Stop vault safety checks from reading unreadable state as empty (closes #51)
check / check (push) Successful in 1m8s
check / check (push) Successful in 1m8s
Adding a PGP unlocker checked unlockers.d for a duplicate and, when the directory could not be read, reported no duplicate and went on. The check now returns an error naming the directory and cause, and the add stops; a duplicate found is still reported as one. The same flaw guarded removing the last unlocker and removing a vault (an unreadable secrets directory counted as no secrets) and vault import (an unreadable pub.age counted as no long-term key). Those now stop with an error too. `unlocker list` keeps skipping entries it cannot read; a comment at the duplicate check says why the two differ. Model: opus-5-5
This commit is contained in:
@@ -25,6 +25,13 @@ Bring the repo into policy compliance in one commit:
|
||||
|
||||
# Completed Steps
|
||||
|
||||
- 2026-10-03: The checks run before changing a vault now stop with an
|
||||
error naming the path and cause when they cannot read what they
|
||||
inspect, instead of reading the failure as "nothing there": the
|
||||
duplicate check before `unlocker add pgp` (an unreadable
|
||||
`unlockers.d`), the secret count that guards removing the last
|
||||
unlocker and removing a vault, and the existing long-term key check
|
||||
before `vault import`.
|
||||
- 2026-10-02: A plain `docker build .` builds again: the size tests
|
||||
skip a case that needs more locked memory than the process can
|
||||
lock, and run every case under `script/cibuild`. The image stamps the
|
||||
|
||||
Reference in New Issue
Block a user