aboutsummaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authorCraig Jennings <c@cjennings.net>2026-10-05 05:08:06 -0500
committerCraig Jennings <c@cjennings.net>2026-10-05 05:08:06 -0500
commit8a1555fa707b8ad7b98b9f312454b77816207bc3 (patch)
tree81f98245000081034ecfa0aa08c7b8f0a5c2ea35
parentd535b4362f07df83c805f1924ccdf663eb978ae1 (diff)
downloadarchsetup-8a1555fa707b8ad7b98b9f312454b77816207bc3.tar.gz
archsetup-8a1555fa707b8ad7b98b9f312454b77816207bc3.zip
chore(tasks): file the headless calendar-sync fixHEADmain
-rw-r--r--todo.org27
1 files changed, 27 insertions, 0 deletions
diff --git a/todo.org b/todo.org
index 0f769e9..ed72255 100644
--- a/todo.org
+++ b/todo.org
@@ -46,6 +46,33 @@ below):
input-side-spec.org (DRAFT, four decisions open).
* Archsetup Open Work
+** TODO [#B] calendar-sync fails headless after every boot until authinfo is unlocked :bug:dotfiles:gpg:
+:PROPERTIES:
+:LAST_REVIEWED: 2026-10-04
+:END:
+Found in the 2026-10-04 velox health check. The calendar-sync timer (every 10 minutes)
+failed on every run from the 2026-09-29 boot onward (711 journal errors, last success
+2026-09-27) with "Decryption failed, Bad session key". The feed URLs live in
+=~/.authinfo.gpg= (dotfiles =common/=), which is symmetric AES256. The batch Emacs
+the timer runs can't answer a passphrase prompt, so the sync fails until something
+interactive caches that passphrase in gpg-agent. The agent's 400-day cache TTL means
+it holds once entered, but every reboot starts cold.
+
+Re-encrypting to the GPG key alone doesn't fix it. It only swaps which passphrase
+has to be typed per boot, and on 2026-10-04 ratio's agent had no GPG key cached at
+all (its sync works only on the cached symmetric passphrase), so the switch would
+break ratio until the key is unlocked there.
+
+The fix that actually makes it headless: install =pam-gnupg= so login presets the
+key passphrase into gpg-agent, then re-encrypt authinfo to the =c@cjennings.net= key
+(B832F070). That needs the key passphrase to match the login password, or a decision
+to make it match. pam-gnupg is three pieces, and all three are required: add
+=allow-preset-passphrase= to =gpg-agent.conf= (the current config lacks it, and
+without it the preset is refused), list the encryption subkey's keygrip in
+=~/.pam-gnupg=, and add the =pam_gnupg.so= auth and session lines to the login PAM
+stack. Do it on both daily drivers. Re-encrypt by piping decrypt into
+encrypt, never via plaintext on disk, and verify by comparing plaintext hashes.
+
** TODO [#C] Closed tasks pinned to the agenda by a live planning line :chore:quick:solo:
:PROPERTIES:
:LAST_REVIEWED: 2026-09-25