Skip corrupt unlocker metadata in unlocker select and remove (closes #72)
check / check (push) Waiting to run
check / check (push) Waiting to run
findUnlockerByID failed on the first unlocker directory whose metadata could not be checked, read or parsed, so `secret unlocker select` and `remove` failed when one sorted before the unlocker asked for. It now skips such a directory with the warning ListUnlockers gives, through the code both now share. A skipped directory is removed by its directory name, with RemoveDirAtomic, and cannot be selected. Removing one whose metadata file is missing or corrupt never counts as removing the last unlocker; removing one whose metadata file cannot be checked for or read does, since it may be the only working unlocker. Model: opus-5-5
This commit was merged in pull request #91.
This commit is contained in:
@@ -25,6 +25,16 @@ Bring the repo into policy compliance in one commit:
|
||||
|
||||
# Completed Steps
|
||||
|
||||
- 2026-10-04: `secret unlocker select` and `secret unlocker remove`
|
||||
skip, with the warning `unlocker list` gives, an unlocker directory
|
||||
whose metadata file cannot be checked for, read or parsed, instead of
|
||||
failing when it sorts before the unlocker asked for. Such a directory,
|
||||
or one without a metadata file, is removed by its directory name, the
|
||||
name the warning gives; only the directory is removed, since its type
|
||||
is unknown. Removing one whose metadata file is missing or corrupt
|
||||
never counts as removing the last unlocker. Removing one whose metadata
|
||||
file cannot be checked for or read always does, since it may be the
|
||||
only working unlocker, so in a vault with secrets it needs `--force`.
|
||||
- 2026-10-04: A failed command prints its error once, without the usage
|
||||
text after it (https://git.eeqj.de/sneak/secret/issues/41). Usage is
|
||||
still printed for a command called wrongly: wrong number of arguments,
|
||||
@@ -121,7 +131,7 @@ Bring the repo into policy compliance in one commit:
|
||||
which `vault create` has already made the current vault;
|
||||
- from an unlocker add stopped before its metadata is written, a
|
||||
directory that `unlocker list` warns about and `unlocker rm`
|
||||
cannot remove;
|
||||
removes only by its directory name;
|
||||
- data under a `.tmp-` name in the state directory: a secret or
|
||||
version being added, or the secret, version, unlocker or vault
|
||||
being removed, encrypted keys included. Nothing deletes it; it
|
||||
|
||||
Reference in New Issue
Block a user