Stop vault safety checks from reading unreadable state as empty (closes #51)
check / check (push) Waiting to run
check / check (push) Waiting to run
Adding a PGP unlocker checked unlockers.d for a duplicate and, when the directory or an unlocker's metadata file could not be read, reported no duplicate and went on. The check now reads unlockers.d itself and stops with an error naming the path and cause; `unlocker list` keeps skipping unlockers it cannot read. The same flaw guarded removing the last unlocker and removing a vault (an unreadable secrets directory counted as no secrets) and vault import (an unreadable pub.age counted as no long-term key). Those now stop with an error too. `vault rm` and `unlocker rm` keep the state directory lock and now do their work in an unexported function, as `vault import` does. Model: opus-5-5
This commit was merged in pull request #64.
This commit is contained in:
@@ -104,6 +104,13 @@ Bring the repo into policy compliance in one commit:
|
||||
being removed, encrypted keys included. Nothing deletes it; it
|
||||
must be deleted by hand
|
||||
(https://git.eeqj.de/sneak/secret/issues/75).
|
||||
- 2026-10-03: The checks run before changing a vault now stop with an
|
||||
error naming the path and cause when they cannot read what they
|
||||
inspect, instead of reading the failure as "nothing there": the
|
||||
duplicate check before `unlocker add pgp` (an unreadable
|
||||
`unlockers.d` or unlocker metadata file), the secret count that
|
||||
guards removing the last unlocker and removing a vault, and the
|
||||
existing long-term key check before `vault import`.
|
||||
- 2026-10-03: `version rm`, `version promote` and `get --version`
|
||||
accept a version only if it is one of the versions `version list`
|
||||
lists for that secret, compared as typed before any path is built
|
||||
|
||||
Reference in New Issue
Block a user