R-105 (decision 169): retire the never-built slim DR record fields (no writer, no reader); 05 §9/§11, 06 §3.5 corrected

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
This commit is contained in:
2026-10-07 10:02:19 +02:00
parent e7fb10200e
commit aeca52ea54
12 changed files with 121 additions and 63 deletions
+3 -9
View File
@@ -87,9 +87,9 @@ func (h *Handler) handleClearRecoveryMode(w http.ResponseWriter, r *http.Request
type reEnrollResponse struct {
HostID string `json:"host_id"`
APIKeyRotated bool `json:"api_key_rotated"`
Directive json.RawMessage `json:"directive"` // non-secret DR directive
KEscrowB64 string `json:"k_escrow_b64"` // opaque PBS-key escrow blob
IdentityEscrowB64 string `json:"identity_escrow_b64"` // opaque identity escrow blob
Directive json.RawMessage `json:"directive"` // always {} — the directive is retired (R-105, decision 169); kept for the wire shape
KEscrowB64 string `json:"k_escrow_b64"` // opaque PBS-key escrow blob
IdentityEscrowB64 string `json:"identity_escrow_b64"` // opaque identity escrow blob
}
// handleReEnroll is the re-enroll handshake (slice 10D.2). Gated ONLY on RECOVERY MODE (the lost box
@@ -136,9 +136,6 @@ func (h *Handler) handleReEnroll(w http.ResponseWriter, r *http.Request, hostID
if bundle, err := h.store.GetHostDRBundle(hostID); err == nil && bundle != nil {
resp.KEscrowB64 = base64.StdEncoding.EncodeToString(bundle.KEscrowBlob)
resp.IdentityEscrowB64 = base64.StdEncoding.EncodeToString(bundle.IdentityBlob)
if bundle.DirectiveJSON != "" {
resp.Directive = json.RawMessage(bundle.DirectiveJSON)
}
}
h.logger.Printf("[INFO] DR: host %s RE-ENROLLED (hub credential rotated; old key revoked; directive served)", hostID)
// The new key is returned so the box can use it; the operator sees the rotation in the response.
@@ -175,9 +172,6 @@ func (h *Handler) handleGetRestoreDirective(w http.ResponseWriter, r *http.Reque
if bundle, err := h.store.GetHostDRBundle(hostID); err == nil && bundle != nil {
resp.KEscrowB64 = base64.StdEncoding.EncodeToString(bundle.KEscrowBlob)
resp.IdentityEscrowB64 = base64.StdEncoding.EncodeToString(bundle.IdentityBlob)
if bundle.DirectiveJSON != "" {
resp.Directive = json.RawMessage(bundle.DirectiveJSON)
}
}
writeJSON(w, http.StatusOK, resp)
}