feat(server): two-operator vault requires at least one recovery share
Some checks failed
ci/woodpecker/pr/server-audit Pipeline was successful
ci/woodpecker/pr/server-lint Pipeline failed
ci/woodpecker/pr/server-vet Pipeline failed
ci/woodpecker/pr/server-test Pipeline was successful

This commit is contained in:
CleverWild
2026-06-13 22:13:07 +02:00
parent 3b090cd3ce
commit f8c621b20e
5 changed files with 44 additions and 2 deletions

View File

@@ -39,6 +39,8 @@ pub enum Error {
Encryption,
#[error("Vault error")]
VaultError,
#[error("Two-operator vaults require at least one recovery share")]
TwoOperatorsRequireRecovery,
#[error("Broken database")]
BrokenDatabase,
}
@@ -200,11 +202,15 @@ impl VaultCoordinator {
&mut self,
operator_id: i32,
declared_count: usize,
recovery_count: usize,
) -> Result<(), Error> {
let _ = operator_id; // fixme!: any authenticated operator may announce the committee size. the first call wins
if !matches!(self.state, CoordinatorState::Idle) {
return Err(Error::AlreadyBootstrapping);
}
if declared_count == 2 && recovery_count == 0 {
return Err(Error::TwoOperatorsRequireRecovery);
}
self.state = CoordinatorState::Bootstrapping {
declared_count,
passphrases: HashMap::new(),
@@ -223,6 +229,7 @@ impl VaultCoordinator {
let CoordinatorState::Bootstrapping {
declared_count,
passphrases,
..
} = &mut self.state
else {
return Err(Error::NotBootstrapping);