Add emergency repository unlock

This commit is contained in:
Mikei386
2026-06-21 13:59:10 +02:00
parent 84df215ad0
commit 92ba5ce05f
11 changed files with 68 additions and 9 deletions
+10
View File
@@ -46,6 +46,7 @@ func New(socket string, svc *service.Service, log *slog.Logger) *Server {
mux.HandleFunc("POST /v1/repositories/{id}/test", s.testRepository)
mux.HandleFunc("POST /v1/repositories/{id}/init", s.initRepository)
mux.HandleFunc("POST /v1/repositories/{id}/unlock", s.unlockRepository)
mux.HandleFunc("POST /v1/repositories/{id}/force-unlock", s.forceUnlockRepository)
mux.HandleFunc("POST /v1/repositories/{id}/password", s.changeRepositoryPassword)
mux.HandleFunc("POST /v1/repositories/{id}/password/adopt", s.adoptRepositoryPassword)
mux.HandleFunc("POST /v1/repositories/{id}/{action}", s.maintenance)
@@ -194,6 +195,15 @@ func (s *Server) unlockRepository(w http.ResponseWriter, r *http.Request) {
}
writeJSON(w, 200, map[string]bool{"ok": true})
}
func (s *Server) forceUnlockRepository(w http.ResponseWriter, r *http.Request) {
ctx, cancel := context.WithTimeout(r.Context(), 2*time.Minute)
defer cancel()
if err := s.service.ForceUnlockRepository(ctx, r.PathValue("id")); err != nil {
writeError(w, err)
return
}
writeJSON(w, 200, map[string]bool{"ok": true})
}
func (s *Server) changeRepositoryPassword(w http.ResponseWriter, r *http.Request) {
s.repositoryPasswordAction(w, r, false)
}
+4
View File
@@ -106,6 +106,10 @@ func (r *Runner) Unlock(ctx context.Context, repo model.Repository) error {
return r.run(ctx, repo, []string{"unlock"}, nil, nil)
}
func (r *Runner) ForceUnlock(ctx context.Context, repo model.Repository) error {
return r.run(ctx, repo, []string{"unlock", "--remove-all"}, nil, nil)
}
func (r *Runner) ChangePassword(ctx context.Context, repo model.Repository, currentPassword, newPassword string) error {
newPasswordPath, cleanup, err := r.writePasswordFile("restic-new-password-*", newPassword)
if err != nil {
+19
View File
@@ -343,6 +343,25 @@ func TestUnlockUsesSafeResticCommand(t *testing.T) {
}
}
func TestForceUnlockRemovesAllRepositoryLocks(t *testing.T) {
dir := t.TempDir()
argsPath := filepath.Join(dir, "args")
script := filepath.Join(dir, "restic")
body := fmt.Sprintf("#!/bin/sh\nprintf '%%s\\n' \"$@\" > '%s'\n", argsPath)
if err := os.WriteFile(script, []byte(body), 0700); err != nil {
t.Fatal(err)
}
runner := &Runner{Binary: script, RuntimeDir: dir, Secrets: fakeSecrets{"password": "secret"}}
repo := model.Repository{Type: model.RepositoryLocal, Location: "/repo", PasswordRef: "password"}
if err := runner.ForceUnlock(context.Background(), repo); err != nil {
t.Fatal(err)
}
args, _ := os.ReadFile(argsPath)
if !strings.Contains(string(args), "unlock\n--remove-all") {
t.Fatalf("force unlock did not use remove-all: %s", args)
}
}
func TestResticErrorExplainsExistingRepository(t *testing.T) {
err := resticError("Fatal: create repository failed: config file already exists", fmt.Errorf("exit status 1"))
if !strings.Contains(err.Error(), "already initialized") || !strings.Contains(err.Error(), "select Test") {
+13
View File
@@ -414,6 +414,19 @@ func (s *Service) UnlockRepository(ctx context.Context, repoID string) error {
return s.restic.Unlock(ctx, mounted.Repository)
}
func (s *Service) ForceUnlockRepository(ctx context.Context, repoID string) error {
repo, ok := s.repository(repoID)
if !ok {
return errors.New("validation: unknown repository")
}
mounted, err := s.mounts.Prepare(ctx, repo)
if err != nil {
return err
}
defer s.mounts.Cleanup(context.Background(), mounted)
return s.restic.ForceUnlock(ctx, mounted.Repository)
}
func (s *Service) execute(ctx context.Context, run model.Run) model.Run {
ctx = restic.WithRunID(ctx, run.ID)
if run.TaskType == "backup" {