91e4ace9b8
Opens the four sealed box-secret columns back to plaintext (all or nothing; keeps api_key_hash; idempotent; counts only in the log) and exits before any start-up sealing, so hub 0.137.0 can run on the database again. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
48 lines
1.5 KiB
Go
48 lines
1.5 KiB
Go
package main
|
|
|
|
import (
|
|
"go/ast"
|
|
"go/parser"
|
|
"go/token"
|
|
"os"
|
|
"strings"
|
|
"testing"
|
|
)
|
|
|
|
// R-879 seam wiring: main() must CALL SealLegacyBoxSecrets, or every box key, owner passphrase and PBS
|
|
// token written before the change stays in plaintext in hub.db. RED-PROOF: comment the call out → FAIL.
|
|
func TestR879_MainSealsLegacyBoxSecrets(t *testing.T) {
|
|
f, err := parser.ParseFile(token.NewFileSet(), "main.go", nil, 0)
|
|
if err != nil {
|
|
t.Fatal(err)
|
|
}
|
|
found := false
|
|
ast.Inspect(f, func(n ast.Node) bool {
|
|
if c, ok := n.(*ast.CallExpr); ok {
|
|
if sel, ok := c.Fun.(*ast.SelectorExpr); ok && sel.Sel.Name == "SealLegacyBoxSecrets" {
|
|
found = true
|
|
}
|
|
}
|
|
return true
|
|
})
|
|
if !found {
|
|
t.Fatal("cmd/hub/main.go never calls SealLegacyBoxSecrets — legacy box secrets stay in plaintext")
|
|
}
|
|
}
|
|
|
|
// R-879 roll-back wiring: the -unseal-box-secrets flag must reach UnsealBoxSecrets and must exit BEFORE
|
|
// the start-up sealing runs (otherwise the command would unseal and the same process re-seal).
|
|
func TestR879_UnsealFlagIsWiredBeforeSealing(t *testing.T) {
|
|
src, err := os.ReadFile("main.go")
|
|
if err != nil {
|
|
t.Fatal(err)
|
|
}
|
|
s := string(src)
|
|
flagAt := strings.Index(s, `"unseal-box-secrets"`)
|
|
runAt := strings.Index(s, "code := runUnsealBoxSecrets(dataStore, logger)")
|
|
sealAt := strings.Index(s, "dataStore.SealLegacyBoxSecrets()")
|
|
if flagAt < 0 || runAt < 0 || sealAt < 0 || runAt > sealAt || !strings.Contains(s, "st.UnsealBoxSecrets()") {
|
|
t.Fatalf("unseal wiring broken: flag@%d run@%d seal@%d", flagAt, runAt, sealAt)
|
|
}
|
|
}
|