Stop vault safety checks from reading unreadable state as empty (closes #51)
check / check (push) Waiting to run
check / check (push) Waiting to run
Adding a PGP unlocker checked unlockers.d for a duplicate and, when the directory could not be read, reported no duplicate and went on. It now stops with an error naming the directory and cause. The same flaw guarded removing the last unlocker and removing a vault (an unreadable secrets directory counted as no secrets) and vault import (an unreadable pub.age counted as no long-term key). Those now stop with an error too. `unlocker list` keeps skipping entries it cannot read. `vault rm` and `unlocker rm` now take the state directory lock and call an unexported function that does the work, as `vault import` does, so the tests can reach their checks. Model: opus-5-5
This commit is contained in:
@@ -138,7 +138,12 @@ func (v *Vault) NumSecrets() (int, error) {
|
||||
|
||||
secretsDir := filepath.Join(vaultDir, "secrets.d")
|
||||
|
||||
exists, _ := afero.DirExists(v.fs, secretsDir)
|
||||
exists, err := afero.DirExists(v.fs, secretsDir)
|
||||
if err != nil {
|
||||
return 0, fmt.Errorf("failed to check secrets directory %s: %w",
|
||||
secretsDir, err)
|
||||
}
|
||||
|
||||
if !exists {
|
||||
return 0, nil
|
||||
}
|
||||
@@ -162,7 +167,7 @@ func (v *Vault) NumSecrets() (int, error) {
|
||||
|
||||
exists, err := afero.Exists(v.fs, currentFile)
|
||||
if err != nil {
|
||||
continue // Skip directories we can't read
|
||||
return 0, fmt.Errorf("failed to check %s: %w", currentFile, err)
|
||||
}
|
||||
|
||||
if exists {
|
||||
|
||||
Reference in New Issue
Block a user