Leave no partial unlocker directory when adding an unlocker fails (closes #48)
check / check (push) Waiting to run
check / check (push) Waiting to run
CreatePGPUnlocker looked up the GPG key's fingerprint, and the keychain unlocker got the long-term key, only after writing part of the unlocker, so a failure there left a directory with no metadata. Both now do every step that can fail before writing anything. `secret unlocker add pgp` looks the fingerprint up once, for its duplicate check, and passes it to CreatePGPUnlocker to record. All four unlocker types write their files through the new secret.WriteDir, which builds a new directory in a temporary directory, renames it into place when complete and removes it on a failure. A directory that already exists, as when an unlocker replaces one of the same name, is written in place and never removed. Model: opus-5-5
This commit was merged in pull request #90.
This commit is contained in:
@@ -25,6 +25,17 @@ Bring the repo into policy compliance in one commit:
|
||||
|
||||
# Completed Steps
|
||||
|
||||
- 2026-10-04: A failed unlocker add no longer leaves a partial unlocker
|
||||
directory (https://git.eeqj.de/sneak/secret/issues/48).
|
||||
`secret unlocker add pgp` resolves the GPG key's fingerprint once, for
|
||||
its duplicate check, and passes it to `CreatePGPUnlocker` to record.
|
||||
`CreatePGPUnlocker` and `CreateKeychainUnlocker` get the long-term key
|
||||
and encrypt everything before writing anything. All four unlocker
|
||||
types write their files through `secret.WriteDir`: a new unlocker is
|
||||
built in a temporary directory, renamed into place when complete and
|
||||
removed on a failure. One added under the directory name of an
|
||||
existing unlocker is still written into that directory in place
|
||||
(https://git.eeqj.de/sneak/secret/issues/71).
|
||||
- 2026-10-04: `secret unlocker select` and `secret unlocker remove`
|
||||
skip, with the warning `unlocker list` gives, an unlocker directory
|
||||
whose metadata file cannot be checked for, read or parsed, instead of
|
||||
@@ -129,13 +140,10 @@ Bring the repo into policy compliance in one commit:
|
||||
- from `init` or `vault create` killed after the passphrase prompt
|
||||
but before the unlocker is written, a vault with no unlocker,
|
||||
which `vault create` has already made the current vault;
|
||||
- from an unlocker add stopped before its metadata is written, a
|
||||
directory that `unlocker list` warns about and `unlocker rm`
|
||||
removes only by its directory name;
|
||||
- data under a `.tmp-` name in the state directory: a secret or
|
||||
version being added, or the secret, version, unlocker or vault
|
||||
being removed, encrypted keys included. Nothing deletes it; it
|
||||
must be deleted by hand
|
||||
- data under a `.tmp-` name in the state directory: a secret,
|
||||
version or unlocker being added, or the secret, version, unlocker
|
||||
or vault being removed, encrypted keys included. Nothing deletes
|
||||
it; it must be deleted by hand
|
||||
(https://git.eeqj.de/sneak/secret/issues/75).
|
||||
- 2026-10-03: The checks run before changing a vault now stop with an
|
||||
error naming the path and cause when they cannot read what they
|
||||
|
||||
Reference in New Issue
Block a user