Correct remote layout and privacy docs for hashed snapshot keys (closes #67)
The remote layout and threat model in three documents described plaintext snapshot IDs as directory names and misattributed the observable backup time to those IDs. In fact `RemoteSnapshotKey` names each metadata directory (and the manifest `snapshot_id`) with a one-way double SHA-256 hash of the human ID, so hostname and snapshot name are not observable; the backup time is, via the plaintext manifest timestamp, an accepted design property (issue 81). Document the derivation once in `docs/REPOSTRUCTURE.md` with a worked example; README, ARCHITECTURE and DATAMODEL now show the hashed layout and link to it. Rewrite the privacy section to state what the unencrypted manifest really exposes. Fix two code comments that claimed the public bytes hide the timestamp. Docs and comments only; no behaviour change. Model: opus-4-8
This commit is contained in:
+7
-1
@@ -366,11 +366,17 @@ bucket/
|
||||
│ └── {full-hash} # Compressed+encrypted blob
|
||||
│
|
||||
└── metadata/
|
||||
└── {snapshot-id}/
|
||||
└── {remote-key}/
|
||||
├── db.zst.age # Encrypted binary SQLite database
|
||||
└── manifest.json.zst # Blob list (for pruning/verification)
|
||||
```
|
||||
|
||||
The `{remote-key}` directory name is a one-way double SHA-256 hash of the human
|
||||
snapshot ID, so the human ID (hostname, snapshot name, timestamp) is never
|
||||
written to the store as a directory name. See
|
||||
[docs/REPOSTRUCTURE.md](docs/REPOSTRUCTURE.md#remote-key-derivation) for the
|
||||
derivation and a worked example.
|
||||
|
||||
## Thread Safety
|
||||
|
||||
- `Packer`: Thread-safe via mutex. Multiple goroutines can call `AddChunk()`.
|
||||
|
||||
Reference in New Issue
Block a user