fix(unfold): carry the database's encryption key when adopting the former name #237
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "ryangr0/fix/adopt-database-key"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Blocks the homelab switch to rc.39. When an install upgrades from the Vloer era,
adoptRenamedDatabaserenamesvloer.sqlite(with-waland-shm) tounfold.sqlite, but it leftvloer.sqlite.keybehind.Storethen found nounfold.sqlite.keyand generated a new random key. Every secret encrypted before the rename stopped decrypting (Unsupported state or unable to authenticate data). Today those secrets are the VS Code editor sign-in tokens (ahp-token:*).The homelab data directory has exactly these files:
vloer.sqlite,-wal,-shmandvloer.sqlite.key. Production has not run rc.39 yet.The fix adds
.keyto the files that move together. A new test writes a secret through a realStoreunder the former name, adopts it and reads the secret back. Without the fix it fails with the error above; with the fix it passes.Verified:
npm run check,npm test(751 pass, 0 fail).I introduced this in #223.
🤖 Generated with Claude Code