R-105 (decision 169): retire the never-built slim DR record fields (no writer, no reader); 05 §9/§11, 06 §3.5 corrected
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
This commit is contained in:
@@ -72,7 +72,7 @@ func TestRestoreDirective_GatedAndExpires(t *testing.T) {
|
||||
seedHost(t, st, "h1", "c1", "HKEY")
|
||||
// Seed a DR bundle: K-escrow row + identity blob + directive.
|
||||
st.SaveHostEscrow("h1", []byte("opaque-K-escrow"), "01:36:e9:…", "zero_knowledge", time.Now().UTC().Format(time.RFC3339), "")
|
||||
st.SaveHostDRBundle("h1", []byte("opaque-identity"), `{"pbs_repo":"r","tunnel_id":"t","expected_key_fingerprint":"01:36:e9:…"}`)
|
||||
st.SaveHostDRBundle("h1", []byte("opaque-identity"))
|
||||
|
||||
// Not in recovery mode → 403.
|
||||
if rr := do(h, http.MethodGet, "/hosts/h1/restore-directive", "HKEY", ""); rr.Code != http.StatusForbidden {
|
||||
|
||||
Reference in New Issue
Block a user