From d866368e33c41747e3432b351e90ff10110d008c Mon Sep 17 00:00:00 2001 From: vastsa Date: Wed, 23 Sep 2026 02:23:30 +0800 Subject: [PATCH] fix(config-sync): keep the vault-password error code visible A wrong backup password was wrapped as "unlock vault", so the settings page treated it as an unknown failure instead of asking for the vault password. --- crates/host-core/src/config_sync/crypto.rs | 5 +++-- 1 file changed, 3 insertions(+), 2 deletions(-) diff --git a/crates/host-core/src/config_sync/crypto.rs b/crates/host-core/src/config_sync/crypto.rs index 9c2bbed6d4..fd15bc8284 100644 --- a/crates/host-core/src/config_sync/crypto.rs +++ b/crates/host-core/src/config_sync/crypto.rs @@ -256,7 +256,7 @@ pub fn unlock_vault(header: &VaultHeader, password: &str) -> Result { encrypted.extend_from_slice(&nonce); encrypted.extend_from_slice(&ciphertext); let plaintext = decrypt_with_key(&wrapping_key, "vault-key", &header.vault_id, &encrypted) - .context("unlock vault")?; + .map_err(|_| anyhow!("CONFIG_SYNC_CRYPTO: backup password did not open this vault"))?; let raw: [u8; KEY_BYTES] = plaintext .try_into() .map_err(|_| anyhow!("CONFIG_SYNC_CRYPTO: vault key has an invalid length"))?; @@ -312,7 +312,8 @@ mod tests { create_vault("correct horse battery staple", "vault-a").expect("create vault"); let unlocked = unlock_vault(&header, "correct horse battery staple").expect("unlock"); assert_eq!(unlocked.as_bytes(), key.as_bytes()); - assert!(unlock_vault(&header, "wrong password").is_err()); + let wrong = unlock_vault(&header, "wrong password").expect_err("wrong password"); + assert!(wrong.to_string().starts_with("CONFIG_SYNC_CRYPTO:")); let mut ciphertext = encrypt_object(&key, "test", "vault-a", b"portable settings").expect("encrypt");