R-304: no 'wrong code' when earlier sealed packages were not all checked (424 older_unchecked)
gates / gates (push) Successful in 55s
gates / gates (push) Successful in 55s
Unreleased; ships with tomorrow's release. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
This commit is contained in:
@@ -127,6 +127,22 @@ func (s *Server) handleRecoverOffsitePassword(w http.ResponseWriter, r *http.Req
|
||||
"retained_has_restic_pw": match.HasResticPassword,
|
||||
},
|
||||
"the recovery code is correct, but it belongs to an EARLIER sealed package (superseded "+match.SupersededAt+"), not the one currently held")
|
||||
// ── R-304 (2026-10-08) — NOT EVERY EARLIER PACKAGE WAS CHECKED. ─────────────────────────
|
||||
//
|
||||
// The current package refused the code, no retained package opened it — and at least one earlier
|
||||
// package the hub holds was never tried (or the list could not be read). Saying „the code is
|
||||
// wrong" here would claim a check that did not happen. 424 (Failed Dependency): the verdict
|
||||
// depends on packages we could not try. The controller classifies on the status, never on this
|
||||
// sentence; an older controller maps an unknown status to its neutral „we do not know why".
|
||||
case errors.Is(err, escrow.ErrRetainedUnchecked):
|
||||
n := -1
|
||||
var ue *escrow.RetainedUncheckedError
|
||||
if errors.As(err, &ue) {
|
||||
n = ue.Unchecked
|
||||
}
|
||||
s.logger.Warn("local-api: offsite key recovery: the code did not open the current package and earlier packages were NOT all checked — not reported as a wrong code (R-304)", "vmid", vmid, "unchecked", n)
|
||||
writeStatus(w, http.StatusFailedDependency, false, map[string]any{"older_unchecked": n},
|
||||
"the recovery code did not open the current sealed package, and earlier packages the hub holds were not all checked — the code may belong to one of them; nothing was written")
|
||||
case errors.Is(err, escrow.ErrNoResticPassword):
|
||||
s.logger.Warn("local-api: offsite key recovery: the bundle opened but predates the repository-password field", "vmid", vmid)
|
||||
writeErr(w, http.StatusConflict, "the recovery code opened the bundle, but it carries NO offsite repository password (sealed before that field existed; it cannot be retro-fitted)")
|
||||
|
||||
@@ -54,6 +54,13 @@ func TestRecoverOffsitePassword_EachSituationGetsItsOwnStatus(t *testing.T) {
|
||||
wantStatus: 404,
|
||||
mustNotSay: []string{"did not open"},
|
||||
},
|
||||
{
|
||||
// R-304: earlier packages were not all tried — never „did not open the sealed bundle" (the wrong-code words).
|
||||
name: "earlier packages not all checked — not a wrong code",
|
||||
err: &escrow.RetainedUncheckedError{Unchecked: 2},
|
||||
wantStatus: 424,
|
||||
mustNotSay: []string{"did not open the sealed bundle", "could not be fetched"},
|
||||
},
|
||||
{
|
||||
name: "the bundle predates the repository-password field",
|
||||
err: escrow.ErrNoResticPassword,
|
||||
|
||||
Reference in New Issue
Block a user