Load a config that has no age recipient #244

Merged
clawbot merged 1 commits from issue-221-recipient-optional-at-load into next 2026-10-06 15:46:14 +02:00
Collaborator

Fixes #221.

The README's steps for restoring on another machine failed after config init. The file held the placeholder age1REPLACE_WITH_YOUR_PUBLIC_KEY, which config.Load rejects, so snapshot list, snapshot restore and snapshot verify never started.

  • config init writes age_recipients: [] under a comment saying how to generate and add a key.
  • config.Load accepts an empty list. A malformed recipient is still rejected at load and never printed.
  • snapshot create returns an error naming age_recipients when the list is empty. The check is the first step of CreateSnapshot, before the index is bound or pruned and before anything is scanned.
  • TestRestoreOnAnotherMachine builds the recovery host's config by running config init and config set storage_url in-process and reading the file with config.Load, then checks that snapshot create refuses to run there.
  • The README configuration table, config.example.yml and the config init template say the field is needed only to create snapshots.

What the diff does not show:

  • On a fresh file, config set age_recipients.0 age1... writes the list in flow style ([age1...]), because the template's empty list is flow style. It loads the same as a block list.
  • Judgement call: the internal/vaultik test imports internal/cli to run the real commands, which write cli's package-level flag variables, so no two tests in that package may run them at the same time.
  • The test's storage_url is a file:// destination where the README uses s3:// with keys. Recipient handling at load is the same for both.

Model: opus-5-5

Fixes https://git.eeqj.de/sneak/vaultik/issues/221. The README's steps for restoring on another machine failed after `config init`. The file held the placeholder `age1REPLACE_WITH_YOUR_PUBLIC_KEY`, which `config.Load` rejects, so `snapshot list`, `snapshot restore` and `snapshot verify` never started. - `config init` writes `age_recipients: []` under a comment saying how to generate and add a key. - `config.Load` accepts an empty list. A malformed recipient is still rejected at load and never printed. - `snapshot create` returns an error naming `age_recipients` when the list is empty. The check is the first step of `CreateSnapshot`, before the index is bound or pruned and before anything is scanned. - `TestRestoreOnAnotherMachine` builds the recovery host's config by running `config init` and `config set storage_url` in-process and reading the file with `config.Load`, then checks that `snapshot create` refuses to run there. - The README configuration table, `config.example.yml` and the `config init` template say the field is needed only to create snapshots. What the diff does not show: - On a fresh file, `config set age_recipients.0 age1...` writes the list in flow style (`[age1...]`), because the template's empty list is flow style. It loads the same as a block list. - Judgement call: the `internal/vaultik` test imports `internal/cli` to run the real commands, which write `cli`'s package-level flag variables, so no two tests in that package may run them at the same time. - The test's `storage_url` is a `file://` destination where the README uses `s3://` with keys. Recipient handling at load is the same for both. Model: opus-5-5
clawbot added the needs-review label 2026-10-06 13:33:25 +02:00
clawbot self-assigned this 2026-10-06 13:33:25 +02:00
Author
Collaborator
  1. internal/vaultik/restore_another_machine_test.go:172-174 (runVaultikCommand): the helper runs cli commands, which set cli's package-level flag variables, and it is called from a t.Parallel() test. A second test in this package that calls it would race with this one. The PR body states this limit, but the code does not, and the code is where the next person to reuse the helper will look. Acceptable: the helper's comment says it must not be called from two tests that run at the same time.

  2. PR body: it is about 270 words, over the ~250-word limit. It also says snapshot create refuses "before it touches the index or the store", but the command takes the lock and opens the local index (creating the file on a fresh host) before CreateSnapshot runs its check. Acceptable: at most ~250 words, with that claim limited to what the code does: the check is the first step of CreateSnapshot, before the index is bound or pruned and before anything is scanned.

Model: opus-5-5

1. `internal/vaultik/restore_another_machine_test.go:172-174` (`runVaultikCommand`): the helper runs `cli` commands, which set `cli`'s package-level flag variables, and it is called from a `t.Parallel()` test. A second test in this package that calls it would race with this one. The PR body states this limit, but the code does not, and the code is where the next person to reuse the helper will look. Acceptable: the helper's comment says it must not be called from two tests that run at the same time. 2. PR body: it is about 270 words, over the ~250-word limit. It also says `snapshot create` refuses "before it touches the index or the store", but the command takes the lock and opens the local index (creating the file on a fresh host) before `CreateSnapshot` runs its check. Acceptable: at most ~250 words, with that claim limited to what the code does: the check is the first step of `CreateSnapshot`, before the index is bound or pruned and before anything is scanned. Model: opus-5-5
clawbot added needs-rework and removed needs-review labels 2026-10-06 14:17:45 +02:00
clawbot force-pushed issue-221-recipient-optional-at-load from 43685e61dd to 01d3ffc0a8 2026-10-06 14:46:25 +02:00 Compare
clawbot added 1 commit 2026-10-06 14:53:07 +02:00
The README's steps for restoring on another machine failed at the first
command: `config init` wrote a placeholder recipient, and `config.Load`
rejects any recipient that does not parse. `config init` now writes an
empty `age_recipients` list, `config.Load` accepts an empty list, and
`snapshot create` refuses to start without a recipient. A malformed
recipient is still rejected at load.

The recovery-host test now builds its config with `config init` and
`config set` and reads it through `config.Load`, so it imports
`internal/cli`. On a fresh file, `config set age_recipients.0` writes the
list in flow style (`[age1...]`).

Model: opus-5-5
clawbot force-pushed issue-221-recipient-optional-at-load from 01d3ffc0a8 to 522d802ba1 2026-10-06 14:53:07 +02:00 Compare
Author
Collaborator
  1. The runVaultikCommand comment now says the command writes the cli package's global flag variables, so it must not be called from two tests that run at the same time.
  2. The PR body is under 250 words, and now says the recipient check is the first step of CreateSnapshot, before the index is bound or pruned and before anything is scanned.

Model: opus-5-5

1. The `runVaultikCommand` comment now says the command writes the `cli` package's global flag variables, so it must not be called from two tests that run at the same time. 2. The PR body is under 250 words, and now says the recipient check is the first step of `CreateSnapshot`, before the index is bound or pruned and before anything is scanned. Model: opus-5-5
clawbot added needs-review and removed needs-rework labels 2026-10-06 15:09:19 +02:00
Author
Collaborator

Review passed.

Model: opus-5-5

Review passed. Model: opus-5-5
clawbot merged commit 14fc4c9893 into next 2026-10-06 15:46:14 +02:00
clawbot deleted branch issue-221-recipient-optional-at-load 2026-10-06 15:46:14 +02:00
Sign in to join this conversation.