Compare commits

..
1 Commits
Author SHA1 Message Date
sneak e5a13e8fdb Fix two misleading messages (closes #240)
check / check (push) Canceled after 0s
The warning for a config file that others can read always said the
file contained S3 credentials, so a file:// config with none got a
false claim. When s3.access_key_id or s3.secret_access_key is set it
now says the file may contain them, because Load sees the values only
after smartconfig has replaced any ${...} reference, so a set
credential need not be in the file. Otherwise it says the file is
readable by others.

snapshot purge wrapped the listing error, which already starts with
"listing remote snapshots:", in that prefix a second time.
syncWithRemote now returns it unwrapped, as CleanupLocalSnapshots
does.

Model: opus-5-5
2026-10-07 12:22:12 +00:00
3 changed files with 39 additions and 13 deletions
+6 -5
View File
@@ -26,11 +26,12 @@ the tag exists and is exercised; what is left is merging `next` to
([issue #240](https://git.eeqj.de/sneak/vaultik/issues/240)). A config ([issue #240](https://git.eeqj.de/sneak/vaultik/issues/240)). A config
file that others can read was warned about as containing S3 file that others can read was warned about as containing S3
credentials even when it set none, as a `file://` config does. The credentials even when it set none, as a `file://` config does. The
warning now names the credentials only when `s3.access_key_id` or warning now says the file may contain S3 credentials only when
`s3.secret_access_key` is set, and otherwise says the file is readable `s3.access_key_id` or `s3.secret_access_key` is set, since either may
by others. `snapshot purge` against a destination store it could not come from a `${...}` reference rather than the file, and otherwise
list gave an error with `listing remote snapshots:` in it twice; the says the file is readable by others. `snapshot purge` against a
prefix now appears once. destination store it could not list gave an error with
`listing remote snapshots:` in it twice; the prefix now appears once.
- 2026-10-07: Made per-name retention work when the hostname contains `_` - 2026-10-07: Made per-name retention work when the hostname contains `_`
([issue #230](https://git.eeqj.de/sneak/vaultik/issues/230)). A ([issue #230](https://git.eeqj.de/sneak/vaultik/issues/230)). A
+4 -2
View File
@@ -412,10 +412,12 @@ func (c *Config) setAgeSecretKey() {
} }
// readableByOthersWarning is the warning Load logs when others can read // readableByOthersWarning is the warning Load logs when others can read
// the config file. It names the S3 credentials only when they are set. // the config file. It says "may contain" because the S3 credentials are
// seen only after smartconfig has replaced any ${...} reference in the
// file with its value, so a set credential need not be in the file.
func (c *Config) readableByOthersWarning() string { func (c *Config) readableByOthersWarning() string {
if c.S3.AccessKeyID != "" || c.S3.SecretAccessKey != "" { if c.S3.AccessKeyID != "" || c.S3.SecretAccessKey != "" {
return "Config file contains S3 credentials and is readable by others" return "Config file is readable by others and may contain S3 credentials"
} }
return "Config file is readable by others" return "Config file is readable by others"
+29 -6
View File
@@ -423,11 +423,16 @@ snapshots:
} }
// TestLoadWarnsReadableConfigWithS3Credentials checks that a config file // TestLoadWarnsReadableConfigWithS3Credentials checks that a config file
// others can read is warned about as holding the S3 credentials it sets. // others can read and that sets S3 credentials, as values or as ${ENV:...}
// references, is warned about as one that may contain them.
// //
//nolint:paralleltest // loadReadableConfig replaces os.Stderr //nolint:paralleltest // loadReadableConfig replaces os.Stderr
func TestLoadWarnsReadableConfigWithS3Credentials(t *testing.T) { func TestLoadWarnsReadableConfigWithS3Credentials(t *testing.T) {
stderr := loadReadableConfig(t, ` t.Setenv("VAULTIK_TEST_ACCESS_KEY_ID", "test-access-key")
t.Setenv("VAULTIK_TEST_SECRET_ACCESS_KEY", "test-secret-key")
configs := map[string]string{
"values": `
storage_url: s3://bucket/prefix?endpoint=s3.example.com storage_url: s3://bucket/prefix?endpoint=s3.example.com
s3: s3:
access_key_id: test-access-key access_key_id: test-access-key
@@ -436,10 +441,28 @@ snapshots:
home: home:
paths: paths:
- /home - /home
`) `,
"references": `
storage_url: s3://bucket/prefix?endpoint=s3.example.com
s3:
access_key_id: ${ENV:VAULTIK_TEST_ACCESS_KEY_ID}
secret_access_key: ${ENV:VAULTIK_TEST_SECRET_ACCESS_KEY}
snapshots:
home:
paths:
- /home
`,
}
if !strings.Contains(stderr, for name, configYAML := range configs {
"Config file contains S3 credentials and is readable by others") { t.Run(name, func(t *testing.T) {
t.Errorf("expected a warning naming the S3 credentials, got %q", stderr) stderr := loadReadableConfig(t, configYAML)
if !strings.Contains(stderr,
"Config file is readable by others and may contain S3 credentials") {
t.Errorf("expected a warning naming the S3 credentials, got %q",
stderr)
}
})
} }
} }