R-366: the hub retains the escrow when the whole-guest backup key changes

A reinstall mints a new PBS key K while R-241 keeps the restic password, so
the supersession rule (restic sha only) overwrote the only copy of the old K
and every pre-reinstall whole-guest archive became unopenable for good. The
current row is now also retained when the key fingerprint changes (case and
space ignored; an empty fingerprint is unknown, not a change).

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
This commit is contained in:
2026-10-06 20:43:29 +02:00
parent ed8b10330c
commit 74009014aa
3 changed files with 81 additions and 5 deletions
+1 -1
View File
@@ -1271,7 +1271,7 @@ func (h *Handler) handleHostEscrowPut(w http.ResponseWriter, r *http.Request, pa
}
if superseded {
n, _ := h.store.CountSupersededEscrow(pathHostID)
h.logger.Printf("[INFO] escrow for host %s superseded a different-passphrase blob — RETAINED (now %d superseded blob(s) held)", pathHostID, n)
h.logger.Printf("[INFO] escrow for host %s superseded an escrow with a different passphrase or backup key (R-366) — RETAINED (now %d superseded blob(s) held)", pathHostID, n)
// Hub-internal audit event (not gated by allowedEventTypes) — tied to the owning customer.
if host, herr := h.store.GetHost(pathHostID); herr == nil && host != nil && host.CustomerID != "" {
details, _ := json.Marshal(map[string]any{"host_id": pathHostID, "retained_count": n})