All checks were successful
check / check (pull_request) Successful in 2m13s
ListSnapshots built its table entirely from the local SQLite index. The only remote access, reportRemoteDrift, was gated on AgeSecretKey being non-empty — so on a correctly configured host, which by design holds no private key, `snapshot list` never contacted the destination store at all. A user who lost their local index could not see their own backups, and the "<remote only>" cell the README documents was unreachable dead code. The listing is now the union of the local index and the destination store, with no age_secret_key gate. The manifest is unencrypted, so a host holding only the public key can enumerate what it has backed up: one streamed listing of the metadata/ prefix, then a manifest read per remote key the local index does not already account for, bounded by maxRemoteOnlyRows and run with bounded concurrency. A remote-only snapshot's hostname and name are deliberately NOT recovered. RemoteSnapshotKey is one-way and the manifest stores the hash rather than the human ID, so they are recoverable only from the encrypted per-snapshot database; making them readable from remote storage would undo a deliberate privacy property (#81). Such rows are labelled "<remote only:<12 hex chars>>", carry the real timestamp and compressed size from the manifest, and show "<remote only>" in the two columns that genuinely require the local index. --json carries the full 64-character key in remote_key, and remote_present distinguishes seen (true), missing (false) and not-listable (null). Local records with no counterpart on the destination store are still surfaced as drift, and the remediation hint now names `vaultik prune`, which exists, rather than `vaultik snapshot cleanup`, which does not: CleanupLocalSnapshots is already wired as prune's first pass, and re-adding a second entry point would undo the CLI consolidation. reportRemoteDrift collapses. Its remote-only half is subsumed by the table — those snapshots are rows now, not a footnote count — and its local-only half reads the merge ListSnapshots already computed, so the command lists the destination exactly once per invocation. An unreachable destination stays a warning plus local-only output and a zero exit code, as the doc comment always claimed. In --json mode that warning goes to stderr, because the logger and the UI writer both emit on stdout and would otherwise corrupt the document. Tests cover remote-only rendering, the no-private-key property (a storer that counts prefix listings and records fetched keys, asserting the destination is read and nothing encrypted is touched), graceful degradation on an unreachable destination in both output modes, local-only drift, and an unreadable manifest not hiding other snapshots.
5.3 KiB
5.3 KiB
Workflow
- branch (from
main) - do the work in Next Step
- move Next Step to the top of Completed Steps
- move the top item of Future Steps into Next Step
- commit (
TODO.mdchanges in the same commit as the work) - merge to
mainif the branch is not protected, otherwise open a PR - push
Status
pre-1.0
Next Step
Triage the stale remote branches (issue #71): for each, merge the work or delete the branch.
Completed Steps
- 2026-08-09: Made
snapshot listlist the destination store without the private key (issue #64). The listing is now the union of the local index and a single streamed listing of themetadata/prefix, with noage_secret_keygate — the manifest is unencrypted, so a host holding only the public key can enumerate its own backups and a host that lost its local index can still see them. A remote-only snapshot's hostname and name are deliberately not recovered (they are not recoverable without the private key, and making them so would undo the privacy property tracked in issue #81); such rows are labelled by an abbreviation of their remote key and carry the real timestamp and compressed size from the manifest, with<remote only>in the two columns that require the local index. Local-only snapshots are reported as drift, and the hint now namesvaultik prune, which exists, instead ofvaultik snapshot cleanup, which does not.reportRemoteDriftcollapsed into the merged view. Every remote manifest read in the codebase now goes throughdownloadManifestByKey, so issue #81 has one call site to change. Verified withscript/cibuildand end to end against afile://destination with no secret key present. - 2026-08-09: Closed the gap between
make lintand CI (issue #78).script/lintnow runs the digest-pinnedgolangci-lintimage taken from theDockerfilelint stage, which is the single source of truth for the linter version; the duplicate pin in theMakefiledepstarget and the unpinnedgolangci-lintinstall inscript/bootstrapare gone. Agolangci-lintonPATHis used only when its version is exactly the pinned one (which is how the lint stage runs it inside the container); anything else goes through Docker, and a missing or unreachable Docker daemon is a hard error rather than a silent fallback.make checkis therefore now as trustworthy asscript/cibuild. - 2026-08-09: Finished the lint remediation under the canonical
.golangci.yml(issue #61, which also unblocks issue #59). The remaining findings were fixed behavior-preservingly:wsl_v5whitespace,sqlclosecheck, andprealloc. Thesqlclosechecksites now closesql.Rowsin a deferred closure instead of via theCloseRowshelper, which the linter could not see through. Only therevivepackage-name findings remain suppressed, with per-site//nolintdirectives; the package-rename question behind them is tracked in issue #76. Verified withscript/cibuild, which exits 0 — that is the only trustworthy gate, becausescript/lintruns whatevergolangci-linthappens to be onPATHrather than the pinned v2.12.2 that CI and theDockerfileuse, somake checkcan report green on findings CI still fails. That tooling gap is tracked in issue #78. - 2026-08-09: The earlier next step "reconcile the uncommitted
ARCHITECTURE.mdedits onmain" needed no work: the working tree is clean andARCHITECTURE.mdis committed onmain. - 2026-08-07: Updated golangci-lint to v2.12.2 everywhere it is pinned
(
Dockerfilelint stage,Makefiledeps target), replaced.golangci.ymlwith the canonical config (v2 schema,default: all), and remediated the bulk of the lint findings it surfaced (issue #61): behavior-preserving fixes across every package, 2,990 findings down to 80.make testandmake fmt-checkwere green at that point butmake lintwas still red; the commit message claimingmake checkwas green was wrong. - 2026-08-07: Added the standard
.golangci.ymland.editorconfig(issue #59); lint findings under the new config are tracked in issue #61.script/bootstrapnow installs sqlite3 (needed by tests). - 2026-07-07 Adopted scripts-to-rule-them-all:
script/entrypoints, Makefile shims, README Entrypoints section - 2026-07-02: Consolidated CLI verbs, retired overlapping commands; bound the local index to its backup destination URL.
- 2026-06-28: snapshot rm now removes metadata only and prints the prune command; restore skips chown when running as non-root.
- 2026-06-26: Snapshot IDs hashed at the storage boundary; snapshot list made resilient to bad remote entries.
- 2026-06-24: Collapsed snapshot prune into vaultik prune; restore streams blobs to disk and restores files in blob-locality order; cron output fixes.
- 2026-06-17: Restore overhaul: ReadAt chunk reads from cached blobs, reference-counted blob sweeper, integration tests; new internal/ui output layer, banner, and progress lines.
- 2025-12-18: Added ARCHITECTURE.md and godoc coverage for exported API.
- 2025-07-26: End-to-end integration tests; manifest format refactor; renamed backup to snapshot; afero filesystem abstraction.
- 2025-07-20: Initial design and implementation: cobra + fx CLI skeleton, SQLite index database, UUID blob storage with streaming chunking.
Future Steps
- Define remaining scope for a first tagged release and cut v0.1.0.