 13m36s
check / check (push) Successful in 13m36s
The README's steps for restoring on another machine failed at the first command: `config init` wrote a placeholder recipient, and `config.Load` rejects any recipient that does not parse. `config init` now writes an empty `age_recipients` list, `config.Load` accepts an empty list, and `snapshot create` refuses to start without a recipient. A malformed recipient is still rejected at load. The recovery-host test now builds its config with `config init` and `config set` and reads it through `config.Load`, so it imports `internal/cli`. On a fresh file, `config set age_recipients.0` writes the list in flow style (`[age1...]`). Model: opus-5-5
This commit is contained in:
@@ -42,9 +42,7 @@ const (
|
||||
|
||||
// Sentinel validation errors.
|
||||
var (
|
||||
errNoConfigPath = errors.New("config path not provided")
|
||||
errNoAgeRecipients = errors.New(
|
||||
"at least one age_recipient is required (generate with: age-keygen)")
|
||||
errNoConfigPath = errors.New("config path not provided")
|
||||
errRecipientIsSecretKey = errors.New(
|
||||
"an age secret key was given where a public key (age1...) belongs")
|
||||
errRecipientNotX25519 = errors.New(
|
||||
@@ -323,9 +321,10 @@ func Load(path string) (*Config, error) {
|
||||
|
||||
// Validate checks if the configuration is valid and complete.
|
||||
// It ensures all required fields are present and have valid values:
|
||||
// - At least one age recipient must be specified, and every recipient must
|
||||
// parse as an X25519 age1... public key (so a bad entry fails at load, not
|
||||
// mid-backup); errors name the position, never the value
|
||||
// - Every age recipient must parse as an X25519 age1... public key (so a
|
||||
// bad entry fails at load, not mid-backup); errors name the position,
|
||||
// never the value. An empty list is accepted, because only snapshot
|
||||
// create needs a recipient and it checks for one itself
|
||||
// - At least one snapshot must be configured with at least one path
|
||||
// - Storage must be configured (either storage_url or s3.* fields)
|
||||
// - Chunk size must be at least 1MB
|
||||
@@ -336,10 +335,6 @@ func Load(path string) (*Config, error) {
|
||||
//
|
||||
// Returns an error describing the first validation failure encountered.
|
||||
func (c *Config) Validate() error {
|
||||
if len(c.AgeRecipients) == 0 {
|
||||
return errNoAgeRecipients
|
||||
}
|
||||
|
||||
for i, recipient := range c.AgeRecipients {
|
||||
err := validateAgeRecipient(recipient)
|
||||
if err != nil {
|
||||
|
||||
Reference in New Issue
Block a user