Lock the state directory and write vault files atomically (closes #34)
check / check (push) Failing after 17s

Each command that changes the state directory holds one lock: flock(2)
on `lock` in the state directory, dropped by the kernel if the process
dies, or a process-wide mutex on the in-memory test filesystem. It
covers the state directory, not each vault, because `currentvault`,
`vault create` and cross-vault moves span vaults, and a lock file in a
vault would be deleted by `vault remove` under a waiting command.

Files go through `secret.WriteFileAtomic`; versions, new secrets and
cross-vault copies are built in a temporary directory and renamed into
place; removals rename out of the way first. Left for later: replacing
an unlocker (#71) and deleting
what an interrupted command leaves under a `.tmp-` name
(#75).

Model: opus-5-5
This commit is contained in:
2026-10-03 16:18:38 +00:00
committed by sneak
parent 7c6531eaf7
commit 60afd590c0
24 changed files with 1832 additions and 187 deletions
+9 -1
View File
@@ -72,10 +72,18 @@ func newDecryptCmd() *cobra.Command {
// resolveEncryptionKey returns a secure buffer holding the age secret key
// for the named secret, generating and storing a new key if the secret
// does not exist. The caller must destroy the returned buffer.
// does not exist. The caller must destroy the returned buffer. It holds the
// state directory lock itself, so that Encrypt streams its input and output
// unlocked and cannot block a secret command at the other end of a pipe.
func (cli *Instance) resolveEncryptionKey(
vlt *vault.Vault, secretName string,
) (*memguard.LockedBuffer, error) {
release, err := vault.LockStateDir(cli.fs, cli.stateDir)
if err != nil {
return nil, err
}
defer release()
// Check if secret exists
secretObj := secret.NewSecret(vlt, secretName)