Skip corrupt unlocker metadata in unlocker select and remove (closes #72)
check / check (push) Failing after 2s
check / check (push) Failing after 2s
findUnlockerByID failed on the first unlocker directory whose metadata could not be checked, read or parsed, so `secret unlocker select` and `remove` failed when one sorted before the unlocker asked for. It now skips such a directory with the warning ListUnlockers gives, through the code both now share. A skipped directory is removed by its directory name, with RemoveDirAtomic, and cannot be selected. `unlocker remove` applies the last-unlocker check only when the ID is that of the single listed unlocker, so removing a skipped directory is never refused as removing the last one. Model: opus-5-5
This commit is contained in:
@@ -25,6 +25,13 @@ Bring the repo into policy compliance in one commit:
|
||||
|
||||
# Completed Steps
|
||||
|
||||
- 2026-10-04: `secret unlocker select` and `secret unlocker remove`
|
||||
skip, with the warning `unlocker list` gives, an unlocker directory
|
||||
whose metadata file cannot be checked for, read or parsed, instead of
|
||||
failing when it sorts before the unlocker asked for. Such a directory,
|
||||
or one without a metadata file, is removed by its directory name, the
|
||||
name the warning gives; only the directory is removed, since its type
|
||||
is unknown. Removing it never counts as removing the last unlocker.
|
||||
- 2026-10-04: The `Makefile` no longer sets `DOCKER_HOST`, so its docker
|
||||
targets use the local docker daemon, or whatever `DOCKER_HOST` the
|
||||
environment sets. `make build` calls the new `script/build`, which
|
||||
@@ -105,7 +112,7 @@ Bring the repo into policy compliance in one commit:
|
||||
which `vault create` has already made the current vault;
|
||||
- from an unlocker add stopped before its metadata is written, a
|
||||
directory that `unlocker list` warns about and `unlocker rm`
|
||||
cannot remove;
|
||||
removes only by its directory name;
|
||||
- data under a `.tmp-` name in the state directory: a secret or
|
||||
version being added, or the secret, version, unlocker or vault
|
||||
being removed, encrypted keys included. Nothing deletes it; it
|
||||
|
||||
Reference in New Issue
Block a user