Delete .tmp- leftovers of a killed command when the lock is next taken (closes #75)
check / check (push) Failing after 3s

A command killed part-way could leave a temporary file or directory of
secret.WriteFileAtomic or secret.TempDirFor, encrypted keys included,
for good. LockStateDir now empties the lock file once it holds the lock
and writes "finished" there just before releasing it. A holder that
does not find that deletes such leftovers from the state directory,
each vault, each secret and each version, the only places those helpers
make them, matching names that start with "." and hold ".tmp-". After a
command that finished nothing is searched, so the added time does not
grow with the number of secrets and versions. A test shows that
`unlocker remove` removes an unlocker directory with no metadata file.

Model: opus-5-5
This commit is contained in:
2026-10-04 16:06:00 +00:00
parent 1cc8653981
commit a23b4e7db7
8 changed files with 317 additions and 17 deletions
+3 -1
View File
@@ -362,7 +362,6 @@ func requireWaitsForLock(
fs := afero.NewMemMapFs()
olderVersion, unlockerID := setupEveryCommand(t, fs, withUnlocker)
before := stateDirModTimes(t, fs)
release, err := vault.LockStateDir(fs, testStateDir)
require.NoError(t, err)
@@ -372,6 +371,9 @@ func requireWaitsForLock(
release = sync.OnceFunc(release)
defer release()
// Taken only now, since taking the lock writes the lock file.
before := stateDirModTimes(t, fs)
unlockPassphrase := memguard.NewBufferFromBytes([]byte(testPassphrase))
defer unlockPassphrase.Destroy()