hub v0.128.0: set-aside deletion through the hub after a 7-day wait (decision 74, R-823), key-file clean-up route (R-826), read-only key check (R-827), window cap = half
gates / gates (push) Successful in 29s

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
This commit is contained in:
2026-10-04 07:05:21 +02:00
parent 697c2a7b10
commit d3c50b50f6
15 changed files with 613 additions and 20 deletions
+13
View File
@@ -391,6 +391,17 @@ func main() {
Store: dataStore, Reg: &offsitekeys.Registrar{Dialer: offsitekeys.SSHDialer{}}, Logger: logger,
Emit: dispatcher.ProcessEvent,
}
// Decision 74: the hub-enforced wait before a set-aside copy is deleted. OFFSITE_ABANDON_DELAY
// overrides the 7-day default ONLY for a test, and is logged loudly when it does.
keySvc.AbandonDelay = offsitekeys.DefaultAbandonDelay
if v := os.Getenv("OFFSITE_ABANDON_DELAY"); v != "" {
if d, derr := time.ParseDuration(v); derr == nil && d > 0 {
keySvc.AbandonDelay = d
logger.Printf("[WARN] OFFSITE_ABANDON_DELAY=%s — set-aside deletions wait %s instead of 7 days (TEST CONFIGURATION)", v, d)
} else {
logger.Printf("[ERROR] OFFSITE_ABANDON_DELAY=%q invalid — keeping 7 days", v)
}
}
apiHandler.SetOffsiteKeyService(keySvc)
runKeyAudit := func(ctx context.Context) any {
start := time.Now()
@@ -415,6 +426,7 @@ func main() {
}
webServer.SetOffsiteKeyAudit(runKeyAudit)
webServer.SetOffsiteWindowAdmin(dataStore.GrantOffsiteWindowOnce, dataStore.SetOffsiteWindowsEnabled)
webServer.SetOffsiteKeyAdmin(keySvc.RemoveUnpinnedKeys, keySvc.CancelAbandon)
// Decision 68: a window the box never closed is closed by the hub at its 20-minute bound.
go func() {
tk := time.NewTicker(60 * time.Second)
@@ -426,6 +438,7 @@ func main() {
case <-tk.C:
sctx, cancel := context.WithTimeout(ctx, 2*time.Minute)
keySvc.SweepExpiredWindows(sctx)
keySvc.SweepAbandons(sctx)
cancel()
}
}