The documented "restoring on another machine" steps fail at the first command #221

Closed
opened 2026-10-06 01:49:43 +02:00 by clawbot · 1 comment
Collaborator

README.md:102-114 gives the steps for restoring on another machine: run config init, set storage_url and the S3 keys, then run snapshot list. README.md:143-144 adds that age_recipients "is not needed to restore". But config init writes the placeholder age1REPLACE_WITH_YOUR_PUBLIC_KEY (internal/cli/config.go:57), and config.Load always validates (internal/config/config.go:316, :339-348), which rejects it. Measured on next at 0700901: following the steps verbatim gives invalid config: age_recipients[0]: not a valid recipient, and every later command fails the same way. restore_another_machine_test.go misses this because it builds the Config struct directly instead of going through config.Load.

Acceptable, as the README says: restoring, verifying and listing do not need a public key. A command that encrypts, snapshot create, still refuses to run without at least one valid recipient. A recipient that is present but malformed is still rejected when the config loads, and is never printed (#153).

One way to get there, offered as a suggestion: config init writes no recipient entry, only the comment explaining how to add one; the "at least one recipient" check moves to snapshot create. The quickstart's config set age_recipients.0 ... must then still work on the fresh file.

Definition of done

  1. On a fresh config init file with only storage_url and the S3 keys set, snapshot list, snapshot restore and snapshot verify load the config.
  2. snapshot create with no valid recipient fails with a clear error.
  3. The quickstart's config set age_recipients.0 ... works on a fresh file.
  4. A test drives the documented recovery steps through config.Load.
  5. make check passes.

Model: fable-5-1 (audit); opus-5-5 (issue)

`README.md:102-114` gives the steps for restoring on another machine: run `config init`, set `storage_url` and the S3 keys, then run `snapshot list`. `README.md:143-144` adds that `age_recipients` "is not needed to restore". But `config init` writes the placeholder `age1REPLACE_WITH_YOUR_PUBLIC_KEY` (`internal/cli/config.go:57`), and `config.Load` always validates (`internal/config/config.go:316`, `:339-348`), which rejects it. Measured on `next` at `0700901`: following the steps verbatim gives `invalid config: age_recipients[0]: not a valid recipient`, and every later command fails the same way. `restore_another_machine_test.go` misses this because it builds the `Config` struct directly instead of going through `config.Load`. Acceptable, as the README says: restoring, verifying and listing do not need a public key. A command that encrypts, `snapshot create`, still refuses to run without at least one valid recipient. A recipient that is present but malformed is still rejected when the config loads, and is never printed (https://git.eeqj.de/sneak/vaultik/issues/153). One way to get there, offered as a suggestion: `config init` writes no recipient entry, only the comment explaining how to add one; the "at least one recipient" check moves to `snapshot create`. The quickstart's `config set age_recipients.0 ...` must then still work on the fresh file. ## Definition of done 1. On a fresh `config init` file with only `storage_url` and the S3 keys set, `snapshot list`, `snapshot restore` and `snapshot verify` load the config. 2. `snapshot create` with no valid recipient fails with a clear error. 3. The quickstart's `config set age_recipients.0 ...` works on a fresh file. 4. A test drives the documented recovery steps through `config.Load`. 5. `make check` passes. Model: fable-5-1 (audit); opus-5-5 (issue)
clawbot self-assigned this 2026-10-06 01:49:43 +02:00
Author
Collaborator

Fixed in #244. The defect still reproduced on next at 81f83b2.

config init now writes an empty age_recipients list. config.Load accepts an empty list, while a malformed recipient is still rejected and never printed. snapshot create refuses to run without a recipient. The recovery-host test builds its config with config init and config set and reads it through config.Load.

Model: opus-5-5

Fixed in https://git.eeqj.de/sneak/vaultik/pulls/244. The defect still reproduced on `next` at `81f83b2`. `config init` now writes an empty `age_recipients` list. `config.Load` accepts an empty list, while a malformed recipient is still rejected and never printed. `snapshot create` refuses to run without a recipient. The recovery-host test builds its config with `config init` and `config set` and reads it through `config.Load`. Model: opus-5-5
Sign in to join this conversation.