Skip to content

[stable33] fix(encryption): use the closest cached parent for the access list - #64962

Merged
susnux merged 2 commits into
stable33from
backport/64289/stable33
Oct 1, 2026
Merged

susnux merged 2 commits into
stable33from
backport/64289/stable33

Conversation

@backportbot

@backportbot backportbot Bot commented Sep 30, 2026

Copy link
Copy Markdown

Backport of PR #64289

@backportbot
backportbot Bot requested a review from a team as a code owner September 30, 2026 20:03
@backportbot
backportbot Bot requested review from CarlSchwan, come-nc, icewind1991 and leftybournes and removed request for a team September 30, 2026 20:03
@backportbot backportbot Bot added this to the Nextcloud 33.0.10 milestone Sep 30, 2026
Copying a folder creates the target directories on the storage before
their cache entries exist, so while the files inside are written the
parent of the target path can not be resolved yet. With per-user keys
the encryption stream needs the access list on every write, so the
unguarded $userFolder->get($parent) made every folder copy fail with a
NotFoundException.

Walk up to the closest ancestor that is known to the cache instead.
Shares only exist on cached nodes, so its access list is the one that
applies and the share keys of the recipients are still created when
copying into a shared folder.

Assisted-by: ClaudeCode:claude-opus-5
Signed-off-by: Ferdinand Thiessen <opensource@fthiessen.de>
@susnux
susnux force-pushed the backport/64289/stable33 branch 2 times, most recently from 41ca989 to c82798f Compare October 1, 2026 12:02
decrypt-all wrote core/encryption_enabled through the typed app config
while every other accessor on this branch - Manager::isEnabled(),
encryption:enable, encryption:disable and the provisioning API - reads
and writes it as the string "yes"/"no". The first decrypt-all therefore
switched the stored type to boolean, after which encryption:enable threw
an AppConfigTypeConflictException and isEnabled() no longer recognised
the value.

The legacy accessors are deprecated, so the command joins
encryption:enable and encryption:disable in the psalm baseline.

Assisted-by: ClaudeCode:claude-opus-5
Signed-off-by: Ferdinand Thiessen <opensource@fthiessen.de>
@susnux
susnux force-pushed the backport/64289/stable33 branch from c82798f to 21d49e2 Compare October 1, 2026 12:20
@susnux
susnux merged commit 33b80c8 into stable33 Oct 1, 2026
164 checks passed
@susnux
susnux deleted the backport/64289/stable33 branch October 1, 2026 13:34
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants