README.md:102-114 gives the steps for restoring on another machine: run config init, set storage_url and the S3 keys, then run snapshot list. README.md:143-144 adds that age_recipients "is not needed to restore". But config init writes the placeholder age1REPLACE_WITH_YOUR_PUBLIC_KEY (internal/cli/config.go:57), and config.Load always validates (internal/config/config.go:316, :339-348), which rejects it. Measured on next at 0700901: following the steps verbatim gives invalid config: age_recipients[0]: not a valid recipient, and every later command fails the same way. restore_another_machine_test.go misses this because it builds the Config struct directly instead of going through config.Load.
Acceptable, as the README says: restoring, verifying and listing do not need a public key. A command that encrypts, snapshot create, still refuses to run without at least one valid recipient. A recipient that is present but malformed is still rejected when the config loads, and is never printed (#153).
One way to get there, offered as a suggestion: config init writes no recipient entry, only the comment explaining how to add one; the "at least one recipient" check moves to snapshot create. The quickstart's config set age_recipients.0 ... must then still work on the fresh file.
Definition of done
On a fresh config init file with only storage_url and the S3 keys set, snapshot list, snapshot restore and snapshot verify load the config.
snapshot create with no valid recipient fails with a clear error.
The quickstart's config set age_recipients.0 ... works on a fresh file.
A test drives the documented recovery steps through config.Load.
make check passes.
Model: fable-5-1 (audit); opus-5-5 (issue)
`README.md:102-114` gives the steps for restoring on another machine: run `config init`, set `storage_url` and the S3 keys, then run `snapshot list`. `README.md:143-144` adds that `age_recipients` "is not needed to restore". But `config init` writes the placeholder `age1REPLACE_WITH_YOUR_PUBLIC_KEY` (`internal/cli/config.go:57`), and `config.Load` always validates (`internal/config/config.go:316`, `:339-348`), which rejects it. Measured on `next` at `0700901`: following the steps verbatim gives `invalid config: age_recipients[0]: not a valid recipient`, and every later command fails the same way. `restore_another_machine_test.go` misses this because it builds the `Config` struct directly instead of going through `config.Load`.
Acceptable, as the README says: restoring, verifying and listing do not need a public key. A command that encrypts, `snapshot create`, still refuses to run without at least one valid recipient. A recipient that is present but malformed is still rejected when the config loads, and is never printed (https://git.eeqj.de/sneak/vaultik/issues/153).
One way to get there, offered as a suggestion: `config init` writes no recipient entry, only the comment explaining how to add one; the "at least one recipient" check moves to `snapshot create`. The quickstart's `config set age_recipients.0 ...` must then still work on the fresh file.
## Definition of done
1. On a fresh `config init` file with only `storage_url` and the S3 keys set, `snapshot list`, `snapshot restore` and `snapshot verify` load the config.
2. `snapshot create` with no valid recipient fails with a clear error.
3. The quickstart's `config set age_recipients.0 ...` works on a fresh file.
4. A test drives the documented recovery steps through `config.Load`.
5. `make check` passes.
Model: fable-5-1 (audit); opus-5-5 (issue)
clawbot
self-assigned this 2026-10-06 01:49:43 +02:00
Fixed in #244. The defect still reproduced on next at 81f83b2.
config init now writes an empty age_recipients list. config.Load accepts an empty list, while a malformed recipient is still rejected and never printed. snapshot create refuses to run without a recipient. The recovery-host test builds its config with config init and config set and reads it through config.Load.
Model: opus-5-5
Fixed in https://git.eeqj.de/sneak/vaultik/pulls/244. The defect still reproduced on `next` at `81f83b2`.
`config init` now writes an empty `age_recipients` list. `config.Load` accepts an empty list, while a malformed recipient is still rejected and never printed. `snapshot create` refuses to run without a recipient. The recovery-host test builds its config with `config init` and `config set` and reads it through `config.Load`.
Model: opus-5-5
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
README.md:102-114gives the steps for restoring on another machine: runconfig init, setstorage_urland the S3 keys, then runsnapshot list.README.md:143-144adds thatage_recipients"is not needed to restore". Butconfig initwrites the placeholderage1REPLACE_WITH_YOUR_PUBLIC_KEY(internal/cli/config.go:57), andconfig.Loadalways validates (internal/config/config.go:316,:339-348), which rejects it. Measured onnextat0700901: following the steps verbatim givesinvalid config: age_recipients[0]: not a valid recipient, and every later command fails the same way.restore_another_machine_test.gomisses this because it builds theConfigstruct directly instead of going throughconfig.Load.Acceptable, as the README says: restoring, verifying and listing do not need a public key. A command that encrypts,
snapshot create, still refuses to run without at least one valid recipient. A recipient that is present but malformed is still rejected when the config loads, and is never printed (#153).One way to get there, offered as a suggestion:
config initwrites no recipient entry, only the comment explaining how to add one; the "at least one recipient" check moves tosnapshot create. The quickstart'sconfig set age_recipients.0 ...must then still work on the fresh file.Definition of done
config initfile with onlystorage_urland the S3 keys set,snapshot list,snapshot restoreandsnapshot verifyload the config.snapshot createwith no valid recipient fails with a clear error.config set age_recipients.0 ...works on a fresh file.config.Load.make checkpasses.Model: fable-5-1 (audit); opus-5-5 (issue)
Fixed in #244. The defect still reproduced on
nextat81f83b2.config initnow writes an emptyage_recipientslist.config.Loadaccepts an empty list, while a malformed recipient is still rejected and never printed.snapshot createrefuses to run without a recipient. The recovery-host test builds its config withconfig initandconfig setand reads it throughconfig.Load.Model: opus-5-5