From 520257b5e539f2a7c88c903ed2a51051799c9481 Mon Sep 17 00:00:00 2001 From: Shuery <2463253700@qq.com> Date: Sun, 27 Sep 2026 11:21:43 +0800 Subject: [PATCH] =?UTF-8?q?fix:=20=E5=8F=A3=E4=BB=A4=E6=96=87=E4=BB=B6?= =?UTF-8?q?=E9=BB=98=E8=AE=A4=E5=80=BC=E5=9B=9E=E5=88=B0=E4=BB=93=E5=BA=93?= =?UTF-8?q?=E6=A0=B9=EF=BC=88=E6=8C=89=E4=BD=A0=E7=9A=84=E5=86=B3=E5=AE=9A?= =?UTF-8?q?=EF=BC=89=EF=BC=8C=E5=B9=B6=E8=AE=A9=E7=9B=B8=E5=AF=B9=E8=B7=AF?= =?UTF-8?q?=E5=BE=84=E4=B8=8E=E5=B7=A5=E4=BD=9C=E7=9B=AE=E5=BD=95=E6=97=A0?= =?UTF-8?q?=E5=85=B3?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit 你的决定:口令文件继续放在仓库根,靠 .gitignore 的 *.key 兜住"不被提交"。我把出厂默认值改回 baknret.key,并把配置注释从"必须放在仓库之外"改成如实说明这是一次取舍:省事 vs 「不提交」依赖一个规则文件(git add -f、或整目录复制到别处再初始化仓库时,口令会跟着走)。 顺手修掉一个潜在陷阱:口令文件写相对路径时,原先的 Test-Path 是按**当前工作目录**找的。计划任务的工作目录通常是 C:\Windows\System32,在那里 Test-Path baknret.key 为假,加密条目就会以"拿不到口令"失败 —— 而配置看上去毫无问题。现在相对路径按仓库根解析(复用上一轮抽出来的 Resolve-BakNRetRootedPath)。 证据:把工作目录切到 C:\Windows\System32 再跑真实清单只读冒烟,仍然 4/4 通过(那份真实配置里有 5 个加密条目、口令文件就是仓库根的 baknret.key)。 验收:test.ps1 9/9 全绿(7 与 5.1)。 --- Backup.ps1 | 5 +++++ BackupConfig.psd1 | 10 +++++++--- Restore.ps1 | 5 +++++ 3 files changed, 17 insertions(+), 3 deletions(-) diff --git a/Backup.ps1 b/Backup.ps1 index 1a5cc51..629d817 100644 --- a/Backup.ps1 +++ b/Backup.ps1 @@ -162,6 +162,11 @@ $manifest = Read-BakNRetManifest -Path $manifestPath $manifest.compressor = [pscustomobject]@{ name = $tool.Name; command = $tool.Command; extension = $tool.Extension; version = $toolVersion } $passwordFile = if ($KeyFile) { $KeyFile } else { $script:Config.Encryption.PasswordFile } +if ($passwordFile) { + # 相对路径按**仓库根**解析,而不是按当前工作目录:计划任务的工作目录是 C:\Windows\System32, + # 在那里 Test-Path 找不到 baknret.key,加密条目就会以"拿不到口令"失败,而配置看上去没问题。 + $passwordFile = Resolve-BakNRetRootedPath -Path $passwordFile -Default $passwordFile -Root $PSScriptRoot +} $password = Get-BakNRetPassword -PasswordFile $passwordFile $encryptAll = [bool]$script:Config.Encryption.Enabled $showToolOutput = (-not $QuietTool) -and ($script:Config.ToolOutput -ne 'quiet') diff --git a/BackupConfig.psd1 b/BackupConfig.psd1 index fd6921b..6930bd7 100644 --- a/BackupConfig.psd1 +++ b/BackupConfig.psd1 @@ -49,15 +49,19 @@ # 口令本身按以下优先级获取(见 README「加密」): # 1. -Password 命令行参数 # 2. $env:BAKNRET_PASSWORD - # 3. PasswordFile 指向的文件首行 —— 必须指向仓库**之外**的文件; - # 出厂默认值留空:默认值指向仓库里的某个文件,等于鼓励把口令放进版本库 + # 3. PasswordFile 指向的文件首行 (首行即口令) + # + # 出厂默认值就是仓库根的 baknret.key,靠 .gitignore 的 *.key 兜住「不被提交」。 + # 这是**取舍**而非疏忽:留在仓库根最省事(口令与配置在一起,搬家不容易丢),代价是 + # 「不提交」这件事依赖一个规则文件 —— 谁写了 git add -f、或把整个目录复制到别处再 + # 初始化仓库,口令就会跟着走。要更稳就把文件放到仓库外,用下面的 B 或 A。 # 4. 交互式询问(仅交互式会话;计划任务里不会停下来等输入) # 全都拿不到时该条目明确失败,绝不退化成明文归档。 # # 注意 7z 只接受命令行口令,口令在本机进程列表里短暂可见,这是 7z 本身的限制。 Encryption = @{ Enabled = $false - PasswordFile = '' + PasswordFile = 'baknret.key' EncryptHeaders = $true } diff --git a/Restore.ps1 b/Restore.ps1 index 5d67ec3..1e552cb 100644 --- a/Restore.ps1 +++ b/Restore.ps1 @@ -115,6 +115,11 @@ if (-not $WhatIfPreference -and -not $VerifyOnly) { } $passwordFile = if ($KeyFile) { $KeyFile } else { $script:Config.Encryption.PasswordFile } +if ($passwordFile) { + # 相对路径按**仓库根**解析,而不是按当前工作目录:计划任务的工作目录是 C:\Windows\System32, + # 在那里 Test-Path 找不到 baknret.key,加密条目就会以"拿不到口令"失败,而配置看上去没问题。 + $passwordFile = Resolve-BakNRetRootedPath -Path $passwordFile -Default $passwordFile -Root $PSScriptRoot +} $password = Get-BakNRetPassword -PasswordFile $passwordFile # ============================================================================