Compare commits

..
1 Commits
Author SHA1 Message Date
sneak cf034d1ac9 Fix two misleading messages (closes #240)
check / check (push) Canceled after 0s
The warning for a config file that others can read always said the
file contained S3 credentials, so a file:// config with none got a
false claim. It now names them only when s3.access_key_id or
s3.secret_access_key is set, and otherwise says the file is readable
by others.

snapshot purge wrapped the listing error, which already starts with
"listing remote snapshots:", in that prefix a second time.
syncWithRemote now returns it unwrapped, as CleanupLocalSnapshots
does.

Judgement call: a credential pulled into the config through smartconfig
substitution counts as set by the file.

Model: opus-5-5
2026-10-07 11:08:57 +00:00
3 changed files with 13 additions and 39 deletions
+5 -6
View File
@@ -26,12 +26,11 @@ the tag exists and is exercised; what is left is merging `next` to
([issue #240](https://git.eeqj.de/sneak/vaultik/issues/240)). A config
file that others can read was warned about as containing S3
credentials even when it set none, as a `file://` config does. The
warning now says the file may contain S3 credentials only when
`s3.access_key_id` or `s3.secret_access_key` is set, since either may
come from a `${...}` reference rather than the file, and otherwise
says the file is readable by others. `snapshot purge` against a
destination store it could not list gave an error with
`listing remote snapshots:` in it twice; the prefix now appears once.
warning now names the credentials only when `s3.access_key_id` or
`s3.secret_access_key` is set, and otherwise says the file is readable
by others. `snapshot purge` against a destination store it could not
list gave an error with `listing remote snapshots:` in it twice; the
prefix now appears once.
- 2026-10-07: Made per-name retention work when the hostname contains `_`
([issue #230](https://git.eeqj.de/sneak/vaultik/issues/230)). A
+2 -4
View File
@@ -412,12 +412,10 @@ func (c *Config) setAgeSecretKey() {
}
// readableByOthersWarning is the warning Load logs when others can read
// the config file. It says "may contain" because the S3 credentials are
// seen only after smartconfig has replaced any ${...} reference in the
// file with its value, so a set credential need not be in the file.
// the config file. It names the S3 credentials only when they are set.
func (c *Config) readableByOthersWarning() string {
if c.S3.AccessKeyID != "" || c.S3.SecretAccessKey != "" {
return "Config file is readable by others and may contain S3 credentials"
return "Config file contains S3 credentials and is readable by others"
}
return "Config file is readable by others"
+6 -29
View File
@@ -423,16 +423,11 @@ snapshots:
}
// TestLoadWarnsReadableConfigWithS3Credentials checks that a config file
// others can read and that sets S3 credentials, as values or as ${ENV:...}
// references, is warned about as one that may contain them.
// others can read is warned about as holding the S3 credentials it sets.
//
//nolint:paralleltest // loadReadableConfig replaces os.Stderr
func TestLoadWarnsReadableConfigWithS3Credentials(t *testing.T) {
t.Setenv("VAULTIK_TEST_ACCESS_KEY_ID", "test-access-key")
t.Setenv("VAULTIK_TEST_SECRET_ACCESS_KEY", "test-secret-key")
configs := map[string]string{
"values": `
stderr := loadReadableConfig(t, `
storage_url: s3://bucket/prefix?endpoint=s3.example.com
s3:
access_key_id: test-access-key
@@ -441,28 +436,10 @@ snapshots:
home:
paths:
- /home
`,
"references": `
storage_url: s3://bucket/prefix?endpoint=s3.example.com
s3:
access_key_id: ${ENV:VAULTIK_TEST_ACCESS_KEY_ID}
secret_access_key: ${ENV:VAULTIK_TEST_SECRET_ACCESS_KEY}
snapshots:
home:
paths:
- /home
`,
}
`)
for name, configYAML := range configs {
t.Run(name, func(t *testing.T) {
stderr := loadReadableConfig(t, configYAML)
if !strings.Contains(stderr,
"Config file is readable by others and may contain S3 credentials") {
t.Errorf("expected a warning naming the S3 credentials, got %q",
stderr)
}
})
if !strings.Contains(stderr,
"Config file contains S3 credentials and is readable by others") {
t.Errorf("expected a warning naming the S3 credentials, got %q", stderr)
}
}