Keep unlocker list working when unlocker metadata is corrupt (closes #42)
check / check (push) Successful in 1m12s
check / check (push) Successful in 1m12s
PGPUnlocker.GetID() panicked when its metadata could not be read or parsed, which took down `secret unlocker list` for every unlocker. It now warns with the unlocker's directory and returns `pgp-unknown`; metadata with an empty GPG key ID counts as corrupt too. ListUnlockers now skips, with a warning, an unlocker whose metadata file is unreadable or not JSON, as it already did for a missing one. This is the first half of the issue only. Passing the mnemonic in memory moved to #60. Model: opus-5-5
This commit is contained in:
@@ -25,6 +25,11 @@ Bring the repo into policy compliance in one commit:
|
||||
|
||||
# Completed Steps
|
||||
|
||||
- 2026-10-03: A PGP unlocker whose metadata has no usable GPG key ID
|
||||
no longer panics: `GetID()` warns with the unlocker's directory and
|
||||
returns `pgp-unknown`. `ListUnlockers` skips, with a warning, an
|
||||
unlocker whose metadata file cannot be read or parsed instead of
|
||||
failing, so `secret unlocker list` still lists the others.
|
||||
- 2026-10-02: A plain `docker build .` builds again: the size tests
|
||||
skip a case that needs more locked memory than the process can
|
||||
lock, and run every case under `script/cibuild`. The image stamps the
|
||||
@@ -101,8 +106,6 @@ Bring the repo into policy compliance in one commit:
|
||||
- Timing attacks: bytes.Equal passphrase compare (cli/init.go:
|
||||
209-216); non-constant-time public key compare (vault.go:95-100).
|
||||
- High priority:
|
||||
- Return errors instead of panicking on corrupted metadata
|
||||
(pgpunlocker.go:116, keychainunlocker.go:141).
|
||||
- Secure temporary file handling and cleanup.
|
||||
- Print cobra usage only for argument errors, not internal
|
||||
failures.
|
||||
|
||||
Reference in New Issue
Block a user