mirror of
https://github.com/home-assistant/supervisor.git
synced 2026-09-30 00:04:07 +01:00
* Fix supervisor config restore from encrypted backups The mount and Docker registry configuration stored in supervisor.tar was never restored from encrypted backups. securetar opens encrypted inner tars in streaming mode since it cannot seek in the ciphertext. Reading a member via getmember() followed by extractfile() requires seeking backwards: to find the member, tarfile reads all headers and thereby advances past the member data. This raises tarfile.StreamError, which was caught by the broad TarError handler and only logged as a warning, so the restore reported success while the mounts were silently missing. This affects every encrypted backup since the supervisor tar was introduced in 2026.03.3, and Core-created backups are encrypted by default. The data in those backups is intact, restoring them again with this fix recovers the configuration. Read the inner tar sequentially and pick up mounts.json and docker.json as they stream past. Add a test which stores and restores mounts and registries with a backup password set, as the existing tests only covered plain tars. Also document the archive layout in the Backup class docstring, noting that Core only encrypts/decrypts inner tars from a fixed list when rewriting a backup, so any new inner tar must be added there as well (see home-assistant/core#182137). Fixes #7213 Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> * Add end-to-end test with encrypted supervisor config fixture Add backup_example_enc_supervisor.tar, a partial backup created by Supervisor with password "test123" that only contains supervisor.tar.gz with a CIFS mount and a registry. Restore it through the backup manager to cover the full encrypted restore path. Also cover supervisor tars with only one of the JSON files, as written by Supervisor 2026.03.x before docker.json was added, including unknown and non-file members which are skipped. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> --------- Co-authored-by: Claude Fable 5.1 <noreply@anthropic.com>