Refuse to create a vault that already exists (closes #74)
check / check (push) Successful in 1m26s

vault.CreateVault now checks for the vault before writing anything and
fails with "vault NAME already exists" (vault.ErrVaultExists). secret
init and secret vault create call it while holding the state directory
lock, so two creates at once cannot both pass the check. Before, either
command over an existing vault replaced its metadata, passphrase
unlocker and longterm.age, so none of its secrets could be decrypted.

The lock tests set up the vault "work" instead of "default", which init
now refuses to create again.

Model: opus-5-5
This commit is contained in:
2026-10-04 04:06:45 +00:00
committed by sneak
parent 663986f551
commit 5586169396
5 changed files with 127 additions and 9 deletions
+9
View File
@@ -25,6 +25,15 @@ Bring the repo into policy compliance in one commit:
# Completed Steps
- 2026-10-04: `secret init` refuses when the default vault exists, and
`secret vault create NAME` when `NAME` does, with "vault NAME already
exists", before writing anything. The check is in `vault.CreateVault`,
which both commands call while holding the state directory lock, so two
creates of one vault at once cannot both pass the check. Before, either
command replaced the vault's metadata, passphrase unlocker and
`longterm.age`, so none of its secrets could be decrypted any more. A
vault left without an unlocker by an `init` or `vault create` stopped at
the passphrase prompt is refused like any other.
- 2026-10-03: `secret mv` rejects a move whose destination is the
source (`mv --force x x`, `mv --force work:x work:`, or an empty
destination, which defaults to the source name) before changing