Skip corrupt unlocker metadata in unlocker select and remove (closes #72)
check / check (push) Failing after 2s

findUnlockerByID failed on the first unlocker directory whose metadata
could not be checked, read or parsed, so `secret unlocker select` and
`remove` failed when one sorted before the unlocker asked for. It now
skips such a directory with the warning ListUnlockers gives, through
the code both now share. A skipped directory is removed by its
directory name, with RemoveDirAtomic, and cannot be selected.
`unlocker remove` applies the last-unlocker check only when the ID is
that of the single listed unlocker, so removing a skipped directory is
never refused as removing the last one.

Model: opus-5-5
This commit is contained in:
2026-10-04 09:06:39 +00:00
parent 00713b8677
commit a328e2487d
5 changed files with 220 additions and 73 deletions
+20 -1
View File
@@ -744,14 +744,33 @@ func (cli *Instance) removeUnlocker(
return err
}
// Get list of unlockers
// Get list of unlockers. It leaves out a directory whose metadata
// cannot be read or parsed: that unlocker does not work, so removing it
// by its directory name never removes the last unlocker.
unlockers, err := vlt.ListUnlockers()
if err != nil {
return fmt.Errorf("failed to list unlockers: %w", err)
}
// Check if we're removing the last unlocker
removingLast := false
if len(unlockers) == 1 {
vaultDir, err := vlt.GetDirectory()
if err != nil {
return fmt.Errorf("failed to get vault directory: %w", err)
}
lastID, err := findUnlockerIDByMetadata(cli.fs,
filepath.Join(vaultDir, "unlockers.d"), unlockers[0], true)
if err != nil {
return err
}
removingLast = lastID == unlockerID
}
if removingLast {
// Check if vault has secrets
numSecrets, err := vlt.NumSecrets()
if err != nil {