Skip to content

Commit 44a42f0

Browse files
arimxyerclaude
andcommitted
fix: use Hextra-compatible callout shortcodes and update CHANGELOG
- Replace Book theme `{{< hint >}}` with Hextra `{{< callout >}}` shortcodes - Fix Hugo build failure in GitHub Pages deployment - Add comprehensive v0.11.0 CHANGELOG entry with V2 vault format details 🤖 Generated with [Claude Code](https://claude.com/claude-code) Co-Authored-By: Claude <noreply@anthropic.com>
1 parent 5a40d42 commit 44a42f0

2 files changed

Lines changed: 43 additions & 8 deletions

File tree

‎CHANGELOG.md‎

Lines changed: 35 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -7,6 +7,41 @@ and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0
77

88
## [Unreleased]
99

10+
## [0.11.0] - 2025-12-05
11+
12+
### Added
13+
- **V2 Vault Format**: New key wrapping architecture with Data Encryption Key (DEK) and dual Key Encryption Keys (KEKs)
14+
- Password-derived KEK for normal vault access
15+
- Recovery-derived KEK for recovery phrase unlock
16+
- Both KEKs wrap the same DEK, enabling secure recovery without password knowledge
17+
- **Vault Migration Command**: `pass-cli vault migrate` to upgrade V1 vaults to V2 format
18+
- Preserves all existing credentials
19+
- Generates new recovery phrase with proper key wrapping
20+
- Interactive verification of new recovery phrase backup
21+
- Optional BIP-39 passphrase protection ("25th word")
22+
- **Recovery Key Integration**: BIP-39 recovery phrases now fully functional for V2 vaults
23+
- 6-word challenge recovery (73.8 quintillion combinations)
24+
- Argon2id key derivation for recovery KEK
25+
- Recovery-wrapped DEK stored in vault metadata
26+
- **New Vault Metadata Fields**: `wrapped_dek`, `wrapped_dek_nonce`, `recovery_wrapped_dek`, `recovery_wrapped_dek_nonce`, `recovery_salt`
27+
28+
### Fixed
29+
- **Critical**: V1 vaults had a bug where recovery phrases could not unlock the vault - V2 format resolves this
30+
- Recovery tests updated for V2 key wrapping format
31+
- Stale keychain state handling in vault tests
32+
- JSON unmarshal error return value checking
33+
34+
### Changed
35+
- Vault initialization now uses V2 format by default with `InitializeWithRecovery`
36+
- Recovery unlock path uses `RecoverWithMnemonic` with proper DEK unwrapping
37+
- Documentation updated with V2 architecture details, migration guide, and recovery workflows
38+
39+
### Security
40+
- AES-256-GCM encryption for DEK wrapping with unique nonces
41+
- Argon2id (memory-hard) for recovery phrase key derivation
42+
- PBKDF2-SHA256 (600,000 iterations) for password key derivation
43+
- Separate salts for password and recovery derivation paths
44+
1045
## [0.10.0] - 2025-11-12
1146

1247
### Added

‎docs/02-guides/recovery-phrase.md‎

Lines changed: 8 additions & 8 deletions
Original file line numberDiff line numberDiff line change
@@ -18,9 +18,9 @@ Pass-CLI's BIP39 recovery feature generates a 24-word recovery phrase when you c
1818
- [OK] **Fast**: Recover in under 30 seconds
1919
- [OK] **Optional**: Can skip with `--no-recovery` flag if you use keychain integration
2020

21-
{{< hint warning >}}
21+
{{< callout type="warning" >}}
2222
**V1 Vault Users**: If you created your vault before v0.2.0, your recovery phrase will NOT work. V1 vaults have a bug where recovery phrases cannot unlock the vault. You must migrate to V2 format first. See [Migrating to V2 Format](#migrating-to-v2-format) below.
23-
{{< /hint >}}
23+
{{< /callout >}}
2424

2525
## Setting Up Recovery
2626

@@ -86,9 +86,9 @@ pass-cli init --no-recovery
8686

8787
V1 vaults (created before pass-cli v0.2.0) have a critical bug: recovery phrases cannot actually unlock the vault. V2 vaults fix this by implementing proper key wrapping, making recovery phrases fully functional.
8888

89-
{{< hint info >}}
89+
{{< callout type="info" >}}
9090
**Check Your Vault Version**: Run `pass-cli doctor` to see if your vault is v1 or v2. If it shows "Vault Format: v1", you need to migrate.
91-
{{< /hint >}}
91+
{{< /callout >}}
9292

9393
### Migration Steps
9494

@@ -162,9 +162,9 @@ Write down these 24 words in order:
162162
• Your old recovery phrase (if any) is now invalid
163163
```
164164

165-
{{< hint danger >}}
165+
{{< callout type="error" >}}
166166
**Important**: Your OLD recovery phrase no longer works. The new recovery phrase shown here is what you must use to recover your vault.
167-
{{< /hint >}}
167+
{{< /callout >}}
168168

169169
#### Step 5: Verify Your Backup
170170

@@ -233,9 +233,9 @@ Use recovery if:
233233
- [OK] You have your 24-word recovery phrase
234234
- [OK] Your vault is V2 format (or migrated to V2)
235235
236-
{{< hint warning >}}
236+
{{< callout type="warning" >}}
237237
**V1 Vaults Cannot Use Recovery**: If you haven't migrated to V2 format yet, recovery will not work. See [Migrating to V2 Format](#migrating-to-v2-format) above.
238-
{{< /hint >}}
238+
{{< /callout >}}
239239
240240
**Note**: If keychain is enabled and accessible, you don't need recovery. Your master password is stored securely in your OS keychain.
241241

0 commit comments

Comments
 (0)